*** gyee has joined #openstack-ansible | 00:08 | |
*** lbragstad has quit IRC | 00:10 | |
*** gyee has quit IRC | 00:12 | |
*** macza has joined #openstack-ansible | 00:25 | |
*** macza has quit IRC | 00:25 | |
*** macza has joined #openstack-ansible | 00:26 | |
*** macza has quit IRC | 00:33 | |
*** openstackgerrit has quit IRC | 00:34 | |
*** hwoarang_ has joined #openstack-ansible | 00:57 | |
*** hwoarang has quit IRC | 00:59 | |
cloudnull | anyone around want to do some reviews on the smart_sources bits https://review.openstack.org/#/q/topic:smart-sources+(status:open) | 00:59 |
---|---|---|
*** TxGirlGeek has quit IRC | 01:00 | |
*** gyee has joined #openstack-ansible | 01:01 | |
cloudnull | I think the pattern is finally in a good place, especially considering all the learnings we had with neutron. I've not tackled all the roles, but this should lead the way for us to easily get it in this cycle allowing us to stop carrying templates unnecessarily . | 01:02 |
*** tosky has quit IRC | 01:05 | |
*** markvoelker has joined #openstack-ansible | 01:15 | |
*** gyee has quit IRC | 01:37 | |
*** gyee has joined #openstack-ansible | 01:38 | |
*** cshen has joined #openstack-ansible | 01:48 | |
*** openstackgerrit has joined #openstack-ansible | 01:48 | |
openstackgerrit | Merged openstack/openstack-ansible-ops master: remove dynamic ns.enable generators https://review.openstack.org/629939 | 01:48 |
*** gyee has quit IRC | 01:49 | |
*** cshen has quit IRC | 01:53 | |
*** markvoelker has quit IRC | 02:42 | |
*** markvoelker has joined #openstack-ansible | 02:52 | |
*** lbragstad has joined #openstack-ansible | 02:53 | |
*** TxGirlGeek has joined #openstack-ansible | 02:56 | |
*** hwoarang has joined #openstack-ansible | 03:09 | |
*** hwoarang_ has quit IRC | 03:09 | |
*** vnogin has joined #openstack-ansible | 03:14 | |
*** vnogin has quit IRC | 03:18 | |
openstackgerrit | Merged openstack/openstack-ansible-os_tempest master: Use the inventory to enable/disable services by default https://review.openstack.org/628979 | 03:25 |
*** markvoelker has quit IRC | 03:28 | |
*** markvoelker has joined #openstack-ansible | 03:49 | |
*** cshen has joined #openstack-ansible | 03:49 | |
cloudnull | evenings all | 03:50 |
*** cshen has quit IRC | 03:54 | |
kaiokmo | cloudnull: o/ | 04:05 |
*** udesale has joined #openstack-ansible | 04:14 | |
openstackgerrit | Merged openstack/openstack-ansible-galera_server master: Tidy yum repository setup https://review.openstack.org/629934 | 04:18 |
*** markvoelker has quit IRC | 04:26 | |
*** lbragstad has quit IRC | 04:35 | |
openstackgerrit | Merged openstack/openstack-ansible-os_keystone master: Add libpython2.7 as a required package https://review.openstack.org/619040 | 04:44 |
*** radeks has joined #openstack-ansible | 04:56 | |
cloudnull | hows it kaiokmo? | 04:58 |
kaiokmo | things are fine. and you? | 05:02 |
*** markvoelker has joined #openstack-ansible | 05:05 | |
*** markvoelker has quit IRC | 05:11 | |
*** markvoelker has joined #openstack-ansible | 05:11 | |
*** markvoelker has quit IRC | 05:15 | |
*** markvoelker has joined #openstack-ansible | 05:17 | |
cloudnull | generally good :) | 05:17 |
*** fatdragon has quit IRC | 05:25 | |
*** fatdragon has joined #openstack-ansible | 05:25 | |
*** dave-mccowan has quit IRC | 05:28 | |
*** fatdragon has quit IRC | 05:31 | |
*** chkumar|out is now known as chandankumar | 05:40 | |
*** TxGirlGeek has quit IRC | 05:41 | |
*** cshen has joined #openstack-ansible | 05:49 | |
*** cshen has quit IRC | 05:54 | |
*** radeks has quit IRC | 05:58 | |
openstackgerrit | Vieri proposed openstack/openstack-ansible-os_aodh master: fix tox python3 overrides https://review.openstack.org/606824 | 06:09 |
openstackgerrit | Chandan Kumar proposed openstack/openstack-ansible-os_tempest master: Remove tempest_image_dir_owner var https://review.openstack.org/629419 | 06:13 |
*** markvoelker has quit IRC | 06:20 | |
*** markvoelker has joined #openstack-ansible | 06:31 | |
*** markvoelker has quit IRC | 06:36 | |
*** czunker_ccc has joined #openstack-ansible | 06:38 | |
*** mathlin has quit IRC | 06:44 | |
*** markvoelker has joined #openstack-ansible | 06:51 | |
*** radeks has joined #openstack-ansible | 06:57 | |
*** markvoelker has quit IRC | 06:58 | |
chandankumar | odyssey4me: Hello | 07:02 |
*** markvoelker has joined #openstack-ansible | 07:02 | |
chandankumar | odyssey4me: what is the use of tempest_service_setup_host in os_tempest https://github.com/openstack/openstack-ansible-os_tempest/blob/master/defaults/main.yml#L35 ? | 07:03 |
chandankumar | odyssey4me: As per comment, It says it will execute shade module and host have already clouds.yaml configured | 07:04 |
chandankumar | odyssey4me: but shade is deprecated in favor of openstacksdk | 07:04 |
*** pcaruana has joined #openstack-ansible | 07:05 | |
*** kopecmartin|off is now known as kopecmartin | 07:07 | |
*** markvoelker has quit IRC | 07:07 | |
*** jawad_axd has joined #openstack-ansible | 07:08 | |
*** markvoelker has joined #openstack-ansible | 07:08 | |
*** mathlin has joined #openstack-ansible | 07:10 | |
*** markvoelker has quit IRC | 07:13 | |
openstackgerrit | Chandan Kumar proposed openstack/openstack-ansible-os_tempest master: [DNM] testing without tempest_service_setup_host https://review.openstack.org/630040 | 07:14 |
*** vnogin has joined #openstack-ansible | 07:14 | |
*** cshen has joined #openstack-ansible | 07:15 | |
*** vnogin has quit IRC | 07:18 | |
*** fatdragon has joined #openstack-ansible | 07:24 | |
*** mathlin has quit IRC | 07:27 | |
*** fatdragon has quit IRC | 07:29 | |
jrosser | chandankumar: all the osa roles have a ...._setup_host | 07:36 |
jrosser | There are times when the deploy host cannot directly do http against the admin endpoint, for example when there is an ssh bastion in between | 07:42 |
jrosser | That var allows service setup tasks to be delegated to a host that the deployer chooses, which can hit the admin endpoint | 07:43 |
*** klamath has joined #openstack-ansible | 07:57 | |
*** radeks_ has joined #openstack-ansible | 08:01 | |
fnpanic | hi | 08:02 |
fnpanic | using rocky and mimic is fine or should i stick with luminous for rocky? | 08:02 |
