*** lenards has joined #openstack-containers | 00:00 | |
*** mnasiadka has joined #openstack-containers | 00:01 | |
*** AlexeyAbashkin has quit IRC | 00:02 | |
*** mnasiadka has quit IRC | 00:06 | |
*** mnasiadka has joined #openstack-containers | 00:09 | |
*** mnasiadka has quit IRC | 00:15 | |
*** mnasiadka has joined #openstack-containers | 00:21 | |
*** mnasiadka has quit IRC | 00:28 | |
*** portdirect has joined #openstack-containers | 00:29 | |
*** mnasiadka has joined #openstack-containers | 00:32 | |
*** mnasiadka has quit IRC | 00:37 | |
*** absubram has quit IRC | 00:39 | |
*** mnasiadka has joined #openstack-containers | 00:39 | |
*** mnasiadka has quit IRC | 00:44 | |
*** hishh1 has joined #openstack-containers | 00:46 | |
*** absubram has joined #openstack-containers | 00:47 | |
*** hishh has quit IRC | 00:48 | |
*** hishh1 is now known as hishh | 00:48 | |
*** mnasiadka has joined #openstack-containers | 00:51 | |
*** jmlowe_ has joined #openstack-containers | 00:54 | |
*** jmlowe has quit IRC | 00:55 | |
*** mnasiadka has quit IRC | 00:58 | |
*** jmlowe_ has quit IRC | 00:59 | |
*** mnasiadka has joined #openstack-containers | 01:01 | |
*** mnasiadka has quit IRC | 01:05 | |
*** mnasiadka has joined #openstack-containers | 01:09 | |
*** mnasiadka has quit IRC | 01:16 | |
*** dardelean_ has quit IRC | 01:17 | |
*** mnasiadka has joined #openstack-containers | 01:21 | |
*** penick has joined #openstack-containers | 01:25 | |
*** mnasiadka has quit IRC | 01:27 | |
*** absubram has quit IRC | 01:30 | |
*** mnasiadka has joined #openstack-containers | 01:31 | |
*** dardelean_ has joined #openstack-containers | 01:32 | |
*** mnasiadka has quit IRC | 01:35 | |
*** dardelean_ has quit IRC | 01:37 | |
*** mnasiadka has joined #openstack-containers | 01:39 | |
*** dardelean_ has joined #openstack-containers | 01:39 | |
*** clenimar has quit IRC | 01:39 | |
*** yamamoto has joined #openstack-containers | 01:41 | |
*** penick has quit IRC | 01:45 | |
*** mnasiadka has quit IRC | 01:45 | |
*** mnasiadka has joined #openstack-containers | 01:51 | |
*** mnasiadka has quit IRC | 01:58 | |
*** jhesketh has quit IRC | 01:59 | |
*** mnasiadka has joined #openstack-containers | 02:01 | |
*** mnasiadka has quit IRC | 02:06 | |
*** fragatina has quit IRC | 02:08 | |
*** mnasiadka has joined #openstack-containers | 02:08 | |
*** fragatina has joined #openstack-containers | 02:10 | |
*** rajivk has quit IRC | 02:12 | |
*** mnasiadka has quit IRC | 02:13 | |
*** fragatina has quit IRC | 02:14 | |
*** mnasiadka has joined #openstack-containers | 02:16 | |
*** absubram has joined #openstack-containers | 02:19 | |
*** rajivk has joined #openstack-containers | 02:23 | |
*** mnasiadka has quit IRC | 02:28 | |
*** mnasiadka has joined #openstack-containers | 02:31 | |
*** mnasiadka has quit IRC | 02:35 | |
*** mnasiadka has joined #openstack-containers | 02:38 | |
*** vijaykc4 has joined #openstack-containers | 02:40 | |
*** clenimar has joined #openstack-containers | 02:41 | |
*** absubram_ has joined #openstack-containers | 02:44 | |
*** dardelean_ has quit IRC | 02:44 | |
*** absubram has quit IRC | 02:45 | |
*** absubram_ is now known as absubram | 02:45 | |
*** mnasiadka has quit IRC | 02:45 | |
*** vijaykc4 has quit IRC | 02:51 | |
*** rajivk has quit IRC | 02:52 | |
*** mnasiadka has joined #openstack-containers | 02:56 | |
*** vijaykc4 has joined #openstack-containers | 02:56 | |
*** dardelean_ has joined #openstack-containers | 03:00 | |
*** mnasiadka has quit IRC | 03:00 | |
*** mnasiadka has joined #openstack-containers | 03:01 | |
*** armaan has quit IRC | 03:02 | |
*** armaan has joined #openstack-containers | 03:02 | |
*** dardelean_ has quit IRC | 03:04 | |
*** rajivk has joined #openstack-containers | 03:04 | |
*** mnasiadka has quit IRC | 03:06 | |
*** ianychoi has joined #openstack-containers | 03:08 | |
*** mnasiadka has joined #openstack-containers | 03:09 | |
*** vijaykc4 has quit IRC | 03:12 | |
*** mnasiadka has quit IRC | 03:14 | |
*** vijaykc4 has joined #openstack-containers | 03:16 | |
*** ramishra has joined #openstack-containers | 03:24 | |
*** oikiki has quit IRC | 03:33 | |
*** mikal_ has joined #openstack-containers | 03:39 | |
*** mikal has quit IRC | 03:42 | |
*** ricolin_ has joined #openstack-containers | 03:43 | |
*** absubram has quit IRC | 03:44 | |
*** vijaykc4 has quit IRC | 03:45 | |
*** ykarel has joined #openstack-containers | 03:53 | |
*** v1k0d3n has quit IRC | 03:56 | |
*** v1k0d3n has joined #openstack-containers | 03:57 | |
*** flwang1 has quit IRC | 04:06 | |
*** fragatina has joined #openstack-containers | 04:15 | |
*** fragatin_ has joined #openstack-containers | 04:16 | |
*** vijaykc4 has joined #openstack-containers | 04:18 | |
*** fragatina has quit IRC | 04:20 | |
*** clenimar has quit IRC | 04:22 | |
*** clenimar has joined #openstack-containers | 04:22 | |
*** shu-mutou has joined #openstack-containers | 04:34 | |
*** vijaykc4 has quit IRC | 04:45 | |
*** chhavi has joined #openstack-containers | 04:48 | |
*** penick has joined #openstack-containers | 04:54 | |
*** janki has joined #openstack-containers | 04:57 | |
*** dpawar has joined #openstack-containers | 05:04 | |
*** flwang1 has joined #openstack-containers | 05:32 | |
*** penick has quit IRC | 05:36 | |
*** robcresswell has quit IRC | 05:39 | |
*** fungi has quit IRC | 05:45 | |
*** fungi has joined #openstack-containers | 05:47 | |
*** absubram has joined #openstack-containers | 06:00 | |
*** ykarel has quit IRC | 06:03 | |
*** ykarel has joined #openstack-containers | 06:03 | |
*** absubram has quit IRC | 06:04 | |
*** vijaykc4 has joined #openstack-containers | 06:05 | |
*** absubram has joined #openstack-containers | 06:05 | |
*** dsariel has joined #openstack-containers | 06:11 | |
*** ykarel_ has joined #openstack-containers | 06:12 | |
*** ykarel has quit IRC | 06:15 | |
*** penick has joined #openstack-containers | 06:19 | |
openstackgerrit | Chandan Kumar proposed openstack/magnum master: Remove intree magnum tempest plugin https://review.openstack.org/526618 | 06:21 |
