*** rcernin_ has joined #openstack-containers | 00:34 | |
*** rcernin has quit IRC | 00:37 | |
*** yamamoto has joined #openstack-containers | 00:43 | |
*** yamamoto has quit IRC | 00:48 | |
*** hongbin has joined #openstack-containers | 01:02 | |
*** yamamoto has joined #openstack-containers | 01:29 | |
*** yamamoto has quit IRC | 01:33 | |
*** yamamoto has joined #openstack-containers | 01:59 | |
*** yamamoto has quit IRC | 02:04 | |
*** rcernin_ has quit IRC | 02:09 | |
*** yamamoto has joined #openstack-containers | 02:14 | |
*** yamamoto has quit IRC | 02:18 | |
*** markguz has joined #openstack-containers | 02:19 | |
*** markguz has quit IRC | 02:23 | |
*** ramishra has joined #openstack-containers | 02:27 | |
*** yamamoto has joined #openstack-containers | 02:29 | |
*** yamamoto has quit IRC | 02:34 | |
*** yamamoto has joined #openstack-containers | 02:44 | |
*** yamamoto has quit IRC | 02:49 | |
*** yamamoto has joined #openstack-containers | 02:49 | |
*** yamamoto has quit IRC | 02:49 | |
*** ianychoi_ has joined #openstack-containers | 02:58 | |
*** yamamoto has joined #openstack-containers | 03:01 | |
*** ianychoi_ has quit IRC | 03:01 | |
*** ianychoi has quit IRC | 03:02 | |
*** ianychoi_ has joined #openstack-containers | 03:02 | |
*** yamamoto has quit IRC | 03:06 | |
*** yamamoto has joined #openstack-containers | 03:16 | |
*** yamamoto has quit IRC | 03:20 | |
*** yamamoto has joined #openstack-containers | 03:21 | |
*** hongbin has quit IRC | 03:23 | |
*** udesale has joined #openstack-containers | 03:51 | |
*** ramishra has quit IRC | 04:08 | |
*** ramishra has joined #openstack-containers | 04:10 | |
*** ramishra has quit IRC | 04:23 | |
*** chhagarw has joined #openstack-containers | 04:24 | |
*** ramishra has joined #openstack-containers | 04:26 | |
*** janki has joined #openstack-containers | 04:40 | |
openstackgerrit | Feilong Wang proposed openstack/magnum master: Sync service account keys for multi masters https://review.openstack.org/576029 | 04:48 |
---|---|---|
*** flwang1 has quit IRC | 04:59 | |
*** rcernin has joined #openstack-containers | 05:20 | |
*** udesale_ has joined #openstack-containers | 05:31 | |
*** udesale has quit IRC | 05:33 | |
*** iranzo has joined #openstack-containers | 05:54 | |
*** gsimondon has joined #openstack-containers | 06:03 | |
*** ramishra has quit IRC | 06:13 | |
*** gsimondon has quit IRC | 06:14 | |
*** sheel has joined #openstack-containers | 06:14 | |
*** ramishra has joined #openstack-containers | 06:14 | |
*** mvpnitesh has joined #openstack-containers | 06:22 | |
*** chhavi__ has joined #openstack-containers | 06:26 | |
*** chhagarw has quit IRC | 06:27 | |
*** udesale__ has joined #openstack-containers | 06:35 | |
*** pcaruana has joined #openstack-containers | 06:35 | |
*** udesale_ has quit IRC | 06:38 | |
*** yolanda__ is now known as yolanda | 06:43 | |
*** udesale__ is now known as udesale | 06:54 | |
*** armaan has joined #openstack-containers | 07:01 | |
*** rcernin has quit IRC | 07:01 | |
*** gsimondon has joined #openstack-containers | 07:11 | |
*** belmoreira has joined #openstack-containers | 07:11 | |
*** janki has quit IRC | 07:36 | |
*** ktibi has joined #openstack-containers | 07:49 | |
*** AlexeyAbashkin has joined #openstack-containers | 07:57 | |
*** janki has joined #openstack-containers | 08:00 | |
*** armaan has quit IRC | 08:01 | |
*** armaan has joined #openstack-containers | 08:01 | |
*** olivenwk has joined #openstack-containers | 08:04 | |
*** flwang1 has joined #openstack-containers | 