*** zenoway has quit IRC | 00:02 | |
*** achanda has quit IRC | 00:03 | |
*** zenoway has joined #openstack-containers | 00:32 | |
*** eghobo has joined #openstack-containers | 00:34 | |
*** zenoway has quit IRC | 00:37 | |
*** zz_dimtruck is now known as dimtruck | 00:43 | |
*** jwcroppe has joined #openstack-containers | 00:44 | |
*** jwcroppe has quit IRC | 00:44 | |
*** jwcroppe has joined #openstack-containers | 00:44 | |
*** jwcroppe has quit IRC | 00:44 | |
*** jwcroppe has joined #openstack-containers | 00:45 | |
*** jwcroppe has quit IRC | 00:45 | |
*** eghobo has quit IRC | 00:55 | |
*** achanda has joined #openstack-containers | 01:01 | |
*** jwcroppe has joined #openstack-containers | 01:06 | |
*** jwcroppe has quit IRC | 01:06 | |
*** jwcroppe has joined #openstack-containers | 01:06 | |
*** jwcroppe has quit IRC | 01:06 | |
*** tbh has joined #openstack-containers | 01:15 | |
*** yamamoto has joined #openstack-containers | 01:16 | |
*** yamamoto has quit IRC | 01:28 | |
*** achanda has quit IRC | 01:39 | |
*** wangqun has joined #openstack-containers | 01:40 | |
*** eghobo has joined #openstack-containers | 01:42 | |
*** chuck_ has joined #openstack-containers | 01:50 | |
*** chuck_ has quit IRC | 01:50 | |
*** eghobo has quit IRC | 01:53 | |
*** jwcroppe has joined #openstack-containers | 01:56 | |
openstackgerrit | Merged openstack/python-magnumclient: Add marker/limit/sort-key/sort-dir features for container-list https://review.openstack.org/294439 | 02:09 |
---|---|---|
*** sdake has joined #openstack-containers | 02:11 | |
*** eghobo has joined #openstack-containers | 02:13 | |
*** eghobo has quit IRC | 02:16 | |
*** sdake has quit IRC | 02:18 | |
*** achanda has joined #openstack-containers | 02:26 | |
*** yamamoto has joined #openstack-containers | 02:29 | |
*** houming has joined #openstack-containers | 02:45 | |
*** dimtruck is now known as zz_dimtruck | 03:00 | |
*** eghobo has joined #openstack-containers | 03:00 | |
*** zenoway has joined #openstack-containers | 03:12 | |
*** zenoway has quit IRC | 03:17 | |
openstackgerrit | Aaron Ding proposed openstack/magnum: Fix config error https://review.openstack.org/298087 | 03:18 |
*** zz_dimtruck is now known as dimtruck | 03:25 | |
*** houming has quit IRC | 03:27 | |
*** dimtruck is now known as zz_dimtruck | 03:28 | |
*** houming has joined #openstack-containers | 03:28 | |
*** zz_dimtruck is now known as dimtruck | 03:28 | |
openstackgerrit | Eli Qiao proposed openstack/magnum: Cleanup duplicated auth_url in k8scluster/master template https://review.openstack.org/298092 | 03:35 |
*** dimtruck is now known as zz_dimtruck | 03:38 | |
*** achanda has quit IRC | 03:44 | |
*** ramishra has quit IRC | 03:47 | |
*** ramishra has joined #openstack-containers | 03:51 | |
*** yuanying has quit IRC | 03:53 | |
*** zz_dimtruck is now known as dimtruck | 03:59 | |
*** eghobo has quit IRC | 04:02 | |
*** eghobo has joined #openstack-containers | 04:12 | |
openstackgerrit | Merged openstack/python-magnumclient: Add marker/limit/sort-key/sort-dir features for bay-list https://review.openstack.org/294431 | 04:28 |
openstackgerrit | Merged openstack/python-magnumclient: Add missing user message https://review.openstack.org/295674 | 04:31 |
*** pgreg has joined #openstack-containers | 04:48 | |
*** yuanying has joined #openstack-containers | 04:56 | |
pgreg | Hi I like to help with adding some functionality/code-coverage tests, can anyone suggest where to start ? | 05:00 |
*** chandankumar has joined #openstack-containers | 05:06 | |
*** zenoway has joined #openstack-containers | 05:11 | |
*** zenoway has quit IRC | 05:15 | |
*** janki91 has joined #openstack-containers | 05:20 | |
*** dimtruck is now known as zz_dimtruck | 05:26 | |
*** achanda has joined #openstack-containers | 05:31 | |
*** ishant has joined #openstack-containers | 05:37 | |
openstackgerrit | Nguyen Hung Phuong proposed openstack/magnum: Fix typos in Magnum files https://review.openstack.org/298105 | 05:39 |
*** yuanying has quit IRC | 05:40 | |
*** yuanying has joined #openstack-containers | 05:48 | |
*** harshs has quit IRC | 05:51 | |
*** vimal has joined #openstack-containers | 06:05 | |
*** chandankumar has quit IRC | 06:09 | |
*** harlowja_at_home has quit IRC | 06:12 | |
*** zz_dimtruck is now known as dimtruck | 06:18 | |
eliqiao | pgreg: there is something I want to do to adding new functionality code coverage | 06:20 |
eliqiao | pgreg: the things are currently, we have bay created on gate (k8s/mesos/swarm), we can add some more test cases to check if the scripts we created in cloud-init are all there and the content are correct. | 06:21 |
pgreg | eliqiao, sure! I would like to help | 06:21 |
eliqiao | just my sugestion, if you wish you can bring it to weekly meeting to discuss about if worthy landing them. | 06:22 |
eliqiao | if you decide to do, you can start from https://github.com/openstack/magnum/blob/master/magnum/tests/functional/python_client_base.py , add some utils functional in to base class so for all 3 coes can share them. | 06:23 |
*** harlowja_at_home has joined #openstack-containers | 06:23 | |
pgreg | eliqiao, let me give it a try. | 06:25 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/magnum-ui: Imported Translations from Zanata https://review.openstack.org/297530 | 06:26 |