---|---|---|
openstackgerrit | Merged openstack/python-magnumclient master: inline comment typo fix https://review.openstack.org/494179 | 06:26 |
*** penick_ has joined #openstack-containers | 06:30 | |
*** penick has quit IRC | 06:31 | |
*** vijaykc4 has quit IRC | 06:32 | |
*** penick_ has quit IRC | 06:36 | |
*** vijaykc4 has joined #openstack-containers | 06:47 | |
*** mjura has joined #openstack-containers | 06:58 | |
*** dardelean_ has joined #openstack-containers | 07:00 | |
*** dsariel has quit IRC | 07:01 | |
*** mnasiadka has joined #openstack-containers | 07:01 | |
*** dardelean_ has quit IRC | 07:04 | |
*** absubram has quit IRC | 07:09 | |
*** magicboiz has joined #openstack-containers | 07:11 | |
*** chhavi__ has joined #openstack-containers | 07:20 | |
*** adisky__ has joined #openstack-containers | 07:20 | |
*** rcernin has quit IRC | 07:21 | |
*** chhavi has quit IRC | 07:22 | |
*** dsariel has joined #openstack-containers | 07:23 | |
*** armaan has quit IRC | 07:33 | |
*** armaan has joined #openstack-containers | 07:34 | |
*** mdnadeem has joined #openstack-containers | 07:36 | |
*** dpawar has quit IRC | 07:37 | |
*** robcresswell has joined #openstack-containers | 07:39 | |
*** AlexeyAbashkin has joined #openstack-containers | 07:53 | |
*** dardelean_ has joined #openstack-containers | 07:57 | |
*** dardelean_ has quit IRC | 08:02 | |
*** armaan has quit IRC | 08:03 | |
*** dpawar has joined #openstack-containers | 08:04 | |
*** b_bezak has joined #openstack-containers | 08:06 | |
*** dardelean_ has joined #openstack-containers | 08:08 | |
openstackgerrit | Spyros Trigazis (strigazi) proposed openstack/magnum master: [doc-migration] Consolidate install guide https://review.openstack.org/526926 | 08:11 |
*** ykarel_ has quit IRC | 08:13 | |
*** ykarel_ has joined #openstack-containers | 08:14 | |
openstackgerrit | Spyros Trigazis (strigazi) proposed openstack/magnum master: [doc-migration] Consolidate install guide https://review.openstack.org/526926 | 08:14 |
*** vijaykc4 has quit IRC | 08:16 | |
*** armaan has joined #openstack-containers | 08:23 | |
*** armaan has quit IRC | 08:32 | |
*** armaan has joined #openstack-containers | 08:32 | |
*** mdnadeem has quit IRC | 08:32 | |
*** dardelean_ has quit IRC | 08:36 | |
*** rcernin has joined #openstack-containers | 08:36 | |
*** mdnadeem has joined #openstack-containers | 08:37 | |
*** dpawar has quit IRC | 08:41 | |
*** ykarel_ is now known as ykarel|away | 08:42 | |
*** dpawar has joined #openstack-containers | 08:44 | |
-openstackstatus- NOTICE: Our CI system Zuul is currently not accessible. Wait with approving changes and rechecks until it's back online. Currently waiting for an admin to investigate. | 08:47 | |
*** ykarel|away has quit IRC | 08:47 | |
*** ykarel has joined #openstack-containers | 08:50 | |
*** linkmark has joined #openstack-containers | 08:51 | |
*** janonymous has joined #openstack-containers | 09:00 | |
openstackgerrit | Merged openstack/magnum master: The os_distro of image is case sensitive https://review.openstack.org/526964 | 09:02 |
*** dpawar has quit IRC | 09:05 | |
-openstackstatus- NOTICE: Zuul is back online, looks like a temporary network problem. | 09:07 | |
*** dardelean_ has joined #openstack-containers | 09:10 | |
*** jappleii__ has quit IRC | 09:10 | |
strigazi_ | savvas_: what is the range of your private network? | 09:17 |
*** strigazi_ is now known as strigazi | 09:17 | |
strigazi | flwang: ping | 09:19 |
*** mnasiadka has quit IRC | 09:21 | |
*** mgoddard has joined #openstack-containers | 09:23 | |
*** armaan has quit IRC | 09:24 | |
*** mnasiadka has joined #openstack-containers | 09:24 | |
*** armaan has joined #openstack-containers | 09:25 | |
*** dardelean_ has quit IRC | 09:34 | |
strigazi | ykarel: Can you have a look? it is ready: https://review.openstack.org/#/c/525662/ | 09:34 |
ykarel | strigazi, Ok will check | 09:37 |