08:07 | |
*** slunkad has joined #openstack-containers | 08:22 | |
*** mvpnitesh has quit IRC | 08:23 | |
*** lpetrut has joined #openstack-containers | 08:23 | |
*** armaan has quit IRC | 08:23 | |
*** armaan has joined #openstack-containers | 08:23 | |
*** mgoddard has joined #openstack-containers | 08:34 | |
*** serlex has joined #openstack-containers | 08:36 | |
*** mvpnitesh has joined #openstack-containers | 08:41 | |
*** chhagarw has joined #openstack-containers | 08:59 | |
*** chhavi__ has quit IRC | 09:02 | |
*** vijaykc4 has joined #openstack-containers | 09:03 | |
*** flwang1 has quit IRC | 09:10 | |
mvpnitesh | hi all, I'm trying to create a k8 cluster with Openstack pike release, i'm getting the below error | 09:12 |
mvpnitesh | + sudo -E atomic install --storage ostree --system --system-package no --set REQUESTS_CA_BUNDLE=/etc/pki/tls/certs/ca-bundle.crt --name heat-container-agent docker.io/openstackmagnum/heat-container-agent:rawhide | 09:12 |
mvpnitesh | pinging docker registry returned: Get http://registry-1.docker.io/v2/: dial tcp 54.152.209.167:80: i/o timeout | 09:12 |
mvpnitesh | + systemctl start heat-container-agent | 09:12 |
mvpnitesh | Failed to start heat-container-agent.service: Unit heat-container-agent.service not found. | 09:12 |
mvpnitesh | i'm finding this error at /var/log/cloud-init-out.log | 09:12 |
*** salmankhan has joined #openstack-containers | 09:14 | |
*** salmankhan1 has joined #openstack-containers | 09:17 | |
*** salmankhan has quit IRC | 09:18 | |
*** salmankhan1 is now known as salmankhan | 09:18 | |
*** flwang1 has joined #openstack-containers | 09:26 | |
*** armaan has quit IRC | 09:33 | |
*** armaan has joined #openstack-containers | 09:36 | |
*** armaan has quit IRC | 09:38 | |
*** armaan has joined #openstack-containers | 09:42 | |
*** vijaykc4 has quit IRC | 09:48 | |
*** vijaykc4 has joined #openstack-containers | 09:49 | |
*** salmankhan has quit IRC | 09:55 | |
*** armaan has quit IRC | 09:55 | |
*** armaan has joined #openstack-containers | 09:57 | |
*** pcichy has joined #openstack-containers | 09:57 | |
*** salmankhan has joined #openstack-containers | 09:59 | |
strigazi | mvpnitesh: It seems you can't reach the docker registry | 10:03 |
strigazi | mnaser: magnum queens? do you have the fixed (for RBAC) queens magnum client? | 10:03 |
mvpnitesh | strigazi: hi, how can i fix it, any suggestions ?? | 10:04 |
strigazi | mnaser: https://docs.openstack.org/releasenotes/magnum/queens.html#upgrade-notes | 10:04 |
strigazi | mvpnitesh: curl -v https://registry-1.docker.io | 10:05 |
strigazi | mvpnitesh: I'll be back in 45' you can mirror all containers like so: | 10:05 |
strigazi | mvpnitesh: https://docs.openstack.org/magnum/latest/user/index.html#container-infra-prefix | 10:05 |
mvpnitesh | strigazi: I've deleted my cluster, i'll re create it and i'll try | 10:06 |
*** vijaykc4 has quit IRC | 10:41 | |
*** kittens has quit IRC | 10:44 | |
*** yamamoto has quit IRC | 10:44 | |
mnaser | strigazi: updated client ended up fixing things. I still have some failing things in terms of k8s conformance tests | 11:05 |
mvpnitesh | strigazi: Same error, should i add the container-infra-prefix in the labels?? | 11:07 |
strigazi | mvpnitesh you need to mirror all images to a local registry if you can not access docker.io from your vms | 11:08 |
strigazi | mvpnitesh: then you can use container_infra_prefix | 11:08 |
mvpnitesh | strigazi: should i use this container_infro_prefix in cluster-template or at cluster-creation ?? | 11:09 |