pgreg | eliqiao, "3 coes" ? | 06:27 |
pgreg | 3 cases | 06:27 |
eliqiao | 3 COES | 06:27 |
eliqiao | COEs | 06:27 |
eliqiao | swarm/mesos/k8s | 06:27 |
pgreg | eliqiao, i am still in the process of getting familiar with some of the terms | 06:28 |
eliqiao | pgreg: cool, no hurry. | 06:28 |
pgreg | eliqiao, is there a bug open for the ^^ | 06:29 |
eliqiao | pgreg: I don't think so. | 06:29 |
eliqiao | feel free to open a bug if you would like to do that. | 06:30 |
pgreg | eliqiao, ok np | 06:30 |
pgreg | eliqiao, sure think | 06:30 |
pgreg | thing* | 06:30 |
pgreg | eliqiao, while running `magnum service-list` i get "ERROR: Policy doesn't allow magnum-service:get_all to be performed (HTTP 403) (Request-ID: req-f8bde49f-0f21-4709-adf0-82b1e222b28a)" | 06:31 |
pgreg | Is there something, i am missing ? | 06:32 |
*** Marga_ has quit IRC | 06:32 | |
eliqiao | pgreg: are you using admin user? | 06:33 |
eliqiao | please check /etc/magnum/policy.json magnum-service:get_all | 06:33 |
eliqiao | that is an admin api --- "magnum-service:get_all": "rule:admin_api" | 06:34 |
*** chandankumar has joined #openstack-containers | 06:38 | |
pgreg | eliqiao, I was using an incorrect password ... thanks for pointing it out | 06:40 |
eliqiao | np | 06:44 |
*** pcaruana has joined #openstack-containers | 06:49 | |
openstackgerrit | Eli Qiao proposed openstack/magnum: Add insecure_registry column to baymoddel https://review.openstack.org/298124 | 07:00 |
openstackgerrit | Eli Qiao proposed openstack/magnum: Support using insecure registry for k8s COE https://review.openstack.org/298125 | 07:00 |
openstackgerrit | Eli Qiao proposed openstack/magnum: Support using insecure registry for swarm COE https://review.openstack.org/298126 | 07:00 |
openstackgerrit | Eli Qiao proposed openstack/magnum: Doc: Add docs on how to your private registry https://review.openstack.org/298127 | 07:00 |
openstackgerrit | Aaron Ding proposed openstack/magnum: Fix config error https://review.openstack.org/298087 | 07:09 |
openstackgerrit | Merged openstack/magnum: Add flannel's host-gw backend option https://review.openstack.org/241866 | 07:30 |
openstackgerrit | Eli Qiao proposed openstack/magnum: Support using insecure registry for k8s COE https://review.openstack.org/298125 | 07:32 |
openstackgerrit | Eli Qiao proposed openstack/magnum: Add insecure_registry column to baymoddel https://review.openstack.org/298124 | 07:32 |
openstackgerrit | Eli Qiao proposed openstack/magnum: Doc: Add docs on how to your private registry https://review.openstack.org/298127 | 07:32 |
openstackgerrit | Eli Qiao proposed openstack/magnum: Support using insecure registry for swarm COE https://review.openstack.org/298126 | 07:32 |
*** zenoway has joined #openstack-containers | 07:36 | |
eliqiao | wangqun: hi | 07:52 |
eliqiao | wangqun: for your reply on https://review.openstack.org/#/c/297908/1 . I don't get why you are saying the patch function only changes container_name (alough it is yes that we can find update_container_name from test case) | 07:54 |
pgreg | eliqiao, Is there a separate entry required for localrc.conf - while building devstack - i.e for getting the tempest pre-req's/repo into `/opt/stack/tempest` ... I am following this link (http://docs.openstack.org/developer/magnum/dev/dev-functional-test.html) but unable to find /opt/stack/tempest/etc/tempest.conf | 07:54 |
eliqiao | I have no comments on it, just would like some other reviewer giving some comments. | 07:55 |
eliqiao | pgreg: sorry, I don't quite get you. | 07:57 |
wangqun | hi eli, I find the unit test only have the update name unit test. I don't ensure if it can update others. | 07:57 |
eliqiao | what's functional testing are you trying to do? | 07:57 |
eliqiao | wangqun: but why not? | 07:58 |
eliqiao | test case is nothing......... | 07:58 |
wangqun | hmm... | 07:58 |
eliqiao | I am okay, just want to be clarify.. | 07:58 |
wangqun | I asked hongbin this quesion. https://bugs.launchpad.net/magnum/+bug/1561401 | 07:59 |
openstack | Launchpad bug 1561401 in Magnum "The container "Patch" function doesn't be used. We should delete it" [Undecided,In progress] - Assigned to wangqun (bjwqun) | 07:59 |
wangqun | I don't ensure if it is needed. | 08:00 |
wangqun | What do you think? | 08:00 |
pgreg | eliqiao, I am trying to run some of the existing tests to get a hang of it, which needs preparing the config-file, however I am unable to find (file from the link ^^^) | 08:01 |
pgreg | so just wondering if that is the correct place to start | 08:01 |
wangqun | Although the contain has the update function. I don't konw why we don't use it. | 08:01 |
eliqiao | wangqun: sure, remove it if it is useless, if someone requires it, they can add. | 08:03 |
wangqun | Ok | 08:03 |
eliqiao | pgreg: yes, you need to install tempest if you want to do functional.api test | 08:04 |
eliqiao | but you can play with functional-k8s/functional-swarm/functional-mesos without tempest installed. | 08:04 |
eliqiao | I don't think http://docs.openstack.org/developer/magnum/dev/dev-functional-test.html is well documented because it maxed tempest test and local functional test. | 08:05 |
pgreg | eliqiao, ok - but any pointers which would help me start off | 08:05 |
