*** shrasool has quit IRC | 00:16 | |
*** hongbin has quit IRC | 00:16 | |
*** shrasool has joined #openstack-containers | 00:16 | |
*** shrasool has quit IRC | 01:17 | |
*** dave-mccowan has quit IRC | 02:00 | |
*** hongbin has joined #openstack-containers | 02:41 | |
*** ramishra has joined #openstack-containers | 03:50 | |
*** ykarel|away has joined #openstack-containers | 03:52 | |
*** lbragstad has quit IRC | 04:23 | |
*** ykarel|away has quit IRC | 04:46 | |
*** janki has joined #openstack-containers | 04:46 | |
*** ykarel|away has joined #openstack-containers | 05:04 | |
*** hongbin has quit IRC | 06:32 | |
*** rcernin has quit IRC | 07:01 | |
*** belmoreira has quit IRC | 07:21 | |
*** belmoreira has joined #openstack-containers | 07:24 | |
*** ykarel|away is now known as ykarel | 07:35 | |
*** dims has quit IRC | 07:44 | |
*** dims has joined #openstack-containers | 07:47 | |
*** ykarel is now known as ykarel|lunch | 08:02 | |
*** ppetit has joined #openstack-containers | 08:04 | |
*** ppetit has quit IRC | 08:06 | |
*** ppetit has joined #openstack-containers | 08:06 | |
*** ppetit has quit IRC | 08:44 | |
*** ykarel|lunch is now known as ykarel | 09:00 | |
*** ttsiouts has joined #openstack-containers | 10:16 | |
*** salmankhan has joined #openstack-containers | 10:21 | |
*** ttsiouts has quit IRC | 10:31 | |
*** ttsiouts has joined #openstack-containers | 10:31 | |
*** salmankhan1 has joined #openstack-containers | 10:38 | |
*** PagliaccisCloud has quit IRC | 10:38 | |
*** salmankhan has quit IRC | 10:38 | |
*** salmankhan1 is now known as salmankhan | 10:38 | |
*** danil has quit IRC | 11:10 | |
*** PagliaccisCloud has joined #openstack-containers | 11:21 | |
*** shrasool has joined #openstack-containers | 11:26 | |
mkuf | is there a way to deploy a specific CA-Certificate on the kubernetes master/nodes with magnum? I'm using a geotrust certificate for all my api endpoints but cloudprovider doesn't seem to know that CA when kube-apiserver is starting. http://paste.openstack.org/show/736812/ | 11:46 |
---|---|---|
*** shrasool has quit IRC | 12:03 | |
*** shrasool has joined #openstack-containers | 12:07 | |
*** shrasool has quit IRC | 12:16 | |
*** ricolin_ has quit IRC | 12:22 | |
*** shrasool has joined #openstack-containers | 12:42 | |
*** shrasool has quit IRC | 12:45 | |
*** janki has quit IRC | 13:24 | |
*** ttsiouts has quit IRC | 14:01 | |
*** ttsiouts has joined #openstack-containers | 14:01 | |
*** dave-mccowan has joined #openstack-containers | 14:05 | |
*** ttsiouts has quit IRC | 14:06 | |
*** lbragstad has joined #openstack-containers | 14:06 | |
*** dave-mccowan has quit IRC | 14:10 | |
*** ttsiouts has joined #openstack-containers | 14:12 | |
*** ttsiouts has quit IRC | 14:18 | |
*** lbragstad has quit IRC | 14:25 | |
*** lbragstad has joined #openstack-containers | 14:29 | |
*** hongbin has joined #openstack-containers | 14:44 | |
*** shrasool has joined #openstack-containers | 14:54 | |
*** mordred has joined #openstack-containers | 15:03 | |
brtknr | strigazi: im trying to assign neutron lbaas vip to k8s service, do the two work seamlessly or does it require any extra config? | 15:05 |
brtknr | the last instructions on the docs is from ocata | 15:05 |
*** ramishra has quit IRC | 15:06 | |
*** ykarel is now known as ykarel|away | 15:11 | |
*** ttsiouts has joined #openstack-containers | 15:12 | |
*** ykarel|away has quit IRC | 15:18 | |
brtknr | strigazi: this link seems to imply that i need to create a cloud.conf somewhere but the location is unclear https://kubernetes.io/docs/concepts/cluster-administration/cloud-providers/#openstack | 15:24 |
*** ykarel|away has joined #openstack-containers | 15:33 | |
brtknr | these docs only have instructuctions for lbaas v1: https://docs.openstack.org/magnum/queens/user/index.html#kubernetes-external-load-balancer | 15:36 |
*** shrasool has quit IRC | 15:37 | |
strigazi | brtknr: you shouldn't need anything extra | 15:38 |
brtknr | strigazi: does it need to be enabled? | 15:39 |
strigazi | brtknr: I'm testing this in master and it works for me | 15:39 |
brtknr | strigazi: does it need to be enabled in some way? | 15:39 |