*** radeks has quit IRC | 08:03 | |
*** mathlin has joined #openstack-ansible | 08:05 | |
*** luksky has joined #openstack-ansible | 08:06 | |
*** gkadam has joined #openstack-ansible | 08:09 | |
*** eumel8 has joined #openstack-ansible | 08:10 | |
*** markvoelker has joined #openstack-ansible | 08:16 | |
jrosser | fnpanic: rocky+mimic is working for me | 08:18 |
*** cshen has quit IRC | 08:18 | |
*** dcdamien has joined #openstack-ansible | 08:18 | |
jrosser | I use my own tooling to deploy ceph, you get to choose if you have osa do the ceph deploy or if you make it separate | 08:19 |
*** gkadam_ has joined #openstack-ansible | 08:20 | |
*** jbadiapa has joined #openstack-ansible | 08:22 | |
*** gkadam has quit IRC | 08:23 | |
*** markvoelker has quit IRC | 08:23 | |
*** cshen has joined #openstack-ansible | 08:24 | |
*** mathlin has quit IRC | 08:24 | |
*** rgogunskiy has joined #openstack-ansible | 08:28 | |
jrosser | odyssey4me: can you take a look at this - ceph finally fixed with brute force permissions change https://review.openstack.org/#/c/629317/ | 08:29 |
*** rgogunskiy has quit IRC | 08:31 | |
*** cshen has quit IRC | 08:31 | |
*** tosky has joined #openstack-ansible | 08:40 | |
*** gkadam__ has joined #openstack-ansible | 08:45 | |
*** gkadam_ has quit IRC | 08:47 | |
*** thuydang has joined #openstack-ansible | 08:47 | |
*** ygk_12345 has joined #openstack-ansible | 08:53 | |
ygk_12345 | hi all my heat playbook of rocky 18.1.2 release is failing | 08:59 |
*** mathlin has joined #openstack-ansible | 09:00 | |
*** dcdamien has quit IRC | 09:01 | |
*** vollman has quit IRC | 09:07 | |
*** thuydang has left #openstack-ansible | 09:13 | |
mbuil | could anybody check https://review.openstack.org/#/c/621249/ please? | 09:16 |
ygk_12345 | hi all my heat playbook of rocky 18.1.2 release is failing | 09:17 |
*** mcela has joined #openstack-ansible | 09:19 | |
*** DanyC has joined #openstack-ansible | 09:19 | |
*** shardy has joined #openstack-ansible | 09:20 | |
*** mathlin has quit IRC | 09:23 | |
openstackgerrit | Frank Kloeker proposed openstack/openstack-ansible-haproxy_server master: Add feature Letsencrypt SSL certification https://review.openstack.org/586774 | 09:24 |
ygk_12345 | shardy: Hi. heat playbook of rocky 18.1.2 release is failing | 09:25 |
ygk_12345 | shardy: can u help me please | 09:26 |
shardy | ygk_12345: sorry I've never deployed heat (or anything else) with openstack-ansible | 09:28 |
shardy | hopefully some other folks around here can help - I'd put the error into paste.openstack.org and add the link here | 09:28 |
ygk_12345 | can someone check this error of heat playbook of rocky 18.1.2 please | 09:30 |
ygk_12345 | http://paste.openstack.org/show/741763/ | 09:30 |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible stable/rocky: Fix git tracking of networking OVN https://review.openstack.org/630099 | 09:46 |
*** DanyC has quit IRC | 09:47 | |
*** DanyC has joined #openstack-ansible | 09:48 | |
*** mathlin has joined #openstack-ansible | 09:54 | |
evrardjp | ygk_12345: hey, thanks for the bug | 09:56 |
evrardjp | we'll triage this appropriately | 09:57 |
fnpanic | jrosser: thanks for the info! | 09:59 |
*** dcdamien has joined #openstack-ansible | 10:04 | |
ygk_12345 | evrardjp: attached those files to the bug | 10:10 |
*** shardy has quit IRC | 10:12 | |
*** shardy has joined #openstack-ansible | 10:15 | |
*** luksky has quit IRC | 10:16 | |
*** mathlin has quit IRC | 10:20 | |
Miouge | Good morning folks! | 10:20 |
*** shardy_ has joined #openstack-ansible | 10:26 | |
*** cshen has joined #openstack-ansible | 10:27 | |
*** shardy has quit IRC | 10:29 | |
ygk_12345 | evrardjp: any workaround possible in the meantime to overcome this issue ? | 10:32 |
*** cshen has quit IRC | 10:33 | |
*** shardy_ has quit IRC | 10:36 | |
*** mathlin has joined #openstack-ansible | 10:46 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/ansible-hardening stable/rocky: Switch to using import_tasks for static inclusion https://review.openstack.org/630139 | 10:47 |
*** electrofelix has joined #openstack-ansible | 10:48 | |
*** shardy has joined #openstack-ansible | 10:49 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-galera_server stable/rocky: Tidy yum repository setup https://review.openstack.org/630140 | 10:50 |
*** mathlin has quit IRC | 10:50 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-galera_server stable/rocky: Switch galera_install_dnf back to being a symlink https://review.openstack.org/630141 | 10:51 |
openstackgerrit | Jakob Englisch proposed openstack/ansible-hardening stable/rocky: Chrony: make ntp server options configurable https://review.openstack.org/630142 | 10:54 |
*** udesale has quit IRC | 10:54 | |
openstackgerrit | Jakob Englisch proposed openstack/ansible-hardening stable/queens: Chrony: make ntp server options configurable https://review.openstack.org/630143 | 10:55 |
*** deployer2 has joined #openstack-ansible | 10:56 | |
openstackgerrit | Jakob Englisch proposed openstack/ansible-hardening stable/rocky: Chrony: add an option to sync the hardware clock https://review.openstack.org/630144 | 10:56 |
openstackgerrit | Jakob Englisch proposed openstack/ansible-hardening stable/queens: Chrony: add an option to sync the hardware clock https://review.openstack.org/630145 | 10:57 |
*** shardy has quit IRC | 10:58 | |
odyssey4me | evrardjp jrosser what do you think about https://review.openstack.org/629499 to help cut down the number of overrides needed for tests? | 11:10 |
odyssey4me | jrosser guilhermesp ygk_12345 interesting, it appears that https://review.openstack.org/629544 shows that, at least for master, adding heat doesn't give any problems | 11:11 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible master: zuul: Add required project openstack/openstack-ansible https://review.openstack.org/629542 | 11:12 |
odyssey4me | jrosser thanks for figuring out https://review.openstack.org/629317 :) | 11:13 |
openstackgerrit | Chandan Kumar proposed openstack/openstack-ansible-os_tempest master: Remove tempest_image_dir_owner var https://review.openstack.org/629419 | 11:16 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible master: Fixes empty metal_query https://review.openstack.org/629930 | 11:17 |
Miouge | I would like to add a “haproxy_whitelist_networks” to a couple of API services (heat_api, magnum, octavia). Do I need to copy the whole “haproxy_default_services” from upstream into my group_var? | 11:19 |
