| *** slagle has joined #openstack-containers | 00:24 | |
| *** Nel1x has joined #openstack-containers | 00:31 | |
| *** sgrasley has quit IRC | 00:37 | |
| *** hongbin has joined #openstack-containers | 00:44 | |
| *** slagle has quit IRC | 00:48 | |
| *** ricolin has joined #openstack-containers | 02:19 | |
| *** dave-mccowan has quit IRC | 02:19 | |
| *** openstack has joined #openstack-containers | 02:35 | |
| *** ChanServ sets mode: +o openstack | 02:35 | |
| *** ramishra has joined #openstack-containers | 02:37 | |
| *** cbrumm has quit IRC | 02:53 | |
| *** Nel1x has quit IRC | 03:11 | |
| *** hongbin has quit IRC | 03:23 | |
| *** hongbin has joined #openstack-containers | 03:28 | |
| *** hongbin_ has joined #openstack-containers | 03:48 | |
| *** hongbin has quit IRC | 03:50 | |
| openstackgerrit | jacky06 proposed openstack/magnum master: Pin get-pip.py to 3.2 https://review.openstack.org/580424 | 04:02 |
|---|---|---|
| *** hongbin_ has quit IRC | 04:14 | |
| flwang | imdigitaljim: around? | 04:20 |
| *** pcaruana has joined #openstack-containers | 05:12 | |
| *** Bhujay has joined #openstack-containers | 05:18 | |
| *** mattgo has joined #openstack-containers | 05:50 | |
| *** mattgo has quit IRC | 06:19 | |
| *** adrianc has joined #openstack-containers | 06:41 | |
| *** mattgo has joined #openstack-containers | 06:55 | |
| openstackgerrit | Shuo Liu proposed openstack/magnum master: change http to https https://review.openstack.org/591939 | 07:23 |
| *** mattgo has quit IRC | 07:33 | |
| *** mattgo has joined #openstack-containers | 07:52 | |
| *** sgordon has quit IRC | 08:08 | |
| mattgo | strigazi, Hi, you mentioned that you posted a link to configure Magnum to run a local discovery service for etcd. I missed it, could you please repost it ? | 08:28 |
| *** flwang1 has joined #openstack-containers | 08:40 | |
| flwang1 | strigazi: pls ping me when you're online | 08:45 |
| strigazi | mattgo: http://paste.openstack.org/show/727709/ | 08:50 |
| mattgo | strigazi, thank you. So you're running etcd discovery service inside a k8s container that was first spawned with Magnum, correct ? | 08:58 |
| strigazi | yes | 08:59 |
| strigazi | mattgo: yes | 08:59 |
| * strigazi is going to a physical meeting | 08:59 | |
| mattgo | strigazi, My concern is that you still need the public discovery service for this first k8s cluster | 08:59 |
| mattgo | strigazi, but I guess you could also setup the local discovery service on the controller node | 09:00 |
| strigazi | mattgo: we had a cluster running already | 09:02 |
| mattgo | strigazi, understood, thank you | 09:06 |
| *** brtknr has joined #openstack-containers | 09:08 | |
| *** salmankhan has joined #openstack-containers | 09:22 | |
| *** ricolin has quit IRC | 09:29 | |
| *** rtjure has joined #openstack-containers | 09:35 | |
| *** dave-mccowan has joined #openstack-containers | 10:12 | |
| *** adrianc has quit IRC | 10:30 | |
| *** adrianc has joined #openstack-containers | 10:50 | |
| *** ricolin has joined #openstack-containers | 11:20 | |
| *** ykarel has joined #openstack-containers | 12:37 | |
| *** zul has joined #openstack-containers | 12:42 | |
| *** ykarel is now known as ykarel|away | 12:49 | |
| *** ykarel|away has quit IRC | 13:17 | |
| *** pbourke has quit IRC | 13:55 | |
| *** pbourke has joined #openstack-containers | 13:57 | |
| *** hongbin has joined #openstack-containers | 14:17 | |
| *** mattgo has quit IRC | 14:30 | |
| *** mattgo has joined #openstack-containers | 14:33 | |
| *** Bhujay has quit IRC | 14:33 | |
| *** markguz_ has joined #openstack-containers | 14:36 | |
| *** markguz_ has quit IRC | 14:36 | |
| *** markguz_ has joined #openstack-containers | 14:37 | |
| *** mattgo has quit IRC | 14:38 | |
| *** zul has quit IRC | 14:39 | |
| imdigitaljim | flwang1: flwang: im here if you are | 14:43 |
| strigazi | imdigitaljim: https://review.openstack.org/#/c/589214/9 | 14:45 |
| imdigitaljim | thank you, i just comment back, all good catches, ill make the changes | 14:46 |
| imdigitaljim | im doing a bit of back and forth with our code until we converge so a few mistakes :( | 14:47 |
| strigazi | I think we should be explicit in bash vs sh, also this way shellcheck is happier :) | 14:48 |
| imdigitaljim | also, this works with sh | 14:49 |
| imdigitaljim | but i can gladly switch it to bash if you'd prefer | 14:49 |
| strigazi | eg configure-minion is bash and others | 14:50 |
| strigazi | let's go for bash | 14:50 |
