*** _fragatina has joined #openstack-containers | 00:01 | |
*** itlinux has joined #openstack-containers | 00:10 | |
*** sdake has quit IRC | 00:23 | |
*** sdake has joined #openstack-containers | 00:24 | |
*** mrodriguez has quit IRC | 00:27 | |
*** hongbin has joined #openstack-containers | 00:27 | |
*** flwang has quit IRC | 00:45 | |
*** hongbin has quit IRC | 01:18 | |
*** hongbin has joined #openstack-containers | 01:20 | |
*** _fragatina has quit IRC | 01:27 | |
*** sdake has quit IRC | 01:28 | |
*** _fragatina has joined #openstack-containers | 01:28 | |
*** _fragatina has quit IRC | 01:32 | |
*** ricolin_ has joined #openstack-containers | 02:01 | |
openstackgerrit | Feilong Wang proposed openstack/python-magnumclient master: Keystone auth support https://review.openstack.org/623092 | 02:07 |
---|---|---|
openstackgerrit | Feilong Wang proposed openstack/python-magnumclient master: Keystone auth support https://review.openstack.org/623092 | 02:21 |
*** sdake has joined #openstack-containers | 02:31 | |
*** sdake has quit IRC | 02:37 | |
*** sdake has joined #openstack-containers | 02:38 | |
openstackgerrit | Feilong Wang proposed openstack/python-magnumclient master: Keystone auth support https://review.openstack.org/623092 | 02:53 |
*** ykarel|away has joined #openstack-containers | 02:55 | |
*** sdake has quit IRC | 02:58 | |
*** sdake has joined #openstack-containers | 02:59 | |
*** _fragatina has joined #openstack-containers | 03:12 | |
*** _fragatina has quit IRC | 03:13 | |
*** _fragatina has joined #openstack-containers | 03:14 | |
*** sdake has quit IRC | 03:26 | |
*** sdake has joined #openstack-containers | 03:30 | |
*** sdake has quit IRC | 03:42 | |
*** ykarel|away is now known as ykarel | 03:42 | |
openstackgerrit | Feilong Wang proposed openstack/magnum master: Support multi k8s image versions https://review.openstack.org/633650 | 03:49 |
*** ykarel is now known as ykarel|afk | 03:50 | |
*** udesale has joined #openstack-containers | 04:02 | |
*** ykarel|afk is now known as ykarel | 04:06 | |
*** _fragatina has quit IRC | 04:08 | |
*** ricolin_ has quit IRC | 04:11 | |
*** ricolin has joined #openstack-containers | 04:11 | |
*** itlinux has quit IRC | 04:41 | |
*** sdake has joined #openstack-containers | 04:50 | |
*** spsurya has joined #openstack-containers | 05:05 | |
*** udesale has quit IRC | 05:29 | |
*** sdake has quit IRC | 05:41 | |
*** sdake has joined #openstack-containers | 05:50 | |
*** udesale has joined #openstack-containers | 05:51 | |
*** udesale has quit IRC | 05:59 | |
*** udesale has joined #openstack-containers | 06:00 | |
*** ykarel has quit IRC | 06:09 | |
*** hongbin has quit IRC | 06:21 | |
*** ykarel has joined #openstack-containers | 06:21 | |
*** ramishra has joined #openstack-containers | 06:33 | |
*** strigazi has quit IRC | 06:42 | |
*** strigazi has joined #openstack-containers | 06:43 | |
*** belmoreira has quit IRC | 06:53 | |
*** udesale has quit IRC | 07:10 | |
*** udesale has joined #openstack-containers | 07:18 | |
*** udesale has quit IRC | 07:22 | |
*** udesale has joined #openstack-containers | 07:26 | |
*** sapd1 has joined #openstack-containers | 07:48 | |
openstackgerrit | Feilong Wang proposed openstack/magnum master: Support multi k8s image versions https://review.openstack.org/633650 | 07:54 |
*** sdake has quit IRC | 08:11 | |
*** ttsiouts has joined #openstack-containers | 08:27 | |
*** ramishra_ has joined #openstack-containers | 08:34 | |
*** ramishra has quit IRC | 08:35 | |
*** janki has joined #openstack-containers | 08:36 | |
*** ttsiouts has quit IRC | 08:39 | |
*** ttsiouts has joined #openstack-containers | 08:40 | |
*** ttsiouts has quit IRC | 08:44 | |
*** pcaruana has joined #openstack-containers | 08:51 | |
*** ykarel is now known as ykarel|lunch | 08:52 | |
*** ttsiouts has joined #openstack-containers | 09:02 | |
*** ricolin has quit IRC | 09:07 | |
*** ign0tus has joined #openstack-containers | 09:15 | |
*** ykarel|lunch is now known as ykarel | 09:20 | |
*** ttsiouts has quit IRC | 10:02 | |
*** ttsiouts has joined #openstack-containers | 10:02 | |
*** ttsiouts has quit IRC | 10:07 | |
*** ramishra_ has quit IRC | 10:23 | |
*** sapd1 has quit IRC | 10:23 | |
*** ramishra has joined #openstack-containers | 10:30 | |
*** ttsiouts has joined #openstack-containers | 10:35 | |
openstackgerrit | Merged openstack/magnum stable/queens: support http/https proxy for discovery url https://review.openstack.org/633064 | 10:53 |
