*** sdake has quit IRC | 00:03 | |
*** ekhugen has quit IRC | 00:09 | |
*** ekhugen has joined #openstack-containers | 00:17 | |
*** thomasem has quit IRC | 00:23 | |
*** thomasem has joined #openstack-containers | 00:25 | |
*** thomasem_ has joined #openstack-containers | 00:27 | |
*** thomasem_ has quit IRC | 00:27 | |
*** jay-lau-513 has quit IRC | 00:30 | |
*** vilobhmm1 has joined #openstack-containers | 00:30 | |
*** vilobhmm11 has joined #openstack-containers | 00:36 | |
*** thomasem has quit IRC | 00:38 | |
*** vilobhmm1 has quit IRC | 00:38 | |
*** thomasem has joined #openstack-containers | 00:38 | |
*** adrian_otto has quit IRC | 00:42 | |
*** daneyon_ has quit IRC | 00:55 | |
*** EricGonczer_ has quit IRC | 01:01 | |
*** vilobhmm11 has quit IRC | 01:04 | |
*** suro-patz has quit IRC | 01:21 | |
*** Marga_ has quit IRC | 01:23 | |
*** EricGonczer_ has joined #openstack-containers | 01:25 | |
*** EricGonc_ has joined #openstack-containers | 01:26 | |
*** EricGonczer_ has quit IRC | 01:30 | |
*** kebray has joined #openstack-containers | 01:31 | |
*** kebray has quit IRC | 01:32 | |
*** jay-lau-513 has joined #openstack-containers | 01:35 | |
*** EricGonczer_ has joined #openstack-containers | 01:40 | |
*** rlrevell has quit IRC | 01:40 | |
*** erkules_ has joined #openstack-containers | 01:40 | |
*** EricGonc_ has quit IRC | 01:42 | |
*** erkules has quit IRC | 01:43 | |
*** kebray has joined #openstack-containers | 01:51 | |
*** unicell has quit IRC | 01:54 | |
*** EricGonczer_ has quit IRC | 02:00 | |
*** kebray has quit IRC | 02:01 | |
*** kebray has joined #openstack-containers | 02:02 | |
*** julim has joined #openstack-containers | 02:03 | |
*** dboik has joined #openstack-containers | 02:07 | |
*** dboik_ has joined #openstack-containers | 02:09 | |
*** achanda has quit IRC | 02:11 | |
*** dboik has quit IRC | 02:11 | |
*** rlrevell has joined #openstack-containers | 02:16 | |
*** rlrevell has quit IRC | 02:37 | |
*** Kennan2 has joined #openstack-containers | 02:49 | |
*** Kennan has quit IRC | 02:50 | |
*** coolsvap|afk is now known as coolsvap | 03:23 | |
*** dims_ has quit IRC | 03:23 | |
*** kebray has quit IRC | 03:35 | |
*** chuenlye has joined #openstack-containers | 03:38 | |
*** Kennan has joined #openstack-containers | 03:39 | |
*** rongze has joined #openstack-containers | 03:39 | |
*** Kennan2 has quit IRC | 03:40 | |
*** Kennan has quit IRC | 03:45 | |
*** Kennan has joined #openstack-containers | 03:47 | |
*** achanda has joined #openstack-containers | 03:51 | |
*** chuenlye has quit IRC | 03:53 | |
*** kebray has joined #openstack-containers | 04:01 | |
*** achanda has quit IRC | 04:12 | |
*** vilobhmm1 has joined #openstack-containers | 04:12 | |
*** chandankumar has joined #openstack-containers | 04:16 | |
*** Kennan2 has joined #openstack-containers | 04:21 | |
*** Kennan has quit IRC | 04:22 | |
*** dims has joined #openstack-containers | 04:23 | |
*** dims has quit IRC | 04:28 | |
*** unicell has joined #openstack-containers | 04:35 | |
*** sdake_ has quit IRC | 04:38 | |
*** fangfenghua_ has joined #openstack-containers | 04:55 | |
*** sdake has joined #openstack-containers | 04:57 | |
*** rongze has quit IRC | 04:58 | |
*** rongze has joined #openstack-containers | 05:00 | |
*** adrian_otto has joined #openstack-containers | 05:05 | |
*** achanda has joined #openstack-containers | 05:10 | |
*** fangfenghua_ has quit IRC | 05:35 | |
juggler | hi all | 05:44 |
---|---|---|
*** rongze has quit IRC | 05:45 | |
*** rongze has joined #openstack-containers | 05:50 | |
*** rongze has quit IRC | 05:52 | |
*** oro has joined #openstack-containers | 06:07 | |
*** suro-patz has joined #openstack-containers | 06:20 | |
*** Tango has quit IRC | 06:22 | |
*** openstackgerrit has quit IRC | 06:23 | |
*** openstackgerrit has joined #openstack-containers | 06:23 | |
*** vilobhmm1 has quit IRC | 06:23 | |
*** vilobhmm1 has joined #openstack-containers | 06:27 | |
*** vilobhmm11 has joined #openstack-containers | 06:29 | |
*** oro has quit IRC | 06:31 | |
*** vilobhmm1 has quit IRC | 06:31 | |
*** suro-patz has quit IRC | 06:47 | |
*** chuenlye has joined #openstack-containers | 06:53 | |
*** suro-patz has joined #openstack-containers | 06:56 | |
juggler | hey suro | 06:57 |
*** chuenlye has quit IRC | 06:58 | |
*** nshaikh has joined #openstack-containers | 07:03 | |
*** kebray has quit IRC | 07:11 | |
*** achanda has quit IRC | 07:16 | |
*** achanda has joined #openstack-containers | 07:22 | |
*** vilobhmm11 has quit IRC | 07:23 | |
*** achanda has quit IRC | 07:24 | |
*** suro-patz has quit IRC | 07:37 | |
*** EricGonczer_ has joined #openstack-containers | 07:38 | |
*** erkules_ is now known as erkules | 07:42 | |
*** erkules has quit IRC | 07:43 | |
*** erkules has joined #openstack-containers | 07:43 | |
*** oro has joined #openstack-containers | 07:47 | |
*** EricGonczer_ has quit IRC | 08:04 | |
*** oro has quit IRC | 08:06 | |
*** adrian_otto has quit IRC | 08:37 | |
*** jsotoca has joined #openstack-containers | 09:27 | |
*** chuenlye has joined #openstack-containers | 09:40 | |
*** chuenlye has quit IRC | 09:45 | |
*** jay-lau-513 has quit IRC | 10:12 | |
*** tobe has joined #openstack-containers | 10:18 | |
*** kbyrne has quit IRC | 10:18 | |
*** dims has joined #openstack-containers | 10:20 | |
*** kbyrne has joined #openstack-containers | 10:20 | |
*** dims_ has joined #openstack-containers | 10:22 | |
openstackgerrit | Tom Cammann proposed openstack/magnum: Add unique column constraints to db https://review.openstack.org/180095 | 10:23 |