*** mathlin has joined #openstack-ansible | 11:20 | |
openstackgerrit | Chandan Kumar proposed openstack/openstack-ansible-os_tempest master: Remove tempest_image_dir_owner var https://review.openstack.org/629419 | 11:23 |
*** vnogin has joined #openstack-ansible | 11:31 | |
chandankumar | odyssey4me: Hello | 11:33 |
chandankumar | odyssey4me: https://review.openstack.org/#/c/627482/35/.zuul.yaml@189 I can set the value here directly https://github.com/openstack/openstack-ansible-os_tempest/blob/master/defaults/main.yml#L35 to inventory_hostname ? | 11:34 |
odyssey4me | chandankumar no, for OSA we want to use local host by default | 11:41 |
*** vnogin has quit IRC | 11:41 | |
chandankumar | odyssey4me: ok, I think i need to take care of that in playbook itself | 11:43 |
odyssey4me | chandankumar just change the var as I suggested | 11:43 |
chandankumar | odyssey4me: yup already updated the patch | 11:44 |
odyssey4me | no need to do anything in the playbook - just change the var | 11:44 |
*** mathlin has quit IRC | 11:50 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_cinder master: Cleanup files and templates using smart sources https://review.openstack.org/588953 | 11:52 |
*** cshen has joined #openstack-ansible | 11:55 | |
*** luksky has joined #openstack-ansible | 11:56 | |
*** cshen has quit IRC | 12:01 | |
*** mathlin has joined #openstack-ansible | 12:16 | |
openstackgerrit | Manuel Buil proposed openstack/openstack-ansible-os_neutron master: Provide support for ovs-sfc https://review.openstack.org/621249 | 12:17 |
openstackgerrit | Manuel Buil proposed openstack/openstack-ansible-os_neutron master: Provide support for ovs-sfc https://review.openstack.org/621249 | 12:18 |
*** czunker_ccc has quit IRC | 12:27 | |
jamesdenton | mornin | 12:27 |
ygk_12345 | evrardjp: is the fix released for this bug ? | 12:29 |
openstackgerrit | Merged openstack/openstack-ansible-os_barbican master: Only implement policy.json if an override is configured https://review.openstack.org/629280 | 12:34 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_barbican stable/rocky: Only implement policy.json if an override is configured https://review.openstack.org/630199 | 12:36 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_barbican stable/rocky: Only implement policy.json if an override is configured https://review.openstack.org/630199 | 12:36 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_barbican stable/queens: Only implement policy.json if an override is configured https://review.openstack.org/630200 | 12:36 |
*** cshen has joined #openstack-ansible | 12:38 | |
*** hwoarang has quit IRC | 12:40 | |
*** mathlin has quit IRC | 12:41 | |
guilhermesp | odyssey4me: that's interesting. ygk_12345 for now I'd suggest you to checkout the master branch of heat and try to run the playbook again just to see the the issue persists | 12:42 |
odyssey4me | guilhermesp I don't think he should do that because it's his production environment | 12:44 |
guilhermesp | He told yesterday was a fresh install? | 12:44 |
guilhermesp | At least the requests I tried to follow | 12:45 |
*** cshen has quit IRC | 12:45 | |
guilhermesp | If it is not a fresh I agree with odyssey4me | 12:46 |
odyssey4me | guilhermesp ah, fair enough - if it's a test environment that can be dstroyed and recreated, then yeah try master and see if that works - if it does, then maybe we have an ansible bug, or something needs backporting | 12:46 |
odyssey4me | master uses ansible 2.7, and rocky uses ansible 2.5 IIRC | 12:47 |
ygk_12345 | guilhermesp: odyssey4me i will try with the master branch of rocky then | 12:47 |
odyssey4me | I'm suspecting an ansible bug at this point | 12:47 |
guilhermesp | Yep, we could have a clue that could make easy for us to build a pr for this | 12:47 |
ygk_12345 | guilhermesp: odyssey4me i will let you know how it goes | 12:47 |
odyssey4me | ygk_12345 master is not rocky - it is stein, and it should not be used for production... but is fine for testing | 12:47 |
ygk_12345 | odyssey4me: so which version is stable as of now for rocky ? | 12:48 |
guilhermesp | ygk_12345: yep, be sure to checkout master in a test env | 12:48 |
ygk_12345 | 18.1.1 ? or 18.1.2 ? | 12:48 |
odyssey4me | ygk_12345 whatever the latest tag is, but nothing's changed for rocky so the experience will be the same regardless | 12:48 |
chandankumar | mnaser: cloudnull jrosser https://review.openstack.org/#/c/629419/ is good to go | 12:49 |
odyssey4me | I suspect an ansible bug. | 12:49 |
*** strobelight has joined #openstack-ansible | 12:51 | |
*** strobelight_ has joined #openstack-ansible | 12:54 | |
*** strobelight is now known as Guest69101 | 12:54 | |
*** strobelight_ is now known as strobelight | 12:55 | |
*** Guest69101 has quit IRC | 12:58 | |
openstackgerrit | Merged openstack/openstack-ansible master: Call ceph-facts role as required by changes to ceph-ansible https://review.openstack.org/629317 | 13:03 |
*** vnogin has joined #openstack-ansible | 13:06 | |
odyssey4me | jrosser could you take a peek at https://review.openstack.org/629542 ? | 13:07 |
odyssey4me | cores - I need another review for https://review.openstack.org/624773 please | 13:08 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible master: Update inventory generator to support container gateway override https://review.openstack.org/629309 | 13:09 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible master: Make OVN track master branch https://review.openstack.org/629914 | 13:09 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible master: Spice console doesn't work on aarch64+kvm. https://review.openstack.org/626593 | 13:11 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible master: Add http proxy test scenario https://review.openstack.org/625523 | 13:11 |
*** mathlin has joined #openstack-ansible | 13:12 | |
*** vnogin has quit IRC | 13:27 | |
*** jawad_axd has quit IRC | 13:32 | |
*** mathlin has quit IRC | 13:36 | |
*** cshen has joined #openstack-ansible | 13:41 | |
*** priteau has joined #openstack-ansible | 13:47 | |
*** mkuf has quit IRC | 13:52 | |
*** cshen has quit IRC | 13:52 | |
*** shardy has joined #openstack-ansible | 13:57 | |
openstackgerrit | Manuel Buil proposed openstack/openstack-ansible-os_neutron master: Provide support for ovs-sfc https://review.openstack.org/621249 | 13:57 |
