*** hongbin has quit IRC | 00:11 | |
*** nick171 has joined #openstack-containers | 00:12 | |
*** catintheroof has joined #openstack-containers | 00:25 | |
*** vijaykc4 has joined #openstack-containers | 00:39 | |
*** adrian_otto has joined #openstack-containers | 00:41 | |
*** catintheroof has quit IRC | 01:02 | |
*** adrian_otto has quit IRC | 01:04 | |
*** NikhilS has joined #openstack-containers | 01:07 | |
*** dave-mccowan has quit IRC | 01:17 | |
*** ramishra has joined #openstack-containers | 01:20 | |
*** EricGonczer_ has joined #openstack-containers | 01:25 | |
*** vijaykc4 has quit IRC | 01:27 | |
*** EricGonczer_ has quit IRC | 01:40 | |
*** ramishra has quit IRC | 01:50 | |
*** harlowja has quit IRC | 02:06 | |
*** adrian_otto has joined #openstack-containers | 02:10 | |
*** adrian_otto has quit IRC | 02:23 | |
*** adrian_otto has joined #openstack-containers | 02:25 | |
*** swatson has quit IRC | 02:34 | |
*** hongbin has joined #openstack-containers | 02:36 | |
*** vijaykc4 has joined #openstack-containers | 02:38 | |
*** Drago1 has quit IRC | 02:38 | |
*** Drago1 has joined #openstack-containers | 02:38 | |
*** Drago1 has quit IRC | 02:43 | |
*** adrian_otto has quit IRC | 02:47 | |
*** harlowja has joined #openstack-containers | 02:50 | |
*** jwcroppe has quit IRC | 02:50 | |
*** jwcroppe has joined #openstack-containers | 02:51 | |
*** vijaykc4 has quit IRC | 03:05 | |
*** jwcroppe_ has joined #openstack-containers | 03:11 | |
*** jwcroppe has quit IRC | 03:13 | |
*** ramishra has joined #openstack-containers | 03:14 | |
*** vijaykc4 has joined #openstack-containers | 03:29 | |
*** trinaths has joined #openstack-containers | 03:51 | |
*** hongbin has quit IRC | 03:53 | |
*** hongbin has joined #openstack-containers | 03:53 | |
*** harlowja has quit IRC | 03:56 | |
*** aparnav has joined #openstack-containers | 03:56 | |
*** adrian_otto has joined #openstack-containers | 03:56 | |
*** vijaykc4 has quit IRC | 03:57 | |
*** hongbin has quit IRC | 04:07 | |
*** harlowja has joined #openstack-containers | 04:07 | |
*** Adri2000 has quit IRC | 04:17 | |
*** Adri2000 has joined #openstack-containers | 04:17 | |
*** harlowja has quit IRC | 04:33 | |
*** janki has joined #openstack-containers | 04:37 | |
*** rcernin has joined #openstack-containers | 04:46 | |
*** dimtruck is now known as zz_dimtruck | 04:48 | |
*** Jack_Iv has joined #openstack-containers | 04:56 | |
*** Jack_Iv_ has joined #openstack-containers | 04:57 | |
*** adrian_otto has quit IRC | 05:00 | |
*** Jack_Iv has quit IRC | 05:01 | |
*** jchhatbar has joined #openstack-containers | 05:05 | |
*** vishwana_ has joined #openstack-containers | 05:05 | |
*** Jack_Iv_ has quit IRC | 05:09 | |
*** rcernin has quit IRC | 05:09 | |
*** Jack_Iv has joined #openstack-containers | 05:10 | |
*** rcernin has joined #openstack-containers | 05:11 | |
*** harlowja has joined #openstack-containers | 05:11 | |
*** janki has quit IRC | 05:14 | |
*** vishwanathj has quit IRC | 05:14 | |
*** zhenguo has quit IRC | 05:14 | |
openstackgerrit | yatin proposed openstack/magnum master: Add kube dashboard and remove kube ui https://review.openstack.org/441046 | 05:15 |
---|---|---|
*** adisky_ has joined #openstack-containers | 05:15 | |
*** Jack_Iv has quit IRC | 05:15 | |
*** ramishra has quit IRC | 05:24 | |
*** vijaykc4 has joined #openstack-containers | 05:26 | |
*** Jack_Iv has joined #openstack-containers | 05:29 | |
*** mdnadeem has joined #openstack-containers | 05:31 | |
*** deu_ has quit IRC | 05:34 | |
*** deu_ has joined #openstack-containers | 05:34 | |
*** Jack_Iv_ has joined #openstack-containers | 05:39 | |
*** Jack_Iv has quit IRC | 05:43 | |
openstackgerrit | yatin proposed openstack/magnum master: Add kube dashboard and remove kube ui https://review.openstack.org/441046 | 05:45 |
*** madgoat has joined #openstack-containers | 05:53 | |
*** madgoat has left #openstack-containers | 05:53 | |
openstackgerrit | yatin proposed openstack/magnum master: [k8s_coreos] Add kubernetes dashboard https://review.openstack.org/449073 | 05:55 |
*** mjura has joined #openstack-containers | 05:57 | |
*** harlowja has quit IRC | 06:02 | |
*** Oku_OS-away is now known as Oku_OS | 06:08 | |
openstackgerrit | Merged openstack/magnum master: Format the quickstart doc https://review.openstack.org/431412 | 06:10 |
*** mjura has quit IRC | 06:17 | |
openstackgerrit | Madhuri Kumari proposed openstack/python-magnumclient master: Make cluster name positional in ca-show https://review.openstack.org/431431 | 06:26 |
*** Serlex has joined #openstack-containers | 06:40 | |
*** mjura has joined #openstack-containers | 06:43 | |
*** vijaykc4 has quit IRC | 06:54 | |
*** hishh has joined #openstack-containers | 06:59 | |
*** mjura has quit IRC | 07:03 | |
*** Jack_Iv_ has quit IRC | 07:04 | |
*** Jack_Iv has joined #openstack-containers | 07:04 | |
*** Jack_Iv has quit IRC | 07:05 | |
*** vijaykc4 has joined #openstack-containers | 07:05 | |
*** Jack_Iv has joined #openstack-containers | 07:05 | |
*** Jack_Iv_ has joined #openstack-containers | 07:06 | |
*** Jack_Iv has quit IRC | 07:10 | |
*** fungusakafungus has joined #openstack-containers | 07:11 | |
*** hishh has quit IRC | 07:12 | |
*** zhenguo has joined #openstack-containers | 07:15 | |
*** Jack_Iv has joined #openstack-containers | 07:16 | |
*** Jack_Iv_ has quit IRC | 07:18 | |
*** pcaruana has joined #openstack-containers | 07:19 | |
*** yasemin_ has joined #openstack-containers | 07:21 | |
yasemin_ | hi, do you know magnum is running successfully on ocata , devstack ? | 07:22 |
