*** k_mouza has joined #openstack-containers | 00:51 | |
*** k_mouza has quit IRC | 00:56 | |
*** k_mouza has joined #openstack-containers | 00:58 | |
*** ricolin_ has joined #openstack-containers | 00:59 | |
*** k_mouza has quit IRC | 01:04 | |
*** k_mouza has joined #openstack-containers | 01:27 | |
*** k_mouza has quit IRC | 01:31 | |
*** xinliang has joined #openstack-containers | 01:32 | |
*** sapd__x has joined #openstack-containers | 02:20 | |
*** rcernin has quit IRC | 02:56 | |
*** rcernin has joined #openstack-containers | 02:58 | |
openstackgerrit | Feilong Wang proposed openstack/magnum stable/ussuri: Fix label fixed_network_cidr https://review.opendev.org/738183 | 03:04 |
---|---|---|
openstackgerrit | Feilong Wang proposed openstack/magnum stable/ussuri: [k8s] Fix PreDeletionFailed if Heat stack is missing https://review.opendev.org/741076 | 03:07 |
openstackgerrit | Feilong Wang proposed openstack/magnum stable/ussuri: Fix ServerAddressOutputMapping for private clusters https://review.opendev.org/738184 | 03:12 |
*** ramishra has quit IRC | 03:13 | |
*** ramishra has joined #openstack-containers | 03:14 | |
*** k_mouza has joined #openstack-containers | 03:44 | |
*** k_mouza has quit IRC | 03:48 | |
*** xinliang has quit IRC | 04:01 | |
*** sapd__x has quit IRC | 04:12 | |
*** ykarel has joined #openstack-containers | 04:34 | |
*** vishalmanchanda has joined #openstack-containers | 04:50 | |
*** sapd__x has joined #openstack-containers | 04:58 | |
*** k_mouza has joined #openstack-containers | 05:13 | |
*** k_mouza has quit IRC | 05:18 | |
*** udesale has joined #openstack-containers | 05:22 | |
*** udesale has quit IRC | 06:07 | |
*** udesale has joined #openstack-containers | 06:20 | |
*** rcernin has quit IRC | 07:07 | |
*** k_mouza has joined #openstack-containers | 07:09 | |
*** born2bake has joined #openstack-containers | 07:13 | |
*** k_mouza has quit IRC | 07:13 | |
*** k_mouza has joined #openstack-containers | 07:18 | |
*** rcernin has joined #openstack-containers | 07:18 | |
*** k_mouza has quit IRC | 07:22 | |
*** udesale has quit IRC | 07:47 | |
*** udesale has joined #openstack-containers | 07:47 | |
*** k_mouza has joined #openstack-containers | 07:54 | |
*** k_mouza has quit IRC | 07:59 | |
*** k_mouza has joined #openstack-containers | 08:03 | |
*** rcernin has quit IRC | 08:27 | |
*** rcernin has joined #openstack-containers | 08:49 | |
*** xinliang has joined #openstack-containers | 08:50 | |
*** flwang1 has joined #openstack-containers | 08:52 | |
flwang1 | brtknr: around for weekly meeting? | 08:53 |
brtknr | flwang1: o/ | 08:53 |
brtknr | yes im around | 08:53 |
flwang1 | brtknr: seems we don't have spyros today | 08:55 |
brtknr | yes, seems that way | 08:56 |
flwang1 | #startmeeting magnum | 09:00 |
openstack | Meeting started Wed Jul 15 09:00:16 2020 UTC and is due to finish in 60 minutes. The chair is flwang1. Information about MeetBot at http://wiki.debian.org/MeetBot. | 09:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 09:00 |
*** openstack changes topic to " (Meeting topic: magnum)" | 09:00 | |
openstack | The meeting name has been set to 'magnum' | 09:00 |
flwang1 | #topic roll call | 09:01 |
*** openstack changes topic to "roll call (Meeting topic: magnum)" | 09:01 | |
flwang1 | o/ | 09:01 |
openstackgerrit | Bharat Kunwar proposed openstack/magnum master: [docs] Bring user docs up to date with recent changes https://review.opendev.org/714721 | 09:01 |
brtknr | o/ | 09:01 |
flwang1 | i think just us | 09:02 |
flwang1 | let's go through the topics for today | 09:02 |
flwang1 | #topic master_lb_enabled | 09:02 |
*** openstack changes topic to "master_lb_enabled (Meeting topic: magnum)" | 09:02 | |
flwang1 | you guys merged the client side patch before merging the server side :) | 09:03 |
flwang1 | so i have to push you again on this one | 09:03 |
brtknr | flwang1: hehe its opt in on client side | 09:04 |
flwang1 | brtknr: can you revisit that one? https://review.opendev.org/#/c/726017/ | 09:04 |
brtknr | so no great harm, i see the server side merging imminently | 09:04 |
