*** jafeha has quit IRC | 00:04 | |
*** rui has quit IRC | 00:05 | |
*** blake has quit IRC | 00:10 | |
*** blake has joined #openstack-dns | 00:12 | |
*** blake has quit IRC | 00:32 | |
*** jafeha has joined #openstack-dns | 00:37 | |
*** blake has joined #openstack-dns | 00:38 | |
*** blake has quit IRC | 00:45 | |
*** trungnv has quit IRC | 01:22 | |
*** trungnv has joined #openstack-dns | 01:23 | |
*** ianychoi_ has quit IRC | 02:27 | |
*** ianychoi has joined #openstack-dns | 02:30 | |
*** Leo_m has quit IRC | 02:49 | |
openstackgerrit | miaoyuliang proposed openstack/designate master: Install and configure for Red Hat Enterprise Linux and CentOS miss several steps https://review.openstack.org/576690 | 03:05 |
---|---|---|
openstackgerrit | miaoyuliang proposed openstack/designate master: Install and configure for Red Hat Enterprise Linux and CentOS miss several steps https://review.openstack.org/576694 | 03:22 |
*** wlmbasson has quit IRC | 03:41 | |
*** fyx has quit IRC | 03:44 | |
*** wlmbasson has joined #openstack-dns | 03:45 | |
*** fyx has joined #openstack-dns | 03:46 | |
*** mwhahaha has quit IRC | 03:48 | |
*** timsim has quit IRC | 03:48 | |
*** amitry has quit IRC | 03:49 | |
*** johnsom has quit IRC | 03:50 | |
*** wlmbasson has quit IRC | 03:50 | |
*** simonmcc has quit IRC | 03:51 | |
*** andrewbogott has quit IRC | 03:51 | |
*** fyx has quit IRC | 03:51 | |
*** lxkong has quit IRC | 03:51 | |
*** serverascode has quit IRC | 03:52 | |
*** openstack has joined #openstack-dns | 04:29 | |
*** ChanServ sets mode: +o openstack | 04:29 | |
*** masber has quit IRC | 04:59 | |
openstackgerrit | miaoyuliang proposed openstack/python-designateclient master: just for test https://review.openstack.org/576715 | 05:10 |
*** andrewbogott has joined #openstack-dns | 05:22 | |
*** wlmbasson has joined #openstack-dns | 05:24 | |
*** lxkong has joined #openstack-dns | 05:24 | |
*** mwhahaha has joined #openstack-dns | 05:28 | |
*** serverascode has joined #openstack-dns | 05:28 | |
*** simonmcc has joined #openstack-dns | 05:33 | |
*** johnsom has joined #openstack-dns | 05:36 | |
*** fyx has joined #openstack-dns | 05:43 | |
*** trungnv has quit IRC | 05:45 | |
*** wlmbasson has quit IRC | 05:51 | |
*** fyx has quit IRC | 05:51 | |
*** andrewbogott has quit IRC | 05:55 | |
*** mwhahaha has quit IRC | 05:56 | |
*** simonmcc has quit IRC | 05:57 | |
*** johnsom has quit IRC | 05:57 | |
*** lxkong has quit IRC | 05:58 | |
*** serverascode has quit IRC | 05:58 | |
*** trungnv has joined #openstack-dns | 06:09 | |
*** andrewbogott has joined #openstack-dns | 06:12 | |
*** fyx has joined #openstack-dns | 06:16 | |
*** wlmbasson has joined #openstack-dns | 06:17 | |
*** simonmcc has joined #openstack-dns | 06:21 | |
*** timsim has joined #openstack-dns | 06:21 | |
*** timsim has quit IRC | 06:21 | |
*** timsim has joined #openstack-dns | 06:21 | |
*** lxkong has joined #openstack-dns | 06:21 | |
*** serverascode has joined #openstack-dns | 06:21 | |
*** serverascode has quit IRC | 06:22 | |
*** serverascode has joined #openstack-dns | 06:22 | |
*** lxkong has quit IRC | 06:22 | |
*** lxkong has joined #openstack-dns | 06:22 | |
*** johnsom has joined #openstack-dns | 06:22 | |
*** d34dh0r53 has quit IRC | 06:24 | |
*** d34dh0r53 has joined #openstack-dns | 06:24 | |
*** mwhahaha has joined #openstack-dns | 06:25 | |
*** serverascode has quit IRC | 06:26 | |
*** serverascode has joined #openstack-dns | 06:26 | |
*** briner has joined #openstack-dns | 06:28 | |
*** serverascode has quit IRC | 06:29 | |
*** serverascode has joined #openstack-dns | 06:30 | |
openstackgerrit | miaoyuliang proposed openstack/python-designateclient master: server-get/update show wrong values about 'id' and 'update_at' https://review.openstack.org/576408 | 06:33 |