tcammann | morning all | 10:25 |
*** dims has quit IRC | 10:26 | |
*** fangfeng_ has joined #openstack-containers | 10:28 | |
*** fangfeng_ is now known as fangfenghua_ | 10:28 | |
*** fangfenghua_ has quit IRC | 11:13 | |
*** chandankumar has quit IRC | 11:44 | |
*** fangfenghua_ has joined #openstack-containers | 11:46 | |
*** fangfenghua_ has quit IRC | 11:55 | |
*** EricGonczer_ has joined #openstack-containers | 11:57 | |
*** EricGonczer_ has quit IRC | 12:00 | |
*** EricGonczer_ has joined #openstack-containers | 12:18 | |
*** EricGonczer_ has quit IRC | 12:24 | |
*** rpothier has joined #openstack-containers | 12:29 | |
tcammann | Could someone look at this high bug - https://bugs.launchpad.net/magnum/+bug/1441586 | 12:31 |
openstack | Launchpad bug 1441586 in Magnum "ERROR: Multiple baymodels exist with same name." [High,Confirmed] - Assigned to Digambar (digambarpatil15) | 12:31 |
tcammann | I don't think its a valid bug anymore as there is no uniqueness constraint in the schema | 12:31 |
openstackgerrit | Tom Cammann proposed openstack/magnum: Add unique column constraints to db https://review.openstack.org/180095 | 12:37 |
*** dims_ has quit IRC | 12:41 | |
*** dims has joined #openstack-containers | 12:41 | |
*** fangfenghua_ has joined #openstack-containers | 12:45 | |
*** jfarschman has joined #openstack-containers | 12:51 | |
*** jfarschman is now known as MilesDenver | 12:51 | |
openstackgerrit | Grzegorz Grasza (xek) proposed openstack/magnum: Move our ObjectSerializer to subclass from the Oslo one https://review.openstack.org/178718 | 12:58 |
openstackgerrit | Grzegorz Grasza (xek) proposed openstack/magnum: Make MagnumObject a subclass of Oslo VersionedObject https://review.openstack.org/180133 | 12:58 |
*** rlrevell has joined #openstack-containers | 13:10 | |
*** MilesDenver has quit IRC | 13:14 | |
*** prad has joined #openstack-containers | 13:32 | |
*** prad_ has joined #openstack-containers | 13:32 | |
*** prad_ has quit IRC | 13:36 | |
*** jfarschman has joined #openstack-containers | 13:37 | |
*** jfarschman is now known as MilesDenver | 13:37 | |
*** tobe has quit IRC | 13:40 | |
*** dboik_ has quit IRC | 13:46 | |
openstackgerrit | Tom Cammann proposed openstack/magnum: Improve validation on baymodel api calls https://review.openstack.org/180158 | 13:56 |
*** fawadkhaliq has joined #openstack-containers | 13:59 | |
*** dboik has joined #openstack-containers | 14:09 | |
*** dboik has quit IRC | 14:09 | |
*** dboik has joined #openstack-containers | 14:10 | |
*** fangfenghua has quit IRC | 14:23 | |
*** fangfenghua_ has quit IRC | 14:24 | |
*** fangfenghua_ has joined #openstack-containers | 14:27 | |
*** Tango has joined #openstack-containers | 14:27 | |
*** fangfenghua_ has quit IRC | 14:28 | |
*** kebray has joined #openstack-containers | 14:41 | |
*** kebray has quit IRC | 14:41 | |
*** dboik_ has joined #openstack-containers | 14:42 | |
*** sdake_ has joined #openstack-containers | 14:43 | |
*** dboik has quit IRC | 14:45 | |
*** sdake has quit IRC | 14:47 | |
*** coolsvap is now known as coolsvap|afk | 14:48 | |
*** rongze has joined #openstack-containers | 14:49 | |
*** chandankumar has joined #openstack-containers | 14:50 | |
*** Marga_ has joined #openstack-containers | 14:57 | |
*** Marga_ has quit IRC | 14:57 | |
*** Marga_ has joined #openstack-containers | 14:58 | |
*** sdake_ is now known as sdake | 15:01 | |
*** achanda has joined #openstack-containers | 15:01 | |
*** fangfenghua has joined #openstack-containers | 15:05 | |
*** jay-lau-513 has joined #openstack-containers | 15:05 | |
*** achanda has quit IRC | 15:06 | |
*** nshaikh has left #openstack-containers | 15:07 | |
*** kebray has joined #openstack-containers | 15:10 | |
*** dboik_ has quit IRC | 15:13 | |
*** dboik has joined #openstack-containers | 15:13 | |
*** chandankumar has quit IRC | 15:15 | |
*** Marga_ has quit IRC | 15:26 | |
*** dims_ has joined #openstack-containers | 15:32 | |
*** dboik has quit IRC | 15:32 | |
*** dims has quit IRC | 15:34 | |
*** sdake has quit IRC | 15:37 | |
*** rongze has quit IRC | 15:38 | |
*** shakamunyi has joined #openstack-containers | 15:39 | |
*** rongze_ has joined #openstack-containers | 15:40 | |
*** sdake has joined #openstack-containers | 15:40 | |
*** rongze has joined #openstack-containers | 15:42 | |
*** rongze_ has quit IRC | 15:46 | |
*** dboik has joined #openstack-containers | 15:47 | |
*** adrian_otto has joined #openstack-containers | 15:52 | |
openstackgerrit | Tom Cammann proposed openstack/magnum: Improve validation on baymodel api calls https://review.openstack.org/180158 | 15:53 |
