*** Leo_m has quit IRC | 00:10 | |
*** Leo_m has joined #openstack-dns | 00:11 | |
*** masber has joined #openstack-dns | 00:58 | |
*** ivve has joined #openstack-dns | 02:52 | |
*** Leo_m has quit IRC | 04:14 | |
*** Leo_m_ has joined #openstack-dns | 04:14 | |
*** Leo_m has joined #openstack-dns | 04:15 | |
*** Leo_m_ has quit IRC | 04:19 | |
*** masber has quit IRC | 04:29 | |
*** Leo_m has quit IRC | 04:34 | |
*** Leo_m has joined #openstack-dns | 04:34 | |
*** AlexeyAbashkin has joined #openstack-dns | 04:48 | |
*** pcaruana has joined #openstack-dns | 05:20 | |
*** AlexeyAbashkin has quit IRC | 05:51 | |
*** AlexeyAbashkin has joined #openstack-dns | 06:01 | |
*** Alexey_Abashkin has joined #openstack-dns | 06:13 | |
*** AlexeyAbashkin has quit IRC | 06:15 | |
*** Alexey_Abashkin is now known as AlexeyAbashkin | 06:15 | |
*** sapcc-bot1 has joined #openstack-dns | 06:29 | |
*** sapcc-bot1 has quit IRC | 06:30 | |
*** sapcc-bot1 has joined #openstack-dns | 06:30 | |
*** sapcc-bot1 has quit IRC | 06:31 | |
*** sapcc-bot1 has joined #openstack-dns | 06:31 | |
*** sapcc-bot1 has quit IRC | 06:32 | |
*** sapcc-bot1 has joined #openstack-dns | 06:32 | |
*** sapcc-bot1 has quit IRC | 06:33 | |
*** sapcc-bot1 has joined #openstack-dns | 06:33 | |
*** AlexeyAbashkin has quit IRC | 06:33 | |
*** sapcc-bot1 has quit IRC | 06:34 | |
*** sapcc-bot1 has joined #openstack-dns | 06:34 | |
*** sapcc-bot1 has quit IRC | 06:35 | |
*** sapcc-bot1 has joined #openstack-dns | 06:35 | |
*** sapcc-bot1 has quit IRC | 06:36 | |
*** sapcc-bot1 has joined #openstack-dns | 06:36 | |
*** sapcc-bot1 has quit IRC | 06:37 | |
*** sapcc-bot has quit IRC | 07:05 | |
*** sapcc-bot has joined #openstack-dns | 07:07 | |
*** d063130_ has joined #openstack-dns | 07:09 | |
*** Shadowphax has joined #openstack-dns | 07:26 | |
*** diman1 has joined #openstack-dns | 08:20 | |
*** mannamne has joined #openstack-dns | 10:07 | |
*** Shadowphax has quit IRC | 11:19 | |
*** Shadowphax has joined #openstack-dns | 11:19 | |
*** rfreire has joined #openstack-dns | 11:26 | |
*** briner has joined #openstack-dns | 11:38 | |
*** briner_ has joined #openstack-dns | 11:41 | |
*** briner has quit IRC | 11:43 | |
*** peereb has joined #openstack-dns | 12:46 | |
*** openstackgerrit has quit IRC | 12:49 | |
*** briner_ has quit IRC | 13:18 | |
*** briner has joined #openstack-dns | 13:27 | |
*** bnemec has joined #openstack-dns | 13:46 | |
*** bnemec is now known as beekneemech | 13:46 | |
*** Shadowphax has quit IRC | 14:05 | |
*** jafeha has quit IRC | 14:22 | |
*** mannamne has quit IRC | 14:34 | |
*** diman1 has quit IRC | 14:40 | |
*** Leo_m_ has joined #openstack-dns | 14:44 | |
*** Leo_m has quit IRC | 14:47 | |
*** briner has quit IRC | 15:11 | |
*** openstack has quit IRC | 15:22 | |
*** openstack has joined #openstack-dns | 15:23 | |
*** ChanServ sets mode: +o openstack | 15:23 | |
*** rpittau has quit IRC | 15:23 | |
beekneemech | Another incoming DNS newbie question... | 15:32 |
---|---|---|
beekneemech | I'm trying to test my authoritative Designate server locally. | 15:32 |
beekneemech | I set up a standalone BIND with an NS record pointing at the Designate BIND. | 15:33 |
beekneemech | It's not working, and I read something that suggested maybe it's not possible to fake NS records this way. | 15:33 |
rfreire | beekneemech, o/ | 15:33 |
beekneemech | Do I need to register a test domain globally or is there some way I can get this working in isolation? | 15:34 |
rfreire | beekneemech, so let me see if I have understood: | 15:34 |
beekneemech | rfreire: o/ | 15:34 |
rfreire | You have: | 15:34 |
rfreire | client -> Your default DNS server -> Designate BIND server | 15:34 |
