*** threestrands has joined #openstack-containers | 00:05 | |
*** threestrands has quit IRC | 00:05 | |
*** threestrands has joined #openstack-containers | 00:05 | |
*** yamamoto has joined #openstack-containers | 00:27 | |
*** yamamoto has quit IRC | 00:34 | |
*** dave-mccowan has joined #openstack-containers | 00:55 | |
*** harlowja has quit IRC | 01:05 | |
*** yamamoto has joined #openstack-containers | 01:05 | |
*** yamamoto has quit IRC | 01:10 | |
*** gyankum has joined #openstack-containers | 01:20 | |
*** dave-mccowan has quit IRC | 01:21 | |
*** fragatin_ has quit IRC | 01:24 | |
*** fragatina has joined #openstack-containers | 01:25 | |
*** fragatina has quit IRC | 01:28 | |
*** yamamoto has joined #openstack-containers | 01:41 | |
*** yamamoto has quit IRC | 01:48 | |
*** fragatina has joined #openstack-containers | 02:16 | |
*** yamamoto has joined #openstack-containers | 02:19 | |
*** yamamoto has quit IRC | 02:25 | |
*** PanFengyun has quit IRC | 02:38 | |
*** ramishra has joined #openstack-containers | 02:56 | |
*** yamamoto has joined #openstack-containers | 02:57 | |
*** yamamoto has quit IRC | 03:01 | |
*** zhubingbing has joined #openstack-containers | 03:08 | |
*** threestrands has quit IRC | 03:10 | |
*** zhubingbing has quit IRC | 03:12 | |
*** threestrands has joined #openstack-containers | 03:13 | |
*** threestrands has quit IRC | 03:13 | |
*** threestrands has joined #openstack-containers | 03:14 | |
*** threestrands has quit IRC | 03:15 | |
*** threestrands has joined #openstack-containers | 03:15 | |
*** yamamoto has joined #openstack-containers | 03:32 | |
*** yamamoto has quit IRC | 03:38 | |
*** janki has joined #openstack-containers | 04:05 | |
*** yamamoto has joined #openstack-containers | 04:08 | |
*** yamamoto has quit IRC | 04:12 | |
*** ykarel|away has joined #openstack-containers | 04:17 | |
*** yamamoto has joined #openstack-containers | 04:43 | |
*** yamamoto has quit IRC | 04:44 | |
*** yamamoto has joined #openstack-containers | 04:44 | |
*** harlowja has joined #openstack-containers | 04:46 | |
*** ykarel|away is now known as ykarel | 04:55 | |
*** flwang1 has quit IRC | 04:58 | |
*** harlowja has quit IRC | 05:11 | |
*** chhagarw has joined #openstack-containers | 05:13 | |
*** udesale has joined #openstack-containers | 05:21 | |
*** yamamoto has quit IRC | 05:25 | |
*** lpetrut has joined #openstack-containers | 05:33 | |
*** mjura has joined #openstack-containers | 05:43 | |
*** yamamoto has joined #openstack-containers | 05:51 | |
*** iranzo has joined #openstack-containers | 05:52 | |
*** iranzo has joined #openstack-containers | 05:52 | |
*** gsimondon has joined #openstack-containers | 06:04 | |
*** ricolin has joined #openstack-containers | 06:10 | |
*** lpetrut has quit IRC | 06:16 | |
*** ricolin has quit IRC | 06:39 | |
*** ricolin has joined #openstack-containers | 06:43 | |
*** lpetrut has joined #openstack-containers | 06:43 | |
*** sfilatov has joined #openstack-containers | 06:58 | |
*** sfilatov has quit IRC | 07:12 | |
*** sfilatov_ has joined #openstack-containers | 07:15 | |
*** lpetrut has quit IRC | 07:17 | |
*** threestrands has quit IRC | 07:18 | |
*** rcernin has quit IRC | 07:20 | |
*** ricolin has quit IRC | 07:21 | |
*** AlexeyAbashkin has joined #openstack-containers | 07:23 | |
*** ricolin has joined #openstack-containers | 07:24 | |
*** Alexey_Abashkin has joined #openstack-containers | 07:26 | |
*** AlexeyAbashkin has quit IRC | 07:28 | |
*** Alexey_Abashkin is now known as AlexeyAbashkin | 07:28 | |
*** sfilatov has joined #openstack-containers | 07:29 | |
*** sfilatov_ has quit IRC | 07:31 | |
*** ykarel is now known as ykarel|lunch | 07:33 | |
*** lpetrut has joined #openstack-containers | 07:34 | |
*** lpetrut has quit IRC | 07:39 | |
*** mgoddard has joined #openstack-containers | 07:40 | |
*** sfilatov has quit IRC | 07:46 | |
*** sfilatov has joined #openstack-containers | 07:47 | |
*** yasemin has quit IRC | 07:51 | |
*** sfilatov has quit IRC | 07:52 | |
*** yasemin has joined #openstack-containers | 07:55 | |
*** sfilatov has joined #openstack-containers | 07:58 | |
*** lpetrut has joined #openstack-containers | 08:29 | |
*** ricolin has quit IRC | 08:30 | |
*** yasemin has quit IRC | 08:43 | |
*** ykarel|lunch is now known as ykarel | 08:54 | |
*** pcaruana has joined #openstack-containers | 08:54 | |
sfilatov | Hey | 08:57 |
---|---|---|
sfilatov | I know probably some of you are on summit | 08:57 |
sfilatov | But I'd like to discuss a topic which I sent to a mailing list | 08:58 |
*** pcaruana is now known as pcaruana|call| | 08:58 | |
sfilatov | I’d like to initiate a discussion about this bug: [1]. | 08:58 |
sfilatov | To resolve this issue we need to generate a secret cert and pass it to master nodes. We also need to store it somewhere to support scaling. | 08:58 |
sfilatov | This issue is specific for kubernetes drivers. Currently in magnum we have a general cert manager which is the same for all the drivers. | 08:58 |
sfilatov | What do you think about moving cert_manager logic into a driver-specific area? | 08:58 |
sfilatov | Having this common cert_manager logic forces us to generate client cert with “admin” and “system:masters” subject & organisation names [2], | 08:58 |
sfilatov | which is really something that we need only for kubernetes drivers. | 08:58 |
sfilatov | [1] https://bugs.launchpad.net/magnum/+bug/1766546 | 08:58 |
openstack | Launchpad bug 1766546 in Magnum "Multi-Master deployments for k8s driver use different service account keys" [Undecided,New] - Assigned to SFilatov (sergeyfilatov) | 08:58 |
sfilatov | [2] https://github.com/openstack/magnum/blob/2329cb7fb4d197e49d6c07d37b2f7ec14a11c880/magnum/conductor/handlers/common/cert_manager.py#L59-L64 | 08:58 |
*** sfilatov has quit IRC | 09:00 | |
*** sfilatov has joined #openstack-containers | 09:01 | |
*** sfilatov has quit IRC | 09:04 | |
*** yasemin has joined #openstack-containers | 09:06 | |
*** sfilatov has joined #openstack-containers | 09:09 | |
*** ktibi has joined #openstack-containers | 09:13 | |
*** sfilatov has quit IRC | 09:15 | |
*** salmankhan has joined #openstack-containers | 09:17 | |
*** sfilatov has joined #openstack-containers | 09:23 | |
*** sfilatov has quit IRC | 09:23 | |
*** sfilatov has joined #openstack-containers | 09:24 | |
*** sfilatov has quit IRC | 09:24 | |
*** sfilatov has joined #openstack-containers | 09:26 | |
*** parasitid has quit IRC | 09:26 | |
*** sfilatov has quit IRC | 09:26 | |
*** AlexeyAbashkin has quit IRC | 09:27 | |
*** AlexeyAbashkin has joined #openstack-containers | 09:30 | |
*** udesale_ has joined #openstack-containers | 09:30 | |
*** dardelean has joined #openstack-containers | 09:31 | |
*** udesale__ has joined #openstack-containers | 09:32 | |
*** udesale has quit IRC | 09:33 | |
*** udesale_ has quit IRC | 09:34 | |
*** ktibi has quit IRC | 09:37 | |
*** sfilatov has joined #openstack-containers | 09:37 | |
*** lpetrut_ has joined #openstack-containers | 09:38 | |
*** ktibi has joined #openstack-containers | 09:38 | |
*** lpetrut has quit IRC | 09:39 | |
*** sfilatov has joined #openstack-containers | 09:40 | |
*** parasitid has joined #openstack-containers | 