*** fungusak_ has joined #openstack-containers | 07:36 | |
*** fungusakafungus has quit IRC | 07:37 | |
*** fungusak_ has quit IRC | 07:39 | |
*** Jack_Iv has quit IRC | 07:44 | |
yasemin_ | i have bugs always :/ | 07:48 |
yatinkarel | going for it | 07:50 |
yatinkarel | yasemin_, it must be working | 07:51 |
*** vijaykc4 has quit IRC | 07:51 | |
*** Drago1 has joined #openstack-containers | 07:52 | |
*** amoralej|off is now known as amoralej | 07:53 | |
yasemin_ | yatinkarel, nova instances not showing and error is "Unable to retrieve instances" | 07:53 |
*** ianychoi has quit IRC | 07:54 | |
yatinkarel | yasemin_, then it must be nova issue | 07:54 |
*** vijaykc4 has joined #openstack-containers | 07:57 | |
yasemin_ | yatinkarel, in multinode devstack installation, magnum not install cluster on compute node ? is there any special services on compute nodes ? | 07:57 |
*** Drago2 has joined #openstack-containers | 07:57 | |
yatinkarel | no services related to magnum are required on compute node | 07:58 |
yatinkarel | magnum create cluster nodes, and these nodes can run on any compute node in the openstack setup | 07:59 |
*** Drago1 has quit IRC | 07:59 | |
yasemin_ | but magnum not create cluster on compute node, it gives n-cell error | 08:00 |
*** fungusakafungus has joined #openstack-containers | 08:02 | |
*** ssbarnea has joined #openstack-containers | 08:10 | |
yatinkarel | can you try without n-cell | 08:10 |
yatinkarel | yasemin_, if you try to create a nova instance(using nova boot, openstack server create) do you succeed | 08:12 |
yasemin_ | yatinkarel, yes, unless i add compute nodes, clusters are created | 08:14 |
*** ianychoi has joined #openstack-containers | 08:17 | |
*** dsariel has joined #openstack-containers | 08:23 | |
*** vijaykc4 has quit IRC | 08:25 | |
*** hishh has joined #openstack-containers | 08:27 | |
*** Jack_Iv has joined #openstack-containers | 08:28 | |
*** Jack_Iv has quit IRC | 08:28 | |
*** dsariel has quit IRC | 08:36 | |
yatinkarel | after adding compute node, do nova boot works? | 08:38 |
yasemin_ | no | 08:39 |
yatinkarel | then it's a nova issue for sure | 08:39 |
yatinkarel | your local.conf for controller and compute node? | 08:39 |
strigazi | yasemin_ magnum works fine in ocata | 08:40 |
yasemin_ | compute http://paste.openstack.org/show/605367/ , controller http://paste.openstack.org/show/605368/ | 08:40 |
*** vijaykc4 has joined #openstack-containers | 08:41 | |
*** dsariel has joined #openstack-containers | 08:43 | |
*** fungusakafungus has quit IRC | 08:51 | |
*** fungusakafungus has joined #openstack-containers | 08:52 | |
*** kevinz has joined #openstack-containers | 08:52 | |
*** fungusak_ has joined #openstack-containers | 08:54 | |
*** fungusakafungus has quit IRC | 08:54 | |
*** salmankhan has joined #openstack-containers | 08:56 | |
*** kevinz has quit IRC | 09:03 | |
*** kevinz has joined #openstack-containers | 09:04 | |
openstackgerrit | Mathieu Velten proposed openstack/magnum master: Fix usage of the trustee user in K8S Cinder plugin https://review.openstack.org/445404 | 09:05 |
*** vijaykc4 has quit IRC | 09:06 | |
*** yatinkarel has left #openstack-containers | 09:12 | |
*** yatinkarel has joined #openstack-containers | 09:12 | |
yatinkarel | yasemin_, Try with ENABLED_SERVICES=n-cpu,q-agt,dstat,placement-client in compute node | 09:13 |
*** vijaykc4 has joined #openstack-containers | 09:14 | |
*** Jack_Iv has joined #openstack-containers | 09:15 | |
*** Jack_Iv_ has joined #openstack-containers | 09:16 | |
openstackgerrit | Mathieu Velten proposed openstack/magnum master: Fix usage of the trustee user in K8S Cinder plugin https://review.openstack.org/445404 | 09:18 |
*** Jack_Iv has quit IRC | 09:19 | |
*** nick171 has quit IRC | 09:24 | |
yatinkarel | strigazi, ping | 09:29 |
strigazi | yatinkarel hi | 09:29 |
yatinkarel | strigazi, i was trying latest image, swarm was working | 09:29 |
yatinkarel | strigazi, k8s atomic also | 09:29 |
strigazi | ok | 09:29 |
yatinkarel | strigazi, but kubectl logs gives error | 09:30 |
strigazi | any problems? | 09:30 |
yatinkarel | strigazi, i remember it was fixed few days ago | 09:30 |
strigazi | This is a bit general | 09:30 |
strigazi | what errors? | 09:30 |
yatinkarel | dns error the same that vijendra fixed few days ago | 09:30 |
yatinkarel | [fedora@k8-abywpyo5b6-0-s6q76trpgyur-kube-master-ui72hds6uwf5 ~]$ kubectl logs kube-proxy-k8-icqu7ymrce-0-gum6irknh72f-kube-minion-zuuronasvbrw --namespace kube-system | 09:31 |
yatinkarel | Error from server: Get https://k8-icqu7ymrce-0-gum6irknh72f-kube-minion-zuuronasvbrw:10250/containerLogs/kube-system/kube-proxy-k8-icqu7ymrce-0-gum6irknh72f-kube-minion-zuuronasvbrw/kube-proxy: dial tcp: lookup k8-icqu7ymrce-0-gum6irknh72f-kube-minion-zuuronasvbrw on 8.8.8.8:53: no such host | 09:31 |