*** lbragstad has joined #openstack-ansible | 13:57 | |
deployer2 | where in OSA rocky are policy.json files located? Looking into nova-api-container and only file /etc/nova/policy.json contains just { } | 13:58 |
odyssey4me | deployer2 the default policy is on code - the policy.json file only contains overrides of the defaults | 13:59 |
deployer2 | odyssey4me hmm, if I want to understand how default permissions work - where to look for policy rules? | 14:01 |
odyssey4me | deployer2 I don't know - either the keystone docs, or the docs of the service itself | 14:02 |
*** strattao has joined #openstack-ansible | 14:04 | |
*** hwoarang has joined #openstack-ansible | 14:04 | |
*** dave-mccowan has joined #openstack-ansible | 14:08 | |
*** mathlin has joined #openstack-ansible | 14:08 | |
*** DanyC has quit IRC | 14:08 | |
*** DanyC has joined #openstack-ansible | 14:09 | |
*** cshen has joined #openstack-ansible | 14:19 | |
*** deployer2 has quit IRC | 14:20 | |
*** cshen has quit IRC | 14:24 | |
*** mathlin has quit IRC | 14:26 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_nova master: Cleanup files and templates using smart sources https://review.openstack.org/588951 | 14:31 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_cinder master: Cleanup files and templates using smart sources https://review.openstack.org/588953 | 14:33 |
*** vnogin has joined #openstack-ansible | 14:40 | |
openstackgerrit | Jonathan Rosser proposed openstack/openstack-ansible-lxc_hosts master: Remove centos copy-on-write backed tests https://review.openstack.org/630276 | 14:41 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_heat stable/rocky: Only implement policy.json if an override is configured https://review.openstack.org/629409 | 14:41 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_heat stable/queens: Only implement policy.json if an override is configured https://review.openstack.org/629410 | 14:42 |
*** kopecmartin is now known as kopecmartin|off | 14:45 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_barbican master: Remove legacy policy.json file https://review.openstack.org/630279 | 14:48 |
ygk_12345 | odyssey4me: evrardjp i tried with 18.1.1 branch and again the heat failed with the same error | 14:48 |
openstackgerrit | Jonathan Rosser proposed openstack/openstack-ansible-lxc_hosts master: Remove centos copy-on-write backed tests https://review.openstack.org/630276 | 14:49 |
odyssey4me | ygk_12345 yes, as expected | 14:49 |
ygk_12345 | odyssey4me: so what could be the problem ? | 14:49 |
odyssey4me | ygk_12345 the suggestion was to build using master to validate that it works for you with your test config | 14:49 |
ygk_12345 | odyssey4me: ok | 14:50 |
odyssey4me | if it does, then it's most likely an ansible bug | 14:50 |
ygk_12345 | odyssey4me: ok i will try master then and let you know | 14:50 |
ygk_12345 | odyssey4me: evrardjp thanks for your support guys. Much appreciated. I will try master and let you know. | 14:50 |
evrardjp | yw | 14:51 |
*** ygk_12345 has quit IRC | 14:51 | |
*** cshen has joined #openstack-ansible | 14:51 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_cinder master: Cleanup files and templates using smart sources https://review.openstack.org/588953 | 14:53 |
jamesdenton | any opposition to extending the MNAIO to lay down something besides LinuxBridge? Or does that functionality already exist? | 14:54 |
odyssey4me | jamesdenton it doesn't exist, and no objection | 14:54 |
jamesdenton | cool | 14:54 |
*** cshen has quit IRC | 14:56 | |
*** vnogin has quit IRC | 15:01 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_cinder stable/rocky: Remove legacy policy.json file https://review.openstack.org/630282 | 15:02 |
*** mathlin has joined #openstack-ansible | 15:03 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_cinder stable/rocky: Only implement policy.json if an override is configured https://review.openstack.org/630282 | 15:04 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_nova stable/rocky: Only implement policy.json if an override is configured https://review.openstack.org/630283 | 15:10 |
openstackgerrit | Merged openstack/openstack-ansible-os_tempest master: Remove tempest_image_dir_owner var https://review.openstack.org/629419 | 15:15 |
openstackgerrit | Merged openstack/openstack-ansible-os_tempest master: Automatically select the correct tempest plugins https://review.openstack.org/629499 | 15:15 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_keystone stable/rocky: Remove legacy policy.json file https://review.openstack.org/630289 | 15:22 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_nova stable/rocky: Only implement policy.json if an override is configured https://review.openstack.org/630283 | 15:23 |
*** cshen has joined #openstack-ansible | 15:24 | |
cloudnull | mornings | 15:28 |
*** cshen has quit IRC | 15:29 | |
jamesdenton | hello | 15:29 |
*** mathlin has quit IRC | 15:30 | |
cloudnull | o/ hows it ? | 15:31 |
openstackgerrit | Manuel Buil proposed openstack/openstack-ansible-os_neutron master: Provide support for ovs-sfc https://review.openstack.org/621249 | 15:32 |
jamesdenton | it's goin | 15:33 |
openstackgerrit | Merged openstack/openstack-ansible master: zuul: Add required project openstack/openstack-ansible https://review.openstack.org/629542 | 15:33 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible stable/rocky: zuul: Add required project openstack/openstack-ansible https://review.openstack.org/630295 | 15:42 |
noonedeadpunk | folks, need 1 more +2 for the patch https://review.openstack.org/#/c/629930/ | 15:43 |
*** cshen has joined #openstack-ansible | 15:50 | |
*** vollman has joined #openstack-ansible | 15:56 | |
*** cshen has quit IRC | 15:57 | |
*** markvoelker has joined #openstack-ansible | 15:58 | |
*** mathlin has joined #openstack-ansible | 16:00 | |
*** priteau has quit IRC | 16:02 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_nova master: Cleanup files and templates using smart sources https://review.openstack.org/588951 | 16:09 |
*** evrardjp has quit IRC | 16:10 | |
*** evrardjp has joined #openstack-ansible | 16:11 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_glance master: Cleanup files and templates using smart sources https://review.openstack.org/588959 | 16:13 |
cloudnull | while folks are in a reviewing mood :) https://review.openstack.org/#/q/topic:smart-sources+(status:open) | 16:13 |