brtknr | im using neutron lbaas v2, not octavia | 15:39 |
strigazi | Oh, try with v1.11.5-1 or v1.11.2-1 | 15:39 |
brtknr | strigazi: oh, im using v1.11.2 | 15:40 |
brtknr | whats changed between v1.11.2 and 1.11.2-1 | 15:41 |
strigazi | brtknr: yeap the -1 was to fix this issue in particular | 15:41 |
brtknr | so until now, neutron lbaas-v2 was not supported? | 15:42 |
strigazi | brtknr: was disabled | 15:42 |
brtknr | ah fair enough | 15:42 |
strigazi | brtknr: use 1.11.5, for the recent k8s CVE | 15:43 |
strigazi | brtknr: use v1.11.5-1, for the recent k8s CVE | 15:43 |
strigazi | skopeo inspect docker://docker.io/openstackmagnum/kubernetes-apiserver:v1.11.5-1 to see all tags | 15:44 |
*** shrasool has joined #openstack-containers | 15:49 | |
*** shrasool has quit IRC | 15:52 | |
*** shrasool has joined #openstack-containers | 15:59 | |
*** janki has joined #openstack-containers | 16:00 | |
*** shrasool has quit IRC | 16:05 | |
*** ttsiouts has quit IRC | 16:06 | |
brtknr | strigazi: cool! I'm doing the upgrade now, will let you know if it works | 16:07 |
brtknr | strigazi: I still see external-IP pending | 16:10 |
brtknr | (venv-openstack) ➜ pangeo git:(master) ✗ kubectl describe svc/proxy-public | 16:10 |
brtknr | Name: proxy-public | 16:10 |
brtknr | Namespace: pangeo | 16:10 |
brtknr | Labels: app=jupyterhub | 16:10 |
brtknr | chart=jupyterhub-0.7.0 | 16:10 |
brtknr | component=proxy-public | 16:10 |
brtknr | heritage=Tiller | 16:10 |
brtknr | release=pangeo | 16:11 |
brtknr | Annotations: <none> | 16:11 |
brtknr | Selector: component=proxy,release=pangeo | 16:11 |
brtknr | Type: LoadBalancer | 16:11 |
brtknr | IP: 10.254.34.249 | 16:11 |
brtknr | IP: 10.60.253.22 | 16:11 |
brtknr | Port: http 80/TCP | 16:11 |
brtknr | TargetPort: 8000/TCP | 16:11 |
brtknr | NodePort: http 31277/TCP | 16:11 |
brtknr | Endpoints: 172.17.0.6:8000 | 16:11 |
brtknr | Session Affinity: None | 16:11 |
brtknr | External Traffic Policy: Cluster | 16:11 |
brtknr | Events: <none> | 16:11 |
brtknr | sorry, automatically copy pasted, my apologies | 16:11 |
*** ttsiouts has joined #openstack-containers | 16:13 | |
brtknr | (neutron) lbaas-loadbalancer-list | 16:14 |
brtknr | +--------------------------------------+--------+----------------------------------+--------------+---------------------+----------+ | 16:14 |
brtknr | | id | name | tenant_id | vip_address | provisioning_status | provider | | 16:14 |
brtknr | +--------------------------------------+--------+----------------------------------+--------------+---------------------+----------+ | 16:14 |
brtknr | | 2b444d19-1d1a-4795-8de3-95b876ffb9ae | k8s-lb | 5638e8577bc84379baba4bfb66177086 | 10.60.253.22 | ACTIVE | haproxy | | 16:14 |
brtknr | thats what my loadbalancer looks like | 16:14 |
brtknr | i must be doing something incorrectly | 16:14 |
strigazi | so, it hasn't created a new one? | 16:15 |
brtknr | dont think so | 16:15 |
strigazi | check the controller manager logs | 16:15 |
brtknr | event.go:221] Event(v1.ObjectReference{Kind:"Service", Namespace:"pangeo", Name:"proxy-public", UID:"4858e8a3-f894-11e8-83a7-246e9648913c", APIVersion:"v1", ResourceVersion:"4142481", FieldPath:""}): type: 'Normal' reason: 'LoadbalancerIP' 10.60.253.151 -> 10.60.253.22 | 16:17 |
brtknr | this is theonly reference to the ip address | 16:17 |
brtknr | in the controller manager log | 16:17 |
*** ttsiouts has quit IRC | 16:18 | |
brtknr | here's what the service config looks like: http://paste.openstack.org/show/736830/ | 16:20 |
brtknr | am I right in assigning the vip ip address (10.60.253.22) as loadBalancerIP ? | 16:21 |
brtknr | strigazi: ^ | 16:21 |
strigazi | you want to select the IP? | 16:25 |
brtknr | I dont mind what IP is assigned | 16:26 |
brtknr | but I'd like to be on the same subnet as the host node | 16:27 |
strigazi | just setting the type LoadBalancer is enough | 16:27 |
strigazi | https://github.com/openstack/magnum/blob/master/magnum/drivers/common/templates/kubernetes/fragments/write-kube-os-config.sh#L20 | 16:27 |
brtknr | proxy-public LoadBalancer 10.254.34.249 <pending> 80:31277/TCP 2d | 16:28 |
brtknr | still pending | 16:29 |
strigazi | all components are using v1.11.5-1? | 16:29 |
