*** khushbu has joined #openstack-dns | 00:02 | |
*** khushbu has quit IRC | 00:07 | |
*** ianychoi has quit IRC | 00:10 | |
*** ianychoi has joined #openstack-dns | 00:11 | |
*** hoangcx has joined #openstack-dns | 00:32 | |
*** EricGonczer_ has joined #openstack-dns | 00:48 | |
*** EricGonc_ has joined #openstack-dns | 00:50 | |
*** EricGonczer_ has quit IRC | 00:52 | |
*** ducttape_ has joined #openstack-dns | 00:54 | |
*** cuongnv has joined #openstack-dns | 00:55 | |
*** ducttape_ has quit IRC | 00:56 | |
*** ducttape_ has joined #openstack-dns | 00:57 | |
*** zhurong has joined #openstack-dns | 01:05 | |
*** ducttape_ has quit IRC | 01:08 | |
*** EricGonc_ has quit IRC | 01:08 | |
*** EricGonczer_ has joined #openstack-dns | 01:11 | |
*** ducttape_ has joined #openstack-dns | 01:32 | |
*** yee379 has quit IRC | 01:33 | |
*** yee379 has joined #openstack-dns | 01:34 | |
*** EricGonczer_ has quit IRC | 01:38 | |
*** EricGonczer_ has joined #openstack-dns | 01:39 | |
*** ducttape_ has quit IRC | 01:47 | |
*** tdink has quit IRC | 01:53 | |
*** khushbu has joined #openstack-dns | 01:56 | |
*** khushbu has quit IRC | 02:01 | |
*** trugnvfet has joined #openstack-dns | 02:12 | |
*** ducttape_ has joined #openstack-dns | 02:16 | |
*** ducttape_ has quit IRC | 02:18 | |
*** khushbu has joined #openstack-dns | 02:27 | |
*** khushbu has quit IRC | 02:32 | |
*** khushbu has joined #openstack-dns | 02:37 | |
*** khushbu has quit IRC | 02:42 | |
*** ducttape_ has joined #openstack-dns | 03:00 | |
*** EricGonczer_ has quit IRC | 03:03 | |
*** sonuk has joined #openstack-dns | 03:07 | |
*** khushbu has joined #openstack-dns | 03:09 | |
*** khushbu has quit IRC | 03:13 | |
*** ducttape_ has quit IRC | 03:14 | |
*** khushbu has joined #openstack-dns | 04:03 | |
*** ducttape_ has joined #openstack-dns | 04:15 | |
*** ducttape_ has quit IRC | 04:20 | |
*** ducttape_ has joined #openstack-dns | 05:16 | |
*** ducttape_ has quit IRC | 05:21 | |
*** cuongnv has quit IRC | 05:28 | |
*** cuongnv has joined #openstack-dns | 05:32 | |
*** khushbu has quit IRC | 05:35 | |
*** khushbu has joined #openstack-dns | 05:36 | |
*** ducttape_ has joined #openstack-dns | 06:17 | |
*** ducttape_ has quit IRC | 06:22 | |
*** yee379 has quit IRC | 06:38 | |
*** yee379 has joined #openstack-dns | 06:39 | |
*** richm has quit IRC | 06:42 | |
*** cuongnv_ has joined #openstack-dns | 07:12 | |
*** cuongnv has quit IRC | 07:14 | |
*** ducttape_ has joined #openstack-dns | 07:18 | |
*** ducttape_ has quit IRC | 07:23 | |
*** yee379 has quit IRC | 07:31 | |
*** yee379 has joined #openstack-dns | 07:31 | |
*** cuongnv has joined #openstack-dns | 07:48 | |
*** pcaruana has joined #openstack-dns | 07:50 | |
*** cuongnv_ has quit IRC | 07:50 | |
*** ratoder2 has joined #openstack-dns | 08:31 | |
*** ratoder2 has quit IRC | 08:33 | |
*** ducttape_ has joined #openstack-dns | 09:19 | |
*** prazumovsky has joined #openstack-dns | 09:20 | |
prazumovsky | hi all! | 09:20 |
---|---|---|
prazumovsky | Could somebody help me? | 09:20 |
prazumovsky | I got error on bind9 "out of range", when try create zone | 09:20 |
prazumovsky | it happens when worker tries to send notification | 09:21 |
*** faizy has joined #openstack-dns | 09:22 | |
prazumovsky | full message is: invalid command from 10.233.102.143#53408: out of range | 09:24 |
prazumovsky | can you help me, designate community?) | 09:24 |
*** ducttape_ has quit IRC | 09:25 | |
prazumovsky | and also mdns get error: connection reset by peer | 09:50 |
prazumovsky | and also Socket close | 09:50 |
prazumovsky | *closed | 09:50 |