*** belmoreira has joined #openstack-containers | 10:55 | |
openstackgerrit | Diogo Guerra proposed openstack/magnum master: [WIP] [k8s] helm install metrics service https://review.openstack.org/632392 | 10:57 |
*** janki has quit IRC | 11:02 | |
*** mkuf_ has quit IRC | 11:07 | |
*** mkuf has joined #openstack-containers | 11:07 | |
*** udesale has quit IRC | 11:09 | |
*** sapd1 has joined #openstack-containers | 11:17 | |
*** ign0tus has quit IRC | 11:17 | |
*** ign0tus has joined #openstack-containers | 11:19 | |
*** sapd1 has quit IRC | 11:36 | |
*** ttsiouts has quit IRC | 11:40 | |
*** ttsiouts has joined #openstack-containers | 11:40 | |
*** ttsiouts has quit IRC | 11:44 | |
*** ttsiouts has joined #openstack-containers | 12:11 | |
*** ttsiouts has quit IRC | 12:16 | |
*** ttsiouts has joined #openstack-containers | 12:18 | |
*** mkuf has quit IRC | 12:20 | |
*** mkuf has joined #openstack-containers | 12:26 | |
*** pcaruana has quit IRC | 12:40 | |
*** pcaruana has joined #openstack-containers | 12:50 | |
*** kaiokmo has joined #openstack-containers | 12:50 | |
*** mkuf_ has joined #openstack-containers | 12:59 | |
*** mkuf has quit IRC | 13:02 | |
*** ttsiouts has quit IRC | 13:32 | |
*** ttsiouts has joined #openstack-containers | 13:33 | |
*** ttsiouts has quit IRC | 13:37 | |
*** zul has quit IRC | 13:38 | |
*** mkuf has joined #openstack-containers | 13:43 | |
*** mkuf_ has quit IRC | 13:45 | |
*** ttsiouts has joined #openstack-containers | 13:50 | |
*** ign0tus has quit IRC | 13:54 | |
*** ign0tus has joined #openstack-containers | 13:57 | |
*** ykarel is now known as ykarel|away | 14:01 | |
*** ign0tus has quit IRC | 14:10 | |
*** zul has joined #openstack-containers | 14:10 | |
*** udesale has joined #openstack-containers | 14:24 | |
*** ykarel|away has quit IRC | 14:25 | |
*** ign0tus has joined #openstack-containers | 14:25 | |
*** ign0tus has quit IRC | 14:37 | |
*** dave-mccowan has joined #openstack-containers | 14:40 | |
*** dave-mccowan has quit IRC | 14:45 | |
*** pcaruana has quit IRC | 14:45 | |
openstackgerrit | Diogo Guerra proposed openstack/magnum master: [WIP] [k8s] helm install metrics service https://review.openstack.org/632392 | 14:46 |
*** sdake has joined #openstack-containers | 14:49 | |
*** sdake has quit IRC | 14:51 | |
*** sdake has joined #openstack-containers | 14:53 | |
*** pcaruana has joined #openstack-containers | 14:53 | |
openstackgerrit | Keith Berger proposed openstack/magnum stable/pike: support http/https proxy for discovery url https://review.openstack.org/633755 | 14:58 |
*** hongbin has joined #openstack-containers | 15:13 | |
*** salmankhan has joined #openstack-containers | 15:14 | |
*** salmankhan has quit IRC | 15:18 | |
*** udesale has quit IRC | 15:18 | |
*** ttsiouts has quit IRC | 15:23 | |
*** ttsiouts has joined #openstack-containers | 15:23 | |
*** ttsiouts has quit IRC | 15:28 | |
*** sdake has quit IRC | 15:32 | |
*** sdake has joined #openstack-containers | 15:36 | |
*** livelace has joined #openstack-containers | 15:37 | |
*** ykarel|away has joined #openstack-containers | 15:38 | |
*** ykarel|away is now known as ykarel | 15:39 | |
*** livelace has quit IRC | 15:39 | |
*** ttsiouts has joined #openstack-containers | 15:42 | |
*** openstackgerrit has quit IRC | 15:51 | |
*** Nel1x has joined #openstack-containers | 16:36 | |
*** sdake has quit IRC | 16:46 | |
*** pcaruana has quit IRC | 17:01 | |
*** ttsiouts has quit IRC | 17:06 | |
*** ttsiouts has joined #openstack-containers | 17:06 | |
*** ttsiouts has quit IRC | 17:10 | |
*** hongbin has quit IRC | 17:14 | |
*** ramishra has quit IRC | 17:25 | |
colby_ | flwang: for what its worth, its just the minions joining the cluster that is the problem. Im seeing the error on the minion only. I can run get nodes on master and it just returns the master nodes. This worked fine with cluster_user_trust=False. But then trustID is never set in the openstack config and I cant use cinder volumes in kubernetes. I switched that config to attempt to use cinder volumes for pvc's and now the minions dont join with | 17:37 |