eliqiao | pgreg: just ignore tempest if you don't install it. you can try "tox -e functional-k8s -- --concurrency=1" first | 08:06 |
eliqiao | that will creat a bay and do some basic testing (I think only 3 or 4 cases) | 08:07 |
pgreg | ok let me try | 08:07 |
eliqiao | don't forget to update functional_creds.conf | 08:12 |
*** nihilifer has quit IRC | 08:16 | |
*** nihilifer has joined #openstack-containers | 08:17 | |
pgreg | eliqiao, http://pastebin.com/fa33eNdX, got some failures, not sure if there are related to missing dependencies ("No module named nose_plugin") | 08:17 |
eliqiao | pgreg: sorry, I can not access pastebin.com | 08:18 |
eliqiao | can you paste it in http://paste.openstack.org/ | 08:18 |
pgreg | eliqiao, sure no worries | 08:20 |
pgreg | http://paste.openstack.org/show/492011/ | 08:20 |
eliqiao | pgreg: have you do this: | 08:25 |
eliqiao | UPPER_CONSTRAINTS=/opt/stack/requirements/upper-constraints.txt | 08:25 |
eliqiao | sudo pip install -c $UPPER_CONSTRAINTS -U -r test-requirements.txt | 08:25 |
*** yuanying has quit IRC | 08:31 | |
*** yuanying has joined #openstack-containers | 08:31 | |
*** yuanying has quit IRC | 08:32 | |
pgreg | eliqiao, most of the deps are up-to-date, imo ... except for argparse and some warning which says "Ignoring dnspython3: markers u"python_version=='3.4'" don't match your environment" | 08:33 |
pgreg | however the same issue persists while running the tests | 08:33 |
pgreg | I have updated the contents of the above paste, plz have a look | 08:34 |
*** eghobo has quit IRC | 08:34 | |
*** GheRiver1 has joined #openstack-containers | 08:35 | |
pgreg | ... to get a better picture as I may be missing on the finer nuances | 08:35 |
*** yuanying has joined #openstack-containers | 08:39 | |
pgreg | eliqiao, As I could not find any reference to the error ... ("ERROR: Policy doesn't allow magnum-service:get_all to be performed (HTTP 403) (Request-ID: req-f8bde49f-0f21-4709-adf0-82b1e222b28a)") I can file bug for this | 08:49 |
pgreg | if you think it would be good idea to add include this error in the trouble shooting guide or doc ... | 08:49 |
*** tbh has quit IRC | 08:51 | |
*** noggin143 has joined #openstack-containers | 08:51 | |
*** vlaza has joined #openstack-containers | 08:52 | |
*** mikelk has joined #openstack-containers | 08:53 | |
*** mikelk has quit IRC | 08:55 | |
*** GheRivero has quit IRC | 08:57 | |
*** GheRivero has joined #openstack-containers | 09:00 | |
*** GheRiver1 has quit IRC | 09:03 | |
*** achanda has quit IRC | 09:04 | |
*** tbh has joined #openstack-containers | 09:05 | |
*** vilobhmm11 has quit IRC | 09:09 | |
*** noggin143 has left #openstack-containers | 09:10 | |
*** achanda has joined #openstack-containers | 09:11 | |
*** yuanying has quit IRC | 09:16 | |
*** shu-mutou has joined #openstack-containers | 09:18 | |
*** noggin143 has joined #openstack-containers | 09:24 | |
*** agireud has quit IRC | 09:27 | |
*** achanda has quit IRC | 09:28 | |
*** agireud has joined #openstack-containers | 09:28 | |
*** pcaruana has quit IRC | 09:42 | |
*** pcaruana has joined #openstack-containers | 09:55 | |
*** noggin143 has quit IRC | 09:56 | |
*** noggin143 has joined #openstack-containers | 10:06 | |
*** vimal has quit IRC | 10:09 | |
eliqiao | pgreg: can you try to install tempest and tempest-lib? | 10:11 |
openstackgerrit | wangqun proposed openstack/python-magnumclient: Fix the container-list with --limit 'a negative number' https://review.openstack.org/298186 | 10:14 |
eliqiao | wangqun: hi I don't hit this issue on https://bugs.launchpad.net/magnum/+bug/1562790 | 10:17 |
openstack | Launchpad bug 1562790 in Magnum ""magnum container-list --limit -1 --bay swarmbay" with the "--limit -1" can get the contianers" [Undecided,New] - Assigned to wangqun (bjwqun) | 10:17 |
*** vimal has joined #openstack-containers | 10:18 | |
wangqun | Hi Eli, You run the command "magnum container-list --limit -2 --bay swarmbay" and I can get them. | 10:20 |
wangqun | But the "limit" is a negtive number | 10:21 |
wangqun | Do you not hit it? | 10:22 |
*** sidx64 has joined #openstack-containers | 10:27 | |
*** achanda has joined #openstack-containers | 10:28 | |
sidx64 | Guys, can someone tell me what the [trust] section in Magnum.conf needs to have? I keep getting | 10:32 |
sidx64 | "TrusteeCreateFailed_Remote: Failed to create trustee in domain None" every time I try to create a mesos bay. | 10:32 |
*** achanda has quit IRC | 10:33 | |
*** mbound has joined #openstack-containers | 10:35 | |
*** achanda has joined #openstack-containers | 10:36 | |
eliqiao | wangqun: I commented on the bug | 10:39 |
eliqiao | python-magnum don't support --limit at all | 10:40 |
*** shu-mutou is now known as shu-mutou-AFK | 10:40 | |
wangqun | https://review.openstack.org/#/c/294439/ | 10:41 |
eliqiao | sidx64: You can try to use tox -egenconfig to get config file example | 10:41 |
wangqun | Hi Eli. These has been fixed | 10:41 |
eliqiao | wangqun: okay, let me update code | 10:42 |
sidx64 | eliqiao, I have the section in magnum, but I am unsure how to create a domain for this. | 10:47 |
sidx64 | I am trying to follow this: https://marc.ttias.be/openstack-dev/2016-02/msg02176.php | 10:48 |
sidx64 | but I cannot run openstack domain create command - It doesn't exist | 10:48 |
sidx64 | "openstack domain create magnum | 10:49 |