09:41 | |
*** mgoddard has quit IRC | 09:48 | |
*** sfilatov has quit IRC | 09:50 | |
*** sfilatov has joined #openstack-containers | 09:51 | |
*** sfilatov has quit IRC | 09:52 | |
*** sfilatov has joined #openstack-containers | 09:57 | |
*** sfilatov has joined #openstack-containers | 09:59 | |
*** sfilatov has joined #openstack-containers | 10:00 | |
*** sfilatov_ has joined #openstack-containers | 10:03 | |
*** sfilatov has quit IRC | 10:03 | |
*** gyankum has quit IRC | 10:03 | |
*** sfilatov_ has quit IRC | 10:06 | |
*** sfilatov has joined #openstack-containers | 10:06 | |
*** sfilatov has quit IRC | 10:07 | |
*** mgoddard has joined #openstack-containers | 10:08 | |
*** sfilatov has joined #openstack-containers | 10:08 | |
*** sfilatov has quit IRC | 10:09 | |
*** zhubingbing has joined #openstack-containers | 10:13 | |
*** sfilatov has joined #openstack-containers | 10:14 | |
*** zhubingbing has quit IRC | 10:19 | |
*** ktibi has quit IRC | 10:28 | |
*** udesale__ has quit IRC | 10:36 | |
*** udesale__ has joined #openstack-containers | 10:36 | |
*** openstackgerrit has joined #openstack-containers | 10:41 | |
openstackgerrit | Piotr Mrowczynski proposed openstack/magnum master: Strip signed certificate https://review.openstack.org/570557 | 10:41 |
*** AlexeyAbashkin has quit IRC | 10:44 | |
*** sfilatov has quit IRC | 10:49 | |
*** sfilatov has joined #openstack-containers | 10:58 | |
*** sfilatov has quit IRC | 10:59 | |
*** sfilatov has joined #openstack-containers | 10:59 | |
*** olivenwk has joined #openstack-containers | 11:16 | |
*** AlexeyAbashkin has joined #openstack-containers | 11:25 | |
*** mikal has quit IRC | 11:26 | |
*** udesale__ has quit IRC | 11:31 | |
*** fragatina has quit IRC | 11:34 | |
*** mikal has joined #openstack-containers | 11:43 | |
*** parasitid has quit IRC | 11:58 | |
*** zhubingbing has joined #openstack-containers | 12:15 | |
*** parasitid has joined #openstack-containers | 12:16 | |
*** zhubingbing has quit IRC | 12:20 | |
*** ktibi has joined #openstack-containers | 12:23 | |
strigazi | sfilatov: Do you have a proposed implementaion in mind? How to move the cert_manager? Add it to the driver interface? | 12:24 |
sfilatov | strigazi: Yes, something like this. Now we call cert_manager in cluster_conductor handler. I suggest we move it out to the driver interface | 12:30 |
sfilatov | strigazi: But I haven't really looked into it the implementation yet. | 12:31 |
sfilatov | strigazi: I'd like to know if magnum community is okay with this | 12:32 |
strigazi | sfilatov: There two things that you descibe. One is the key to sign the token and one is the difference in the client certs | 12:48 |
sfilatov | strigazi: Yes, I meant that both this features require cert_manager driver-specific enhancements | 12:56 |
sfilatov | strigazi: Right now we have admin and system:masters as common and organization name which has no point for drivers other than k8s | 12:57 |
sfilatov | strigazi: And we need some methods to generate keypair for signing tokens | 12:58 |
sfilatov | strigazi: I though we could have this method for Kubernetes cert_manager class | 12:59 |
strigazi | sfilatov: for the client cert ok | 12:59 |
strigazi | sfilatov: but for the second certificate, where is it going to be stored? | 12:59 |
strigazi | sfilatov: unless it is not stored at all | 13:00 |
strigazi | sfilatov: and lives only as a heat param | 13:00 |
sfilatov | That is an open case | 13:01 |
sfilatov | We do need to have it somewhere so we could properly scale a cluster | 13:02 |
strigazi | sfilatov: if it is in heat, it will be there | 13:02 |
