*** sshnaidm has quit IRC | 00:04 | |
*** sshnaidm has joined #openstack-ansible | 00:05 | |
*** jamesdenton has quit IRC | 00:10 | |
*** jamesden_ has joined #openstack-ansible | 00:10 | |
*** sep has quit IRC | 02:04 | |
*** sshnaidm has quit IRC | 02:19 | |
*** sep has joined #openstack-ansible | 02:24 | |
*** sshnaidm has joined #openstack-ansible | 02:25 | |
*** cshen has quit IRC | 02:43 | |
*** mcarden has quit IRC | 03:38 | |
*** raukadah is now known as chandankumar | 04:06 | |
*** evrardjp has quit IRC | 05:33 | |
*** evrardjp has joined #openstack-ansible | 05:33 | |
*** pto has joined #openstack-ansible | 06:22 | |
*** pto has joined #openstack-ansible | 06:23 | |
*** yourstruly has joined #openstack-ansible | 06:23 | |
yourstruly | hello | 06:23 |
---|---|---|
*** yourstruly has quit IRC | 06:24 | |
*** YoursTruly has joined #openstack-ansible | 06:27 | |
YoursTruly | hello | 06:29 |
*** miloa has joined #openstack-ansible | 07:11 | |
*** rpittau|afk is now known as rpittau | 07:26 | |
YoursTruly | hmm | 07:31 |
noonedeadpunk | o/ | 07:59 |
*** SiavashSardari has joined #openstack-ansible | 08:01 | |
jrosser | morning | 08:05 |
*** cshen has joined #openstack-ansible | 08:10 | |
*** jbadiapa has joined #openstack-ansible | 08:27 | |
*** andrewbonney has joined #openstack-ansible | 08:30 | |
*** tosky has joined #openstack-ansible | 08:37 | |
*** yann-kaelig has joined #openstack-ansible | 08:49 | |
admin0 | morning | 09:36 |
admin0 | osa daily -- searching for people who have successfully deployed magnum/k8 | 10:12 |
jrosser | admin0: that would be guilhermesp, and as far as I know the important thing (a starting point for the cluster template) has already been shared | 10:14 |
jrosser | but magnum is hard, you've just got to systematically work through the logs in the magnum containers, then in the cloud-init and heat container agent logs in the VM it deploys | 10:14 |
*** gshippey has joined #openstack-ansible | 10:26 | |
admin0 | yes . which is why i feel its time we should have at least one working osa config for k8 | 10:42 |
kleini | admin0: I have deployed at least K8s with Magnum in Pike version correctly. But I think, a lot changed between P and U | 10:49 |
admin0 | if you have some free time, even in an aio .. requesting you to give it a 2nd try :) | 11:01 |
admin0 | what is the difference between member and _member_ ? | 11:31 |
admin0 | in the openstack role | 11:31 |
admin0 | and what is generally used | 11:31 |
admin0 | or are they the same ? | 11:31 |
*** fridtjof[m] has quit IRC | 11:34 | |
*** ioni has quit IRC | 11:35 | |
*** masterpe has quit IRC | 11:35 | |
*** csmart has quit IRC | 11:35 | |
SiavashSardari | admin0 I'm not sure but I think _member_ was part of old roles in oslo policy. I'm updating my policies on all services and _member_ is not in the codes | 11:37 |
admin0 | so better to use member and not "_underscore member underscore_ " | 11:38 |
*** pto has quit IRC | 11:38 | |
SiavashSardari | I'm thinking about removing that role, but I need to make sure nothing will break | 11:38 |
admin0 | my chat app (hexchat on ubuntu) does not show _ correctly | 11:38 |
admin0 | show "_underscore_" | 11:38 |
SiavashSardari | np | 11:39 |
*** pto has joined #openstack-ansible | 11:39 | |
SiavashSardari | yeah generally I recommend using member without underscore | 11:40 |
SiavashSardari | admin0 did you try to use new policies for services? | 11:41 |
admin0 | SiavashSardari, i just use default osa :D | 11:43 |
admin0 | and the services | 11:43 |
admin0 | " try to use new policies for services?" -- not had a chance to look or even know them | 11:43 |
SiavashSardari | admin0 oh OK. | 11:44 |
*** masterpe has joined #openstack-ansible | 11:44 | |
admin0 | i think for new tags, we can let go of the _member_ role ( just redundant/confusing ) and put that in the documentation | 11:44 |
admin0 | underscore_member_underscore role* | 11:45 |
