*** caowei has joined #openstack-dns | 00:37 | |
*** kbyrne has quit IRC | 01:27 | |
*** kbyrne has joined #openstack-dns | 01:32 | |
*** wlmbasson_ has joined #openstack-dns | 02:08 | |
*** beekneemech has joined #openstack-dns | 02:10 | |
*** keithmnemonic[m] has quit IRC | 02:12 | |
*** wlmbasson has quit IRC | 02:12 | |
*** mordred has quit IRC | 02:12 | |
*** bnemec has quit IRC | 02:12 | |
*** wlmbasson_ is now known as wlmbasson | 02:12 | |
*** mordred has joined #openstack-dns | 02:13 | |
*** daidv has joined #openstack-dns | 02:46 | |
*** daidv has quit IRC | 02:49 | |
*** trungnv has joined #openstack-dns | 03:00 | |
*** trungnv_ has joined #openstack-dns | 03:01 | |
*** trungnv_ has quit IRC | 03:05 | |
*** caowei has quit IRC | 03:59 | |
*** diman_ has joined #openstack-dns | 04:08 | |
*** diman_ has quit IRC | 04:13 | |
*** caowei has joined #openstack-dns | 04:42 | |
*** trungnv has quit IRC | 06:43 | |
*** trungnv has joined #openstack-dns | 06:44 | |
*** openstackgerrit has joined #openstack-dns | 07:28 | |
*** ChanServ sets mode: +v openstackgerrit | 07:28 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/designate-dashboard stable/pike: Imported Translations from Zanata https://review.openstack.org/564409 | 07:28 |
---|---|---|
*** pcaruana has joined #openstack-dns | 07:31 | |
*** AlexeyAbashkin has joined #openstack-dns | 07:45 | |
*** diman_ has joined #openstack-dns | 08:03 | |
*** keithmnemonic[m] has joined #openstack-dns | 08:46 | |
*** Alexey_Abashkin has joined #openstack-dns | 08:57 | |
*** AlexeyAbashkin has quit IRC | 09:01 | |
*** Alexey_Abashkin is now known as AlexeyAbashkin | 09:01 | |
*** trungnv has quit IRC | 09:27 | |
*** trungnv has joined #openstack-dns | 09:28 | |
*** trungnv_ has joined #openstack-dns | 09:34 | |
*** trungnv has quit IRC | 09:39 | |
*** keithmnemonic[m] has quit IRC | 09:39 | |
*** trungnv_ has quit IRC | 10:00 | |
*** keithmnemonic[m] has joined #openstack-dns | 10:17 | |
*** diman_ has quit IRC | 10:29 | |
*** rfreire has joined #openstack-dns | 10:40 | |
*** caowei has quit IRC | 10:52 | |
rfreire | mugsie, hullo there Graham! o/ | 11:34 |
rfreire | mugsie, I have reviewed my setup procedures and I think this is a more refined step-by-step Designate install for CentOS/RHEL/RDO/etc | 11:34 |
rfreire | wondering if would you be interested in taking a look | 11:34 |
rfreire | URL: https://pastebin.com/yKUVtz1G | 11:42 |
rfreire | eandersson, ^^ | 11:42 |
*** tacco has joined #openstack-dns | 11:49 | |
tacco | Hi there. Anyone knows how to configure multiple bind server to send axfr to via rndc by designate? | 11:50 |
rfreire | tacco, hi, I think I know this | 11:53 |
rfreire | tacco, https://pastebin.com/cXr4n5zE | 11:55 |
rfreire | tacco, relevant lines: 10-15 | 11:55 |
rfreire | if I understood correctly your question ¯\_(ツ)_/¯ | 11:56 |
tacco | maybe. :) | 11:57 |
tacco | but from my point if view nameservers w il only be used to check if the record is active | 11:57 |
tacco | more importang maybe are the masters and options | 11:57 |
rfreire | Ah | 11:58 |
tacco | what is behind? $EXTERNAL_DNS_SERVER_IP some of the $EXTERNAL_DNS_SERVER_IP_1-3? | 11:58 |
rfreire | masters: those are the designate servers, which runs the mdns service (port 5453) | 11:58 |
tacco | if i see this correctly in this setup the records get distributed by bind itself | 11:58 |
rfreire | I think that yes, you are right, the designate then sends a NOTIFY message to the server listed in port 28 | 11:59 |
rfreire | ops | 11:59 |
rfreire | listed in line 28 | 11:59 |
tacco | or by designate and behind every designate should be one of the external_DNS_Server 1-3 | 11:59 |
rfreire | the external dns -> systems running ISC bind | 12:00 |
rfreire | the designate_sever -> systems running Designate/mdns | 12:00 |
rfreire | I have multiple designate services because we built a HA system | 12:00 |
rfreire | with three Designate nodes. | 12:00 |
tacco | yes. i understand that | 12:00 |
rfreire | I crafted quickly this yml file for you with lines 12-15 | 12:01 |
rfreire | But I think that you are right | 12:01 |
rfreire | that will not be of help | 12:01 |
rfreire | When theres a zone update | 12:01 |