*** ramishra has quit IRC | 09:43 | |
*** ramishra has joined #openstack-containers | 09:44 | |
*** dardelean_ has joined #openstack-containers | 09:49 | |
*** dardelean_ has quit IRC | 09:50 | |
*** dardelean_ has joined #openstack-containers | 09:50 | |
*** dardelean_ has quit IRC | 09:56 | |
*** jhesketh has joined #openstack-containers | 10:04 | |
*** janki has quit IRC | 10:07 | |
*** lpetrut has joined #openstack-containers | 10:09 | |
*** kiennt26 has quit IRC | 10:09 | |
*** ykarel_ has joined #openstack-containers | 10:12 | |
*** ykarel has quit IRC | 10:16 | |
*** vijaykc4 has joined #openstack-containers | 10:16 | |
*** vijaykc4 has quit IRC | 10:16 | |
*** vijaykc4 has joined #openstack-containers | 10:19 | |
*** vijaykc4 has quit IRC | 10:21 | |
*** salmankhan has joined #openstack-containers | 10:24 | |
*** sheva_ has joined #openstack-containers | 10:25 | |
*** ykarel__ has joined #openstack-containers | 10:26 | |
*** armaan has quit IRC | 10:29 | |
*** armaan has joined #openstack-containers | 10:30 | |
*** ykarel_ has quit IRC | 10:30 | |
*** lpetrut has quit IRC | 10:31 | |
*** vijaykc4 has joined #openstack-containers | 10:33 | |
*** yamamoto has quit IRC | 10:35 | |
*** lpetrut has joined #openstack-containers | 10:35 | |
*** dardelean_ has joined #openstack-containers | 10:39 | |
*** vijaykc4 has quit IRC | 10:42 | |
*** yamamoto has joined #openstack-containers | 10:48 | |
*** vijaykc4 has joined #openstack-containers | 10:50 | |
*** vijaykc4 has quit IRC | 10:50 | |
*** shu-mutou is now known as shu-mutou-AWAY | 10:59 | |
*** vijaykc4 has joined #openstack-containers | 11:11 | |
*** AlexeyAbashkin has quit IRC | 11:15 | |
gokhan | strigazi, ykarel__ I tried create kubernates and swarm cluster again get timeout error. I can not ssh any nodes. | 11:17 |
gokhan | I am sharing logs on console | 11:17 |
gokhan | for swarm http://paste.openstack.org/show/628706/ | 11:17 |
gokhan | for kubernates http://paste.openstack.org/show/628707/ | 11:17 |
gokhan | I am on pike branch | 11:18 |
gokhan | and used https://ftp-stud.hs-esslingen.de/pub/Mirrors/alt.fedoraproject.org/atomic/stable/Fedora-Atomic-26-20171030.0/CloudImages/x86_64/images/Fedora-Atomic-26-20171030.0.x86_64.qcow2 this image | 11:18 |
*** vijaykc4 has quit IRC | 11:25 | |
*** ricolin_ has quit IRC | 11:31 | |
*** salmankhan has quit IRC | 11:34 | |
*** vijaykc4 has joined #openstack-containers | 11:36 | |
ykarel__ | gokhan, looking at the console logs it seems vms are not able to reach the metadata server, are you able to successfully boot an instance using nova | 11:38 |
*** ykarel__ is now known as ykarel | 11:38 | |
*** AlexeyAbashkin has joined #openstack-containers | 11:40 | |
gokhan | ykarel, yes I can booot. I think problem is about fedora image. | 11:42 |
gokhan | ykarel, When I create fedora image, I am using --property os_distro='fedora-atomic' | 11:43 |
gokhan | is this be problem ? | 11:43 |
ykarel | this is required by magnum | 11:43 |
*** salmankhan has joined #openstack-containers | 11:43 | |
ykarel | gokhan, we are using following image in the CI jobs: Fedora-Atomic-26-20170723.0.x86_64 | 11:45 |
ykarel | https://github.com/openstack/magnum/blob/stable/pike/magnum/tests/contrib/gate_hook.sh#L88-L89 | 11:46 |
gokhan | ykarel, ok now I am trying this image | 11:48 |
ykarel | gokhan, also have you used this patch: https://review.openstack.org/#/c/524151/1 | 11:48 |
*** dpawar has joined #openstack-containers | 11:49 | |
gokhan | ykarel, yes I used this patch and also https://review.openstack.org/#/c/518700/ this patch. | 11:50 |
*** vijaykc4 has quit IRC | 11:51 | |
*** yamamoto has quit IRC | 11:54 | |
ykarel | gokhan, Ok | 11:54 |
*** yamamoto has joined #openstack-containers | 11:58 | |
*** yamamoto has quit IRC | 12:03 | |
*** vijaykc4 has joined #openstack-containers | 12:08 | |
*** dpawar has quit IRC | 12:14 | |
savvas_ | strigazi: I've tried default where it creates 10.0.0.0/24, and an existing private range 10.0.35.0/24 | 12:15 |
gokhan | ykarel, agaim same metadata warning http://paste.openstack.org/show/628716/ | 12:17 |
*** sheva_ has quit IRC | 12:17 | |
gokhan | ykarel, when I boot this image, I don't get this metada warning http://paste.openstack.org/show/628718/ | 12:22 |
gokhan | ykarel, when magnum tries to boot this image, I see this warning | 12:22 |
ykarel | gokhan, strange, can you try creating a cluster with fixed-network and fixed-subnet(same that you used during nova boot) | 12:26 |
gokhan | ykarel, ok I am trying now | 12:28 |
gokhan | ykarel, now I didn't get metadata warninghttp://paste.openstack.org/show/628719/ | 12:34 |
*** yamamoto has joined #openstack-containers | 12:35 | |
*** chhavi__ has quit IRC | 12:43 | |
*** chhavi__ has joined #openstack-containers | 12:44 | |
*** vijaykc4 has quit IRC | 12:52 | |
*** dpawar has joined #openstack-containers | 12:53 | |
gokhan | ykarel, I restart master node , I can ssh | 12:56 |
gokhan | ykarel, this is cloud init output log http://paste.openstack.org/show/628723/ | 12:57 |
*** armaan has quit IRC | 12:59 | |
*** armaan has joined #openstack-containers | 13:15 | |
*** ricolin_ has joined #openstack-containers | 13:17 | |
*** janonymous has quit IRC | 13:20 | |
ykarel | gokhan, looks like you are facing the same issue you faced earlier, the issue is with the network created by magnum | 13:23 |
*** fragatin_ has quit IRC | 13:43 | |
*** fragatina has joined #openstack-containers | 13:43 | |
*** dave-mccowan has joined #openstack-containers | 13:45 | |
gokhan | ykarel, I think this is different because I can not see any docker bridge | 13:46 |
*** vijaykc4 has joined #openstack-containers | 13:47 | |
*** kiennt26 has joined #openstack-containers | 13:48 | |
*** dave-mccowan has quit IRC | 13:48 | |
*** dave-mccowan has joined #openstack-containers | 13:56 | |
*** dave-mccowan has quit IRC | 14:00 | |
openstackgerrit | Murali Annamneni proposed openstack/magnum master: Enables MySQL Cluster Support for Magnum https://review.openstack.org/465746 | 14:04 |