odyssey4me | cloudnull pretty quiet today - no major drama... I pushed up a few patches to remove policy.json, even from stable branches - it seems we've been carrying them for a long time and a lot of services dropped them ages ago, some even in queens | 16:17 |
*** gkadam__ has quit IRC | 16:18 | |
odyssey4me | plenty of patches need review | 16:19 |
odyssey4me | ;) | 16:19 |
prometheanfire | so... it looks like the ssl/tls vars are not used at all in os_barbican (defaults) should I just remove them? | 16:21 |
*** cshen has joined #openstack-ansible | 16:21 | |
cloudnull | odyssey4me looking now :) | 16:25 |
*** mathlin has quit IRC | 16:26 | |
*** cshen has quit IRC | 16:27 | |
cloudnull | for reference: | 16:28 |
cloudnull | rocky policy changes need to reviewed - https://review.openstack.org/#/q/topic:smart-sources-stable/rocky+(status:open+OR+status:merged) | 16:28 |
cloudnull | queens policy changes need to be reviewed - https://review.openstack.org/#/q/topic:smart-sources-stable/queens+(status:open+OR+status:merged) | 16:28 |
*** luksky has quit IRC | 16:31 | |
*** pcaruana has quit IRC | 16:36 | |
hwoarang | hey everybody. just so you know i am investigating the distro install failures on opensuse. sorry it took so long! | 16:38 |
odyssey4me | thanks hwoarang - appreciate the time you're taking! | 16:39 |
*** shardy has quit IRC | 16:40 | |
cloudnull | ++ | 16:40 |
*** macza has joined #openstack-ansible | 16:40 | |
cloudnull | appreciate it hwoarang! | 16:41 |
*** gyee has joined #openstack-ansible | 16:47 | |
pabelanger | q: about updating services (specifically venvs) with OSA. I can see, with nova you have a nova_venv_tag variable. If, I have set that to 18.0.0, that will install that version. However, if I rev that up to 18.0.1, I am assuming a new venv gets created with that version number | 16:50 |
pabelanger | if that is right, does the nova service keep running when the new venv is created? If so, I am guessing when you restart the services the old copy stops and new venv starts | 16:51 |
pabelanger | cloudnull: odyssey4me: mnaser: ^ | 16:51 |
cloudnull | yes the venvs are tagged and on upgrade you'll get a new one. the role will restart the service using the new venv at the completion of the upgrade using a handler. | 16:53 |
cloudnull | if the upgrade fails for any reason you should be able to roll the service back to the old venv | 16:53 |
pabelanger | cloudnull: okay, so I guess you've never had an issue with say systemd stopping the running service, using new venv | 16:53 |
cloudnull | nope, i've never had that issue. | 16:54 |
cloudnull | systemd should keep track of the pid and kill it on service restart. | 16:54 |
*** mathlin has joined #openstack-ansible | 16:56 | |
openstackgerrit | Merged openstack/openstack-ansible-lxc_container_create stable/rocky: Resolve btrfs backing store variable inconsistency https://review.openstack.org/629137 | 16:59 |
openstackgerrit | Merged openstack/openstack-ansible-lxc_container_create stable/queens: Resolve btrfs backing store variable inconsistency https://review.openstack.org/629138 | 16:59 |
jamesdenton | there are some nuances to that, for neutron anyway. jrosser and i observed some neutron agents still running on old venv post-upgrade. Not sure where that went | 16:59 |
pabelanger | cloudnull: okay cool, going to test it our for some local plays I am writing. thanks for info | 17:02 |
cloudnull | anytime! | 17:03 |
*** dcdamien has quit IRC | 17:05 | |
pabelanger | cloudnull: if running from stable/rocky, does the venv become venv/nova-stable/rocky ? | 17:08 |
pabelanger | or do you substring / | 17:08 |
*** cshen has joined #openstack-ansible | 17:11 | |
openstackgerrit | Merged openstack/openstack-ansible-os_keystone stable/rocky: Remove legacy policy.json file https://review.openstack.org/630289 | 17:16 |
*** cshen has quit IRC | 17:17 | |
*** DanyC has quit IRC | 17:17 | |
*** hamzaachi has joined #openstack-ansible | 17:18 | |
openstackgerrit | Merged openstack/openstack-ansible-galera_server stable/rocky: Tidy yum repository setup https://review.openstack.org/630140 | 17:18 |
*** DanyC has joined #openstack-ansible | 17:18 | |
*** stuartgr has quit IRC | 17:21 | |
*** mathlin has quit IRC | 17:22 | |
*** DanyC has quit IRC | 17:23 | |
openstackgerrit | Manuel Buil proposed openstack/openstack-ansible-os_neutron master: Provide support for ovs-sfc https://review.openstack.org/621249 | 17:23 |
*** fatdragon has joined #openstack-ansible | 17:28 | |
openstackgerrit | Merged openstack/openstack-ansible master: Spice console doesn't work on aarch64+kvm. https://review.openstack.org/626593 | 17:28 |
*** ostackz has joined #openstack-ansible | 17:31 | |
*** electrofelix has quit IRC | 17:31 | |
*** vicky84 has joined #openstack-ansible | 17:31 | |
ostackz | Anyone using domains in rocky? For me domains worked in queens but cannot login to domains in rocky | 17:32 |
*** hamzaachi_ has joined #openstack-ansible | 17:33 | |
*** lbragstad has quit IRC | 17:35 | |
*** hamzaachi has quit IRC | 17:36 | |
*** hamzaachi_ has quit IRC | 17:37 | |
*** tosky has quit IRC | 17:40 | |
cloudnull | pabelanger it should be XX.0.0-devYYY | 17:42 |
cloudnull | I think? | 17:43 |
jenglisch | i previously opened a bug https://bugs.launchpad.net/openstack-ansible/+bug/1782195 i'd like to fix properly, hence upstream | 17:43 |
openstack | Launchpad bug 1782195 in openstack-ansible "neutron l3 agent fails to spawn HA router" [High,In progress] | 17:43 |
jenglisch | the l3-agent invokes a custom python script in a subprocess https://github.com/openstack/neutron/blob/9ad2e05088400a57f5e1fe0246006b9e213f101f/neutron/agent/l3/ha_router.py#L368 | 17:43 |
jenglisch | but l3-agent does not include it's own venv in it's path as i can see | 17:44 |
jenglisch | cat /proc/17403/environ | 17:44 |
jenglisch | LANG=de_AT.UTF-8PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/binHOME=/var/lib/neutronLOGNAME=neutronUSER=neutronSHELL=/bin/false | 17:44 |
jenglisch | in my issue i symlinked the binary, i don't thin thats the proper solution | 17:44 |
jenglisch | i'd rather add /openstack/venvs/neutron-$VERSION/bin/ to the PATH in the systemd unit | 17:45 |
jenglisch | WDYT? | 17:45 |
cloudnull | that sounds reasonable | 17:47 |