strigazi | sfilatov: it won't get lost | 13:02 |
strigazi | sfilatov: scaling would work | 13:02 |
sfilatov | Yeah, but can we trust heat on storing it as a parameter | 13:03 |
sfilatov | since it is a secret for out cluster | 13:03 |
strigazi | sfilatov: if we don't pass it with heat, the magnum API needs to be extended | 13:03 |
sfilatov | hmm | 13:04 |
sfilatov | strigazi: what kind of functionality? | 13:06 |
strigazi | sfilatov: at the moment we get the ca from the cluster | 13:06 |
sfilatov | strigazi: yes | 13:06 |
strigazi | sfilatov: at the moment we get the ca from the API | 13:06 |
strigazi | sfilatov: and we send cert requests for magnum to sign | 13:07 |
sfilatov | strigazi: yeah I see why we do that | 13:08 |
strigazi | sfilatov: we will need one more api request for the magnum api to be accepted | 13:08 |
strigazi | sfilatov: give me the private key to sign token | 13:09 |
sfilatov | strigazi: I'll get back to you in half an hour. Glad we could finally discuss this :) | 13:09 |
strigazi | ok | 13:11 |
*** sfilatov has quit IRC | 13:15 | |
*** gyankum has joined #openstack-containers | 13:25 | |
*** sfilatov has joined #openstack-containers | 13:34 | |
sfilatov | strigazi: >give me the private key to sign token | 13:35 |
sfilatov | strigazi: is there a use case for this? | 13:35 |
sfilatov | strigazi: all I know is that you pass this to controller-manager and api server | 13:35 |
sfilatov | strigazi: So controller-manager would sign the token | 13:36 |
strigazi | sfilatov: yes but we need the same key in all masters | 13:38 |
sfilatov | strigazi: I thought we could store the keypair the same way we store ca and client cert | 13:40 |
sfilatov | strigazi: so we could retrieve it anytime we need it | 13:40 |
sfilatov | strigazi: Or are you referring to an API to retrieve so we could call it from cluster nodes? | 13:41 |
strigazi | sfilatov: this ^^ | 13:41 |
*** gsimondon has quit IRC | 13:42 | |
sfilatov | strigazi: what benefits do we have in API in comparison to passing it through heat? | 13:42 |
sfilatov | strigazi: Security? | 13:42 |
strigazi | sfilatov: security only. All the others are cons | 13:43 |
strigazi | sfilatov: slower, since the nodes will do api calls, | 13:43 |
strigazi | sfilatov: heat provides a way to encrypt the data in the db already | 13:44 |
strigazi | sfilatov: and we also pass the trustID with heat which has the same level of security concern | 13:44 |
strigazi | sfilatov: it sounds like passing it with heat is ok | 13:45 |
sfilatov | strigazi: Yes, I guess that's the way | 13:45 |
strigazi | sfilatov: a concern that I have is | 13:46 |
strigazi | sfilatov: at the moment openstack doesn't have scoped tokens | 13:46 |
strigazi | sfilatov: so the trust ID has maximum access in the project. certs and openstack APIs | 13:47 |
strigazi | sfilatov: I'm not sure if it a security improvement to introduce a new keypair instead if the ca.key when the trustID is in the cluster. | 13:48 |
strigazi | sfilatov: even without the trustID, with the trustee user and pass, one can access the magnum api which means admin access to the cluster. | 13:50 |
sfilatov | strigazi: I see your point. But one cannot get the ca.key even with all the trust info | 13:51 |
strigazi | sfilatov: no he can't but he can access the kube api as admin | 13:51 |
sfilatov | strigazi: Well basically I agree with you. We expose quite a lot of sensitive information. So there's no point in doing so many code changes for that | 13:55 |
*** olivenwk has quit IRC | 13:55 | |
sfilatov | strigazi: but in this case we need to always expose ca.key | 13:55 |
