Sunday, 2017-12-10

*** mgariepy has quit IRC00:24
*** mgariepy has joined #openstack-ansible00:28
*** vnogin has joined #openstack-ansible00:29
*** vnogin has quit IRC00:30
*** vnogin has joined #openstack-ansible00:32
*** DanyC has joined #openstack-ansible00:35
*** vnogin has quit IRC00:39
*** DanyC has quit IRC00:40
*** vnogin has joined #openstack-ansible00:47
*** Brew has joined #openstack-ansible01:00
*** mgariepy has quit IRC01:15
*** mgariepy has joined #openstack-ansible01:21
*** DanyC has joined #openstack-ansible01:36
*** markvoelker has joined #openstack-ansible01:38
*** DanyC has quit IRC01:41
*** markvoelker has quit IRC02:11
openstackgerritMerged openstack/openstack-ansible-repo_build stable/pike: Fix ansible lint tests  https://review.openstack.org/52616402:16
openstackgerritMerged openstack/openstack-ansible master: Do not apply varstest to all scenarios  https://review.openstack.org/52392002:23
*** DanyC has joined #openstack-ansible02:37
*** dave-mccowan has joined #openstack-ansible02:38
*** DanyC has quit IRC02:42
openstackgerritMerged openstack/openstack-ansible stable/newton: Update all SHAs for 14.2.14  https://review.openstack.org/52668402:44
openstackgerritKevin Carter (cloudnull) proposed openstack/openstack-ansible-repo_server master: Set pypi-server to cache and use known built wheels  https://review.openstack.org/52688602:54
*** dave-mccowan has quit IRC02:57
*** vnogin has quit IRC03:02
openstackgerritKevin Carter (cloudnull) proposed openstack/openstack-ansible master: Enable access to the pypi-server on the repo infra  https://review.openstack.org/52688703:03
*** markvoelker has joined #openstack-ansible03:08
openstackgerritKevin Carter (cloudnull) proposed openstack/openstack-ansible-pip_install master: Set pip to use the pypi-server when locked down  https://review.openstack.org/52688903:40
*** vnogin has joined #openstack-ansible03:41
*** markvoelker has quit IRC03:41
*** Brew has quit IRC03:43
openstackgerritKevin Carter (cloudnull) proposed openstack/openstack-ansible master: [DNM] Testing pip_install and repo_server changes  https://review.openstack.org/52689003:44
*** vnogin has quit IRC03:44
openstackgerritKevin Carter (cloudnull) proposed openstack/openstack-ansible-pip_install master: Set pip to use the pypi-server when locked down  https://review.openstack.org/52688903:47
openstackgerritMerged openstack/openstack-ansible-os_neutron stable/pike: Ensure LBaaSv2 deployment is tested  https://review.openstack.org/52565503:54
openstackgerritKevin Carter (cloudnull) proposed openstack/openstack-ansible-pip_install master: Set pip to use the pypi-server when locked down  https://review.openstack.org/52688904:01
openstackgerritKevin Carter (cloudnull) proposed openstack/openstack-ansible-pip_install master: Set pip to use the pypi-server when locked down  https://review.openstack.org/52688904:20
*** adreznec has quit IRC04:20
*** adreznec has joined #openstack-ansible04:26
*** armaan has quit IRC04:26
openstackgerritKevin Carter (cloudnull) proposed openstack/openstack-ansible master: [DNM] Testing pip_install and repo_server changes  https://review.openstack.org/52689004:29
*** bhujay has joined #openstack-ansible04:35
*** bhujay has quit IRC04:35
*** adreznec has quit IRC04:37
openstackgerritKevin Carter (cloudnull) proposed openstack/openstack-ansible master: [DNM] Testing pip_install and repo_server changes  https://review.openstack.org/52689004:40
openstackgerritMerged openstack/openstack-ansible stable/ocata: Update all SHAs for 15.1.14  https://review.openstack.org/52685204:56
*** indistylo has joined #openstack-ansible05:00
*** indistylo has quit IRC05:06
*** indistylo has joined #openstack-ansible05:08
SamYaplecloudnull prometheanfire re: nginx+uwsgi+glance. got it all working, mostly. haproxy was severing the connection after 1m ('timeout server 1m'). the way its working seems to mean nginx isn't doing any kind of keepalive stuff and that upsets haproxy. bumped timout to 30m and its all good05:11