openstackgerrit | Mathieu Velten proposed openstack/magnum master: Fix usage of the trustee user in K8S Cinder plugin https://review.openstack.org/445404 | 09:31 |
strigazi | I don't think it related to the updated though | 09:32 |
strigazi | s/updated/update | 09:32 |
yatinkarel | May be | 09:33 |
yatinkarel | do you have a k8s cluster with latest image | 09:34 |
strigazi | in a bit I will | 09:34 |
yatinkarel | strigazi, ok try kubectl logs | 09:34 |
openstackgerrit | Mathieu Velten proposed openstack/magnum master: Fix usage of the trustee user in K8S Cinder plugin https://review.openstack.org/445404 | 09:37 |
openstackgerrit | Mathieu Velten proposed openstack/magnum master: Fix usage of the trustee user in K8S Cinder plugin https://review.openstack.org/445404 | 09:38 |
strigazi | yatinkarel in my devstack works | 09:39 |
yatinkarel | with latest image and hyperkube 1.5.3 | 09:40 |
strigazi | yatinkarel recreating | 09:43 |
yatinkarel | strigazi, Ok | 09:45 |
*** NikhilS has quit IRC | 10:01 | |
*** NikhilS has joined #openstack-containers | 10:01 | |
*** NikhilS has quit IRC | 10:02 | |
*** rpi has joined #openstack-containers | 10:04 | |
strigazi | yatinkarel I can't exec with -it but I can do cat for example | 10:05 |
yasemin_ | yatinkarel, okey i try it | 10:06 |
strigazi | yatinkarel I can do exec from insied the master | 10:08 |
strigazi | yatinkarel I can do exec from inside the master | 10:08 |
strigazi | yatinkarel with -it | 10:08 |
strigazi | yatinkarel it was something on my host. I can do it fine now | 10:10 |
strigazi | yatinkarel works fine for me | 10:11 |
strigazi | yatinkarel going out for lunch | 10:11 |
yatinkarel | strigazi, Ok then | 10:12 |
yatinkarel | strigazi, then there might be some issue with my environment, i will check that | 10:13 |
*** vijaykc4 has quit IRC | 10:25 | |
*** vijaykc4 has joined #openstack-containers | 10:25 | |
*** vijaykc4 has quit IRC | 10:26 | |
*** vijaykc4 has joined #openstack-containers | 10:26 | |
*** vijaykc4 has quit IRC | 10:27 | |
*** vijaykc4 has joined #openstack-containers | 10:27 | |
*** dsariel has quit IRC | 10:27 | |
*** vijaykc4 has quit IRC | 10:27 | |
*** Jack_Iv_ has quit IRC | 10:29 | |
*** Jack_Iv has joined #openstack-containers | 10:30 | |
*** Jack_Iv has quit IRC | 10:35 | |
*** fungusak_ has quit IRC | 10:44 | |
*** Jack_Iv has joined #openstack-containers | 10:47 | |
*** trinaths has left #openstack-containers | 10:49 | |
yatinkarel | strigazi, i tried with old image and hyperkube 1.5.2 and exec/log working. I will try again with latest image and hyperkube 1.5.3 | 10:55 |
*** Jack_Iv_ has joined #openstack-containers | 10:59 | |
*** Jack_Iv_ has quit IRC | 10:59 | |
*** Jack_Iv_ has joined #openstack-containers | 10:59 | |
*** Jack_Iv has quit IRC | 11:02 | |
*** manikanta_tadi has joined #openstack-containers | 11:10 | |
*** askb has quit IRC | 11:15 | |
yasemin_ | yatinkarel : i try it, but again error the same; Error: Failed to perform requested operation on instance "demo", the instance has an error status: Please try again later [Error: Host 'devstack-magnum-compute-4' is not mapped to any cell]. | 11:18 |
*** dave-mccowan has joined #openstack-containers | 11:21 | |
*** fungusakafungus has joined #openstack-containers | 11:21 | |
*** vijaykc4 has joined #openstack-containers | 11:28 | |
*** chhavi has joined #openstack-containers | 11:29 | |
yatinkarel | yasemin_, nova and devstack guys can help you out in this. Can you check with them | 11:31 |
yatinkarel | yasemin_, i am not getting why n-cells is enabled in your environment with the configuration shared by you | 11:34 |
yatinkarel | yasemin_, nova service-list can tell where your nova services lie | 11:34 |
*** mdnadeem has quit IRC | 11:36 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/magnum master: Updated from global requirements https://review.openstack.org/451021 | 11:39 |
yatinkarel | strigazi, i tried again with latest image and hyperkube 1.5.3, this time also same error | 11:41 |
strigazi | yatinkarel which pod exactly? | 11:43 |
yatinkarel | kubectl log kube-proxy-k8-aj4iynqn7s-0-lw5df6tikldo-kube-minion-dmoxgl53kbxw --namespace kube-system | 11:44 |
strigazi | yatinkarel so the minion kube-proxy | 11:44 |
strigazi | yatinkarel this is what I see http://paste.openstack.org/show/605388/ | 11:46 |
strigazi | yatinkarel serivces are accessible in my cluster, from inside and with kube proxy and with nodeport | 11:49 |
*** mdnadeem has joined #openstack-containers | 11:51 | |
*** Jack_Iv_ has quit IRC | 11:54 | |
*** EricGonczer_ has joined #openstack-containers | 11:54 | |
*** Jack_Iv has joined #openstack-containers | 11:54 | |
*** dsariel has joined #openstack-containers | 12:04 | |
*** vijaykc4 has quit IRC | 12:05 | |
*** catintheroof has joined #openstack-containers | 12:05 | |
*** vijaykc4 has joined #openstack-containers | 12:07 | |
*** amoralej is now known as amoralej|lunch | 12:08 | |
*** foutatoro has joined #openstack-containers | 12:09 | |
openstackgerrit | Colleen Murphy proposed openstack/magnum master: Fix database grant instructions in install guide https://review.openstack.org/453149 | 12:11 |