sidx64 | " | 10:49 |
sidx64 | eliqiao | 10:49 |
sidx64 | openstack: 'domain' is not an openstack command. See 'openstack --help' | 10:49 |
*** wangqun has quit IRC | 10:50 | |
*** yamamoto has quit IRC | 10:59 | |
*** janki91 has quit IRC | 11:02 | |
openstackgerrit | Merged openstack/magnum: Remove the "Patch" function https://review.openstack.org/297908 | 11:03 |
pgreg | eliqiao, I think this is related to another issue filed https://bugs.launchpad.net/magnum/+bug/1553035 | 11:03 |
openstack | Launchpad bug 1553035 in Magnum "Missing tempest package in test-requirement" [Undecided,New] - Assigned to Eli Qiao (taget-9) | 11:03 |
pgreg | eliqiao, "sudo pip install tempest tempest-lib" was successful | 11:04 |
pgreg | still the issue persists | 11:04 |
*** noggin143 has quit IRC | 11:05 | |
eliqiao | pgreg: can you try to load magnum in your python enviroment? | 11:08 |
eliqiao | tempest (10.0.0) | 11:08 |
eliqiao | tempest-lib (0.14.0) | 11:08 |
eliqiao | this is my version | 11:08 |
*** pcaruana has quit IRC | 11:09 | |
pgreg | $ pip freeze | grep tempest | 11:09 |
pgreg | tempest==10.0.0 | 11:09 |
pgreg | tempest-lib==1.0.0 | 11:09 |
eliqiao | sidx64: sorry, I don't know the detail, maybe you can turn to wanghua(the author) or hongbin for help. | 11:09 |
sidx64 | Sure thing :) thank you anyway | 11:10 |
*** achanda has quit IRC | 11:11 | |
eliqiao | pgreg: add tempest to test-requirements.txt, and rerun tox again | 11:12 |
eliqiao | tox is running in a virtual enviroment(not in your host) | 11:12 |
eliqiao | if that's not work, delete .tox and rerun tox | 11:12 |
*** noggin143 has joined #openstack-containers | 11:14 | |
openstackgerrit | Eli Qiao proposed openstack/magnum: Support using insecure registry for k8s COE https://review.openstack.org/298125 | 11:16 |
openstackgerrit | Eli Qiao proposed openstack/magnum: Add insecure_registry column to baymoddel https://review.openstack.org/298124 | 11:16 |
openstackgerrit | Eli Qiao proposed openstack/magnum: Doc: Add docs on how to your private registry https://review.openstack.org/298127 | 11:16 |
openstackgerrit | Eli Qiao proposed openstack/magnum: Support using insecure registry for swarm COE https://review.openstack.org/298126 | 11:16 |
*** noggin143 has quit IRC | 11:17 | |
*** pcaruana has joined #openstack-containers | 11:23 | |
pgreg | eliqiao, 'tox -e py27' goes through successfully, which installs all the deps, from test-req.txt, not the import error is not a issue any more ... | 11:23 |
pgreg | eliqiao, but still see a "RuntimeError: Not Authorized", so I tried "magnum service-list" which works fine, and re-checked ... | 11:24 |
pgreg | if I am using the admin credentials properly this time. | 11:24 |
*** chandankumar has quit IRC | 11:27 | |
*** chandankumar has joined #openstack-containers | 11:28 | |
pgreg | eliqiao, also 'tempest-lib==1.0.0' is not upgraded to 0.14.0 | 11:37 |
*** sid_cerner has joined #openstack-containers | 11:39 | |
*** wangqun has joined #openstack-containers | 11:40 | |
*** tbh has quit IRC | 11:49 | |
*** wangqun has quit IRC | 11:52 | |
*** noggin143 has joined #openstack-containers | 11:55 | |
*** pauloewerton has joined #openstack-containers | 11:55 | |
*** shu-mutou-AFK has quit IRC | 11:56 | |
*** houming has quit IRC | 12:07 | |
*** tbh has joined #openstack-containers | 12:08 | |
*** noggin143 has quit IRC | 12:09 | |
*** achanda has joined #openstack-containers | 12:12 | |
*** mbound has quit IRC | 12:15 | |
pgreg | eliqiao, was able to get the 4 tests working, looks like one of them still fails | 12:16 |
*** achanda has quit IRC | 12:17 | |
*** noggin143 has joined #openstack-containers | 12:20 | |
*** tbh has quit IRC | 12:27 | |
*** yamamoto has joined #openstack-containers | 12:28 | |
*** sergmelikyan has joined #openstack-containers | 12:30 | |
*** julim has joined #openstack-containers | 12:36 | |
*** mbound has joined #openstack-containers | 12:36 | |
*** pcaruana has quit IRC | 12:39 | |
*** yamamoto has quit IRC | 12:44 | |
*** yamamoto has joined #openstack-containers | 12:47 | |
*** yamamoto has quit IRC | 12:52 | |
*** pcaruana has joined #openstack-containers | 12:52 | |
*** jzb has quit IRC | 12:52 | |
*** mbound has quit IRC | 12:53 | |
*** yamamoto has joined #openstack-containers | 12:55 | |
*** kushal has quit IRC | 12:56 | |
*** rlrossit has joined #openstack-containers | 12:58 | |
*** dimtruck is now known as zz_dimtruck | 13:01 | |
*** gsagie has joined #openstack-containers | 13:04 | |
*** sidx64 has quit IRC | 13:04 | |
*** gsagie has left #openstack-containers | 13:05 | |
*** yamamoto has quit IRC | 13:12 | |
*** achanda has joined #openstack-containers | 13:15 | |
*** julim has quit IRC | 13:17 | |
*** yamamoto has joined #openstack-containers | 13:17 | |
*** kushal has joined #openstack-containers | 13:19 | |
*** achanda has quit IRC | 13:19 | |
*** yamamoto has quit IRC | 13:21 | |
*** julim has joined #openstack-containers | 13:23 | |
*** zz_dimtruck is now known as dimtruck | 13:24 | |
*** absubram has quit IRC | 13:24 | |
*** banix has joined #openstack-containers | 13:26 | |
*** ishant has quit IRC | 13:28 | |
*** sidx64 has joined #openstack-containers | 13:35 | |
*** noggin143 has quit IRC | 13:41 | |
*** noggin143 has joined #openstack-containers | 13:46 | |
*** vlaza has quit IRC | 