*** cuongnv has quit IRC | 10:12 | |
*** hoangcx has quit IRC | 10:16 | |
*** ducttape_ has joined #openstack-dns | 10:21 | |
*** ducttape_ has quit IRC | 10:26 | |
*** openstackgerrit has quit IRC | 10:33 | |
*** trugnvfet has quit IRC | 10:46 | |
*** richm has joined #openstack-dns | 11:12 | |
*** faizy has quit IRC | 12:12 | |
*** ftpd has joined #openstack-dns | 12:21 | |
ftpd | Hi again. | 12:21 |
ftpd | Is there a possibility to blacklist/whitelist addresses, that users can use in records? | 12:22 |
ftpd | I want my user to add dns records to floating IP's only, not for internal ones. | 12:22 |
ftpd | I know it sounds stupid ;-) | 12:23 |
*** catintheroof has joined #openstack-dns | 12:24 | |
*** khushbu has quit IRC | 12:25 | |
carthaca_ | Hi, have a look here for blacklists: https://docs.openstack.org/developer/designate/howtos/blacklists.html | 12:28 |
ftpd | It's about domain names. | 12:29 |
ftpd | And I want it for addresses. | 12:30 |
ftpd | I don't want to blacklist foo.mydomain.com. I want to blacklist 10.20.30.5 and allow 10.50.50.x only. | 12:30 |
kiall | ftpd: no, there's no method to blacklist the IPs used in e.g. A records | 12:34 |
ftpd | O, thanks. | 12:39 |
*** zhurong has quit IRC | 12:45 | |
ftpd | Hmm. And am I understading this correctly: when I make changes in Designate, it uses rndc (TCP 953) to talk to bind9 backend servers and later those servers make zone transfer (TCP 5354) back to the minidns instance, right? | 12:47 |
ftpd | I'm thinking about firewall rules to be prepared. | 12:48 |
*** sgr7 has joined #openstack-dns | 12:58 | |
*** chlong has joined #openstack-dns | 13:00 | |
*** faizy has joined #openstack-dns | 13:01 | |
*** faizy has quit IRC | 13:20 | |
*** Drankis has joined #openstack-dns | 13:21 | |
*** ducttape_ has joined #openstack-dns | 13:23 | |
*** khushbu has joined #openstack-dns | 13:27 | |
*** ducttape_ has quit IRC | 13:28 | |
*** EricGonczer_ has joined #openstack-dns | 13:33 | |
*** zhurong has joined #openstack-dns | 13:35 | |
*** cleong has joined #openstack-dns | 13:46 | |
*** ducttape_ has joined #openstack-dns | 13:49 | |
mugsie | ftpd: yes, that is correct | 14:03 |
ftpd | And what with infoblox? What network ports should be opened? | 14:04 |
*** prazumovsky has quit IRC | 14:11 | |
*** ducttape_ has quit IRC | 14:12 | |
*** zhurong has quit IRC | 14:16 | |
*** mlavalle has joined #openstack-dns | 14:17 | |
*** khushbu has quit IRC | 14:22 | |
*** EricGonc_ has joined #openstack-dns | 14:26 | |
*** EricGonczer_ has quit IRC | 14:27 | |
mugsie | ftpd: eh, let me look | 14:37 |
mugsie | I think just the API, and 53 | 14:38 |
ftpd | Ok, thanks! | 14:38 |
*** sonuk has quit IRC | 14:40 | |
*** ducttape_ has joined #openstack-dns | 14:55 | |
*** ducttape_ has quit IRC | 14:59 | |
*** tdink has joined #openstack-dns | 15:01 | |
*** pcaruana has quit IRC | 15:09 | |
*** ducttape_ has joined #openstack-dns | 15:22 | |
*** pcaruana has joined #openstack-dns | 15:23 | |
*** ducttape_ has quit IRC | 15:39 | |
*** ducttape_ has joined #openstack-dns | 15:40 | |
*** ducttape_ has quit IRC | 15:42 | |
*** ducttape_ has joined #openstack-dns | 15:42 | |
*** sgr7 has quit IRC | 15:52 | |
timsim | Hey mugsie do you want to respond to the "[openstack-dev] [cross-project][nova][cinder][designate][neutron] Common support-matrix.py" ML thread with your thoughts about that? | 16:06 |
timsim | herp. scrolls up in email and sees you did | 16:07 |
*** ducttape_ has quit IRC | 16:07 | |
*** ducttape_ has joined #openstack-dns | 16:09 | |
*** openstackgerrit has joined #openstack-dns | 16:10 | |
*** ChanServ sets mode: +v openstackgerrit | 16:10 | |
openstackgerrit | Graham Hayes proposed openstack/designate master: Bump hacking to new required version https://review.openstack.org/442596 | 16:10 |