*** amitry_ has joined #openstack-dns | 06:55 | |
*** rui has joined #openstack-dns | 07:31 | |
*** andrewbogott has quit IRC | 07:42 | |
*** andrewbogott has joined #openstack-dns | 07:42 | |
*** rui has quit IRC | 07:46 | |
*** AlexeyAbashkin has joined #openstack-dns | 07:49 | |
*** briner has quit IRC | 07:56 | |
*** rpittau is now known as rpittau_ | 08:05 | |
*** rpittau_ is now known as elfosardo | 08:05 | |
*** elfosardo is now known as rpittau | 08:05 | |
*** rpittau is now known as rpittau__ | 08:09 | |
*** rpittau__ is now known as rpittau | 08:09 | |
*** rpittau has quit IRC | 08:10 | |
*** rpittau has joined #openstack-dns | 08:10 | |
*** peereb has joined #openstack-dns | 08:10 | |
*** briner has joined #openstack-dns | 08:10 | |
*** pcaruana has joined #openstack-dns | 08:11 | |
*** peereb has quit IRC | 08:14 | |
*** peereb has joined #openstack-dns | 08:15 | |
*** peereb has quit IRC | 08:16 | |
*** peereb has joined #openstack-dns | 08:16 | |
*** peereb has quit IRC | 08:17 | |
*** peereb has joined #openstack-dns | 08:18 | |
*** peereb has quit IRC | 08:19 | |
*** peereb has joined #openstack-dns | 08:19 | |
*** peereb has quit IRC | 08:20 | |
*** peereb has joined #openstack-dns | 08:21 | |
*** peereb has quit IRC | 08:21 | |
*** briner_ has joined #openstack-dns | 08:36 | |
*** briner has quit IRC | 08:37 | |
*** salmankhan has joined #openstack-dns | 09:02 | |
*** briner_ has quit IRC | 09:04 | |
*** briner has joined #openstack-dns | 09:05 | |
*** briner has quit IRC | 09:10 | |
*** salmankhan has quit IRC | 10:04 | |
*** salmankhan has joined #openstack-dns | 10:04 | |
*** Shadowphax has joined #openstack-dns | 10:04 | |
*** briner has joined #openstack-dns | 12:00 | |
*** salmankhan has quit IRC | 12:10 | |
*** rfreire has joined #openstack-dns | 12:26 | |
Shadowphax | I actually have no idea what i am doing with designate | 12:44 |
rfreire | ¯\_(ツ)_/¯ | 12:44 |
Shadowphax | okay .. so i've configured designate and the first thing I have seen in the logs is related to " not enough nameservers " | 12:44 |
Shadowphax | how does the resolution occur from external clients to my DNS servers ? | 12:46 |
Shadowphax | if i create shadowphax.sample.org | 12:46 |
rfreire | Shadowphax, well jokes apart | 12:47 |
Shadowphax | my upstream DNS servers should be delegating that to bind right ? | 12:47 |
rfreire | Shadowphax, I have just entered the IRC channel and might have lost some extra context | 12:47 |
Shadowphax | let me paste | 12:47 |
rfreire | Shadowphax, but I have written a somewhat step-by-step, tests included, for Designate setup (for Newton version, might be good enough for latest) | 12:47 |
rfreire | Shadowphax, https://access.redhat.com/documentation/en-us/red_hat_openstack_platform/10/html-single/dns-as-a-service_guide/index#manual_dnsaas_installation | 12:48 |
rfreire | Shadowphax, take a look at this. It is really easy to follow | 12:48 |
rfreire | Shadowphax, and then there's a test session down there, on what to do and what to expect. | 12:48 |
Shadowphax | awesome thanks | 12:48 |
Shadowphax | I used Kolla to deploy | 12:49 |
Shadowphax | so its does most of what you have listed | 12:49 |
Shadowphax | but I will compare | 12:49 |