13:46 | |
*** yamamoto has joined #openstack-containers | 13:47 | |
*** openstackgerrit has quit IRC | 13:48 | |
*** hongbin has joined #openstack-containers | 13:48 | |
*** openstackgerrit has joined #openstack-containers | 13:48 | |
*** dimtruck is now known as zz_dimtruck | 13:50 | |
*** sidx64 has quit IRC | 13:51 | |
*** yamamoto has quit IRC | 13:52 | |
*** mbound has joined #openstack-containers | 13:54 | |
*** chandankumar has quit IRC | 13:57 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 13:59 | |
*** apuimedo has joined #openstack-containers | 13:59 | |
*** mbound has quit IRC | 13:59 | |
*** yamamoto has joined #openstack-containers | 14:12 | |
*** muralia has joined #openstack-containers | 14:22 | |
*** muralia_ has quit IRC | 14:25 | |
*** adrian_otto has joined #openstack-containers | 14:26 | |
*** zz_dimtruck is now known as dimtruck | 14:27 | |
*** noggin143 has quit IRC | 14:29 | |
*** pauloewerton has quit IRC | 14:34 | |
*** rpothier has joined #openstack-containers | 14:35 | |
*** chandankumar has joined #openstack-containers | 14:41 | |
*** sdake has joined #openstack-containers | 14:42 | |
*** csoukup has joined #openstack-containers | 14:43 | |
*** sdake has quit IRC | 14:46 | |
*** sdake has joined #openstack-containers | 14:47 | |
*** jberkus has joined #openstack-containers | 14:50 | |
*** pauloewerton has joined #openstack-containers | 14:56 | |
*** fawadkhaliq has joined #openstack-containers | 14:58 | |
*** JoseMello has joined #openstack-containers | 15:01 | |
*** apuimedo has quit IRC | 15:07 | |
*** Marga_ has joined #openstack-containers | 15:12 | |
*** Marga_ has quit IRC | 15:13 | |
dims | hongbin : adrian_otto : is there a summary of significant changes for Magnum in Mitaka anywhere? | 15:13 |
*** Marga_ has joined #openstack-containers | 15:13 | |
adrian_otto | 2.0.0 release notes | 15:13 |
hongbin | No from me | 15:14 |
*** yamamoto has quit IRC | 15:16 | |
*** yamamoto has joined #openstack-containers | 15:17 | |
*** achanda has joined #openstack-containers | 15:17 | |
*** vimal has quit IRC | 15:19 | |
-openstackstatus- NOTICE: Gerrit is restarting on review.openstack.org in an attempt to address an issue reading an object from the ec2-api repository | 15:20 | |
*** yamamoto has quit IRC | 15:21 | |
*** achanda has quit IRC | 15:22 | |
*** absubram has joined #openstack-containers | 15:23 | |
*** pgreg_ has joined #openstack-containers | 15:25 | |
*** noggin143 has joined #openstack-containers | 15:25 | |
*** bpokorny has joined #openstack-containers | 15:26 | |
*** yamamoto has joined #openstack-containers | 15:28 | |
*** pgreg has quit IRC | 15:28 | |
*** fawadkhaliq has quit IRC | 15:28 | |
*** Drago1 has joined #openstack-containers | 15:32 | |
*** Drago1 has quit IRC | 15:32 | |
*** Drago1 has joined #openstack-containers | 15:32 | |
*** pgreg_ has quit IRC | 15:38 | |
*** gangil has joined #openstack-containers | 15:38 | |
*** gangil has quit IRC | 15:38 | |
*** gangil has joined #openstack-containers | 15:38 | |
*** pgreg has joined #openstack-containers | 15:38 | |
dims | adrian_otto : can't seem to find things today, can you please point me in the right direction? (url?) | 15:39 |
dims | adrian_otto : i see a list of bug id's in here - https://github.com/openstack/magnum/releases under 2.0.0 | 15:42 |
*** EricGonczer_ has joined #openstack-containers | 15:46 | |
*** malini has joined #openstack-containers | 15:47 | |
*** gangil has quit IRC | 15:49 | |
*** noggin143 has quit IRC | 15:53 | |
*** noggin143 has joined #openstack-containers | 15:55 | |
*** pgreg has quit IRC | 15:56 | |
*** askb has joined #openstack-containers | 15:57 | |
*** EricGonc_ has joined #openstack-containers | 15:58 | |
*** gordc has joined #openstack-containers | 15:59 | |
*** EricGonczer_ has quit IRC | 16:02 | |
*** jberkus has quit IRC | 16:05 | |
*** noggin143 has quit IRC | 16:06 | |
*** noggin143 has joined #openstack-containers | 16:08 | |
*** jberkus has joined #openstack-containers | 16:08 | |
*** adrian_otto has quit IRC | 16:09 | |
*** dimtruck is now known as zz_dimtruck | 16:13 | |
*** Marga_ has quit IRC | 16:13 | |
*** harshs has joined #openstack-containers | 16:16 | |
*** zenoway has quit IRC | 16:19 | |
*** adrian_otto has joined #openstack-containers | 16:24 | |
*** fawadkhaliq has joined #openstack-containers | 16:25 | |
*** madhuri has joined #openstack-containers | 16:28 | |
*** yamamoto has joined #openstack-containers | 16:28 | |
*** hieulq has joined #openstack-containers | 16:31 | |
*** gangil has joined #openstack-containers | 16:33 | |
*** gangil has quit IRC | 16:33 | |
*** gangil has joined #openstack-containers | 16:33 | |
*** harshs has quit IRC | 16:34 | |
*** zz_dimtruck is now known as dimtruck | 16:35 | |
*** harshs has joined #openstack-containers | 16:36 | |
*** yamamoto has quit IRC | 16:36 | |
*** noggin143 has quit IRC | 16:42 | |
*** david-lyle_ has joined #openstack-containers | 16:44 | |
*** david-lyle has quit IRC | 16:44 | |
*** noggin143 has joined #openstack-containers | 16:44 | |
*** noggin143 has quit IRC | 16:47 | |
*** malini has quit IRC | 16:47 | |
*** noggin143 has joined #openstack-containers | 16:47 | |
*** david-lyle has joined #openstack-containers | 16:48 | |
*** david-lyle_ has quit IRC | 16:49 | |
*** malini has joined #openstack-containers | 16:51 | |
*** noggin143 has quit IRC | 16:51 | |
*** tbh has joined #openstack-containers | 16:53 | |
*** noggin143 has joined #openstack-containers | 16:54 | |
*** harshs has quit IRC | 17:02 | |
*** Marga_ has joined #openstack-containers | 17:02 | |
*** malini has quit IRC | 17:06 | |
*** noggin143 has quit IRC | 17:08 | |
adrian_otto | coreyob: you around? | 17:12 |
