openstackgerrit | Shu Muto proposed openstack/magnum-ui master: Add upper-constraints.txt into post-install https://review.openstack.org/607067 | 00:10 |
---|---|---|
openstackgerrit | Shu Muto proposed openstack/magnum-ui master: Imported Translations from Zanata https://review.openstack.org/603311 | 00:18 |
openstackgerrit | Shu Muto proposed openstack/magnum-ui master: fix tox python3 overrides https://review.openstack.org/606648 | 00:47 |
openstackgerrit | Merged openstack/magnum-ui master: Add upper-constraints.txt into post-install https://review.openstack.org/607067 | 00:50 |
openstackgerrit | Shu Muto proposed openstack/magnum-ui master: Add blueprints link in documents https://review.openstack.org/606309 | 01:00 |
*** jaewook_oh has joined #openstack-containers | 01:20 | |
*** hongbin has joined #openstack-containers | 01:23 | |
*** threestrands_ has joined #openstack-containers | 01:30 | |
*** threestrands has quit IRC | 01:33 | |
*** threestrands_ has quit IRC | 01:43 | |
openstackgerrit | Merged openstack/magnum-ui master: Imported Translations from Zanata https://review.openstack.org/603311 | 01:50 |
openstackgerrit | Merged openstack/magnum-ui master: Add blueprints link in documents https://review.openstack.org/606309 | 01:51 |
*** ricolin has joined #openstack-containers | 02:12 | |
openstackgerrit | Feilong Wang proposed openstack/magnum stable/rocky: Fix enable_cloud_provider check https://review.openstack.org/607089 | 02:31 |
openstackgerrit | Merged openstack/magnum-ui master: fix tox python3 overrides https://review.openstack.org/606648 | 02:36 |
openstackgerrit | Shu Muto proposed openstack/magnum-ui master: Support api-version when building client https://review.openstack.org/604955 | 02:53 |
openstackgerrit | Shu Muto proposed openstack/magnum-ui master: Limit cluster update properties https://review.openstack.org/604966 | 02:57 |
openstackgerrit | Shu Muto proposed openstack/magnum-ui master: Display master_flavor_id and flavor_id when updating cluster https://review.openstack.org/604967 | 02:58 |
*** dave-mccowan has quit IRC | 03:07 | |
openstackgerrit | Merged openstack/magnum-ui stable/pike: Add attributes for cluster to show https://review.openstack.org/603956 | 03:08 |
*** hongbin has quit IRC | 03:15 | |
openstackgerrit | Shu Muto proposed openstack/magnum-ui master: Use initial maps for supported network and volume drivers https://review.openstack.org/607095 | 04:20 |
openstackgerrit | Merged openstack/magnum-ui master: Support Calico as network driver for k8s https://review.openstack.org/603966 | 04:26 |
openstackgerrit | Merged openstack/magnum-ui master: Disable rotate certificate https://review.openstack.org/603963 | 04:30 |
openstackgerrit | Merged openstack/magnum-ui master: Limit cluster update properties https://review.openstack.org/604966 | 04:35 |
*** pcaruana has joined #openstack-containers | 04:36 | |
*** pcaruana has quit IRC | 04:43 | |
openstackgerrit | Merged openstack/magnum-ui master: Support api-version when building client https://review.openstack.org/604955 | 04:47 |
openstackgerrit | Merged openstack/magnum-ui master: Display master_flavor_id and flavor_id when updating cluster https://review.openstack.org/604967 | 04:47 |
openstackgerrit | Merged openstack/magnum-ui master: Use initial maps for supported network and volume drivers https://review.openstack.org/607095 | 04:50 |
openstackgerrit | Merged openstack/magnum stable/rocky: Fix enable_cloud_provider check https://review.openstack.org/607089 | 05:10 |
*** Namrata has joined #openstack-containers | 06:19 | |
*** dims has quit IRC | 06:38 | |
Namrata | Hi folks, I created a magnum managed kubernetes cluster but `https://flaoting_ip_of_master:6443/ui` gives me { "kind": "Status", "apiVersion": "v1", "metadata": { }, "status": "Failure", "message": "no endpoints available for service \"kubernetes-dashboard\"", "reason": "ServiceUnavailable", "code": 503 } | 06:39 |