colby_ | the error I gave before. Do you want the magnum conductor logs or logs from the the actual nodes? | 17:37 |
*** ykarel is now known as ykarel|away | 17:41 | |
*** sdake has joined #openstack-containers | 17:43 | |
colby_ | it appears to get the availibility zone from the cloud providor calls: Adding node label from cloud provider: failure-domain.beta.kubernetes.io/zone=West Datacenter | 17:59 |
colby_ | then fails when joining the cluster: invalid: metadata.labels: Invalid value: "West Datacenter" | 17:59 |
*** sdake has quit IRC | 18:10 | |
*** sdake has joined #openstack-containers | 18:38 | |
*** _fragatina has joined #openstack-containers | 19:01 | |
*** ykarel|away has quit IRC | 19:06 | |
*** ttsiouts has joined #openstack-containers | 20:26 | |
*** openstackgerrit has joined #openstack-containers | 20:26 | |
openstackgerrit | Keith Berger proposed openstack/magnum stable/pike: support http/https proxy for discovery url https://review.openstack.org/633755 | 20:26 |
*** sdake has quit IRC | 20:45 | |
strigazi | meeting anyone? | 21:01 |
cbrumm | I'm here, not sure who else it | 21:02 |
strigazi | #startmeeting containers | 21:02 |
openstack | Meeting started Tue Jan 29 21:02:26 2019 UTC and is due to finish in 60 minutes. The chair is strigazi. Information about MeetBot at http://wiki.debian.org/MeetBot. | 21:02 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 21:02 |
*** openstack changes topic to " (Meeting topic: containers)" | 21:02 | |
openstack | The meeting name has been set to 'containers' | 21:02 |
strigazi | #topic Roll Call | 21:02 |
*** openstack changes topic to "Roll Call (Meeting topic: containers)" | 21:02 | |
cbrumm | o/ | 21:02 |
strigazi | o/ | 21:02 |
jakeyip | o/ | 21:02 |
*** imdigitaljim has joined #openstack-containers | 21:03 | |
imdigitaljim | o/ | 21:04 |
strigazi | #topic Stories/Tasks | 21:04 |
*** openstack changes topic to "Stories/Tasks (Meeting topic: containers)" | 21:04 | |
strigazi | From my side: | 21:05 |
strigazi | k8s v1.11.6 images rebuilt https://review.openstack.org/#/c/633478/ | 21:05 |
strigazi | (v1.11.7 was out just yesterday) | 21:06 |
strigazi | tiller deployment can be taken in, please review https://review.openstack.org/#/c/612336/ | 21:06 |
imdigitaljim | from us: | 21:07 |
strigazi | two patches for upgrades: add openssh clients to the heat-agent https://review.openstack.org/#/c/633504/ AND add the agent to all nodes: https://review.openstack.org/#/c/561858/ | 21:07 |
imdigitaljim | we just got kubernetes org approval to submit | 21:07 |
imdigitaljim | so we might have some openstack-ccm updates to provide in the near future | 21:08 |
imdigitaljim | cluster autoscaler work and inplace upgrades for the centos driver | 21:08 |
imdigitaljim | once this is in place and stable ill be making effort to upstreaming the driver | 21:08 |
imdigitaljim | we run v1.13.2 atm as well | 21:09 |
imdigitaljim | we also want to finalize any core magnum changes we'd probably need to do | 21:09 |
strigazi | imdigitaljim: please build also the ci for the special centos image. | 21:10 |
imdigitaljim | cluster-autoscaler work is k8s specific (mostly), trivial driver changes if any i forget | 21:10 |
colin- | o/ | 21:10 |
imdigitaljim | yes i definitely will | 21:10 |
imdigitaljim | make an mvp centos CI | 21:10 |
*** munimeha1 has joined #openstack-containers | 21:11 | |
imdigitaljim | although strigazi: i might need some help getting that setup im unfamiliar | 21:11 |