jenglisch | futhermore the l3-agent tries to kill the process again aftermore, however even with (imo) a generous rootwrap.d it isn't able to kill it | 17:47 |
jenglisch | http://paste.openstack.org/show/oJFFypq14ttbEt3K8Nmb/ | 17:47 |
cloudnull | you should be able to add additional options to the system provided units under `/etc/systemd/system/<service_name>.d/` | 17:48 |
jenglisch | L90-94 got added by myself, i just saw afterwards that the python* kill thingy is already present for metadata anyway | 17:48 |
jenglisch | cloudnull: i know, but i'd like to provide an upstream fix | 17:48 |
jenglisch | or is this the prefered fix already? | 17:48 |
cloudnull | ah a fix into neutron specifically | 17:48 |
jenglisch | this issue should hit all users with l3 ha routers currently | 17:49 |
jenglisch | (in all releases from queens on) | 17:49 |
jenglisch | although i only tested it on queens, but the subprocess thingy is still in neutron-l3-agent master and i haven't found a (related) fix in openstack-ansible | 17:50 |
*** mathlin has joined #openstack-ansible | 17:51 | |
cloudnull | so is it a rootwarp command issue with the path being wrong? | 17:51 |
* cloudnull sorry may be being dense | 17:51 | |
openstackgerrit | Merged openstack/openstack-ansible master: Fixes empty metal_query https://review.openstack.org/629930 | 17:52 |
openstackgerrit | Merged openstack/openstack-ansible master: Make OVN track master branch https://review.openstack.org/629914 | 17:52 |
jenglisch | sorry for the confusion, those are actually two seperate bugs | 17:52 |
*** hwoarang has quit IRC | 17:52 | |
jenglisch | the first one is, that l3-agent isn't able to invoke neutron-keepalived-state-change at first, since it's not in the $PATH | 17:52 |
jenglisch | (it's located in the venv) | 17:53 |
jenglisch | the second one is: if the router gets deleted, neutron tries to kill it again, that doesn't work beacuse of rootwrap(?) | 17:53 |
jenglisch | i resolved the first one, initially, by symlinking the script from the venv env to /usr/local/bin/ | 17:54 |
jenglisch | neutron expects this script in the $PATH as far as i can see | 17:54 |
jenglisch | https://github.com/openstack/neutron/blob/master/neutron/agent/l3/ha_router.py#L366 | 17:54 |
cloudnull | ah ok. | 17:54 |
*** dcdamien has joined #openstack-ansible | 17:55 | |
cloudnull | so the path issue is something we'd need to fix by making sure its in the service unit we (OSA) creates and that the neutron_sudoers file has the correct path. | 17:55 |
cloudnull | the additional rootwrap conf should go into upstream neutron though we can override it for a time, until if goes upstream | 17:56 |
cloudnull | **it goes | 17:56 |
cloudnull | this is where we create the sudoers files https://github.com/openstack/openstack-ansible-os_neutron/blob/ef07cd02c5f469f7e5899109b132a93069463100/tasks/neutron_pre_install.yml#L113-L119 and this is where we'd need to make sure the path is included in the systemd unit file we create for neutron https://github.com/openstack/openstack-ansible-os_neutr | 17:57 |
cloudnull | on/blob/ee5f750859fd0bb458b99493f15ebab1612362eb/tasks/main.yml#L92-L123 | 17:57 |
cloudnull | I'm not sure the missing PATH issue is a specific upstream neutron problem, it sounds like its something we're just not feeding into the service correctly | 17:58 |
openstackgerrit | Merged openstack/openstack-ansible-os_heat stable/queens: Only implement policy.json if an override is configured https://review.openstack.org/629410 | 17:58 |
openstackgerrit | Merged openstack/openstack-ansible-os_heat stable/rocky: Only implement policy.json if an override is configured https://review.openstack.org/629409 | 17:58 |
*** hwoarang has joined #openstack-ansible | 17:59 | |
*** stuartgr has joined #openstack-ansible | 17:59 | |
openstackgerrit | Merged openstack/openstack-ansible-os_barbican stable/rocky: Only implement policy.json if an override is configured https://review.openstack.org/630199 | 18:00 |
jenglisch | cloudnull: the sudoers file is actually fine, since it accepts everything in the secure_path where the venv's bin directory is already listed | 18:01 |
jenglisch | i think it's an OSA problem, since it only affects venv installations imo | 18:05 |
jenglisch | is upstream neutron venv compatible ? | 18:05 |
jenglisch | i'd like to add 'Environment=PATH=${venv}:$PATH' into the systemd unit. it seems like i need to extend the OSA systemd_service for that | 18:06 |
cloudnull | yes neutron works in a venv just fine. at least it has for a few years now. | 18:07 |
openstackgerrit | Merged openstack/openstack-ansible-os_barbican stable/queens: Only implement policy.json if an override is configured https://review.openstack.org/630200 | 18:09 |
*** mathlin has quit IRC | 18:10 | |
jenglisch | hm, neutron spawns external processes in multiple modules, however it seems that this helper script is the only shell-out command which is shipped with neutron itself | 18:10 |
cloudnull | that entry into the systemd unit file should be able to be added by setting the init_config_overrides for the given service | 18:10 |
jenglisch | other process invokes includes radvd, keepalived and other software which is typically installed into $PATH | 18:10 |
cloudnull | however, i think it would be a good addition to extend the systemd_service role to add Environment options when defined | 18:11 |
*** mmercer has quit IRC | 18:23 | |
*** hamzaachi has joined #openstack-ansible | 18:27 | |
openstackgerrit | Jakob Englisch proposed openstack/ansible-role-systemd_service master: Add an option to configure a service environment https://review.openstack.org/630370 | 18:29 |
jenglisch | cloudnull: https://review.openstack.org/#/c/630370/2/templates/systemd-service.j2 like this? | 18:30 |
jenglisch | could be used like this http://paste.openstack.org/show/741834/ | 18:31 |
openstackgerrit | Jakob Englisch proposed openstack/ansible-role-systemd_service master: Add an option to configure a service environment https://review.openstack.org/630370 | 18:32 |
jenglisch | * https://review.openstack.org/#/c/630370/3/templates/systemd-service.j2 ; got a typo | 18:32 |
*** mathlin has joined #openstack-ansible | 18:34 | |
jrosser | jenglisch: interesting stuff - is it related to this? https://bugs.launchpad.net/openstack-ansible/+bug/1780733 | 18:38 |