Shadowphax | i am also confused about possible the other infrastructural components | 12:49 |
Shadowphax | like external DNS and how it references the designate-backend-bind9 stuff | 12:50 |
rfreire | Shadowphax, ah been there man. | 12:51 |
frickler | actually it would be a good idea to add this step to our installation guide I think. might be a bit out of scope, but certainly helpful for newcomers. what to you think, mugsie? | 12:55 |
Shadowphax | @frickler, which installation guide / | 12:56 |
frickler | Shadowphax: if you create a zone shadowphax.sample.org in designate and your bind server is named ns1.sample.org, you would need to create an entry "shadowphax.sample.org. NS ns1.sample.org" in your sample.org zone | 12:57 |
frickler | Shadowphax: https://docs.openstack.org/designate/queens/install/index.html | 12:57 |
Shadowphax | i don't have that | 12:58 |
*** rfreire has quit IRC | 12:59 | |
frickler | Shadowphax: well, if you want globally visible DNS, you need to start with some zone that you register at some registrar | 12:59 |
Shadowphax | which I have | 12:59 |
Shadowphax | and they have delegated shadowphax.sample.org to the designate nameservers | 12:59 |
Shadowphax | which would be the controller nodes | 13:00 |
frickler | well, if that is where your bind servers are running, then things should be fine | 13:00 |
Shadowphax | hmm .. just noticed that my public ip is not listening on 53 | 13:02 |
*** salmankhan has joined #openstack-dns | 13:02 | |
*** rfreire has joined #openstack-dns | 13:04 | |
Shadowphax | now complaining about SERVFAIL | 13:10 |
Shadowphax | when doing external lookups | 13:11 |
rfreire | Shadowphax, hi hi | 13:11 |
* rfreire is back | 13:11 | |
rfreire | Shadowphax, what's going on right now? | 13:11 |
Shadowphax | so from what i could see my backend-bind9 was not listening with its external_ip on port 53 | 13:12 |
Shadowphax | i've changed that now .. | 13:12 |
rfreire | Shadowphax, nicey! | 13:12 |
Shadowphax | so when doing lookups against shadowphax.sample.org i'm getting these SERVFAIl errors | 13:13 |
frickler | Shadowphax: but zone creation in designate worked and the zone status is active? | 13:14 |
*** briner has quit IRC | 13:15 | |
Shadowphax | no.. i get an error after the pending state | 13:15 |
Shadowphax | its actually erroring out at the creation process | 13:16 |
frickler | so there should be some error message related to that either in one of the designate-* logs or in the bind log | 13:17 |
Shadowphax | Could not find 1529497922 for shadowphax.sample.org. on enough nameservers. | 13:19 |
Shadowphax | that comes from designate-worker | 13:19 |
rfreire | Shadowphax, nice | 13:20 |
frickler | Shadowphax: well, that is the result of the zone not being created in bind, but there should be some other error before that. your maybe your pool.yaml is broken, can you share it on paste.openstack.org? | 13:20 |
rfreire | Shadowphax, that menas: Designate could not create the zone (and verify it) in your BIND servers | 13:21 |
Shadowphax | all other logs are good | 13:21 |
rfreire | Shadowphax, a grep ERR /var/log/designate/* will also be of help in the pastebin. | 13:22 |
rfreire | Shadowphax, other side note; in the BIND servers: | 13:23 |
rfreire | Shadowphax, if you are using SELinux, you will need to apply a boolean | 13:23 |
rfreire | Shadowphax, AND you will also have to set a group permission | 13:23 |
rfreire | Otherwise, it will hinder the zone creation | 13:23 |
rfreire | and thus | 13:23 |
rfreire | the errors. | 13:23 |
rfreire | Namely: | 13:23 |