Namrata | can anybody help me to solve this issue? | 06:40 |
*** dims has joined #openstack-containers | 06:44 | |
*** dims has quit IRC | 06:48 | |
*** dims has joined #openstack-containers | 06:51 | |
*** rcernin has quit IRC | 07:01 | |
*** pcaruana has joined #openstack-containers | 07:01 | |
*** suanand has joined #openstack-containers | 07:03 | |
openstackgerrit | Spyros Trigazis proposed openstack/magnum stable/rocky: [k8s] Add new label `service_cluster_ip_range` https://review.openstack.org/607107 | 07:11 |
openstackgerrit | Spyros Trigazis proposed openstack/magnum stable/rocky: [k8s] Set order in kubemaster software deployments https://review.openstack.org/607108 | 07:12 |
openstackgerrit | Spyros Trigazis proposed openstack/magnum stable/rocky: Remove the last slash of extra_params['auth_url'] https://review.openstack.org/607109 | 07:14 |
openstackgerrit | Feilong Wang proposed openstack/magnum stable/rocky: Remove the last slash of extra_params['auth_url'] https://review.openstack.org/607109 | 07:29 |
*** serlex has joined #openstack-containers | 07:43 | |
*** mattgo has joined #openstack-containers | 07:50 | |
*** ricolin has quit IRC | 08:00 | |
Namrata | Hi after succesfull creation of coe cluster `kubectl describe pods --namespace=kube-system kubernetes-dashboard` gives http://paste.openstack.org/show/731233/ | 08:19 |
Namrata | and kubectl describe nodes is empty | 08:19 |
Namrata | how to have access to kubernetes dashboard | 08:20 |
*** ttsiouts has joined #openstack-containers | 08:51 | |
*** ykarel has joined #openstack-containers | 08:53 | |
*** ttsiouts has quit IRC | 09:00 | |
*** ttsiouts has joined #openstack-containers | 09:02 | |
*** flwang1 has joined #openstack-containers | 09:18 | |
*** salmankhan has joined #openstack-containers | 09:21 | |
*** ykarel is now known as ykarel|away | 09:22 | |
*** ttsiouts has quit IRC | 10:01 | |
*** ttsiouts has joined #openstack-containers | 10:03 | |
*** ricolin has joined #openstack-containers | 10:05 | |
flwang1 | strigazi: hello | 10:15 |
strigazi | flwang1: hello | 10:17 |
flwang1 | strigazi: sync for stable/rocky? | 10:19 |
strigazi | flwang1: yes, about cherry-picks | 10:19 |
strigazi | from the log here: | 10:19 |
strigazi | https://git.openstack.org/cgit/openstack/magnum/log/ | 10:20 |
flwang1 | strigazi: sorry for the rush approve for https://review.openstack.org/607089 | 10:20 |
flwang1 | it's breaking our env | 10:20 |
strigazi | np | 10:20 |
strigazi | flwang1: I think we need also all off them apart from CI changes | 10:21 |
strigazi | flwang1: I can propose them and you merge? | 10:21 |
flwang1 | no problem | 10:21 |
strigazi | I'll make a list quickly now | 10:21 |
flwang1 | sure | 10:22 |
strigazi | give me 5' | 10:22 |
flwang1 | strigazi: btw, we have tested magnum on our pre-production env, no major problem | 10:22 |
flwang1 | there are some cases failed, but probably because our preprod env | 10:23 |
flwang1 | we probably deploy it on prod in this week or early next week | 10:23 |
*** ykarel|away has quit IRC | 10:26 | |
strigazi | flwang1: http://paste.openstack.org/show/731239/ | 10:31 |
strigazi | I'll cherry-pick with gerrit and then stack them with gerrit again. Otherwise I can create a branch quickly locally and push. The commit applly cleanly | 10:32 |
strigazi | flwang1: thoughts? | 10:33 |
flwang1 | do you want to cherry pick all of them in the list? | 10:33 |
flwang1 | some patches are not necessary IMHO | 10:33 |
strigazi | like which one? | 10:34 |
strigazi | kubelet in the master node we need it for flannel to be followed by: https://review.openstack.org/#/c/597150/ | 10:35 |