SiavashSardari | this is a good idea, I checked and there is no role assignment in default osa with _member_ role. so I don't think this change will break anything. just to be sure, I'd like to hear if anyone else has any comment on this matter | 11:50 |
SiavashSardari | so while we are kinda on the topic let me ask my question too. I am working on updating our policy files for all openstack services, the problem is service users have project scope admin roles, some of services like neutron needs to have more privilages policies for example to update nova on port state change. my workaround for that is I added | 11:52 |
SiavashSardari | service project_id to system_scope policies. my problem with my workaround is I have to run openstack_openrc role on almost all of my containers. | 11:52 |
SiavashSardari | I would appreciate if anyone can help me with this. and also I think we need to eventually add this functionality to osa | 11:54 |
admin0 | "problem is service users have project scope admin roles, some of services like neutron needs to have more privilages policies for example to update nova on port state chang" -- why is this an issue .. except ansible and the cluster working internally, no one ever sees the passwords ? | 12:02 |
*** ioni has joined #openstack-ansible | 12:09 | |
*** fridtjof[m] has joined #openstack-ansible | 12:09 | |
*** csmart has joined #openstack-ansible | 12:09 | |
guilhermesp | it looks like magnum is still a big challenge admin0 ? :) | 12:26 |
guilhermesp | yes I got magnum successfully working with most of the k8s cool features under ussuri | 12:26 |
*** ianychoi_ has joined #openstack-ansible | 12:35 | |
*** ianychoi has quit IRC | 12:36 | |
*** rfolco has joined #openstack-ansible | 12:37 | |
SiavashSardari | admin0, that is an issue because the new policies enforce some restrictions for service users, maybe I should talk to oslo.policy guys. anyways, right now there is no leaking of credentials, and like you said it is internally, I just thought maybe there is a better way of handling this, running openstack_openrc role on all containers seems a bit | 12:51 |
SiavashSardari | redundant. | 12:51 |
*** dpaclt has joined #openstack-ansible | 13:02 | |
*** rfolco is now known as rfolco|ruck | 13:09 | |
*** simondodsley has quit IRC | 13:42 | |
*** simondodsley has joined #openstack-ansible | 13:42 | |
*** pto_ has joined #openstack-ansible | 13:45 | |
*** pto_ has quit IRC | 13:46 | |
*** pto_ has joined #openstack-ansible | 13:46 | |
*** pto has quit IRC | 13:49 | |
admin0 | guilhermesp, please share the exact tag you are using and the docs/command line .. that way, we can try to replicate | 13:55 |
admin0 | i am trying, ThiagoCMC is trying .. djhankb is trying | 13:56 |
guilhermesp | admin0: ThiagoCMC djhankb this should be enough... https://gist.github.com/guilhermesteinmuller/c23722dcabe5e6175fa722b7c278113a if you face issues and have access to the master, please share the whole heat-config log | 14:03 |
*** cshen has quit IRC | 14:15 | |
*** chandankumar is now known as raukadah | 14:16 | |
openstackgerrit | Rafael Folco proposed openstack/openstack-ansible-os_tempest stable/train: Switch tripleo job to content provider https://review.opendev.org/c/openstack/openstack-ansible-os_tempest/+/761021 | 14:30 |
openstackgerrit | Merged openstack/openstack-ansible stable/ussuri: Fix octavia tempest tests https://review.opendev.org/c/openstack/openstack-ansible/+/763048 | 14:34 |
openstackgerrit | Rafael Folco proposed openstack/openstack-ansible-os_tempest stable/train: Switch tripleo job to content provider https://review.opendev.org/c/openstack/openstack-ansible-os_tempest/+/761021 | 14:36 |
admin0 | guilhermesp, thank you .. i will start in the evening and post success/failure/logs :) | 14:39 |
admin0 | you mentioned the branch/tag for magnum: fe35af8ef5d9e65a4074aa3ba3ed3116b7322415 .. is that for info.. or we need to override and use this specific one | 14:40 |
