*** openstackstatus has quit IRC | 00:12 | |
*** openstackstatus has joined #openstack-ansible | 00:13 | |
*** ChanServ sets mode: +v openstackstatus | 00:13 | |
*** acormier has joined #openstack-ansible | 00:30 | |
*** lbragstad has quit IRC | 00:32 | |
*** acormier has quit IRC | 00:35 | |
*** chyka has quit IRC | 00:36 | |
*** chyka has joined #openstack-ansible | 00:37 | |
*** chyka has quit IRC | 00:41 | |
*** openstackgerrit has joined #openstack-ansible | 00:42 | |
openstackgerrit | Merged openstack/openstack-ansible-os_ceilometer stable/pike: [pike only] Stop using 'latest' for pymongo installation https://review.openstack.org/546293 | 00:42 |
---|---|---|
openstackgerrit | Merged openstack/openstack-ansible-os_ceilometer stable/pike: Zuul: Remove project name https://review.openstack.org/542601 | 00:42 |
openstackgerrit | Merged openstack/openstack-ansible-os_ceilometer master: Deprecate os_endpoint_type option Option "os_endpoint_type" from groups "service_credentials" and "keystone_authtoken" is deprecated[1]. Use option "interface" from groups "service_credentials" and "keystone_authtoken". https://review.openstack.org/521857 | 00:42 |
openstackgerrit | Merged openstack/openstack-ansible-os_aodh master: Standardize services list and package installation https://review.openstack.org/492580 | 00:50 |
*** acormier has joined #openstack-ansible | 00:58 | |
*** dave-mccowan has joined #openstack-ansible | 01:07 | |
*** acormier has quit IRC | 01:22 | |
*** acormier has joined #openstack-ansible | 01:22 | |
*** acormier has quit IRC | 01:35 | |
*** woodard_ has joined #openstack-ansible | 01:39 | |
*** woodard has quit IRC | 01:39 | |
*** sm806 has joined #openstack-ansible | 01:51 | |
*** woodard_ has quit IRC | 01:56 | |
*** woodard has joined #openstack-ansible | 01:57 | |
JohnnyOSA | Hey all -- after doing a simple typo with using the --limit flag with an ansible ad-hoc command (using --limit galera_container[12 instead of --limit galera_container[1]), the inventory python tools have broken and yield the following error: http://paste.openstack.org/show/679696/ | 02:01 |
JohnnyOSA | Has anyone seen this or know how to fix it? | 02:01 |
JohnnyOSA | (Hitting the road, but will check for any feedback shortly) | 02:02 |
openstackgerrit | Jimmy McCrory proposed openstack/openstack-ansible-os_glance stable/queens: Remove registry options from scrubber config https://review.openstack.org/546471 | 02:24 |
*** sm806 has quit IRC | 02:24 | |
*** sm806 has joined #openstack-ansible | 02:25 | |
*** sm806_ has joined #openstack-ansible | 02:29 | |
sm806_ | NickServ | 02:29 |
sm806_ | NickServ | 02:31 |
*** sm806_ has quit IRC | 02:32 | |
*** sm806_ has joined #openstack-ansible | 02:35 | |
sm806_ | NickServ | 02:35 |
*** tux_ has joined #openstack-ansible | 02:39 | |
mattt | JohnnyOSA: sounds like this: https://bugs.launchpad.net/openstack-ansible/+bug/1750233 | 02:45 |
openstack | Launchpad bug 1750233 in openstack-ansible "corrupted dynamic_inventory.py backup file" [High,Confirmed] | 02:45 |
mnaser | hwoarang: https://review.openstack.org/#/c/521860/2 please let me know if its okay to drop your -2 | 03:09 |
*** gkadam has quit IRC | 03:14 | |
*** gkadam has joined #openstack-ansible | 03:15 | |
*** sm806 has quit IRC | 03:17 | |
tux_ | Question:- br-vxlan vs br-vlan if i am not doing VLAN network type then i don't need that interface right? my all tenant going to be on VxLAN for inter communication | 03:25 |
*** udesale has joined #openstack-ansible | 03:36 | |
*** udesale has quit IRC | 03:38 | |
*** udesale has joined #openstack-ansible | 03:39 | |
*** sm806 has joined #openstack-ansible | 03:41 | |
*** lbragstad has joined #openstack-ansible | 03:43 | |
*** udesale has quit IRC | 03:55 | |
*** dave-mccowan has quit IRC | 04:34 | |
*** acormier has joined #openstack-ansible | 04:36 | |
*** esberglu has quit IRC | 04:37 | |
*** nurdie has quit IRC | 04:38 | |
*** nurdie has joined #openstack-ansible | 04:38 | |
*** ivve has quit IRC | 04:39 | |
*** acormier has quit IRC | 04:40 | |
openstackgerrit | German Eichberger proposed openstack/openstack-ansible-os_octavia master: Fixes Lint errors and improve tests https://review.openstack.org/544117 | 04:47 |
*** taseer2 is now known as Taseer | 04:54 | |
*** ivve has joined #openstack-ansible | 04:56 | |
JohnnyOSA | mattt: great tip! Thanks for the link -- that solved the issue. | 04:57 |
*** sm806 has quit IRC | 04:59 | |
*** sm80664 has joined #openstack-ansible | 05:03 | |
*** sm80664 is now known as sm806 | 05:03 | |
*** sm806 has quit IRC | 05:04 | |
*** sm806 has joined #openstack-ansible | 05:07 | |
*** tux_ has quit IRC | 05:12 | |
*** udesale has joined #openstack-ansible | 05:14 | |
cloudnull | evenings | 05:18 |
cloudnull | mhayden: I love this https://review.openstack.org/#/c/546319/2/tasks/dirty_hacks.yml | 05:19 |
cloudnull | a commit after my own heart :) | 05:19 |
cloudnull | tux_ did you get your questions answered? | 05:20 |
*** lbragstad has quit IRC | 05:28 | |
*** indistylo has joined #openstack-ansible | 05:34 | |
*** taseer1 has joined #openstack-ansible | 05:37 | |
*** Taseer has quit IRC | 05:37 | |
*** dariko has joined #openstack-ansible | 05:41 | |
*** poopcat has quit IRC | 05:50 | |
*** SmearedBeard has joined #openstack-ansible | 05:54 | |
*** SmearedBeard has quit IRC | 05:58 | |
gokhan | odyssey4me, sorry I had been ill for these days. we can talk about panko role when you are available on there. | 06:00 |
*** dariko has quit IRC | 06:00 | |
*** pmannidi has quit IRC | 06:04 | |
JohnnyOSA | Hi Cloudnull -- I'm experiencing what seems like a source routing issue between the external LB vip and br-mgmt gateway with my setup. Any ideas? (http://eavesdrop.openstack.org/irclogs/%23openstack-ansible/%23openstack-ansible.2018-02-20.log.html#t2018-02-20T12:59:49) | 06:16 |
prometheanfire | cloudnull: mhayden: LOL, love the dirty hack, I'm trying to figure out if I should yell at heat to put them in extras or not (hint, they should) | 06:18 |
prometheanfire | cloudnull: mhayden: you know if heat NEEDS any of the clients? | 06:18 |
prometheanfire | JohnnyOSA: can you make (even via simple ascii) something like https://dev.gentoo.org/~prometheanfire/images/VM-host-network.svg to describe your issue? | 06:20 |
*** aruns has joined #openstack-ansible | 06:21 | |
prometheanfire | JohnnyOSA: the ip route from a horizon container would help (and from the haproxy too) | 06:22 |
prometheanfire | JohnnyOSA: also, traceroute | 06:22 |
*** indistylo has quit IRC | 06:23 | |
JohnnyOSA | Prometheanfire: that's a nice diagram you have there. Yes I could do something like that. I'm a little perplexed though. I've brought the full OSA environment down and back up and the issue appears to have disappeared. I'm not sure what, if anything has changed. | 06:25 |
prometheanfire | ubuntu networking sucks | 06:25 |
JohnnyOSA | Let me investigate for another day and if the issue comes back up, I'll draft up a diagram and return. | 06:25 |
prometheanfire | networkd is better | 06:25 |
prometheanfire | netifrc is good too (what gentoo uses) | 06:25 |
JohnnyOSA | Really appreciate the support and expertise you guys offer on the channel. | 06:26 |
prometheanfire | best effort, ymmv, ybyb :P | 06:27 |
JohnnyOSA | haha :) | 06:27 |
prometheanfire | to be honest I don't even do OSA all that much | 06:28 |
prometheanfire | I'm just here to annoy people and be a helper | 06:28 |
JohnnyOSA | welp, I'm still enough of an OSA newbie that when I try to troubleshoot and fix something, I seem to break something else in the process. Still a little clumsy :). | 06:29 |
JohnnyOSA | From the 2017 OS survey, page 42, Ansible is shown as the leading deployment tool for OS (https://www.openstack.org/assets/survey/April2017SurveyReport.pdf). | 06:37 |
prometheanfire | lol, that's good | 06:37 |
prometheanfire | we were not on the last one | 06:37 |
prometheanfire | got skipped | 06:37 |
JohnnyOSA | Since some of the other Ansible projects are broken out on that page (Kolla, Lxc), does that mean the OSA is the majority of that large percentage? | 06:37 |
prometheanfire | hell if I know | 06:38 |
prometheanfire | they only mention newton too | 06:38 |
JohnnyOSA | yeah -- I came across a newer reference recently somewhere (don't have the link handy at the moment). I think they broke OSA out as a seperate category and then another "Ansible" category separately. Made me wonder how they were classifying the main "Ansible" category. Maybe they were just lumping everything together that used Ansible. | 06:41 |
JohnnyOSA | Anyway, I'm out for the night... Later! | 06:41 |
prometheanfire | ansible is the new hotness | 06:42 |
* prometheanfire waits for the next thing | 06:43 | |
prometheanfire | it's probably in go or rust | 06:43 |
prometheanfire | https://fishofgold.files.wordpress.com/2012/01/get-off-my-lawn.jpg | 06:44 |
*** udesale_ has joined #openstack-ansible | 06:54 | |
*** taseer2 has joined #openstack-ansible | 06:55 | |
*** taseer1 has quit IRC | 06:55 | |
*** taseer3 has joined #openstack-ansible | 06:55 | |
sm806 | I am seeing failures while ansible is creating repo_container --> http://paste.openstack.org/show/680126/ | 06:56 |
*** udesale_ has quit IRC | 06:56 | |
*** udesale_ has joined #openstack-ansible | 06:56 | |
sm806 | Same setup worked few weeks before. I changed few networking configs and installing the setup again.... any idea why this failure is seen ? | 06:57 |
sm806 | Looks like some failure with git cloning, but cant figure out why its failing. | 06:57 |
*** udesale has quit IRC | 06:58 | |
*** taseer2 has quit IRC | 07:00 | |
*** udesale_ has quit IRC | 07:02 | |
*** udesale has joined #openstack-ansible | 07:02 | |
*** chyka has joined #openstack-ansible | 07:13 | |
*** sar has joined #openstack-ansible | 07:16 | |
*** chyka has quit IRC | 07:18 | |
*** udesale_ has joined #openstack-ansible | 07:43 | |
*** udesale has quit IRC | 07:44 | |
*** pcaruana has joined #openstack-ansible | 07:47 | |
*** mancdaz has quit IRC | 07:57 | |
*** mancdaz_ has joined #openstack-ansible | 07:58 | |
*** mancdaz_ is now known as mancdaz | 07:58 | |
*** mbuil has joined #openstack-ansible | 07:58 | |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible master: [Docs] Uniform landing text https://review.openstack.org/546521 | 08:05 |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible master: [Docs] Move AIO to first scenario https://review.openstack.org/546522 | 08:05 |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible master: [Docs] Include test scenario as a new user story https://review.openstack.org/546523 | 08:05 |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible master: [Docs] Fix references https://review.openstack.org/546524 | 08:05 |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible master: [Docs] Move more examples to user guide https://review.openstack.org/546525 | 08:05 |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible master: [Docs] Move Ceph example to user guides https://review.openstack.org/546526 | 08:05 |
*** epalper has joined #openstack-ansible | 08:07 | |
*** udesale_ is now known as udesale | 08:09 | |
*** aruns has quit IRC | 08:10 | |
*** Guy has joined #openstack-ansible | 08:14 | |
ThomasS | hi | 08:17 |