adrian_otto | Our team meeting will begin in 5 minutes in #openstack-meeting-alt so I look forward to seeing you all there! | 15:55 |
adrian_otto | uuh | 15:56 |
adrian_otto | seems I got mixed up. Our schedule says today we meet at 2200 UTC. Sorry about that. See you this afternoon. | 15:56 |
*** chandankumar has joined #openstack-containers | 16:00 | |
*** dboik_ has joined #openstack-containers | 16:01 | |
*** Marga_ has joined #openstack-containers | 16:01 | |
*** daneyon has joined #openstack-containers | 16:02 | |
*** daneyon_ has joined #openstack-containers | 16:03 | |
*** dboik has quit IRC | 16:04 | |
*** daneyon has quit IRC | 16:06 | |
*** unicell has quit IRC | 16:13 | |
*** dboik_ has quit IRC | 16:17 | |
*** dboik has joined #openstack-containers | 16:17 | |
*** daneyon_ has quit IRC | 16:21 | |
*** daneyon has joined #openstack-containers | 16:21 | |
*** EricGonczer_ has joined #openstack-containers | 16:31 | |
*** dboik_ has joined #openstack-containers | 16:31 | |
*** jsotoca has quit IRC | 16:32 | |
*** dboik has quit IRC | 16:34 | |
*** EricGonczer_ has quit IRC | 16:35 | |
*** chandankumar has quit IRC | 16:36 | |
sdake | adrian_otto: | 16:40 |
sdake | using kolla: | 16:41 |
sdake | [sdake@bigiron magnum]$ magnum bay-list | 16:41 |
sdake | +--------------------------------------+---------+------------+-----------------+ | 16:41 |
sdake | | uuid | name | node_count | status | | 16:41 |
sdake | +--------------------------------------+---------+------------+-----------------+ | 16:41 |
sdake | | 6ff943e5-f95f-48a2-84d8-8242a1483d3a | testbay | 2 | CREATE_COMPLETE | | 16:41 |
sdake | +--------------------------------------+---------+------------+----------------- | 16:41 |
*** EricGonczer_ has joined #openstack-containers | 16:41 | |
sdake | boy that was hard | 16:44 |
*** sdake_ has joined #openstack-containers | 16:45 | |
*** unicell has joined #openstack-containers | 16:45 | |
adrian_otto | WHOOT | 16:46 |
adrian_otto | how can I do that too???!!!! | 16:47 |
*** sdake has quit IRC | 16:49 | |
*** EricGonczer_ has quit IRC | 16:51 | |
*** EricGonczer_ has joined #openstack-containers | 16:51 | |
*** suro-patz has joined #openstack-containers | 16:52 | |
*** chandankumar has joined #openstack-containers | 16:52 | |
*** suro-patz has quit IRC | 16:53 | |
*** Marga_ has quit IRC | 16:56 | |
*** Marga_ has joined #openstack-containers | 16:57 | |
-openstackstatus- NOTICE: zuul has been restarted to troubleshoot an issue, gerrit events between 15:00-17:00 utc were lost and changes updated or approved during that time will need to be rechecked or have their approval votes readded to trigger testing | 17:03 | |
sdake_ | adrian_otto you want to setup on your own hardware? | 17:04 |
sdake_ | you need 1 internet connection, 1 extra switch, 2 boxes with fedora on them | 17:06 |
sdake_ | and I can help you get setup from there using my system as a benchmark | 17:06 |
sdake_ | you also need a floating rangey ou can use safely | 17:08 |
sdake_ | altneratively you can use my environment which I'd probably recommend at this point | 17:08 |
*** EricGonczer_ has quit IRC | 17:10 | |
*** rongze has quit IRC | 17:12 | |
*** suro-patz has joined #openstack-containers | 17:12 | |
*** sdake_ has quit IRC | 17:14 | |
adrian_otto | sdake: I suppose I need a modified Heat template that does not define a cinder volume? | 17:14 |
adrian_otto | I have new hardware on the desk in front of me | 17:14 |
adrian_otto | I am taking it to the data center today | 17:14 |
*** vilobhmm1 has joined #openstack-containers | 17:14 | |
adrian_otto | so we'll have both setups, just in case one falls victim to trouble | 17:15 |
*** vilobhmm1 has quit IRC | 17:15 | |
*** achanda has joined #openstack-containers | 17:16 | |
*** vilobhmm1 has joined #openstack-containers | 17:16 | |
*** dboik_ has quit IRC | 17:17 | |
*** Tango has quit IRC | 17:17 | |
*** dboik has joined #openstack-containers | 17:17 | |
*** pradk has joined #openstack-containers | 17:32 | |
*** oro has joined #openstack-containers | 17:33 | |
*** dims_ has quit IRC | 17:33 | |
*** dims has joined #openstack-containers | 17:34 | |
*** dboik_ has joined #openstack-containers | 17:39 | |
*** hongbin has joined #openstack-containers | 17:39 | |
hongbin | good afternoon folks! | 17:40 |
*** sdake has joined #openstack-containers | 17:41 | |
tcammann | hello hongbin | 17:41 |
adrian_otto | hi hongbin | 17:41 |
*** dboik has quit IRC | 17:42 | |
hongbin | hi tcammann adrian_otto | 17:42 |
sdake | hey guys | 17:42 |
sdake | dropped off for a second adrian_otto | 17:42 |
sdake | hey hongbin | 17:42 |
sdake | welcome back ;) | 17:42 |
hongbin | :) | 17:42 |
sdake | adrian_otto how did you want to proceed re setup | 17:42 |
adrian_otto | any chance we can earmark a little time together to work on it as a pair? | 17:43 |
sdake | ya i'm available all day | 17:44 |
adrian_otto | humm, looking at my calendar, that's going to be touch until later tonight. | 17:44 |
