Monday, 2017-02-06

*** EricGonczer_ has joined #openstack-dns00:11
*** EricGonczer_ has quit IRC00:12
*** cuongnv has joined #openstack-dns00:46
*** hoangcx has joined #openstack-dns00:49
*** hoangcx_ has joined #openstack-dns02:11
*** hoangcx has quit IRC02:14
*** hoangcx has joined #openstack-dns02:16
*** hoangcx_ has quit IRC02:18
*** hoangcx_ has joined #openstack-dns02:43
*** hoangcx has quit IRC02:45
*** mikal has quit IRC03:29
*** mikal has joined #openstack-dns03:34
*** AlexeyAbashkin has joined #openstack-dns06:06
*** cvstealth has quit IRC06:17
*** cvstealth has joined #openstack-dns06:18
*** AlexeyAbashkin has quit IRC06:21
*** AlexeyAbashkin has joined #openstack-dns07:45
openstackgerritRui Chen proposed openstack/python-designateclient master: Set client module __version__  https://review.openstack.org/42954507:48
*** pcaruana has joined #openstack-dns07:55
*** pcaruana has quit IRC08:07
*** pcaruana has joined #openstack-dns08:07
*** databus23_ has joined #openstack-dns08:39
*** ct_ has joined #openstack-dns08:41
*** AlexeyAbashkin has quit IRC09:57
*** cuongnv has quit IRC10:11
*** slevchenko_ has quit IRC10:20
*** hoangcx_ has quit IRC10:30
*** ct_ has quit IRC10:49
*** EricGonczer_ has joined #openstack-dns12:20
TahvokIs there any mitaka specific guide for ubuntu I should follow? Or I should use the developer one? http://docs.openstack.org/developer/designate/12:35
*** EricGonczer_ has quit IRC12:46
*** leitan has joined #openstack-dns13:00
*** catintheroof has joined #openstack-dns13:03
*** EricGonczer_ has joined #openstack-dns13:10
leitanHi mugsie , good morning, any news about this bug https://bugs.launchpad.net/ubuntu/+source/designate-dashboard/+bug/1659620 ?13:12
openstackLaunchpad bug 1659620 in Designate Dashboard "Panels get broken with COMPRESS_OFFLINE = True" [Critical,Triaged]13:12
mugsieleitan: I think it is the ubuntu packaging of the horion dashboard13:15
mugsieI could not replicate it in devstack13:16
leitanmugsie: i see, so installing the dashboard from source should address this ?13:17
mugsieI think so13:19
mugsie(not the plugin, the actual horizon dashboard13:19
leitanyes, i mean the actual horizon13:20
leitanill try this13:21
*** EricGonczer_ has quit IRC13:26
*** EricGonczer_ has joined #openstack-dns13:37
*** EricGonczer_ has quit IRC13:38
*** chlong has joined #openstack-dns14:19
*** cleong has joined #openstack-dns14:28
*** tdink has joined #openstack-dns14:54
*** EricGonczer_ has joined #openstack-dns14:58
*** mlavalle has joined #openstack-dns15:09
ftpdHi again. I'm creating new zone via 'openstack zone create', after a bit of waiting got status 'ERROR'. Where to search logs describing the error?15:17
*** tdink has quit IRC15:17
mugsieftpd: pool manager is the best bet15:26
mugsiethen minidns15:26
ftpdFound it already. Stderr: u'rndc: /etc/rndc.conf does not exist\n'.15:28
ftpdDon't know what to put into it.15:28
ftpdI have rndc.key on central service VM15:28
mugsiethat needs to be on the vm where pool manager is15:28
ftpdOk.15:28
ftpdIs there any example available?15:29
mugsiehttp://docs.openstack.org/developer/designate/backends/bind9.html15:29
ftpdI have it open, but no .conf example, just for .key.15:30
mugsieif the key is there, it shouldnt need it15:31
mugsieafaik15:31
ftpdOn pool manager vm i have /etc/designate/rndc.key15:31