| imdigitaljim | sounds good | 14:50 |
| openstackgerrit | Akihiro Motoki proposed openstack/magnum-ui master: Drop nose dependencies https://review.openstack.org/592069 | 14:51 |
| openstackgerrit | Jim Bach proposed openstack/magnum master: cleanup config-k8s-masters.sh, added roles to nodes on startup https://review.openstack.org/589214 | 14:55 |
| strigazi | imdigitaljim: maybe "added roles" should be removed from the commit msg? | 14:55 |
| strigazi | Do we add roles somewhere? | 14:56 |
| openstackgerrit | Jim Bach proposed openstack/magnum master: cleanup config-k8s-masters.sh, added roles to nodes on startup https://review.openstack.org/589214 | 14:57 |
| imdigitaljim | yeah | 14:57 |
| imdigitaljim | master role is added | 14:57 |
| imdigitaljim | kubelet args | 14:57 |
| imdigitaljim | "--node-labels=node-role.kubernetes.io/master=\"\"" | 14:57 |
| *** ramishra has quit IRC | 15:03 | |
| *** livelace has joined #openstack-containers | 15:25 | |
| strigazi | imdigitaljim: I think in 590346 we can drop the second make-certm thoughts? | 15:31 |
| strigazi | imdigitaljim: or make-cert and make-cert-client should converge in a way | 15:32 |
| imdigitaljim | yeah we can definitely do that | 15:32 |
| imdigitaljim | it would at most leave some unused artifacts on the minion | 15:32 |
| imdigitaljim | but thats not a big issue | 15:32 |
| strigazi | imdigitaljim: we should not generate the master certs | 15:32 |
| imdigitaljim | which where? | 15:32 |
| imdigitaljim | the admin cert? | 15:33 |
| strigazi | imdigitaljim: in the minion, if we use the same script | 15:33 |
| strigazi | yes | 15:33 |
| imdigitaljim | oh yeah | 15:33 |
| strigazi | however | 15:33 |
| imdigitaljim | we could make it in a conditional | 15:33 |
| imdigitaljim | (another PR) | 15:33 |
| strigazi | if we have the trust creds in the node | 15:33 |
| strigazi | if someone takes over a minion he can take over the cluster | 15:34 |
| imdigitaljim | yeah | 15:34 |
| imdigitaljim | i was thinking that as well | 15:34 |
| imdigitaljim | that is an attack vector | 15:34 |
| imdigitaljim | we could deploy it as another file | 15:34 |
| imdigitaljim | and software deployment to delete it or something? | 15:34 |
| imdigitaljim | although kind of a hack | 15:34 |
| strigazi | we don't have a solution for this at the moment | 15:34 |
| imdigitaljim | or wait | 15:35 |
| imdigitaljim | we could deploy the minion with the Trust token | 15:35 |
| strigazi | we could invalidate the trust user after cluster creation | 15:35 |
| imdigitaljim | and it would eventually just expire | 15:35 |
| strigazi | we could, | 15:35 |
| imdigitaljim | or if we can set a custom ttl on the token for like 15 minutes | 15:36 |
| strigazi | still with what you said and what I just mentioned if someone takes it at that time it is still a problem. | 15:36 |
| strigazi | much smaler problem | 15:36 |
| strigazi | the issue is when doing a cluster update | 15:37 |
| strigazi | we should generate a token or trust again | 15:37 |
| strigazi | because new nodes will need it again | 15:37 |
| imdigitaljim | what use cases are a token needed on a minion after startup? | 15:40 |
| *** mattgo has joined #openstack-containers | 15:40 | |
| strigazi | imdigitaljim: today you create a cluster with N nodes and all minmions get a token | 15:41 |
| strigazi | imdigitaljim: next week the app was super successful and you want more nodes | 15:41 |
| imdigitaljim | oh you mean on the cluster updates | 15:42 |
| strigazi | imdigitaljim: the new nodes will need to authenticate with magnum to get the cluster ca | 15:42 |
| imdigitaljim | couldnt you just generate a new token in that case and update the param? | 15:42 |
| strigazi | yes | 15:42 |
| imdigitaljim | as you do the update | 15:42 |
| strigazi | imdigitaljim: in that case we need to make the minion config a software deployment | 15:42 |
| strigazi | imdigitaljim: because if it is the same resource group in heat and we change the user-data | 15:43 |
| strigazi | imdigitaljim: heat will replace the servers | 15:43 |
| strigazi | imdigitaljim: makes sense? | 15:43 |
| imdigitaljim | yeah | 15:43 |
| imdigitaljim | definitely | 15:43 |
| imdigitaljim | we can look into that | 15:43 |
| strigazi | imdigitaljim: fyi fedora-coreos meeting in ~1hr https://apps.fedoraproject.org/calendar/meeting/9282/ | 15:43 |
| imdigitaljim | maybe a story for now? | 15:43 |
| strigazi | imdigitaljim: https://review.openstack.org/#/c/561858/ | 15:44 |