sdake | did you want to use my hardware or yours | 17:44 |
adrian_otto | I can put the servers up between 1:00 and 2:00 today | 17:44 |
sdake | do they ahve a floating range they can use/ | 17:45 |
adrian_otto | it looks like you already have a working magnum setup on yours with kolla, right? | 17:45 |
sdake | yup | 17:45 |
adrian_otto | I have both public and private IP ranges that work wit these new ones | 17:45 |
sdake | getting you setup will take hours | 17:45 |
sdake | are these onmetal or at your house | 17:46 |
adrian_otto | I have them here at the office, and I'm taking them to a colo to host them | 17:46 |
adrian_otto | this way I have full control over the hardware, and the network | 17:47 |
*** oro has quit IRC | 17:47 | |
sdake | interesting, well in that case you may be able to get your eth0 and eht1 routed | 17:48 |
sdake | (to the internet) | 17:48 |
*** chandankumar has quit IRC | 17:48 | |
sdake | in which case setup is easy | 17:48 |
adrian_otto | yeah, we have both public and private interfaces on each server | 17:49 |
adrian_otto | but they are funky interface names, not eth0 and eth1 | 17:49 |
sdake | ya thats fine | 17:49 |
sdake | it doesn't have to be eth0 | 17:49 |
adrian_otto | I did not spend any wffort working to rename them | 17:49 |
sdake | but they both have to be routed | 17:49 |
adrian_otto | both need internet access? | 17:49 |
sdake | unfortunately | 17:49 |
sdake | alternaviley you can do what i do and only have one routed | 17:50 |
sdake | one interface routed | 17:50 |
adrian_otto | well in that case they would be in the same ip range | 17:50 |
sdake | and ssh in over that 11.11.11.100 that i showed you | 17:50 |
adrian_otto | because I only have one external address block | 17:50 |
sdake | the secon dinterface doesn't get an ip | 17:50 |
sdake | public interface gets an ip flat interface doesn't get an ip | 17:50 |
sdake | flat interface must be routed tho | 17:51 |
sdake | we create your floats off the flat interface | 17:51 |
adrian_otto | ok, I guess I'll look at your setup to understand that better | 17:51 |
sdake | and your private network also goes over the flat interface | 17:51 |
sdake | maybe daneyon can explain why that is :) | 17:51 |
sdake | it makes zero sense to me | 17:52 |
sdake | i would think the private interface would go over a third network | 17:52 |
daneyon | one sec, let me read the thread | 17:52 |
sdake | the floats we create on your flat interface are teh same ip address range as your public ip | 17:52 |
adrian_otto | it sounds to me like what we really want here is a bridge interface | 17:53 |
adrian_otto | not an additional physical port | 17:54 |
sdake | i tried a bridge interface | 17:54 |
sdake | couldn't get it to work | 17:54 |
daneyon | sdake the private network gets tunneled (by vxlan) over the kolla node mgt network (i.e. eth0). | 17:54 |
sdake | daneyon thanks I was wondering how that worked | 17:55 |
daneyon | in a real deploy, we will require a 3rd interface that is used for vxlan tunnels, aka the tenant private networks | 17:55 |
daneyon | first we need to test multi-node | 17:55 |
sdake | jtriley got multinode working | 17:56 |
sdake | atleat multi-compute | 17:56 |
daneyon | i believe right now the vxlan interface is defaulted to the PUBLIC_IP definition, but that will change when we test kolla multi-node | 17:56 |
sdake | daneyon where is this option | 17:56 |
sdake | I have 3 interfaces available | 17:56 |
adrian_otto | daneyon: so if I am pulling in a new pair of servers, each with two phyical NIC interfaces, should eth0 be on the internet, and eth1 be on a private VLAN, or is there another physical layout I need to plan for? | 17:57 |
adrian_otto | I can put in a third physical interface into each as well | 17:57 |
sdake | openstack docs indicate the reuiqrements for 3 network interfaces for the network managment node | 17:58 |
sdake | one for managmenet, one for vxlan, one for public ips | 17:58 |
sdake | sorry floating ips | 17:58 |
sdake | the floatingip and management network need to be routed i think | 17:59 |
sdake | the reasonthe management network needs to be routed is becaue of the api server access | 17:59 |
daneyon | the kolla mgt net (ie eth0) requires outbound Internet access so pkgs, images, etc.. can be downloaded. This could be circumvented with a local mirror, registry, etc.. The NEUTRON_FLAT_NETWORK_INTERFACE is used by the neutron-agents container, specifically the neutron linux bridge agent to bridge traffic to/from Nova instances to the public network. This allos instances to hit the Internet. If you assign a floating- | 17:59 |
daneyon | ip to an instance, the floating ip comes from this network. This allows instances to be accessed from the outside world. | 17:59 |
sdake | therefore the flat interface needs to be routed as well? | 18:00 |
sdake | the kolla mgt net eth0 also needs to be routed for access to the api servers | 18:01 |
daneyon | adrian_otto you can add the 3rd interface, but I will need to hack at the code and test separating the vxlan interface. i am spinning up a 2nd kolla node, so i can work on this if sdake agrees. | 18:01 |