ftpdonly15:31
ftpdshould I copy it to /etc/rndc.conf?15:31
mugsieno, it is separate15:32
timsimrndc.conf is pretty simple, I think this will work https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/3/html/Reference_Guide/s1-bind-rndc.html15:32
*** akholkin_ has joined #openstack-dns15:32
* mugsie is getting ready to give a talk, so will hand over to timsim 15:32
timsimTirefire it up!15:32
mugsie:)15:33
mugsiealso got the burning container ship in there15:33
ftpdOk, got it.15:34
ftpdSo: I have to set /etc/rndc.conf with my key and options {} on pool-manager VM and _also_ on bind9 backend host, right?15:34
ftpd2017-02-06 16:34:50.994 10038 ERROR designate.pool_manager.service Stderr: u'rndc: connection to remote host closed\nThis may indicate that\n* the remote server is using an older version of the command protocol,\n* this host is not authorized to connect,\n* the clocks are not synchronized, or\n* the key is invalid.\n'15:35
ftpd2017-02-06 16:34:50.994 10038 ERROR designate.pool_manager.service15:35
ftpdSorry for long paste.15:35
timsimhttp://tecadmin.net/configure-rndc-for-bind9/# This should help15:36
timsimYeah you need to configure the remote bind instance to use the rndc key15:36
timsimthe same key15:36
timsimOf if this is just dev, you can not use them at all15:37
ftpdhttp://pastebin.com/B65EGgEa15:39
ftpdhere is my setup15:40
ftpdrndc status on bind9 host is ok15:41
ftpdnetwork traffic to 10.2.22.220 953 is allowed (tcp and utp)15:42
ftpds/utp/udp/15:42
ftpdhttp://pastebin.com/itsZxveH - and full error from pool-manager.log15:43
*** tdink has joined #openstack-dns15:44
ftpdIn bind9 logs: Feb 06 16:45:36 bstalewski-fakebind.novalocal named[10125]: invalid command from 10.2.22.135#59026: bad auth15:45
ftpdSo it seems like key was invalid.15:46
ftpdrndc version is the same15:47
timsimit seems like your rndc key paths are mixed? /etc/rndc.key /etc/des/rndc.key15:47
ftpdNope, my mistek when creating paste. Couldn't edit it after, sorry.15:48
ftpdI have /etc/rndc on all hosts15:48
ftpdI don't have any rndc.conf on bind host15:49
ftpdCreated it there, nothing changed.15:50
ftpdLol.15:53
ftpdThe key was different. I don't know, how.15:53
ftpdAnyway, now I have the same key everywhere15:53
ftpd2017-02-06 16:54:05.756 10038 ERROR designate.pool_manager.service Stderr: u"rndc: 'addzone' failed: permission denied\n"15:54
ftpd;-)15:54
ftpdIt's almost working.15:54
timsimYou can check syslog for that, but it's usually apparmor15:59
timsimSometimes you have to `touch /etc/apparmor.d/disable/usr.sbin.named && service apparmor reload`16:00
ftpdselinux, they are RHEL's16:00
ftpdAnd yes, it's enabled on bind host. Let me reboot it.16:00
ftpdhttp://pastebin.com/EjTXBjAv - now I'm really confused ;-)16:06
ftpdGot named working, rndc status is ok, everything is ok, selinux is disabled... still permission denied on addzone.16:09
ftpdbut I have a clue16:09
ftpd    "create_zone": "rule:admin_or_owner", in policy.json16:09
ftpdAnd I'm authorizing as 'member' in tenant.16:09
timsimDesignate policy doesn't go that far.16:13
timsimYou'd have an earlier failure if policy was tripping you up.16:13
timsimAt the API16:13
timsimI think on ubuntu it's actually the "bind" user, not the "named" user. idk about RHEL16:13
ftpdit's 'named'.16:13