SamYaplethough im not entirely happy with that solution, but its still downs the backend if the checks fail, so meh. ill be ok with it for now05:12
prometheanfireSamYaple: must be why I don't hit it (I don't use haproxy)05:13
SamYapleoh yea. for sure then. straight to nginx its no problem at all05:13
SamYaplei bet there is a way to make everything happy, but im not an nginx/haproxy/uwsgi expert enough to know what that is05:14
SamYaplei did turn on all the gzip support in nginx though, and that helped alot with raw images05:14
prometheanfiregzip + web server is a sec issue05:17
prometheanfirehttps://www.wikiwand.com/en/BREACH05:17
SamYaplesurely there are work arounds for that...05:20
prometheanfirecompress before upload, but could turn things into a preimage attack05:22
prometheanfirenot sure those work on tls05:23
SamYapleill have to investigate further, but given the environment where this runs, im not sure this attack could be really exploited05:24
* prometheanfire shrugs05:26
openstackgerritMerged openstack/openstack-ansible stable/pike: Disable offloading in test by default  https://review.openstack.org/52417305:28
*** indistylo has quit IRC05:28
SamYaplealright fair enough. ill remove it. can't miss performance you never had05:30
prometheanfireheh05:33
SamYapledude. you won an argument with "shurgs"05:33
SamYaplego you!05:33
prometheanfireneat05:33
prometheanfire:P05:33
SamYapleprometheanfire: would you have a reference nginx file that you use that has lots of knobs turned for security laying around?05:34
*** markvoelker has joined #openstack-ansible05:39
prometheanfirelol, looks like I use gzip05:41
prometheanfirehttps://gist.github.com/prometheanfire/c5a24d6375d3dad0b9fb3526ad488a2e and https://gist.github.com/prometheanfire/2a5ea3d8e97f32ba7789c367c7fe088c05:42
prometheanfirelet me know when you have them, want to take them down05:42
SamYaplehaha05:45
SamYapleok moment05:45
SamYapleprometheanfire: take em down05:46
SamYaplethanks man05:46
SamYapleim considering using nginx instead of haproxy, then setting up 3 vips with keepalived and using dns loadbalncing as well (each node will know about all the other ones, but will have a weighted preference for its local server)05:47
SamYaplebut i can't figure out a clean way for keepalived to hand the vip back without severing connections05:47
prometheanfireya, I don't do any vip stuff05:48
SamYaplehow do you achieve the HA?05:48
prometheanfirewhat HA?05:49
prometheanfireI back up my server and can restore it if needed05:49
prometheanfireeventually I want to run OSA, but that'd require getting it working on gentoo :P05:49
SamYaplefair enough. this is for real servers though :P05:49
prometheanfirespeaking of, need to look at the images, should be able to make a gentoo job...05:50
SamYaplei bet i can do some conntrack magic to make vip transferring work05:50
prometheanfireya, those sec stuff I got from some doc I found online somewhere05:50
*** ivve_ is now known as ivve05:50
prometheanfireprobably05:50
SamYaplecool man. i appreciate it05:50
prometheanfireso it should be good at least :D05:50
SamYaplei was about to start looking for the HSTS stuff, now i dont have too05:50
prometheanfiresome stuff then :D05:51
SamYapledoesnt look like you are passing in the client ip to the backend server, nor the X-Forward-Proto05:51
SamYaplewould that be needed or useful for uwsgi backend?05:52
SamYaplei suppose the nginx logs would have that info instead05:52
prometheanfireya, I don't pass it in for my openstack setup (that was blog setup)05:52
SamYapleill have to play with it to see how the logs look05:53
SamYaplesuper helpful info here though. thanks buddy!05:53
SamYaplenow if i can just get that ERROR 104 in the nonovncproxy logs to go away....05:54
prometheanfirenot sure what that's about05:55
