flwang1 | brtknr: we just need a default value in heat as i changed in the previous patch, unless we're talking about different things | 00:52 |
---|---|---|
flwang1 | brtknr: i saw your comments in the calico patch, do you mean it works now? | 00:52 |
openstackgerrit | Feilong Wang proposed openstack/magnum master: Fix calico regression issue caused by default ipv4pool change https://review.opendev.org/715093 | 00:55 |
*** xinliang has joined #openstack-containers | 00:58 | |
*** pcaruana has quit IRC | 02:54 | |
*** pcaruana has joined #openstack-containers | 03:07 | |
*** ykarel|away is now known as ykarel | 04:08 | |
*** xinliang has quit IRC | 04:20 | |
*** udesale has joined #openstack-containers | 04:47 | |
brtknr | flwang1: yes upgraded calico works with the regression fix but need to run comformance | 04:51 |
*** udesale has quit IRC | 05:10 | |
*** udesale has joined #openstack-containers | 05:12 | |
flwang1 | brtknr: i'm running the conformance test | 05:15 |
flwang1 | btw | 05:15 |
flwang1 | it's still running, i will update the result on the patch | 05:23 |
*** rcernin has quit IRC | 05:40 | |
*** rcernin has joined #openstack-containers | 05:41 | |
*** rcernin has quit IRC | 05:41 | |
*** rcernin has joined #openstack-containers | 05:42 | |
*** rcernin has quit IRC | 05:42 | |
*** rcernin has joined #openstack-containers | 05:47 | |
*** ykarel is now known as ykarel|meeting | 06:01 | |
*** rcernin has quit IRC | 06:02 | |
*** rcernin has joined #openstack-containers | 06:02 | |
*** rcernin has quit IRC | 06:05 | |
*** rcernin has joined #openstack-containers | 06:05 | |
*** ykarel|meeting is now known as ykarel | 06:49 | |
brtknr | flwang1 Cool | 06:59 |
brtknr | flwang1: when I checked, pod to pod communication was restored | 07:02 |
brtknr | Are you going to split coredns into a separate ps? | 07:04 |
brtknr | flwang1: Can you please also review some of the other ps before you disappear? Mainly the rootfs one as I’d like to back port if possible | 07:06 |
brtknr | Cheers | 07:15 |
flwang1 | brtknr: sure, will do | 07:25 |
flwang1 | the conformance testing is soooooo slow | 07:25 |
*** vishalmanchanda has joined #openstack-containers | 07:56 | |
*** sapd1 has joined #openstack-containers | 07:57 | |
*** guilhermesp has quit IRC | 08:06 | |
brtknr | flwang1: did it complete? | 09:18 |
*** ykarel is now known as ykarel|lunch | 09:27 | |
openstackgerrit | Diogo Guerra proposed openstack/magnum master: [k8s] label to select helm client container tag https://review.opendev.org/715142 | 09:32 |
openstackgerrit | Diogo Guerra proposed openstack/magnum master: [k8s] label to select helm client container tag https://review.opendev.org/715142 | 09:34 |
*** rcernin has quit IRC | 09:51 | |
tobias-urdin | solved my issue by using heat_container_agent_tag=stein-stable | 10:14 |
*** ykarel|lunch is now known as ykarel | 10:14 | |
brtknr | tobias-urdin: good to hear! | 11:49 |
brtknr | can you tell me what configuration you were using again? | 11:49 |
*** udesale_ has joined #openstack-containers | 12:21 | |
*** udesale has quit IRC | 12:24 | |
*** sapd1 has quit IRC | 12:36 | |
*** guilhermesp has joined #openstack-containers | 14:26 | |
*** guilhermesp has quit IRC | 14:27 | |
*** guilhermesp has joined #openstack-containers | 14:27 | |
*** sapd1 has joined #openstack-containers | 14:28 | |
*** yankcrime has quit IRC | 14:29 | |
tobias-urdin | brtknr: rocky release with kube_tag=v1.15.7,cloud_provider_tag=v1.15.0,ingress_controller=octavia | 14:29 |
tobias-urdin | labels | 14:29 |
brtknr | tobias-urdin: great thanks] | 14:30 |
brtknr | tobias-urdin: which rocky release? | 14:30 |
tobias-urdin | kubectl in heat-container-agent for rocky-stable failed to apply some configs | 14:30 |
tobias-urdin | latest 7.2.0 iirc | 14:30 |
tobias-urdin | i.e kubectl v1.10.3 in heat-container-agent tag rocky-stable could not apply for k8s cluster with version v1.15.7 | 14:31 |
*** guilhermesp has quit IRC | 14:34 | |
*** guilhermesp has joined #openstack-containers | 14:35 | |
*** yankcrime has joined #openstack-containers | 14:38 | |
*** guilhermesp has quit IRC | 14:38 | |
*** guilhermesp has joined #openstack-containers | 14:38 | |
brtknr | tobias-urdin: ok i have updated the wiki, https://wiki.openstack.org/wiki/Magnum#Compatibility_Matrix | 14:39 |
*** guilhermesp has quit IRC | 14:39 | |
brtknr | the most important bit is the heat container agent tag i think | 14:39 |
