*** catintheroof has joined #openstack-dns | 00:11 | |
*** hoangcx has joined #openstack-dns | 00:41 | |
*** cuongnv has joined #openstack-dns | 01:06 | |
*** catintheroof has quit IRC | 01:09 | |
*** leitan has joined #openstack-dns | 01:17 | |
*** leitan has quit IRC | 01:21 | |
*** mlavalle has quit IRC | 01:26 | |
*** EricGonczer_ has joined #openstack-dns | 01:34 | |
*** EricGonczer_ has quit IRC | 01:37 | |
*** EricGonczer_ has joined #openstack-dns | 01:43 | |
*** EricGonczer_ has quit IRC | 01:45 | |
*** fandi has joined #openstack-dns | 02:38 | |
*** fandi has quit IRC | 02:39 | |
openstackgerrit | Cuong Nguyen proposed openstack/designate: Make exception catching more python3-ish https://review.openstack.org/421027 | 02:43 |
---|---|---|
*** EricGonczer_ has joined #openstack-dns | 02:45 | |
*** leitan has joined #openstack-dns | 03:18 | |
*** leitan has quit IRC | 03:23 | |
*** brensen has quit IRC | 03:26 | |
*** brensen has joined #openstack-dns | 03:27 | |
*** EricGonczer_ has quit IRC | 04:01 | |
*** leitan has joined #openstack-dns | 05:19 | |
*** leitan has quit IRC | 05:23 | |
*** rahul1911 has joined #openstack-dns | 05:27 | |
*** cliles has joined #openstack-dns | 06:00 | |
*** rahul1911 has quit IRC | 06:04 | |
*** rahul1911 has joined #openstack-dns | 06:30 | |
*** richm has quit IRC | 06:42 | |
*** eandersson_ has joined #openstack-dns | 06:48 | |
*** eandersson has quit IRC | 06:51 | |
*** leitan has joined #openstack-dns | 07:20 | |
*** leitan has quit IRC | 07:24 | |
*** leitan has joined #openstack-dns | 09:21 | |
*** leitan has quit IRC | 09:26 | |
openstackgerrit | avnish proposed openstack/designate-dashboard: Switch to oslo_log https://review.openstack.org/421169 | 09:27 |
*** hoangcx has quit IRC | 10:10 | |
*** cuongnv has quit IRC | 10:17 | |
*** haplo37_ has quit IRC | 10:19 | |
*** haplo37_ has joined #openstack-dns | 10:19 | |
*** abalutoiu has quit IRC | 11:06 | |
*** richm has joined #openstack-dns | 11:13 | |
*** rahul1911 has quit IRC | 11:19 | |
*** leitan has joined #openstack-dns | 11:23 | |
*** rahul1911 has joined #openstack-dns | 11:25 | |
*** leitan has quit IRC | 11:27 | |
*** rahul1911 has quit IRC | 11:35 | |
*** leitan has joined #openstack-dns | 11:55 | |
*** EmilienM has joined #openstack-dns | 12:21 | |
EmilienM | o/ | 12:21 |
EmilienM | I've reported a bug a few weeks ago about ipv6 binding, which looks broken: https://bugs.launchpad.net/designate/+bug/1653839 | 12:21 |
openstack | Launchpad bug 1653839 in Designate "ipv6 binding is broken" [High,Triaged] | 12:21 |
EmilienM | timsim: I saw you did some triage on it but do you know if it's in your radar? | 12:22 |
EmilienM | we had to stop to test designate in Puppet OpenStack CI, which is odd | 12:22 |
*** catintheroof has joined #openstack-dns | 12:32 | |
*** EricGonczer_ has joined #openstack-dns | 12:32 | |
*** EricGonc_ has joined #openstack-dns | 14:00 | |
*** EricGonczer_ has quit IRC | 14:01 | |
*** EricGonc_ has quit IRC | 14:13 | |
*** EricGonczer_ has joined #openstack-dns | 14:14 | |
*** mlavalle has joined #openstack-dns | 14:22 | |
*** cleong has joined #openstack-dns | 14:23 | |
*** ducttape_ has quit IRC | 14:26 | |
*** abalutoiu has joined #openstack-dns | 14:31 | |
*** stanzgy has quit IRC | 14:31 | |
*** rahul1911 has joined #openstack-dns | 14:32 | |
*** rahul1911 has quit IRC | 14:36 | |
*** rahul1911 has joined #openstack-dns | 14:37 | |
*** tdink has joined #openstack-dns | 14:52 | |
*** ducttape_ has joined #openstack-dns | 14:59 | |
*** pcaruana has quit IRC | 15:15 | |
*** rahul1911 has quit IRC | 15:16 | |
*** _ducttape_ has joined #openstack-dns | 15:59 | |
*** ducttape_ has quit IRC | 16:03 | |
mugsie | EmilienM: it is on our radar, but we may not have developer time to fix it in ocata | 16:11 |