sfilatov | strigazi: I'll commit this change and we can get to this topic with others later | 13:57 |
*** olivenwk has joined #openstack-containers | 13:58 | |
*** openstacking_123 has joined #openstack-containers | 13:58 | |
strigazi | sfilatov: I would create a new keypair and pass with jeat | 14:00 |
*** ykarel is now known as ykarel|away | 14:00 | |
strigazi | sfilatov: I would create a new keypair and pass with heat | 14:00 |
strigazi | sfilatov: I would create a new keypair and pass it with heat :) | 14:01 |
*** olivenwk has quit IRC | 14:12 | |
brtknr | What do I need to do to get magnum working on devstack? | 14:16 |
*** zhubingbing has joined #openstack-containers | 14:17 | |
brtknr | With all the default settings, I can get magnum to spawn VMs but they fail to start any of the kubernetes services during cloud-init | 14:19 |
*** AlexeyAbashkin has quit IRC | 14:19 | |
brtknr | Btw, it works fine on swarm-mode, only kubernetes fails | 14:19 |
brtknr | If this is a known issue, what is the recommended way to test new features for magnum? | 14:20 |
*** zhubingbing has quit IRC | 14:22 | |
strigazi | brtknr where it fails for kubernetes? | 14:23 |
brtknr | strigazi: all the kube*.service fail to start after configuring kube | 14:33 |
strigazi | brtknr: journalctl -u kube-apiserver --no-pager | 14:33 |
brtknr | the thing is, the service does not exist because kubernetes is not installed inside my image | 14:34 |
*** armaan has joined #openstack-containers | 14:35 | |
brtknr | (or it fails to install) | 14:36 |
strigazi | cat /var/log/cloud-init-output.log | 14:39 |
brtknr | i checkout out the master branch and am currently running ./stack.sh so may be a little while, one sec | 14:40 |
*** armaan has quit IRC | 14:42 | |
brtknr | currently on part-007 | 14:50 |
brtknr | cloud-init-output says configuring kubernetes (master) | 14:51 |
*** AlexeyAbashkin has joined #openstack-containers | 14:56 | |
brtknr | ... for the last 10 mins | 14:59 |
brtknr | http://paste.openstack.org/show/721984/ | 15:01 |
brtknr | actually, now it failed as before | 15:01 |
brtknr | that is my cloud-init-output.log | 15:01 |
brtknr | looks like it is timing out | 15:01 |
openstacking_123 | anyone now good way to figureout exactly what part of a cloud init script is throwing a warnig ? for example util.py[WARNING]: Failed running /var/lib/cloud/instance/scripts/part-005 [1] ? If I just manually execute the script using sh -x I don't see any issue. | 15:01 |
openstacking_123 | Trying to figure out if I need to execute the script using some util.py function to recreate the error? | 15:02 |
*** yamamoto has quit IRC | 15:02 | |
brtknr | here's my cluster template and cluster create commands: http://paste.openstack.org/show/721985/ | 15:04 |
openstacking_123 | brtknr are you on pike? | 15:05 |
brtknr | openstacking_123: cat /var/log/cloud-init.log | 15:05 |
brtknr | openstacking_123: no i am testing rocky | 15:05 |
openstacking_123 | Aww alright | 15:06 |
openstacking_123 | Was going to say switch to 26 if on pike | 15:06 |
brtknr | openstacking_123: what do you mean switch to 26? | 15:06 |
brtknr | openstacking_123: ahhh atomic? | 15:06 |
brtknr | i have managed to get k8s working on 27 on a different cluster, its just failing on devstack | 15:07 |
openstacking_123 | brtknr interesting | 15:07 |
brtknr | but the other cluster has openstack pike but magnum queens | 15:07 |
*** parasitid has quit IRC | 15:07 | |
brtknr | https://www.stackhpc.com/magnum-queens.html | 15:08 |
openstacking_123 | brtknr I think our issues are similar I none of my services start I think all related to ssl | 15:08 |