openstack | Launchpad bug 1780733 in openstack-ansible "Neutron rootwrap error" [High,Triaged] - Assigned to David Wilde (david-wilde-rackspace) | 18:38 |
*** cshen has joined #openstack-ansible | 18:39 | |
openstackgerrit | Damian Cikowski (dcdamien) proposed openstack/openstack-ansible-os_designate stable/rocky: Set project that owns managed resources https://review.openstack.org/630371 | 18:41 |
jenglisch | probably, but this 'only' affects my second problem that rootwarp isn't able to kill the HA router helper script anymore | 18:41 |
jenglisch | the first problem is the invocation itself, that's missing in the mentioned log, unfortunately | 18:42 |
jenglisch | however your bug could be a subsequent fault of the first one | 18:42 |
jrosser | yeah, it felt very much in the same area | 18:43 |
*** cshen has quit IRC | 18:44 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/ansible-role-systemd_service master: Add the ability to set additional Environment settings https://review.openstack.org/630373 | 18:53 |
cloudnull | jenglisch ^ that should give us an interface to add environment options as needed | 18:53 |
openstackgerrit | Jakob Englisch proposed openstack/openstack-ansible-os_neutron master: Fix the subprocess invocation of neutron-l3-agent https://review.openstack.org/630374 | 18:59 |
jenglisch | ^ this would be the full fix of the first problem, depending on the systemd role addition | 18:59 |
*** cshen has joined #openstack-ansible | 19:00 | |
openstackgerrit | Jakob Englisch proposed openstack/ansible-role-systemd_service master: Add an option to configure a service environment https://review.openstack.org/630370 | 19:00 |
openstackgerrit | Jakob Englisch proposed openstack/ansible-role-systemd_service master: Add an option to configure a service environment https://review.openstack.org/630370 | 19:04 |
*** cshen has quit IRC | 19:06 | |
openstackgerrit | James Denton proposed openstack/openstack-ansible-ops master: Add mnaio_data_disk_suffix var to support NVMe partition naming https://review.openstack.org/630375 | 19:14 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/ansible-role-systemd_service master: Add the ability to set additional Environment settings https://review.openstack.org/630373 | 19:15 |
cloudnull | my bad, jenglisch. ill abandon my patch and build off of yours | 19:17 |
jenglisch | actually yours is better documented and adds env file aswell, so i can just depend on your's as well :) | 19:17 |
*** cshen has joined #openstack-ansible | 19:19 | |
jenglisch | is there a possibility to tell zuul to do another try, if just the dependency got updated? | 19:20 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/ansible-role-systemd_service master: Add docs and tests to the environment capabilities https://review.openstack.org/630376 | 19:24 |
cloudnull | I abandoned mine and depended on yours :) | 19:25 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/ansible-role-systemd_service master: Add docs and tests to the environment capabilities https://review.openstack.org/630376 | 19:26 |
openstackgerrit | James Denton proposed openstack/openstack-ansible-ops master: Add support for OVN in MNAIO deploy https://review.openstack.org/630377 | 19:27 |
*** Soopaman has joined #openstack-ansible | 19:31 | |
jenglisch | funfact: the only other executable which neutron expects (but not by default) in the path and ships itself is neutron-rootwrap which had already the full path added instead of the relvative one | 19:33 |
jenglisch | https://github.com/openstack/neutron/blob/7b850a9f6054ea640e262efc7fa1a843fd3c2b65/neutron/conf/agent/common.py#L81 | 19:33 |
jenglisch | https://github.com/openstack/openstack-ansible-os_neutron/blob/614e3bd1d6c61124410b1e5ea7f999b73a227bdb/templates/neutron.conf.j2#L245 | 19:33 |
jenglisch | but changing the relative path for neutron-keepalived-state-change to the full qualified path is quite hard, if the thing is hardcoded | 19:35 |
jenglisch | https://github.com/openstack/neutron/blob/9ad2e05088400a57f5e1fe0246006b9e213f101f/neutron/agent/l3/ha_router.py#L367 | 19:35 |
*** openstackstatus has quit IRC | 19:43 | |
*** openstackstatus has joined #openstack-ansible | 19:43 | |
*** ChanServ sets mode: +v openstackstatus | 19:43 | |
jenglisch | jrosser: i guess i analyzed your problem as well | 19:46 |
jenglisch | first of all, the fix i proposed (by adding the venv's bin to PATH) is required, since the KillFilter depends on PATH | 19:46 |
jenglisch | https://github.com/openstack/oslo.rootwrap/blob/99f6383e97f59c110211bdbc60894befc3fdc4e9/oslo_rootwrap/filters.py#L157 | 19:46 |
jenglisch | the funny thing is, you can define an exec_path in rootwrap.conf, but rootwrap decides to just use PATH | 19:47 |
jenglisch | the exec_path is only for the CommandFilter | 19:47 |
jenglisch | the second problem is, that the KillFilter is entirely missing in neutron upstream | 19:47 |
jenglisch | https://github.com/openstack/neutron/blob/master/etc/neutron/rootwrap.d/l3.filters#L59 | 19:47 |
jenglisch | but they're sending SIGTERM explicitly in the code https://github.com/openstack/neutron/blob/8db1a47fa8d4a245ea7163599a10b6699761de6d/neutron/agent/l3/ha_router.py#L394 | 19:48 |
mnaser | jenglisch: you need to look at differences, recently we started using a new system in openstack called privsep | 19:50 |
mnaser | which is a python native way of making calls instead of using rootwrap | 19:50 |
mnaser | also, that neutron keepalived thing, you're using centos right? | 19:50 |
mnaser | me and guilhermesp ran into it, i think he's going to submit a patch for that soon | 19:50 |
mnaser | always good to check what codebase you're looking at, so stable/rocky is the branch you wanna read | 19:51 |
mnaser | or whatever series you'r egoing for | 19:51 |
jenglisch | mnaser: yep, centos. currently queens, but as i checked privsep is just getting introduced, and rootwrap is still used for l3-agent on master | 19:56 |
*** DanyC has joined #openstack-ansible | 19:56 | |
*** DanyC has quit IRC | 20:00 | |
jenglisch | hm. actually in queens, it seems like extending rootwrap.d/l3.filters isn't necessary by accident | 20:01 |
jenglisch | only the PATH fix is needed | 20:02 |
jenglisch | they still have the python-yolo approach in there https://github.com/openstack/neutron/blob/stable/queens/etc/neutron/rootwrap.d/l3.filters#L26 | 20:02 |