ThomasS | i wnated to enable VPNaaS | 08:18 |
ThomasS | added vpnaas to user_vars and did openstack-ansible os-neutron-install.yml && openstack-ansible os-horizon-install.yml | 08:18 |
*** woodard has quit IRC | 08:18 | |
ThomasS | without errors but not showing i n horizon under network | 08:18 |
ThomasS | neutron_plugin_base: - router - metering - vpnaas - qos | 08:19 |
ThomasS | maybe i am missing something here | 08:19 |
openstackgerrit | Periyasamy Palanisamy proposed openstack/openstack-ansible master: Make Opendaylight as the BGP speaker using Quagga https://review.openstack.org/523907 | 08:23 |
ThomasS | looks like i am missing the kernel modules | 08:24 |
ThomasS | followed this guide | 08:24 |
ThomasS | https://docs.openstack.org/openstack-ansible/mitaka/install-guide/configure-network-services.html | 08:24 |
ThomasS | but this does look outdated | 08:24 |
ThomasS | openstack-ansible openstack-hosts-setup.yml --limit network_hosts\ --tags "openstack-hosts-setup,openstack-host-specific-kernel-modules" | 08:24 |
ThomasS | i am trying this guide now | 08:29 |
ThomasS | https://docs.openstack.org/openstack-ansible-os_neutron/latest/configure-network-services.html | 08:29 |
*** sar has quit IRC | 08:29 | |
ThomasS | this looks better so far :-) | 08:29 |
*** indistylo has joined #openstack-ansible | 08:30 | |
evrardjp | ThomasS: the guide is I guess for mitaka | 08:38 |
evrardjp | why not checking on the one for your branch? | 08:38 |
evrardjp | but yeah vpnaas might require updating the docs | 08:39 |
*** electrofelix has joined #openstack-ansible | 08:39 | |
*** SmearedBeard has joined #openstack-ansible | 08:41 | |
*** jwitko_ has quit IRC | 08:42 | |
ThomasS | i used this one now | 08:48 |
ThomasS | https://docs.openstack.org/openstack-ansible-os_neutron/latest/configure-network-services.html | 08:48 |
ThomasS | this is for 17.0 | 08:48 |
ThomasS | all steps of vpnaas worked | 08:48 |
ThomasS | but no vpnaas in horizon | 08:49 |
ThomasS | so am on 16.0 | 08:51 |
evrardjp | might have a bug. Check also pike instead of latest? | 08:51 |
*** sxc731 has joined #openstack-ansible | 08:51 | |
ThomasS | i think the guide is fine but it is missing one step i guess | 08:52 |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible master: [Docs] Move network architecture into reference https://review.openstack.org/546538 | 08:53 |
ThomasS | pike and queens are the same guides :-) | 08:54 |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible master: [Docs] Include test scenario as a new user story https://review.openstack.org/546523 | 08:58 |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible master: [Docs] Fix references https://review.openstack.org/546524 | 08:58 |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible master: [Docs] Move more examples to user guide https://review.openstack.org/546525 | 08:58 |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible master: [Docs] Move Ceph example to user guides https://review.openstack.org/546526 | 08:58 |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible master: [Docs] Move network architecture into reference https://review.openstack.org/546538 | 09:01 |
evrardjp | ThomasS: patches welcome :) | 09:01 |
*** shardy has joined #openstack-ansible | 09:12 | |
*** PTO has joined #openstack-ansible | 09:13 | |
*** SmearedBeard has quit IRC | 09:14 | |
*** hamzy_ has joined #openstack-ansible | 09:17 | |
*** pbandark has joined #openstack-ansible | 09:17 | |
*** sar has joined #openstack-ansible | 09:17 | |
*** hamzy has quit IRC | 09:19 | |
ThomasS | if i find the püroblem | 09:22 |
ThomasS | problem | 09:22 |
*** sxc731 has quit IRC | 09:23 | |
ThomasS | i currently have no clue | 09:24 |
evrardjp | ThomasS: it's the dashboard that doesn't show up? | 09:24 |
ThomasS | yes | 09:24 |
evrardjp | under pike | 09:24 |
ThomasS | yes | 09:24 |
Miouge | Good morning, feedback on https://review.openstack.org/#/c/517856/ is welcome. Let me know if there is anything else I can do for ceph-rgw integration | 09:26 |
*** SmearedBeard has joined #openstack-ansible | 09:26 | |
evrardjp | ThomasS: it looks like the vpnaas dashboard isn't copied over | 09:26 |
ThomasS | ok... | 09:26 |
evrardjp | ThomasS: https://github.com/openstack/openstack-ansible-os_horizon/blob/stable/pike/tasks/horizon_post_install.yml#L35-L115 | 09:27 |
evrardjp | I don't see anything for vpnaas | 09:27 |
evrardjp | Can you either file a bug, stating it, or proposing a patch? | 09:28 |
evrardjp | has anyone the chance to look at the apt package install issue that's appearing in all branches? | 09:29 |
evrardjp | Miouge: great ! | 09:29 |
evrardjp | Miouge: really great work there | 09:31 |
*** gillesMo has joined #openstack-ansible | 09:31 | |
evrardjp | do you mind if I edit it? | 09:31 |
Miouge | evrardjp: Thanks but I wouldn’t have managed without logan- and your help. Go ahead with edits. I was wondering if I should add things around documentation for rgw. | 09:32 |
evrardjp | Don't for now | 09:32 |
evrardjp | I am refactoring the docs | 09:32 |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible master: Ceph RadosGW integration https://review.openstack.org/517856 | 09:33 |
evrardjp | small detail but would help later. | 09:33 |
odyssey4me | gokhan you around now? | 09:33 |
evrardjp | Miouge: I took this change into consideration, so the user story around ceph can be more extended if need be | 09:33 |
evrardjp | https://review.openstack.org/#/c/546526/ | 09:34 |
evrardjp | if there are ppl ready to vote on https://review.openstack.org/#/q/topic:bp/docs-improvements+(status:open) that would be great. | 09:34 |
odyssey4me | sm806_ for that repo build failure, can you find the wheel build log in /var/log/repo/ and extract the actual failure - the ansible result is hard to read | 09:36 |
evrardjp | sm806: what issue do you have? | 09:36 |
evrardjp | oh nvm I read the logs | 09:37 |
odyssey4me | Miouge evrardjp perhaps add some rgw stuff to the ceph example appendix? | 09:37 |
evrardjp | odyssey4me: it's moving to a ceph user story indeed | 09:38 |
Miouge | evrardjp: Good idea. I can add doc’ about ceph-rgw in the ceph/full-deploy.rst file. I wait for the refactor to be merged to avoid conflicts? | 09:38 |
evrardjp | a chapter can be dedicated to ceph rgw | 09:38 |
*** aruns has joined #openstack-ansible | 09:38 | |
evrardjp | Miouge: yeah, just wait or add your patch on top of mine | 09:38 |
odyssey4me | evrardjp there is one already: https://docs.openstack.org/project-deploy-guide/openstack-ansible/latest/app-config-prod-ceph.html | 09:39 |
evrardjp | odyssey4me: ofc I know :) | 09:39 |
Miouge | I think he is moving that from the deploy-guide to the user-guide? | 09:39 |
evrardjp | I am refactoring the docs according to the accepted blueprint | 09:39 |
evrardjp | see https://review.openstack.org/#/c/546526/ | 09:39 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_glance stable/queens: Remove registry options from scrubber config https://review.openstack.org/546471 | 09:40 |
sm806 | evrardjp, odyssey4me: I did some drill down and found out that keystone and nova-xxxx package's git clone in /var/www/repo/openstackgit was not checked out with required commit version. I checked them out manually to the version expected in the error log and it went ahead. | 09:40 |
odyssey4me | sm806 hmm, odd - you could have done the force reclone too - but happy you figured it out | 09:40 |
odyssey4me | unfortunately ansible doesn't do retries when doing async tasks :/ | 09:40 |
evrardjp | sm806: which SHA did you check out? | 09:40 |
*** indistylo has quit IRC | 09:40 | |
sm806 | odyssey4me : how to trigger force reclone ? | 09:41 |
evrardjp | The branch or the expected sha from defaults? | 09:41 |
evrardjp | sm806: there is an option for that. | 09:41 |
odyssey4me | sm806 https://github.com/openstack/openstack-ansible-repo_build/blob/master/defaults/main.yml#L56 | 09:41 |
odyssey4me | so you would do: openstack-ansible repo-build.yml -e "repo_build_git_reclone=yes,repo_build_wheel_rebuild=yes,repo_build_venv_rebuild=yes" for a full rebuild | 09:42 |
*** aruns__ has joined #openstack-ansible | 09:42 | |
sm806 | odyssey4me thanks | 09:43 |
*** shardy has quit IRC | 09:43 | |
sm806 | evrardjp : i checked out the commit "6a67918f9d5f39564af8eacc57b80cba98242683" for keystone. Couple of other packages has similar issues. I took the commit id from ansible error log. | 09:44 |
evrardjp | ok good | 09:44 |
*** aruns has quit IRC | 09:45 | |
*** Sha000000 has joined #openstack-ansible | 09:45 | |
evrardjp | ok, good and bad thing. All the failures I got in the periodics of today seem to not apply on my first node. Retrying with a different branch. | 09:46 |
odyssey4me | evrardjp very odd, but in a test in my own env https://review.openstack.org/#/c/537015/ works just fine for the integrated build, but in the experimental results it seems to consistently not have the lbaas wheel... very odd | 09:46 |
evrardjp | and working on suse? | 09:47 |
*** armaan has joined #openstack-ansible | 09:47 | |
odyssey4me | I haven't tried SuSE, but the failures in that patch for the tests historically have related to container access failure and not anything to do with the code itself. | 09:48 |
*** aruns has joined #openstack-ansible | 09:48 | |
odyssey4me | in this case it failed to build rally with an obscure error: http://logs.openstack.org/15/537015/17/check/openstack-ansible-functional_selective-opensuse-423/dbbb02b/logs/openstack/container1/repo/venv_build_rally-testing-x86_64.log.txt.gz | 09:49 |
*** aruns__ has quit IRC | 09:51 | |
evrardjp | haha yeah | 09:51 |
PTO | odyssey4me: Regaring the ceph-ansible guide you mentioned before. I cant quite figure out hot to configure which disks devices the Ceph OSD are supposed to use. Can you help clarify? | 09:51 |
odyssey4me | anyway, I'll keep plugging at it - don't worry about looking into it | 09:51 |
evrardjp | bad zip | 09:52 |
evrardjp | bad zippy! | 09:52 |
evrardjp | I can have a look if you want | 09:53 |
evrardjp | PTO: it's probably linked to ceph ansible. You should check ceph-ansible docs | 09:53 |
evrardjp | odyssey4me: when you say container access failure, you mean the rsync task? | 09:54 |
evrardjp | oh no it must be somthing else | 09:54 |
PTO | evrardjp: I allready did, and they have a configuration parameter called devices: []. How is this translated into the user_variables.yml? | 09:55 |
evrardjp | you should probably use it directly, and it will be passed into ceph ansible. | 09:55 |
evrardjp | that applies to all nodes. | 09:55 |
evrardjp | we don't do namespacing when including roles for now | 09:55 |