rfreire | the notify is sent to specified in line 28, which is the bind server | 12:01 |
rfreire | and there's no provision for multiple servers as far as i know | 12:01 |
rfreire | I know about that because I misconfigured it | 12:01 |
tacco | yes i'm looking for the case if i have 3 bind servers and want to notify them | 12:01 |
rfreire | and it was trying to send notifies to 127.0.0.1 | 12:02 |
tacco | there is a also-notify for designate | 12:02 |
tacco | but | 12:02 |
tacco | there i can only specify a host and port | 12:02 |
tacco | no rndc keys etc | 12:02 |
rfreire | And tnhen eandersson pointed that I forgot to declare lines 28-29. By then, it started sending notifies to my external dns server. | 12:02 |
tacco | ok maybe i just try to use multiple notify-to parts.. don't know if this is possible | 12:03 |
rfreire | I don't know man, sorry ;-/ | 12:03 |
tacco | no worrys thanks for your help anyway | 12:03 |
rfreire | tacco, re-thinking; | 12:04 |
rfreire | tacco, I _think_ that, upon the notify from the master by rndc/mdns; | 12:05 |
rfreire | the receiving BIND server would send notifies to other BIND servers | 12:05 |
rfreire | I _think_ | 12:05 |
tacco | from https://docs.openstack.org/designate/pike/admin/pools.html#managing-pools i think it should be done by also_notifies option on the bottom of the config | 12:06 |
* rfreire mira | 12:06 | |
tacco | rfreire: yes this is also a option what i was thinking about | 12:06 |
tacco | because bind can notify slaves by themself | 12:06 |
rfreire | tacco, and by that, it would need the multiple nameservers | 12:07 |
rfreire | so the bind servers would know who are all the members for that zone and send the notifies | 12:07 |
rfreire | just speculating | 12:07 |
tacco | yes should but i'm in a environment that is not perfect. already build up and running but with some issues. | 12:08 |
tacco | ;) | 12:08 |
tacco | but my first tought was that bind should handle this by themself | 12:08 |
rfreire | life's hard, right? | 12:10 |
tacco | yes but there will be a solution. i just want to figure out if this is a easy way just to use designate for notify or bind | 12:11 |
*** diman has joined #openstack-dns | 12:11 | |
rfreire | tacco, I just saw the document | 12:11 |
rfreire | and yes | 12:11 |
rfreire | the also_notifies looks pretty much what you need! | 12:11 |
tacco | ok so i will try this with multiple hosts because we have 3 :) | 12:12 |
rfreire | so thats going to be | 12:12 |
rfreire | - host: | 12:12 |
rfreire | port: | 12:12 |
rfreire | - host: | 12:12 |
rfreire | port: | 12:12 |
rfreire | - host: | 12:12 |
rfreire | port: | 12:12 |
rfreire | -- | 12:12 |
tacco | ok | 12:12 |
tacco | thanks a lot man | 12:12 |
rfreire | I did nothing! :-) | 12:12 |
rfreire | Good luck!! And let us know | 12:12 |
tacco | sure | 12:12 |
tacco | can't do this change right now but will see when we can do the change and let you know what happend. | 12:13 |
rfreire | alrighto! | 12:13 |
*** diman has quit IRC | 12:16 | |
openstackgerrit | Merged openstack/designate-dashboard stable/pike: Imported Translations from Zanata https://review.openstack.org/564409 | 12:41 |
*** diman has joined #openstack-dns | 12:41 | |
*** diman has quit IRC | 12:46 | |
*** diman has joined #openstack-dns | 12:48 | |
*** diman has quit IRC | 12:53 | |
openstackgerrit | Merged openstack/designate-dashboard master: Fix horizon install for tox https://review.openstack.org/559578 | 13:26 |
*** diman has joined #openstack-dns | 13:45 | |
*** diman has quit IRC | 13:56 | |
rfreire | tacco, hi | 14:19 |
rfreire | tacco, I got curious on what you have mentioned and I'm doing some tests here | 14:19 |
rfreire | tacco, this is what I have right now: https://pastebin.com/W2Yf47s4 | 14:20 |
rfreire | tacco, I have created a zone, and it indeed list the records correctly in the zone: | 14:21 |
rfreire | -- | 14:21 |
rfreire | [root@aa10-cont1 designate(keystone_admin)]# openstack recordset list 82c357d2-66b2-4a28-93a5-8d2d76b17bd0 | 14:21 |
rfreire | +-----------------------+-----------------------+------+------------------------+--------+--------+ | 14:21 |
rfreire | | id | name | type | records | status | action | | 14:21 |
