*** Leo_m_ has quit IRC | 00:00 | |
*** abaindur has quit IRC | 00:43 | |
*** abaindur has joined #openstack-dns | 00:44 | |
*** abaindur_ has joined #openstack-dns | 00:47 | |
*** abaindur has quit IRC | 00:48 | |
*** abaindur_ has quit IRC | 01:09 | |
Krenair | In Horizon when I go to create a record set there's no option for the NS type. Is that normal? | 01:35 |
---|---|---|
Krenair | -> https://bugs.launchpad.net/designate-dashboard/+bug/1791865 | 02:03 |
openstack | Launchpad bug 1791865 in Designate Dashboard "Can't create NS record?" [Undecided,New] | 02:03 |
*** kiall has joined #openstack-dns | 04:12 | |
*** kiall has joined #openstack-dns | 04:12 | |
*** pcaruana has joined #openstack-dns | 05:00 | |
*** pcaruana has quit IRC | 05:09 | |
*** AlexeyAbashkin has joined #openstack-dns | 06:06 | |
*** AlexeyAbashkin has quit IRC | 06:10 | |
*** Emine has quit IRC | 06:32 | |
*** ginopc has joined #openstack-dns | 07:10 | |
*** pcaruana has joined #openstack-dns | 07:13 | |
*** ginopc has quit IRC | 07:54 | |
*** ginopc has joined #openstack-dns | 07:54 | |
*** AlexeyAbashkin has joined #openstack-dns | 08:01 | |
*** Emine has joined #openstack-dns | 08:31 | |
*** trident has quit IRC | 09:15 | |
*** trident has joined #openstack-dns | 09:16 | |
*** bnemec has quit IRC | 09:49 | |
*** rpittau has joined #openstack-dns | 10:20 | |
*** rpittau has quit IRC | 10:21 | |
*** rpittau has joined #openstack-dns | 10:21 | |
*** trungnv has quit IRC | 10:50 | |
*** trungnv has joined #openstack-dns | 10:51 | |
*** ircuser-1 has joined #openstack-dns | 11:00 | |
*** ginopc has quit IRC | 12:58 | |
*** ginopc has joined #openstack-dns | 13:03 | |
*** bnemec has joined #openstack-dns | 14:20 | |
*** Leo_m has joined #openstack-dns | 14:29 | |
*** bnemec has quit IRC | 14:39 | |
*** sapd1_ has joined #openstack-dns | 14:44 | |
*** pcaruana has quit IRC | 14:47 | |
*** bnemec has joined #openstack-dns | 15:08 | |
*** aniketh has joined #openstack-dns | 15:23 | |
*** Emine has quit IRC | 15:44 | |
*** ginopc has quit IRC | 15:57 | |
*** joshkelly has joined #openstack-dns | 16:50 | |
joshkelly | Hi everybody, I'm new here. I have a question about an issue I'm running into with a 2nd Designate host and BIND9 | 16:53 |
joshkelly | what happened was we changed the host we are running designate worker and mdns on. The first one went down, we brought up a 2nd designate worker/mdns host. Now the zones that were created using the 1st Designate host are in Error and only new zones created with the 2nd Designate host are working. We are also seeing notify refused from non-master on the bind server. I have set allow-notify{designate ho | 17:02 |
joshkelly | st ip}, but no luck. | 17:02 |
joshkelly | Similarily, how does this work when we have multiple designate workers/mdns's? Which one is the master? | 17:02 |
*** bnemec has quit IRC | 17:09 | |
*** AlexeyAbashkin has quit IRC | 17:09 | |
*** sapd1_ has quit IRC | 17:13 | |
*** bnemec has joined #openstack-dns | 17:13 | |
*** Leo_m has quit IRC | 17:17 | |
*** pcaruana has joined #openstack-dns | 17:32 | |
*** abaindur has joined #openstack-dns | 18:04 | |
devx | in my limited experience all dns servers have to be up | 18:22 |
*** joshkelly has quit IRC | 18:27 | |
*** joshkelly has joined #openstack-dns | 18:35 | |
*** bnemec has quit IRC | 18:40 | |
joshkelly | @devx The issue is that the first Designate host was removed due to h/w issues and won't be coming back online anytime soon. | 18:41 |
*** Leo_m has joined #openstack-dns | 18:41 | |
*** briner has joined #openstack-dns | 18:45 | |
*** joshkelly has quit IRC | 19:05 | |
*** joshkelly has joined #openstack-dns | 19:06 | |
abaindur | devx: similarily, how does this work when we have multiple designate workers/mdns's? Which one is the master? Wouldn't the bind server receive NOTIFYs and zone transfers from different IPs? | 19:31 |
*** briner has quit IRC | 19:35 | |
mugsie | abaindur: you would usually have mulitple masters | 19:42 |
mugsie | joshkelly: the allow-notfiy should be working on bind | 19:42 |
abaindur | What if as joshkelly mentioned, one went away and we had to replace them (or all) with different hosts | 19:42 |
abaindur | in thise case, we updated the pools.yaml to have IPs of new designate hosts, re-ran db sync command | 19:43 |
mugsie | you may have to loop through the zones on the bind server to update the masters | 19:43 |
