*** slagle has joined #openstack-containers | 00:24 | |
*** Nel1x has joined #openstack-containers | 00:31 | |
*** sgrasley has quit IRC | 00:37 | |
*** hongbin has joined #openstack-containers | 00:44 | |
*** slagle has quit IRC | 00:48 | |
*** ricolin has joined #openstack-containers | 02:19 | |
*** dave-mccowan has quit IRC | 02:19 | |
*** openstack has joined #openstack-containers | 02:35 | |
*** ChanServ sets mode: +o openstack | 02:35 | |
*** ramishra has joined #openstack-containers | 02:37 | |
*** cbrumm has quit IRC | 02:53 | |
*** Nel1x has quit IRC | 03:11 | |
*** hongbin has quit IRC | 03:23 | |
*** hongbin has joined #openstack-containers | 03:28 | |
*** hongbin_ has joined #openstack-containers | 03:48 | |
*** hongbin has quit IRC | 03:50 | |
openstackgerrit | jacky06 proposed openstack/magnum master: Pin get-pip.py to 3.2 https://review.openstack.org/580424 | 04:02 |
---|---|---|
*** hongbin_ has quit IRC | 04:14 | |
flwang | imdigitaljim: around? | 04:20 |
*** pcaruana has joined #openstack-containers | 05:12 | |
*** Bhujay has joined #openstack-containers | 05:18 | |
*** mattgo has joined #openstack-containers | 05:50 | |
*** mattgo has quit IRC | 06:19 | |
*** adrianc has joined #openstack-containers | 06:41 | |
*** mattgo has joined #openstack-containers | 06:55 | |
openstackgerrit | Shuo Liu proposed openstack/magnum master: change http to https https://review.openstack.org/591939 | 07:23 |
*** mattgo has quit IRC | 07:33 | |
*** mattgo has joined #openstack-containers | 07:52 | |
*** sgordon has quit IRC | 08:08 | |
mattgo | strigazi, Hi, you mentioned that you posted a link to configure Magnum to run a local discovery service for etcd. I missed it, could you please repost it ? | 08:28 |
*** flwang1 has joined #openstack-containers | 08:40 | |
flwang1 | strigazi: pls ping me when you're online | 08:45 |
strigazi | mattgo: http://paste.openstack.org/show/727709/ | 08:50 |
mattgo | strigazi, thank you. So you're running etcd discovery service inside a k8s container that was first spawned with Magnum, correct ? | 08:58 |
strigazi | yes | 08:59 |
strigazi | mattgo: yes | 08:59 |
* strigazi is going to a physical meeting | 08:59 | |
mattgo | strigazi, My concern is that you still need the public discovery service for this first k8s cluster | 08:59 |
mattgo | strigazi, but I guess you could also setup the local discovery service on the controller node | 09:00 |
strigazi | mattgo: we had a cluster running already | 09:02 |
mattgo | strigazi, understood, thank you | 09:06 |
*** brtknr has joined #openstack-containers | 09:08 | |
*** salmankhan has joined #openstack-containers | 09:22 | |
*** ricolin has quit IRC | 09:29 | |
*** rtjure has joined #openstack-containers | 09:35 | |
*** dave-mccowan has joined #openstack-containers | 10:12 | |
*** adrianc has quit IRC | 10:30 | |
*** adrianc has joined #openstack-containers | 10:50 | |
*** ricolin has joined #openstack-containers | 11:20 | |
*** ykarel has joined #openstack-containers | 12:37 | |
*** zul has joined #openstack-containers | 12:42 | |
*** ykarel is now known as ykarel|away | 12:49 | |
*** ykarel|away has quit IRC | 13:17 | |
*** pbourke has quit IRC | 13:55 | |
*** pbourke has joined #openstack-containers | 13:57 | |
*** hongbin has joined #openstack-containers | 14:17 | |
*** mattgo has quit IRC | 14:30 | |
*** mattgo has joined #openstack-containers | 14:33 | |
*** Bhujay has quit IRC | 14:33 | |
*** markguz_ has joined #openstack-containers | 14:36 | |
*** markguz_ has quit IRC | 14:36 | |
*** markguz_ has joined #openstack-containers | 14:37 | |
*** mattgo has quit IRC | 14:38 | |
*** zul has quit IRC | 14:39 | |
imdigitaljim | flwang1: flwang: im here if you are | 14:43 |
strigazi | imdigitaljim: https://review.openstack.org/#/c/589214/9 | 14:45 |
imdigitaljim | thank you, i just comment back, all good catches, ill make the changes | 14:46 |
imdigitaljim | im doing a bit of back and forth with our code until we converge so a few mistakes :( | 14:47 |
strigazi | I think we should be explicit in bash vs sh, also this way shellcheck is happier :) | 14:48 |
imdigitaljim | also, this works with sh | 14:49 |
imdigitaljim | but i can gladly switch it to bash if you'd prefer | 14:49 |
strigazi | eg configure-minion is bash and others | 14:50 |
strigazi | let's go for bash | 14:50 |