adrian_otto | so ip adresses on the eth0 interface need to be in a different subnet than ip addresses on the NEUTRON_FLAT_NETWORK_INTERFACE? | 18:01 |
sdake | yup you need two /24 address ranges | 18:02 |
sdake | one with floats one without | 18:02 |
adrian_otto | that's going to be impossible | 18:03 |
*** fangfenghua has quit IRC | 18:03 | |
sdake | i keep telling daneyon that ;) | 18:03 |
adrian_otto | there is no way I'm going to be able to get two /24s of routable addresses | 18:03 |
sdake | well you really only need 1 with 2 ips | 18:03 |
sdake | and 1 with /24 float | 18:03 |
sdake | i use one /24 range for all my traffic | 18:04 |
adrian_otto | why does it need to be a /24? | 18:04 |
sdake | it could be /28 | 18:04 |
sdake | or /30 | 18:04 |
adrian_otto | ok | 18:04 |
sdake | howemany over vms you want to run | 18:04 |
daneyon | sdake the NEUTRON_FLAT_NETWORK_INTERFACE physical to be connected to an IP network that can reach the Internet. This network does not need to be routable if the upstream physcial gateway NAT's this network. However, typical deployments do not NAT this network upstream and assign a routable address block. | 18:04 |
sdake | daneyon how owuld you ssh into the machine then? | 18:05 |
sdake | need to get in as well as out | 18:06 |
daneyon | adrian_otto that is correct. sdake the networks do not need to be /24's. The netmask needs to be whatever is needed to support the number of req'd hosts. We are not doing anything funky here. This is the standard neutron networking model... well when we support a 3rd interface for vxlan then it will be on point with the neutron networking model | 18:06 |
daneyon | adrian_otto A typical deployment will not assign publicly routable addresses to the kolla mgt network (ie eth0). In a typical deployment, the kolla mgt network will be assigned a private IP block and connect to a pair of redundant firewalls. The firewalls will be configured to allow the necessary outbound/inbound traffic. Connectivity will be provided by the firewall by NAT'ing the private IP's from this network to | 18:11 |
daneyon | a public IP associated to the firewall. | 18:11 |
*** barra204 has joined #openstack-containers | 18:12 | |
sdake | so the firwall forwards traffic to the api ports/addresses? | 18:12 |
daneyon | sdake as i mentioned, typical deployments will have the NEUTRON_FLAT from publicly routable address space so NAT'ing is not required. If a device upstream NAT'd addresses from the NEUTRON_FLAT network, then each floating-ip will be associated to an upstream NAT'd address. Users would ssh/ping, etc this upstream NAT'd address. This is far from normal but it's technically possible. | 18:14 |
daneyon | sdake The firewall will fwd/filter traffic to/from the API endpoints. We will eventually want to split the admin/user endpoints. Since these are the same today, they are on the same network and would have the same firewall policies. Of course we will want to address this in the future. | 18:16 |
sdake | the problem is the public_ip (eth0) needs to be able to get out to the internet, so it needs routing as well right? | 18:16 |
sdake | to pull packages/etc | 18:16 |
sdake | networking sucks | 18:17 |
* sdake groans | 18:17 | |
sdake | so if I plug my eth1 into my home router, and use floats in 192.168.1.150-199, it should be able to get access the the internet? | 18:18 |
* sdake wtbs a picture | 18:19 | |
*** EricGonczer_ has joined #openstack-containers | 18:19 | |
daneyon | sdake eth0 can sit behind a firewall on a private network block. The firewall will expose the API endpoints by NAT'ing public/private and applying the necessary firewall rules, ie permit any > nova-api (192.168.20.100) eq tcp 8774-8775. | 18:20 |
daneyon | sdake yes if the env has been config'd properly | 18:21 |
sdake | I dind't know vxlan was routed over eth0 | 18:21 |
sdake | that totally changes my perspective about how all this works | 18:21 |
*** EricGonczer_ has quit IRC | 18:22 | |
*** EricGonc_ has joined #openstack-containers | 18:23 | |
sdake | i thought vxlan was routed over eth1 (flat inteface) | 18:24 |
sdake | if we could get the flat interface on my main network, it would hvae internet routing | 18:24 |
sdake | any chance we can do a webex screenshare debug session on that? | 18:25 |
*** Tango has joined #openstack-containers | 18:25 | |
sdake | and my managmeent network (eth) would also have intenet routing | 18:25 |
sdake | eth0 that is | 18:26 |
*** barra204 has quit IRC | 18:27 | |
*** oro has joined #openstack-containers | 18:27 | |
*** logan2 has quit IRC | 18:28 | |
*** fawadkhaliq has quit IRC | 18:30 | |
*** logan2 has joined #openstack-containers | 18:31 | |
*** suro-patz has quit IRC | 18:32 | |
*** suro-patz has joined #openstack-containers | 18:33 | |
*** vilobhmm1 has quit IRC | 18:33 | |
daneyon | sdake as of today vxlan uses the PUBLIC_IP param to set the vxlan endpoint IP of the linuxbridge agent. traffic from an instance would get encapsulated into a vxlan packet. The src ip of the packet will be from PUBLIC_IP and the dst ip of the vxlan packet will be asscocoiated to a 2nd kolla node's PUBLIC_IP. The 2nx kolla node strips the vxlan header off and bridges the traffic to the internal bridge associated to | 18:33 |