strigazi | kubelet, api, cm? | 16:30 |
strigazi | try to delete the service and create again a k8s svc monitoring the k8s cm | 16:30 |
brtknr | Nothing showed up on k8s cm logs related to LoadBalancer | 16:35 |
strigazi | anything related to openstack? | 16:36 |
brtknr | using all the right images: > docker.io/openstackmagnum/kubernetes-controller-manager v1.11.5-1 cd7a72d6a5ad 2018-12-07 16:07 32.35 MB ostree | 16:37 |
brtknr | > docker.io/openstackmagnum/kubernetes-scheduler v1.11.5-1 2597333f0774 2018-12-07 16:08 14.59 MB ostree | 16:37 |
brtknr | > docker.io/openstackmagnum/kubernetes-proxy v1.11.5-1 2b65ca736aa8 2018-12-07 16:07 32.01 MB ostree | 16:37 |
brtknr | > docker.io/openstackmagnum/kubernetes-apiserver v1.11.5-1 c9ab73c65d29 2018-12-07 16:07 63.13 MB ostree | 16:37 |
strigazi | looks correct | 16:39 |
strigazi | ps aux | grep apiserver | grep openstacl | 16:40 |
strigazi | ps aux | grep apiserver | grep openstacl | 16:40 |
strigazi | ps aux | grep apiserver | grep openstack | 16:40 |
brtknr | which apiserver? kube-apiserver? | 16:42 |
strigazi | yes, inthe master ndoe | 16:43 |
strigazi | yes, in the master node | 16:43 |
brtknr | do you mean ps aux? | 16:44 |
*** shrasool has joined #openstack-containers | 16:44 | |
strigazi | yes | 16:44 |
brtknr | no nothing there | 16:45 |
brtknr | sounds like im missing some config | 16:45 |
strigazi | in /etc/kubernetes/controller-manager ? | 16:46 |
brtknr | nope empty | 16:46 |
brtknr | oh wait | 16:46 |
strigazi | you miss smth then | 16:46 |
brtknr | KUBE_CONTROLLER_MANAGER_ARGS="--leader-elect=true --service-account-private-key-file=/etc/kubernetes/certs/server.key --root-ca-file=/etc/kubernetes/certs/ca.crt" | 16:47 |
brtknr | I'm using queens | 16:47 |
strigazi | /etc/magnum/magnum.conf | 16:47 |
strigazi | [trust] | 16:47 |
strigazi | cluster_user_trust = True | 16:47 |
strigazi | is it set? | 16:47 |
brtknr | in master node? | 16:48 |
strigazi | in the all ckuster nodes: cat /etc/sysconfig/heat-params | grep TRUST_ID | 16:48 |
brtknr | ne sec | 16:48 |
brtknr | oh you mean magnum config | 16:49 |
brtknr | TRUST_ID="" | 16:49 |
strigazi | this is the issue | 16:49 |
*** shrasool has quit IRC | 16:49 | |
brtknr | thanks! I will set this to true and retry | 16:50 |
*** shrasool has joined #openstack-containers | 17:10 | |
*** dims has quit IRC | 17:21 | |
*** janki has quit IRC | 17:33 | |
*** salmankhan has quit IRC | 17:36 | |
*** ykarel|away has quit IRC | 18:17 | |
*** udesale has joined #openstack-containers | 18:26 | |
*** udesale has quit IRC | 18:27 | |
openstackgerrit | Spyros Trigazis proposed openstack/magnum master: Updating cloud-controller arguments for external providers https://review.openstack.org/577477 | 18:38 |
*** shrasool has quit IRC | 18:46 | |
*** dims has joined #openstack-containers | 18:50 | |
*** shrasool has joined #openstack-containers | 19:20 | |
*** shrasool has quit IRC | 19:22 | |
openstackgerrit | Mohammed Naser proposed openstack/magnum master: kubernetes: add retry logic for atomic installs https://review.openstack.org/623567 | 19:25 |
openstackgerrit | Mohammed Naser proposed openstack/magnum master: kubernetes: add retry logic for atomic installs https://review.openstack.org/623567 | 19:26 |
openstackgerrit | Mohammed Naser proposed openstack/magnum master: functional: retrieve cluster to get stack_id https://review.openstack.org/623575 | 20:17 |
*** shrasool has joined #openstack-containers | 20:22 | |
eandersson | Anyone going to KubeCon in Seattle? | 20:30 |
*** shrasool has quit IRC | 21:13 | |
*** shrasool has joined #openstack-containers | 21:15 | |
*** shrasool_ has joined #openstack-containers | 21:23 | |
*** shrasool has quit IRC | 21:23 | |
*** shrasool_ is now known as shrasool | 21:23 | |
*** shrasool has quit IRC | 21:30 | |
*** brtknr has quit IRC | 22:03 | |
*** shrasool has joined #openstack-containers | 22:09 | |
*** brtknr has joined #openstack-containers | 22:18 | |
*** brtknr has quit IRC | 22:46 | |
*** brtknr has joined #openstack-containers | 22:59 | |
*** hongbin has quit IRC | 23:01 | |
*** shrasool has quit IRC | 23:29 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!