odyssey4me | evrardjp nope, I mean http://eavesdrop.openstack.org/irclogs/%23openstack-ansible/%23openstack-ansible.2018-02-20.log.html#t2018-02-20T18:34:58 | 09:56 |
odyssey4me | PTO it doesn't look like devices are set in that config - maybe there should be some words to say it's missing on purpose - not sure - logan- ? | 09:56 |
odyssey4me | and wow, I'm surprised that ceph-ansible does no namespacing for its vars... that's terribad | 09:57 |
evrardjp | well, namespacing of vars is hard, but at least proper naming to avoid collisions would be a good start. | 09:59 |
odyssey4me | namespacing is not hard, it's just something that should be done - transitioning from non-namespaced vars to namespaced vars *is* hard | 10:00 |
evrardjp | PTO: if you think you're gonna have issues with overlaps (depends on what you have on the side), you can apply these vars more surgically with host and group vars | 10:00 |
odyssey4me | but wow, many of those vars will collide with so many other things | 10:00 |
evrardjp | I meant real ansible namespacing. | 10:00 |
evrardjp | like not having vars scoped in vars[] | 10:01 |
evrardjp | anyway, that's details, the variable naming right now really sucks. | 10:01 |
evrardjp | but that's outside our control | 10:01 |
odyssey4me | PTO our very own evrardjp did a very neat blog post explaining how to make use of host vars with OSA: https://evrard.me/group-and-host-variables-overriding-in-openstack-ansible.html | 10:01 |
evrardjp | odyssey4me: my goal is to have that move to our very own reference :) | 10:02 |
odyssey4me | oh sure, that should probably go into the existing chapter about the inventory | 10:02 |
evrardjp | I've noticed the configuration details about how to configure osa was spread in ... 4 guides. | 10:02 |
evrardjp | Kinda not easy for new comers. And that's how the spec started... | 10:03 |
evrardjp | after long hours of re-reading the guide :) | 10:03 |
odyssey4me | evrardjp oh sure - the different guides have not been updated to suit the audience better since docs set them out | 10:03 |
evrardjp | when your head is in it, it seems obvious, but it's not so for newcomers | 10:03 |
odyssey4me | we were given categories, and did a simple rename of our existing guides to try and fit them into those categories | 10:03 |
evrardjp | yeah | 10:04 |
evrardjp | I think we'll be in a very good place later. | 10:04 |
evrardjp | "Definitely the most readable openstack deploy guide" | 10:04 |
evrardjp | "Probably the best _OS deploy guide_ in the world" | 10:04 |
evrardjp | hahaha. That calls for a Stella. | 10:05 |
*** pcaruana has quit IRC | 10:05 | |
odyssey4me | now that we have specific categories, I expect we'll need to revisit the content to suit the audiences... and I expect that a ton of the operations guide content is duplicated all over the place... seeing as that was wholly imported and not modified much | 10:05 |
evrardjp | so many beer references. | 10:05 |
odyssey4me | the rest of the docs were built before that existed | 10:05 |
evrardjp | odyssey4me: well, in my refactor I remove the duplications, and rephrase a few things. Not a lot, but it simplifies. | 10:06 |
evrardjp | well let's talk about that later :) | 10:08 |
evrardjp | when it's all merged! | 10:08 |
*** nikm has joined #openstack-ansible | 10:10 | |
Miouge | PTO: something like this: http://paste.openstack.org/show/680298/ | 10:11 |
nikm | evrardjp : hi there | 10:11 |
openstackgerrit | git-harry proposed openstack/openstack-ansible-galera_server master: Fix cache update after initial apt_repository fail https://review.openstack.org/546312 | 10:11 |
nikm | evrardjp: we are getting an issue while running infrastructure playbook of openstack-ansible ocata for production environment | 10:13 |
nikm | following is the issue: http://paste.openstack.org/show/680299/ | 10:13 |
evrardjp | oh interesting nikm | 10:13 |
nikm | pip_validate_certs: false | 10:14 |
*** Sha000000 has quit IRC | 10:14 | |
nikm | do we have to use this | 10:14 |
evrardjp | nikm: no | 10:14 |
evrardjp | do you have a complete log of the run? | 10:14 |
evrardjp | not only the last taks | 10:14 |
evrardjp | that log, not a new run | 10:14 |
nikm | what starting point of logs u want | 10:15 |
evrardjp | the whole playbook | 10:15 |
evrardjp | the infrastructure one | 10:16 |
evrardjp | also | 10:16 |
evrardjp | if you could connect on your infra1_repo_container, and do a curl of the https://repos.fedorapeople.org that would be great. | 10:16 |
*** SmearedBeard has quit IRC | 10:17 | |
odyssey4me | fyi evrardjp it looks like the infra ubuntu mirrors may be out of date - asking in infra | 10:20 |
*** pcaruana has joined #openstack-ansible | 10:20 | |
odyssey4me | see http://logs.openstack.org/39/546239/1/check/openstack-ansible-functional-ubuntu-xenial/10034d0/logs/host/lxc-cache-prep-commands.log.txt.gz for why I think that's the case. | 10:20 |
nikm | evrardjp: http://paste.openstack.org/show/680305/ | 10:22 |
nikm | evrardjp: above is the curl output inside container | 10:23 |
nikm | ? | 10:27 |
*** shardy has joined #openstack-ansible | 10:27 | |
*** aruns__ has joined #openstack-ansible | 10:28 | |
*** aruns has quit IRC | 10:30 | |
gokhan | hi odyssey4me, I am here now :) | 10:30 |
odyssey4me | gokhan :) | 10:31 |
gokhan | odyssey4me, we can pull panko role. It would be great. | 10:33 |
*** Guy has quit IRC | 10:34 | |
*** acormier has joined #openstack-ansible | 10:37 | |
odyssey4me | gokhan ok awesome - could you do the things I mentioned quickly? | 10:39 |
openstackgerrit | git-harry proposed openstack/openstack-ansible-galera_client master: Fix cache update after initial apt_repository fail https://review.openstack.org/546559 | 10:39 |
odyssey4me | actually, never mind - I think we can do it instead | 10:40 |
evrardjp | odyssey4me: yeah that's the same issue I got everywhere | 10:40 |
evrardjp | I am trying locally to see if that works better. | 10:40 |
evrardjp | yes I've got my success in my logs :) | 10:40 |
evrardjp | we can do that? | 10:41 |
evrardjp | odyssey4me: "we can do it instead"? | 10:41 |
odyssey4me | evrardjp we can do everything ;) | 10:41 |
*** acormier has quit IRC | 10:41 | |
odyssey4me | it's just a patch away :p | 10:41 |
nikm | evrardjp : curl output inside container http://paste.openstack.org/show/680305/ | 10:42 |
evrardjp | nikm: ping of repos.fedorapeople.org ? | 10:42 |
gokhan | odyssey4me, also about redis, I wrote a role about redis cluster. what do you think about using redis role ? it can be used either gnocchi storage driver or coordinator for telemetry services. I wonder your and mnaser thoughts? | 10:43 |
evrardjp | nikm: I think you have a connectivity issue | 10:43 |
evrardjp | gokhan: I think a redis role can be used by dragonflow IIRC. So I am thinking that a generic redis role could be useful, but we should maybe "just consume it" ? | 10:44 |
*** SmearedBeard has joined #openstack-ansible | 10:45 | |
odyssey4me | gokhan redis integration in the roles wherever applicable would be great, but if possible I'd like to avoid using a role which is OSA-specific... I would definitely prefer using a well established redis community role if there is such a thing... if you see opportunities for integration, then it might be a good idea to submit a spec outlining where you think it would be a good fit... and if you feel that a custom role would be more | 10:45 |
odyssey4me | beneficial than a redis community role, then explain why in the spec | 10:45 |
gokhan | odyssey4me, evrardjp I searched for redis community role but I didn't find it. There are lots of custom redis roles. so I decided to write its role myself with benefit from custom roles. | 10:50 |
gokhan | I wrote a one whose address is https://github.com/gokhan27/openstack-ansible-os_redis | 10:51 |
gokhan | I am using it now with openstack-ansible | 10:51 |
gokhan | sorry for its name ''openstack-ansible-os_redis' | 10:52 |
gokhan | may be it could be good to use only 'redis' | 10:52 |
odyssey4me | ansible-role-redis would be a more appropriate name | 10:54 |
evrardjp | yeah | 10:54 |
odyssey4me | the os_ names are meant for openstack services | 10:54 |
odyssey4me | redis is definitely not an openstack service ;) | 10:54 |
PTO | nikm: Thanks for the clarifications. I will try and make and deploy it straight away | 10:55 |
evrardjp | odyssey4me: until...! | 10:55 |
nikm | evrardjp : I am able to run curl command from ansible node but with container it is getting failed, any suggestion to fix it | 10:56 |
evrardjp | nikm: could you do a ping ? | 10:57 |
nikm | sure | 10:57 |
evrardjp | with name not, the ip | 10:57 |
*** mbuil has quit IRC | 10:58 | |
evrardjp | I think you might have seen what mattt has seen recently -- a failure in dnsmasq when rebooting. He did another reboot to fix it. Weird as nothing appeared in the logs | 10:58 |
*** mbuil has joined #openstack-ansible | 10:58 | |
nikm | ping is working and curl is also working using this command >> repos.fedorapeople.org | 10:58 |
evrardjp | ? | 10:59 |
evrardjp | do you have a new log ? | 10:59 |
gokhan | odyssey4me, ok I will change its name with ansible-role-redis :) | 10:59 |
nikm | sorry the command is >> curl -k https://repos.fedorapeople.org | 11:00 |
evrardjp | gokhan: that is great :) | 11:00 |
evrardjp | ok | 11:00 |
evrardjp | so insecure | 11:00 |
nikm | it is giving web page content output | 11:00 |
nikm | I am facing this issue first time while deployment in production | 11:00 |
evrardjp | gokhan: what I generally do with galaxy roles, is try to submit issues to other roles to see if they want to work with me. And I try to make the role very generic | 11:00 |
evrardjp | nikm: it's weird because validate cert is not done in pip install | 11:01 |
odyssey4me | gokhan I'll be doing some PR's to the os_panko repo. Please look out for them. | 11:02 |
evrardjp | wait | 11:02 |
evrardjp | sorry I meant that to nikm | 11:03 |
gokhan | odyssey4me, ok. | 11:04 |
evrardjp | nikm: so let me rephrase: host "curl" works, container "curl" works when insecure , container "curl" doesn't work when secure | 11:06 |
evrardjp | do you have a proxy? | 11:06 |
gokhan | evrardjp, yep in fact you are right. this is the best to submit issue. I should have do like you. but it was urgent to see redis role on my production so I choose this way. | 11:07 |
nikm | evrardjp: I don't have idea regarding proxy in network, my client has not provide proxy details | 11:07 |
evrardjp | gokhan: don't get me wrong, I only get good results like 10% of the time | 11:08 |
evrardjp | and don't worry, I understand the constraints | 11:08 |
ThomasS | hi | 11:13 |
ThomasS | wanted to fill a bug for vpnaas | 11:13 |
ThomasS | where to do so? Github openstack ansible repo? | 11:13 |
ThomasS | launchpad? | 11:13 |
evrardjp | launchpad | 11:14 |
evrardjp | https://bugs.launchpad.net/openstack-ansible | 11:14 |
evrardjp | report a bug on the top right | 11:14 |
nikm | evrardjp: is there any work around to not check certificates | 11:14 |