*** ykarel|away has joined #openstack-containers | 10:35 | |
flwang1 | like https://git.openstack.org/cgit/openstack/magnum/commit/?id=a400ea7980938714625437a18e53d6c8a5149e52 | 10:36 |
flwang1 | and https://git.openstack.org/cgit/openstack/magnum/commit/?id=32f805676d0ec88f40efe299c8d57a52b9e3daaa | 10:36 |
flwang1 | https://git.openstack.org/cgit/openstack/magnum/commit/?id=4f121e50c547abee195e30ce4aef588f71f509ee in queens but not in rocky --- I don't really understand why it's in queens but not in rocky | 10:38 |
flwang1 | 10:38 | |
strigazi | oh, I picked the patch from the bot? we must not pick that one | 10:38 |
strigazi | a400ea7980938714625437a18e53d6c8a5149e52 we must not cherry-pick | 10:38 |
strigazi | 32f805676d0ec88f40efe299c8d57a52b9e3daaa is doc changes, I don't mind if we leave it behind | 10:39 |
flwang1 | and we wont' cherry-pick this https://git.openstack.org/cgit/openstack/magnum/commit/?id=7d4d22b901b7b88a8c00305d69f96694e39c421e | 10:39 |
strigazi | flwang1: for https://git.openstack.org/cgit/openstack/magnum/commit/?id=4f121e50c547abee195e30ce4aef588f71f509ee see https://review.openstack.org/#/q/Icb8e7c3b8c75a3ab087c818c8580c0c8a9111d30 | 10:39 |
strigazi | https://git.openstack.org/cgit/openstack/magnum/commit/?id=7d4d22b901b7b88a8c00305d69f96694e39c421e same category as 32f805676d0ec88f40efe299c8d57a52b9e3daaa | 10:40 |
flwang1 | oh, no | 10:40 |
strigazi | lets see them here: https://etherpad.openstack.org/p/magnum-rocky-cherry-picks | 10:41 |
flwang1 | that's my fault, in openstack world, we don't allow cross release cherry-pick | 10:41 |
flwang1 | we have to cherry-pick patch from master to rocky and then to queens | 10:41 |
strigazi | I updated the list in the etherpad | 10:42 |
openstackgerrit | Feilong Wang proposed openstack/magnum stable/rocky: [k8s] Add proxy to master and set cluster-cidr https://review.openstack.org/607150 | 10:44 |
strigazi | flwang1: I propose to take them in order now | 10:44 |
strigazi | as they went into master | 10:45 |
flwang1 | cool | 10:45 |
Namrata | flwang1: strigazi can you help me resolving the issue of kubernetes dashboard after (queens) after successful creation of cluster when I try https://floatiing_ip_of_master:6443/ui it gives me { "kind": "Status", "apiVersion": "v1", "metadata": { }, "status": "Failure", "message": "no endpoints available for service \"kubernetes-dashboard\"", "reason": "ServiceUnavailable", "code": 503 } | 10:52 |
flwang1 | you probably need to check the log of kube dashboard | 10:53 |
Namrata | ssh into the master node and `kubectl describe pods --namespace=kube-system kubernetes-dashboard` gives me http://paste.openstack.org/show/731242/ | 10:54 |
flwang1 | and i would suggest use kube proxy to access the dashboard | 10:54 |
Namrata | no nodes available to schedule pods | 10:54 |
flwang1 | Namrata: so you already got the your answer | 10:54 |
Namrata | flwang1: how to resolve this | 10:55 |
flwang1 | Namrata: you need to check the cpu, ram your pod requesting and check why it's failed for scheduling, better to check kube scheduler's log | 10:56 |
Namrata | okay will try digging up into it | 10:56 |
*** suanand has quit IRC | 10:59 | |
*** dave-mccowan has joined #openstack-containers | 11:02 | |
*** ttsiouts has quit IRC | 11:03 | |
*** ttsiouts has joined #openstack-containers | 11:03 | |
*** ttsiouts has quit IRC | 11:08 | |
openstackgerrit | Spyros Trigazis proposed openstack/magnum stable/rocky: [k8s] Add new label `service_cluster_ip_range` https://review.openstack.org/607107 | 11:09 |
openstackgerrit | Spyros Trigazis proposed openstack/magnum stable/rocky: [k8s] Set order in kubemaster software deployments https://review.openstack.org/607108 | 11:09 |
openstackgerrit | Spyros Trigazis proposed openstack/magnum stable/rocky: Remove the last slash of extra_params['auth_url'] https://review.openstack.org/607109 | 11:09 |