openstackgerrit | Kevin Lefevre proposed openstack/magnum master: Fix CoreOS cluster creation and heat notify https://review.openstack.org/445934 | 12:12 |
*** zz_dimtruck is now known as dimtruck | 12:16 | |
foutatoro | hi all, I've installed magnum in Prod environment using openstack-ansible but I always get this error "Failed to create certificates for Cluster" when trying to create a cluster | 12:18 |
foutatoro | does someone know what could cause this error ? | 12:19 |
ArchiFleKs | foutatoro: is your external API network on another network as the internal one ? | 12:20 |
ArchiFleKs | foutatoro: which branch ? | 12:20 |
foutatoro | ArchiFleKs: I'm using stable/newton | 12:22 |
ArchiFleKs | foutatoro: Magnum is sending the KEYSTONE_URL to the internal one, I think it is also the case for MAGNUM_URL, if you're instanecs cannot access the cluster internal URL, which is necessary to generate the certs it does not work | 12:22 |
foutatoro | ArchiFleKs: the external net is the one attached to linux bridge br-vlan | 12:23 |
ArchiFleKs | foutatoro: yes by default, can your instances reach keystone and magnum API via internal URL endpoints ? | 12:24 |
ArchiFleKs | if you are on fedora you can try try running the make-cert script in /var/lib/cloud/instance/ if think it is part-004 or part-005 with a bash -x part-00X and see a more detail error | 12:25 |
*** mdnadeem has quit IRC | 12:27 | |
foutatoro | ArchiFleKs: yes my instances can reach internal URL endpoints. openstack-ansible uses default self signed cert. does magnum use that ? | 12:28 |
foutatoro | I'm using ubuntu 16.04 | 12:29 |
*** ramishra has joined #openstack-containers | 12:29 | |
*** jchhatbar has quit IRC | 12:30 | |
*** EricGonczer_ has quit IRC | 12:32 | |
*** EricGonczer_ has joined #openstack-containers | 12:32 | |
ArchiFleKs | foutatoro: the curl command inside the scripts should be insecured but I do not know if thats the case in newton i'll check, can you run the script ? | 12:33 |
foutatoro | ArchiFleKs: whichscript ? | 12:34 |
openstackgerrit | Colleen Murphy proposed openstack/magnum master: Install client in install guide instructions https://review.openstack.org/453153 | 12:35 |
*** EricGonc_ has joined #openstack-containers | 12:36 | |
*** aparnav has quit IRC | 12:36 | |
ArchiFleKs | foutatoro: https://github.com/openstack/magnum/blob/stable/newton/magnum/drivers/common/templates/kubernetes/fragments/make-cert.sh I think in newton the curl are not insecure, one think you can do as a workaround is buil a custom fedora image with youe openstack-ansible custom CA inside for now :/ that what I did at first, now in master every request is insecure I think. If you're willinkg to | 12:36 |
ArchiFleKs | make loca patch you can use magnum_developer_mode with OSA | 12:36 |
*** EricGonczer_ has quit IRC | 12:37 | |
*** dimtruck is now known as zz_dimtruck | 12:40 | |
*** Jack_Iv has quit IRC | 12:43 | |
*** Jack_Iv has joined #openstack-containers | 12:43 | |
foutatoro | ArchiFleKs: I don't understand what's this script is supposed to do. how to set magnum_developer_mode with OSA ? | 12:44 |
*** mdnadeem has joined #openstack-containers | 12:45 | |
*** janki has joined #openstack-containers | 12:45 | |
*** Jack_Iv has quit IRC | 12:51 | |
*** jwcroppe_ has quit IRC | 12:52 | |
*** Jack_Iv has joined #openstack-containers | 12:52 | |
*** Jack_Iv has quit IRC | 12:53 | |
*** Jack_Iv has joined #openstack-containers | 12:53 | |
*** vijaykc4 has quit IRC | 13:02 | |
*** Jack_Iv has quit IRC | 13:02 | |
*** jchhatbar has joined #openstack-containers | 13:05 | |
*** belmoreira has joined #openstack-containers | 13:07 | |
*** janki has quit IRC | 13:07 | |
ArchiFleKs | foutatoro: the script is talking to keystone to get a token and then to magnum to generate the TLS requiered for Kubernetes and ETCD | 13:08 |
*** Jack_Iv has joined #openstack-containers | 13:11 | |
*** zul has quit IRC | 13:12 | |
yatinkarel | strigazi, this is what i get with latest image and your patch: http://paste.openstack.org/show/605401/ | 13:12 |
*** jwcroppe has joined #openstack-containers | 13:12 | |
*** Jack_Iv has quit IRC | 13:12 | |
strigazi | yatinkarel You are in devstack? It look in 8.8.8.8 for the host. I'm surpirsed that it works with the old image | 13:14 |
*** amoralej|lunch is now known as amoralej | 13:14 | |
yatinkarel | strigazi, yes it works | 13:14 |
strigazi | yatinkarel Try do delete that proxy | 13:14 |
strigazi | kubelet will recreate is | 13:15 |
strigazi | kubelet will recreate it | 13:15 |
*** Jack_Iv has joined #openstack-containers | 13:15 | |
yatinkarel | earlier i used to get the same error, but after vijendra's patch https://review.openstack.org/#/c/439906/ it got resolved | 13:16 |
yatinkarel | Ok will try deleting | 13:16 |
yatinkarel | I deleted and it got recreated | 13:17 |
yatinkarel | strigazi, still same dns error when i run kubectl logs | 13:18 |
yatinkarel | foutatoro, did you got any nova instance after running cluster-create? | 13:18 |
foutatoro | yatinkarel: no I didn't get instancew | 13:19 |