*** guilhermesp has joined #openstack-containers | 14:40 | |
tobias-urdin | brtknr: another question, if we set cluster_user_trust to True in magnum.conf the trust ID will always be added | 14:57 |
tobias-urdin | to the nodes, but there is no way to per cluster/per template override that behavior right? | 14:57 |
tobias-urdin | so we'd need to introduce a label to not add credentials for a specific cluster/spawned from a specific template | 14:57 |
tobias-urdin | here https://github.com/openstack/magnum/blob/master/magnum/drivers/heat/template_def.py#L382 | 14:57 |
brtknr | no sorry, | 14:59 |
brtknr | the closest i think is cloud_provider_enabled=False | 14:59 |
brtknr | but I havent checked | 14:59 |
tobias-urdin | yeah, i thought about that as well but that doesn't keep the credentials out of the node | 15:00 |
tobias-urdin | after reading through all code i can't find that having an impact anywhere on the installmed of the credentials file | 15:00 |
tobias-urdin | in /etc/kubernetes/cloud-config | 15:00 |
*** ykarel is now known as ykarel|away | 15:06 | |
*** KeithMnemonic has quit IRC | 15:13 | |
*** sapd1 has quit IRC | 15:36 | |
*** sapd1 has joined #openstack-containers | 15:49 | |
*** udesale_ has quit IRC | 15:50 | |
*** mgariepy has quit IRC | 16:36 | |
*** mgariepy has joined #openstack-containers | 16:43 | |
*** openstack has quit IRC | 17:49 | |
*** openstack has joined #openstack-containers | 17:51 | |
*** ChanServ sets mode: +o openstack | 17:51 | |
flwang1 | brtknr: strigazi: around? | 18:31 |
brtknr | flwang1: ill be on and off | 20:30 |
flwang1 | When network traffic is not encapsulated, all traffic must be open from workers to master nodes. For example, in my example DS, to curl HTTP from worker to master port 80 protocol TCP must be allowed.I am not sure if you (CERN does not have security groups) want traffic from workers to masters to be open. If conformance passes it should be ok. | 20:30 |
flwang1 | as for the comments you and strigazi discussed in the calico patch | 20:31 |
flwang1 | brtknr: i can't really get why a worker needs to access master node | 20:31 |
flwang1 | brtknr: technically, a worker node only needs to talk to the k8s api and other necessary ports, but not ANY port | 20:32 |
brtknr | all pods in a daemonset should be able to talk to each other no? | 20:33 |
brtknr | esp in the same namespace | 20:33 |
brtknr | this problem doesnt exist in flannel | 20:33 |
brtknr | also this problem did not exist before calico upgrade | 20:33 |
flwang1 | brtknr: you mean in a DS, from the pod on worker to a pod on master? | 20:34 |
brtknr | flwang1: thats right | 20:36 |
flwang1 | do you have a sample yaml i can test? | 20:37 |
brtknr | flwang1: strigazi has provided a link on gerrit | 20:38 |
flwang1 | i can see it, he just provided a link to calico requirements | 20:39 |
flwang1 | brtknr: you said in the comments you can reproduce, how did you do? | 20:39 |
brtknr | i hit the same issue, master can reach worker port 80 but not the other way round | 20:40 |
brtknr | flwang1: from the pods in the daemonset | 20:41 |
brtknr | flwang1: https://gist.githubusercontent.com/strigazi/5e75559e2221d4b9e3f63f7b33c82c9b/raw/3ac84e9416403fd1b9981ff77184c5b8542b6409/debugging-daemonset.yaml | 20:42 |
flwang1 | brtknr: cool, i'm going to test it on our prod first to see if it's working on old calico version | 20:44 |
flwang1 | brtknr: seems there is no curl or wget in the httpd pod, what's the command you used to verify the connection to the pod on master? | 20:54 |
openstackgerrit | Feilong Wang proposed openstack/magnum master: Fix calico regression issue caused by default ipv4pool change https://review.opendev.org/715093 | 21:14 |
flwang1 | brtknr: never mind, i found there is a sidecar centos | 21:18 |
flwang1 | brtknr: i can reproduce it | 21:27 |
flwang1 | it works on 3.3.6 but not work on 3.13.1 | 21:28 |
*** rcernin has joined #openstack-containers | 22:25 | |
openstackgerrit | Feilong Wang proposed openstack/magnum master: [k8s] Support updating k8s cluster health status https://review.opendev.org/710384 | 22:58 |
*** rcernin has quit IRC | 23:06 | |
*** rcernin has joined #openstack-containers | 23:07 | |
*** rcernin has quit IRC | 23:07 | |
*** rcernin has joined #openstack-containers | 23:08 | |
*** vishalmanchanda has quit IRC | 23:39 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!