abaindur | pre-existing zones error out in bind saying refused from non-master | 19:43 |
abaindur | but new zones create fine | 19:43 |
abaindur | mugsie: thanks, thats what i figured. any idea how to exactly do that? "loop through the zones on the bind server" - do you mean manually edit the bind zone files? | 19:44 |
mugsie | unfortunately, i think so | 19:44 |
mugsie | there may be a global setting | 19:44 |
mugsie | let me hve a look | 19:45 |
abaindur | I guess it makes sense from a security point of view... im a bind DNS server previously talking to server A. I wouldn't all of a sudden trust IP B sending me DNS packets | 19:45 |
mugsie | abaindur: it looks like it has to be manual :/ | 19:46 |
mugsie | yeah | 19:46 |
abaindur | manual meaning editng the zone files? | 19:46 |
abaindur | ok we'll have to look into that... haven't mucked around with bind manually much | 19:46 |
abaindur | mugsie: also had a question about zone imports/exports. As I understand, this is just to import into designate's DB the zones/records from another Openstack/designate deployment | 19:47 |
abaindur | ? | 19:47 |
abaindur | basically move from one cloud deployment into another? | 19:48 |
mugsie | or other DNS servers - it imprts and exports a standard text/dns formatted file | 19:48 |
mugsie | nearly all DNS servers can import and export from this format | 19:48 |
mugsie | it also allows for point in time backup | 19:49 |
abaindur | ah ok. thats where i hit same issue joshkelly described. I exported a zone from one Openstack cloud, imported into another. Designate loaded all the zones and records, but I was unable to add any records to them with same "refused notify from non master" | 19:49 |
abaindur | because bind still thought master was the old cloud | 19:49 |
abaindur | mugsie: one more ? | 19:52 |
mugsie | sure :) | 19:53 |
abaindur | what does then the allow-notify { any }; do in bind? | 19:53 |
abaindur | allow-transfer any as well | 19:53 |
mugsie | it is supposed to be a setting that allows any node to say "go pull the latest zone data from your master" | 19:53 |
mugsie | but, I have never seen it work | 19:54 |
abaindur | This is in the named.conf file. I believe I tried changing that to any, but still saw the same error So I guess it does something completely different | 19:54 |
mugsie | the allow-transfer allows any other client to do a AFXR pull from bind | 19:54 |
mugsie | this would allow anyone to see all your records | 19:54 |
abaindur | ah | 19:55 |
*** pcaruana has quit IRC | 19:55 | |
mugsie | anyone could do `dig AFXR zone.tld @bind-ip` to get all records | 19:56 |
mugsie | abaindur: oh - if a zone also has a "allow-notify" block it could be overriding the one in named.conf | 19:58 |
joshkelly | mugsie: Thank you! This is really helpful | 20:05 |
mugsie | joshkelly: no problem | 20:08 |
joshkelly | If we want to run multiple designate hosts then how would we need to configure the environment so that all designate hosts can notify the BIND servers? Essentially add all IPs to the zone allow-notify. | 20:17 |
mugsie | yeah, that can be set in the pools.yaml | 20:21 |
*** bnemec has joined #openstack-dns | 20:23 | |
mugsie | just add extra masters in the targets section | 20:25 |
devx | mugsie are you available to sync up about designate integration with nuetron & nova? | 20:26 |
mugsie | devx: I am | 20:26 |
mugsie | does 3:30pm suit? | 20:26 |
devx | sure | 20:27 |
devx | we can meet by registration if you want. then figure out where to go | 20:29 |
mugsie | devx: I just booked ballroom C | 20:30 |
devx | ok see you there | 20:30 |
*** bnemec has quit IRC | 21:17 | |
*** Leo_m_ has joined #openstack-dns | 21:20 | |
*** bnemec has joined #openstack-dns | 21:21 | |
*** Leo_m_ has quit IRC | 21:22 | |
*** Leo_m has quit IRC | 21:22 | |
*** aniketh has quit IRC | 21:27 | |
mugsie | devx: https://docs.openstack.org/neutron/latest/admin/config-dns-int-ext-serv.html | 21:27 |
mugsie | devx: https://launchpad.net/~grahamhayes/+sshkeys | 21:43 |
d34dh0r53 | devx: curl -O https://github.com/d34dh0r53.keys >> ~/.ssh/authorized_keys | 21:43 |
*** Emine has joined #openstack-dns | 21:45 | |
devx | 65.61.151.110 | 21:45 |
*** Emine has quit IRC | 21:49 | |
*** bnemec has quit IRC | 22:17 | |
*** joshkell_ has joined #openstack-dns | 23:22 | |
*** joshkelly has quit IRC | 23:25 | |
*** joshkell_ has quit IRC | 23:42 | |
*** joshkelly has joined #openstack-dns | 23:43 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!