daneyon | the tenant-id | 18:33 |
sdake | cool i got it | 18:34 |
sdake | so about this connecting my eth1 to my 192.168.1.0/24 network | 18:34 |
sdake | and possibly making flat 192.168.1.0/29 | 18:34 |
sdake | would that work? | 18:35 |
*** vilobhmm1 has joined #openstack-containers | 18:35 | |
*** prad has quit IRC | 18:35 | |
*** prad has joined #openstack-containers | 18:36 | |
daneyon | sdake https://github.com/stackforge/kolla/blob/master/docker/neutron/neutron-agents/config-scripts/config-linuxbridge-agent.sh#L21 set to PUBLIC_IP. We will want to create a 3rd network interface on each kolla host that has an ip from a private network used by vxlan to encap/decap vxlan traffic between the nodes | 18:36 |
sdake | nice | 18:37 |
*** suro-patz has quit IRC | 18:38 | |
daneyon | the flat network mask should match the mask of the upstream gw of the flat net | 18:39 |
*** kebray has quit IRC | 18:39 | |
sdake | so it needs to be a /24 network? | 18:39 |
daneyon | you can hack around it and make /24 upstream work with /29 but any addresses outside of /29 will black hole | 18:39 |
*** rlrevell has quit IRC | 18:40 | |
sdake | ok, given the following, is it possible to route both my flat and public interfaces | 18:40 |
sdake | connect eth0 into switch connected to internet | 18:40 |
sdake | connect eth1 into switch connected to internet | 18:40 |
sdake | ? | 18:40 |
*** Marga_ has quit IRC | 18:41 | |
*** Marga_ has joined #openstack-containers | 18:42 | |
*** suro-patz has joined #openstack-containers | 18:42 | |
*** barra204 has joined #openstack-containers | 18:42 | |
*** sdake_ has joined #openstack-containers | 18:43 | |
*** fawadkhaliq has joined #openstack-containers | 18:43 | |
daneyon | the flat network ip/mask should match the setting of the upstream gw. kolla-node-eth1<>switchport-eth1<>switch<>switchport-eth2<>upstream-gw-eth1 <-- This network should be routable. Meaning from a routable address space. For testing purposes this network can be from RFC 1918, but the addresses will not be reachable from the Internet without some add'l magic. This network should have the same IP settings, same addr | 18:44 |
daneyon | ess block, mask, etc.. | 18:44 |
sdake_ | ok I dont care if its accessible from the internet | 18:44 |
daneyon | could be a /24, /29, /26, depending on the number of IP's you need to support | 18:44 |
sdake_ | daneyon did you see shannon's repsonse to my plea for help | 18:46 |
sdake_ | he said to use a static route | 18:46 |
*** sdake has quit IRC | 18:47 | |
daneyon | then you can use a 1918 address. The problem you have with your home network is that your home router is a home router and a typical router. A typical router will have multiple interfaces, each interface has an ip/mask and acts as a gw for the hosts and routes between these networks associated to it's interfaces or routes to other routers. | 18:47 |
daneyon | sdake_ i di not. I'm confused. I thought we had your home network at a point that worked for your dev'ing? | 18:48 |
sdake_ | here is the deal | 18:48 |
sdake_ | i ahve to reboot between dev and demo mode | 18:48 |
sdake_ | i don't want to have to reboot | 18:48 |
sdake_ | it puts a serious crimp in my development | 18:48 |
sdake_ | check out shannon's response, maybe that static route would work | 18:48 |
*** dboik has joined #openstack-containers | 18:50 | |
daneyon | for you to properly simulate a real deployment. You will need to get a real router with at least 3 interfaces. 1 interface from this router connects to your kolla mgt network and the 2nd router interface connects to your neutron flat network. The 3rd interface connects to your upstream cable modem. This router will NAT traffic so that the kolla mgt and neutron flat network can reach the internet. | 18:50 |
*** dboik_ has quit IRC | 18:50 | |
sdake_ | ok thats what I want | 18:51 |
sdake_ | can you recommend one | 18:51 |
daneyon | sdake If you do not have a real router, take a linux box that has 3 network cards and do the same. Vendors make home routers with limited functionality because most home users are not trying to do this. | 18:51 |
daneyon | sdake_ do you have a linux box with 3 interfaces? | 18:52 |
sdake_ | yes but I'd prefer to not use those | 18:52 |
sdake_ | is there a "cheap" 3 port router on the market ;) | 18:53 |
sdake_ | or are they all like a billion dollars | 18:53 |
*** dboik has quit IRC | 18:53 | |
*** dboik has joined #openstack-containers | 18:54 | |
daneyon | sdake_ i'm sure you can find a router with 3 ethernet interfaces. The bigger issue is learning IOS or JunOS or whatever router you get. Then you add the time it take to purchase and ship. If I were you, I would at least try a linux box with 3 interfaces. All you need is a static route or two and firewalld/iptables to handle NAT'ing traffic. | 18:58 |