rfreire | +-----------------------+-----------------------+------+------------------------+--------+--------+ | 14:21 |
rfreire | | 9211f7fb-f1e7-49ad- | openstack.rf01.co. | SOA | ll- | ACTIVE | NONE | | 14:21 |
rfreire | | a6aa-8c6e35c8e6d8 | | | rhel7.interna.rf01.co. | | | | 14:21 |
rfreire | | | | | admin.openstack.rf01.c | | | | 14:21 |
rfreire | | | | | o. 1524751326 3569 600 | | | | 14:21 |
rfreire | | | | | 86400 3600 | | | | 14:21 |
rfreire | | 989c709a-3235-470d- | openstack.rf01.co. | NS | aa10-dns1.interna.rf01 | ACTIVE | NONE | | 14:21 |
rfreire | | ac88-c4e3bf6303e2 | | | .co. | | | | 14:21 |
rfreire | | | | | ll- | | | | 14:21 |
rfreire | | | | | rhel7.interna.rf01.co. | | | | 14:21 |
rfreire | | ebfbcb2b-96c3-4f5d- | fafa.openstack.rf01.c | A | 127.0.0.1 | ACTIVE | NONE | | 14:21 |
rfreire | | 81c3-c6119db3ed37 | o. | | | | | | 14:21 |
rfreire | +-----------------------+-----------------------+------+------------------------+--------+--------+ | 14:21 |
rfreire | -- | 14:21 |
rfreire | Notice that there are TWO NS servers, as per the file. | 14:21 |
rfreire | However, the zone is only created at the server that is specified in targets: options: config in pool file | 14:22 |
rfreire | As we were discussing earlier, I _expected_ that the primary BIND server would replicate to the other | 14:22 |
rfreire | But that did not happen. | 14:22 |
rfreire | -- | 14:23 |
rfreire | So, it seems the missing link here is a BIND configuration to replicate zones created automatically in one node to other | 14:23 |
rfreire | mugsie surely knows the black magic, but is not readily available today. | 14:23 |
rfreire | eandersson, ^ maybe? | 14:23 |
mugsie | rfreire: you need a second target | 14:27 |
rfreire | mugsie, tellmemoar | 14:27 |
rfreire | ah | 14:27 |
rfreire | line 18; replicate | 14:27 |
rfreire | rinse; repeat? | 14:27 |
mugsie | https://pastebin.com/Xn1Pa08e | 14:27 |
mugsie | yeah | 14:28 |
rfreire | Dammit <3 | 14:28 |
mugsie | :) | 14:28 |
rfreire | isn't this Designate Thing... LOVELY? | 14:29 |
rfreire | tacco, ^ here it is. The answer to your question :-) | 14:29 |
*** beekneemech is now known as bnemec | 14:37 | |
*** pcaruana has quit IRC | 14:42 | |
*** Leo_m has joined #openstack-dns | 14:43 | |
rfreire | tacco, small word of advice. After changing the pool config and loading it with designate-manage pool update, at least in my OSP version, it will NOT start working immediately notifying the new servers of the new zones. You will need to restart the designate service. | 14:52 |
rfreire | Then, it will make some checks (10 checks) for zone in the new dns servers, and after then, will populate the DNS server with the existing configuration. | 14:52 |
rfreire | just.works++ (TM) | 14:52 |
rfreire | but takes a while. be patient. | 14:58 |
*** diman has joined #openstack-dns | 15:05 | |
-openstackstatus- NOTICE: We've successfully troubleshooted the issue that prevented paste.openstack.org from loading and it's now back online, thank you for your patience. | 15:05 | |
*** diman has quit IRC | 15:07 | |
*** diman has joined #openstack-dns | 15:07 | |
*** diman has quit IRC | 15:12 | |
*** AlexeyAbashkin has quit IRC | 15:56 | |
*** diman has joined #openstack-dns | 16:37 | |
*** diman has quit IRC | 16:43 | |
eandersson | ah man mugsie beat me to it :D | 17:14 |
rfreire | eandersson, ;-D | 17:49 |
*** diman has joined #openstack-dns | 19:56 | |
*** diman has quit IRC | 19:56 | |
rfreire | ping tacco hey | 20:31 |
*** sapcc-bot has quit IRC | 21:00 | |
*** sapcc-bot1 has quit IRC | 21:00 | |
*** sapcc-bot2 has joined #openstack-dns | 21:00 | |
*** sapcc-bot has joined #openstack-dns | 21:00 | |
*** livelace-link has joined #openstack-dns | 21:03 | |
mugsie | Oh, people may be interested in https://pypi.org/project/certbot-dns-openstack/ | 21:37 |
mugsie | It is *very* new but does just about work | 21:37 |
mugsie | No docs or tests or anything really yet | 21:38 |
eandersson | fancy :D | 22:01 |
*** Leo_m has quit IRC | 22:22 | |
rfreire | bnemec, thanks for your update in SELinux AVC bug | 22:55 |
*** jmccrory has quit IRC | 23:17 | |
*** jmccrory has joined #openstack-dns | 23:18 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!