openstackgerrit | Spyros Trigazis proposed openstack/magnum stable/rocky: [k8s] Add proxy to master and set cluster-cidr https://review.openstack.org/607150 | 11:09 |
openstackgerrit | Spyros Trigazis proposed openstack/magnum stable/rocky: Fixing CoreOS driver https://review.openstack.org/607153 | 11:09 |
openstackgerrit | Spyros Trigazis proposed openstack/magnum stable/rocky: Fix unit test failure with python3.6 https://review.openstack.org/607154 | 11:09 |
openstackgerrit | Spyros Trigazis proposed openstack/magnum stable/rocky: [k8s] Add kubelet to the master nodes https://review.openstack.org/607155 | 11:09 |
openstackgerrit | Spyros Trigazis proposed openstack/magnum stable/rocky: Add prometheus & grafana container image tags https://review.openstack.org/607156 | 11:09 |
openstackgerrit | Spyros Trigazis proposed openstack/magnum stable/rocky: Make X-Subject-Token search case unsensitive https://review.openstack.org/607157 | 11:09 |
flwang1 | the commit message of https://review.openstack.org/#/c/607150/ looks not correct | 11:12 |
flwang1 | strigazi: ^ | 11:13 |
*** ttsiouts has joined #openstack-containers | 11:13 | |
strigazi | flwang1: it includes the queens commit-id, I'll remove it | 11:15 |
flwang1 | strigazi: thank you | 11:15 |
openstackgerrit | Spyros Trigazis proposed openstack/magnum stable/rocky: [k8s] Add proxy to master and set cluster-cidr https://review.openstack.org/607150 | 11:24 |
openstackgerrit | Spyros Trigazis proposed openstack/magnum stable/rocky: Fixing CoreOS driver https://review.openstack.org/607153 | 11:24 |
openstackgerrit | Spyros Trigazis proposed openstack/magnum stable/rocky: Fix unit test failure with python3.6 https://review.openstack.org/607154 | 11:24 |
openstackgerrit | Spyros Trigazis proposed openstack/magnum stable/rocky: [k8s] Add kubelet to the master nodes https://review.openstack.org/607155 | 11:24 |
openstackgerrit | Spyros Trigazis proposed openstack/magnum stable/rocky: Add prometheus & grafana container image tags https://review.openstack.org/607156 | 11:24 |
openstackgerrit | Spyros Trigazis proposed openstack/magnum stable/rocky: Make X-Subject-Token search case unsensitive https://review.openstack.org/607157 | 11:24 |
*** ttsiouts has quit IRC | 11:25 | |
openstackgerrit | Spyros Trigazis proposed openstack/magnum master: [k8s] Make flannel self-hosted https://review.openstack.org/597150 | 11:30 |
*** ykarel|away has quit IRC | 11:49 | |
*** ykarel has joined #openstack-containers | 11:50 | |
*** ykarel is now known as ykarel|away | 12:08 | |
*** ttsiouts has joined #openstack-containers | 12:10 | |
Namrata | flwang1: I have checked that machine has enough storage and I only see connection refused error in scheduler log | 12:13 |
brtknr | strigazi: how easy is it to upgrade k8s on an existing cluster? | 12:15 |
*** ykarel|away has quit IRC | 12:19 | |
Namrata | flwang1: my kube scheduler log: http://paste.openstack.org/show/731246/ | 12:20 |
flwang1 | Namrata: seems your kube-apiserver is not in health status | 12:22 |
Namrata | flwang1: so should I dig up in apiserver logs | 12:26 |
*** mattgo has quit IRC | 12:28 | |
Namrata | flwang1: I see TLS handsake error here in apiserver logs http://paste.openstack.org/show/731249/ | 12:34 |
*** Bhujay has joined #openstack-containers | 12:36 | |
flwang1 | did you create the cluster with magnum? | 12:42 |
Namrata | flwang1: yes with magnum | 12:42 |
flwang1 | pls tell me more, version? | 12:42 |
Namrata | magnum (6.1.2.dev8) | 12:44 |
Namrata | and kubectl version if you are asking v1.9.3 | 12:44 |
*** yolanda has quit IRC | 12:45 | |
flwang1 | 6.1.2 is queens, IIRC | 12:45 |
flwang1 | then better check your cloud-init-output.log | 12:45 |
Namrata | yes | 12:45 |
Namrata | flwang1: http://paste.openstack.org/show/731250/ cloud-init-output.log in master node does not contain any error and seems okay | 12:52 |