gokhan | evrardjp yep you are right also me too. thanks for your advices. may be this was a bad experince for me. after that, I will choose your way because this is sensible, right way. | 11:14 |
ThomasS | ok will do | 11:14 |
evrardjp | ThomasS: please write what you expected to happen, what happened, and your configuration (conf files/openstack-ansible version), that should be enough to help us | 11:15 |
odyssey4me | gokhan actually, never mind - I'll fork and make the right changes to make it ready for import, and then just import from the fork | 11:17 |
ThomasS | ok | 11:17 |
odyssey4me | I'm not sure what your time zone is, but I suspect it might be getting quite late for you... no need to stay up. | 11:18 |
nikm | evrardjp: on the all hosts curl is working fine, curl is not working with container | 11:18 |
*** pcaruana has quit IRC | 11:19 | |
ThomasS | done | 11:20 |
ThomasS | https://bugs.launchpad.net/openstack-ansible/+bug/1750789 | 11:21 |
openstack | Launchpad bug 1750789 in openstack-ansible "VPNaaS dashboard not copied to horizon container" [Undecided,New] | 11:21 |
gokhan | odyssey4me, ok I am following your changes. my timezone is Europe/Istanbul (+03, +0300) | 11:21 |
nikm | evrardjp: If the issue is because of proxy, then what is solution to avoid this issue ? | 11:25 |
*** epalper has quit IRC | 11:25 | |
*** acormier has joined #openstack-ansible | 11:25 | |
*** acormier has quit IRC | 11:26 | |
*** acormier has joined #openstack-ansible | 11:26 | |
*** acormier has quit IRC | 11:27 | |
*** acormier has joined #openstack-ansible | 11:27 | |
evrardjp | nikm: 1) you can configure your proxy appropriately to return correct certificates 2) you can maybe pass environment variables to have a proper behavior on the proxy side | 11:28 |
*** acormier has quit IRC | 11:32 | |
*** pcaruana has joined #openstack-ansible | 11:33 | |
odyssey4me | gokhan you've done a good job prepping this role with many things :) I'm just adding a few more things which are required for it to work in openstack-infra once it's imported | 11:36 |
*** udesale has quit IRC | 11:39 | |
nikm | evrardjp: same issue after enabling "pip_validate_certs: false" | 11:43 |
*** stuartgr has joined #openstack-ansible | 11:45 | |
*** epalper has joined #openstack-ansible | 11:51 | |
evrardjp | odyssey4me: does that look right to you? https://review.openstack.org/#/c/546577/ | 11:52 |
evrardjp | nikm: ok let me double check | 11:52 |
odyssey4me | evrardjp yep, I think so | 11:53 |
gunix | odyssey4me: cloudnull: i switched to ubuntu and the AIO worked without issues. | 11:54 |
evrardjp | nikm: so | 11:59 |
*** armaan has quit IRC | 12:00 | |
evrardjp | we generally have something to check for certificates | 12:00 |
evrardjp | https://github.com/openstack/openstack-ansible-pip_install/blob/stable/ocata/tasks/pre_install_yum.yml#L71 | 12:00 |
evrardjp | however this task: https://github.com/openstack/openstack-ansible-pip_install/blob/stable/ocata/tasks/pre_install_yum.yml#L23 | 12:00 |
evrardjp | doesn't have validate_certs | 12:00 |
evrardjp | it just has disable_gpg_check | 12:00 |
evrardjp | so we could add this feature to be able to bypass those for people that have intercepting proxies. | 12:01 |
evrardjp | nikm: please note the mechanism is different in Pike and above | 12:02 |
evrardjp | and should work | 12:02 |
evrardjp | without patching | 12:02 |
evrardjp | nikm: is there a reason you need to be in ocata? | 12:03 |
nikm | yes our client requirement is ocata | 12:03 |
evrardjp | I'd strongly advise to discuss with your client :) | 12:04 |
evrardjp | but hey, that's outside my scope :D | 12:04 |
*** Sha000000 has joined #openstack-ansible | 12:04 | |
evrardjp | you could fork the role if you want a fast answer. | 12:04 |
odyssey4me | nikm your client requirement is both centos and ocata? | 12:05 |
evrardjp | Else, you will need to wait for this kind of patches to land in stable/ocata. | 12:05 |
evrardjp | odyssey4me: valid point! | 12:05 |
nikm | odyssey4me: yes | 12:05 |
odyssey4me | I'm not sure centos works for ocata. It was only ever experimental, and to my knowledge it doesn't work. | 12:06 |
odyssey4me | By that I mean the OSA CentOS implementation for Ocata is probably a bit broken. | 12:06 |
*** lvdombrkr has joined #openstack-ansible | 12:06 | |
evrardjp | depends on the role I'd say | 12:06 |
evrardjp | but we are welcoming fixes ! | 12:06 |
nikm | I have working ocata on centos locally | 12:06 |
odyssey4me | That's not to say it couldn't be fixed, but that would require some effort and someone would have to volunteer to do it. | 12:07 |
evrardjp | ok | 12:07 |
evrardjp | I can propose a patch | 12:07 |
lihi | odyssey4me, evrardjp, gokhan, I'm working on a Dragonflow(with redis) deployment with OSA. I'm using a general role (https://github.com/idealista/redis-role), but I'm running into issues integrating it with osa, so maybe a osa-spesific-role would be benefitional. | 12:08 |
odyssey4me | Oh? Well, that's nice then. :) If you find patches to improve things in the later branches, you can propose backports yourself if you're able to do so. | 12:08 |
lihi | gokhan, your role currently supports only redis HA clusters(redis-sentinel). If you could add support for regular redis clustering, I can help you test it in different envs | 12:08 |
odyssey4me | lihi what sort of issues are you hitting? | 12:08 |
nikm | Please propose the patch | 12:08 |
evrardjp | nikm: you'll have to wait quite a certain amount of time | 12:09 |
evrardjp | just fyi | 12:10 |
nikm | evrardjp: No problem, I can wait for it | 12:10 |
*** aruns has joined #openstack-ansible | 12:10 | |
evrardjp | nikm: it would need to get accepted by the community, but you have an idea this way. | 12:11 |
evrardjp | I still think you should mirror | 12:11 |
nikm | can you tell the what are the steps we need to follow for fix ?? | 12:12 |
lihi | odyssey4me, I install redis clusters on several containers. The role uses ansible_play_hosts to know which hosts are used, in order to split the key hash between the clusters. But the role is ran from the os-neutron playbook, so ansible_play_hosts includes all the hosts instead only the one I want to install redis on | 12:12 |
*** aruns__ has quit IRC | 12:13 | |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible-pip_install stable/ocata: Make possible to skip certificate checking for rdo repo https://review.openstack.org/546582 | 12:14 |
evrardjp | nikm: ^ | 12:14 |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible-pip_install stable/ocata: Make possible to skip certificate checking for rdo repo https://review.openstack.org/546582 | 12:15 |
*** acormier has joined #openstack-ansible | 12:16 | |
evrardjp | nikm: ^ updated | 12:16 |
evrardjp | have a look at the commit. | 12:16 |
*** armaan has joined #openstack-ansible | 12:17 | |
odyssey4me | lihi that role is debian only - it'd be better to use one that supports more distributions, or to PR it to add more distribution support | 12:17 |
evrardjp | this will need some time to land (we need ppl willing to merge it, and then bump it) | 12:17 |
nikm | yeah, I can see the changes | 12:17 |
nikm | evrardjp: shall I add this line manually in role and try it ?? | 12:18 |
odyssey4me | lihi however, you should be able to scope the hosts included by changing the play to target the right hosts, so instead of calling it from inside os_neutron, call it from the play | 12:18 |
*** mgagne has quit IRC | 12:19 | |
*** afranc has quit IRC | 12:20 | |
*** d34dh0r53 has quit IRC | 12:20 | |
*** toan has quit IRC | 12:20 | |
*** chris_hultin has quit IRC | 12:20 | |
*** arbrandes has quit IRC | 12:20 | |
*** evrardjp has quit IRC | 12:22 | |
openstackgerrit | Markos Chandras (hwoarang) proposed openstack/openstack-ansible-repo_build stable/pike: SUSE: Fix MariaDB development package https://review.openstack.org/546583 | 12:22 |
*** dhellmann has quit IRC | 12:22 | |
*** acormier has quit IRC | 12:23 | |
lihi | odyssey4me, I will try, thanks :) | 12:23 |
*** acormier has joined #openstack-ansible | 12:25 | |
*** evrardjp has joined #openstack-ansible | 12:26 | |
*** d34dh0r53 has joined #openstack-ansible | 12:26 | |
*** afranc has joined #openstack-ansible | 12:26 | |
lihi | odyssey4me, I was looking for redis role that supports redis regular clustering (splitting the keys between clusters), but seems like most the ansible redis roles supports only ha clusters. It can send them PL for more distributions after I'll manage to get a working env with it :) | 12:27 |
*** toan has joined #openstack-ansible | 12:27 | |
nikm | evrardjp: thanks, we applied manually and that failed step passed and now the script is executing | 12:29 |
nikm | we will let u know if it fails some where else | 12:29 |
nikm | https://review.openstack.org/#/c/546582/2 worked | 12:29 |
*** dhellmann has joined #openstack-ansible | 12:30 | |
*** arbrandes has joined #openstack-ansible | 12:31 | |
evrardjp | nikm: you should review it | 12:31 |
evrardjp | tell it's fixing the issue for you | 12:32 |
evrardjp | it might never land :) | 12:32 |
odyssey4me | nikm if you can vote and comment that it worked for you, it helps other reviewers to understand that it's been tested | 12:33 |
nikm | evrardjp: now it is failing for https://review.openstack.org/#/c/546582/2 | 12:33 |
nikm | sorry | 12:33 |
nikm | http://paste.openstack.org/show/680349/ | 12:34 |
nikm | looks like it will fail for many others | 12:34 |
odyssey4me | yep, I expect that it will | 12:35 |
*** mgagne has joined #openstack-ansible | 12:36 | |
*** mgagne is now known as Guest20946 | 12:36 | |
odyssey4me | nikm it might be easier to just override the repo URL's to all use HTTP instead of HTTPS | 12:36 |
nikm | odyssey4me evrardjp : here one question, if curl https://repos.fedorapeople.org is working from controller node then why it is failing from a container inside controller node | 12:36 |
odyssey4me | nikm do you have the correct environment variables set to make the container use the proxy properly | 12:37 |
persia | For clarity, is this intending to add an option to intentionally permit detected MITM attacks on the transport layer? | 12:38 |
odyssey4me | there's a whole thing in https://github.com/openstack/openstack-ansible/blob/stable/ocata/etc/openstack_deploy/user_variables.yml#L113-L138 which explains how to make proxies work | 12:38 |
*** chris_hultin|AWA has joined #openstack-ansible | 12:38 | |
evrardjp | persia: YES | 12:39 |
*** chris_hultin|AWA is now known as chris_hultin | 12:39 | |
evrardjp | that's insane right? | 12:39 |
persia | Then surely there's another option to solve the underlying problem, isn't there? | 12:39 |
evrardjp | Yes, many | 12:39 |
persia | evrardjp: YES | 12:39 |
odyssey4me | persia unfortunately in some environments there are proxies which intercept HTTPS - terrible, but what can we do... if that's what's there all we can do is give you the rope ;) | 12:39 |