admin0 | if this is not what i get for any reasons, how to tell osa i need this specific one ? | 14:40 |
openstackgerrit | Rafael Folco proposed openstack/openstack-ansible-os_tempest stable/ussuri: Switch tripleo jobs to content provider https://review.opendev.org/c/openstack/openstack-ansible-os_tempest/+/761019 | 14:46 |
*** NewJorg has quit IRC | 14:53 | |
*** NewJorg has joined #openstack-ansible | 14:59 | |
*** frickler is now known as frickler_pto | 15:02 | |
*** SiavashSardari has quit IRC | 15:02 | |
*** mathlin has joined #openstack-ansible | 15:11 | |
ThiagoCMC | guilhermesp, I'm suprised about how big is your line to start the Kubernetes cluster with Magnum... | 15:12 |
ThiagoCMC | Any idea why something simpler fails, like: `openstack coe cluster template create k8s-cluster-template --image fedora-coreos-32 --keypair testkey --external-network public --dns-nameserver 8.8.8.8 --flavor ds1G --master-flavor ds2G --docker-volume-size 5 --network-driver flannel --docker-storage-driver overlay2 --coe kubernetes` ? | 15:13 |
ThiagoCMC | I got it from: https://docs.openstack.org/magnum/latest/contributor/quickstart.html (since the Ussuri branch still points to old Fedora Atomic). | 15:13 |
*** miloa has quit IRC | 15:29 | |
*** YoursTruly has quit IRC | 15:35 | |
*** cshen has joined #openstack-ansible | 15:37 | |
jrosser | admin0: quite often you need to be running a very recent version of magnum (i.e newer than your OSA release) to make it work | 15:46 |
admin0 | how do i get/set it jrosser ? | 15:47 |
jrosser | stuff seems to change here much quicker than the openstack release lifcycle, which is why it's basically impossible to ship a "known working" config with OSA | 15:47 |
jrosser | magnum_git_install_branch is a variable to put in user_variables | 15:48 |
jrosser | it specifies a hash of the magmin git repo to install in the magnum service containers | 15:48 |
admin0 | guilhermesp, in your instructions, the download is qcow2, but the add command is using raw | 15:52 |
admin0 | is that an intentional easter egg :) | 15:53 |
*** macz_ has joined #openstack-ansible | 16:03 | |
jrosser | noonedeadpunk: any release blocking patches need looking at before my week is over? | 16:04 |
noonedeadpunk | that one would be awesome to merge https://review.opendev.org/c/openstack/openstack-ansible/+/763908 | 16:06 |
jrosser | new gerrit is taking some getting used to | 16:08 |
noonedeadpunk | it does.... | 16:28 |
noonedeadpunk | I tried not to it it this week :( | 16:28 |
noonedeadpunk | *not to touch | 16:28 |
admin0 | looks liek a tubelight theme :) .. not sure if such exist | 16:28 |
admin0 | in AIO .. when you run the tests, do you only create volumes or mount them also | 16:30 |
noonedeadpunk | we're testing VM creation and if it is operational | 16:31 |
noonedeadpunk | eventaully we run tempest basic scenario | 16:31 |
openstackgerrit | Jonathan Rosser proposed openstack/openstack-ansible-os_swift master: Stop to use the __future__ module. https://review.opendev.org/c/openstack/openstack-ansible-os_swift/+/732883 | 16:32 |
*** YoursTruly has joined #openstack-ansible | 16:43 | |
YoursTruly | hello | 16:43 |
YoursTruly | could I small hint how to install openstack-ansible on my single node hp580 g7 with centos7 and 4 x 1GB, 2 x 10GB NICs? | 16:45 |
noonedeadpunk | YoursTruly: I think you need aio in case it's single node | 16:49 |
noonedeadpunk | you should look at https://docs.openstack.org/openstack-ansible/latest/user/aio/quickstart.html | 16:49 |
noonedeadpunk | but ussuri is the latest release where we have support of centos 7 | 16:50 |
YoursTruly | can I have br-mgmt on private network or it has to be internet facing one? | 16:50 |
noonedeadpunk | it's designed to be private network | 16:50 |
jrosser | YoursTruly: the AIO makes all the choices for you and gives you something that 'just works', but it's not a production cloud | 16:50 |