flwang1 | and it can make our life easier | 09:05 |
flwang1 | at this moment, we're maintaining 6 templates | 09:05 |
flwang1 | with this one, we can reduce it to 3 | 09:05 |
brtknr | flwang1: nice are you guys already using the server side patch? | 09:06 |
flwang1 | no, we only maintain private patch when we have to | 09:06 |
flwang1 | as long as this one merged, i will propose a patch on magnum ui to add a checkbox for this | 09:07 |
brtknr | flwang1: sounds good | 09:07 |
flwang1 | brtknr: i will bug you again if i didn't see your comments by this Friday :D | 09:08 |
brtknr | flwang1: yes things have been quite busy recently so not had a chance to work on much upstream stuff | 09:09 |
flwang1 | i understand and I appreciate any contribution when people are busy on internal work | 09:09 |
flwang1 | let's move on? | 09:10 |
brtknr | flwang1: actually the reason I proposed the cluster template clone patch was to test your cluster upgrade patch | 09:10 |
brtknr | as i was too lazy to create a new template from scratch everytime | 09:10 |
flwang1 | brtknr: that's a clever command, i like it TBH | 09:11 |
flwang1 | i will test it before +2 | 09:11 |
brtknr | flwang1: one thing i noticed was that after the upgrade fails, i cannot upgrade the cluster | 09:11 |
brtknr | is that expected? | 09:11 |
flwang1 | you mean the cluster will be in update_failed? | 09:12 |
brtknr | yeah | 09:12 |
flwang1 | and can't be upgrade again? | 09:12 |
brtknr | e.g. if i try to upgrade to 2.19 and the update_failed | 09:12 |
brtknr | looks like we are already talking about the next topic btw | 09:12 |
flwang1 | #topic upgrade disallow minor version skipped | 09:13 |
*** openstack changes topic to "upgrade disallow minor version skipped (Meeting topic: magnum)" | 09:13 | |
flwang1 | yep, so noticed that as well. so i'm thinking if we should move this logic to api layer | 09:13 |
flwang1 | or when there is an error, just reset the status back | 09:14 |
flwang1 | or when there is a upgrade failed error, just reset the status | 09:14 |
brtknr | flwang1: yes that would make sense | 09:15 |
flwang1 | i will dig it | 09:15 |
brtknr | or allow upgrade even when state is update_failed? | 09:15 |
brtknr | otherwise how will the user know? | 09:16 |
flwang1 | brtknr: or allow upgrade even when state is update_failed? --- yes, that one should be fixed as well | 09:16 |
flwang1 | brtknr: good point | 09:16 |
*** rcernin has quit IRC | 09:17 | |
flwang1 | i think we just need to allow upgrade a cluster which in 'update_failed' status | 09:17 |
flwang1 | very efficient discussion | 09:17 |
flwang1 | next one? | 09:17 |
brtknr | flwang1: may I make a request btw | 09:17 |
flwang1 | sure | 09:17 |
brtknr | when i test your changes, your topics are often story/xxxxxx-xxxx | 09:18 |
brtknr | while this is good for the commit messsage, it is difficult to see what this change is about when i do `git branch` | 09:19 |
flwang1 | haha | 09:19 |
brtknr | especially when there are lots of branches already | 09:19 |
brtknr | may i suggest that you use a semantic topic :) | 09:19 |
flwang1 | i will replace the 'story' withe a meaningful name | 09:19 |
brtknr | flwang1: thanks | 09:20 |
flwang1 | btw, as your comment about major version, i don't mind to add it, but i prefer to see spyros's opinion on the existing code before i putting much effort on that | 09:21 |
brtknr | flwang1: understood | 09:22 |
flwang1 | brtknr: your docs patch looks good for me, i will +2, easy one | 09:23 |
flwang1 | brtknr: btw, it would be nice if you can revisit the ca rotate patch. Spyros gave some good comments and I think i have already addressed that. so please revisit it when you have time | 09:25 |
*** xinliang has quit IRC | 09:27 | |
brtknr | flwang1: no problem i will test it by the end of this week | 09:29 |
flwang1 | thank you very much | 09:29 |
brtknr | flwang1: probably just a basic test to make sure it works as expected | 09:29 |
brtknr | flwang1: btw have you tried the k8s cluster API? | 09:30 |
flwang1 | no, why? | 09:30 |