strigazi | mvpnitesh: it is the same, labels from CT are copied to cluster | 11:10 |
strigazi | I usually have in CT | 11:10 |
mvpnitesh | stragazi: will it be something like this "magnum cluster-template-create k8s-cluster-template-nitesh --label docker.io/openstackmagnum/kubernetes-apiserver=docker.io/openstackmagnum/kubernetes-apiserver" | 11:18 |
mvpnitesh | is that the i've to to container-infra-prefix ?? | 11:19 |
strigazi | --labels container_infra_prefix="THE_LOCAL_REGISTRY/" | 11:20 |
strigazi | mvpnitesh: Can yo confirm that you don't have internet access from your vms? | 11:20 |
strigazi | mvpnitesh: if you can not access docker.io probably there are a lot of things that you can not access | 11:21 |
mvpnitesh | stragazi: thanks. I've internet access, some times proxy is set and sometimes proxy is not getting set automatically | 11:21 |
canori01 | strigazi: Are there plans to get the CoreOS driver working again? | 11:26 |
*** vijaykc4 has joined #openstack-containers | 11:26 | |
strigazi | canori01: no one works on it, people ask about it but no one contributes. My team is using fedora. If you want, I can help you fix it. | 11:29 |
canori01 | yeah, that would be great. I'll take a stab at it | 11:30 |
*** dave-mccowan has joined #openstack-containers | 11:30 | |
strigazi | canori01: excellent, if you give it a go, we can also discuss it tmr in the meeting. | 11:30 |
strigazi | canori01: You can create a story in storyboard.openstack.org | 11:31 |
*** dave-mcc_ has joined #openstack-containers | 11:33 | |
*** dave-mccowan has quit IRC | 11:35 | |
openstackgerrit | Spyros Trigazis proposed openstack/magnum master: [cern] Create admin cluster-role https://review.openstack.org/576112 | 11:39 |
openstackgerrit | Spyros Trigazis proposed openstack/magnum master: k8s_fedora: Create admin cluster-role https://review.openstack.org/576112 | 11:39 |
strigazi | the [cern] tag was muscle memory | 11:40 |
*** armaan has quit IRC | 11:43 | |
*** armaan has joined #openstack-containers | 11:43 | |
*** yamamoto has joined #openstack-containers | 11:45 | |
*** udesale_ has joined #openstack-containers | 11:49 | |
*** yamamoto has quit IRC | 11:52 | |
*** udesale has quit IRC | 11:52 | |
*** yamamoto has joined #openstack-containers | 11:52 | |
*** udesale_ has quit IRC | 11:54 | |
openstackgerrit | Spyros Trigazis proposed openstack/magnum master: k8s_fedora: Create admin cluster-role https://review.openstack.org/576112 | 11:59 |
*** ispp has joined #openstack-containers | 12:00 | |
*** mvpnitesh has quit IRC | 12:11 | |
*** armaan has quit IRC | 12:18 | |
*** armaan has joined #openstack-containers | 12:18 | |
*** serlex has quit IRC | 12:52 | |
*** vijaykc4 has quit IRC | 13:02 | |
*** jmlowe has quit IRC | 13:15 | |
*** flwang1 has quit IRC | 13:19 | |
*** armaan has quit IRC | 13:31 | |
*** ispp has quit IRC | 13:31 | |
*** armaan has joined #openstack-containers | 13:32 | |
*** belmorei_ has joined #openstack-containers | 13:33 | |
*** belmoreira has quit IRC | 13:34 | |
*** canori01 has quit IRC | 13:35 | |
*** ispp has joined #openstack-containers | 13:35 | |
*** flwang1 has joined #openstack-containers | 13:36 | |
*** flwang1 has quit IRC | 13:41 | |
*** yamamoto has quit IRC | 13:42 | |
*** yamamoto has joined #openstack-containers | 13:42 | |
*** udesale has joined #openstack-containers | 13:48 | |
*** armaan has quit IRC | 13:52 | |
*** armaan has joined #openstack-containers | 13:52 | |
*** jmlowe has joined #openstack-containers | 13:55 | |
*** markguz has joined #openstack-containers | 