noonedeadpunk | well yes^ | 16:51 |
jrosser | i would highly recommend having a play with the AIO to familiarise yourself with how everything is plumbed together | 16:51 |
jrosser | then re-do it if necessary for something more real | 16:51 |
YoursTruly | I have 2 other nodes waiting in the line to add, so AIO is death trap :D | 16:51 |
noonedeadpunk | and, you can deploy basic openstack on it just by clonning repo and running ./scripts/gate-check-commit.sh | 16:51 |
jrosser | everyone says that they won't do AIO because they want to end up with something better | 16:51 |
YoursTruly | will check that ./scripts/gate-check-commit.sh | 16:51 |
noonedeadpunk | well not really as you can expand it | 16:52 |
noonedeadpunk | gate-check-commit.sh will deploy aio for you as well | 16:52 |
jrosser | IMHO AIO will get you to your destination quicker even if you throw it away after learning | 16:52 |
YoursTruly | hmm I was basing my config on aio | 16:52 |
noonedeadpunk | you casn provide services that need to be deployed with positional argiments, like ./scripts/gate-check-commit.sh aio_heat_ceph | 16:53 |
YoursTruly | all was going smothly but some nodes could not connect internet | 16:53 |
jrosser | also be aware that centos-7 is also a dead end | 16:53 |
jrosser | ussuri is the last release that it is possible to support | 16:53 |
YoursTruly | what about train? | 16:53 |
noonedeadpunk | it goes before ussri so it does support it | 16:53 |
YoursTruly | oh nice, other distributions only support up to train :D | 16:54 |
YoursTruly | my hardware will not go withy centos8 | 16:55 |
YoursTruly | i tried :( | 16:55 |
jrosser | OSA deploys from source code so we are not limited by the packages produced by other parties | 16:55 |
jrosser | so long as the python code works and the required versions of libvirt and stuff are avaialble, things are OK | 16:55 |
*** jbadiapa has quit IRC | 16:56 | |
YoursTruly | hmm I make some ansible playbooks to configure networking on my centos7 | 16:58 |
YoursTruly | would that be fine for bridges? | 16:58 |
noonedeadpunk | well 8gb of ram is not really sufficient indeed | 16:58 |
YoursTruly | - interface: br-host # 0 => bond0 address: 192.168.8.20 gateway: 192.168.8.1 type: br role: node000 master controller metric: 0 defroute: yes - interface: br-mgmt # 0 => bond1 address: 172.29.236.20 gateway: 172.29.236.1 type: br role: management metric: | 16:58 |
YoursTruly | 200 defroute: yes - interface: br-vxlan # 0 => bond2 address: 172.29.240.20 type: br role: vxlan # - interface: br-vlan # 0 => bond2 type: br-unused role: vlan # - interface: br-storage # 0 => bond3 type: br-unused role: storage # | 16:58 |
YoursTruly | damn | 16:58 |
noonedeadpunk | -> paste.openstack.org | 16:58 |
*** mmethot_ has quit IRC | 17:06 | |
YoursTruly | ok I have made config for my networking | 17:11 |
YoursTruly | http://paste.openstack.org/show/800469/ | 17:11 |
*** yann-kaelig has quit IRC | 17:11 | |
YoursTruly | and based on that put that openstack_user_config.yml | 17:12 |
YoursTruly | http://paste.openstack.org/show/800470/ | 17:12 |
YoursTruly | could You look at it? | 17:15 |
*** dasp_ has quit IRC | 17:16 | |
*** tosky has quit IRC | 17:17 | |
YoursTruly | so basically I have networking like http://paste.openstack.org/show/800471/ | 17:22 |
admin0 | guilhermesp, it did not even went to the cluster template ( heat stack) step.. just died in internal:error :) | 17:24 |
admin0 | ThiagoCMC, yours working yet ? | 17:24 |
guilhermesp | sorry admin0 regading the raw, is becasue our backend being ceph, so raw | 17:26 |
admin0 | that i figured | 17:26 |
*** dasp has joined #openstack-ansible | 17:26 | |
guilhermesp | admin0: logs from magnum-api/conductor? | 17:27 |
guilhermesp | ThiagoCMC: probably missing some labels :) as jrosser has been saying too, magnum is a matter of getting the right combination of labels depending on the version you're running :) | 17:28 |