*** mdnadeem_ has joined #openstack-containers | 14:09 | |
*** mdnadeem has quit IRC | 14:10 | |
*** ykarel is now known as ykarel|afk | 14:23 | |
*** yamamoto has quit IRC | 14:24 | |
*** yamamoto has joined #openstack-containers | 14:24 | |
*** salmankhan has quit IRC | 14:25 | |
*** ykarel|afk has quit IRC | 14:28 | |
*** vijaykc4 has quit IRC | 14:33 | |
*** salmankhan has joined #openstack-containers | 14:38 | |
-openstackstatus- NOTICE: We're currently seeing an elevated rate of timeouts in jobs and the zuulv3.openstack.org dashboard is intermittently unresponsive, please stand by while we troubleshoot the issues. | 14:38 | |
*** marst has joined #openstack-containers | 14:50 | |
*** salmankhan has quit IRC | 14:53 | |
*** salmankhan has joined #openstack-containers | 15:00 | |
*** rcernin has quit IRC | 15:00 | |
*** armaan has quit IRC | 15:01 | |
*** armaan has joined #openstack-containers | 15:03 | |
openstackgerrit | Spyros Trigazis (strigazi) proposed openstack/magnum master: k8s_fedora: Add RBAC configuration https://review.openstack.org/527103 | 15:04 |
*** dave-mccowan has joined #openstack-containers | 15:08 | |
*** armaan_ has joined #openstack-containers | 15:10 | |
*** armaan has quit IRC | 15:10 | |
*** kiennt26 has quit IRC | 15:23 | |
openstackgerrit | Spyros Trigazis (strigazi) proposed openstack/python-magnumclient master: Make cluster-config rbac compatible for kubebernetes https://review.openstack.org/527428 | 15:30 |
*** chhavi__ has quit IRC | 15:34 | |
strigazi | Hi everyone, magnum meeting in #openstack-meeting-alt in 23 mins | 15:36 |
*** salmankhan has quit IRC | 15:37 | |
*** jmlowe has joined #openstack-containers | 15:44 | |
*** vijaykc4 has joined #openstack-containers | 15:47 | |
*** jmlowe has quit IRC | 15:48 | |
*** salmankhan has joined #openstack-containers | 15:55 | |
*** oikiki has joined #openstack-containers | 15:59 | |
*** mjura has quit IRC | 16:00 | |
*** dave-mccowan has quit IRC | 16:02 | |
*** b_bezak has quit IRC | 16:04 | |
*** b_bezak has joined #openstack-containers | 16:04 | |
*** mnasiadka has quit IRC | 16:08 | |
*** b_bezak has quit IRC | 16:09 | |
*** jmlowe has joined #openstack-containers | 16:10 | |
*** mnasiadka has joined #openstack-containers | 16:11 | |
*** armaan_ has quit IRC | 16:12 | |
*** mnasiadka has quit IRC | 16:18 | |
*** mnasiadka has joined #openstack-containers | 16:21 | |
*** jmlowe has quit IRC | 16:21 | |
*** mnasiadka has quit IRC | 16:26 | |
*** AlexeyAbashkin has quit IRC | 16:26 | |
*** dpawar has quit IRC | 16:26 | |
openstackgerrit | Spyros Trigazis (strigazi) proposed openstack/magnum master: Remove intree magnum tempest plugin https://review.openstack.org/526618 | 16:27 |
*** mnasiadka has joined #openstack-containers | 16:28 | |
*** hishh has quit IRC | 16:29 | |
*** dsariel has quit IRC | 16:34 | |
flwang1 | strigazi: ping | 16:34 |
strigazi | flwang1: hi | 16:35 |
strigazi | flwang1: you just missed the meeting | 16:36 |
flwang1 | strigazi: have a moment for some quick questions? | 16:36 |
strigazi | flwang1: yes | 16:36 |
flwang1 | strigazi: oh, it's 5:36 am here :) | 16:36 |
*** mnasiadka has quit IRC | 16:36 | |
flwang1 | strigazi: 1. about the monitoring | 16:36 |
*** KwozyMan has joined #openstack-containers | 16:36 | |
strigazi | flwang1: oh sorry about that :( we can set a time if you want that we can sync | 16:37 |
strigazi | flwang1: tell me | 16:37 |
*** armaan has joined #openstack-containers | 16:37 | |
flwang1 | we'd like to charge our customer for a little extra fee for upgrade and maintenance for clusters, but the question is | 16:37 |
flwang1 | that's alright, i can read the log :) | 16:38 |
*** AlexeyAbashkin has joined #openstack-containers | 16:38 | |
flwang1 | the question is currently based on the code, seems magnum only monitors the lb of cluster | 16:38 |
flwang1 | does magnum plan to monitor the health of the cluster itself? | 16:38 |
flwang1 | or it's out of the scope of magnum based on current goal of magnum? | 16:39 |
strigazi | flwang1 for kuberentes we have two types of monitoring | 16:39 |
*** jmlowe has joined #openstack-containers | 16:39 | |
strigazi | flwang1: one is the kubernetes-dashboard and the other one is a stack based on prometheus, node-exporter, cadvisor and grafana | 16:40 |
flwang1 | but can admin user access them? or only the tenant user (owner) has the access? | 16:40 |
strigazi | flwang1: for swarm we have a contributor working on porting the above stack from kube to swarm | 16:41 |
*** mnasiadka has joined #openstack-containers | 16:41 | |
*** dsariel has joined #openstack-containers | 16:42 | |
flwang1 | in other words, can the admin user help tenant user take care the clustrers so that tenant user don't have to pay any attention to the clusters but just use it? | 16:42 |
strigazi | flwang1 At the moment, only the owner of the cluster can get the credentials to talk to the cluster as admin of the cluster we can change it to allow the operator to have this kind access but the are privacy concerns there | 16:43 |
flwang1 | in order to make it like a k8s 'service' | 16:43 |
strigazi | you need to have moniroing that only the openstack operator can access? | 16:43 |
flwang1 | both will be great | 16:43 |