13:59 | |
*** sheel has quit IRC | 13:59 | |
*** flwang1 has joined #openstack-containers | 14:22 | |
*** canori01 has joined #openstack-containers | 14:22 | |
*** serlex has joined #openstack-containers | 14:25 | |
*** hongbin has joined #openstack-containers | 14:42 | |
*** janki has quit IRC | 14:44 | |
*** lpetrut has quit IRC | 15:01 | |
*** lpetrut has joined #openstack-containers | 15:02 | |
*** dtruong_ has joined #openstack-containers | 15:07 | |
*** dtruong has quit IRC | 15:12 | |
*** belmorei_ has quit IRC | 15:12 | |
*** ispp has quit IRC | 15:12 | |
*** lpetrut has quit IRC | 15:13 | |
*** gsimondon has quit IRC | 15:14 | |
*** ispp has joined #openstack-containers | 15:15 | |
*** belmoreira has joined #openstack-containers | 15:15 | |
*** flwang1 has quit IRC | 15:15 | |
*** udesale_ has joined #openstack-containers | 15:20 | |
*** udesale has quit IRC | 15:22 | |
*** udesale_ has quit IRC | 15:25 | |
*** armaan has quit IRC | 15:31 | |
*** olivenwk has quit IRC | 15:36 | |
*** flwang1 has joined #openstack-containers | 15:40 | |
*** lpetrut has joined #openstack-containers | 15:47 | |
*** lpetrut has quit IRC | 15:49 | |
*** ktibi has quit IRC | 15:49 | |
*** lpetrut has joined #openstack-containers | 15:49 | |
*** janki has joined #openstack-containers | 15:51 | |
*** ispp has quit IRC | 15:52 | |
*** yamamoto has quit IRC | 15:53 | |
*** yamamoto has joined #openstack-containers | 15:54 | |
*** yamamoto has quit IRC | 15:56 | |
*** yamamoto has joined #openstack-containers | 15:56 | |
*** lpetrut has quit IRC | 15:56 | |
*** lpetrut has joined #openstack-containers | 15:58 | |
*** lpetrut has quit IRC | 16:11 | |
*** AlexeyAbashkin has quit IRC | 16:11 | |
*** lpetrut has joined #openstack-containers | 16:16 | |
*** pcaruana has quit IRC | 16:20 | |
*** dave-mcc_ has quit IRC | 16:30 | |
*** yamamoto has quit IRC | 16:36 | |
*** yamamoto has joined #openstack-containers | 16:36 | |
*** armaan has joined #openstack-containers | 16:36 | |
*** yamamoto has quit IRC | 16:41 | |
*** mgoddard has quit IRC | 17:00 | |
*** iranzo has quit IRC | 17:30 | |
*** armaan has quit IRC | 17:37 | |
*** yamamoto has joined #openstack-containers | 17:38 | |
*** mgoddard has joined #openstack-containers | 17:39 | |
*** yamamoto has quit IRC | 17:42 | |
*** janki has quit IRC | 17:56 | |
flwang1 | imdigitaljim: ping re the multi master keys | 18:02 |
flwang1 | strigazi: ^ | 18:02 |
flwang1 | based on my testing, seems we don't have to sign the keypair by cluster ca | 18:03 |
imdigitaljim | it in theory works because its still pki but having it be cert/key vs public/private key because the (signed) cert usually contains additional metadata and signed by the CA to verify authenticity | 18:15 |
imdigitaljim | https://github.com/kelseyhightower/kubernetes-the-hard-way/blob/master/docs/04-certificate-authority.md#the-service-account-key-pair | 18:15 |
imdigitaljim | k8s the hard way still uses ca signing method | 18:16 |
imdigitaljim | not to mention we still have signing methods built into magnum so it still shouldnt be too difficult to integrate it if we still want to go that route | 18:16 |
*** dave-mccowan has joined #openstack-containers | 18:17 | |
*** armaan has joined #openstack-containers | 18:21 | |
*** armaan has quit IRC | 18:23 | |
*** pcaruana has joined #openstack-containers | 18:26 | |
*** AlexeyAbashkin has joined #openstack-containers | 18:32 | |
*** mgoddard has quit IRC | 18:34 | |
*** AlexeyAbashkin has quit IRC | 18:35 | |
flwang1 | imdigitaljim: but in my testing, if i use a signed cert with the private key, it doesn't work | 18:38 |