brtknr | flwang1: i had a quick look at it recently: https://github.com/kubernetes-sigs/cluster-api-provider-openstack | 09:31 |
flwang1 | brtknr: how do you think? | 09:32 |
brtknr | I was surprised it required a kubernetes cluster for bootstrapping | 09:32 |
brtknr | well the image that i uploaded to glance did not boot so i havent had a chance to try it fully | 09:32 |
brtknr | the documentation is lacking too | 09:32 |
flwang1 | yep, it needs a "root" k8s cluster | 09:33 |
flwang1 | one day, if EKS or GKE start to use cluster API, then i think Magnum can think about it, otherwise. it doesn't fit our scope | 09:34 |
brtknr | flwang1: it is a long way from being stable actually | 09:35 |
brtknr | e.g. i cannot delete the clusters ive created | 09:35 |
flwang1 | without many people's hard work, hard to get it stable | 09:36 |
brtknr | it complains about a security group that is in use but the controller manager should delete things in the correct order | 09:36 |
flwang1 | btw, did you guys using designate in your cloud? | 09:37 |
flwang1 | s/did/are | 09:37 |
brtknr | we do on one of the sites but i didnt deploy it | 09:38 |
flwang1 | right | 09:40 |
flwang1 | i'm doing some research work now | 09:40 |
flwang1 | anything else you would like to discuss? | 09:40 |
brtknr | flwang1: what are you hoping to do with designate? | 09:41 |
flwang1 | basic integration with VM layer and integrate with k8s with external-dns | 09:42 |
brtknr | flwang1: i see | 09:43 |
flwang1 | cool, let's call this one done | 09:45 |
flwang1 | brtknr: thanks for joining | 09:45 |
brtknr | flwang1: can i quickly clarify something | 09:46 |
flwang1 | sure | 09:46 |
brtknr | https://docs.openstack.org/magnum/latest/user/#keystone-authentication-and-authorization-for-kubernetes | 09:46 |
brtknr | https://docs.openstack.org/magnum/latest/user/#keystone-authn-and-authz | 09:47 |
brtknr | flwang1: these two sections seems to serve a similar purpose | 09:47 |
brtknr | flwang1: shall we keep the first and remove the second? | 09:47 |
brtknr | or merge the two together? | 09:48 |
flwang1 | i will take a look and see if they can be merged | 09:48 |
*** ricolin_ has quit IRC | 09:49 | |
flwang1 | seems the 2nd part can be merged into the 1st part | 09:50 |
flwang1 | brtknr: anything else? | 09:50 |
brtknr | shall I update the docs PS with this change in that case? | 09:51 |
brtknr | I was also thinking about moving #keystone-authentication-and-authorization-for-kubernetes to #kubernetes as a subsection | 09:51 |
brtknr | also Kubernetes Health Monitoring which is currecntly H1 | 09:51 |
brtknr | but I think it should be H2 under kubernetes section | 09:52 |
flwang1 | i would suggest put it into a separate patch | 09:52 |
brtknr | https://docs.openstack.org/magnum/latest/user/#kubernetes-external-load-balancer also seems out of date since neutron lbaas is now completely removed | 09:53 |
brtknr | Ok separate patch sounds good | 09:54 |
brtknr | As it will involve some reorganisation | 09:55 |
flwang1 | yep | 09:55 |
flwang1 | thanks for putting time on the docs work | 09:55 |
flwang1 | appreciate that | 09:55 |
brtknr | flwang1: np, it needs some love | 09:56 |
flwang1 | true | 09:56 |
flwang1 | ok, i'm going to close this meeting | 09:56 |
flwang1 | #endmeeting | 09:57 |
*** openstack changes topic to "OpenStack Containers Team | Meeting: every Wednesday @ 9AM UTC | Agenda: https://etherpad.openstack.org/p/magnum-weekly-meeting" | 09:57 | |
openstack | Meeting ended Wed Jul 15 09:57:11 2020 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 09:57 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/magnum/2020/magnum.2020-07-15-09.00.html | 09:57 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/magnum/2020/magnum.2020-07-15-09.00.txt | 09:57 |
openstack | Log: http://eavesdrop.openstack.org/meetings/magnum/2020/magnum.2020-07-15-09.00.log.html | 09:57 |
flwang1 | brtknr: thanks for joining, have a good day | 09:57 |
brtknr | flwang1: you too! | 09:57 |