*** YoursTruly has quit IRC | 17:30 | |
admin0 | i am reconfigung it with the tag you mentioned | 17:34 |
guilhermesp | yes. Add it in your user_variables and re-run os-magnum playbooks | 17:35 |
ThiagoCMC | Right, I see... This sounds more complicated than advertised... lol | 17:38 |
guilhermesp | which errors in specific are you seeing ThiagoCMC ? | 17:38 |
guilhermesp | yeah unfortunately docs are not so up-to-date | 17:39 |
guilhermesp | that's why i say magnum is an adventure | 17:39 |
guilhermesp | but totally doable | 17:39 |
ThiagoCMC | I really wanna do it! Let me try again and collect some some... | 17:40 |
ThiagoCMC | some logs... =P | 17:40 |
*** rfolco|ruck has quit IRC | 17:40 | |
openstackgerrit | Merged openstack/openstack-ansible-os_adjutant master: Make role fit to the OSA standards https://review.opendev.org/c/openstack/openstack-ansible-os_adjutant/+/756313 | 17:41 |
ThiagoCMC | guilhermesp, first command worked: `openstack coe cluster template create k8s-ultra-cluster --image fedora-coreos-32 --keypair default --external-network public --dns-nameserver 1.1.1.1 --master-flavor m1.small --flavor r1.large --docker-volume-size 8 --network-driver flannel --docker-storage-driver overlay2 --coe kubernetes` | 17:42 |
*** YoursTruly has joined #openstack-ansible | 17:44 | |
ThiagoCMC | Then, `openstack coe cluster create k8s-test --cluster-template k8s-ultra-cluster --node-count 1` was accepted. | 17:47 |
ThiagoCMC | But, by default, it has to copy the fedora-coreos-32 from Glance (Ceph) to the Compute Node /var/lib/, since I'm not using Ceph `vms` pool by default, it takes time here... That *might* be a problem and it times out, let's see. | 17:48 |
YoursTruly | hello guys | 17:53 |
YoursTruly | could you gimme hint about openstack-ansible networking setup | 17:53 |
YoursTruly | http://paste.openstack.org/show/800471/ | 17:53 |
YoursTruly | will that work? | 17:53 |
YoursTruly | nothig long in there | 17:54 |
YoursTruly | so basically I have networking like: br-host (internet, 192.168.8.20) -> bond0 -> nic0, br-mgmt (private, 172.29.236.20) -> bond1 -> nic1, br-vxlan (private, 172.29.240.20) -> bond2.10, -> bond2br-vlan (private, manual) -> bond2.20, -> bond2br-vlan (private, manual) -> bond2 | 17:54 |
YoursTruly | (192.168.8.22) -> nic2, nic3, br-storage (private 10GB, manual) -> bond4 -> sfp0, sfp1 | 17:54 |
admin0 | do i have to nuke the repo containers to have it redownload the magnum of that specific version ? | 17:54 |
YoursTruly | so the thing is I have 4 x 1GB nics named: net0, net1, net2, net3; 2 x 10GB nics named sfp0, sfp1 - kinda have to setup bridges on them | 17:56 |
admin0 | YoursTruly, why is your br-vlan that complex | 17:56 |
admin0 | others look ok | 17:56 |
admin0 | bridge setup is straightforward | 17:56 |
admin0 | netplan currently ( if on ubuntu) | 17:56 |
admin0 | i would do the br-storage and br-vxlan on the 10g , would create 2 more bonds on net0 and net2 for br-mgmt and net1 and net3 for br-vlan | 17:57 |
admin0 | should be enough to get going .. where east-west and storage is on the 10g | 17:57 |
admin0 | and mgmt and north-south on the 2g | 17:57 |
YoursTruly | ok thanks, I was following https://docs.openstack.org/openstack-ansible/latest/user/network-arch/example.html | 17:58 |
YoursTruly | and I have centos7 xD | 17:59 |
YoursTruly | hmm so what about this config with two br-vlan | 17:59 |
YoursTruly | can I skip that? | 17:59 |
*** andrewbonney has quit IRC | 17:59 | |
YoursTruly | I mean would be nice to have flat network too | 18:00 |
admin0 | dunno why .. but i always struggled with flat network .. 8 years of using osa .. zero flat network | 18:01 |
admin0 | step1. create the bridges in centos .. do brctl show and paste again | 18:01 |
admin0 | you need to have only 1 of each bridge | 18:01 |
YoursTruly | openswitch bridges will work fine? | 18:03 |