flwang1 | public/private key works | 18:38 |
*** AlexeyAbashkin has joined #openstack-containers | 18:38 | |
*** yamamoto has joined #openstack-containers | 18:39 | |
*** pcaruana has quit IRC | 18:39 | |
flwang1 | I also checked KH's guide | 18:39 |
flwang1 | and I assume the signed cert/key should work, but it's not, at least in my testing | 18:39 |
flwang1 | imdigitaljim: ^ | 18:39 |
imdigitaljim | id assume key distribution is correct but maybe perhaps relates to a common problem of the "keyusages" which should contain ["signing", "key encipherment", "server auth", "client auth"], | 18:41 |
flwang1 | imdigitaljim: https://review.openstack.org/#/c/576029/1/magnum/drivers/heat/k8s_fedora_template_def.py | 18:42 |
flwang1 | i'm using the existing sign function | 18:42 |
imdigitaljim | does our api include all 4 of these? I couldnt find x509.OID_SERVER_AUTH | 18:42 |
*** salmankhan has quit IRC | 18:43 | |
flwang1 | seems the answer is no | 18:44 |
flwang1 | is there any document mentioned the common problem of the 'keyusages'? | 18:44 |
*** yamamoto has quit IRC | 18:44 | |
imdigitaljim | i believe x509.KeyUsage(True, False, True, False, False, False, False, | 18:45 |
imdigitaljim | False, False) covers key encipherment and signing | 18:45 |
imdigitaljim | but i never saw a server auth | 18:45 |
imdigitaljim | but i wasnt sure if i just missed it | 18:45 |
*** AlexeyAbashkin has quit IRC | 18:45 | |
*** lpetrut has quit IRC | 18:48 | |
*** jmlowe has quit IRC | 18:50 | |
flwang1 | imdigitaljim: is there any document mentioned the common problem of the 'keyusages'? | 18:52 |
flwang1 | in other words, why do we have to contain those 4 items? | 18:52 |
openstackgerrit | Jim Bach proposed openstack/magnum master: Added error handling for discoveryurl https://review.openstack.org/576233 | 18:53 |
imdigitaljim | its in the kelsey hightower stuff | 18:53 |
imdigitaljim | when he uses the -profile=kubernetes in the arg for cfssl | 18:54 |
*** armaan has joined #openstack-containers | 18:54 | |
imdigitaljim | the profile it refers to is https://github.com/kelseyhightower/kubernetes-the-hard-way/blob/master/docs/04-certificate-authority.md#the-service-account-key-pair | 18:54 |
imdigitaljim | https://github.com/kelseyhightower/kubernetes-the-hard-way/blob/master/docs/04-certificate-authority.md#certificate-authority | 18:54 |
imdigitaljim | ^ | 18:54 |
imdigitaljim | "profiles": { | 18:54 |
imdigitaljim | "kubernetes": { | 18:54 |
imdigitaljim | "usages": ["signing", "key encipherment", "server auth", "client auth"], | 18:54 |
imdigitaljim | "expiry": "8760h" | 18:54 |
imdigitaljim | } | 18:54 |
imdigitaljim | } | 18:54 |
imdigitaljim | I guess the common problem might be in my own experience and working with others on TLS | 18:55 |
flwang1 | ok, i see. | 18:57 |
flwang1 | but changing the config of cluster CA is a little bit risky | 18:57 |
flwang1 | i know strigazi probably doesn't like it | 18:58 |
imdigitaljim | im just suggesting doing what KH is showing to be done | 18:58 |
flwang1 | imdigitaljim: i know | 18:58 |
flwang1 | but | 18:58 |
flwang1 | that changes more and may introduce regression issue we don't know yet | 18:59 |
imdigitaljim | i would think the branches/tags separate that concern? | 19:00 |
imdigitaljim | but maybe theres something procedural im not aware of yet | 19:00 |
imdigitaljim | so i speak in ignorance :) | 19:01 |
flwang1 | ;) | 19:02 |