yatinkarel | ArchiFleKs, ^^ | 13:20 |
yatinkarel | foutatoro, what's the exact error you saw | 13:20 |
foutatoro | I get "Failed to create certificates for Cluster" after running cluster-create | 13:22 |
yatinkarel | any logs from magnum-conductor? | 13:23 |
yatinkarel | and in barbican? | 13:23 |
*** Drago2 has quit IRC | 13:24 | |
foutatoro | yatinkarel: here are logs http://paste.openstack.org/show/605404/ | 13:28 |
ArchiFleKs | foutatoro: oh ok for the instances, that make sens ^^ | 13:29 |
yatinkarel | AuthorizationFailure: unexpected keystone client error occurred: internalURL endpoint for key-manager service not found | 13:30 |
yatinkarel | foutatoro, output of, openstack catalog list | 13:31 |
foutatoro | I don't know why magnum use certs to run clusters ? | 13:31 |
foutatoro | yatinkarel: http://paste.openstack.org/show/605405/ | 13:32 |
*** zul has joined #openstack-containers | 13:32 | |
*** jchhatbar has quit IRC | 13:32 | |
*** jmlowe has quit IRC | 13:32 | |
yatinkarel | foutatoro, you don't have endpoint for barbican service | 13:34 |
yatinkarel | that's why it failed | 13:34 |
foutatoro | yatinkarel: Is barbican to run cluster ? | 13:34 |
yatinkarel | for storing certs | 13:35 |
ArchiFleKs | foutatoro: redploy magnum using x509keypair, you can do it with user_variables in osa, magnum_cert_manager_type: x509keypair | 13:35 |
yatinkarel | for now you can try without barbican | 13:35 |
yatinkarel | ArchiFleKs, is correct try this | 13:35 |
yatinkarel | i think it's not required to redeploy, try updating magnum.conf and restarting magnum-api and magnum-conductor | 13:36 |
ArchiFleKs | foutatoro: it is fix in ocata but not in newton https://review.openstack.org/#/c/408627/ | 13:36 |
foutatoro | yatinkarel ArchiFleKs: Ok thanks I will redeploy magnum. So cloud you explain why magnum required certs to run cluster ? | 13:37 |
ArchiFleKs | foutatoro: just redeploy magnum or if you are in AIO you can fix it inside magnum container | 13:37 |
foutatoro | ArchiFleKs: yes I'm in AIO now | 13:38 |
ArchiFleKs | foutatoro: yatinkarel correct me if i'm wrong, magnum is managing a custom CA per cluster to enable TLS inside your cluster (for kubernetes API and ETCD), so your master and worker get a token from keystone, then ask magnum to sign some CSR with the cluster CA | 13:38 |
yatinkarel | foutatoro, may be this answers https://docs.openstack.org/developer/magnum/dev/quickstart.html#using-a-kubernetes-cluster | 13:38 |
ArchiFleKs | yatinkarel, strigazi : sorry for the delay I finally did the changes to fix CoreOS https://review.openstack.org/#/c/445934/ | 13:41 |
yatinkarel | ArchiFleKs, certs description looks correct. | 13:44 |
*** dsariel has quit IRC | 13:45 | |
yatinkarel | strigazi, can confirm more on this | 13:45 |
yatinkarel | strigazi, do cluster ca created for tls-disabled cluster as well | 13:45 |
*** jmckind has joined #openstack-containers | 13:46 | |
*** kevinz has quit IRC | 13:50 | |
yatinkarel | strigazi, do you know for what ca is created in tls-disabled cluster | 13:51 |
openstackgerrit | Jason Dunsmore proposed openstack/python-magnumclient master: Make --cluster option required for ca-rotate https://review.openstack.org/451942 | 13:54 |
strigazi | yatinkarel AFAIK it doesn't | 13:54 |
*** jwcroppe has quit IRC | 14:00 | |
*** jwcroppe has joined #openstack-containers | 14:02 | |
*** janki has joined #openstack-containers | 14:03 | |
*** jasond has joined #openstack-containers | 14:04 | |
*** jmlowe has joined #openstack-containers | 14:05 | |
*** mdnadeem has quit IRC | 14:07 | |
yatinkarel | strigazi, what does following command do, magnum ca-show --cluster <tls-disabled-cluster> | 14:08 |
foutatoro | yatinkarel ArchiFleKs: I still get the same error after redeploying magnum with magnum_cert_manager_type: x509keypair | 14:12 |
foutatoro | http://paste.openstack.org/show/605411/ | 14:12 |
yatinkarel | foutatoro, your magnum.conf? | 14:17 |
foutatoro | yatinkarel: http://paste.openstack.org/show/605412/ | 14:18 |
yatinkarel | foutatoro, [certificates] section is missing, there must be some bug in your deployment method | 14:21 |
*** jmlowe has quit IRC | 14:21 | |
*** jmlowe has joined #openstack-containers | 14:21 | |
yatinkarel | [certificates] | 14:21 |
yatinkarel | cert_manager_type = barbican | 14:21 |
yatinkarel | barbican --> local | 14:21 |
foutatoro | yatinkarel: barbian is not running in my env | 14:22 |
foutatoro | it should be : cert_manager_type =local ? | 14:22 |
yatinkarel | yes | 14:22 |
yatinkarel | post this restart magnum-api and magnum-conductor | 14:22 |
foutatoro | ok thanks. But is there a guide explaining how to deploy magnum with openstack-ansible ? | 14:23 |
*** janki has quit IRC | 14:23 | |
yatinkarel | No idea, ArchiFleKs do you know ^^ | 14:24 |
*** dsariel has joined #openstack-containers | 14:24 | |
*** janki has joined #openstack-containers | 14:29 | |
ArchiFleKs | foutatoro: I'm not sure there is full guide, but you have the role https://docs.openstack.org/developer/openstack-ansible-os_magnum/ | 14:31 |