ThiagoCMC | admin0, guilhermesp, the k8s master node came up but, the node didn't. It still shows CREATE_IN_PROGRESS though but, I'm not seeing Heat trying to launch the node anywhere. | 18:03 |
YoursTruly | or have to struggle with that https://www.openstackfaq.com/openstack-ansible-with-openvswitch/ | 18:03 |
admin0 | YoursTruly, i am working on a new set of configs for the site | 18:04 |
admin0 | forget ovs for a moment | 18:04 |
admin0 | use bridges | 18:04 |
admin0 | basically for osa, you need 4 bridges .. it can be 4 interfaces, 40 or a single interface and vlan tags | 18:04 |
guilhermesp | ok ThiagoCMC so "node came up" means you have a master active and running? | 18:05 |
admin0 | all you need is 4 bridges .. so in your case, you can forget the bonds and everything for a bit and just use 4 interfaces and map them to 4 bridges | 18:05 |
admin0 | what i have observed guilhermesp ThiagoCMC is that the master comes up, does nothing when logged in, but the stack shows master always in creation process | 18:05 |
guilhermesp | are you able to ssh into master? | 18:06 |
ThiagoCMC | guilhermesp, yes, the master is up and running but, no "node". | 18:06 |
admin0 | ThiagoCMC, does the heat template mark the master node as DONE .. or is it still on creation process ? | 18:06 |
guilhermesp | ok i see, you mean k8s node, ok. That means heat-config is stuck at some point | 18:06 |
YoursTruly | ok :D how do I assign IP when my external router gateway is 192.168.8.1, and my host is node000 | 18:06 |
YoursTruly | then br-mgmt will be 192.168.8.21? | 18:07 |
guilhermesp | nexxt step is: login in the master, look what is going on inside /var/log/heat-config | 18:07 |
admin0 | YoursTruly, use the IPs in the document .. for br-mgmt, br-vxlan and br-storage | 18:07 |
guilhermesp | or check the status of heat-container-agent | 18:07 |
admin0 | as they are un-routed networks | 18:07 |
admin0 | but for br-mgmt, you can use any routable ip range that you can ssh into | 18:07 |
admin0 | or you can use another ethernet to have the ips you need to be able to ssh in | 18:07 |
ThiagoCMC | guilhermesp, the "master" doesn't have the "default" ssh key, is there a default user/pass? lol | 18:08 |
YoursTruly | ok, so If my node000 has nic0 with 192.168.8.20, then br-mgmt -> nic0? | 18:08 |
admin0 | in most servers, where you have 1G port and 4x 10g port, the 1G will be for ssh,internet connectivity etc .. while the 4 ports could be on a single or multiple bond or separate and are part of br-mgmt br-etc | 18:08 |
guilhermesp | i dont think so ThiagoCMC keys are injected into ignition | 18:08 |
admin0 | YoursTruly, yes | 18:09 |
admin0 | you have to add nic0 to be on br-mgmt and set the same IP there | 18:09 |
ThiagoCMC | The key pair is empty | 18:09 |
ThiagoCMC | at Horizon display | 18:09 |
admin0 | YoursTruly, you alread have br-host which is the ssh ip right | 18:10 |
admin0 | leave it like that | 18:10 |
guilhermesp | ideally, create you cluster with your keys and ssh into master. Otherwise, you can try to find logs in heat service. But for me, faster debugging happens when we are able to connect to master and see how heat-config is doing what it needs to do :) | 18:10 |
admin0 | create the 4 extra bridges on the remaining nics | 18:10 |
YoursTruly | ok thanks :D | 18:10 |
admin0 | guilhermesp, mine scripts are almost done with the rebuild | 18:10 |
admin0 | then i can also get on and paste logs | 18:10 |
YoursTruly | then what about this two vlan interfaces | 18:15 |
YoursTruly | - network: container_bridge: "br-vlan" container_interface: "eth12" host_bind_override: "eth12" | 18:15 |
YoursTruly | what put in place of host_bind_override? | 18:15 |
YoursTruly | if I do 1) br-vlan -> bondX -> nicX + nicY, then 2) br-vlan -> ? | 18:20 |
YoursTruly | is this 2) even needed? | 18:21 |
admin0 | YoursTruly, first goal is to get the bonds up | 18:23 |
admin0 | and not look into the configs | 18:23 |