Namrata | and it has TLS_DISABLED=False | 12:52 |
*** jaewook_oh has quit IRC | 12:53 | |
*** pcaruana has quit IRC | 12:57 | |
*** ttsiouts has quit IRC | 13:23 | |
*** pcaruana has joined #openstack-containers | 13:27 | |
*** ttsiouts has joined #openstack-containers | 13:33 | |
*** Namrata_ has joined #openstack-containers | 13:36 | |
*** Namrata has quit IRC | 13:38 | |
*** hongbin has joined #openstack-containers | 13:57 | |
*** mattgo has joined #openstack-containers | 13:57 | |
*** ttsiouts has quit IRC | 13:58 | |
openstackgerrit | Merged openstack/magnum stable/rocky: [k8s] Add new label `service_cluster_ip_range` https://review.openstack.org/607107 | 14:07 |
openstackgerrit | Merged openstack/magnum stable/rocky: [k8s] Set order in kubemaster software deployments https://review.openstack.org/607108 | 14:07 |
openstackgerrit | Merged openstack/magnum stable/rocky: Remove the last slash of extra_params['auth_url'] https://review.openstack.org/607109 | 14:07 |
*** ttsiouts has joined #openstack-containers | 14:12 | |
openstackgerrit | Merged openstack/magnum stable/rocky: [k8s] Add proxy to master and set cluster-cidr https://review.openstack.org/607150 | 14:15 |
openstackgerrit | Merged openstack/magnum stable/rocky: Fixing CoreOS driver https://review.openstack.org/607153 | 14:15 |
openstackgerrit | Merged openstack/magnum stable/rocky: Fix unit test failure with python3.6 https://review.openstack.org/607154 | 14:15 |
openstackgerrit | Merged openstack/magnum stable/rocky: [k8s] Add kubelet to the master nodes https://review.openstack.org/607155 | 14:38 |
*** ttsiouts has quit IRC | 14:46 | |
openstackgerrit | Merged openstack/magnum stable/rocky: Add prometheus & grafana container image tags https://review.openstack.org/607156 | 14:46 |
openstackgerrit | Merged openstack/magnum stable/rocky: Make X-Subject-Token search case unsensitive https://review.openstack.org/607157 | 14:46 |
*** ttsiouts has joined #openstack-containers | 15:00 | |
openstackgerrit | Spyros Trigazis proposed openstack/magnum master: Add swarm-mode labels for networking https://review.openstack.org/607283 | 15:07 |
*** dave-mccowan has quit IRC | 15:27 | |
*** dave-mccowan has joined #openstack-containers | 15:28 | |
*** ttsiouts has quit IRC | 15:42 | |
*** serlex has quit IRC | 16:05 | |
*** Bhujay has quit IRC | 16:12 | |
*** Namrata_ has quit IRC | 16:29 | |
*** mattgo has quit IRC | 17:15 | |
*** salmankhan has quit IRC | 17:16 | |
*** spiette has quit IRC | 17:26 | |
*** spiette has joined #openstack-containers | 17:29 | |
*** spiette has quit IRC | 17:29 | |
*** spiette has joined #openstack-containers | 17:38 | |
*** openstackgerrit has quit IRC | 17:51 | |
*** pcaruana has quit IRC | 18:02 | |
*** ricolin has quit IRC | 18:05 | |
*** flwang1 has quit IRC | 18:33 | |
*** imdigitaljim has joined #openstack-containers | 19:07 | |
*** spiette has quit IRC | 19:18 | |
*** spiette has joined #openstack-containers | 19:21 | |
*** dave-mccowan has quit IRC | 19:41 | |
*** openstackgerrit has joined #openstack-containers | 19:41 | |
openstackgerrit | Erik Olof Gunnar Andersson proposed openstack/magnum master: Trivial code cleanups https://review.openstack.org/601904 | 19:41 |
*** dave-mccowan has joined #openstack-containers | 20:30 | |
*** dave-mccowan has quit IRC | 20:36 | |
*** ttsiouts has joined #openstack-containers | 20:55 | |
strigazi | #startmeeting containers | 21:00 |
openstack | Meeting started Tue Oct 2 21:00:38 2018 UTC and is due to finish in 60 minutes. The chair is strigazi. Information about MeetBot at http://wiki.debian.org/MeetBot. | 21:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 21:00 |
*** openstack changes topic to " (Meeting topic: containers)" | 21:00 | |
openstack | The meeting name has been set to 'containers' | 21:00 |
strigazi | #topic Roll Call | 21:00 |