mugsie | timsim: I think ^ fixes it | 16:11 |
mugsie | *think* | 16:11 |
mugsie | it may cause other, bigger issues | 16:11 |
* mugsie curses at f**king eventlet | 16:11 | |
timsim | Yeah that was my initial reaction | 16:11 |
timsim | bleh | 16:12 |
*** pcaruana has quit IRC | 16:26 | |
*** n3q has joined #openstack-dns | 16:29 | |
n3q | hello | 16:29 |
mugsie | o/ | 16:30 |
n3q | anybody help? | 16:30 |
n3q | how to restart whole service of dev-designate? | 16:30 |
n3q | how to restart whole services of dev-designate? | 16:30 |
mugsie | n3q: how are you running it? | 16:30 |
n3q | I just use it in the first time | 16:31 |
n3q | after reboot laptop then It's not auto running. | 16:31 |
mugsie | how did you start it? | 16:31 |
mugsie | or install it? | 16:31 |
*** Drankis has quit IRC | 16:32 | |
n3q | I am follow instruction document via openstack's website to setup and configure | 16:33 |
n3q | https://docs.openstack.org/developer/designate/devstack.html | 16:33 |
mugsie | n3q: ah, you need to run ./stack.sh again | 16:33 |
n3q | this is document which I used to setup. | 16:33 |
n3q | what? | 16:34 |
n3q | It will re-install everything | 16:34 |
mugsie | yes | 16:34 |
mugsie | devstack cannot be shut down | 16:34 |
n3q | for each time, It take me long time | 16:34 |
n3q | Do you have any solutions? | 16:35 |
mugsie | unfortuntaly, devstack is not designed to be shutdown, and restarted | 16:35 |
mugsie | it is just for development | 16:35 |
mugsie | so the only solution is ./stack.sh | 16:35 |
n3q | I remember that It can restart via ./rejoin.sh --- but not found at the moment | 16:36 |
n3q | perhaps this script isn't mature then they must be leave out of devstack | 16:37 |
mugsie | that was removed by the devstack team | 16:37 |
n3q | yep. thanks so much! | 16:37 |
mugsie | and rejoin did not work most of the time | 16:37 |
mugsie | no problem | 16:37 |
n3q | I will drink coffee for each time to ./stack.sh command. ^.^ | 16:38 |
mugsie | :D | 16:39 |
* mugsie decides to have a coffee :) | 16:39 | |
n3q | yep. | 16:39 |
n3q | with ubuntu 16.04 the devstack will work stable? | 16:40 |
n3q | I use ubuntu 16.10 at my home the devstack is working fine. | 16:40 |
timsim | `Devstack attempts to support Ubuntu 14.04/16.04` https://docs.openstack.org/developer/devstack/# | 16:41 |
n3q | But with ubuntu 16.04 the a lot issues during setup and configure designate. | 16:41 |
timsim | It seems like every time I use devstack I see a lot of issues, regardless :P | 16:42 |
n3q | ubuntu 16.04 is smoothest --- perhaps, due to myself. ^^ | 16:43 |
n3q | thank you Tim. have a nice day. | 16:45 |
*** n3q has left #openstack-dns | 16:48 | |
*** n3q has joined #openstack-dns | 17:03 | |
*** n3q has quit IRC | 17:04 | |
timsim | mugsie: welp https://review.openstack.org/#/c/442596/1 | 17:28 |
timsim | At least the functional tests passed | 17:29 |
timsim | Looks like central isn't responding to anything over rpc, in the unit tests | 17:33 |
*** en_austin has joined #openstack-dns | 17:33 | |
en_austin | hi all! Trying to install Designate Ocata from scratch, following this manual https://docs.openstack.org/project-install-guide/dns/ocata/install-ubuntu.html ... but i'm receiving an "timed out waiting for RPC response" error in logs of all daemons (api, central, etc). Is it ok or I have misconfigured something? | 17:35 |
en_austin | 2017-03-07 20:34:28.239 9262 DEBUG oslo.messaging._drivers.impl_rabbit [-] Timed out waiting for RPC response: Timeout while waiting on RPC response - topic: "<unknown>", RPC method: "<unknown>" info: "<unknown>" _raise_timeout /usr/lib/python2.7/site-packages/oslo_messaging/_drivers/impl_rabbit.py:1054 | 17:35 |