adrian_otto | I wanted to ask you about your objection to https://review.openstack.org/259930 (Add docs for docker registry) | 17:13 |
*** EricGonc_ has quit IRC | 17:14 | |
*** sergmelikyan has quit IRC | 17:17 | |
*** noggin143 has joined #openstack-containers | 17:19 | |
*** noggin143 has quit IRC | 17:21 | |
*** achanda has joined #openstack-containers | 17:22 | |
*** david-lyle has quit IRC | 17:24 | |
*** noggin143 has joined #openstack-containers | 17:25 | |
*** david-lyle has joined #openstack-containers | 17:25 | |
*** achanda has quit IRC | 17:27 | |
*** noggin143 has quit IRC | 17:28 | |
openstackgerrit | Adrian Otto proposed openstack/magnum: Add docs for docker registry https://review.openstack.org/259930 | 17:29 |
coreyob | adrian_otto what objection? I don't see any comment from me on that change | 17:30 |
adrian_otto | oh, that's weird. | 17:32 |
adrian_otto | coreyob: here it is: https://review.openstack.org/254705 | 17:33 |
*** malini has joined #openstack-containers | 17:33 | |
adrian_otto | from 2016-01-07 | 17:33 |
*** suro-patz has joined #openstack-containers | 17:34 | |
coreyob | ah yeah that's the same security issue that I brought up at the midcycle. having that username and password on the box means anyone who has access to the cluster temporarily can grab those creds. then even after their own access is revoked, they retain access via that username/password | 17:36 |
coreyob | plus if the user that takes those credentials didn't already have access to swift or whatever other services that username/password have access to, they've just escalated to having access | 17:37 |
coreyob | but at this point, this has already merged https://review.openstack.org/#/c/261285 so the username and password are already on the cluster so the security issue already exists. adding another place that they are stored on the cluster doesn't make it any worse really | 17:38 |
coreyob | actually maybe that isn't true. that other change just created them, it didn't use them | 17:39 |
*** rods has joined #openstack-containers | 17:39 | |
coreyob | so maybe they aren't on the cluster yet | 17:39 |
adrian_otto | so can we make an actionable suggestion to make the feature possible without this risk, or a way to reduce the scope of the risk further? | 17:39 |
*** hieulq has quit IRC | 17:41 | |
coreyob | for the registry specifically I don't think there is a way to use swift as a backend without having a username and password on the cluster. the only way to fix it that I've thought of would be to block users of the cluster from accessing it by disabling sshd and blocking host filesystem mounting through docker | 17:44 |
*** Marga_ has quit IRC | 17:44 | |
*** Marga_ has joined #openstack-containers | 17:46 | |
*** achanda has joined #openstack-containers | 17:46 | |
*** abe_music has joined #openstack-containers | 17:46 | |
adrian_otto | the blocking of host filesystem mounting would need to be done with an apparmor or selinux rule, right? | 17:46 |
*** abe_music has quit IRC | 17:47 | |
*** sergmelikyan has joined #openstack-containers | 17:48 | |
coreyob | presumably. possible a docker authorization plugin, kernel-level stuff like apparmor and selinux would be better | 17:48 |
adrian_otto | so Magnum could have a 'secure bay' mode that works in this way that must be enabled before the docker registry v2 (docker distribution) feature can be turned on. | 17:48 |
adrian_otto | so you could have some bays that work in that way, and other bays that allow bind mounting | 17:48 |
*** malini has quit IRC | 17:49 | |
adrian_otto | I suppose that could be expressed as a baymodel flag | 17:49 |
coreyob | you could still allow mounting for everything except the path with the secrets presumably | 17:50 |
adrian_otto | or anything above it | 17:50 |
coreyob | true | 17:51 |
adrian_otto | so that leaves very little to allow | 17:51 |
coreyob | GETing the bay would have to hid the password too presumably since it is a bay attribute in that change | 17:51 |
adrian_otto | but we could move them somewhere else like /secrets | 17:51 |
adrian_otto | so you'd only need to prohibit /secrets and / | 17:51 |
coreyob | and if the registry was going to be run as a container, that would pose a problem too | 17:52 |
coreyob | because the password would be available in the container and users have access to the container | 17:52 |
*** malini has joined #openstack-containers | 17:53 | |
adrian_otto | so really the issue is that we don't have a way to create a trust token that only works for swift, and only for a specific use of swift | 17:53 |
coreyob | the option that we discussed at midcycle was actually around the CA sign process | 17:54 |
adrian_otto | no, thinking further it's worse | 17:54 |
adrian_otto | I see the issue with multi-user bays now. | 17:54 |