*** openstack changes topic to "Roll Call (Meeting topic: containers)" | 21:00 | |
strigazi | o/ | 21:00 |
brtknr | o/ | 21:00 |
imdigitaljim | o/ | 21:00 |
strigazi | Thanks for joining the meeting brtknr imdigitaljim | 21:02 |
*** schaney has joined #openstack-containers | 21:02 | |
strigazi | #topic Announcements | 21:02 |
*** openstack changes topic to "Announcements (Meeting topic: containers)" | 21:02 | |
brtknr | glad to be finally joining! | 21:02 |
openstackgerrit | Theodoros Tsioutsias proposed openstack/magnum-specs master: [WIP] Instoduce magnum nodegroups https://review.openstack.org/607363 | 21:02 |
ttsiouts | o/ | 21:02 |
strigazi | We cherry-picked a couple of patches in rocky with flwang https://review.openstack.org/#/q/status:merged+project:openstack/magnum+branch:stable/rocky | 21:03 |
strigazi | and btw the ttsiouts pushed a WIP of the nodegroups spec just now, as you can see. | 21:03 |
strigazi | and btw ttsiouts pushed a WIP of the nodegroups spec just now, as you can see. | 21:03 |
ttsiouts | It's really a WIP | 21:03 |
strigazi | no worries, thanks | 21:04 |
ttsiouts | I need to update the patches also.. | 21:04 |
strigazi | regarding the cherry-picks, | 21:04 |
cbrumm | o/ | 21:05 |
strigazi | we want the self-hosted flannel patch in too and me and me and flwang will push for the health check patch too, | 21:05 |
strigazi | hey cbrumm | 21:05 |
strigazi | #topic Stories/Tasks | 21:06 |
*** openstack changes topic to "Stories/Tasks (Meeting topic: containers)" | 21:06 | |
strigazi | Apart from the cherry-picks and the release that will follow them, I only have two patches for swarm-mode | 21:07 |
colin- | sorry i'm late | 21:08 |
strigazi | I pushed one to allow the configuration of the overlay networks cidr, probable brtknr is interested | 21:08 |
strigazi | colin-: o/ | 21:08 |
strigazi | s/probable/probably/ | 21:08 |
strigazi | and one more to set the socket where dockerd listens to. Set it to /var/run/docker.sock | 21:09 |
strigazi | this last one, came up after our L1TF reboots | 21:10 |
strigazi | docker didn't start | 21:10 |
strigazi | it couldn't create the socket on boot | 21:10 |
*** ttsiouts has quit IRC | 21:10 | |
*** ttsiouts has joined #openstack-containers | 21:11 | |
strigazi | That is all from me for last week | 21:11 |
imdigitaljim | we've got our openstack cluster auto scaler poc working well and we auto deploy services (dash, prom, etc) with a remote helm in the cluster creation, we've also been heavily weighing in on a new data flow pattern for bootstrapping. | 21:11 |
imdigitaljim | the new pattern could easily be staged for supporting the old version and new version together | 21:12 |
strigazi | I didn't get the last part, what new flow | 21:12 |
imdigitaljim | to take some burden off the cloud-init user_data (which we are capping out) | 21:12 |
imdigitaljim | strigazi its similar to some of the data flow we discussed in cern | 21:13 |
strigazi | for prom, dash, coredns, calico we aren not using cloud-init | 21:14 |
imdigitaljim | yeah we are not either | 21:14 |
strigazi | ok, got it | 21:14 |
imdigitaljim | sorry that was like a word vomit of things | 21:14 |
imdigitaljim | 3 things not 2 | 21:14 |
strigazi | deploy services with helm pointing to a remote repo | 21:14 |
imdigitaljim | 1) autoscaler 2) deploying services with helm instead of software deployments 3) considering redesign to reduce cloud-init payload and decouple the dynamic magnum template data | 21:15 |
strigazi | I get the insentive for helm, but cloud-init is not an issue since queens | 21:16 |
imdigitaljim | how so? | 21:16 |
strigazi | software deployments are not bound by the user_data limit in nova | 21:17 |
strigazi | we can have as many SD as we wont | 21:17 |
strigazi | we can have as many SD as we want | 21:17 |
strigazi | no? | 21:17 |