timsim | en_austin: Is rabbitmq running? | 17:38 |
en_austin | sure, some lines above it reports "connected to AMQP ...." | 17:38 |
timsim | Can you make a paste.openstack.org with the actual errors? | 17:39 |
en_austin | http://paste.openstack.org/show/601805/ , for example. | 17:40 |
timsim | I mean that doesn't seem good, do things work regardless? | 17:40 |
en_austin | Seems nope, it raises NoServersConfigured even after designate-manage pool update command. | 17:41 |
en_austin | Last time I've installed Designate from scratch on Liberty release... and, it seems, _some_ things have changed. :D | 17:41 |
timsim | What is the response to the pool update command? | 17:42 |
en_austin | http://paste.openstack.org/show/601807/ | 17:46 |
en_austin | and POST to v2/zones still responds with HTTP 500 :( | 17:47 |
*** abalutoiu has joined #openstack-dns | 17:55 | |
*** ducttape_ has quit IRC | 17:59 | |
*** ducttape_ has joined #openstack-dns | 18:04 | |
*** khushbu has joined #openstack-dns | 18:18 | |
*** khushbu has quit IRC | 18:18 | |
*** khushbu has joined #openstack-dns | 18:29 | |
*** khushbu has quit IRC | 18:33 | |
*** khushbu has joined #openstack-dns | 18:33 | |
*** khushbu has quit IRC | 18:34 | |
en_austin | And there is a "connection_closed_abruptly" warning into the rabbitmq logs. Still cannot understand what I am doing wrong. | 18:37 |
*** abalutoiu has quit IRC | 18:41 | |
*** khushbu has joined #openstack-dns | 18:44 | |
*** khushbu has quit IRC | 18:49 | |
openstackgerrit | Graham Hayes proposed openstack/designate master: Bump hacking to new required version https://review.openstack.org/442596 | 18:55 |
mugsie | en_austin: is there any logs from the central side? | 18:55 |
mugsie | it seems to be theo one having issues | 18:55 |
*** ducttape_ has quit IRC | 18:56 | |
en_austin | it was not even running, but i've started it now and it logs the same "timed out waiting for rpc response". | 19:00 |
en_austin | I've tried to modify oslo_messaging/_drivers/impl_rabbit.py in order to let it throw an actual exception caused, and here's what I've got: | 19:01 |
en_austin | http://paste.openstack.org/show/601820/ | 19:02 |
en_austin | Nevertheless, telnet 127.0.0.1 5672 works well. | 19:02 |
mugsie | en_austin: ssl vs non ssl? | 19:04 |
en_austin | non-ssl in confi | 19:04 |
en_austin | Well, i've restarted it with "keystone" auth_strategy and it stopped to throw these errors (but I don't know, will it work at all, since I do not installed Keystone in my designate installation - it works in private network and do not require an authentication) | 19:07 |
mugsie | en_austin: whta? | 19:07 |
en_austin | [service:api] has a "auth_strategy" key with "keystone" as default value. I've changed it to "noauth" and starting to receive such strange errors. | 19:09 |
en_austin | I've returned it back to "keystone" and received HTTP 401, but w/o AMQ errors. | 19:09 |
*** ducttape_ has joined #openstack-dns | 19:13 | |
*** _ducttape_ has joined #openstack-dns | 19:14 | |
*** en_austin has quit IRC | 19:15 | |
*** shewless has joined #openstack-dns | 19:16 | |
shewless | Hi. I have designate installed and I've had a lot of success with it thanks to all of your help in the past. | 19:16 |
shewless | I have another query | 19:16 |
shewless | in my pool.yml file there is a targets: masters: section | 19:17 |
shewless | I have added my degnate-mdns server as a master | 19:17 |
shewless | but the trouble is that I'm sending updates to a "master" bind server | 19:17 |
shewless | and in turn that server is setup to push updates to 2 slaves | 19:18 |