nikm | odyssey4me evrardjp: we ran openstack-ansible setup-hosts.yml with repo_pkg_cache_enabled: false initially | 12:39 |
nikm | then we ran openstack-ansible setup-infrastructure.yml | 12:40 |
odyssey4me | nikm sure, but that doesn't really solve the problem - that just removes the local package caching | 12:40 |
nikm | which failed with this cert issue | 12:40 |
persia | odyssey4me: There are many badly implemented HTTPS proxies. Most of them can be worked around, either by a) importing the proxy certificate into the trusted certificates for the downloading platform or b) tunneling transport. | 12:40 |
*** acormier has quit IRC | 12:40 | |
evrardjp | persia: 1) don't use a intercepting proxy 2) use it with a proper ca 3) give the CA on the host 4) override the URL to a local valid one 5) move back to http 6) the rope solution. | 12:40 |
persia | I'd think docs explaining how to do a) would be more valuable than breaking things. | 12:40 |
*** acormier has joined #openstack-ansible | 12:40 | |
persia | If one is forced to deal with a bad proxy, and can't change much, 5) is probably the least bad. | 12:41 |
odyssey4me | agreed on both counts | 12:41 |
persia | but 6) just seems like overkill :) | 12:41 |
evrardjp | what you are asking in a) is basically 3) | 12:41 |
nikm | odyssey4me : which environment variables need to set to make the container use the proxy properly | 12:42 |
*** acormier has quit IRC | 12:42 | |
evrardjp | this patch just adds the 6) | 12:42 |
persia | evrardjp: Yep, as 4) is something that I hadn't considered (and likely requires one of 1,2,3 to do cleanly) | 12:42 |
odyssey4me | nikm please read https://github.com/openstack/openstack-ansible/blob/stable/ocata/etc/openstack_deploy/user_variables.yml#L113-L138, it explains it all | 12:42 |
evrardjp | persia: well, not really you could have a server in your environment with proper certificates that do it | 12:42 |
evrardjp | but that's detail | 12:43 |
evrardjp | odyssey4me: I advised nikm to use proper proxy environment setting, but it was not possible. | 12:44 |
evrardjp | at least to what I understood | 12:44 |
evrardjp | you know my english :p | 12:44 |
nikm | odyssey4me: we did not set any variable on controller node but curl is working | 12:44 |
evrardjp | nikm: and curl is broken ONLY on containers? | 12:44 |
evrardjp | that sounds like a mtu issue. | 12:44 |
nikm | yes | 12:44 |
evrardjp | or nat issue | 12:45 |
odyssey4me | nikm I'm guessing that the proxy is transparent then, so it doesn't *require* OS configuration to us it, but it intecepts the packets anyway. | 12:45 |
evrardjp | I meant a checksum issue | 12:45 |
odyssey4me | but yeah, this could be some other issue too if it's isolated to the container | 12:45 |
*** persia has quit IRC | 12:46 | |
evrardjp | try icmp with increased packet size | 12:46 |
odyssey4me | it could be MTU, or bad routing/CIDR config | 12:46 |
nikm | evrardjp: i remember client is providing internet to management network using NAT | 12:46 |
odyssey4me | you'd have to trace the packets to see why it's really failing | 12:47 |
*** persia has joined #openstack-ansible | 12:47 | |
gokhan | lihi, yep my role currently supports redis-sentinel. I can also work on regular clustering but I need time. | 12:48 |
*** electrofelix has quit IRC | 12:49 | |
nikm | evrardjp: ping is working with increased packet size | 12:57 |
evrardjp | so definitely a checksum thing | 12:58 |
nikm | evrardjp: I remember they are using NAT for providing internet to management network, any suggestion for this | 12:58 |
evrardjp | should be okay | 12:58 |
*** acormier has joined #openstack-ansible | 12:59 | |
*** omegapoint has joined #openstack-ansible | 12:59 | |
nikm | I have verified the connectivity in all nodes , looks fine | 12:59 |
omegapoint | hey, i have a quick question regarding configuring the swift service: can i disable mounting the drives in the playbook completely somehow? i have overriden mount_check in the swift conf, but the playbook fails because i'm not mounting any drives (I've run swift without a separate partition previously and it would be a huge hassle to set up my hosts with a partition for swift now (fully expanded LVM vol group)) | 13:00 |
Tahvok | Hey guys! Will you be coming to ptg meeting in Dublin? On what days? | 13:03 |
*** dave-mccowan has joined #openstack-ansible | 13:09 | |
evrardjp | Tahvok: yes! From Wed to Friday. | 13:09 |
evrardjp | I have to leave early on Friday though. | 13:09 |
evrardjp | Well that's for OSA sessions | 13:10 |
Tahvok | Will you be going to other sessions? | 13:10 |
evrardjp | Tahvok: But I will be there from cross projects sessions too (and some others too), so you can meet us even on Sunday/Monday. | 13:10 |
Tahvok | I'm new at this, and would like to stick to some group | 13:10 |
evrardjp | Tahvok: welcome :) | 13:10 |
Tahvok | Sunday? It starts at Monday | 13:11 |
evrardjp | It starts on Monday, so I'll land on Sunday evening | 13:11 |
Tahvok | Oh, I see :) | 13:11 |
*** sxc731 has joined #openstack-ansible | 13:11 | |
Tahvok | Well, I'll cross fingers that my management approves my travel | 13:12 |
evrardjp | haha | 13:12 |
evrardjp | persia: for a moment I thought you had rage quitted this channel. :D | 13:13 |
evrardjp | could I get some votes on https://review.openstack.org/#/q/topic:bp/docs-improvements+(status:open) ? | 13:14 |
ArchiFleKs | Hi, evrardjp , regarding : https://review.openstack.org/#/c/545307/ is there some manual cleanup needed when upgrading ? I'm on master and I still have the systemd-unit etc even if heat does not include cloudwatch, also haproxy entries are not cleaned up either | 13:14 |
evrardjp | ArchiFleKs: queens is not released yet :) | 13:15 |
evrardjp | but yeah | 13:15 |
ArchiFleKs | yes but i mean when running master day to day :p | 13:16 |
ArchiFleKs | I just wanted to know if there was some plan to do so and how it was handle ? | 13:16 |
evrardjp | I don't know how to handle it yet | 13:16 |
evrardjp | either in major upgrades work, or in role | 13:17 |
evrardjp | the haproxy is a good point, I completely forgot that | 13:18 |
evrardjp | that's the problem of the assemble | 13:18 |
evrardjp | it's good for user stories, but it's awful for upgrades | 13:18 |
ArchiFleKs | yes I'm a bit lost when it comes to removing things automaticly ^^ But for haproxy, just removing the entries in openstack-ansible group_vars should only affect people in master/queens right ? | 13:20 |
ArchiFleKs | also I'm wondering how is it planned to handle the "container merge" I had no issue on master but I got left with a bunch of container (the old ones for nova, neutron, heat) so I cleaned them up manually | 13:21 |
evrardjp | ArchiFleKs: removing the group vars is preventing the greenfield, but also for ppl that cleanup their conf.d | 13:24 |
evrardjp | I hean haproxy/conf.d/ | 13:24 |
evrardjp | ArchiFleKs: that last part is handled by Kevin Carter | 13:25 |
evrardjp | he said he will write a toolkit for doing that | 13:25 |
evrardjp | cloudnull: we are waiting for your patch there! | 13:25 |
*** woodard has joined #openstack-ansible | 13:25 | |
Miouge | I’m seeing a couple of “E: Unable to correct problems, you have held broken packages.” (545849, 517856, …) in Zuul checks. Is there something wrong with Zuul tests? It’s a matter of recheck? | 13:25 |
evrardjp | Miouge: broken apt mirror | 13:26 |
evrardjp | gcc thing? | 13:26 |
Miouge | Yep :) | 13:26 |
evrardjp | Miouge: odyssey4me was tracking the status | 13:26 |
Miouge | OK. I see odyssey4me asked about it this morning in #openstack-infra . so a recheck won’t help until the mirror is up to date I guess | 13:29 |
odyssey4me | yeah, it seems that the base image from lxc has packages newer than the mirror | 13:31 |
odyssey4me | you could fix it by changing it from a download to a debootstrap, or you could wait until the mirror updates ;) | 13:32 |
Miouge | odyssey4me: I like option 2: grab beer and wait for the mirror to update :) | 13:32 |
odyssey4me | Miouge sounds good, although we might have to wait for a day | 13:33 |
odyssey4me | unless we make another plan | 13:33 |
odyssey4me | that is, of course, if an outdated mirror is the actual problem | 13:33 |
odyssey4me | lemme finish something up, then I'll double-check that | 13:34 |
persia | evrardjp: No, just poor connectivity. | 13:35 |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible master: Remove cloudwatch haproxy configuration https://review.openstack.org/546615 | 13:37 |
odyssey4me | ArchiFleKs if you want to take a stab at something, perhaps the automated clean-up done in https://github.com/openstack/openstack-ansible-os_glance/commit/4fa98725102f98700ddc0844272222ab7b8bfea1 can inspire you? cc evrardjp | 13:38 |
evrardjp | odyssey4me: I want to introduce a new pattern in systemd. | 13:40 |
evrardjp | odyssey4me: when I see this: https://github.com/openstack/openstack-ansible-os_heat/blob/master/tasks/heat_init_systemd.yml#L63 | 13:42 |
*** kstev has joined #openstack-ansible | 13:42 | |
evrardjp | the with_items is included in ALL tasks of that thing | 13:42 |
evrardjp | we should probably loop over the include, so we can do smarter things in the default configuration, like the removal. | 13:42 |
evrardjp | s/so/and/ | 13:43 |
evrardjp | ArchiFleKs: patches welcome on the heat role side :) | 13:43 |
odyssey4me | evrardjp I'm not sure what you mean. | 13:44 |
evrardjp | each task gets the same with_items clause. | 13:45 |
*** kstev1 has joined #openstack-ansible | 13:45 | |
evrardjp | 1) we could loop over the include instead to avoid repetition | 13:46 |
*** kstev has quit IRC | 13:46 | |
odyssey4me | fair enough | 13:46 |
evrardjp | 2) if change the tasks to handle removals too, we don't need new code | 13:46 |
evrardjp | the include is becoming a state machine | 13:47 |
evrardjp | (you only pass it state changes) | 13:48 |
odyssey4me | looking forward to seeing your proposal then | 13:49 |
*** acormier has quit IRC | 13:53 | |
*** gillesMo has quit IRC | 13:53 | |
*** woodard has quit IRC | 13:56 | |
*** gillesMo has joined #openstack-ansible | 13:57 | |
*** woodard has joined #openstack-ansible | 13:57 | |
*** aruns has quit IRC | 14:06 | |
*** aruns has joined #openstack-ansible | 14:06 | |
*** bhujay has joined #openstack-ansible | 14:13 | |
odyssey4me | ok, the ubuntu mirrors will be updated shortly - infra's on it | 14:14 |
*** lbragstad has joined #openstack-ansible | 14:15 | |
armaan | evrardjp: Hello, how are you? You mentioned the bug related to mariadb, I changed the ram allocation ratio re-ran the nova-playbook in on of our production environment and it failed on this task http://paste.openstack.org/show/680371/ | 14:19 |
armaan | evrardjp: do i need this https://docs.openstack.org/releasenotes/openstack-ansible/ocata.html#id1 | 14:20 |
evrardjp | armaan: yes it would seem so. But on top of that a cleanup would be advised. | 14:21 |
evrardjp | you are in the middle of two states I guess? | 14:22 |