strigazi | you reached a limit? | 21:17 |
imdigitaljim | i suppose the heat-container has issues with certain SDs | 21:18 |
imdigitaljim | if you wanted to do everything via SD | 21:18 |
imdigitaljim | we'll need to revisit the heat container | 21:18 |
strigazi | if there is a limit we can look into it. deploying anything with the k8s API is not an issue. | 21:19 |
imdigitaljim | its not a limit | 21:20 |
imdigitaljim | its the extent of what the heat container has access to use | 21:20 |
imdigitaljim | on the host OS | 21:20 |
imdigitaljim | since they heat-agent is atomic mounted into the host OS | 21:20 |
imdigitaljim | there are permissions issues, binaries unreachable, etc | 21:21 |
imdigitaljim | due to mounting | 21:21 |
strigazi | this model has not limits: https://review.openstack.org/#/c/561858/1/magnum/drivers/common/templates/kubernetes/fragments/configure-kubernetes-minion.sh@16 | 21:21 |
strigazi | s/not/no | 21:21 |
strigazi | it is like ansible | 21:22 |
imdigitaljim | :) not entirely | 21:22 |
strigazi | Do you have a use case in mind? | 21:22 |
imdigitaljim | https://github.com/openstack/magnum/blob/master/magnum/drivers/common/image/heat-container-agent/config.json.template#L25 | 21:23 |
imdigitaljim | anything that doesnt fall here | 21:23 |
imdigitaljim | in the hostOS | 21:23 |
strigazi | in the patch I sent the heat-agent is talking to the host over ssh. | 21:24 |
strigazi | so any binary is reachable | 21:24 |
imdigitaljim | well check it out | 21:24 |
strigazi | in the line that I shared it creates inodes in the host's fs | 21:25 |
strigazi | imdigitaljim: you're typing? | 21:27 |
imdigitaljim | no | 21:27 |
imdigitaljim | im checking out the PR | 21:27 |
imdigitaljim | we can move on! | 21:27 |
imdigitaljim | thanks for the info on the PR | 21:27 |
*** ttsiouts has quit IRC | 21:27 | |
strigazi | ok, if you have a concern with the heat-agent please share | 21:28 |
*** ttsiouts has joined #openstack-containers | 21:28 | |
strigazi | brtknr: you have something? | 21:28 |
strigazi | brtknr: Are you still there? | 21:32 |
strigazi | I don't have anything else to add, so | 21:32 |
colin- | nothing from me but i'm still here :) | 21:32 |
strigazi | imdigitaljim and @all have a look in ttsiouts WIP on nodegroups | 21:32 |
strigazi | colin-: :) | 21:33 |
imdigitaljim | yeah thats looking imo | 21:33 |
ttsiouts | imdigitaljim: there are still lots of changes especially in the patch but you can get the general idea from the spec | 21:33 |
imdigitaljim | we should be able to support testing it out as well | 21:34 |
ttsiouts | awesome! | 21:34 |
ttsiouts | thanks a lot!!! | 21:34 |
imdigitaljim | np! | 21:34 |
imdigitaljim | good work! | 21:34 |
ttsiouts | :D | 21:35 |
strigazi | let's wrap then? | 21:36 |
strigazi | said once | 21:37 |
strigazi | said twice | 21:37 |
strigazi | see you in the channel or next week :) | 21:38 |
ttsiouts | bye! | 21:38 |
strigazi | #endmeeting | 21:38 |
*** openstack changes topic to "OpenStack Containers Team" | 21:38 | |
openstack | Meeting ended Tue Oct 2 21:38:37 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 21:38 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/containers/2018/containers.2018-10-02-21.00.html | 21:38 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/containers/2018/containers.2018-10-02-21.00.txt | 21:38 |
openstack | Log: http://eavesdrop.openstack.org/meetings/containers/2018/containers.2018-10-02-21.00.log.html | 21:38 |
imdigitaljim | see ya! | 21:39 |
strigazi | imdigitaljim: if you need to address an issue with the heat-agent ping me, here or pm :) | 21:40 |
imdigitaljim | yeah sounds good! | 21:41 |
imdigitaljim | i overlooked the ssh approach at first i didnt notice the changes here https://review.openstack.org/#/c/561858/1/magnum/drivers/common/templates/kubernetes/fragments/start-container-agent.sh | 21:41 |