imdigitaljim | to connect with existing stuff to be easily consumed | 21:12 |
strigazi | for the cluster-autoscaler I'm testing our own https://github.com/cernops/autoscaler/pull/3 | 21:12 |
*** flwang has joined #openstack-containers | 21:12 | |
imdigitaljim | ill forward to our cas man | 21:12 |
strigazi | I'm giving priority to that one. | 21:12 |
flwang | sorry, i'm late | 21:12 |
colin- | nice strigazi looks like a lot of progress | 21:13 |
*** schaney has joined #openstack-containers | 21:13 | |
flwang | strigazi: what are we discussing? | 21:15 |
flwang | i'd like to discuss the k8s image versions we support, related to patch https://review.openstack.org/633650 | 21:16 |
strigazi | flwang: looks ok, maybe we can use the vars file | 21:16 |
strigazi | other than that it is ok | 21:17 |
strigazi | flwang: what do you think? | 21:17 |
flwang | strigazi: use vars is also ok for me and it's more clean i think, i will propose another patchset | 21:18 |
strigazi | flwang: thanks, building all of them is fine | 21:19 |
strigazi | I have another thing I want to discuss | 21:19 |
strigazi | We have an issue in k8s_fedora | 21:19 |
strigazi | maybe in centos that imdigitaljim is solved | 21:19 |
strigazi | k8s uostrean beeds three CAs | 21:20 |
strigazi | CA= certificate authority not cluster autoscaler | 21:20 |
strigazi | one for etcd | 21:20 |
strigazi | one for front-proxy | 21:20 |
strigazi | and one for the API | 21:20 |
strigazi | In magnum we create only one. | 21:20 |
strigazi | In the same manner that we create the service account keys, we need two more CAs. | 21:21 |
flwang | what's the affection now? | 21:22 |
flwang | affection/impact i mean | 21:22 |
strigazi | For example, a new feature like the metrics-server doesn't work correctly | 21:22 |
flwang | is there any security hole now? | 21:22 |
strigazi | see here: | 21:22 |
imdigitaljim | oh? | 21:22 |
imdigitaljim | helm chart metrics server? | 21:23 |
strigazi | https://review.openstack.org/#/c/632392/ | 21:23 |
strigazi | https://review.openstack.org/#/c/632392/4/magnum/drivers/common/templates/kubernetes/fragments/configure-kubernetes-master.sh@75 | 21:23 |
strigazi | This option kind of works | 21:23 |
strigazi | but the proper thing to do is to have tree CAs | 21:23 |
strigazi | see docs here: | 21:23 |
strigazi | https://github.com/kubernetes/website/blob/master/content/en/docs/setup/certificates.md | 21:24 |
flwang | so you mean though we can use the current, only one, CA, but we'd better to create 3, right? | 21:25 |
strigazi | installing the metrics-server with helm or not, it doesn'r matter | 21:25 |
strigazi | flwang: yes | 21:25 |
strigazi | quoting docs: You can create a single root CA, controlled by an administrator. This root CA can then create multiple intermediate CAs, and delegate all further creation to Kubernetes itself. | 21:25 |
imdigitaljim | yeah | 21:26 |
imdigitaljim | 1 CA is okay | 21:26 |
strigazi | having these three CAs would make the transition to kubeadm ~trivial | 21:26 |
imdigitaljim | 3 CA is better | 21:26 |
flwang | strigazi: i see | 21:26 |
strigazi | kubeadm will try to create these three CAs. | 21:26 |
flwang | strigazi: so i think it's important but not urgent issue | 21:26 |
strigazi | if you provide them it will use them | 21:27 |
flwang | cool | 21:27 |
imdigitaljim | also note: we dont use kubeadm at this time | 21:27 |
imdigitaljim | in case you were wondering | 21:27 |
imdigitaljim | theres a few issues in using kubeadm that we need to be better before/if we transition to them | 21:27 |
imdigitaljim | i think they are publicly listed in their design docs | 21:28 |
strigazi | kubeadm or not, to use API aggregators we need to deploy front-proxy certs properly | 21:28 |
openstackgerrit | Feilong Wang proposed openstack/magnum stable/pike: support http/https proxy for discovery url https://review.openstack.org/633755 | 21:29 |