ArchiFleKs | and you also can get some example in the openstack ansible repo, in the case of your AIO you can check inside /etc/openstack_deploy/conf.d there is also example for each service in the openstack ansible-ansible repo in ./etc/conf.d i think | 14:32 |
ArchiFleKs | foutatoro: https://github.com/openstack/openstack-ansible/tree/master/etc/openstack_deploy/conf.d | 14:33 |
*** ssbarnea has quit IRC | 14:34 | |
ArchiFleKs | foutatoro: prefer x509keypair, local is working but only in AIO because you have only one magnum container | 14:34 |
*** EricGonc_ has quit IRC | 14:34 | |
*** chhavi has quit IRC | 14:34 | |
ArchiFleKs | foutatoro: is there a particular for you to deploy neutron and not ocata ? there were lot of fixes between openstack-ansible_os-magnum and magnum on ocata | 14:35 |
foutatoro | ArchiFleKs yatinkarel: cluster creation fails after setting cert_manager_type = local but the logs are differents. It seems thats magnum can not store certs http://paste.openstack.org/show/605415/ | 14:35 |
ArchiFleKs | s/neutron/newton | 14:35 |
*** EricGonczer_ has joined #openstack-containers | 14:36 | |
ArchiFleKs | foutatoro: maybe try to create the directory inside the magnum container, or add magnum_cert_manager_type: x509keypair inside /etc/openstack_deploy/user_variables.yml and then run openstack-ansible os-magnum.yml | 14:36 |
*** zz_dimtruck is now known as dimtruck | 14:37 | |
*** fungusakafungus has left #openstack-containers | 14:37 | |
*** hongbin has joined #openstack-containers | 14:37 | |
foutatoro | ArchiFleKs yatinkarel: Thanks guys. I will upgrade to ocata | 14:38 |
foutatoro | to avoid certs issues | 14:38 |
*** jmlowe has quit IRC | 14:44 | |
*** jmlowe has joined #openstack-containers | 14:44 | |
*** janki has quit IRC | 14:48 | |
*** jmlowe has quit IRC | 14:51 | |
*** jmlowe has joined #openstack-containers | 14:52 | |
*** janki has joined #openstack-containers | 14:52 | |
ArchiFleKs | yatinkarel: strigazi : we are not testing multi master in jenkins ? I've run some test and report this bug I was telling you about laste week https://bugs.launchpad.net/magnum/+bug/1679724 | 14:53 |
openstack | Launchpad bug 1679724 in Magnum "multi master cluster creation fails with ETCD LB" [Undecided,New] | 14:53 |
ArchiFleKs | about etcd LB being hardcoded to HTTP | 14:53 |
strigazi | ArchiFleKs no | 14:53 |
strigazi | ArchiFleKs we didn't have resources | 14:53 |
strigazi | ArchiFleKs no with multinode jobs we might be able to test but it's still difficult | 14:54 |
ArchiFleKs | Ok so I'm not 100% percent sure but I think that multi master with LB with TLS enable and ETCD LB with HTTP might have never work, do you know if it ever has ? | 14:54 |
strigazi | ArchiFleKs I haven't tested etcd with lb and tls | 14:56 |
yatinkarel | ArchiFleKs, i am also not sure about this | 14:56 |
strigazi | ArchiFleKs, yatinkarel we maybe able to remove etcd lb | 14:56 |
strigazi | ArchiFleKs, yatinkarel in recent etcd versions you can specify all etcd endpoints | 14:57 |
strigazi | ArchiFleKs, yatinkarel no need for lb | 14:57 |
ArchiFleKs | I have just tested with fedora | 14:57 |
yatinkarel | strigazi, if it works we can | 14:57 |
ArchiFleKs | strigazi: yes but you have to deal with master update non ? | 14:57 |
yatinkarel | strigazi, we need to specify in kube, swarm config | 14:58 |
strigazi | ArchiFleKs we don't scale the masters at the moment. In that case maybe it's a problem | 14:58 |
ArchiFleKs | I think we can keep lb for ETCD, like the LB for the kubernetes API (https://review.openstack.org/#/c/450841/) | 14:58 |
ArchiFleKs | We have to find a way to add the VIP to the certificates, but that should be an issue because when we generate certs on master node we already now the etcd lb ip right ? | 14:59 |
strigazi | ArchiFleKs etcd lb works in coreos? | 14:59 |
ArchiFleKs | strigazi: nope it is hardcoded in HTTP in every template | 14:59 |
strigazi | ArchiFleKs I mean with your pathc | 15:00 |
strigazi | ArchiFleKs I mean with your patch | 15:00 |
strigazi | ArchiFleKs we know the etcd lb ip | 15:00 |
ArchiFleKs | TLS is working yes but the certs is not valid because we do not add the IP of the etcd lb vip in the make-cert scripts | 15:00 |
yatinkarel | ArchiFleKs, VIP must be added with current code | 15:00 |
ArchiFleKs | yes i'll try that | 15:00 |
strigazi | ArchiFleKs ok | 15:01 |
strigazi | ArchiFleKs you can add it :) | 15:01 |
ArchiFleKs | i'm not sure it passed as heat param for the master, just for the minions | 15:01 |
yatinkarel | ArchiFleKs, Yes it might be. Ok go on with the fix | 15:01 |
ArchiFleKs | oh and another thing i'll file a bug to but since grafan has been merged it also breaks Coreos because we share the K8s_template_def.py between drivers and the label are only available in fedora but not for Coreos so cluster creation is failing, maybe we can move label specific to drivers inside fedora-template-def.py ? | 15:05 |
*** jwcroppe has quit IRC | 15:05 | |
ArchiFleKs | strigazi: yatinkarel http://paste.openstack.org/show/605422/ | 15:06 |
*** Oku_OS is now known as Oku_OS-away | 15:06 | |
strigazi | ArchiFleKs I prefer to put the paremetes in coreos and default to "" | 15:06 |
ArchiFleKs | strigazi: ok :) | 15:07 |