imdigitaljim | sounds good | 14:50 |
openstackgerrit | Akihiro Motoki proposed openstack/magnum-ui master: Drop nose dependencies https://review.openstack.org/592069 | 14:51 |
openstackgerrit | Jim Bach proposed openstack/magnum master: cleanup config-k8s-masters.sh, added roles to nodes on startup https://review.openstack.org/589214 | 14:55 |
strigazi | imdigitaljim: maybe "added roles" should be removed from the commit msg? | 14:55 |
strigazi | Do we add roles somewhere? | 14:56 |
openstackgerrit | Jim Bach proposed openstack/magnum master: cleanup config-k8s-masters.sh, added roles to nodes on startup https://review.openstack.org/589214 | 14:57 |
imdigitaljim | yeah | 14:57 |
imdigitaljim | master role is added | 14:57 |
imdigitaljim | kubelet args | 14:57 |
imdigitaljim | "--node-labels=node-role.kubernetes.io/master=\"\"" | 14:57 |
*** ramishra has quit IRC | 15:03 | |
*** livelace has joined #openstack-containers | 15:25 | |
strigazi | imdigitaljim: I think in 590346 we can drop the second make-certm thoughts? | 15:31 |
strigazi | imdigitaljim: or make-cert and make-cert-client should converge in a way | 15:32 |
imdigitaljim | yeah we can definitely do that | 15:32 |
imdigitaljim | it would at most leave some unused artifacts on the minion | 15:32 |
imdigitaljim | but thats not a big issue | 15:32 |
strigazi | imdigitaljim: we should not generate the master certs | 15:32 |
imdigitaljim | which where? | 15:32 |
imdigitaljim | the admin cert? | 15:33 |
strigazi | imdigitaljim: in the minion, if we use the same script | 15:33 |
strigazi | yes | 15:33 |
imdigitaljim | oh yeah | 15:33 |
strigazi | however | 15:33 |
imdigitaljim | we could make it in a conditional | 15:33 |
imdigitaljim | (another PR) | 15:33 |
strigazi | if we have the trust creds in the node | 15:33 |
strigazi | if someone takes over a minion he can take over the cluster | 15:34 |
imdigitaljim | yeah | 15:34 |
imdigitaljim | i was thinking that as well | 15:34 |
imdigitaljim | that is an attack vector | 15:34 |
imdigitaljim | we could deploy it as another file | 15:34 |
imdigitaljim | and software deployment to delete it or something? | 15:34 |
imdigitaljim | although kind of a hack | 15:34 |
strigazi | we don't have a solution for this at the moment | 15:34 |
imdigitaljim | or wait | 15:35 |
imdigitaljim | we could deploy the minion with the Trust token | 15:35 |
strigazi | we could invalidate the trust user after cluster creation | 15:35 |
imdigitaljim | and it would eventually just expire | 15:35 |
strigazi | we could, | 15:35 |
imdigitaljim | or if we can set a custom ttl on the token for like 15 minutes | 15:36 |
strigazi | still with what you said and what I just mentioned if someone takes it at that time it is still a problem. | 15:36 |
strigazi | much smaler problem | 15:36 |
strigazi | the issue is when doing a cluster update | 15:37 |
strigazi | we should generate a token or trust again | 15:37 |
strigazi | because new nodes will need it again | 15:37 |
imdigitaljim | what use cases are a token needed on a minion after startup? | 15:40 |
*** mattgo has joined #openstack-containers | 15:40 | |
strigazi | imdigitaljim: today you create a cluster with N nodes and all minmions get a token | 15:41 |
strigazi | imdigitaljim: next week the app was super successful and you want more nodes | 15:41 |
imdigitaljim | oh you mean on the cluster updates | 15:42 |
strigazi | imdigitaljim: the new nodes will need to authenticate with magnum to get the cluster ca | 15:42 |
imdigitaljim | couldnt you just generate a new token in that case and update the param? | 15:42 |
strigazi | yes | 15:42 |
imdigitaljim | as you do the update | 15:42 |
strigazi | imdigitaljim: in that case we need to make the minion config a software deployment | 15:42 |
strigazi | imdigitaljim: because if it is the same resource group in heat and we change the user-data | 15:43 |
strigazi | imdigitaljim: heat will replace the servers | 15:43 |
strigazi | imdigitaljim: makes sense? | 15:43 |
imdigitaljim | yeah | 15:43 |
imdigitaljim | definitely | 15:43 |
imdigitaljim | we can look into that | 15:43 |
strigazi | imdigitaljim: fyi fedora-coreos meeting in ~1hr https://apps.fedoraproject.org/calendar/meeting/9282/ | 15:43 |
imdigitaljim | maybe a story for now? | 15:43 |
strigazi | imdigitaljim: https://review.openstack.org/#/c/561858/ | 15:44 |