*** jmlowe has quit IRC | 16:44 | |
flwang1 | i haven't dig into that part, is it possible to generate another ops credential? | 16:44 |
flwang1 | which could be transparent for the owner (tenant user), i'm not too sure at the moment | 16:45 |
flwang1 | otherwise, if we (cloud provider) can't help monitor the cluster, it's not really like a 'k8s' as a service, does that make any sense? | 16:46 |
strigazi | it does | 16:46 |
*** AlexeyAbashkin has quit IRC | 16:47 | |
flwang1 | we can discuss more about this if you think it's reasonable | 16:48 |
flwang1 | 2. this is related to 1st question, about the remote access | 16:48 |
strigazi | The easiest thing to do is allow the operator to get the certs of the cluster and be able to act on it, but in this case you can see the secrets of the cluster | 16:48 |
*** dave-mccowan has joined #openstack-containers | 16:49 | |
strigazi | with RBAC we can limit that by adding a new role. I also think that if the user has his role configured properly even the admin won't be able to see secrets etc | 16:49 |
strigazi | what about 2? | 16:50 |
flwang1 | strigazi: when there is a failure/error happening in a node/instance, admin don't have permission to debug it | 16:51 |
flwang1 | what's the best practice in CERN? | 16:51 |
flwang1 | because admin user can't login to the instance without credentials | 16:52 |
strigazi | flwang1 yes, admin can't access the node. We ask the user to add our ssh-key in the vms and permission to access the kuberentes-api | 16:52 |
flwang1 | ha | 16:52 |
flwang1 | that's the 'best' way we can do :D | 16:53 |
*** absubram has joined #openstack-containers | 16:53 | |
strigazi | a lot of access means less privacy for the user | 16:53 |
flwang1 | yep, i totally understand | 16:54 |
strigazi | The perfect balance is: | 16:54 |
flwang1 | i think it's because of the original design | 16:54 |
flwang1 | it's not a service, technically | 16:54 |
*** absubram has quit IRC | 16:55 | |
strigazi | access to the nodes and access only for moniring to the cluster API | 16:55 |
flwang1 | strigazi: agree | 16:55 |
strigazi | this is very doable and not too difficult to do | 16:55 |
strigazi | but, | 16:56 |
flwang1 | i'm not really keen to resolve the 2nd question now | 16:56 |
flwang1 | because i totally understand the privacy concern | 16:56 |
flwang1 | but for the 1st, i think it's a valid requirement | 16:56 |
strigazi | if the user doesn implement best practices he is more are risk | 16:56 |
strigazi | it is the same with let's say a db on demand service | 16:57 |
flwang1 | and we could be able to do it by proper role/permission settings | 16:57 |
*** mnasiadka has quit IRC | 16:57 | |
strigazi | the operator can see your data but if you encrypt them he can't | 16:57 |
flwang1 | true | 16:57 |
strigazi | we can add ways to allow you to select what you want to have access to | 16:59 |
strigazi | eg pass the operator ssh-key | 16:59 |
flwang1 | strigazi: you're talking about the 2nd? | 16:59 |
flwang1 | yep, i understand | 16:59 |
strigazi | yes, and for the 1st | 17:00 |
*** fragatina has quit IRC | 17:00 | |
flwang1 | but there is no difference between this and asking the user to add it manually | 17:00 |
*** fragatina has joined #openstack-containers | 17:00 | |
strigazi | change the policy to allow the admin user do cluster-condig | 17:00 |
strigazi | *cluster-config | 17:00 |
strigazi | flwang1: we can differenciate, eg access only the master nodes | 17:01 |
strigazi | the end result regarding access level will be same | 17:01 |
flwang1 | strigazi: personally, i'd like to see an argument when creating cluster | 17:01 |
strigazi | flwang1: easy to implement | 17:02 |
flwang1 | --allow-admin-login or something like that | 17:02 |
*** ramishra has quit IRC | 17:02 | |
strigazi | we are talking about ssh access right? | 17:02 |
flwang1 | yes | 17:02 |
strigazi | we can have theree options: NO, master, all | 17:03 |
flwang1 | because i'm not sure if we should silently inject keys | 17:03 |
flwang1 | exactly | 17:03 |
strigazi | So the user should know that the admin will have root access | 17:04 |
flwang1 | yes | 17:04 |
strigazi | if he implements best practices he can limit what the operator can see even with root access | 17:05 |
*** dave-mccowan has quit IRC | 17:05 | |
flwang1 | i think so | 17:05 |
flwang1 | but may need more tests | 17:05 |
strigazi | do you have any other concerns/questions? | 17:07 |
flwang1 | yes, a small one | 17:07 |
flwang1 | at summit, you mentioned there is a server group created for nodes | 17:08 |
*** absubram has joined #openstack-containers | 17:08 | |
strigazi | in heat it is a resource group | 17:08 |
flwang1 | would you mind pointing me where is the code so that I can set the affinity policy ? | 17:08 |
flwang1 | ah, yes, it's a resource group, i can see it | 17:08 |
strigazi | https://github.com/openstack/magnum/blob/master/magnum/drivers/k8s_fedora_atomic_v1/templates/kubecluster.yaml#L544 | 17:09 |
flwang1 | you mean heat will create a sever group automatically? | 17:09 |
strigazi | https://github.com/openstack/magnum/blob/master/magnum/drivers/k8s_fedora_atomic_v1/templates/kubeminion.yaml#L407 | 17:09 |
strigazi | flwang1: They will be independent servers that are on the same network and have the same flavor image | 17:10 |
strigazi | I think it is not a server group | 17:10 |
flwang1 | ok, so we need to create a server group | 17:10 |