rfreire | beekneemech, is my understanding correcT? | 15:35 |
* rfreire fires up his test environment | 15:35 | |
beekneemech | rfreire: Right, although the "default" server is actually a standalone local BIND that I stood up for this testing, so I have complete control over it. | 15:37 |
rfreire | beekneemech, sweet. | 15:37 |
rfreire | beekneemech, so have you delegated the subzone at your standalone to your Designate server? | 15:37 |
rfreire | like: | 15:38 |
beekneemech | rfreire: I have tried to. :-) | 15:38 |
rfreire | $ dig NS @standalone designate.sub.zone | 15:38 |
rfreire | whats the result? | 15:38 |
beekneemech | http://paste.openstack.org/show/724602/ | 15:39 |
* rfreire mira | 15:39 | |
beekneemech | (I tried a made up tld this morning to see if it made any difference, but it didn't) | 15:39 |
rfreire | beekneemech, nice. Now try. | 15:40 |
beekneemech | I also made the local server authoritative for ns1-1.example.org since I had deployed designate with the example pool file. | 15:40 |
rfreire | beekneemech, use dig NS | 15:40 |
rfreire | please | 15:40 |
rfreire | dig NS @11.2.2.3 cloud.foo.fooxample | 15:40 |
rfreire | beekneemech, example: | 15:41 |
rfreire | -- | 15:41 |
rfreire | [root@aa10-cont1 ~(keystone_admin)]# dig +short NS @172.25.250.128 openstack.rf01.co | 15:41 |
rfreire | dns02.interna.rf01.co. | 15:41 |
rfreire | dns01.interna.rf01.co. | 15:41 |
rfreire | -- | 15:41 |
rfreire | beekneemech, next step, in order to it be able to work, it should also resolve the NS for the zone. | 15:42 |
rfreire | See: | 15:42 |
rfreire | -- | 15:42 |
rfreire | [root@aa10-cont1 ~(keystone_admin)]# dig +short A dns02.interna.rf01.co. | 15:42 |
rfreire | 172.25.250.130 | 15:42 |
rfreire | -- | 15:42 |
beekneemech | rfreire: Yeah, I get nothing from that. | 15:42 |
rfreire | beekneemech, so your delegation is not correctly done | 15:43 |
rfreire | beekneemech, can you share a paste of your zone config? | 15:43 |
rfreire | the db file | 15:43 |
rfreire | (where the delegation would be done) | 15:43 |
beekneemech | http://paste.openstack.org/show/724603/ | 15:44 |
* rfreire mira | 15:44 | |
rfreire | beekneemech, I'm assuming foo.fooxample is the designate subzone? | 15:45 |
beekneemech | rfreire: Yeah | 15:45 |
rfreire | beekneemech, well, then you will have to set a forwarder instead. No need to create a zone. | 15:46 |
rfreire | UNLESS if you wanted to create, for instance; mycloudzone.foo.fooxample.com | 15:46 |
rfreire | THEN you would have: | 15:46 |
rfreire | mycloudzone IN NS ns1-1.example.org. | 15:46 |
rfreire | -- | 15:47 |
rfreire | Edit your named.conf and move it to: | 15:47 |
rfreire | -- | 15:47 |
rfreire | zone "foo.fooxample" { | 15:47 |
rfreire | type forward; | 15:47 |
rfreire | forwarders { <designate bind ip address>; }; | 15:47 |
rfreire | }; | 15:47 |
rfreire | -- | 15:47 |
rfreire | Go for it | 15:47 |
beekneemech | rfreire: I'm trying to replicate a production deployment in my local environment. Is that a how a typical user would set things up? | 15:51 |
beekneemech | I want to have something that looks and acts like production. | 15:51 |
beekneemech | Or as much like production as possible anyway. | 15:52 |
rfreire | beekneemech, hold on a sec | 16:04 |
rfreire | phone call | 16:04 |
*** beekneemech has quit IRC | 16:09 | |
*** mugsie has quit IRC | 16:09 | |
*** zigo has quit IRC | 16:09 | |
*** baffle has quit IRC | 16:09 | |
*** Shadowphax has joined #openstack-dns | 16:12 | |
*** beekneemech has joined #openstack-dns | 16:14 | |
*** mugsie has joined #openstack-dns | 16:14 | |
*** zigo has joined #openstack-dns | 16:14 | |
*** baffle has joined #openstack-dns | 16:14 | |
*** keithmnemonic[m] has quit IRC | 16:17 | |
*** vinhags[m] has quit IRC | 16:17 | |
rfreire | beekneemech, so network is put back again | 16:26 |