admin0 | forget that you have osa configs or the yaml files | 18:23 |
admin0 | that is not the concern here | 18:23 |
admin0 | first get the bonds and bridges up | 18:23 |
admin0 | when its up then do a brctl and show | 18:23 |
admin0 | you don't touch the configs at all.. they are like that for a reason | 18:24 |
admin0 | you have one network card, or 4 or 10 .. the configs remain the same and it not changed .. | 18:24 |
admin0 | so first goal for you is on all your servers, create the bridges and bonds | 18:24 |
admin0 | or vlan or how you want the servers to talk to each other | 18:25 |
YoursTruly | ok thank You very much, not its somehow more clear :D | 18:26 |
ThiagoCMC | guilhermesp, cool, I could ssh into the "master"! The username is "core". | 18:30 |
ThiagoCMC | There is no "/var/log/heat-config" within it | 18:31 |
ThiagoCMC | I just got more hardware, gonna try again later, without bottleneck lol | 18:31 |
openstackgerrit | Merged openstack/openstack-ansible stable/ussuri: Add magnum tempest URL https://review.opendev.org/c/openstack/openstack-ansible/+/763908 | 18:34 |
guilhermesp | oh yeah, forgot to mention that the df username is core :) | 18:37 |
guilhermesp | so how about | 18:37 |
guilhermesp | systemctl status heat-container-agent | 18:38 |
admin0 | is boot-volume-type required ? | 18:47 |
admin0 | it just says create failed .. internal error .. without even creating a heat stack | 18:47 |
admin0 | doing a pastebin | 18:47 |
admin0 | guilhermesp, this first step is due to ERROR magnum.drivers.heat.k8s_fedora_template_def [req-d0c4c196-de3e-44e5-afc3-ec150fd6c264 - - - - -] Failed to load default keystone auth policy: FileNotFoundError: [Errno 2] No such file or directory: '/etc/magnum/keystone_auth_default_policy.json' | 18:50 |
admin0 | if osa supples the role, should it also not create the policy file ? | 18:50 |
admin0 | i mean all other projects work out of the box | 18:51 |
openstackgerrit | Merged openstack/openstack-ansible master: Bump SHAs for master https://review.opendev.org/c/openstack/openstack-ansible/+/762762 | 18:52 |
admin0 | there is only policy.json .. no file name keystone_auth_policy.json | 18:53 |
admin0 | ThiagoCMC, you got keystone_auth_policy.json insinde the /etc/magnum ? | 18:53 |
admin0 | YoursTruly, done ? are the bridges created ? ready for next step ? | 18:54 |
*** sep has quit IRC | 18:57 | |
admin0 | guilhermesp, can you share your keystone_auth_policy.json that is inside /etc/magnum ? | 18:57 |
*** sep has joined #openstack-ansible | 18:58 | |
jrosser | admin0: the OSA auth policy was only recently added https://github.com/openstack/openstack-ansible-os_magnum/commit/200dcd89aaba6b2b3e78a16b7f45f18af34408a8 | 19:05 |
*** mmethot has joined #openstack-ansible | 19:07 | |
ThiagoCMC | admin0, nop... I'm installing new bond channels in my cloud, there was a bottleneck hehe | 19:23 |
ThiagoCMC | gonna try again in about 3 hours, I also got a job interview, wish me luck! :-P | 19:24 |
admin0 | best of luck | 19:27 |
admin0 | log file: https://gist.github.com/a1git/da364eca1793c7e13a82a58a2fff2c46 | 19:56 |
*** cshen has quit IRC | 19:59 | |
admin0 | jrosser, thanks .. | 20:10 |
*** rfolco has joined #openstack-ansible | 20:10 | |
*** cshen has joined #openstack-ansible | 20:10 | |
*** sshnaidm has quit IRC | 20:41 | |
*** gshippey has quit IRC | 20:44 | |
*** rpittau is now known as rpittau|afk | 20:45 | |
*** tosky has joined #openstack-ansible | 21:09 | |
*** cshen has quit IRC | 21:37 | |
*** cshen has joined #openstack-ansible | 22:04 | |
*** YoursTruly has quit IRC | 22:27 | |
*** sshnaidm has joined #openstack-ansible | 23:00 | |
*** sshnaidm is now known as sshnaidm|off | 23:01 | |
*** rfolco has quit IRC | 23:32 | |
*** rfolco has joined #openstack-ansible | 23:32 | |
*** YoursTruly has joined #openstack-ansible | 23:42 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!