*** ducttape_ has quit IRC | 19:18 | |
*** _ducttape_ has quit IRC | 19:18 | |
shewless | The problem is that, since the records I'm pushing to the master identify my designate server as the master (instead of identifying the bind server as the master) the slaves will not accept the update | 19:18 |
timsim | shewless: So having a tiered bind setup like that isn't strictly supported in Designate | 19:44 |
timsim | You can certainly do it, but you're going to need some glue somewhere that's outside of Designate, probably. | 19:45 |
shewless | timsim: can you tell me what the "--masters" option is for when I do "openstack zone create"? | 19:47 |
timsim | That's something related to secondary zones, completely different than this situation https://docs.openstack.org/developer/designate/howtos/secondary-zones.html | 19:47 |
shewless | timsim: ah okay thanks | 19:47 |
timsim | You could run the Designate agent on that master, and use the agent backend, and that will create your zones on the master as type master, and write zonefiles. | 19:48 |
timsim | But the you've got to figure a way to get them created/deleted on the slaves. | 19:48 |
shewless | timsim: so ideally we want our master bind server to handle the DNS zone / record propogation to slaves | 19:48 |
shewless | and it sort of does this now | 19:48 |
shewless | but since the "master" of the zone created by designate doesn't match the "master bind server" it's not authoritative and doesn't work | 19:49 |
timsim | Right. Well you could change the masters of those slave "targets" in pools.yaml. | 19:49 |
timsim | masters -> your master bind server | 19:49 |
shewless | timsim: I was thinkgin about that.. but wasn't sure because the comments in the pool file say it's my mdns server | 19:50 |
timsim | But, if they get created on the slave before the master the transfer will fail. | 19:50 |
shewless | wasn't sure if that would have adverse effect | 19:50 |
timsim | Well it _should_ be your mdns server, that's how Designate is designed. | 19:50 |
timsim | But there are situations where you might not want it to be. | 19:50 |
shewless | Interesting | 19:50 |
timsim | There's going to be occasional/constant propagation issues, I'd think. | 19:51 |
shewless | timsim: there isn't really a case where it would get created on the slave before the master | 19:51 |
shewless | that I can think of | 19:51 |
timsim | Well Designate has to create the zone right? | 19:51 |
shewless | timsim: yes designate will create the zone and update the "master bind server" | 19:52 |
shewless | the rest will just work I think? | 19:52 |
timsim | What creates the zone on the slave? | 19:52 |
timsim | Something has to | 19:52 |
shewless | the master bind server does | 19:53 |
timsim | I don't believe it does. | 19:53 |
shewless | it's already trying to but since the "master" is the mds server the slave is not allowing it | 19:53 |
timsim | Can I see your pools.yaml file? | 19:53 |
shewless | timsim: let me try to flip the master and see what happens. I think my sys admin guys have bind setup in a weird way | 19:54 |
shewless | timsim: yes I will share | 19:54 |
timsim | Bind doesn't automatically create/delete servers on a slave, in my experience. | 19:54 |
timsim | We've always had to have somethign do that. | 19:54 |
shewless | http://paste.ubuntu.com/24132542/ | 19:55 |
shewless | .0.13 is bind master | 19:55 |
shewless | .210.111 is designate | 19:56 |
mugsie | shewless: *maybe* adding the bind master to that list might work. but the slave will still try on occasion to talk to mini-dns | 19:57 |
timsim | I don't see how the zones will ever get created on the slave | 19:57 |