armaan | evrardjp: http://paste.openstack.org/show/680372/ | 14:22 |
armaan | evrardjp: could you please suggest on how i can perform cleanup? | 14:22 |
evrardjp | armaan: could you output somewhere the content of your repo? | 14:22 |
evrardjp | your repo lis | 14:22 |
evrardjp | wow | 14:22 |
evrardjp | that's terrible wording | 14:22 |
evrardjp | could you do: | 14:22 |
odyssey4me | evrardjp what do you mean 'a cleanup' ? | 14:23 |
odyssey4me | the venvs will rebuild, and life will be good again after deploying | 14:23 |
armaan | evrardjp: sorry, i am stupid. This is a Pike setup, 16.05 | 14:23 |
evrardjp | ansible -m shell -a "cat /etc/apt/sources.list.d/*" all > /root/aptlist; pastebinit /root/aptlist | 14:23 |
odyssey4me | oh, you're speaking about the mariadb issues? | 14:23 |
armaan | 16.0.5 | 14:23 |
evrardjp | odyssey4me: yes. | 14:24 |
evrardjp | I'd think that armaan has booth repos setup and one is giving 503. | 14:24 |
odyssey4me | ah ok, never mind | 14:24 |
evrardjp | both* | 14:24 |
evrardjp | armaan: this is no stupid question | 14:25 |
evrardjp | it looks like an apt issue, so always worrying. | 14:25 |
*** rromans has quit IRC | 14:27 | |
armaan | evrardjp: http://paste.openstack.org/show/680374/ | 14:27 |
*** weezS has joined #openstack-ansible | 14:28 | |
evrardjp | armaan: that's not for all your containers :) | 14:28 |
evrardjp | I don't see galera there | 14:28 |
*** esberglu has joined #openstack-ansible | 14:29 | |
armaan | evrardjp: I should execute this "ansible -m shell -a "cat /etc/apt/sources.list.d/*" all > /root/aptlist; pastebinit /root/aptlist" from inside the playbooks directory? | 14:29 |
armaan | evrardjp: "deb http://mirror.rackspace.com/mariadb/repo/10.1/ubuntu xenial main" | 14:31 |
armaan | evrardjp: http://paste.openstack.org/show/680376/ | 14:31 |
evrardjp | armaan: yeah, a cleanup would be necessary. | 14:33 |
evrardjp | this mirror is pointing to 10.1.31 | 14:33 |
*** srf_ has joined #openstack-ansible | 14:34 | |
openstackgerrit | German Eichberger proposed openstack/openstack-ansible-os_octavia master: Fixes Lint errors and improve tests https://review.openstack.org/544117 | 14:35 |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible stable/ocata: Update all SHAs for 15.1.17 https://review.openstack.org/545666 | 14:35 |
armaan | evrardjp: Do you think this will fix the problem http://paste.openstack.org/show/680379/ | 14:36 |
*** jwitko_ has joined #openstack-ansible | 14:36 | |
evrardjp | armaan: it would be better on all the infra containers | 14:37 |
evrardjp | but that would be enough | 14:37 |
evrardjp | you can also remove the ocata uca that is a remnant of your thing before the upgrade | 14:38 |
armaan | evrardjp: ok, understood... Let me try it. I hope this is not affecting our customers in any way :/ | 14:39 |
*** weezS has quit IRC | 14:42 | |
*** rromans has joined #openstack-ansible | 14:43 | |
*** kstev1 has quit IRC | 14:52 | |
srf_ | i want know, can i use ansible to install package to instance ? when i want to try, still error in ssh key pair | 14:52 |
cloudnull | g'mornings | 14:53 |
spotz | hey | 14:54 |
armaan | srf_: have you tried with cloud init? | 14:55 |
*** bhujay has quit IRC | 14:55 | |
cloudnull | hows it spotz | 14:56 |
*** aruns has quit IRC | 14:56 | |
*** sm806_ has quit IRC | 14:57 | |
spotz | cloudnull: mudpuppy got me sick, you? | 14:57 |
*** sar has quit IRC | 15:03 | |
evrardjp | srf_: ansible is using ssh, that's it. If you have ssh you're good. | 15:03 |
*** Sha000000 has quit IRC | 15:04 | |
evrardjp | then you need to ofc point your inventory and credentials, but that's standard ansible. You should maybe ask on #ansible channel :) | 15:04 |
srf_ | armaan : what means? | 15:04 |
evrardjp | cloudnull: spotz good monring | 15:05 |
*** kstev has joined #openstack-ansible | 15:05 | |
evrardjp | spotz: here are a few docs changes for you: https://review.openstack.org/#/q/topic:bp/docs-improvements+(status:open) | 15:06 |
evrardjp | my present to you on this day! | 15:06 |
evrardjp | :D | 15:06 |
spotz | thanks evrardjp checking now | 15:06 |
*** sxc731 has quit IRC | 15:06 | |
srf_ | evrardjp : but instance have cloud.key for access the instance when use the ansible i don't know how command to connect with cloud.key | 15:07 |
*** SmearedBeard has quit IRC | 15:07 | |
openstackgerrit | Amy Marrich (spotz) proposed openstack/openstack-ansible master: [Docs] Move Ceph example to user guides https://review.openstack.org/546526 | 15:10 |
*** acormier has joined #openstack-ansible | 15:14 | |
*** sar has joined #openstack-ansible | 15:17 | |
mudpuppy | cloudnull: lies propagated by the spotz collation | 15:20 |
openstackgerrit | Amy Marrich (spotz) proposed openstack/openstack-ansible master: [Docs] Include test scenario as a new user story https://review.openstack.org/546523 | 15:22 |
spotz | evrardjp: done | 15:26 |
*** SmearedBeard has joined #openstack-ansible | 15:26 | |
armaan | evrardjp: aha, that worked. Thanks a lot :D | 15:30 |
*** kstev1 has joined #openstack-ansible | 15:32 | |
mnaser | hwoarang: just a small ping that this patch now has functional tests so not sure if you want to remove your -2 https://review.openstack.org/#/c/521860/ :) | 15:32 |
*** kstev has quit IRC | 15:32 | |
shananigans | srf_: You should be able to use something like '--key-file /location/of/cloud.key' with ansible to specify a key file. | 15:35 |
*** deadnull has joined #openstack-ansible | 15:35 | |
shananigans | srf_: I think '--private-key' also works. | 15:37 |
*** epalper has quit IRC | 15:37 | |
*** epalper has joined #openstack-ansible | 15:38 | |
evrardjp | mudpuppy: :) | 15:40 |
evrardjp | mnaser: making it happen! | 15:41 |
hwoarang | mnaser: i didn't add -2 there | 15:41 |
hwoarang | it's just -1 | 15:41 |
mnaser | hwoarang: oh my bad, i just like to avoid +A when i see red D: | 15:41 |
hwoarang | :) | 15:42 |
srf_ | shananigans : '--private-key' in YAML ? | 15:44 |
shananigans | srf_: When using on the command line. The inventory yml will be ansible_ssh_private_key_file | 15:45 |
shananigans | srf_: http://docs.ansible.com/ansible/latest/intro_inventory.html#list-of-behavioral-inventory-parameters | 15:46 |
srf_ | shananigans : oh thank you so use ansible_ssh_private_key_file to get cloud.key locate for connection some intances, i'll try so thanks | 15:51 |
*** weezS has joined #openstack-ansible | 15:53 | |
evrardjp | cloudnull: you'd be pleased to know things are going forward: This just merged: https://review.openstack.org/#/c/546075/ | 15:57 |
evrardjp | still a few paperwork things to get throught though | 15:58 |
*** cmorelli has joined #openstack-ansible | 15:58 | |
cmorelli | hi all | 15:58 |
*** taseer3 is now known as Taseer | 16:00 | |
*** woodard has quit IRC | 16:02 | |
cmorelli | Kindly asking some help. I'm trying to setup openstack with openstack-ansible 15.1.15 playbooks following instructions at https://docs.openstack.org/project-deploy-guide/openstack-ansible/ocata/run-playbooks.html . Unfortunately the 'setup-infrastructure.yml' playbook fails because of this error >>>> "stderr": " Could not find a version that satisfies the requirement pyasn1-modules>=0.1.5 (from | 16:03 |
cmorelli | python-ldap) (from versions: 0.0.8)\nNo matching distribution found for pyasn1-modules>=0.1.5 (from python-ldap)" | 16:03 |
*** srf_ has quit IRC | 16:05 | |
cmorelli | found this LaunchPad issue here : https://bugs.launchpad.net/openstack-ansible/+bug/1736789 --> following the link it seems that a patch about this was merged in 15.1.13, but appareantly it is not fixed for me | 16:06 |
openstack | Launchpad bug 1736241 in openstack-ansible "duplicate for #1736789 Keystone role should use pyldap instead of python-ldap" [Critical,Fix released] | 16:06 |
cloudnull | cmorelli: That's an error due to an unversioned dependency, which was fixed, but it would seem it's not in a released tag. | 16:06 |
cmorelli | :( | 16:06 |
cloudnull | you might want to just checkout the SHA from the head of the ocata branch | 16:07 |
cloudnull | 4aba989d084d373a58a06af93d980279f3aba5f5 | 16:07 |
cloudnull | this was the fix for ocata | 16:07 |
cloudnull | https://github.com/openstack/openstack-ansible-os_keystone/commit/929e1114722825fdc48e67922956825ef1651583 | 16:07 |
cloudnull | evrardjp: ^ do we know when there will be another ocata tag ? | 16:07 |
cmorelli | cloudnull: great thanks I will try. It is enough to rerun the setup-infrastructure.yml or do I need to start from scratch with setup-hosts.yml ? thank you | 16:07 |
cloudnull | checkout that SHA, rerun ./scripts/bootstrap-ansible.sh, then setup-infrastructure.yml setup-openstack.yml | 16:08 |
cmorelli | oh ok, I also need to re-run the bootstrap | 16:08 |
cmorelli | thanks | 16:08 |
cloudnull | to be SUPER sure its all happy, you might want to nuke the repo containers. but totally optional. `openstack-ansible lxc-container-destroy.yml --limit repo_all; openstack-ansible lxc-container-create.yml --limit 'hosts:repo_all'` | 16:10 |
cloudnull | but that's totally optional | 16:10 |
*** lvdombrkr has quit IRC | 16:10 | |
cloudnull | evrardjp: nice to see that progressing | 16:10 |
evrardjp | cloudnull: there was just one last week. It's every 2 weeks. | 16:11 |
evrardjp | well it's mid month, and the last friday of the month basically | 16:11 |
cloudnull | maybe we missed the keystone change? | 16:12 |
cloudnull | ah... | 16:12 |
cloudnull | 15.1.16 - cmorelli | 16:12 |
cloudnull | that tag has the fix in it | 16:12 |
cloudnull | same process to pull it all together. checkout, bootstrap, run | 16:13 |
* cloudnull was thinking 15.1.15 was the latest, my bad | 16:13 | |
* cloudnull goes back to being on PTO today :) | 16:13 | |
*** omegapoint has quit IRC | 16:16 | |
*** pcaruana has quit IRC | 16:16 | |
spotz | have fun cloudnull | 16:17 |
cmorelli | cloudnull: just bootstrapped again, after the bootstrap do I need to wipe away /etc/openstack-ansible as well ? | 16:17 |
cloudnull | no. | 16:18 |
cmorelli | great | 16:18 |
cloudnull | bootstrap will gather the required roles and make sure the system is ready to use with the release checked out | 16:18 |
*** openstackgerrit has quit IRC | 16:19 | |
*** efried_omalley has joined #openstack-ansible | 16:19 | |
efried_omalley | Howdy folks. Here's an infra patch that may interest you: | 16:20 |
efried_omalley | Eric Fried proposed openstack-infra/project-config master: Regex gerritbot notifications: #openstack-ansible https://review.openstack.org/546682 | 16:20 |
evrardjp | efried_omalley: I know :) | 16:20 |
evrardjp | we had to wait for it to be released right? | 16:20 |
evrardjp | It's done now ? | 16:20 |
evrardjp | oh yeah I see | 16:20 |
efried_omalley | evrardjp: Oh, hi there. Yeah, the feature is merged. | 16:20 |
evrardjp | woot | 16:24 |
evrardjp | I have to go afk, will talk to you later. And thanks for the feature :) | 16:24 |
* efried_omalley waves | 16:25 | |