flwang1 | and set the default policy to 'anti-affinity' | 17:11 |
strigazi | flwang1: the server group is a parameter to the the server right? | 17:12 |
flwang1 | yes | 17:12 |
strigazi | ok, we can modify slightly the cluster template | 17:13 |
*** lpetrut has quit IRC | 17:14 | |
strigazi | not very difficult as well | 17:14 |
strigazi | savvas_: hi | 17:15 |
flwang1 | cool, do you think we need a bp/spec? | 17:15 |
flwang1 | i can take this | 17:15 |
savvas_ | hi strigazi | 17:16 |
strigazi | flwang1: not spec, bp or bug | 17:16 |
savvas_ | thanks for getting back to me | 17:16 |
flwang1 | strigazi: just do it? ;) | 17:16 |
strigazi | flwang1: bugs have comments, open a bug and go for it | 17:17 |
strigazi | flwang1: just to track what we do | 17:17 |
strigazi | savvas_: tell me | 17:17 |
flwang1 | cool | 17:17 |
flwang1 | i have another thing wann double check | 17:18 |
savvas_ | alrighty. So I am still where I was yesterday, haven't made any progress. Have tried various cluster deployments (mostly kubernetes ) on OpenStack Ansible's integration of Magnum | 17:18 |
strigazi | savvas_ magnum version? | 17:18 |
savvas_ | my first and foremost problem is that the Atomic VMs that are being created as part of the process don't seem to have network connectivity partially or throughout the entire process | 17:18 |
strigazi | flwang1: what is it? | 17:18 |
flwang1 | strigazi: when create cluster, there are script in the instance need to call heat to notify its status, right? | 17:18 |
flwang1 | strigazi: like https://github.com/openstack/magnum/blob/master/magnum/drivers/common/templates/kubernetes/fragments/wc-notify-master.sh#L14 | 17:19 |
savvas_ | strigazi: 2.7.0 | 17:19 |
*** oikiki has quit IRC | 17:19 | |
strigazi | savvas_: can you boot a standalone vm with fedora-atomic | 17:19 |
strigazi | flwang1 yes | 17:19 |
*** mdnadeem_ has quit IRC | 17:19 | |
strigazi | savvas_ 2.7.0 is the client version | 17:19 |
flwang1 | so we need the instance to be able to access the api node, right? | 17:19 |
strigazi | flwang1 yes | 17:20 |
strigazi | savvas_: ok, maybe pike | 17:20 |
savvas_ | ye it is definitely pike | 17:20 |
savvas_ | I am running checkout stable/pike on OA | 17:20 |
strigazi | savvas_: can you boot a standalone vm with fedora atomic 26? | 17:20 |
savvas_ | booting one now, I got atomic 25 and 27 on my install | 17:21 |
strigazi | savvas_ try 26, it is better for pike | 17:21 |
savvas_ | pings right away, an Atomic 27 VM | 17:21 |
*** mgoddard has quit IRC | 17:21 | |
strigazi | flwang1 the vms in general need to be able to access the openstack apis, keystone, heat, magnum and for the k8s cloud provider, nova and cidner too | 17:23 |
savvas_ | can acces the VM via SSH as well, ssh key is on there, so deploying a regular VM with Fedora Atomic 27 shows no issues | 17:23 |
strigazi | savvas_ is docker running when you login? | 17:23 |
strigazi | system status docker | 17:23 |
strigazi | systemctl status docker | 17:23 |
*** magicboiz has quit IRC | 17:24 | |
savvas_ | yes sir | 17:24 |
*** dsariel has quit IRC | 17:24 | |
strigazi | what I would do is create a cluster and monitor nova, then try to login as soon as you see that a vm is running | 17:25 |
*** dardelean_ has quit IRC | 17:25 | |
strigazi | the monitor /var/log/cloud-init-output.log to see when you lose connectivity | 17:26 |
strigazi | I suspect that the flannel/docker configuration break the network | 17:26 |
strigazi | s/the/then | 17:26 |
strigazi | but | 17:26 |
savvas_ | I don't get any connectivity straight out of the gate | 17:26 |
strigazi | try fedora atomic 26 | 17:26 |
savvas_ | I monitor the spawn process and as soon as it gets an IP assigned, I start pinging | 17:27 |
savvas_ | and monitor the console output | 17:27 |
*** mgoddard has joined #openstack-containers | 17:27 | |
savvas_ | I am downloading Atomic 26 now as well | 17:27 |
strigazi | https://download.fedoraproject.org/pub/alt/atomic/stable | 17:28 |
savvas_ | hehe thx, ye I noticed they aren't too font of publicly listing other releases | 17:29 |
savvas_ | but I had found that | 17:29 |
strigazi | When you are in the vm, keep a copy of /var/lib/cloud/instance/user_data.txt | 17:30 |
savvas_ | stack creating now | 17:30 |
flwang1 | strigazi: for the 2nd issue, should we create a bp/spec to track the discussion in case we lost it? | 17:30 |
strigazi | this what is executed in that order when the vm boots | 17:31 |
*** aspiers has quit IRC | 17:31 | |
savvas_ | strigazi: will do | 17:31 |
savvas_ | that is, if I get access at all | 17:31 |
*** salmankhan has quit IRC | 17:31 | |
strigazi | flwang1 Create a bug | 17:32 |
flwang1 | strigazi: great | 17:32 |
*** KwozyMan has quit IRC | 17:32 | |
flwang1 | strigazi: and as for the 1st, i'm not too sure if we have a conclusion | 17:33 |
flwang1 | do you think we should merge it with 2nd? | 17:33 |
flwang1 | or it's separated track? | 17:33 |
strigazi | flwang1 for the first, we need to give access to the cluster API to the operator right? | 17:34 |
flwang1 | strigazi: yes | 17:34 |
flwang1 | so that ops can monitor the cluster's health | 17:34 |
savvas_ | strigazi: I don't know how long I should wait but it is at login prompt already and sometime during the boot process it says that eth0 isn't ready, apart from that I can't catch anything | 17:35 |