timsim | slave bind servers, I should clarify | 19:58 |
timsim | That yaml should get the thing created on the bind master as a "type slave" zone with mdns as the master. | 19:59 |
shewless | timsim: can I make the yaml create a zone with "type master" instead? | 20:00 |
mugsie | shewless: no | 20:00 |
mugsie | we transfer the records as a XFR | 20:00 |
mugsie | so, it has to be type slave, for the bind server to pull from designate | 20:00 |
mugsie | why do you have the extra layer? | 20:01 |
timsim | mugsie: looks like your ps2 is going to pass, except for this api-ref error http://logs.openstack.org/96/442596/2/check/gate-designate-api-ref/5bcb621/console.html#_2017-03-07_19_03_33_019348 | 20:01 |
shewless | timsim, mugsie: Okay. I tried changing the "master" in yaml to by my master bind server instead of the mdns server. But the zone created was still "type slave" zone with mdns as the master | 20:01 |
timsim | shewless: Yeah, it's always going to be. | 20:01 |
mugsie | it should have changed IP address | 20:02 |
shewless | it doesn't seem to have changed | 20:02 |
mugsie | did you restart pool manager / worker? | 20:02 |
mugsie | pool manager caches it afaik | 20:02 |
mugsie | timsim: damn it | 20:02 |
mugsie | will fix that noiw | 20:02 |
timsim | and run the pool update command | 20:02 |
mugsie | oh, ^^^^^ | 20:02 |
mugsie | that needs to be highlighted better | 20:03 |
timsim | run the pool update, then restart | 20:04 |
*** castlemilk has quit IRC | 20:05 | |
timsim | mugsie: What do we need to do to get designate-tempest-plugin docs on docs.openstack.org/ | 20:06 |
*** castlemilk has joined #openstack-dns | 20:06 | |
*** ducttape_ has joined #openstack-dns | 20:07 | |
mugsie | merge a patch that makes a docs change | 20:08 |
mugsie | I did path then jobs | 20:08 |
*** ducttape_ has quit IRC | 20:08 | |
mugsie | which is wrong | 20:08 |
*** ducttape_ has joined #openstack-dns | 20:08 | |
*** castlemilk has quit IRC | 20:11 | |
* timsim does that right quick | 20:14 | |
openstackgerrit | Tim Simmons proposed openstack/designate-tempest-plugin master: Fix doc typos https://review.openstack.org/442765 | 20:16 |
shewless | mugsie, timsim, I'll try restarting the pool manager/worker. I hadn't done that. I just did the pool update | 20:19 |
timsim | (only one of pool mgr/worker should be running btw, preferably worker) | 20:19 |
timsim | Pretty sure one of them won't start. | 20:20 |
shewless | I have designate-agent, designate-pool-manager, designate-central, designate-mdns, designate-api | 20:21 |
shewless | so I restart poo-manager? | 20:25 |
timsim | Sure | 20:25 |
shewless | ..and that is what we call a freudian slip :) | 20:25 |
mugsie | shewless: it is honestly not even the worst one on this channel | 20:26 |
timsim | heh | 20:26 |
* mugsie had a cracking one a while back | 20:27 | |
shewless | you know it's been a long couple of days.. I'm sitting in my chair laughing hysterically right now.. .poo-manager.. | 20:27 |
*** castlemilk has joined #openstack-dns | 20:29 | |
shewless | at any rate. I'm trying now iwth the master set to my bind server. I restarted all designate servers and updated my pool | 20:30 |
shewless | so far my zone creation says "PENDING" which isn't a great sign | 20:30 |
timsim | Yeah Designate is going to try and create the zone in bind, and bind is going to set the master to itself. | 20:31 |
timsim | That's not gonna work. | 20:31 |
shewless | timsim: darn | 20:32 |
timsim | Or, rather, Designate is going to create the zone of type slave, with the master being the bind server itself. | 20:32 |
shewless | should I just have designate update the master and the slaves via RNDC? Is that possible? | 20:32 |