ftpdnamed     2120  0.0  0.6 160408 12828 ?        Ssl  17:07   0:00 /usr/sbin/named -u named16:15
ftpdBtw. if I'll set up zone in my bind9 server, will designate see it?16:15
ftpdI mean creating it manually.16:16
timsimNope16:16
ftpdOk, so the zone has to be created from designate.16:16
timsimCorrect16:16
timsimbind     22888  0.0  0.5 432164 22812 ?        Ssl  Jan25   0:01 /usr/sbin/named -f -u bind16:16
timsimweird16:16
ftpdYou have ubuntu, I have rhel, it's not weird ;-)16:16
timsimJust make it slightly different, not confusing at all16:17
ftpdGot named -g running (I'm an idiot, should drink yesterday - when running manually I had to use -u also, sorry).16:20
ftpdBut still permission denied on addzone.16:20
ftpd06-Feb-2017 17:20:51.508 received control channel command 'addzone examples.com  { type slave; masters { 10.2.22.220 port 53;}; file "slave.examples.com.db4b645c-8e0d-48f2-ae0f-e26132810aa7"; };16:20
ftpdIn bind's log.16:21
ftpdBut nothing happens.16:21
ftpdI don't have to have named configured on pool manager VM, correct? Just need /sbin/rndc.16:24
timsimCorrect16:29
ftpdHmmm.16:29
ftpdhttp://eavesdrop.openstack.org/irclogs/%23openstack-dns/%23openstack-dns.2015-03-27.log16:29
ftpd2015-03-27T00:24:18  <kfox1111> heh. chmod 770 /var/named16:29
ftpd2015-03-27T00:24:20  <kfox1111> problem solved. :/16:29
ftpdAaaaand....16:30
ftpd2017-02-06 17:29:20.473 10038 INFO designate.mdns.rpcapi [req-3c052ed8-0fab-4c76-8702-be49f220b0e9 - - - - -] notify_zone_changed: Calling mdns for zone 'examples.com.', serial '1486397563' to nameserver '127.0.0.1:53'16:30
ftpd2017-02-06 17:29:20.478 10038 INFO designate.mdns.rpcapi [req-3c052ed8-0fab-4c76-8702-be49f220b0e9 - - - - -] poll_for_serial_number: Calling mdns for zone 'examples.com.', serial '1486397563' on nameserver '10.2.22.220:53'16:30
ftpd;-)16:30
ftpdBut who openstack zone list still shows the zone as 'error'?16:30
timsimDesignate periodically tries to fix those error'd zones, it won't change to active until it tries to create it again, sees that worked, and does a successful DNS query for it.16:31
timsimYou could try creating another zone, and that should resolve itself a bit quicker if all is well16:31
ftpd06-Feb-2017 17:29:21.506 zone examples.com/IN: refresh: unexpected rcode (SERVFAIL) from master 10.2.22.220#53 (source 0.0.0.0#0)16:31
ftpdSomething on named host16:32
timsimYeah in your rndc addzone "masters { 10.2.22.220 port 53;}" That needs to be port 5354 (the port mdns runs on)16:33
ftpdSo I have mistake in my pools.yaml.16:33
timsimYeah, probably.16:34
timsim"masters" i believe16:34
ftpdhttp://pastebin.com/W7qL8JkA - it's my pools.json (other guy wrote it, I've got this to get running after him).16:37
ftpd10.2.22.220 is my bind host, 172.16.2.40 is minidns instance (with pool manager on it).16:37
ftpdBind doesn't listen on 5354.16:38
*** pcaruana has quit IRC16:38
ftpdSo which host should be in masters, and which one in options?16:38
timsimThat looks right to me16:39
timsimIs that rndc command what designate ran? Or something you ran ad-hoc?16:39
timsimTry creating another zone, and see what happens16:40
ftpd2017-02-06 17:39:05.412 10038 INFO designate.backend.impl_bind9 [req-2d154e28-e3c1-4285-8263-f3eb66bce447 - - - - -] RNDC call failure: Unexpected error while running command.16:40