prometheanfirenovnc was annoying though05:55
SamYaplei think its just some bad nova code. i *think* its fixed upstream, but im on mitaka (heopfully getting approval to push to ocata this week)05:56
SamYapleits not novnc or the novnc html code itself, thats for sure05:56
prometheanfirejust 370 or so packages left to update...05:57
SamYapletis nothing05:57
prometheanfiremonthly server update time here, enabling python35 and 36, switching the defaults, etc05:57
prometheanfirebinpkgs help some05:58
SamYapleimrunning python35 openstack pike at my house :)05:58
prometheanfireI was doing 34 on a few services, but 35 now05:58
SamYaplenot quite related, but i like bringing it up whenever someone mentions python305:58
prometheanfire35 wasn't stable in gentoo05:58
SamYaplepor que?05:58
prometheanfirethen 35 and 36 went stable within a month of eachother :D05:59
SamYapleoh i see what you mean05:59
SamYaplehaha yea thats alot of work05:59
SamYaplei want to do more with python3 async stuff05:59
prometheanfirenew glibc new gcc new profiles05:59
prometheanfirea bunch of stuff recently05:59
prometheanfireshould do OSA on gentoo musl, just to see what breaks06:00
SamYaplei want to get some gentoo LOCI going myself. havent had the time06:00
prometheanfireI would have done more openstack or puppet stuff last weekend (or this weekend), but had to work on arm64 stages...06:01
prometheanfireI'm not even the arm64 guy06:01
SamYapleyou are now!06:02
prometheanfirenot for long, the build box goes back to his house tomorrow06:02
prometheanfireI did fix the catalyst specs (just a couple small things), so anyone can build it now06:03
prometheanfireanyway, this weekend is server update and backup weekend, next weekend maybe...06:04
SamYaplewell good luck man!see you in dublin...?06:04
prometheanfireyarp, should be going06:04
SamYapleawesome. cool man. well ima take off06:04
SamYaplethanks again forthe help06:04
prometheanfirenot sure if I'll be PTL, but should be going06:04
prometheanfirenn06:05
*** markvoelker has quit IRC06:12
openstackgerritKevin Carter (cloudnull) proposed openstack/openstack-ansible master: Add nspawn container driver  https://review.openstack.org/47701706:12
openstackgerritKevin Carter (cloudnull) proposed openstack/openstack-ansible master: Add nspawn container driver  https://review.openstack.org/47701706:28
*** bhujay has joined #openstack-ansible06:34
*** bhujay has quit IRC06:54
*** gkadam has joined #openstack-ansible06:58
*** markvoelker has joined #openstack-ansible07:09
*** markvoelker has quit IRC07:43
openstackgerritMerged openstack/openstack-ansible stable/pike: Run ARA only if enabled  https://review.openstack.org/51221608:24
*** markvoelker has joined #openstack-ansible08:40
*** DanyC has joined #openstack-ansible08:42
*** vnogin has joined #openstack-ansible08:45
*** DanyC has quit IRC08:46
*** vnogin has quit IRC08:49
*** sxc731 has joined #openstack-ansible08:50
*** gouthamr has quit IRC09:02
*** markvoelker has quit IRC09:13
*** bhujay has joined #openstack-ansible09:20
openstackgerritManuel Buil proposed openstack/openstack-ansible master: Add networking-sfc repo to repo_packages  https://review.openstack.org/52526409:34
openstackgerritManuel Buil proposed openstack/openstack-ansible-os_neutron master: Provide support for SFC deployments  https://review.openstack.org/51090909:45
*** SmearedBeard has quit IRC09:51
*** SmearedBeard has joined #openstack-ansible09:54
openstackgerritManuel Buil proposed openstack/openstack-ansible master: Add networking-sfc repo to repo_packages  https://review.openstack.org/52526410:06
*** DanyC has joined #openstack-ansible10:36
*** DanyC has quit IRC10:41
*** markvoelker has joined #openstack-ansible11:10
openstackgerritJean-Philippe Evrard proposed openstack/openstack-ansible master: Build everything on metal  https://review.openstack.org/50422411:18