adrian_otto | if you have multiple users that each have access to a bay, and they can get access to the trust token, then they can fool with each others registry contents. Ick. | 17:55 |
coreyob | I'm recalling now that we talked about having the ca-sign be ephemeral so that we could easily rotate the CA to revoke access and we could restrict access to ca-sign to only users that had at least as much access as the trust so they couldn't escalate | 17:55 |
coreyob | although we have to be able to rotate the trust too, so n/m | 17:57 |
adrian_otto | how would we know the scope of access of the identity requesting ca-sign? | 17:57 |
coreyob | maybe I forgot some part of that solution | 17:57 |
*** gordc has left #openstack-containers | 17:57 | |
coreyob | so yeah the other thing we talked about like you said, was single-user bays so that the trust expired as soon as the user's creds were revoked in identity | 17:58 |
adrian_otto | I keep coming back to the thought that a "secure" bay can only allow single-user access. | 17:58 |
*** noggin143 has joined #openstack-containers | 17:58 | |
*** askb has quit IRC | 18:00 | |
coreyob | and by "secure" bay you mean one that maintains the security of keystone for the rest of the openstack cloud | 18:00 |
adrian_otto | yes | 18:01 |
*** sergmelikyan has quit IRC | 18:09 | |
*** sergmelikyan has joined #openstack-containers | 18:12 | |
*** david-lyle_ has joined #openstack-containers | 18:12 | |
*** david-lyle has quit IRC | 18:14 | |
*** rods has quit IRC | 18:15 | |
*** pcaruana has quit IRC | 18:16 | |
*** rods has joined #openstack-containers | 18:17 | |
*** JoseMello has quit IRC | 18:19 | |
*** rods has quit IRC | 18:21 | |
*** rods has joined #openstack-containers | 18:23 | |
*** EricGonczer_ has joined #openstack-containers | 18:26 | |
*** pcaruana has joined #openstack-containers | 18:30 | |
*** EricGonczer_ has quit IRC | 18:31 | |
*** Tango has joined #openstack-containers | 18:32 | |
*** EricGonczer_ has joined #openstack-containers | 18:32 | |
*** kdas_ has joined #openstack-containers | 18:33 | |
*** noggin143 has quit IRC | 18:33 | |
*** sdake_ has joined #openstack-containers | 18:34 | |
*** noggin143 has joined #openstack-containers | 18:34 | |
*** sdake_ has quit IRC | 18:35 | |
*** kushal has quit IRC | 18:35 | |
*** hongbin has quit IRC | 18:36 | |
*** hongbin has joined #openstack-containers | 18:36 | |
*** sdake has quit IRC | 18:37 | |
*** sergmelikyan has quit IRC | 18:37 | |
*** sdake has joined #openstack-containers | 18:39 | |
*** banix_ has joined #openstack-containers | 18:42 | |
*** banix has quit IRC | 18:43 | |
*** banix_ is now known as banix | 18:43 | |
*** sdake has quit IRC | 18:44 | |
*** sdake has joined #openstack-containers | 18:48 | |
*** madhuri has quit IRC | 18:48 | |
*** malini has quit IRC | 18:50 | |
*** achanda has quit IRC | 18:51 | |
*** achanda has joined #openstack-containers | 18:54 | |
*** fawadkhaliq has quit IRC | 18:55 | |
*** fawadkhaliq has joined #openstack-containers | 18:55 | |
*** eghobo has joined #openstack-containers | 18:58 | |
*** zenoway has joined #openstack-containers | 18:58 | |
*** vilobhmm11 has joined #openstack-containers | 19:02 | |
*** EricGonczer_ has quit IRC | 19:10 | |
*** vlaza has joined #openstack-containers | 19:13 | |
*** chandankumar has quit IRC | 19:19 | |
*** noggin143 has quit IRC | 19:24 | |
*** noggin143 has joined #openstack-containers | 19:26 | |
*** eghobo has quit IRC | 19:33 | |
*** sdake_ has joined #openstack-containers | 19:36 | |
*** fawadkhaliq has quit IRC | 19:38 | |
*** sdake has quit IRC | 19:38 | |
*** fawadkhaliq has joined #openstack-containers | 19:38 | |
*** zenoway has quit IRC | 19:40 | |
*** zenoway has joined #openstack-containers | 19:42 | |
*** eghobo has joined #openstack-containers | 19:42 | |
*** Drago2 has joined #openstack-containers | 19:43 | |
*** noggin143 has quit IRC | 19:43 | |
*** Drago2 has quit IRC | 19:44 | |
*** Drago2 has joined #openstack-containers | 19:44 | |
*** Drago1 has quit IRC | 19:45 | |
*** clenimar has quit IRC | 19:45 | |
*** harshs has joined #openstack-containers | 19:46 | |
*** omnipresent has joined #openstack-containers | 19:50 | |
*** omnipresent has quit IRC | 19:53 | |
*** zenoway has quit IRC | 19:53 | |
*** zenoway has joined #openstack-containers | 19:54 | |
*** vlaza has quit IRC | 19:58 | |
*** EricGonczer_ has joined #openstack-containers | 19:59 | |
*** sdake has joined #openstack-containers | 20:03 | |
*** sdake_ has quit IRC | 20:06 | |
*** omnipresent has joined #openstack-containers | 20:09 | |
*** zenoway_ has joined #openstack-containers | 20:12 | |
*** zenoway has quit IRC | 20:12 | |
*** omnipresent has quit IRC | 20:14 | |
*** vlaza has joined #openstack-containers | 20:16 | |
*** zenoway has joined #openstack-containers | 20:18 | |
*** zenoway_ has quit IRC | 20:20 | |
*** tbh has quit IRC | 20:20 | |
*** fawadkhaliq has quit IRC | 20:24 | |
*** fawadkhaliq has joined #openstack-containers | 20:25 | |
*** zenoway has quit IRC | 20:25 | |
*** vlaza has quit IRC | 20:27 | |
*** ybathia has joined #openstack-containers | 20:27 | |
*** zenoway has joined #openstack-containers | 20:28 | |
*** adrian_otto has quit IRC | 20:31 | |
*** suro-patz has quit IRC | 20:40 | |
*** sdake_ has joined #openstack-containers | 20:43 | |
openstackgerrit | Merged openstack/magnum: Remove minion dependency on master https://review.openstack.org/275405 | 20:43 |