savvas_ | but I have no network, so I can't access the VM | 17:35 |
savvas_ | I don't think atomic has a predefined user/pass for console access | 17:35 |
flwang1 | but it would be nice if it can work with the 2nd, otherwise, after detected there is a shit happened, ops still can't do anything | 17:35 |
strigazi | flwang1 so open a bug to add what we can do, what kind of policy we need to add for the operator to access the api | 17:36 |
flwang1 | strigazi: cool | 17:36 |
strigazi | flwang1: also | 17:36 |
strigazi | flwang1: we have some periodic tasks that talk to the API | 17:36 |
flwang1 | yep, i see there is a basic monitor | 17:37 |
*** salmankhan has joined #openstack-containers | 17:37 | |
flwang1 | can we leverage that api? | 17:37 |
strigazi | a thought is to check that the cluster has all it's nodes in ready status | 17:37 |
flwang1 | i mean the task | 17:37 |
*** vijaykc4 has quit IRC | 17:37 | |
savvas_ | strigazi: I do see it resizing the atomic volume now to, this is something that was failing on the other versions | 17:37 |
savvas_ | *though | 17:37 |
strigazi | flwang1: and add new statuses to mark as healthy or unhealthy | 17:38 |
*** dave-mccowan has joined #openstack-containers | 17:38 | |
flwang1 | strigazi: yep, sounds good for stage 1 | 17:40 |
flwang1 | i will take a look | 17:40 |
strigazi | flwang1: do you still have the heat template I gave you for testing a couple of days ago, savvas_ can benefit from it | 17:41 |
flwang1 | strigazi: i'm allll good now. thank you sooo much for your time, very helpful | 17:41 |
flwang1 | strigazi: yes, i have | 17:41 |
strigazi | flwang1: you are very welcome | 17:41 |
savvas_ | That would be wonderful | 17:41 |
flwang1 | savvas_: wait a sec | 17:41 |
savvas_ | :) | 17:41 |
savvas_ | strigazi: I am right to assume that network should be available evne though cloud-init scripts are still running right? There's nothing in there which locks up network until it is done? | 17:42 |
flwang1 | savvas_: https://gist.github.com/openstacker/26e31c9715d52cc502397b65d3cebab6 | 17:42 |
strigazi | savvas_: it is a heat template that creates only the vm, the networks and the ports that magnum usually creates | 17:42 |
strigazi | savvas_ exactly | 17:42 |
savvas_ | Reason I am asking is because it does seem to go further with Atommic 26 then with the other 2 releases. It actually resized and recreated the docker pool volume and now says configuring kubernetes (master), for a couple of minutes now | 17:42 |
*** vijaykc4 has joined #openstack-containers | 17:42 | |
strigazi | as soon the vm is running and sshd us up you should be able to login | 17:42 |
savvas_ | ok ye than it is still as messed up as before | 17:43 |
savvas_ | thanks for sharing flwang1 | 17:43 |
flwang1 | savvas_: no problem | 17:43 |
savvas_ | could this be a bug in our release? | 17:43 |
savvas_ | I've seen it reported recently by another OA user | 17:44 |
strigazi | savvas_ magnum release? | 17:44 |
savvas_ | https://bugs.launchpad.net/magnum/+bug/1720816 | 17:44 |
openstack | Launchpad bug 1720816 in Magnum "magnum create cluster "create_in_progress" and changes to "create_failed" after timeout" [Undecided,New] | 17:44 |
savvas_ | symptoms are similar | 17:45 |
strigazi | savvas_: I don't think so, since they can login | 17:45 |
savvas_ | ah ye just noticed that in the comments | 17:45 |
savvas_ | I don't have that luxury lol | 17:45 |
strigazi | how did you boot your vm that worked? | 17:45 |
savvas_ | from horizon | 17:46 |
savvas_ | not on volume | 17:46 |
strigazi | in a private network? | 17:46 |
savvas_ | ye same private network | 17:46 |
savvas_ | worked like a charm, 30 secs and it was up and running | 17:46 |
savvas_ | docker works etc | 17:46 |
strigazi | so you are able to login | 17:47 |
*** aspiers has joined #openstack-containers | 17:47 | |
savvas_ | yes, when I create a VM manually with Atomic image Iam able to access it just fine | 17:47 |
savvas_ | other networking aspects of the cloud and this particular private network also work | 17:47 |
strigazi | ok, try to create a swarm-mode cluster | 17:47 |
savvas_ | it is just when I create a magnum cluster through the CLI or horizon that it doesn't work | 17:47 |
savvas_ | Are volume and devicemapper settings mandatory? | 17:48 |
strigazi | you can try overlay | 17:48 |
strigazi | savvas_: do you use the --docker-volume-size param? | 17:49 |
strigazi | if yes try without | 17:49 |
savvas_ | with it, it fails right a way | 17:49 |
savvas_ | I think it has something to do with how I deployed magnum | 17:49 |
savvas_ | should've added a cinder variables | 17:49 |
savvas_ | -s | 17:49 |
savvas_ | so I am trying to deploy on image rather than volume | 17:49 |
strigazi | try swarm-mode with overlay and WITHOUT docker-volume-size | 17:50 |
savvas_ | running already | 17:50 |
*** absubram has quit IRC | 17:51 | |
*** oikiki has joined #openstack-containers | 17:51 | |
strigazi | I need to go now, I'm sorry about that, we can continue tmr morining (morining for you) | 17:51 |
strigazi | if you can login to a swarm-mode node | 17:51 |
savvas_ | that's fine, I need to go as well, appreciate the help | 17:51 |
strigazi | mean that the kube config breaks something | 17:52 |
savvas_ | I am usually online around 1PM CET, so I'll try you then if you're available | 17:52 |