daneyon | sdake_ http://www.tritondatacomonline.com/products/cisco-2851-router-cisco2851?utm_medium=cpc&utm_source=googlepla&variant=286797386&gclid=CjwKEAjw1KGqBRC55bru-sa7zCcSJAAxsBf5hTl8CtSTFhlVplGTn4sV5aUcgv5p-OKFVfH7wir63BoC9xXw_wcB | 18:59 |
sdake_ | danyeon will that router do the job? | 19:00 |
sdake_ | what is a hwic | 19:00 |
sdake_ | pvdm | 19:00 |
sdake_ | nme-xd | 19:00 |
sdake_ | aim ?:) | 19:00 |
daneyon | that router has 2 GigE interfaces. If your switch supports trunking (802.1Q or ISL), you can get away with less than 3 interfaces. On the switch you would create 3 VLANs, kolla-mgt, neutron-flat, router_modem. Leave the router_modem untagged and tag the other 2 with a UID. Then configure trunking between the router and switch ports. | 19:01 |
daneyon | wan interface card, nothing to worry about since you;re not erminating a T1, DS3, etc.. | 19:01 |
sdake_ | so it only has 2 gig e interfaces right? | 19:01 |
sdake_ | don't I need 3? | 19:01 |
daneyon | don;t worry about any of those acronyms | 19:02 |
daneyon | see my msg above | 19:02 |
sdake_ | oh right 802.1q | 19:02 |
sdake_ | no diea what that is :) | 19:02 |
*** rlrevell has joined #openstack-containers | 19:02 | |
daneyon | a standard for tagging ethernet frames for providing logic separation of layer 2 domains | 19:04 |
*** suro-patz has quit IRC | 19:04 | |
*** suro-patz1 has joined #openstack-containers | 19:04 | |
sdake_ | ok I think my plan of action should be as follows | 19:06 |
sdake_ | I'll order that switch | 19:06 |
sdake_ | I'll try to get rolling with one of my 3 ip boxes and use that in the meantime | 19:06 |
sdake_ | 150 bucks is alot cheaper then those 1500 machines | 19:06 |
sdake_ | did you see the idea to use static routes from shannon? | 19:07 |
sdake_ | daneyon how should I connect my environment to use this third node as a router | 19:10 |
daneyon | sdake_ let me draw it up and txt it to u. give me 5 min | 19:11 |
daneyon | sdake_ you have a cable modem that connects to a home router, correct? | 19:12 |
sdake_ | yup | 19:12 |
*** vilobhmm1 has quit IRC | 19:12 | |
sdake_ | is that router actually gige daneyon | 19:12 |
sdake_ | before I order it | 19:13 |
sdake_ | I am going gige soon in my household | 19:13 |
*** vilobhmm1 has joined #openstack-containers | 19:13 | |
sdake_ | and want something that can do gige rates | 19:13 |
sdake_ | (my internet will be gige) | 19:13 |
daneyon | then you have a cvo router too? If so, does that connect to your home router? | 19:13 |
sdake_ | the cvo connects to my home wireless | 19:13 |
sdake_ | ya wireless router | 19:13 |
daneyon | home wirelss comes from your home router, correct? | 19:14 |
sdake_ | i have a cablemodel connected to a linksys wireless router connected to eth0 | 19:14 |
daneyon | cvo router has no physical connections? | 19:14 |
sdake_ | it connects to a phone and my linksys wireless router over ethenet | 19:14 |
daneyon | sdake_ since you do have a cvo router, we may be able to come up with a solution w/o adding another router. | 19:17 |
*** pradk has quit IRC | 19:19 | |
*** subscope_ has joined #openstack-containers | 19:27 | |
*** kebray has joined #openstack-containers | 19:30 | |
*** EricGonc_ has quit IRC | 19:34 | |
*** sdake has joined #openstack-containers | 19:42 | |
*** sdake has quit IRC | 19:42 | |
*** sdake_ has quit IRC | 19:45 | |
*** Tango has quit IRC | 19:45 | |
*** sdake has joined #openstack-containers | 19:46 | |
*** sdake_ has joined #openstack-containers | 19:47 | |
*** sdake has quit IRC | 19:51 | |
*** sdake has joined #openstack-containers | 20:01 | |
*** sdake_ has quit IRC | 20:05 | |
*** chuenlye has joined #openstack-containers | 20:07 | |
*** adrian_otto has quit IRC | 20:09 | |
*** sdake has quit IRC | 20:10 | |
*** sdake has joined #openstack-containers | 20:10 | |
*** achanda has quit IRC | 20:11 | |
*** kebray has quit IRC | 20:15 | |
*** kebray has joined #openstack-containers | 20:17 | |
*** vilobhmm1 has quit IRC | 20:24 | |
*** achanda has joined #openstack-containers | 20:35 | |
*** barra204 has quit IRC | 20:37 | |
*** jsotoca has joined #openstack-containers | 20:38 | |
*** rlrevell has quit IRC | 20:39 | |
*** rlrevell1 has joined #openstack-containers | 20:39 | |
*** rlrevell1 has quit IRC | 20:42 | |
*** rlrevell has joined #openstack-containers | 20:43 | |
*** rlrevell has quit IRC | 20:51 | |
*** fawadkhaliq has quit IRC | 20:51 | |
*** adrian_otto has joined #openstack-containers | 20:54 | |
*** rpothier has quit IRC | 20:56 | |
*** vilobhmm1 has joined #openstack-containers | 21:00 | |
*** suro-patz1 has quit IRC | 21:01 | |
*** vilobhmm1 has quit IRC | 21:01 | |
*** vilobhmm1 has joined #openstack-containers | 21:02 | |
*** suro-patz has joined #openstack-containers | 21:03 | |
*** suro-patz has quit IRC | 21:07 | |
*** adrian_otto1 has joined #openstack-containers | 21:17 | |
*** adrian_otto has quit IRC | 21:20 | |
*** adrian_otto1 is now known as adrian_otto | 21:22 | |
*** sdake_ has joined #openstack-containers | 21:35 | |
*** sdake has quit IRC | 21:39 | |
*** rpothier has joined #openstack-containers | 21:40 | |
juggler | hey all | 21:40 |