*** k_mouza has quit IRC | 10:07 | |
*** k_mouza has joined #openstack-containers | 10:10 | |
*** nikparasyr has joined #openstack-containers | 10:13 | |
*** cyrilleb has joined #openstack-containers | 10:56 | |
*** flwang1 has quit IRC | 11:05 | |
*** sapd__x has quit IRC | 11:22 | |
*** udesale_ has joined #openstack-containers | 11:31 | |
*** rcernin has joined #openstack-containers | 11:32 | |
*** udesale has quit IRC | 11:34 | |
*** rcernin has quit IRC | 11:47 | |
*** cyrilleb has quit IRC | 11:48 | |
*** mgariepy has joined #openstack-containers | 12:09 | |
*** nikparasyr has quit IRC | 13:12 | |
*** nikparasyr has joined #openstack-containers | 13:13 | |
*** ramishra has quit IRC | 13:59 | |
*** ramishra has joined #openstack-containers | 14:19 | |
*** ramishra has quit IRC | 14:28 | |
*** dave-mccowan has quit IRC | 14:43 | |
*** dave-mccowan has joined #openstack-containers | 14:47 | |
*** ramishra has joined #openstack-containers | 14:48 | |
*** nikparasyr has left #openstack-containers | 14:52 | |
*** ykarel is now known as ykarel|away | 15:13 | |
*** ykarel|away has quit IRC | 15:43 | |
*** ramishra has quit IRC | 15:46 | |
*** k_mouza has quit IRC | 15:55 | |
*** k_mouza has joined #openstack-containers | 16:11 | |
*** k_mouza has quit IRC | 16:16 | |
*** mgariepy has quit IRC | 16:22 | |
*** ramishra has joined #openstack-containers | 16:24 | |
*** k_mouza has joined #openstack-containers | 16:24 | |
*** k_mouza has quit IRC | 16:24 | |
*** k_mouza has joined #openstack-containers | 16:24 | |
*** k_mouza has quit IRC | 16:29 | |
*** ykarel|away has joined #openstack-containers | 16:35 | |
*** udesale_ has quit IRC | 16:38 | |
*** mgariepy has joined #openstack-containers | 17:09 | |
*** ykarel|away has quit IRC | 17:25 | |
*** vishalmanchanda has quit IRC | 18:20 | |
*** arkan has joined #openstack-containers | 18:58 | |
arkan | hi guys, when I'm trying to create kubernetes cluster on magnum I'm receiving | 18:59 |
arkan | reason: Resource CREATE failed: AuthorizationFailure: resources.kube_masters.resources[0].resources.kube-master: Authorization failed. | 18:59 |
arkan | I'm on stable/train OSA | 19:00 |
arkan | journalctl -xf --> magnum container http://paste.openstack.org/show/795953/ | 19:00 |
arkan | journalctl -xf ---> keyston container http://paste.openstack.org/show/795956/ | 19:04 |
arkan | journalctl -xf ---> heat api container http://paste.openstack.org/show/795957/ | 19:05 |
*** KeithMnemonic has joined #openstack-containers | 19:12 | |
brtknr | arkan: Sounds like authorisation failed | 21:00 |
arkan | yes, and I read now the doc | 21:00 |
arkan | https://docs.openstack.org/heat/train/install/install-ubuntu.html | 21:00 |
arkan | I installed openstack using Openstack Ansible, and the above doc I used it to verify the config that I have | 21:01 |
arkan | it seems that this line openstack role add --domain heat --user-domain heat --user heat_domain_admin admin | 21:02 |
arkan | which is in my case with OSA (stable/train), it's not heat_domain_admin but stack_domain_admin | 21:03 |
brtknr | arkan: sorry I’m not too familiar with OSA | 21:04 |
arkan | after I did this openstack role add --domain heat --user-domain heat --user stack_domain_admin admin | 21:04 |
brtknr | It works? | 21:04 |
arkan | the error disappeared | 21:04 |
brtknr | great! | 21:04 |
arkan | I think the user was not authorised that manages the stack | 21:05 |
arkan | now I'm having a problem related to cinder volume | 21:05 |
arkan | I saw this bug https://bugs.launchpad.net/openstack-ansible/+bug/1877421 | 21:06 |
openstack | Launchpad bug 1877421 in openstack-ansible "Cinder-volume is not able to recognize a ceph cluster on OpenStack Train." [Undecided,New] | 21:06 |
arkan | I think I solved the problem with authorisation with magnum, the user stack_domain_admin was not added to the heat domain with a role admin | 21:10 |
*** logan- has quit IRC | 22:17 | |
*** logan- has joined #openstack-containers | 22:19 | |
*** rcernin has joined #openstack-containers | 22:20 | |
*** rcernin has quit IRC | 22:20 | |
*** rcernin has joined #openstack-containers | 22:21 | |
*** born2bake has quit IRC | 23:28 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!