*** vnogin has joined #openstack-ansible11:21
*** DanyC has joined #openstack-ansible11:29
*** DanyC_ has joined #openstack-ansible11:38
*** vnogin has quit IRC11:38
*** DanyC has quit IRC11:41
*** markvoelker has quit IRC11:43
*** DanyC_ has quit IRC11:54
*** sxc731 has quit IRC11:59
*** sxc731 has joined #openstack-ansible12:03
*** bhujay has quit IRC12:18
*** openstackstatus has quit IRC12:26
*** openstackstatus has joined #openstack-ansible12:27
*** ChanServ sets mode: +v openstackstatus12:27
*** vnogin has joined #openstack-ansible12:27
*** markvoelker has joined #openstack-ansible12:40
*** hamza21 has joined #openstack-ansible12:51
*** markvoelker has quit IRC13:14
*** sxc731 has quit IRC13:44
*** vnogin has quit IRC13:47
openstackgerritMerged openstack/openstack-ansible-os_tempest master: Allow the experimental trigger of the integrated repo  https://review.openstack.org/52597013:56
*** sxc731 has joined #openstack-ansible14:30
*** vnogin has joined #openstack-ansible14:37
openstackgerritMerged openstack/openstack-ansible master: Update variable scopes  https://review.openstack.org/52346814:38
*** vnogin has quit IRC14:39
*** sxc731 has left #openstack-ansible14:55
*** markvoelker has joined #openstack-ansible15:11
*** woodard has joined #openstack-ansible15:24
*** hamza21 has quit IRC15:26
*** cshen has joined #openstack-ansible15:28
openstackgerritKevin Carter (cloudnull) proposed openstack/openstack-ansible master: DNM - Testing pip_install and repo_server changes  https://review.openstack.org/52689015:33
openstackgerritKevin Carter (cloudnull) proposed openstack/openstack-ansible master: [DNM] Testing pip_install and repo_server changes  https://review.openstack.org/52689015:36
cloudnullanyone have an idea why that change is not triggering the gate? ^15:37
openstackgerritMerged openstack/openstack-ansible stable/pike: Update all SHAs for 16.0.6  https://review.openstack.org/52668215:38
*** phalmos has joined #openstack-ansible15:39
*** vnogin has joined #openstack-ansible15:41
*** markvoelker has quit IRC15:44
openstackgerritKevin Carter (cloudnull) proposed openstack/openstack-ansible master: Add nspawn container driver  https://review.openstack.org/47701715:53
*** vnogin has quit IRC15:55
*** phalmos has quit IRC15:56
openstackgerritKevin Carter (cloudnull) proposed openstack/openstack-ansible master: [DNM] Testing pip_install and repo_server changes  https://review.openstack.org/52689015:57
openstackgerritJean-Philippe Evrard proposed openstack/openstack-ansible master: Use Ansible 2.4  https://review.openstack.org/52277816:15
*** savvas has quit IRC16:16
*** savvas has joined #openstack-ansible16:16
*** savvas_ has joined #openstack-ansible16:20
*** savvas has quit IRC16:20
*** armaan has joined #openstack-ansible16:20
*** cshen has quit IRC16:24
*** DanyC has joined #openstack-ansible16:27
*** markvoelker has joined #openstack-ansible16:42
*** gkadam has quit IRC16:42
openstackgerritKevin Carter (cloudnull) proposed openstack/openstack-ansible-os_glance master: Update glance NFS for systemd  https://review.openstack.org/52693017:11
*** markvoelker has quit IRC17:15
*** cshen has joined #openstack-ansible17:25
*** cshen has quit IRC17:32
*** armaan has quit IRC17:33
openstackgerritKevin Carter (cloudnull) proposed openstack/openstack-ansible-os_glance master: Update glance NFS for systemd  https://review.openstack.org/52693017:41
openstackgerritKevin Carter (cloudnull) proposed openstack/openstack-ansible master: Converge neutron agents onto Baremetal  https://review.openstack.org/45445017:42
openstackgerritKevin Carter (cloudnull) proposed openstack/openstack-ansible master: Add nspawn container driver  https://review.openstack.org/47701717:43
cloudnullgit anyone is around and can take a look at those last two ^. I'd greatly appreciate it17:43
*** ArchiFleKs has joined #openstack-ansible18:05
*** DanyC_ has joined #openstack-ansible18:05
*** DanyC has quit IRC18:08
*** woodard has quit IRC18:08
savvas_Good Morning everyone18:11