ftpdCommand: sudo designate-rootwrap /etc/designate/rootwrap.conf rndc -s 10.2.22.220 -p 953 -c /etc/rndc.conf -k /etc/rndc.key addzone examples.com  { type slave; masters { 10.2.22.220 port 53;}; file "slave.examples.com.db4b645c-8e0d-48f2-ae0f-e26132810aa7"; };16:40
ftpdExit code: 116:40
timsimUmm. Have you run `designate-manage pool update` recently? and bounced the pool manager?16:42
ftpdI've deleted zone (by openstack zone delete <id> from my api VM) and now have this in bind logs:16:42
ftpd06-Feb-2017 17:40:57.604 received control channel command 'delzone examples.com '16:42
ftpd06-Feb-2017 17:40:57.604 zone examples.com removed via delzone16:43
ftpd06-Feb-2017 17:41:02.625 client 10.2.27.198#47377 (examples.com): query (cache) 'examples.com/SOA/IN' denied16:43
ftpdLast line occurs every 15 seconds16:43
ftpdopenstack zone list shows nothing16:43
ftpdWhy is designate trying to delete it?16:43
ftpdOk, it stopped. Maybe it was ok.16:44
ftpdLet's go with new one16:45
ftpdopenstack zone create --email admin@example.com ewjrwer.net.16:45
ftpdhttp://pastebin.com/4z6CFkg3 - same error16:46
timsimHave you run `designate-manage pool update` recently? and bounced the pool manager?16:46
ftpdNot today.16:47
ftpdLet me do it16:47
ftpdOk, did pool update (http://pastebin.com/eC1kvecg - my designate-manage pool show_config) and bounced designate-central and designate-pool-manager. Let's try to create new zone.16:49
ftpdAlmost there: http://pastebin.com/p2si9Bx616:51
timsimProgress16:51
ftpdDo I have allow notify...16:51
timsimYeah it looks like it16:51
ftpdStill 'PENDING'. I'll do a quick smoke break and see.16:52
*** cliles has quit IRC16:55
*** ducttape_ has quit IRC16:55
*** cliles has joined #openstack-dns16:56
ftpdStill error, but now (on bind):16:57
ftpd06-Feb-2017 17:56:14.901 zone ewjrwer.net/IN: notify from 10.2.27.198#54602: refresh in progress, refresh check queued16:57
ftpd06-Feb-2017 17:57:23.057 zone ewjrwer.net/IN: refresh: retry limit for master 172.16.2.40#5354 exceeded (source 0.0.0.0#0)16:57
timsimTry doing (from the bind box) a `dig @mdnsip -p 5354 zonename -t AXFR`16:58
ftpdI don't think I have traffic allowed to @mdnsip.17:01
*** nkinder has joined #openstack-dns17:01
ftpdI have, but from floating network, and I suppose it queries from local address.17:02
timsimWell you'll need it, BIND has to do zone transfers from it's master17:02
ftpdIs there any way to force bind to do this transfer from specific IP?17:03
ftpdNope, VM isn't concious it's floating IP :/17:03
ftpdOk, it's the problem to solve for tomorrow.17:05
timsimI think you can set a "transfer-source" ip. But sounds like that won't work for you17:05
ftpdBut:17:06
ftpd06-Feb-2017 18:05:45.380 zone ewjrwer.net/IN: notify from 10.2.27.198#41643: refresh in progress, refresh check queued17:06
ftpd10.2.27.198 is floting ip of minidns instance17:06
ftpdAnd later:17:06
ftpd06-Feb-2017 18:05:57.703 zone ewjrwer.net/IN: refresh: failure trying master 172.16.2.40#5354 (source 0.0.0.0#0): operation canceled17:06
ftpd172.16.2.40 is local IP.17:06
ftpdHmm, maybe I should change it to floating in pools.yaml?17:07
ftpd06-Feb-2017 18:09:36.021 client 10.2.27.198#56671: received notify for zone 'examplne.net'17:11
ftpdHere we go.17:11
ftpdAlmost:17:12
ftpd06-Feb-2017 18:11:38.356 transfer of 'examplne.net/IN' from 10.2.27.198#5354: failed to connect: timed out17:12