timsim | You _could_ do set the bind master's masters -> designate, and the slaves to be the bind master. | 20:33 |
timsim | But then you'll have a situation where if the create lands on the slaves first, the initial transfer will fail. It'll probably retry, but maybe not. | 20:33 |
timsim | Perhaps if you set also notifies in your bind config, that will solve that problem. | 20:34 |
shewless | where do I set the slaves? | 20:35 |
shewless | in the targets section of the pool file? | 20:35 |
timsim | Yep | 20:36 |
timsim | That's pretty ugly, I bet it'll fail somehow. | 20:36 |
shewless | timsim: I didn't know that was an option. Is there a template file that shows all available options? | 20:37 |
timsim | It's just yaml, so you can have as many targets as you'd like | 20:37 |
shewless | timsim: can I list two masters? | 20:37 |
timsim | same with nameservers, pools, etc. | 20:37 |
timsim | sure | 20:37 |
shewless | or is taht what you meant? | 20:37 |
shewless | like. is "slaves" a keyword allowed in teh targets section/ | 20:37 |
timsim | no | 20:37 |
shewless | ah.. so you meant add two masters | 20:38 |
timsim | So you'd need one target per dns server that Designate needs to create the zone on. | 20:38 |
timsim | So three for you. | 20:38 |
timsim | Then in the masters section of the "slave" servers, you'd set it to the Bind master. | 20:38 |
timsim | So that when designate creates teh zones, they are like "type slave; masters { bind9 master ip} ;" | 20:38 |
timsim | But I really don't think that's going to work well | 20:39 |
timsim | I think what you really want is something like this http://jpmens.net/2013/02/13/automatic-provisioning-of-slave-dns-servers/ | 20:39 |
*** ducttape_ has quit IRC | 20:40 | |
shewless | timsim: thanks. reading up now. what a weird problem. | 20:43 |
timsim | Yeah. It's kind of annoying. | 20:43 |
timsim | Yeah, we ran tiered bind, and had crappy custom daemons to handle that replication. | 20:44 |
shewless | timsim: I think if I add 3 targets in the pool file it may work. but how much load is this going to add to the designate server? | 20:49 |
timsim | It should be ok | 20:49 |
shewless | timsim: so I added another target. I actually set the master to my mdns server for both targets. The master bind server just won't notify the slaves for these dynamic zones | 20:59 |
shewless | it seems to work... but when I do a recordset list I see that all the records are in status PENDING.. not sure why | 21:00 |
timsim | Yeah so what you're doing now is just having three bind slaves | 21:01 |
shewless | but If I check the "master bind" and the "slave bind" they definintly got the zone/records created that I need | 21:01 |
timsim | slaving off of designate | 21:01 |
shewless | timsim: for now that should work for me | 21:01 |
shewless | but I don't get why the status is PENDING for all of my records.. any way to debug that? | 21:01 |
timsim | Designate assigns a status, once it sees that the records are active on the "nameservers" in your pools yaml, it'll change them to active. | 21:02 |
timsim | I think you should see some of the logs of that polling in the mdns log, maybe the pool mgr log for state changes. | 21:02 |
shewless | timsim: so if I have two targets should I add two nameservers to my pools file? | 21:02 |
timsim | Probably. | 21:03 |
timsim | Shouldn't you have three? | 21:03 |
timsim | Because you have three servers | 21:03 |
shewless | yes. fair. I just tried adding 1 slave for now but once it's working I'll add the other and I will ahve a total of 3 | 21:03 |