openstacking_123 | Im using openstack ansible pike | 15:08 |
brtknr | i see, we use kayobe to deploy openstack | 15:09 |
openstacking_123 | brtknr is your ssl dir populated ? | 15:09 |
brtknr | inside the instance? | 15:09 |
strigazi | brtknr do you have access to docker hub from the vm | 15:09 |
strigazi | ? | 15:09 |
openstacking_123 | yeah | 15:10 |
brtknr | strigazi: as in sudo docker ps? | 15:10 |
openstacking_123 | brtknr all my stuff fails [0;1;31mFAILED[0m] Failed to start kubernetes-kubelet. seemed related to tls not generating | 15:11 |
brtknr | strigazi: ping hub.docker.com is not responsive | 15:11 |
strigazi | brtknr: try do docker pull docker.io/openstackmagnum/kubernetes-apiserver:v1.9.3 | 15:11 |
strigazi | brtknr: this is the problem | 15:12 |
ykarel|away | strigazi++ | 15:12 |
strigazi | brtknr: or this skopeo inspect docker://docker.io/openstackmagnum/kubernetes-apiserver:v1.9.3 | 15:13 |
brtknr | looks that that is the problem! | 15:13 |
ykarel|away | strigazi, skopeo installed in vm? | 15:13 |
brtknr | i have no access to docker hub | 15:14 |
ykarel|away | in atomic vm | 15:14 |
strigazi | ykarel|away: yes | 15:14 |
ykarel|away | okk good | 15:14 |
strigazi | atomic uses skopeo | 15:14 |
ykarel|away | ohh good, didn't knew that | 15:14 |
* ykarel|away leaving | 15:15 | |
brtknr | strigazi: do i need to do something special to configure instances to have access to docker hub | 15:15 |
strigazi | openstacking_123: pike needs fedora 26 it doesn | 15:16 |
strigazi | openstacking_123: pike needs fedora 26 it doesn't work with newer versions | 15:16 |
openstacking_123 | strigazi thanks for confirming | 15:16 |
strigazi | brtknr: cluster template create --dns-nameserver <a dns that works> | 15:16 |
strigazi | brtknr: that works for your cloud | 15:16 |
strigazi | brtknr: or mirror all containers somewhere that the vms can pull from | 15:17 |
openstacking_123 | strigazi would you be kind enough to check out this error on part-0005 https://gist.githubusercontent.com/fritzstauff/3c296c03612108f3c8a54f1bde9a84cd/raw/ed4d58cdaf63c086f7fd581599d3033041060f1c/magnum%2520error | 15:19 |
*** ykarel|away has quit IRC | 15:19 | |
strigazi | openstacking_123: more lines? | 15:20 |
openstacking_123 | Thats it | 15:20 |
strigazi | which file is this? | 15:20 |
openstacking_123 | strigazi /var/log/cloud-init.log | 15:21 |
strigazi | openstacking_123 /var/log/cloud-init-output.log | 15:21 |
openstacking_123 | examining /usr/lib/python3.6/site-packages/cloudinit/util.py", line 802 | 15:21 |
openstacking_123 | Seems related to ssl | 15:21 |
*** chhagarw has quit IRC | 15:22 | |
openstacking_123 | strigazi https://gist.github.com/fritzstauff/3c296c03612108f3c8a54f1bde9a84cd updated with comment | 15:23 |
*** iranzo has quit IRC | 15:23 | |
*** parasitid has joined #openstack-containers | 15:26 | |
brtknr | strigazi: i can ping 8.8.8.8 from the master node and my dns_nameserver is currently set to 8.8.8.8 | 15:26 |
*** pcaruana|call| has quit IRC | 15:27 | |
brtknr | although my /etc/resolv.conf has nameserver set to 10.0.0.2 despite the fact that my cluster template has dns nameserver as 8.8.8.8 | 15:31 |
strigazi | openstacking_123 what is the file /var/lib/cloud/instance/scripts/part-005 ? | 15:31 |
strigazi | openstacking_123: the make-cert one? | 15:32 |
openstacking_123 | Yes sir | 15:32 |
strigazi | can you execute it from the node? | 15:32 |
strigazi | sh -x /var/lib/cloud/instance/scripts/part-005 | 15:32 |
strigazi | brtknr in my env at cern this doesn't work either for devstack, I need to set our internal dns | 15:33 |