strigazi | docs for front proxy: https://kubernetes.io/docs/tasks/access-kubernetes-api/configure-aggregation-layer/ | 21:31 |
imdigitaljim | Warning: Do not reuse a CA that is used in a different context unless you understand the risks and the mechanisms to protect the CA’s usage. | 21:32 |
imdigitaljim | :D | 21:32 |
imdigitaljim | i see your concern | 21:32 |
openstackgerrit | Keith Berger proposed openstack/magnum stable/pike: support http/https proxy for discovery url https://review.openstack.org/633755 | 21:32 |
strigazi | I can mention a horrible side-effect of using one CA. using the same CA to sign certs for kubelets and etcd, means compromise of kubelet certs gives access to etcd. | 21:33 |
imdigitaljim | sure | 21:34 |
strigazi | provided that there is a route from from the kubelet node to etcd | 21:34 |
imdigitaljim | preventing lateral movement is always good | 21:34 |
strigazi | same for the etcd that calico uses | 21:34 |
imdigitaljim | ill probably start working on solving some of these in the upcoming weeks | 21:35 |
imdigitaljim | good point out strigazi | 21:35 |
colin- | yeah. been working on Octavia on the side and have been going through this due to all the CAs it uses to secure communications between components | 21:35 |
colin- | and wanting them to be signed uniquely by service made deployment more complex but ultimately better for the security, imo | 21:36 |
strigazi | it is a ~chicken-egg problem. Who sings whose certs :) | 21:37 |
imdigitaljim | we were looking at other solutions like vault as a CA | 21:38 |
imdigitaljim | and such | 21:38 |
strigazi | The problem to cert management in kubernetes is more CAs | 21:38 |
imdigitaljim | https://github.com/hashicorp/vault | 21:38 |
strigazi | s/problem/solution/ | 21:38 |
imdigitaljim | not sure their CA capabilities | 21:38 |
strigazi | Anything else anyone? (the day is ending for me) | 21:41 |
imdigitaljim | not here | 21:42 |
imdigitaljim | o/ | 21:42 |
strigazi | flwang colin- jakeyip anything else? | 21:42 |
strigazi | jakeyip: for tempest python3, all good? | 21:43 |
jakeyip | Nothing to report :) | 21:43 |
strigazi | cool | 21:44 |
colin- | nope | 21:44 |
strigazi | let's end the meeting then | 21:45 |
colin- | have a good night! | 21:45 |
strigazi | see you next week | 21:45 |
strigazi | colin-: cheers | 21:45 |
cbrumm | bye all | 21:45 |
strigazi | #endmeeting | 21:45 |
*** openstack changes topic to "OpenStack Containers Team" | 21:45 | |
openstack | Meeting ended Tue Jan 29 21:45:49 2019 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 21:45 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/containers/2019/containers.2019-01-29-21.02.html | 21:45 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/containers/2019/containers.2019-01-29-21.02.txt | 21:45 |
openstack | Log: http://eavesdrop.openstack.org/meetings/containers/2019/containers.2019-01-29-21.02.log.html | 21:45 |
openstackgerrit | Merged openstack/magnum stable/rocky: Support Keystone AuthN and AuthZ for k8s https://review.openstack.org/633571 | 22:13 |
*** sdake has joined #openstack-containers | 22:15 | |
*** munimeha1 has quit IRC | 22:43 | |
openstackgerrit | Feilong Wang proposed openstack/magnum master: Support multi k8s image versions https://review.openstack.org/633650 | 22:53 |
-openstackstatus- NOTICE: http://zuul.openstack.org is not working. https://zuul.openstack.org does work. Please use that while we investigate. | 23:12 | |
colby_ | flwang: any suggestions for me? Is renaming our availability zone going to be our solution? | 23:31 |
*** sdake has quit IRC | 23:35 | |
*** sdake has joined #openstack-containers | 23:37 | |
*** rcernin has quit IRC | 23:53 | |
flwang | colby_: did you upgrade your cinder recently? | 23:55 |
*** sdake has quit IRC | 23:55 | |
*** sdake has joined #openstack-containers | 23:55 | |
openstackgerrit | Feilong Wang proposed openstack/magnum master: Support multi k8s image versions https://review.openstack.org/633650 | 23:59 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!