*** sdake has quit IRC | 20:43 | |
*** banix has quit IRC | 20:49 | |
*** sergmelikyan has joined #openstack-containers | 20:50 | |
*** achanda has quit IRC | 20:52 | |
*** eil397 has joined #openstack-containers | 20:55 | |
*** eil397 has left #openstack-containers | 20:56 | |
*** suro-patz has joined #openstack-containers | 20:57 | |
*** harshs has quit IRC | 20:58 | |
*** fawadkhaliq has quit IRC | 20:59 | |
*** pauloewerton has quit IRC | 21:00 | |
*** fawadkhaliq has joined #openstack-containers | 21:00 | |
openstackgerrit | Merged openstack/magnum: Fix typos in Magnum files https://review.openstack.org/298105 | 21:04 |
*** achanda has joined #openstack-containers | 21:04 | |
*** rods has quit IRC | 21:05 | |
*** rods has joined #openstack-containers | 21:06 | |
*** Marga_ has quit IRC | 21:06 | |
*** Marga_ has joined #openstack-containers | 21:06 | |
*** harshs has joined #openstack-containers | 21:10 | |
Tango | Ping Yolanda | 21:14 |
*** EricGonczer_ has quit IRC | 21:14 | |
*** EricGonczer_ has joined #openstack-containers | 21:15 | |
*** julim has quit IRC | 21:18 | |
eghobo | hongbin: if i would like to run kub test at gate with fedora 23, what should i change? | 21:19 |
hongbin | eghobo: I guess you can submit a patch that depends on the fedora 23 patch | 21:20 |
Tango | eghobo: Do you mean the public Fedora Atomic 23 image? | 21:21 |
eghobo | yes, the same as i used for hw | 21:21 |
Tango | Coreyb has a patch for this: https://review.openstack.org/#/c/276232/ | 21:22 |
Tango | It just need some refactoring, as noted in the comment | 21:22 |
Tango | Basically removing several files which have been broken out into another patch which has merged | 21:23 |
eghobo | got it, thx | 21:23 |
*** EricGonczer_ has quit IRC | 21:27 | |
*** sdake_ is now known as sdake | 21:27 | |
*** bpokorny has quit IRC | 21:27 | |
*** bpokorny has joined #openstack-containers | 21:30 | |
*** suro-patz has quit IRC | 21:33 | |
*** ybathia has quit IRC | 21:33 | |
*** rpothier has quit IRC | 21:35 | |
*** achanda has quit IRC | 21:37 | |
*** sergmelikyan has quit IRC | 21:40 | |
*** Drago2 has quit IRC | 21:42 | |
*** Drago1 has joined #openstack-containers | 21:43 | |
*** ybathia has joined #openstack-containers | 21:50 | |
*** adrian_otto has joined #openstack-containers | 21:51 | |
*** adrian_otto has quit IRC | 21:54 | |
*** dflorea has joined #openstack-containers | 21:55 | |
*** suro-patz has joined #openstack-containers | 21:56 | |
*** adrian_otto has joined #openstack-containers | 21:57 | |
*** rlrossit has quit IRC | 22:01 | |
*** achanda has joined #openstack-containers | 22:04 | |
*** dimtruck is now known as zz_dimtruck | 22:15 | |
*** Marga_ has quit IRC | 22:19 | |
*** Marga_ has joined #openstack-containers | 22:19 | |
*** zenoway has quit IRC | 22:28 | |
*** zenoway has joined #openstack-containers | 22:31 | |
*** harlowja has joined #openstack-containers | 22:32 | |
*** harlowja has quit IRC | 22:32 | |
*** harlowja has joined #openstack-containers | 22:33 | |
*** mbound has joined #openstack-containers | 22:35 | |
*** zenoway has quit IRC | 22:36 | |
*** mbound has quit IRC | 22:39 | |
*** banix has joined #openstack-containers | 22:40 | |
*** fawadkhaliq has quit IRC | 22:48 | |
*** csoukup has quit IRC | 22:49 | |
*** fawadkhaliq has joined #openstack-containers | 22:49 | |
*** harlowja has quit IRC | 22:54 | |
*** harlowja has joined #openstack-containers | 22:54 | |
*** david-lyle_ is now known as david-lyle | 22:57 | |
*** Drago1 has quit IRC | 22:58 | |
*** bpokorny_ has joined #openstack-containers | 23:02 | |
*** bpokorny_ has quit IRC | 23:02 | |
*** bpokorny_ has joined #openstack-containers | 23:03 | |
*** ybathia has quit IRC | 23:04 | |
*** bpokorny has quit IRC | 23:04 | |
*** bpokorny_ has quit IRC | 23:11 | |
*** yuanying has joined #openstack-containers | 23:11 | |
*** ybathia has joined #openstack-containers | 23:13 | |
*** absubram has quit IRC | 23:15 | |
*** harshs has quit IRC | 23:20 | |
*** harlowja has quit IRC | 23:25 | |
*** harlowja has joined #openstack-containers | 23:25 | |
*** vilobhmm11 has quit IRC | 23:26 | |
*** jwcroppe_ has joined #openstack-containers | 23:27 | |
openstackgerrit | Merged openstack/magnum: Fix config error https://review.openstack.org/298087 | 23:29 |
openstackgerrit | Merged openstack/magnum: Cleanup duplicated auth_url in k8scluster/master template https://review.openstack.org/298092 | 23:29 |
*** jwcroppe has quit IRC | 23:30 | |
*** shakamunyi has joined #openstack-containers | 23:30 | |
*** barra204 has quit IRC | 23:32 | |
*** zenoway has joined #openstack-containers | 23:34 | |
*** zenoway has quit IRC | 23:39 | |
*** achanda has quit IRC | 23:41 | |
*** zz_dimtruck is now known as dimtruck | 23:44 | |
*** fawadkhaliq has quit IRC | 23:50 | |
*** fawadkhaliq has joined #openstack-containers | 23:50 | |
*** fawadkhaliq has quit IRC | 23:52 | |
*** fawadkhaliq has joined #openstack-containers | 23:52 | |
*** EricGonczer_ has joined #openstack-containers | 23:54 | |
*** hongbin has quit IRC | 23:56 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 23:58 | |
*** fawadkhaliq has quit IRC | 23:59 | |
*** fawadkhaliq has joined #openstack-containers | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!