openstacking_123 | I think I am actually missing a python package | 15:34 |
openstacking_123 | Could be testing wrong but on my atomic host util.py | 15:34 |
openstacking_123 | ImportError: No module named yaml | 15:34 |
openstacking_123 | When manually run just using system python | 15:35 |
strigazi | openstacking_123 kubernetes or swarm-mode? | 15:35 |
strigazi | which coe? | 15:35 |
openstacking_123 | Kubernetes | 15:35 |
strigazi | atomic host status | 15:35 |
openstacking_123 | If I execute part-005 by hand no errors | 15:35 |
openstacking_123 | Version: 26.157 (2017-10-29 14:42:37) | 15:36 |
openstacking_123 | Commit: c099633883cd8d06895e32a14c63f6672072430c151de882223e4abe20efa7ca | 15:36 |
openstacking_123 | GPGSignature: Valid signature by E641850B77DF435378D1D7E2812A6B4B64DAB85D | 15:36 |
strigazi | which command exactly fail when you run /var/lib/cloud/instance/scripts/part-005 ? | 15:37 |
openstacking_123 | No idea since the log just refernce util.py lines that fail | 15:38 |
openstacking_123 | util.py", line 802 | 15:38 |
strigazi | . /etc/sysconfig/heat-paras | 15:39 |
strigazi | curl $MAGNUM_URL | 15:39 |
strigazi | . /etc/sysconfig/heat-params | 15:39 |
strigazi | curl $MAGNUM_URL | 15:39 |
openstacking_123 | https://gist.githubusercontent.com/fritzstauff/3c296c03612108f3c8a54f1bde9a84cd/raw/0cf5034dd3be598279ca3ce64622a31d37aad86f/Magnum%2520details | 15:41 |
strigazi | openstacking_123: did you run this cmd: | 15:42 |
strigazi | sh -x /var/lib/cloud/instance/scripts/part-005 | 15:43 |
openstacking_123 | yup | 15:43 |
openstacking_123 | no bad output | 15:43 |
openstacking_123 | will test again | 15:43 |
openstacking_123 | install gcc so I can try adding that python yaml module as well | 15:43 |
strigazi | give me all the output, I don't get where it fails, in which call | 15:43 |
brtknr | strigazi: thank you! all i had to do in the end was `openstack subnet set private-subnet --dns-nameserver 8.8.8.8` then reboot the instance | 15:43 |
strigazi | openstacking_123: that is not the point, you don't need to add anything | 15:44 |
openstacking_123 | strigazi will cancel | 15:44 |
strigazi | I don't understand if it manages to get the ca from the magnum api | 15:46 |
openstacking_123 | Output https://gist.githubusercontent.com/fritzstauff/dc7568f395f6a80cacdf9498b00c815e/raw/831a3f90c24e5bf278d9ca8cc1f4b8c5aea43e5f/part-005 | 15:46 |
openstacking_123 | strigazi ^ | 15:46 |
strigazi | openstacking_123: it can not get a token from keystone | 15:47 |
strigazi | openstacking_123: http://paste.openstack.org | 15:49 |
openstacking_123 | strigazi Thank you! Can I think that past url is missing the end part? | 15:53 |
strigazi | did that curl call work? | 15:55 |
openstacking_123 | Nope! | 15:56 |
openstacking_123 | strigazi recource not found | 15:57 |
openstacking_123 | Must be an issue with my public endpoint | 15:57 |
openstacking_123 | Thank you so much will report back soon | 15:57 |
openstacking_123 | going to test on internal endpoint | 15:57 |
openstacking_123 | 3 days of off and on troubleshooting! | 15:58 |
openstacking_123 | same issue on internal guess I will need to double check my keystone / magnum integration | 16:01 |
*** yamamoto has joined #openstack-containers | 16:06 | |
*** yamamoto has quit IRC | 16:10 | |
*** mjura has quit IRC | 16:11 | |
*** zhubingbing has joined #openstack-containers | 16:19 | |
*** zhubingbing has quit IRC | 16:23 | |
openstacking_123 | strigazi any idea where it is populating the token url? After some testing it all works if the url is 5000/v3/auth/tokens instead of :5000/auth/tokens | 16:24 |