*** jwcroppe has joined #openstack-containers | 15:07 | |
*** flwang has quit IRC | 15:07 | |
yatinkarel | ArchiFleKs, i can't find change id: Ibcb694eddc20a9344f2d951d6664b32adad3c3d5, for what was it? | 15:10 |
yatinkarel | ArchiFleKs, Got it. | 15:11 |
*** Guest52040 has joined #openstack-containers | 15:12 | |
yatinkarel | ArchiFleKs, it's the same thing we discussed on: https://review.openstack.org/#/c/426291/ | 15:16 |
ArchiFleKs | yatinkarel: oh yes I did catch up with everything :) | 15:18 |
ArchiFleKs | not | 15:18 |
*** jmlowe has quit IRC | 15:19 | |
*** jmlowe has joined #openstack-containers | 15:19 | |
*** hishh has quit IRC | 15:20 | |
*** flwang has joined #openstack-containers | 15:20 | |
*** jmlowe has quit IRC | 15:22 | |
*** Jack_Iv_ has joined #openstack-containers | 15:22 | |
*** jmlowe has joined #openstack-containers | 15:22 | |
*** Jack_Iv__ has joined #openstack-containers | 15:22 | |
*** Jack_Iv__ has quit IRC | 15:24 | |
*** belmoreira has quit IRC | 15:24 | |
*** Jack_Iv has quit IRC | 15:24 | |
*** Jack_Iv has joined #openstack-containers | 15:24 | |
*** Jack_Iv_ has quit IRC | 15:25 | |
*** Jack_Iv has quit IRC | 15:25 | |
*** Jack_Iv has joined #openstack-containers | 15:25 | |
*** jmlowe has quit IRC | 15:31 | |
*** jmlowe has joined #openstack-containers | 15:32 | |
*** foutatoro has quit IRC | 15:33 | |
*** ssbarnea has joined #openstack-containers | 15:38 | |
ArchiFleKs | strigazi: I have heat dependencies issue when trying https://github.com/ArchiFleKs/magnum/commit/1c5d47b4e16e30caf478ebbdddd56940107c704c http://paste.openstack.org/show/605427/ I think because de lb_switch need the master created and I need to path the lb private ip to master | 15:38 |
*** Jack_Iv has quit IRC | 15:48 | |
*** jmlowe has quit IRC | 15:51 | |
*** EricGonczer_ has quit IRC | 15:53 | |
*** juggler has joined #openstack-containers | 15:54 | |
*** tonanhngo has joined #openstack-containers | 15:54 | |
*** tonanhngo has quit IRC | 15:54 | |
*** tonanhngo has joined #openstack-containers | 15:56 | |
*** hieulq_ has joined #openstack-containers | 15:56 | |
*** aparnav has joined #openstack-containers | 15:57 | |
*** vijaykc4 has joined #openstack-containers | 15:58 | |
openstackgerrit | Spyros Trigazis proposed openstack/magnum master: [WIP] Add cluster_attributes table and migrate data https://review.openstack.org/395012 | 15:58 |
*** hieulq__ has joined #openstack-containers | 15:58 | |
*** EricGonczer_ has joined #openstack-containers | 15:59 | |
*** aparna has joined #openstack-containers | 16:00 | |
*** pcaruana has quit IRC | 16:01 | |
*** aparnav has quit IRC | 16:02 | |
*** hieulq_ has quit IRC | 16:02 | |
*** aparna has quit IRC | 16:03 | |
*** swatson has joined #openstack-containers | 16:03 | |
swatson | #openstack-meeting-alt | 16:03 |
swatson | ...I forgot /join, my bad | 16:03 |
*** ArchiFleKs has quit IRC | 16:04 | |
*** EricGonc_ has joined #openstack-containers | 16:06 | |
*** ArchiFleKs has joined #openstack-containers | 16:06 | |
*** EricGonczer_ has quit IRC | 16:06 | |
*** Jack_Iv has joined #openstack-containers | 16:09 | |
*** EricGonczer_ has joined #openstack-containers | 16:11 | |
*** EricGonc_ has quit IRC | 16:12 | |
*** aparnav has joined #openstack-containers | 16:19 | |
*** hieulq__ has quit IRC | 16:21 | |
*** hieulq__ has joined #openstack-containers | 16:22 | |
*** hieulq__ has quit IRC | 16:25 | |
*** janki has quit IRC | 16:26 | |
*** Jack_Iv has quit IRC | 16:27 | |
strigazi | We can update update master and ocata first. We can see for newton. yatinkarel Push a patch if you want. I'll do it as soon as I can | 16:31 |
yatinkarel | strigazi, In newton do we need :Z | 16:33 |
strigazi | with f25 yes | 16:33 |
yatinkarel | https://review.openstack.org/#/c/452763/ | 16:33 |
strigazi | swarm can work with f25 without any chnages onlt :Z | 16:33 |
strigazi | swarm can work with f25 without any chnages only :Z | 16:33 |
strigazi | hence https://review.openstack.org/#/c/452763/ | 16:34 |
yatinkarel | have you tried this change in newton with fedora 25? | 16:35 |
strigazi | yatinkarel no, but the changes are almost none | 16:36 |
*** juggler has quit IRC | 16:36 | |
yatinkarel | strigazi, i told you about 2 bugs earlier, i think they are required in newton for 25 to work | 16:37 |
*** chhavi has joined #openstack-containers | 16:38 | |
strigazi | yatinkarel About the disk space? | 16:38 |
yatinkarel | no | 16:39 |
strigazi | yatinkarel can you send them again? | 16:39 |
yatinkarel | Ok | 16:39 |
*** mtanino has joined #openstack-containers | 16:39 | |
yatinkarel | https://bugs.launchpad.net/magnum/+bug/1658049 | 16:40 |
openstack | Launchpad bug 1658049 in Magnum "swarm node error, swarm-agent.service: Failed at step EXEC spawning /usr/local/bin/notify-heat: Permission denied" [Undecided,Confirmed] | 16:40 |
yatinkarel | https://bugs.launchpad.net/magnum/+bug/1658010 | 16:40 |
openstack | Launchpad bug 1658010 in Magnum "swarm-docker status dead" [Undecided,New] | 16:40 |
strigazi | yatinkarel 1658049 | 16:40 |
strigazi | yatinkarel 1658049 will be closed with the new image, without any change | 16:41 |
yatinkarel | Ok | 16:41 |
