*** blake has quit IRC | 02:00 | |
*** blake has joined #openstack-dns | 02:01 | |
*** blake has quit IRC | 02:05 | |
*** Shadowphax has joined #openstack-dns | 05:21 | |
*** Shadowphax has quit IRC | 05:33 | |
*** Shadowphax has joined #openstack-dns | 05:37 | |
*** briner has joined #openstack-dns | 05:37 | |
*** briner has quit IRC | 05:39 | |
*** blake has joined #openstack-dns | 05:41 | |
*** blake has quit IRC | 05:43 | |
*** blake has joined #openstack-dns | 05:44 | |
*** AlexeyAbashkin has joined #openstack-dns | 05:54 | |
*** masber has joined #openstack-dns | 05:57 | |
*** AlexeyAbashkin has quit IRC | 06:13 | |
*** andrewbogott has quit IRC | 06:28 | |
*** andrewbogott has joined #openstack-dns | 06:28 | |
*** pcaruana has joined #openstack-dns | 06:30 | |
*** briner has joined #openstack-dns | 06:31 | |
*** Shadowphax has quit IRC | 06:33 | |
*** AlexeyAbashkin has joined #openstack-dns | 07:10 | |
*** rui2 has joined #openstack-dns | 07:15 | |
*** Shadowphax has joined #openstack-dns | 07:16 | |
*** blake has quit IRC | 07:21 | |
*** rui2 has quit IRC | 07:29 | |
*** rui2 has joined #openstack-dns | 07:31 | |
*** rui2 has quit IRC | 07:32 | |
Shadowphax | thanks mugsie | 07:39 |
---|---|---|
*** briner has quit IRC | 07:41 | |
*** peereb has joined #openstack-dns | 08:05 | |
*** briner has joined #openstack-dns | 08:23 | |
*** AlexeyAbashkin has quit IRC | 08:29 | |
*** salmankhan has joined #openstack-dns | 08:57 | |
*** salmankhan has quit IRC | 09:28 | |
*** salmankhan has joined #openstack-dns | 09:31 | |
*** AlexeyAbashkin has joined #openstack-dns | 09:36 | |
*** briner has quit IRC | 09:49 | |
*** trungnv has quit IRC | 10:02 | |
*** kbyrne has quit IRC | 10:49 | |
*** kbyrne has joined #openstack-dns | 10:51 | |
mugsie | KeithMnemonic: in theory yes, that could work. | 11:30 |
mugsie | however. | 11:30 |
mugsie | I would recommend against it | 11:30 |
mugsie | and there is no upstream support for doing it that way :) | 11:30 |
*** diman has joined #openstack-dns | 11:37 | |
*** briner has joined #openstack-dns | 11:40 | |
*** briner has quit IRC | 11:49 | |
*** rfreire has joined #openstack-dns | 11:53 | |
openstackgerrit | Pavlo Shchelokovskyy proposed openstack/designate master: Init config before service start https://review.openstack.org/576886 | 11:54 |
*** AlexeyAbashkin has quit IRC | 11:57 | |
*** AlexeyAbashkin has joined #openstack-dns | 12:11 | |
KeithMnemonic | mugsie: Thanks! We had a query about using two different backend in one OpenStack deployment. | 12:56 |
mugsie | you can use 2 different backends, but I would tell people to do it in 2 different pools | 12:57 |
KeithMnemonic | that is what i meant, one pool for bind, one pool for inofblox | 12:58 |
Shadowphax | mugsie: what would the usecase be for that ? | 13:04 |
mugsie | sorry, I completely miss read that | 13:04 |
mugsie | that is ++ KeithMnemonic | 13:04 |
mugsie | Shadowphax: if you have infoblox for internal DNS but want a real DNS server for external internet facing traffic | 13:05 |
Shadowphax | okay | 13:06 |
mugsie | it allows you to have DNS zones availible to different networks, or have tiers of DNS services (so one teir may have servers globally, one has just US and one is just in a single DC) | 13:06 |
KeithMnemonic | or vice versa, maybe your corp IT is Infoblox but for a devops lab you want something opensource | 13:07 |
Shadowphax | mugsie: how do I prevent the private address space from being looked up ? | 13:22 |
Shadowphax | i only want the floating_ip to be available externally | 13:22 |
Shadowphax | internally the project zone private address space can be done | 13:23 |
*** briner has joined #openstack-dns | 13:25 | |
*** briner has quit IRC | 13:29 | |
*** brad[] has quit IRC | 14:02 | |
*** peereb has quit IRC | 14:10 | |
*** Shadowphax has quit IRC | 14:31 | |
bnemec | Hey, I noticed that I was unable to delete my example.com. zone in a TripleO-based deployment, but it worked in devstack (tm). | 15:27 |
bnemec | It turns out that it's because puppet turns on recursion in BIND by default, and since example.com is a real domain it looked like it never went away. | 15:28 |
bnemec | devstack disable recursion though. | 15:28 |
bnemec | Is that just for simplicity or should I not have recursion turned on in TripleO either? | 15:28 |
bnemec | It seems like that would make the Designate-managed BIND kind of useless as a general purpose DNS server though. | 15:29 |
kiall | Generally, it's best practice to split your authoritative DNS servers from your recursive DNS servers. | 15:32 |
kiall | There have been many DNS vunlerabilities over the years causes by combining the two | 15:33 |
*** diman has quit IRC | 15:34 | |
*** rpittau has quit IRC | 15:35 | |
bnemec | Okay, that's good to know. Thanks. | 15:47 |
*** Shadowphax has joined #openstack-dns | 15:57 | |
*** pcaruana has quit IRC | 16:04 | |
*** Shadowphax has quit IRC | 16:17 | |
*** kberger has joined #openstack-dns | 16:51 | |
mugsie | bnemec: yeah, I would disable it in the tripleO bind server - it could also block people who move a domain to a new server from deleting a zone in designate | 17:00 |
*** briner has joined #openstack-dns | 17:02 | |
*** briner has quit IRC | 17:05 | |
bnemec | mugsie: A lot of stuff suddenly makes more sense now that I know you're not supposed to have clients hit that server directly. | 17:05 |
bnemec | Unfortunately it also complicates the deployment process quite a bit. :-) | 17:07 |
*** briner has joined #openstack-dns | 17:13 | |
*** briner has quit IRC | 17:14 | |
*** salmankhan has quit IRC | 17:20 | |
*** briner has joined #openstack-dns | 17:40 | |
*** kberger has quit IRC | 17:42 | |
*** briner has quit IRC | 18:26 | |
*** briner has joined #openstack-dns | 18:32 | |
*** AlexeyAbashkin has quit IRC | 18:44 | |
*** Shadowphax has joined #openstack-dns | 18:52 | |
*** Shadowphax has quit IRC | 18:59 | |
*** Shadowphax has joined #openstack-dns | 19:14 | |
*** cmurphy is now known as cmurphy_vacation | 19:31 | |
*** briner has quit IRC | 19:56 | |
*** rfreire has quit IRC | 20:57 | |
*** AlexeyAbashkin has joined #openstack-dns | 21:02 | |
*** Shadowphax has quit IRC | 21:06 | |
*** AlexeyAbashkin has quit IRC | 21:11 | |
*** KeithMnemonic has quit IRC | 21:15 | |
*** eandersson_ has joined #openstack-dns | 21:30 | |
*** eandersson_ has quit IRC | 21:30 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!