savvas_I still seem to be having some issues on my OA Magnum deployment, I can't get clusters to create, they simply timeout. I think it is probably a communication issue between the Magnum containers and other services, but I can't really find any errors. It also doesn't help that the master VMs created become unavailable via network sometime during provisioning18:14
wlmbassonHi guys, how do I get external network access on a fresh build of a single interface OSA AIO? I created a VM with a floating IP that I can access from the host. The VM can ping the br-vlan and host interface, but not the outside world.18:14
savvas_I related my issue to https://bugs.launchpad.net/magnum/+bug/172081618:14
openstackLaunchpad bug 1720816 in Magnum "magnum create cluster "create_in_progress" and changes to "create_failed" after timeout" [Undecided,New]18:14
savvas_anyone has any thoughts on that?18:14
savvas_I already tried increasing the timeout18:14
*** cshen has joined #openstack-ansible18:33
*** hamza21 has joined #openstack-ansible18:38
*** openstackgerrit has quit IRC18:47
*** DanyC_ has quit IRC18:53
*** gouthamr has joined #openstack-ansible19:00
*** markvoelker has joined #openstack-ansible19:12
*** DanyC has joined #openstack-ansible19:21
wlmbasson'iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE' solves external network access on a fresh AIO19:28
*** cshen has quit IRC19:32
*** markvoelker has quit IRC19:45
*** cshen has joined #openstack-ansible19:49
*** pester has joined #openstack-ansible19:54
*** fxpester has quit IRC19:57
*** hybridpollo has joined #openstack-ansible20:02
*** dave-mccowan has joined #openstack-ansible20:06
*** cshen has quit IRC20:17
*** dave-mccowan has quit IRC20:20
*** dave-mccowan has joined #openstack-ansible20:25
*** dave-mccowan has quit IRC20:30
*** dave-mccowan has joined #openstack-ansible20:36
*** hamza21 has quit IRC20:36
*** dave-mccowan has quit IRC20:40
*** markvoelker has joined #openstack-ansible20:43
*** cshen has joined #openstack-ansible20:54
*** markvoelker has quit IRC21:15
*** threestrands has joined #openstack-ansible21:28
*** threestrands has quit IRC21:28
*** threestrands has joined #openstack-ansible21:28
*** vnogin has joined #openstack-ansible21:29
*** savvas_ has quit IRC21:33
*** cshen has quit IRC21:36
*** DanyC has quit IRC21:43
*** DanyC has joined #openstack-ansible21:44
*** DanyC has quit IRC21:59
*** askb has joined #openstack-ansible22:03
*** markvoelker has joined #openstack-ansible22:13
*** vnogin has quit IRC22:30
*** markvoelker has quit IRC22:46
*** gouthamr has quit IRC22:55
*** openstackstatus has quit IRC22:57
*** openstackstatus has joined #openstack-ansible22:57
*** ChanServ sets mode: +v openstackstatus22:57
*** lihi has quit IRC23:04
*** lihi has joined #openstack-ansible23:06
cloudnullsavvas_: i've not done a tun of work with magnum however if there's a comms issue between services the first thing I'd go look through would be the magnum logs and the logs of the services where the timeout is happening23:08
cloudnullDimGR: ^ maybe you have some thoughts on that ?23:08
cloudnullwlmbasson: got everything goin g?23:08
*** markvoelker has joined #openstack-ansible23:12
*** vnogin has joined #openstack-ansible23:14
*** vnogin has quit IRC23:20
*** openstackgerrit has joined #openstack-ansible23:39
openstackgerritKevin Carter (cloudnull) proposed openstack/openstack-ansible-os_glance master: Update glance NFS for systemd  https://review.openstack.org/52693023:39
*** masber has quit IRC23:40
*** gouthamr has joined #openstack-ansible23:43
openstackgerritKevin Carter (cloudnull) proposed openstack/openstack-ansible-os_glance master: Update glance NFS for systemd  https://review.openstack.org/52693023:54
*** vnogin has joined #openstack-ansible23:55

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!