| strigazi | imdigitaljim: https://review.openstack.org/#/c/561858/1/magnum/drivers/k8s_fedora_atomic_v1/templates/kubeminion.yaml@383 | 15:44 |
| strigazi | no one looked into it | 15:44 |
| strigazi | I mean to review | 15:44 |
| strigazi | I'm going home, to attend the meeting from there | 15:45 |
| imdigitaljim | see ya | 15:45 |
| *** adrianc has quit IRC | 15:48 | |
| *** adrianc has joined #openstack-containers | 15:48 | |
| *** itlinux has joined #openstack-containers | 15:52 | |
| *** FracKen has joined #openstack-containers | 15:54 | |
| openstackgerrit | Merged openstack/magnum master: [k8s] Set order in kubemaster software deployments https://review.openstack.org/591592 | 15:56 |
| *** sayalilunkad has quit IRC | 16:16 | |
| *** sayalilunkad has joined #openstack-containers | 16:20 | |
| *** sayalilunkad has quit IRC | 16:32 | |
| *** Bhujay has joined #openstack-containers | 16:33 | |
| *** sayalilunkad has joined #openstack-containers | 16:47 | |
| *** ricolin has quit IRC | 16:50 | |
| *** sayalilunkad has quit IRC | 16:51 | |
| *** sayalilunkad has joined #openstack-containers | 16:52 | |
| *** openstackstatus has joined #openstack-containers | 16:56 | |
| *** ChanServ sets mode: +v openstackstatus | 16:56 | |
| *** sayalilunkad has quit IRC | 17:09 | |
| *** salmankhan has quit IRC | 17:13 | |
| *** ykarel has joined #openstack-containers | 18:11 | |
| *** livelace has quit IRC | 18:15 | |
| *** markguz_ has quit IRC | 18:18 | |
| *** Nisha_away has joined #openstack-containers | 18:25 | |
| Nisha_away | flwang, hi | 18:26 |
| *** Nisha_away has quit IRC | 18:36 | |
| *** adrianc has quit IRC | 18:41 | |
| *** salmankhan has joined #openstack-containers | 18:41 | |
| *** salmankhan has quit IRC | 18:46 | |
| *** markguz_ has joined #openstack-containers | 18:55 | |
| *** markguz_ has quit IRC | 18:59 | |
| openstackgerrit | Feilong Wang proposed openstack/magnum master: Fix Keystone URL joining issue https://review.openstack.org/592181 | 19:07 |
| *** openstackgerrit has quit IRC | 19:19 | |
| *** ykarel has quit IRC | 19:29 | |
| *** imdigitaljim has quit IRC | 20:00 | |
| *** flwang1 has quit IRC | 20:05 | |
| *** mattgo has quit IRC | 20:45 | |
| *** mattgo has joined #openstack-containers | 20:53 | |
| *** mattgo has quit IRC | 21:02 | |
| *** openstackgerrit has joined #openstack-containers | 21:22 | |
| openstackgerrit | Feilong Wang proposed openstack/magnum master: Fix Keystone URL joining issue https://review.openstack.org/592181 | 21:22 |
| *** rcernin has joined #openstack-containers | 21:29 | |
| *** imdigitaljim has joined #openstack-containers | 22:03 | |
| imdigitaljim | back | 22:03 |
| imdigitaljim | sorry dc'd | 22:03 |
| flwang | imdigitaljim: thanks for the link, i didn't notice that patch | 22:05 |
| flwang | and I think that one is better than mine, so I just abandoned mine | 22:05 |
| imdigitaljim | yeah i wasnt sure from the description but i was pretty sure they were the same problem | 22:05 |
| flwang | i think it's a regression issue by devstack or keystone | 22:06 |
| imdigitaljim | also https://review.openstack.org/#/c/589214/ | 22:06 |
| imdigitaljim | if you would check that | 22:06 |
| flwang | though the way doing url joint in magnum is not good for sure | 22:06 |
| flwang | imdigitaljim: it's on my list, the code looks good for me, just need some testing | 22:07 |
| imdigitaljim | great thanks man! | 22:07 |
| flwang | imdigitaljim: thank you for the great work | 22:09 |
| flwang | imdigitaljim: btw, in blizzard, are you happy using 3 dedicated master nodes without running workload on that? | 22:10 |
| imdigitaljim | we run a light workload on them | 22:11 |
| imdigitaljim | control plane stuff mostly | 22:11 |
| *** livelace has joined #openstack-containers | 22:11 | |
| imdigitaljim | no "customer related" pods | 22:12 |
| *** FracKen has left #openstack-containers | 22:17 | |
| flwang | imdigitaljim: ok, i see. | 22:18 |
| *** imdigitaljim has quit IRC | 22:18 | |
| flwang | so not sure if i asked before, are you interested in the architecture like GKE/Gardener, totally hide the master noes to end users? | 22:18 |
| *** itlinux has quit IRC | 22:22 | |
| *** FracKen has joined #openstack-containers | 22:22 | |
| *** livelace has quit IRC | 23:16 | |
| *** livelace has joined #openstack-containers | 23:17 | |
| *** rcernin has quit IRC | 23:18 | |
| *** rcernin has joined #openstack-containers | 23:19 | |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!