juggler | wondering if anyone is around to peer-review some ideas/q's | 21:41 |
*** jsotoca has quit IRC | 21:42 | |
* adrian_otto here | 21:42 | |
adrian_otto | juggler: what's your idea? | 21:43 |
juggler | pls stand by for some pasteup | 21:44 |
juggler | Document: https://github.com/openstack/magnum/blob/master/doc/source/dev/dev-manual-devstack.rst | 21:45 |
juggler | Q1: Could you confirm that the "refs" to dev-quickstart are invalid? They seem circular (pointing to this link..) | 21:46 |
juggler | Seems like a bug. | 21:47 |
juggler | Q2: If yes to Q1, does that require a bug report, or is that merely a wiki fix? | 21:47 |
juggler | Q3: The "Manually" of the title and description of the document seems to suggest that there is an _Automatic_ method of installing Magnum. Is there? | 21:49 |
*** sdake has joined #openstack-containers | 21:50 | |
adrian_otto | Our team meeting will begin in 10 minutes in #openstack-meeting-alt so I look forward to seeing you all there (for real this time) | 21:50 |
*** tcammann_ has joined #openstack-containers | 21:51 | |
adrian_otto | juggler: Q1 does sound like a bug | 21:51 |
adrian_otto | Q2, you need to submit a patch to fix that doc | 21:51 |
adrian_otto | and patches require an associated bug, so yes. | 21:52 |
adrian_otto | Q3: The "manual" approach assumes you already have an OpenStack cloud to wire magnum to | 21:52 |
adrian_otto | The other approach assumes you will be setting up a new (devstack) cloud to use Magnum with | 21:52 |
adrian_otto | make sense? | 21:52 |
*** sdake__ has joined #openstack-containers | 21:54 | |
*** sdake_ has quit IRC | 21:54 | |
juggler | adrian_otto: Q1&Q2: got it. | 21:55 |
juggler | Q3: not entirely..but I will take your word for it until I get it. :) | 21:56 |
*** sdake has quit IRC | 21:58 | |
*** Tango has joined #openstack-containers | 22:00 | |
*** oro has quit IRC | 22:03 | |
*** vilobhmm1 has quit IRC | 22:04 | |
*** vilobhmm1 has joined #openstack-containers | 22:05 | |
*** vilobhmm1 has quit IRC | 22:05 | |
*** vilobhmm1 has joined #openstack-containers | 22:05 | |
*** vilobhmm1 has quit IRC | 22:10 | |
*** suro-patz has joined #openstack-containers | 22:12 | |
*** vilobhmm1 has joined #openstack-containers | 22:14 | |
*** ramishra_ has joined #openstack-containers | 22:26 | |
*** ramishra has quit IRC | 22:29 | |
*** ramishra_ is now known as ramishra | 22:30 | |
*** dboik_ has joined #openstack-containers | 22:31 | |
*** unicell1 has joined #openstack-containers | 22:31 | |
*** unicell has quit IRC | 22:31 | |
*** kebray has quit IRC | 22:32 | |
*** subscope_ has quit IRC | 22:34 | |
*** chuenlye has quit IRC | 22:34 | |
*** dboik has quit IRC | 22:35 | |
*** chuenlye has joined #openstack-containers | 22:35 | |
*** dboik_ has quit IRC | 22:35 | |
*** kebray has joined #openstack-containers | 22:40 | |
*** chuenlye has quit IRC | 22:40 | |
*** suro-patz1 has joined #openstack-containers | 22:44 | |
*** vilobhmm1 has quit IRC | 22:45 | |
*** suro-patz has quit IRC | 22:46 | |
*** vilobhmm1 has joined #openstack-containers | 22:47 | |
*** vilobhmm1 has quit IRC | 22:47 | |
*** vilobhmm1 has joined #openstack-containers | 22:48 | |
tcammann_ | adrian_otto: could you look at bug 1441586, its a high but I don't think its valid anymore. | 22:59 |
openstack | bug 1441586 in Magnum "ERROR: Multiple baymodels exist with same name." [High,Confirmed] https://launchpad.net/bugs/1441586 - Assigned to Digambar (digambarpatil15) | 22:59 |
adrian_otto | tcammann: ok | 23:00 |
adrian_otto | tcammann: can you check to see if you can reproduce? | 23:00 |
*** EricGonczer_ has joined #openstack-containers | 23:01 | |
adrian_otto | I am heading out to an appointment. Will regroup with you tonight or tomorrow. | 23:01 |
tcammann_ | adrian_otto: I have, there are no unique constraints on the db and raised bug 1451761 | 23:01 |
openstack | bug 1451761 in Magnum "Database does not have unique constraints" [Undecided,New] https://launchpad.net/bugs/1451761 | 23:01 |
tcammann_ | adrian_otto: sure | 23:02 |
adrian_otto | tcammann: I think that's the actual complaint | 23:02 |
adrian_otto | diga might be expecting names to be unique | 23:02 |
* adrian_otto bbl | 23:02 | |
juggler | ok o/ | 23:03 |
*** adrian_otto has quit IRC | 23:04 | |
*** tcammann_ has quit IRC | 23:07 | |
*** MilesDenver has quit IRC | 23:09 | |
*** jay-lau-513 has quit IRC | 23:26 | |
*** jay-lau-513 has joined #openstack-containers | 23:27 | |
Kennan2 | :juggler the ref is right, you can double check the context | 23:29 |
*** shakamunyi has quit IRC | 23:31 | |
*** rpothier has quit IRC | 23:37 | |
juggler | kennan2..hmm? | 23:37 |
Kennan2 | I checked you talked about adrian about the ref in guide | 23:38 |
Kennan2 | the ref is right in the manual guide | 23:38 |
*** Kennan2 is now known as Kennan | 23:38 | |
*** apmelton is now known as apmelton_away | 23:40 | |
*** sdake__ has quit IRC | 23:42 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!