rfreire | beekneemech, what do I see around | 16:26 |
rfreire | Let example.com <---- The root zone of the company | 16:26 |
rfreire | Example.com has several subdomains, including some that they want to be managed by designate. | 16:27 |
rfreire | So, in example.com we would have: | 16:27 |
rfreire | cloudsubdomain.example.com IN NS designate-bind.servers.example.com. | 16:27 |
rfreire | So see what we have here up to this moment three entirely different zones: | 16:28 |
rfreire | 1. the root example.com | 16:28 |
rfreire | 2. The servers.example.com where the BIND server resides | 16:28 |
rfreire | 3. And then finally, the cloudsubdomain.example.com which is going to be managed by Designate. | 16:28 |
*** Shadowphax has quit IRC | 16:32 | |
beekneemech | rfreire: So maybe my problem is thinking that Designate should manage the root domain, when I should just be giving it a subdomain? | 16:33 |
rfreire | beekneemech, THERE! | 16:33 |
rfreire | beekneemech, unless some other higher root can point the queries toward your Designate server | 16:34 |
*** Shadowphax has joined #openstack-dns | 16:34 | |
rfreire | Like, a public domain from godaddy for example? | 16:35 |
beekneemech | rfreire: Okay, thanks. I'll mess around with this for a while then. | 16:35 |
rfreire | Then godaddy is the higher root and will point toward your BIND server | 16:35 |
beekneemech | rfreire: Yeah, I was trying to avoid that and basically set up my own little private registrar, but I'll try the simpler method first. | 16:36 |
rfreire | hope I have helped beekneemech o/ | 16:36 |
*** pcaruana has quit IRC | 16:40 | |
*** Shadowphax has quit IRC | 16:51 | |
*** Shadowphax has joined #openstack-dns | 16:53 | |
*** keithmnemonic[m] has joined #openstack-dns | 17:00 | |
*** openstack has quit IRC | 17:11 | |
*** openstack has joined #openstack-dns | 17:12 | |
*** ChanServ sets mode: +o openstack | 17:12 | |
*** kbyrne has quit IRC | 18:14 | |
beekneemech | rfreire: Using a subdomain did the trick. Thanks! | 18:32 |
rfreire | beekneemech, YAY | 18:32 |
rfreire | o/ | 18:32 |
rfreire | beekneemech, oh wow Ben, that is you :-P | 18:33 |
* rfreire bothered to run the /whois just like now | 18:33 | |
rfreire | haha | 18:33 |
beekneemech | rfreire: Casual nick friday. ;-) | 18:33 |
rfreire | NICE | 18:34 |
rfreire | ;-D | 18:34 |
*** idlemind has joined #openstack-dns | 18:37 | |
*** peereb has quit IRC | 19:07 | |
*** Shadowphax has quit IRC | 19:29 | |
*** renmak has joined #openstack-dns | 20:53 | |
*** renmak_ has joined #openstack-dns | 20:53 | |
*** openstackgerrit has joined #openstack-dns | 21:11 | |
*** ChanServ sets mode: +v openstackgerrit | 21:11 | |
openstackgerrit | Ben Nemec proposed openstack/python-designateclient master: Fix copy-pasta in quota command descriptions https://review.openstack.org/579285 | 21:11 |
openstackgerrit | Ben Nemec proposed openstack/python-designateclient master: Fix copy-pasta in quota command descriptions https://review.openstack.org/579285 | 21:13 |
*** rfreire has quit IRC | 21:28 | |
*** beekneemech has quit IRC | 22:34 | |
*** renmak has quit IRC | 23:08 | |
*** renmak_ has quit IRC | 23:08 | |
*** Leo_m_ has quit IRC | 23:21 | |
*** Leo_m has joined #openstack-dns | 23:21 | |
*** renmak has joined #openstack-dns | 23:42 | |
*** renmak_ has joined #openstack-dns | 23:42 | |
*** renmak has quit IRC | 23:50 | |
*** renmak_ has quit IRC | 23:50 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!