*** castlemilk has quit IRC | 21:04 | |
shewless | timsim: it's weird though.. if I only have 1 nameserver listed I'd think it'd just check that and be done with it | 21:06 |
shewless | the nameserver I have listed definitly got the record | 21:06 |
timsim | Yeah, it probably is. | 21:06 |
timsim | It's actually checking the SOA record for the updated serial number. | 21:06 |
shewless | hmm.. wierd.. I added the other nameserver and now it's working | 21:07 |
shewless | dunno if it was a timing thing or what.. but it works so that's good | 21:07 |
timsim | of course pbr http://logs.openstack.org/65/442765/1/check/gate-designate-tempest-plugin-pep8-ubuntu-xenial/5bafef6/console.html | 21:08 |
* timsim gets it | 21:08 | |
shewless | timsim, mugsie: thanks for the help. It seems to be working by having my 3 bind servers slave off of designate | 21:11 |
shewless | timsim, mugsie: I'm noticing that designate is not informing bind of a change in the IP address. Is that normal? | 21:13 |
shewless | would I use the "also notify" section for that in the pool yaml? | 21:14 |
shewless | oops.. nevermind | 21:14 |
openstackgerrit | Tim Simmons proposed openstack/designate-tempest-plugin master: Fix doc typos and hacking requirement https://review.openstack.org/442765 | 21:14 |
shewless | the bind servers seem to be updated.. but my ping doesn't work | 21:14 |
shewless | does ubuntu have a DNS cache? | 21:15 |
shewless | ping of my dns name resolves to an old address, but nslookup against all 3 of my bind servers resolves to the correct address. weird | 21:16 |
*** castlemilk has joined #openstack-dns | 21:18 | |
timsim | Is there something in /etc/hosts? | 21:20 |
timsim | Or maybe dnsmasq or something | 21:20 |
*** ducttape_ has joined #openstack-dns | 21:40 | |
*** ducttape_ has quit IRC | 21:46 | |
*** abalutoiu has joined #openstack-dns | 21:51 | |
*** cleong has quit IRC | 21:55 | |
openstackgerrit | Graham Hayes proposed openstack/designate master: Bump hacking to new required version https://review.openstack.org/442596 | 21:56 |
mugsie | timsim: ^^ | 21:56 |
timsim | lol. Maybe not an auto +2 on that one. | 21:57 |
mugsie | well, it can't merge if it fails :P | 21:58 |
timsim | I suppose. | 21:58 |
timsim | I'm a bit concerned there might be a massive performance regression. | 21:58 |
timsim | But it's probably fine. | 21:58 |
mugsie | :/ | 22:02 |
mugsie | yeah | 22:02 |
*** tdink has quit IRC | 22:08 | |
mugsie | timsim: I am heading out - if that passes, can you +A+2 it? | 22:12 |
* mugsie just looked at a clock | 22:12 | |
*** ducttape_ has joined #openstack-dns | 22:16 | |
timsim | Sure, have a good night mugsie | 22:22 |
timsim | and if you'd like, +A this https://review.openstack.org/#/c/442765/ plz | 22:23 |
* mugsie - http://replygif.net/i/712.gif | 22:25 | |
timsim | <3 | 22:27 |
*** tdink has joined #openstack-dns | 22:33 | |
*** catintheroof has quit IRC | 22:41 | |
*** catintheroof has joined #openstack-dns | 22:42 | |
*** catintheroof has quit IRC | 22:47 | |
*** ducttape_ has quit IRC | 23:04 | |
*** ducttape_ has joined #openstack-dns | 23:07 | |
*** Guest45345 has joined #openstack-dns | 23:08 | |
openstackgerrit | Merged openstack/designate-tempest-plugin master: Fix doc typos and hacking requirement https://review.openstack.org/442765 | 23:14 |
*** kiall has quit IRC | 23:18 | |
*** kiall has joined #openstack-dns | 23:19 | |
*** kiall is now known as Guest41069 | 23:19 | |
*** Guest45345 has quit IRC | 23:22 | |
*** EricGonc_ has quit IRC | 23:31 | |
*** catintheroof has joined #openstack-dns | 23:32 | |
*** ducttape_ has quit IRC | 23:55 | |
*** ducttape_ has joined #openstack-dns | 23:56 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!