yatinkarel | and 1658010 | 16:42 |
strigazi | I'll have to check if that fix is enough. | 16:42 |
yatinkarel | Ok | 16:42 |
strigazi | Some chnages will be required. But only a few I believe | 16:43 |
yatinkarel | hmm | 16:43 |
yatinkarel | is the CVE fix isn't backported to fedora 23? | 16:43 |
yatinkarel | we can create it again and add it to fedorapeople | 16:43 |
*** Jack_Iv has joined #openstack-containers | 16:45 | |
strigazi | yatinkarel I am not sure what fixes are included in f23. I think they don't support f23 for long | 16:45 |
strigazi | yatinkarel https://fedoraproject.org/wiki/End_of_life they don't support f23 any more | 16:46 |
yatinkarel | Ok then we should add support for latest fedora | 16:46 |
strigazi | yeap | 16:47 |
strigazi | What ever fix we need we must backport to not force users use an oudated OS | 16:47 |
yatinkarel | Ok | 16:48 |
strigazi | yatinkarel I have to go, see you later or tomorrow | 16:48 |
yatinkarel | Me too. Bye | 16:48 |
*** Jack_Iv has quit IRC | 16:50 | |
*** aparnav has quit IRC | 16:51 | |
*** jmckind_ has joined #openstack-containers | 17:03 | |
*** jmckind has quit IRC | 17:05 | |
*** Jack_Iv has joined #openstack-containers | 17:09 | |
*** vijaykc4 has quit IRC | 17:14 | |
*** Jack_Iv has quit IRC | 17:15 | |
*** salmankhan has quit IRC | 17:16 | |
*** amoralej is now known as amoralej|off | 17:20 | |
*** vijaykc4 has joined #openstack-containers | 17:26 | |
*** Guest52040 has quit IRC | 17:28 | |
*** tonanhngo has quit IRC | 17:29 | |
*** jvgrant_ has quit IRC | 17:35 | |
*** jvgrant has joined #openstack-containers | 17:35 | |
*** randallburt has joined #openstack-containers | 17:35 | |
*** chhavi has quit IRC | 17:36 | |
*** dsariel has quit IRC | 17:44 | |
*** vijaykc4 has quit IRC | 18:03 | |
*** vijaykc4 has joined #openstack-containers | 18:07 | |
*** vijaykc4 has quit IRC | 18:13 | |
*** Jain has joined #openstack-containers | 18:22 | |
*** Jain is now known as Guest16553 | 18:22 | |
*** Guest321 has quit IRC | 18:24 | |
*** yatinkarel has quit IRC | 18:24 | |
*** salmankhan has joined #openstack-containers | 18:27 | |
*** salmankhan has quit IRC | 18:31 | |
*** Jack_Iv has joined #openstack-containers | 18:34 | |
*** Drago1 has joined #openstack-containers | 18:34 | |
*** Jack_Iv_ has joined #openstack-containers | 18:35 | |
*** Jack_Iv has quit IRC | 18:36 | |
*** yatinkarel has joined #openstack-containers | 18:37 | |
*** Jack_Iv has joined #openstack-containers | 18:37 | |
*** Jack_Iv_ has quit IRC | 18:37 | |
*** Jack_Iv_ has joined #openstack-containers | 18:38 | |
*** Jack_Iv has quit IRC | 18:40 | |
*** jwcroppe has quit IRC | 18:47 | |
*** jwcroppe has joined #openstack-containers | 18:48 | |
*** salmankhan has joined #openstack-containers | 18:49 | |
*** Jack_Iv has joined #openstack-containers | 18:50 | |
*** Jack_Iv_ has quit IRC | 18:51 | |
*** jwcroppe has quit IRC | 18:52 | |
*** salmankhan has quit IRC | 19:05 | |
*** Jack_Iv_ has joined #openstack-containers | 19:05 | |
*** dimtruck is now known as zz_dimtruck | 19:05 | |
*** Jack_Iv__ has joined #openstack-containers | 19:08 | |
*** Jack_Iv has quit IRC | 19:09 | |
*** Jack_Iv_ has quit IRC | 19:11 | |
*** salmankhan has joined #openstack-containers | 19:13 | |
*** EricGonczer_ has quit IRC | 19:13 | |
*** harlowja has joined #openstack-containers | 19:24 | |
*** Jack_Iv__ has quit IRC | 19:28 | |
*** Jack_Iv has joined #openstack-containers | 19:28 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/magnum stable/newton: Updated from global requirements https://review.openstack.org/453310 | 19:30 |
*** Jack_Iv has quit IRC | 19:32 | |
*** Jack_Iv has joined #openstack-containers | 19:35 | |
*** Jack_Iv has quit IRC | 19:36 | |
*** kbyrne has quit IRC | 19:46 | |
*** kbyrne has joined #openstack-containers | 19:50 | |
*** dave-mccowan has quit IRC | 20:03 | |
*** jmckind_ has quit IRC | 20:52 | |
*** zz_dimtruck is now known as dimtruck | 20:53 | |
*** rcernin has quit IRC | 20:55 | |
*** jmlowe has joined #openstack-containers | 21:01 | |
*** salmankhan has quit IRC | 21:02 | |
*** salmankhan has joined #openstack-containers | 21:08 | |
*** dave-mccowan has joined #openstack-containers | 21:15 | |
*** Serlex has quit IRC | 21:19 | |
*** randallburt has quit IRC | 21:24 | |
*** askb has joined #openstack-containers | 21:30 | |
*** salmankhan has quit IRC | 21:35 | |
*** dimtruck is now known as zz_dimtruck | 21:41 | |
*** Drago1 has quit IRC | 21:43 | |
*** Drago1 has joined #openstack-containers | 21:44 | |
*** foutatoro has joined #openstack-containers | 21:46 | |
*** Drago1 has quit IRC | 21:48 | |
*** jmlowe has quit IRC | 21:48 | |
*** jmlowe has joined #openstack-containers | 21:50 | |
*** jasond has quit IRC | 22:06 | |
*** zz_dimtruck is now known as dimtruck | 22:08 | |
*** ssbarnea has quit IRC | 22:49 | |
*** catintheroof has quit IRC | 22:57 | |
*** foutatoro has quit IRC | 23:00 | |
*** dimtruck is now known as zz_dimtruck | 23:35 | |
*** mtanino has quit IRC | 23:39 | |
*** zz_dimtruck is now known as dimtruck | 23:46 | |
*** yuanying_ has quit IRC | 23:53 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!