*** kukacz_ has joined #openstack-ansible | 16:26 | |
*** sar has quit IRC | 16:28 | |
*** kukacz_ is now known as kukacz | 16:29 | |
efried_omalley | Sorry folks, I made a paperwork error. Your new review is | 16:29 |
efried_omalley | Regex gerritbot notifications: #openstack-ansible https://review.openstack.org/546687 | 16:29 |
*** wagner__ has joined #openstack-ansible | 16:36 | |
*** efried_omalley has left #openstack-ansible | 16:41 | |
*** john51 has quit IRC | 16:45 | |
*** openstackgerrit has joined #openstack-ansible | 16:46 | |
openstackgerrit | Merged openstack/openstack-ansible master: [Docs] Uniform landing text https://review.openstack.org/546521 | 16:46 |
*** john51 has joined #openstack-ansible | 16:49 | |
*** dariko has joined #openstack-ansible | 16:50 | |
*** woodard has joined #openstack-ansible | 16:52 | |
*** sar has joined #openstack-ansible | 16:54 | |
*** chyka has joined #openstack-ansible | 17:00 | |
*** sxc731 has joined #openstack-ansible | 17:06 | |
wagner__ | hy guys, I've deployed an openstack pike environment with 4 computes and 2 controllers (all services on-metal), after this I turned off the HA for neutron. After this I start 4 instances, one instance in each compute. The instances on compute 3 and 4 are accessible and the cloud_init procceed as expected they get the IP and other data from metadata agent. The instances inside compute 1 and 2 get the IP but not get the me | 17:07 |
wagner__ | All the configs are the same on the computes and the NTPD are synced. The security group are configured, all ICMP are working from and to any instance | 17:07 |
*** epalper has quit IRC | 17:08 | |
*** Smeared_Beard has joined #openstack-ansible | 17:22 | |
*** SmearedBeard has quit IRC | 17:23 | |
sar | Hi. I'm using ocata 15.1.13 and trying to migrate a volume. Getting these errors in cinder-volume.log: 2018-02-21 09:23:04.944 1258 ERROR cinder.volume.manager [req-2b86722a-06eb-4d31-979f-e3b31aa210c5 cfd622d9765c47579609b4e4cc0f551e 225e74483bbc49369ef6442f85f02081 - default default] Failed to copy volume 3131aeae-e92c-4a56-b308-4d3c8fdab7d2 to cb8dd14d-0d5e-4d1f-a7c4-f21979b87920 | 17:32 |
sar | 2018-02-21 09:23:04.977 1258 ERROR oslo_messaging.rpc.server DiscoveryFailure: Could not determine a suitable URL for the plugin | 17:32 |
sar | Does anyone know what the problem is? | 17:33 |
*** openstackgerrit has quit IRC | 17:48 | |
*** lvdombrkr has joined #openstack-ansible | 17:51 | |
*** Smeared_Beard has quit IRC | 17:55 | |
*** mbuil has quit IRC | 18:09 | |
sm806 | I want to configure additional provider/external network apart from br-vlan and br-vxlan. I would like to know how to define this additional provider network in openstack_user_config.xml. A sample openstack_user_config.xml and interfaces file will be very much useful. | 18:09 |
*** SmearedBeard has joined #openstack-ansible | 18:13 | |
*** gillesMo has quit IRC | 18:14 | |
*** SmearedBeard has quit IRC | 18:20 | |
*** sxc731 has quit IRC | 18:20 | |
*** hamza21 has joined #openstack-ansible | 18:28 | |
*** wagner__ has quit IRC | 18:49 | |
*** poopcat has joined #openstack-ansible | 18:59 | |
*** stuartgr has quit IRC | 19:15 | |
*** sxc731 has joined #openstack-ansible | 19:15 | |
*** openstackgerrit has joined #openstack-ansible | 19:16 | |
openstackgerrit | Andreas Jaeger proposed openstack/openstack-ansible-nspawn_container_create master: Remove zuul.d https://review.openstack.org/546746 | 19:16 |
*** esberglu has quit IRC | 19:19 | |
spotz | sar what plugin are you using? I'm asking over on openstack-cinder | 19:27 |
sar | I haven't changed any defaults on this, as far as i know. By plugin, do you mean what is specified in auth_type? | 19:29 |
*** hamza21 has quit IRC | 19:30 | |
*** MikeW has joined #openstack-ansible | 19:33 | |
MikeW | Hey guys I'm trying to add magnum to my install... I updated the user_config.yml, and when I try to run the playbooks it populates the dynamic inventory, but it doesn't try and create the containers. Any idea on steps I'm missing? | 19:35 |
evrardjp | MikeW: your openstack_user_config | 19:36 |
evrardjp | that's where the host would get assigned | 19:36 |
evrardjp | I mean that's what we use to populate groups | 19:37 |
evrardjp | or conf.d | 19:37 |
evrardjp | maybe check on the os_magnum docs? | 19:37 |
MikeW | Yeah let me double check them again. I'm not sure what's happening exactly, because it fails on gather variables which seems to work elsewhere just fine | 19:38 |
*** lbragstad has quit IRC | 19:40 | |
*** armaan has quit IRC | 19:43 | |
*** esberglu has joined #openstack-ansible | 19:43 | |
*** esberglu has quit IRC | 19:44 | |
*** esberglu has joined #openstack-ansible | 19:44 | |
*** SmearedBeard has joined #openstack-ansible | 19:53 | |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible-nspawn_hosts master: Remove zuul.d bad jobs https://review.openstack.org/546758 | 20:00 |
*** lbragstad has joined #openstack-ansible | 20:01 | |
sar | So i'm getting this stack trace in cinder-volumes.log when trying to migrate a volume: https://pastebin.com/AhwAXQkd | 20:03 |
sar | The stack trace leads me to believe it's related to some keystone auth problem. I'm looking at https://docs.openstack.org/ocata/config-reference/compute/config-options.html, under the keystone_authtoken section. In the nova.conf file generated by os-ansible there is a parameter like "username = nova", but as far as i can tell, that is not a valid config option according to the config-reference. | 20:03 |
sar | Could something like this be the reason it's failing? | 20:04 |
MikeW | evrardjp: Hey my /etc/ansible/facts.d directory shouldn't be empty on my infra hosts should it? | 20:06 |
MikeW | sar How up is your environment at this point? Can you run openstack endpoint list? | 20:07 |
sar | Yeah, sure | 20:07 |
MikeW | Run that real quick and make sure your endpoints are all registered correctly | 20:07 |
sar | And cinder works fine. I can create volumes etc. from horizon | 20:07 |
sar | I don't see anything wrong with the endpoints. They look fine to me | 20:08 |
evrardjp | MikeW: check identation and all of your files, and then double check the inventory.json | 20:09 |
evrardjp | Then you can amaybe try to run | 20:09 |
evrardjp | ansible -m setup all | 20:09 |
MikeW | Interesting as setup has been what's failing let fine comb through all my configs | 20:12 |
MikeW | sar: Are you migrating from one cinder setup to another? | 20:13 |
sar | What do you mean? I'm migrating from one storage host to another | 20:13 |
MikeW | sar: Oooh ok totally different than my setup I have a massive ceph cluster behind my openstack install | 20:13 |
MikeW | evrardjp ansible -m setup all would show specific errors if I had formatting problems right? | 20:16 |
sar | The storage hosts are configured like this in openstack_user_config.yml: | 20:16 |
sar | cinder_backends: | 20:16 |
sar | limit_container_types: cinder_volume | 20:16 |
sar | lvm: | 20:16 |
sar | volume_backend_name: LVM_iSCSI | 20:16 |
sar | volume_driver: cinder.volume.drivers.lvm.LVMVolumeDriver | 20:16 |
sar | volume_group: cinder-volumes | 20:16 |
sar | iscsi_ip_address: x.x.x.x | 20:16 |
evrardjp | MikeW: you'd expect that inventory failure would prevent from proper connecting to all nodes. | 20:18 |
*** armaan has joined #openstack-ansible | 20:18 | |
MikeW | evrardjp Yeah setup all works on everything but these magnum containers, here's the error they're giving: https://pastebin.com/C6qiG96L I've got the magnum-infra_hosts setup in openstack_user_config.yml and they're showing up in the dynamic inventory. Where else should they be? | 20:19 |
logan- | "Error: container infra2_magnum_container-4c7ba388 is not defined" -- did you run the lxc-containers-create playbook? | 20:20 |
*** hybridpollo has joined #openstack-ansible | 20:22 | |
MikeW | logan- Yeah I've attempted to run that playbook as well... I read this playbook and saw it contained the common container create. Are these non equivalent? | 20:24 |
MikeW | I should also note I'm trying to touch as little of the environment as possible as it's currently a dev cluster for those brave enough to start working inside of it | 20:25 |
MikeW | logan- Thanks I was being too careful before in my scoping this should be my fix | 20:27 |
*** lbragstad has quit IRC | 20:29 | |
mnaser | evrardjp: fyi os_gnocchi change merged if you want to add me onto that | 20:29 |
*** lbragstad has joined #openstack-ansible | 20:29 | |
*** lbragstad has quit IRC | 20:29 | |
evrardjp | mnaser: ofc! | 20:29 |
*** lbragstad has joined #openstack-ansible | 20:30 | |
openstackgerrit | Merged openstack/openstack-ansible-nspawn_container_create master: Remove zuul.d https://review.openstack.org/546746 | 20:32 |
*** lbragstad has quit IRC | 20:32 | |
*** lbragstad has joined #openstack-ansible | 20:33 | |
evrardjp | mnaser: I think we did it wrong, I can't add you there. | 20:33 |
evrardjp | :D | 20:33 |
mnaser | uhoh | 20:34 |
evrardjp | I can add you on ceilometer, where you currently already are. | 20:34 |
evrardjp | good. | 20:34 |
mnaser | can you add anyone else? | 20:34 |
evrardjp | nope I am not part of the group | 20:34 |
mnaser | i mean, do you have admin access to the group | 20:34 |
mnaser | ok | 20:34 |
evrardjp | I thought the other one had the openstack-ansible-core group into it | 20:35 |
mnaser | i think we have to ask an infra-root to do it | 20:35 |
mnaser | one sec | 20:35 |
evrardjp | mnaser: done! | 20:39 |
mnaser | evrardjp: merci beaucoup | 20:39 |
evrardjp | and congrats! | 20:39 |
evrardjp | de rien! | 20:39 |
evrardjp | did I finally get a french speaking core? | 20:39 |
mnaser | oui | 20:39 |
evrardjp | wow | 20:39 |
evrardjp | "achievement unlocked" | 20:40 |
mnaser | mais bon du francais de quebec de quelqu'un qui est plutot plus anglophone | 20:40 |
mnaser | lol | 20:40 |
evrardjp | haha | 20:40 |
evrardjp | so you have gnocchi, ceilometer... Let me check aodh | 20:40 |
evrardjp | that's done | 20:40 |
mnaser | yup, os_panko is left once that unbreaks the world | 20:41 |
evrardjp | well it's already in gerrit | 20:41 |
mnaser | and we'll hopefully have enough roles to do a full telemetry (attempt) | 20:41 |
mnaser | https://review.openstack.org/#/admin/groups/1869,members | 20:41 |
evrardjp | so maybe we can ask in infra | 20:41 |
mnaser | indeed it is | 20:41 |
* mnaser already used up an 'ask' token | 20:41 | |
mnaser | :P | 20:41 |
mnaser | is there a gate issue right now | 20:43 |
mnaser | with installing gcc? | 20:43 |
evrardjp | yeah, wrong images in infra or something | 20:43 |
mnaser | ok cool | 20:43 |
mnaser | doesnt look like its here https://wiki.openstack.org/wiki/Infrastructure_Status | 20:43 |
evrardjp | so basically the lxc template downloaded from ubuntu has a version of gcc that's different than the host | 20:43 |
mnaser | i thought that was fixed earlier today | 20:43 |
mnaser | or thats what i thought | 20:43 |
evrardjp | mnaser: you got your answer. | 20:45 |
evrardjp | Yeah I thought it was fixed too, so I did a few rechecks. But then I realized it wasn't. | 20:45 |