mugsie | it is weird, it looks like the issue is in olso.service | 16:11 |
mugsie | is there any other project that have this issue? | 16:11 |
EmilienM | mugsie: not afik, only designate | 16:11 |
EmilienM | mugsie: we deploy other services with ipv6 | 16:12 |
mugsie | :/ | 16:13 |
leitan | Hi guys, wondering if there is a resource to create and manage servers on the v2 version, cause i dont seem to get it working | 16:20 |
mugsie | leitan: kinda | 16:22 |
leitan | mugsie: enlight me please :) | 16:22 |
mugsie | but the v1/servers endpoint will update the servers applied in v2 | 16:22 |
leitan | im getting 403 forbidden | 16:23 |
mugsie | we moved the config to a yaml file that is then loaded into the DB | 16:23 |
leitan | calling v1/servers | 16:23 |
leitan | with designate client | 16:23 |
leitan | or with curl | 16:23 |
leitan | both | 16:23 |
mugsie | are you an admin? | 16:23 |
leitan | i am | 16:23 |
mugsie | what version of designate again? | 16:23 |
leitan | mitaka | 16:23 |
mugsie | ah | 16:23 |
mugsie | ok, we made it much better since then | 16:24 |
leitan | for example in other deployment | 16:24 |
mugsie | http://docs.openstack.org/developer/designate/pools.html#managing-pools | 16:24 |
leitan | i have created the server previously to switching to v2 | 16:24 |
leitan | designate server-create etc | 16:24 |
mugsie | the "servers" are now the section called "ns_records" | 16:24 |
leitan | and listing works with curl | 16:24 |
mugsie | in that yaml file | 16:25 |
leitan | ok great | 16:25 |
leitan | yes, so i dont need anymore | 16:25 |
leitan | the "server" that i create with server create | 16:25 |
leitan | in v1 | 16:25 |
mugsie | yeah - there was a loooooong transition - but we managed to move to the new config format | 16:25 |
mugsie | no | 16:25 |
leitan | mugsie: great, i have a fully working v2 env with that pool.yml, so i was mixing concepts then | 16:25 |
leitan | mugsie: are you related with the neutron integration ? cause i need to know if ptr should be created automatically from floating ips allocated | 16:26 |
mugsie | I have a working knowledge | 16:26 |
mugsie | they should be created | 16:27 |
mugsie | but you would need to delegate the in-arpa domain to the designate servers for it to be useful | 16:27 |
mugsie | they are not in the tenant / project though, they are in the admin tenat | 16:27 |
*** carthaca_ has joined #openstack-dns | 16:30 | |
carthaca_ | Hi mugsie: are you up for more questions? :slightly_smiling_face: | 16:30 |
carthaca_ | We are trying to use the akamai backend to create a zone there, but run into some kind of chicken-egg-problem | 16:30 |
mugsie | carthaca_: sure :) | 16:30 |
mugsie | OK, - is it TSIG Keys? | 16:31 |
carthaca_ | Here is in short how I understand what is happening: the backend is sending out SOA requests to akamai before setting the zone to active, but akamai can't retrieve the details via axfr from mdns because it is not active yet. | 16:31 |
carthaca_ | no tsig-keys is the thing I submitted and patched already xD | 16:31 |
mugsie | oh. mdns should serve the zone regardless of the status | 16:31 |
mugsie | if you dig @mdns:5354 zone.tld. SOA does it work? | 16:32 |
mugsie | OH, akamai ! are you running miniDNS on port 53 ? | 16:32 |
carthaca_ | no that doesn't work | 16:32 |
mugsie | you have to run it on 53 for akamai to read it | 16:32 |
mugsie | (they do not support non standard ports) | 16:33 |
carthaca_ | ok, I have to check with my colleague with the loadbalacing setup | 16:33 |
carthaca_ | but anyhow, it does not work on port 5354, too | 16:33 |
mugsie | sorry "dig @mdns -p 5453 zone SOA" | 16:33 |
mugsie | 5453 i think is the right one | 16:34 |