ftpd06-Feb-2017 18:11:38.356 transfer of 'examplne.net/IN' from 10.2.27.198#5354: Transfer completed: 0 messages, 0 records, 0 bytes, 127.321 secs (0 bytes/sec)17:12
ftpd06-Feb-2017 18:11:38.875 zone examplne.net/IN: refresh: skipping zone transfer as master 10.2.27.198#5354 (source 0.0.0.0#0) is unreachable (cached)17:12
ftpdSo...17:12
ftpdIt's clearly network's fault.17:13
ftpdOk, but I know where to look at.17:16
ftpdThanks timsim, I hope tomorrow it will work17:16
ftpdEnough for today, I'm an hour longer at the office ;-)17:16
timsimNo17:16
ftpd?17:16
timsim*np17:17
timsimLol17:17
ftpd;-)17:17
timsimYOU WILL STAY UNTIL IT WORKS17:17
ftpdHaha. Lol, nope ;-)17:17
ftpdNot today.17:18
ftpdIt's weird, I have security group and firewall rule which allows traffic to 535417:19
ftpdIt's TCP, right?17:20
ftpdafair DNS uses udp for queries and tcp for transfers17:20
*** ducttape_ has joined #openstack-dns17:20
ftpdHmm. But on my poll manager instance I don't have 5354 open.17:22
ftpdAnyway, I have to go. Thanks again and see you tomorrow :P17:26
*** akholkin_ has quit IRC17:31
*** pcaruana has joined #openstack-dns18:36
*** chlong has quit IRC18:52
*** haplo37 has quit IRC19:08
*** chlong has joined #openstack-dns19:09
*** pcaruana has quit IRC19:11
*** haplo37 has joined #openstack-dns19:18
*** ducttape_ has quit IRC19:25
*** ducttape_ has joined #openstack-dns19:27
*** ducttape_ has quit IRC19:36
*** ducttape_ has joined #openstack-dns19:37
*** kberger has joined #openstack-dns19:37
*** kberger has quit IRC19:37
*** kberger has joined #openstack-dns19:38
*** ducttape_ has quit IRC20:05
*** chlong has quit IRC20:49
*** ducttape_ has joined #openstack-dns21:00
*** ducttape_ has quit IRC21:15
*** cleong has quit IRC21:21
*** ducttape_ has joined #openstack-dns22:00
*** haplo37 has quit IRC22:01
*** haplo37_ has quit IRC22:01
*** haplo37 has joined #openstack-dns22:09
*** ducttape_ has quit IRC22:11
*** haplo37_ has joined #openstack-dns22:12
*** ducttape_ has joined #openstack-dns22:13
*** ducttape_ has quit IRC22:25
*** tdink has quit IRC22:42
*** EricGonczer_ has quit IRC22:45
*** ducttape_ has joined #openstack-dns22:53
*** leitan has quit IRC23:01
*** tdink has joined #openstack-dns23:05
*** fyxim_ has joined #openstack-dns23:27
*** boris-42_ has joined #openstack-dns23:27
*** ratoder2 has joined #openstack-dns23:29
*** iggy_ has joined #openstack-dns23:29
*** ratoder2 is now known as ratoder323:29
*** harmw_ has joined #openstack-dns23:29
*** ratoder3 is now known as ratoder223:31
*** simonmcc_ has joined #openstack-dns23:32
*** v12aml_ has joined #openstack-dns23:32
*** simonmcc has quit IRC23:34
*** iggy has quit IRC23:34
*** ratoder has quit IRC23:34
*** v12aml has quit IRC23:34
*** harmw has quit IRC23:34
*** fyxim has quit IRC23:34
*** tg90nor has quit IRC23:34
*** boris-42 has quit IRC23:34
*** v12aml_ is now known as v12aml23:34
*** simonmcc_ is now known as simonmcc23:35
*** fyxim_ is now known as fyxim23:36
*** boris-42_ is now known as boris-4223:37
*** ducttape_ has quit IRC23:41
*** haplo37_ has quit IRC23:45
*** ratoder2 is now known as ratoder23:51
*** haplo37_ has joined #openstack-dns23:54
*** catintheroof has quit IRC23:54
*** EricGonczer_ has joined #openstack-dns23:59

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!