flwang1 | i will talk with strigazi to figure out a way, personally, i prefer to use a safer way, given it's Rocky-3 and we'd like to backport it to queens | 19:03 |
flwang1 | we can revisit this in Stein to figure out a better way | 19:03 |
imdigitaljim | i just want the way that works correctly and but also doesn't compromise security :) | 19:04 |
imdigitaljim | correctly for multimaster especially | 19:05 |
flwang1 | no problem, that's my goal as well | 19:06 |
flwang1 | so you still prefer using signed cert/key? | 19:06 |
flwang1 | you mentioned you did the way sharing keys by etcd and it works, so how did you make the keys? are they public/private key pair or signed certs/private key pair? | 19:07 |
flwang1 | imdigitaljim: ^ | 19:07 |
*** jmlowe has joined #openstack-containers | 19:11 | |
imdigitaljim | i used a different bootstrapping method because I did with with centos7. I used kubeadm to simplify the process of the k8s configuration. They use an "sa.key/.pub" that I distributed but I'm not entirely sure if they sign it either tbh. I am just seeing this KH stuff and throwing out open questions :) | 19:12 |
imdigitaljim | and hopefully we can concretely justify doing approach XYZ | 19:13 |
flwang1 | ok, i see. if kubeadm using sa.key/.pub, then i think we're safe to use pub/private keys | 19:14 |
flwang1 | if we really want to do the same way like KH, we may need the change at https://github.com/openstack/magnum/blob/master/magnum/common/x509/operations.py#L89 to support server auth | 19:14 |
*** mgoddard has joined #openstack-containers | 19:22 | |
flwang1 | imdigitaljim: thank you for all the good comments | 19:25 |
*** mgoddard has quit IRC | 19:27 | |
flwang1 | heading to office now, ttyl | 19:33 |
*** flwang1 has quit IRC | 19:33 | |
*** yamamoto has joined #openstack-containers | 19:40 | |
*** yamamoto has quit IRC | 19:45 | |
*** armaan has quit IRC | 20:02 | |
*** armaan has joined #openstack-containers | 20:02 | |
*** dave-mccowan has quit IRC | 20:12 | |
*** dave-mccowan has joined #openstack-containers | 20:13 | |
*** serlex has quit IRC | 20:25 | |
*** itlinux has joined #openstack-containers | 20:27 | |
*** armaan has quit IRC | 20:40 | |
*** armaan has joined #openstack-containers | 20:41 | |
*** yamamoto has joined #openstack-containers | 20:41 | |
*** yamamoto has quit IRC | 20:46 | |
*** dave-mcc_ has joined #openstack-containers | 20:52 | |
*** dave-mccowan has quit IRC | 20:54 | |
*** flwang1 has joined #openstack-containers | 21:05 | |
*** armaan has quit IRC | 21:27 | |
*** armaan has joined #openstack-containers | 21:28 | |
*** yamamoto has joined #openstack-containers | 21:43 | |
*** yamamoto has quit IRC | 21:49 | |
*** jmlowe has quit IRC | 21:56 | |
*** itlinux has quit IRC | 21:59 | |
*** jmlowe has joined #openstack-containers | 21:59 | |
*** chhagarw has quit IRC | 22:08 | |
*** jmlowe has quit IRC | 22:17 | |
*** jmlowe has joined #openstack-containers | 22:30 | |
openstackgerrit | Jim Bach proposed openstack/magnum master: Added error handling for discoveryurl https://review.openstack.org/576233 | 22:35 |
*** rcernin has joined #openstack-containers | 22:36 | |
*** hongbin has quit IRC | 22:40 | |
*** yamamoto has joined #openstack-containers | 22:45 | |
*** yamamoto has quit IRC | 22:49 | |
*** dave-mcc_ has quit IRC | 23:16 | |
*** pc_m has quit IRC | 23:31 | |
*** markguz has quit IRC | 23:46 | |
openstackgerrit | Feilong Wang proposed openstack/magnum master: Sync service account keys for multi masters https://review.openstack.org/576029 | 23:53 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!