*** acormier has quit IRC | 20:46 | |
evrardjp | mnaser: you should be on panko now | 20:46 |
mnaser | evrardjp: thank you, is the project technically imported now? | 20:47 |
mnaser | looks like its there | 20:48 |
openstackgerrit | Mohammed Naser proposed openstack/openstack-ansible-os_panko master: dnm: test commit to get first ci pass https://review.openstack.org/546771 | 20:49 |
mnaser | look at thaaat | 20:49 |
mnaser | thanks to odyssey4me for doing the bulk of the import work | 20:50 |
evrardjp | yeah | 20:50 |
spotz | evrardjp: or logan- know of any reason why sar can make volumes but gets an auth url error when migrating one? | 20:50 |
evrardjp | mmm. I don't know, it's probably another endpoint? Could we have a log with --debug? That would probably help | 20:51 |
spotz | sar can you get that? | 20:51 |
logan- | yeah id watch --debug output on the client side and also cinder-api logs while doing the request | 20:52 |
logan- | and maybe keystone logs also | 20:52 |
openstackgerrit | Andreas Jaeger proposed openstack/openstack-ansible-os_panko master: Zuul: Remove project name https://review.openstack.org/546773 | 20:52 |
openstackgerrit | Andreas Jaeger proposed openstack/openstack-ansible-os_panko stable/pike: Zuul: Remove project name https://review.openstack.org/546775 | 20:54 |
openstackgerrit | Andreas Jaeger proposed openstack/openstack-ansible-os_panko stable/queens: Zuul: Remove project name https://review.openstack.org/546776 | 20:55 |
*** sxc731 has quit IRC | 20:55 | |
*** dave-mccowan has quit IRC | 21:00 | |
*** SmearedBeard has quit IRC | 21:01 | |
openstackgerrit | Merged openstack/openstack-ansible-nspawn_hosts master: Remove zuul.d bad jobs https://review.openstack.org/546758 | 21:01 |
*** openstackgerrit has quit IRC | 21:03 | |
*** armaan has quit IRC | 21:04 | |
MikeW | I'm running into an issue very similar to this https://bugs.launchpad.net/openstack-ansible/+bug/1696802 is there a workaround that doesn't require me to destroy all containers? | 21:04 |
openstack | Launchpad bug 1696802 in openstack-ansible "lxc-containers-create fails when run on a host with existing containers" [Critical,Fix released] - Assigned to Jimmy McCrory (jimmy-mccrory) | 21:04 |
*** mardim has quit IRC | 21:06 | |
*** armaan has joined #openstack-ansible | 21:08 | |
*** lvdombrkr has quit IRC | 21:09 | |
mnaser | evrardjp: do we have to make a change to os_panko to remove the zuul.d stuff? | 21:16 |
mnaser | no jobs for os_panko seem to be running | 21:17 |
evrardjp | I think that's not needed | 21:18 |
evrardjp | I am surprised there is no job running | 21:18 |
evrardjp | maybe the system is jammed and we should indeed remove them to better add them later | 21:19 |
evrardjp | I thought this was good though. | 21:19 |
*** weezS has quit IRC | 21:19 | |
MikeW | evrardjp Hey how do containers get connected to before the management network is setup? | 21:21 |
MikeW | I'm getting the same error as an old bug, but I know it's not the same. I have the updated role, the correct ansible version, etc. | 21:22 |
evrardjp | mnaser: there are still discussions in infra | 21:22 |
mnaser | evrardjp: ah ok | 21:22 |
* mnaser gets back to fixing nova bugs for now | 21:22 | |
evrardjp | MikeW: lxbr0 | 21:22 |
evrardjp | but it's not really "before" | 21:22 |
MikeW | Right os it should be using the osa ssh plugin right? | 21:22 |
evrardjp | we generate the configuration for all the nics when creating the container | 21:22 |
evrardjp | Yes, anything ansible using our connection plugin should attach to the container independantly of the network | 21:23 |
MikeW | Any ideas on how this is happening? https://pastebin.com/wxWNtkDk | 21:24 |
evrardjp | (ssh to the physical host if need be) | 21:24 |
evrardjp | MikeW: I'd need your openstack_user_config / conf.d | 21:25 |
evrardjp | and maybe the container definition | 21:25 |
*** olivierbourdon38 has quit IRC | 21:26 | |
evrardjp | that's into /var/lib/lxc/containername/ | 21:27 |
evrardjp | MikeW: try running with python2 | 21:28 |
evrardjp | I don't know that's stabbing in the dark for me :) | 21:29 |
sar | This is the output from the cinder api container: https://pastebin.com/6TAiPTkV | 21:31 |
MikeW | hahah I'm running in circles myself I'll try it | 21:31 |
evrardjp | MikeW: please paste the openstack_user_config/conf.d | 21:32 |
evrardjp | that would help. | 21:32 |
evrardjp | and the inventory.json | 21:32 |
evrardjp | openstack_inventory.json | 21:32 |
sar | The problem does not appear to be on the client side, as the migrate command works, but the back end side fails with the stack trace i've pasted earlier | 21:32 |
evrardjp | sar: where is that stacktrace? | 21:32 |
evrardjp | could you paste it here? | 21:32 |
sar | https://pastebin.com/AhwAXQkd | 21:33 |
sar | "Could not determine a suitable URL" | 21:33 |
MikeW | evrardjp My conf.d is pretty sparse I'll paste in the inventory | 21:33 |
MikeW | evrardjp: https://pastebin.com/pG6JBpY7 | 21:36 |
sar | (the output is from cinder-volume.log on the donating storage host) | 21:36 |
evrardjp | sar endpoint list and cinder config would be needed | 21:37 |
evrardjp | MikeW: has that ever worked? | 21:40 |
evrardjp | or is that a new deploy ? | 21:40 |
evrardjp | I don't think your openstack_user_config is right. | 21:40 |
MikeW | This deploy is working believe it or not, but magnum is a new additon | 21:40 |
evrardjp | could you tell me what you changed to get magnum? | 21:41 |
MikeW | haha feel free to help me out on fixing stuff | 21:41 |
*** niraj_singh has quit IRC | 21:41 | |
MikeW | I've got probably 40-50 vms working right now hopefully I've not got everything too effed up | 21:41 |
evrardjp | MikeW: I still haven't seen the openstack_user_config | 21:41 |
evrardjp | first lesson is not to do it on prod :) | 21:42 |
evrardjp | configuration management isn't forgiving | 21:42 |
MikeW | So true so true | 21:42 |
MikeW | I'm deploying two more clouds, and then they want a prod | 21:42 |
MikeW | Out of just me | 21:42 |
MikeW | https://pastebin.com/Yi4YBcW7 | 21:43 |
MikeW | evrardjp Above is my user config... I'm new to ansible and openstack simultaneously but somehow deployed a "working" cloud | 21:43 |
sar | Here is the endpoint list: https://pastebin.com/RKHygQ2R | 21:43 |
evrardjp | did you change L23 and L57? | 21:44 |
MikeW | I left out some of the superfluous services in favor of finishing the first deployment early, and now I'm adding them in as they're request.. fml | 21:44 |
evrardjp | also ceph mon hosts are misaligned | 21:44 |
MikeW | evrardjp Yeah I pulled ceph out of here those are old and not cleaned up yet. For sure I probably changed both those lines | 21:45 |
MikeW | evrardjp I wrote some custom playbooks for the ceph cluster separate of this | 21:45 |
MikeW | evrardjp If you mean did I recently change them... no that's how they've been since I completed the deployment | 21:46 |
evrardjp | also you have weird double wrongly indented group_binds | 21:46 |
evrardjp | else it's your copy paste that's flaky :) | 21:46 |
MikeW | Could be either :) please elaborate | 21:47 |
evrardjp | L61 missing a space | 21:47 |
evrardjp | same for L52 | 21:47 |
evrardjp | L52 and L53 are opposite in ideas, you shouldn't do that | 21:47 |
evrardjp | L40 missing a space | 21:48 |
evrardjp | l27 too | 21:48 |
evrardjp | and container_interface are generally not overriden, so you might have hit a bug | 21:48 |
sar | evrardjp: And here is cinder.conf: https://pastebin.com/gpJkx8pK | 21:49 |
evrardjp | it's very late for me | 21:49 |
evrardjp | sar: looks okay to me, could you show endpoints just for making sure? | 21:51 |
sar | Here are endpoints: https://pastebin.com/RKHygQ2R | 21:51 |
MikeW | evrardjp Is there anything directly wrong with the magnum part? I know this configs messed up a lot, but it hasn't been a huge issue | 21:52 |
evrardjp | MikeW: I am worried your openstack_user_config doesn't generate anything good in openstack_inventory.json, but hey I am so tired, don't trust my word on it :) | 21:52 |
MikeW | evrardjp Would it help you to know I deployed heat today with no issues? | 21:52 |
evrardjp | mmm | 21:53 |
MikeW | evrardjp Also is there a vim plugin I can use to help me keep these json files not crappy? | 21:53 |
evrardjp | MikeW: never edit json files :) | 21:53 |
MikeW | hahah sorry :) I couldn't help it | 21:53 |
evrardjp | it's hard to know what's wrong, maybe your inventory is completely busted, and there is no way to find out | 21:54 |
MikeW | If you need to leave that's fine I'm just doing this so I can deploye a kubernetes cluster for a demo tomrrow. I'll find a way just like I did before | 21:54 |
evrardjp | yeah sorry | 21:55 |
evrardjp | sar: it looks okay. haproxy is fine I guess | 21:56 |
sar | yes, haproxy is working fine | 21:56 |
evrardjp | sar: interesting enough we don't have the same output when doing endpoint list | 21:58 |
evrardjp | for keystone I don't have the /v3 | 21:58 |
evrardjp | which branch are you on? | 21:58 |
evrardjp | I am definitely off for today -- Sorry guys | 21:59 |
evrardjp | I am sleeping on my keyboard :p | 21:59 |
*** acormier has joined #openstack-ansible | 21:59 | |
*** weezS has joined #openstack-ansible | 21:59 | |
evrardjp | if I could get some votes on https://review.openstack.org/#/q/topic:bp/docs-improvements+(status:open) that would be great! | 22:01 |
evrardjp | see you tomorrow! | 22:02 |
*** acormier has quit IRC | 22:03 | |
sar | evrardjp: i'm on ocata 15.1.13 | 22:10 |
*** armaan has quit IRC | 22:14 | |
*** armaan has joined #openstack-ansible | 22:14 | |
*** openstackgerrit has joined #openstack-ansible | 22:18 | |
openstackgerrit | Merged openstack/openstack-ansible master: [Docs] Move AIO to first scenario https://review.openstack.org/546522 | 22:18 |
*** kstev1 has quit IRC | 22:29 | |
*** acormier has joined #openstack-ansible | 22:31 | |
*** acormier has quit IRC | 22:32 | |
*** acormier has joined #openstack-ansible | 22:33 | |
*** jwitko__ has joined #openstack-ansible | 22:34 | |
*** jwitko_ has quit IRC | 22:37 | |
*** jwitko__ has quit IRC | 22:39 | |
*** lbragstad has quit IRC | 22:47 | |
*** lbragstad has joined #openstack-ansible | 22:48 | |
*** jwitko_ has joined #openstack-ansible | 23:02 | |
*** weezS has quit IRC | 23:02 | |
*** MikeW has quit IRC | 23:11 | |
*** acormier has quit IRC | 23:19 | |
*** wagner has joined #openstack-ansible | 23:32 | |
*** wagner has left #openstack-ansible | 23:33 | |
*** wagner has joined #openstack-ansible | 23:33 | |
*** acormier has joined #openstack-ansible | 23:38 | |
*** acormier has quit IRC | 23:40 | |
*** acormier has joined #openstack-ansible | 23:40 | |
*** acormier has quit IRC | 23:41 | |
*** acormier has joined #openstack-ansible | 23:41 | |
*** wagner has quit IRC | 23:54 | |
*** chyka has quit IRC | 23:55 | |
*** chyka has joined #openstack-ansible | 23:56 | |
*** acormier has quit IRC | 23:58 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!