strigazi | savvas_ I'll be arount 14:30pm CET | 17:52 |
savvas_ | ye the docker vm is spawning now, let's see if that does anything | 17:52 |
strigazi | I have a meeting before | 17:52 |
savvas_ | ok that works perfect for me, appreciate the support | 17:53 |
strigazi | savvas_: you can also try this https://review.openstack.org/#/c/524151/ | 17:53 |
strigazi | see you tmr | 17:53 |
savvas_ | talk to you tmr, bb | 17:54 |
*** absubram has joined #openstack-containers | 17:59 | |
*** mgoddard has quit IRC | 18:09 | |
*** jmlowe has joined #openstack-containers | 18:12 | |
*** penick has joined #openstack-containers | 18:12 | |
*** dardelean_ has joined #openstack-containers | 18:13 | |
*** penick has quit IRC | 18:14 | |
*** AlexeyAbashkin has joined #openstack-containers | 18:14 | |
*** lpetrut has joined #openstack-containers | 18:16 | |
*** penick has joined #openstack-containers | 18:16 | |
*** AlexeyAbashkin has quit IRC | 18:18 | |
*** ricolin_ has quit IRC | 18:21 | |
*** dardelean_ has quit IRC | 18:27 | |
*** dardelean_ has joined #openstack-containers | 18:27 | |
*** dardelean_ has quit IRC | 18:29 | |
*** lpetrut has quit IRC | 18:32 | |
*** AlexeyAbashkin has joined #openstack-containers | 18:34 | |
*** AlexeyAbashkin has quit IRC | 18:38 | |
*** lpetrut has joined #openstack-containers | 18:48 | |
*** adisky__ has quit IRC | 18:50 | |
*** armaan has quit IRC | 18:59 | |
*** armaan has joined #openstack-containers | 19:00 | |
*** armaan has quit IRC | 19:03 | |
*** armaan has joined #openstack-containers | 19:04 | |
*** dardelean_ has joined #openstack-containers | 19:08 | |
DimGR | eimaste poloi | 19:11 |
*** mgoddard has joined #openstack-containers | 19:12 | |
*** dardelean_ has quit IRC | 19:13 | |
*** flwang1 has quit IRC | 19:16 | |
*** salmankhan has quit IRC | 19:34 | |
*** mdnadeem has joined #openstack-containers | 19:44 | |
*** fragatina has quit IRC | 19:44 | |
*** masuberu has joined #openstack-containers | 19:48 | |
*** masber has quit IRC | 19:51 | |
*** dave-mccowan has quit IRC | 19:56 | |
*** mgoddard has quit IRC | 19:58 | |
*** fragatina has joined #openstack-containers | 20:12 | |
-openstackstatus- NOTICE: The zuul scheduler has been restarted after lengthy troubleshooting for a memory consumption issue; earlier changes have been reenqueued but if you notice jobs not running for a new or approved change you may want to leave a recheck comment or a new approval vote | 20:14 | |
*** vijaykc4 has quit IRC | 20:16 | |
*** absubram has quit IRC | 20:21 | |
*** lpetrut has quit IRC | 20:30 | |
*** savvas has joined #openstack-containers | 20:33 | |
*** openstackgerrit has quit IRC | 20:34 | |
*** sahilsinha_ has quit IRC | 20:35 | |
*** armaan has quit IRC | 20:35 | |
*** armaan has joined #openstack-containers | 20:35 | |
*** savvas_ has quit IRC | 20:35 | |
*** mgariepy has quit IRC | 20:35 | |
*** vkmc has quit IRC | 20:36 | |
*** penick has quit IRC | 20:38 | |
*** mgoddard has joined #openstack-containers | 20:39 | |
*** sahilsinha has joined #openstack-containers | 20:39 | |
*** oikiki has quit IRC | 20:40 | |
*** mgariepy has joined #openstack-containers | 20:40 | |
*** Oku_OS-away has quit IRC | 20:45 | |
*** Oku_OS-away has joined #openstack-containers | 20:45 | |
*** vkmc has joined #openstack-containers | 20:45 | |
*** vkmc has quit IRC | 20:46 | |
*** vkmc has joined #openstack-containers | 20:46 | |
*** oikiki has joined #openstack-containers | 20:48 | |
*** flwang1 has joined #openstack-containers | 20:58 | |
*** mgoddard has quit IRC | 20:59 | |
*** dave-mcc_ has joined #openstack-containers | 20:59 | |
*** linkmark has quit IRC | 21:20 | |
*** penick has joined #openstack-containers | 21:23 | |
*** jappleii__ has joined #openstack-containers | 21:23 | |
*** jappleii__ has quit IRC | 21:24 | |
*** jappleii__ has joined #openstack-containers | 21:25 | |
*** jappleii__ has quit IRC | 21:26 | |
*** jappleii__ has joined #openstack-containers | 21:27 | |
*** jappleii__ has quit IRC | 21:27 | |
*** jappleii__ has joined #openstack-containers | 21:28 | |
*** chhavi__ has joined #openstack-containers | 21:30 | |
*** chhavi__ has quit IRC | 21:34 | |
*** AlexeyAbashkin has joined #openstack-containers | 21:34 | |
*** AlexeyAbashkin has quit IRC | 21:38 | |
*** AlexeyAbashkin has joined #openstack-containers | 21:57 | |
*** rcernin has joined #openstack-containers | 21:58 | |
*** AlexeyAbashkin has quit IRC | 22:02 | |
*** flwang has quit IRC | 22:06 | |
*** flwang has joined #openstack-containers | 22:19 | |
*** jmlowe has quit IRC | 22:55 | |
*** armaan has quit IRC | 23:03 | |
*** armaan has joined #openstack-containers | 23:04 | |
*** absubram has joined #openstack-containers | 23:05 | |
*** marst has quit IRC | 23:08 | |
*** penick has quit IRC | 23:12 | |
*** jmlowe has joined #openstack-containers | 23:21 | |
*** chandankumar has quit IRC | 23:22 | |
*** chandankumar has joined #openstack-containers | 23:23 | |
*** chandankumar has quit IRC | 23:29 | |
*** jmlowe has quit IRC | 23:33 | |
*** chandankumar has joined #openstack-containers | 23:34 | |
*** penick has joined #openstack-containers | 23:36 | |
*** jmlowe has joined #openstack-containers | 23:53 | |
*** absubram has quit IRC | 23:54 | |
*** oikiki has quit IRC | 23:55 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!