mugsie | sorry, it is 5354 | 16:35 |
mugsie | OK, I would check the mdns logs then | 16:35 |
carthaca_ | it is telling ZoneNotFound | 16:37 |
carthaca_ | I cross-checked it earlier with dig AXFR, where I got 'ZoneNotFound while handling axfr request' for the zone that is in status pending | 16:39 |
*** cleong has quit IRC | 16:40 | |
carthaca_ | but it worked for another one that lives on the bind backend | 16:40 |
mugsie | and your using the tsig key? | 16:41 |
carthaca_ | yes that as well | 16:41 |
carthaca_ | dig -y keyname:secret ..etc | 16:41 |
mugsie | humm ... | 16:42 |
carthaca_ | makes no difference | 16:42 |
mugsie | brb | 16:43 |
carthaca_ | asking for SOA gives a similar log entry: "NotFound, refusing. Question was domain. IN SOA" | 16:44 |
timsim | Do you have different pools? | 16:52 |
timsim | Also, what version of designate? | 16:52 |
carthaca_ | yes, two | 16:52 |
carthaca_ | newton | 16:53 |
carthaca_ | fwiw, we tried it both with poolmanager on mitaka, and with worker on newton | 16:53 |
timsim | But the main issue seems to be mdns notfounding your zone right? | 16:53 |
carthaca_ | yes, it is not serving the zone that is still in 'pending' | 16:54 |
timsim | Is that tsig key scoped to the right pool? | 16:55 |
timsim | or zone? | 16:55 |
leitan | mugsie: thanks ill take a look, and yes the ptr for that in-arpa zone will be delegated to the powerdns servers that designate autoprovisinos | 16:57 |
carthaca_ | timsim: how I should best check that? | 16:59 |
*** _ducttape_ has quit IRC | 16:59 | |
mugsie | tsig keys are not in the client yet, are they? | 16:59 |
*** ducttape_ has joined #openstack-dns | 16:59 | |
timsim | I don't think so | 17:00 |
carthaca_ | in db it has scope POOL and the correct resource_id of the akamai pool | 17:00 |
mugsie | EmilienM: found the issue for #1653839 | 17:00 |
mugsie | https://github.com/openstack/designate/blob/master/designate/service.py#L130 | 17:00 |
EmilienM | nice :) | 17:00 |
timsim | carthaca_: The resource_id matches the id of the pool in the db? | 17:00 |
carthaca_ | oh wait.. I was too quick... it doesn't match the pool id | 17:01 |
*** _ducttape_ has joined #openstack-dns | 17:01 | |
timsim | BOOM | 17:01 |
timsim | That's probably it | 17:01 |
carthaca_ | it matches the wrong pool | 17:01 |
mugsie | that will cause it | 17:01 |
carthaca_ | okay, time for some database fumbling :slightly_smiling_face: | 17:02 |
timsim | You can use the API too | 17:02 |
carthaca_ | you are my heroes if that's it | 17:03 |
mugsie | carthaca_: all timsim's doing :) | 17:03 |
timsim | Lucky guess, I was totally out after that. | 17:03 |
carthaca_ | ah tsigkey patch, then I will go that way | 17:03 |
*** ducttape_ has quit IRC | 17:04 | |
carthaca_ | btw: to properly introduce myself: if you remember we met in Barcelona. I was the outsider in your working session on thursday :slightly_smiling_face: | 17:05 |
mugsie | ah, welcome to the channel! | 17:06 |
mugsie | summits help putting faces to IRC names :) | 17:06 |
timsim | o/ | 17:07 |
mugsie | EmilienM: can you try setting "host" and "port" options instead of "listen" ? | 17:10 |
EmilienM | mugsie: sure thing | 17:10 |
EmilienM | mugsie: done, i'll let you know results | 17:12 |
mugsie | EmilienM: thanks | 17:13 |
carthaca_ | It's not working yet, but I least I got another error, I can work with tomorrow, thanks :slightly_smiling_face: | 17:29 |
*** ftpd has joined #openstack-dns | 17:39 | |
ftpd | Hi guys. I'm creating heat stack for designate as a service. After creating I'm trying to use designate cli client or curl on api instance and still have: | 17:40 |
ftpd | 2017-01-17 18:38:56.467 11772 INFO keystonemiddleware.auth_token [-] Rejecting request | 17:41 |