jenglisch | and the full cmdline is '/openstack/venvs/neutron-17.0.6/bin/python /usr/local/bin/neutron-keepalived-state-change [...]' | 20:03 |
jenglisch | so this should be the fix already, mnaser - https://review.openstack.org/#/c/630374/1 | 20:04 |
jenglisch | i'd be glad if guilhermesp could do a review :) | 20:05 |
openstackgerrit | Jakob Englisch proposed openstack/openstack-ansible-os_neutron master: Fix the subprocess invocation of neutron-l3-agent https://review.openstack.org/630374 | 20:07 |
*** cshen has quit IRC | 20:08 | |
*** luksky has joined #openstack-ansible | 20:12 | |
*** openstack has joined #openstack-ansible | 20:18 | |
*** ChanServ sets mode: +o openstack | 20:18 | |
*** sreejithp has joined #openstack-ansible | 20:39 | |
*** sreejithp has quit IRC | 20:39 | |
*** sreejithp has joined #openstack-ansible | 20:41 | |
*** cshen has joined #openstack-ansible | 20:42 | |
jamesdenton | anyone here work with networking-vpp for Neutron? | 20:42 |
*** sreejithp has left #openstack-ansible | 20:46 | |
*** cshen has quit IRC | 20:46 | |
*** DanyC has joined #openstack-ansible | 20:49 | |
*** sreejithp has joined #openstack-ansible | 20:50 | |
cloudnull | ^ jrosser | 20:50 |
cloudnull | he was working on (looking at?) some FIDO things back in the day | 20:50 |
jrosser | well i keep looking and wishing it was easier to try | 20:50 |
* cloudnull ran FIDO on a nuc for a min | 20:51 | |
jrosser | imho it has great potential particularly for network nodes | 20:52 |
jrosser | but it is sad you have(had?) to go all-in with it and couldnt do a bit of mix/match | 20:52 |
jamesdenton | any interest in getting it in OSA for dev? | 20:52 |
cloudnull | https://i.stack.imgur.com/MNeE7.jpg | 20:53 |
jrosser | its been a while since i looked but iirc there were a number of approaches | 20:54 |
jrosser | you could run it 'native' with etcd acting as a shim between neutron and vpp | 20:54 |
jrosser | or you could go full SDN with opendaylight and so on and a shim between ODL and VPP | 20:54 |
*** Soopaman has quit IRC | 20:55 | |
jamesdenton | yeah i was just thinking the ML2 route.. native | 20:58 |
jrosser | i'm interested to see how that would go | 20:58 |
jrosser | it's properly innovative stuff underneath that has the potential for extreme performance, on a par with hardware routers | 20:59 |
jenglisch | i think we'll see a lot of change in the near future in routing/networking on linux and in software | 21:01 |
jenglisch | also eBPF and XDP is a very hot topic currently | 21:01 |
openstackgerrit | Merged openstack/ansible-role-systemd_service master: Add an option to configure a service environment https://review.openstack.org/630370 | 21:02 |
*** corvus is now known as thecount | 21:02 | |
*** thecount is now known as corvus | 21:02 | |
jenglisch | i think cumulus neutron is currently a better chance as ODL | 21:03 |
jenglisch | https://docs.cumulusnetworks.com/display/DOCS/OpenStack+Neutron+ML2+and+Cumulus+Linux | 21:03 |
openstackgerrit | Merged openstack/ansible-role-systemd_service master: Add docs and tests to the environment capabilities https://review.openstack.org/630376 | 21:03 |
jenglisch | the last time i checked ODL, i thought it would be faster and more stable if i implemented the stuff i needed myself | 21:05 |
jrosser | jenglisch: lots of options around for l2, but much less so for l3 | 21:07 |
jenglisch | indeed, at least as core router | 21:08 |
jenglisch | cumulus switches may do l3 as well, but only on edges i think (i had not yet the chance to test them in depth) | 21:09 |
jrosser | i mean l3 in openstack terms - no whitebox l2/l3 switch running cumulus is going to do the SNAT/DNAT you need | 21:10 |
jenglisch | https://docs.cumulusnetworks.com/display/DOCS/Routing 32k :/ | 21:10 |
jenglisch | no DNAT/SNAT needed for ipv6 :3 | 21:11 |
jrosser | stateful firewall, blah blah theres tons that a real router does that merchant switching silicon doenst | 21:11 |
jrosser | having said that there will be a new breed of whitebox router this year | 21:12 |
jrosser | as opposed to whitebox switch | 21:12 |
jenglisch | yep, XDP and eBPF is currently on a good road and they yet don't require to give your nic fully to DPDK | 21:14 |
jenglisch | https://people.netfilter.org/hawk/presentations/OpenSourceDays2017/XDP_DDoS_protecting_osd2017.pdf | 21:14 |
jenglisch | https://blog.cloudflare.com/l4drop-xdp-ebpf-based-ddos-mitigations/ | 21:14 |
jenglisch | ^ just the first two links i remembered and could google quite fast | 21:15 |
*** cshen has joined #openstack-ansible | 21:18 | |
jenglisch | [22:12] <jrosser> having said that there will be a new breed of whitebox router this year << can you name a decent one already, or are they still all WIP ? | 21:22 |
*** cshen has quit IRC | 21:23 | |
jrosser | nothing yet - but im told there will be silicon vendors selling routing chipsets this year rather than those being proprietary to single manufacturers | 21:25 |
*** radeks_ has quit IRC | 21:41 | |
*** radeks_ has joined #openstack-ansible | 21:41 | |
*** tosky has joined #openstack-ansible | 21:42 | |
*** hamzaachi has quit IRC | 21:45 | |
*** strattao has quit IRC | 21:50 | |
jenglisch | hm. https://review.openstack.org/630374 i guess zuul marked this one as failed since the ODL xenial build timed out ; is there a re-run functionallity? | 21:50 |
*** radeks_ has quit IRC | 22:04 | |
mnaser | jenglisch: yes, you wanna comment with the words 'recheck' :) | 22:07 |
*** hamzaachi has joined #openstack-ansible | 22:10 | |
*** vollman has quit IRC | 22:13 | |
*** mmercer has joined #openstack-ansible | 22:16 | |
*** hamzaachi has quit IRC | 22:17 | |
*** mcela has quit IRC | 22:19 | |
*** noonedeadpunk has quit IRC | 22:26 | |
*** macza has quit IRC | 22:28 | |
*** strobelight has quit IRC | 22:31 | |
*** dcdamien has quit IRC | 22:32 | |
*** markvoelker has quit IRC | 22:32 | |
*** strobelight has joined #openstack-ansible | 22:33 | |
*** mathlin has quit IRC | 22:41 | |
*** DanyC has quit IRC | 22:55 | |
*** mathlin has joined #openstack-ansible | 23:13 | |
*** rjgibson has quit IRC | 23:17 | |
*** cshen has joined #openstack-ansible | 23:19 | |
*** cshen has quit IRC | 23:24 | |
*** hwoarang has quit IRC | 23:46 | |
*** mathlin has quit IRC | 23:47 | |
*** hwoarang has joined #openstack-ansible | 23:47 | |
*** pabelanger has quit IRC | 23:58 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!