*** salmankhan has quit IRC | 16:25 | |
*** cliles has quit IRC | 16:27 | |
*** cliles has joined #openstack-containers | 16:27 | |
strigazi | openstacking_123: http://git.openstack.org/cgit/openstack/magnum/tree/magnum/drivers/common/templates/kubernetes/fragments/make-cert.sh?h=stable%2Fpike#n96 | 16:30 |
openstacking_123 | strigazi seems like if I add v3 to my keytone endpoint it will work then | 16:33 |
openstacking_123 | Its odd because I have a working version that does not have that | 16:33 |
*** ramishra has quit IRC | 16:44 | |
*** yamamoto has joined #openstack-containers | 16:50 | |
*** fragatina has joined #openstack-containers | 16:54 | |
*** mgoddard has quit IRC | 16:59 | |
*** yamamoto has quit IRC | 17:00 | |
*** lpetrut__ has joined #openstack-containers | 17:17 | |
*** mgoddard has joined #openstack-containers | 17:20 | |
*** lpetrut_ has quit IRC | 17:21 | |
*** janki has quit IRC | 17:31 | |
*** pcaruana has joined #openstack-containers | 17:35 | |
*** iranzo has joined #openstack-containers | 17:39 | |
*** iranzo has joined #openstack-containers | 17:39 | |
*** sfilatov has quit IRC | 17:59 | |
*** sfilatov has joined #openstack-containers | 18:05 | |
*** gyankum has quit IRC | 18:07 | |
*** AlexeyAbashkin has quit IRC | 18:10 | |
*** iranzo has quit IRC | 18:12 | |
*** pcaruana has quit IRC | 18:14 | |
*** lpetrut__ has quit IRC | 18:14 | |
*** zhubingbing has joined #openstack-containers | 18:20 | |
*** zhubingbing has quit IRC | 18:25 | |
*** mgoddard has quit IRC | 18:31 | |
*** mikal has quit IRC | 18:34 | |
*** mikal has joined #openstack-containers | 18:34 | |
*** fragatina has quit IRC | 18:59 | |
*** lpetrut__ has joined #openstack-containers | 19:08 | |
*** pcichy has quit IRC | 19:12 | |
*** sfilatov has quit IRC | 19:15 | |
*** sfilatov has joined #openstack-containers | 19:16 | |
*** sfilatov has quit IRC | 19:17 | |
*** sfilatov has joined #openstack-containers | 19:18 | |
*** pcichy has joined #openstack-containers | 19:19 | |
*** sfilatov has quit IRC | 19:23 | |
*** lpetrut__ has quit IRC | 19:35 | |
*** sfilatov has joined #openstack-containers | 20:07 | |
*** sfilatov has quit IRC | 20:12 | |
*** harlowja has joined #openstack-containers | 20:16 | |
*** ktibi has quit IRC | 20:26 | |
*** dardelean has quit IRC | 20:32 | |
*** yolanda has quit IRC | 20:34 | |
*** fragatina has joined #openstack-containers | 20:43 | |
*** fragatin_ has joined #openstack-containers | 20:44 | |
*** fragatin_ has quit IRC | 20:44 | |
*** fragatina has quit IRC | 20:44 | |
*** fragatina has joined #openstack-containers | 20:44 | |
*** fragatina has quit IRC | 20:45 | |
*** fragatina has joined #openstack-containers | 20:46 | |
*** fragatina has quit IRC | 20:46 | |
*** fragatina has joined #openstack-containers | 20:47 | |
*** fragatina has quit IRC | 20:47 | |
*** fragatina has joined #openstack-containers | 20:47 | |
*** zhubingbing has joined #openstack-containers | 21:22 | |
*** zhubingbing has quit IRC | 21:27 | |
*** pcichy has quit IRC | 21:43 | |
*** flwang1 has joined #openstack-containers | 21:52 | |
*** harlowja has quit IRC | 22:02 | |
*** openstacking_123 has quit IRC | 22:14 | |
*** openstacking_123 has joined #openstack-containers | 23:20 | |
*** zhubingbing has joined #openstack-containers | 23:24 | |
*** pcichy has joined #openstack-containers | 23:25 | |
*** zhubingbing has quit IRC | 23:29 | |
*** openstacking_123 has quit IRC | 23:39 | |
*** kbyrne has quit IRC | 23:52 | |
*** kbyrne has joined #openstack-containers | 23:56 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!