ftpd | I have auth_url (and identity_uri and several other things) pointed to my openstack controllers, but as I can see all the traffic stays on the machine. | 17:42 |
ftpd | Nothing in keystone logs, nothing in tcpdumump (just connections from my floating ip to the 'basic' one0. | 17:42 |
ftpd | Ideas? | 17:42 |
mugsie | ftpd: what does your designate.conf file look like? | 17:45 |
ftpd | What section do you like do see? | 17:46 |
ftpd | http://pastebin.com/5w4vrrd4 | 17:46 |
ftpd | it's the authotoken section | 17:46 |
ftpd | I've changed 35357 to 5000, it's my working public endpoint address from keystone (verified by openstack endpoint show on controller). | 18:04 |
ftpd | Still the same error message. | 18:04 |
mugsie | ftpd: seems to be coming from https://github.com/openstack/keystonemiddleware/blob/2092d5783607223c7cbdfed690997e9c9f831b6f/keystonemiddleware/auth_token/__init__.py#L642 | 18:07 |
mugsie | try removing the "/v2.0" | 18:08 |
mugsie | you may also need the "domain" settings | 18:09 |
ftpd | Do I need both, auth_url and auth_uri? | 18:13 |
mugsie | the keystoneauthmiddleware example just uses auth_url | 18:14 |
ftpd | Seems so. auth_url is needed (MissingRequiredOptions: Auth plugin requires parameters which were not given: auth_url) and auth_uri recommended (Configuring auth_uri to point to the public identity endpoint is required; clients may not be able to authenticate against an admin endpoint). | 18:14 |
ftpd | Nevermind, I have both. | 18:15 |
ftpd | But still the same 401 | 18:15 |
ftpd | 19:09:17 mugsie| you may also need the "domain" settings | 18:15 |
mugsie | project_domain and user_domain | 18:16 |
ftpd | like project_domain and user_domain_id? | 18:16 |
ftpd | Ok. | 18:16 |
mugsie | 90% of the time they are just "default" | 18:16 |
EmilienM | mugsie: https://review.openstack.org/#/c/403967/ | 18:17 |
EmilienM | mugsie: it sounds like host/port do not exist anymore in puppet-designate, because they are deprecated in designate | 18:17 |
mugsie | api_port + api_host are gone | 18:18 |
mugsie | host + port in the [service:api] shouldnt be | 18:18 |
mugsie | but let me check | 18:18 |
mugsie | ah | 18:19 |
mugsie | its not depricated, as we did a weird thing in the API | 18:19 |
mugsie | damn | 18:19 |
mugsie | OK, need a code change in our side then | 18:19 |
ftpd | Nothing new after project_domain and user_domain. | 18:20 |
mugsie | :/ | 18:21 |
mugsie | can you curl that endpoint from the designate VM ? | 18:21 |
ftpd | http://pastebin.com/gs3bAJ4U | 18:24 |
EmilienM | mugsie: do I need to do something in puppet-designate? | 18:24 |
mugsie | EmilienM: nope, its on us | 18:24 |
EmilienM | ok, let me know when I can test something etc | 18:25 |
EmilienM | thanks! | 18:25 |
mugsie | ack | 18:25 |
EmilienM | and thanks for helping, it's appreciated :) | 18:25 |
ftpd | Ok, mugsie, I have to go home for today. Don't hesitate to hilight me here if you have more ideas to test, will do it tomorrow morning | 18:25 |
EmilienM | mwhahaha: ^ fyi | 18:25 |
leitan | guys, using COMPRESS_ENABLED = True and COMPRESS_OFFLINE = True the designatedashboard newton version has a lot of JS errors on the CREATE ZONE form, without using compression it works just fines, it seems that the JS used by the designate dashboard are getting compressed before other needed classes | 18:53 |
*** ducttape_ has joined #openstack-dns | 21:01 | |
*** _ducttape_ has quit IRC | 21:04 | |
*** ducttape_ has quit IRC | 21:17 | |
*** ducttape_ has joined #openstack-dns | 21:17 | |
*** leitan has quit IRC | 21:52 | |
*** catintheroof has quit IRC | 22:20 | |
*** thiagolib has quit IRC | 22:28 | |
*** tdink has quit IRC | 23:00 | |
*** ducttape_ has quit IRC | 23:07 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!