strigazi | imdigitaljim: https://review.openstack.org/#/c/561858/1/magnum/drivers/k8s_fedora_atomic_v1/templates/kubeminion.yaml@383 | 15:44 |
strigazi | no one looked into it | 15:44 |
strigazi | I mean to review | 15:44 |
strigazi | I'm going home, to attend the meeting from there | 15:45 |
imdigitaljim | see ya | 15:45 |
*** adrianc has quit IRC | 15:48 | |
*** adrianc has joined #openstack-containers | 15:48 | |
*** itlinux has joined #openstack-containers | 15:52 | |
*** FracKen has joined #openstack-containers | 15:54 | |
openstackgerrit | Merged openstack/magnum master: [k8s] Set order in kubemaster software deployments https://review.openstack.org/591592 | 15:56 |
*** sayalilunkad has quit IRC | 16:16 | |
*** sayalilunkad has joined #openstack-containers | 16:20 | |
*** sayalilunkad has quit IRC | 16:32 | |
*** Bhujay has joined #openstack-containers | 16:33 | |
*** sayalilunkad has joined #openstack-containers | 16:47 | |
*** ricolin has quit IRC | 16:50 | |
*** sayalilunkad has quit IRC | 16:51 | |
*** sayalilunkad has joined #openstack-containers | 16:52 | |
*** openstackstatus has joined #openstack-containers | 16:56 | |
*** ChanServ sets mode: +v openstackstatus | 16:56 | |
*** sayalilunkad has quit IRC | 17:09 | |
*** salmankhan has quit IRC | 17:13 | |
*** ykarel has joined #openstack-containers | 18:11 | |
*** livelace has quit IRC | 18:15 | |
*** markguz_ has quit IRC | 18:18 | |
*** Nisha_away has joined #openstack-containers | 18:25 | |
Nisha_away | flwang, hi | 18:26 |
*** Nisha_away has quit IRC | 18:36 | |
*** adrianc has quit IRC | 18:41 | |
*** salmankhan has joined #openstack-containers | 18:41 | |
*** salmankhan has quit IRC | 18:46 | |
*** markguz_ has joined #openstack-containers | 18:55 | |
*** markguz_ has quit IRC | 18:59 | |
openstackgerrit | Feilong Wang proposed openstack/magnum master: Fix Keystone URL joining issue https://review.openstack.org/592181 | 19:07 |
*** openstackgerrit has quit IRC | 19:19 | |
*** ykarel has quit IRC | 19:29 | |
*** imdigitaljim has quit IRC | 20:00 | |
*** flwang1 has quit IRC | 20:05 | |
*** mattgo has quit IRC | 20:45 | |
*** mattgo has joined #openstack-containers | 20:53 | |
*** mattgo has quit IRC | 21:02 | |
*** openstackgerrit has joined #openstack-containers | 21:22 | |
openstackgerrit | Feilong Wang proposed openstack/magnum master: Fix Keystone URL joining issue https://review.openstack.org/592181 | 21:22 |
*** rcernin has joined #openstack-containers | 21:29 | |
*** imdigitaljim has joined #openstack-containers | 22:03 | |
imdigitaljim | back | 22:03 |
imdigitaljim | sorry dc'd | 22:03 |
flwang | imdigitaljim: thanks for the link, i didn't notice that patch | 22:05 |
flwang | and I think that one is better than mine, so I just abandoned mine | 22:05 |
imdigitaljim | yeah i wasnt sure from the description but i was pretty sure they were the same problem | 22:05 |
flwang | i think it's a regression issue by devstack or keystone | 22:06 |
imdigitaljim | also https://review.openstack.org/#/c/589214/ | 22:06 |
imdigitaljim | if you would check that | 22:06 |
flwang | though the way doing url joint in magnum is not good for sure | 22:06 |
flwang | imdigitaljim: it's on my list, the code looks good for me, just need some testing | 22:07 |
imdigitaljim | great thanks man! | 22:07 |
flwang | imdigitaljim: thank you for the great work | 22:09 |
flwang | imdigitaljim: btw, in blizzard, are you happy using 3 dedicated master nodes without running workload on that? | 22:10 |
imdigitaljim | we run a light workload on them | 22:11 |
imdigitaljim | control plane stuff mostly | 22:11 |
*** livelace has joined #openstack-containers | 22:11 | |
imdigitaljim | no "customer related" pods | 22:12 |
*** FracKen has left #openstack-containers | 22:17 | |
flwang | imdigitaljim: ok, i see. | 22:18 |
*** imdigitaljim has quit IRC | 22:18 | |
flwang | so not sure if i asked before, are you interested in the architecture like GKE/Gardener, totally hide the master noes to end users? | 22:18 |
*** itlinux has quit IRC | 22:22 | |
*** FracKen has joined #openstack-containers | 22:22 | |
*** livelace has quit IRC | 23:16 | |
*** livelace has joined #openstack-containers | 23:17 | |
*** rcernin has quit IRC | 23:18 | |
*** rcernin has joined #openstack-containers | 23:19 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!