rfreire | # setsebool named_write_master_zones 1 (the SELinux boolean) | 13:24 |
rfreire | # chmod g+w /var/named | 13:24 |
rfreire | (the permission group in /var/named) | 13:24 |
Shadowphax | using ubuntu so no selinux | 13:25 |
rfreire | alrighto; check the group write perms | 13:27 |
*** Shadowphax has quit IRC | 13:39 | |
*** briner has joined #openstack-dns | 13:42 | |
*** PsionTheory has joined #openstack-dns | 13:49 | |
frickler | why do folks always leave when things get interesting? ftr, the directory would be /var/cache/bind/ for ubuntu and should be owned by bind:bind | 13:54 |
rfreire | frickler++ | 14:03 |
*** diman has joined #openstack-dns | 14:22 | |
*** Shadowphax has joined #openstack-dns | 14:41 | |
*** briner has quit IRC | 14:43 | |
openstackgerrit | Pavlo Shchelokovskyy proposed openstack/designate master: Init sslutils before service start https://review.openstack.org/576886 | 14:50 |
*** rfreire_ has joined #openstack-dns | 14:58 | |
*** rfreire has quit IRC | 15:00 | |
*** briner has joined #openstack-dns | 15:03 | |
*** PsionTheory has quit IRC | 15:27 | |
*** briner has quit IRC | 15:28 | |
*** rfreire_ has quit IRC | 15:38 | |
*** Shadowphax has quit IRC | 16:43 | |
*** briner has joined #openstack-dns | 16:45 | |
*** rfreire has joined #openstack-dns | 16:49 | |
*** diman has quit IRC | 16:54 | |
*** salmankhan has quit IRC | 17:16 | |
*** AlexeyAbashkin has quit IRC | 17:23 | |
*** briner has quit IRC | 17:50 | |
*** diman has joined #openstack-dns | 18:07 | |
*** diman has quit IRC | 18:18 | |
*** ianychoi has quit IRC | 18:36 | |
*** ircuser-1 has quit IRC | 18:45 | |
*** rui has joined #openstack-dns | 18:46 | |
*** rfreire has quit IRC | 19:00 | |
*** Shadowphax has joined #openstack-dns | 19:08 | |
*** rui has quit IRC | 19:13 | |
*** Shadowphax has quit IRC | 19:17 | |
*** Shadowphax has joined #openstack-dns | 19:19 | |
Shadowphax | @frickler, apologies for leaving ... our upstream provider had problems with their network | 19:21 |
*** rfreire has joined #openstack-dns | 19:31 | |
Shadowphax | rfreire: apologies for quiting earlier, had problems with our upstream provider | 19:35 |
Shadowphax | so it seems that BIND is the problem in this case - http://paste.openstack.org/show/723955/ | 19:37 |
Shadowphax | but its port 5354 which is not listening on the private IP thats causing the issue | 19:39 |
*** Deknos has joined #openstack-dns | 19:39 | |
Shadowphax | its only listening on the public interface, which it should not | 19:39 |
*** Deknos has left #openstack-dns | 19:41 | |
*** salmankhan has joined #openstack-dns | 19:41 | |
*** boris_42_ has joined #openstack-dns | 20:10 | |
mugsie | Shadowphax: you need to update the designate.conf to make minidns listen on the right interface | 20:26 |
Shadowphax | @mugsie, indeed i did | 20:29 |
Shadowphax | and it work | 20:29 |
Shadowphax | worked | 20:29 |
Shadowphax | and now everything is working . | 20:29 |
*** salmankhan has quit IRC | 20:30 | |
Shadowphax | definitely going to update the Kolla documentation of Designate :) | 20:37 |
*** pcaruana has quit IRC | 20:41 | |
*** briner has joined #openstack-dns | 20:52 | |
*** briner has quit IRC | 21:14 | |
*** rfreire has quit IRC | 21:30 | |
*** Shadowphax has quit IRC | 21:31 | |
*** Shadowphax has joined #openstack-dns | 21:49 | |
*** Shadowphax has quit IRC | 22:34 | |
*** rui has joined #openstack-dns | 22:43 | |
*** rui has quit IRC | 23:09 | |
*** boris_42_ has quit IRC | 23:19 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!