imdigitaljim | so yes like ansible, you're right :) | 21:41 |
imdigitaljim | we'll have to feel out this ssh approach vs design change with bigger picture in mind | 21:42 |
strigazi | I had this with upgrading syscontainers | 21:42 |
imdigitaljim | yeah? | 21:42 |
strigazi | syscontainers need to create hard link in the fs, so you need to be in the same fs namespace | 21:42 |
strigazi | hence the ssh approach | 21:43 |
imdigitaljim | still a useful approach | 21:44 |
strigazi | discussing what we can deploy with the heat-agent then is matter of choice not a limitation | 21:44 |
strigazi | I'll push a patch to add helm too, the binary | 21:44 |
imdigitaljim | which is good | 21:45 |
strigazi | oh, actually, I want to ask you about it | 21:45 |
imdigitaljim | sure | 21:45 |
imdigitaljim | pm's or here | 21:45 |
imdigitaljim | im available | 21:45 |
strigazi | I was thiking that we can create an svc account | 21:45 |
strigazi | in the default k8s ns for users to use not in kube-system with the cluster role | 21:46 |
strigazi | have you tried that? | 21:46 |
imdigitaljim | yeah a few | 21:47 |
imdigitaljim | ns's | 21:47 |
strigazi | each ns to have each own tiller | 21:47 |
strigazi | ohhg, s/each/its/ sorry it is late | 21:48 |
imdigitaljim | apiVersion: v1 | 21:48 |
imdigitaljim | kind: ServiceAccount | 21:48 |
imdigitaljim | metadata: | 21:48 |
imdigitaljim | name: tiller | 21:48 |
imdigitaljim | namespace: kube-system | 21:48 |
imdigitaljim | --- | 21:48 |
imdigitaljim | kind: ClusterRoleBinding | 21:48 |
imdigitaljim | apiVersion: rbac.authorization.k8s.io/v1 | 21:48 |
imdigitaljim | metadata: | 21:48 |
imdigitaljim | name: tiller-cluster-rule | 21:48 |
imdigitaljim | roleRef: | 21:48 |
imdigitaljim | apiGroup: rbac.authorization.k8s.io | 21:48 |
imdigitaljim | kind: ClusterRole | 21:48 |
imdigitaljim | name: cluster-admin | 21:48 |
imdigitaljim | subjects: | 21:48 |
imdigitaljim | - kind: ServiceAccount | 21:48 |
imdigitaljim | name: tiller | 21:48 |
imdigitaljim | namespace: kube-system | 21:48 |
imdigitaljim | yeah you could kind of template this stuff | 21:48 |
imdigitaljim | and apply that for more ns's | 21:48 |
imdigitaljim | but you'd only need this if you want varying levels of access | 21:49 |
imdigitaljim | but i suppose if you have multiple users with varying level of usage in varying ns's you could definitely have a tiller for each locked down | 21:49 |
imdigitaljim | a neat idea for sure | 21:50 |
strigazi | yes, we could deploy prom or even the cni with helm in their own ns and user should use tiller in other nses | 21:50 |
imdigitaljim | yeah | 21:50 |
imdigitaljim | thats definitely a cluster/tenant/organization specific configuration but you could do it that | 21:51 |
imdigitaljim | way | 21:51 |
imdigitaljim | oh also have you noticed/considered that the software deployments deploy in alphabetical order of their software config resource in heat queens | 21:52 |
imdigitaljim | (it might require you update the template version to queens as well to be noticed if you havent seen this) | 21:53 |
strigazi | imdigitaljim: https://review.openstack.org/#/c/607108/ | 21:54 |
strigazi | this patch sets the order ^^ | 21:55 |
imdigitaljim | alternatively you could use deterministic lexicographic naming of the resources instead of the depends_on | 21:57 |
imdigitaljim | eg 000_myfirstthing 001_mysecondthing 002_mythirdthing | 21:58 |
imdigitaljim | so its more visibly apparent of the order | 21:58 |
strigazi | depends on VS 00X should have the same result | 22:02 |
strigazi | I got to go, see you tmr | 22:02 |
strigazi | bye | 22:02 |
*** ttsiouts has quit IRC | 22:04 | |
*** hongbin has quit IRC | 23:02 | |
*** rcernin has joined #openstack-containers | 23:59 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!