*** goldyfruit has quit IRC | 00:57 | |
*** goldyfruit has joined #openstack-dns | 00:57 | |
*** goldyfruit has quit IRC | 00:57 | |
*** abaindur has quit IRC | 01:10 | |
*** abaindur has joined #openstack-dns | 01:11 | |
*** abaindur has quit IRC | 01:17 | |
*** abaindur has joined #openstack-dns | 05:36 | |
*** pcaruana has joined #openstack-dns | 06:19 | |
*** ivve has joined #openstack-dns | 06:53 | |
*** ginopc has joined #openstack-dns | 08:08 | |
*** awalende has joined #openstack-dns | 08:09 | |
*** abaindur has quit IRC | 08:31 | |
*** FlorianFa has joined #openstack-dns | 09:23 | |
*** Emine has joined #openstack-dns | 09:53 | |
*** awalende has quit IRC | 12:43 | |
*** awalende has joined #openstack-dns | 12:45 | |
*** goldyfruit has joined #openstack-dns | 13:50 | |
goldyfruit | Hi guys | 13:55 |
---|---|---|
goldyfruit | Since few days now I'm in a fight with Designate ^^ | 13:56 |
goldyfruit | I got this error: While checking domain freshness: Query to '10.121.135.11:5354' for SOA of 'pouet5.com.' produced no results (RCode: Query Refused) from PowerDNS | 13:56 |
goldyfruit | But I got the same issue with Bind | 13:56 |
*** Emine has quit IRC | 13:59 | |
goldyfruit | In MDNS logs I got this: | 14:00 |
goldyfruit | 2019-03-13 13:57:58.449 31 WARNING designate.mdns.handler [req-72f06c25-8aa0-4999-b3f0-158cb90e3512 - - - - -] ZoneNotFound while handling query request. Question was pouet5.com. IN SOA: ZoneNotFound: Could not find Zone | 14:00 |
*** Emine has joined #openstack-dns | 14:08 | |
*** irclogbot_0 has quit IRC | 14:09 | |
*** irclogbot_0 has joined #openstack-dns | 14:13 | |
*** faridda has joined #openstack-dns | 14:16 | |
*** bnemec has quit IRC | 14:22 | |
*** Emine has quit IRC | 14:24 | |
*** Emine has joined #openstack-dns | 14:24 | |
*** irclogbot_0 has quit IRC | 14:25 | |
*** bnemec has joined #openstack-dns | 14:27 | |
*** irclogbot_0 has joined #openstack-dns | 14:28 | |
openstackgerrit | Jens Harbott (frickler) proposed openstack/designate-tempest-plugin master: Properly quote TXT/SPF sample data https://review.openstack.org/617809 | 14:40 |
goldyfruit | It's seems to be related to pool-manager and the pool_id value | 15:17 |
gmann | frickler: thanks for looking into designate failure for legacy job on bionic. | 15:19 |
gmann | today is deadline so last step i will do is to make those failed jobs as n-v before we merge the base job patches. | 15:19 |
frickler | gmann: I hope we should be able to fix these soon, no need to add additional stuff on the designate side | 15:24 |
gmann | frickler: perfect. | 15:24 |
frickler | gmann: also we really should move these away from legacy | 15:24 |
gmann | yeah that is best way. | 15:25 |
*** awalende has quit IRC | 15:28 | |
goldyfruit | Is there any documentation about pool_target section ? | 15:29 |
*** ginopc has quit IRC | 15:33 | |
*** ginopc has joined #openstack-dns | 15:35 | |
goldyfruit | How the pools.yaml file and this https://github.com/openstack/designate/blob/056ceb7f4ba4a4b86fe212aa31a7506ac1b27f20/designate/pool_manager/__init__.py#L29 interact when you have multiple pools ? | 15:36 |
*** irclogbot_0 has quit IRC | 15:36 | |
mugsie | goldyfruit: if you are running pool manger (and not designate-producer and -worker) you need a pool manager instance per pool | 15:37 |
goldyfruit | :o !! | 15:38 |
mugsie | so 2 pools, 2 instances of pool manager, and each one will have a different pool-id in its config | 15:38 |
mugsie | it was part of the re-arch that we did when we went to designate-worker and producer - we broke the direct link between pool-managers and pools | 15:38 |
*** irclogbot_0 has joined #openstack-dns | 15:40 | |
goldyfruit | mugsie: Thanks !!!! | 15:40 |
mugsie | frickler: is it pdns install issues, or something elese? | 15:40 |
*** irclogbot_0 has quit IRC | 15:49 | |
*** irclogbot_0 has joined #openstack-dns | 15:51 | |
*** irclogbot_0 has quit IRC | 15:52 | |
*** irclogbot_0 has joined #openstack-dns | 15:57 | |
*** Emine has quit IRC | 16:20 | |
goldyfruit | mugsie: we enabled the producer but still no working with multi pools | 16:23 |
mugsie | can I see logs from producer and worker? | 16:24 |
goldyfruit | mugsie: there is not logs related to the zone creation in the producer | 16:24 |
mugsie | there wont be - the worker is where that will be | 16:25 |
goldyfruit | Let me give you that | 16:26 |
mugsie | and a copy of pools.yaml would hel | 16:27 |
mugsie | and a copy of pools.yaml would help* | 16:27 |
frickler | mugsie: looks like pnds might not be running, but it also looks like we don't have logs for that, so hopefully the held node will tell more. if it gets more complicated, I'll look into moving away from legacy instead | 16:33 |
mugsie | frickler: cool. if you need anything - shout. I have some free time today | 16:33 |
goldyfruit | mugsie: I sent you the logs in DM | 16:35 |
*** abaindur has joined #openstack-dns | 16:36 | |
mugsie | goldyfruit: looking | 16:36 |
goldyfruit | We are using attributes to create zone: openstack zone create --attributes service_tier:pdns --email pouet@toto.com pouet16.com. | 16:37 |
mugsie | goldyfruit: and both pdns servers have a different database behind them? | 16:39 |
goldyfruit | yepo | 16:39 |
goldyfruit | yep* | 16:39 |
*** ivve has quit IRC | 16:40 | |
goldyfruit | mugsie: If I set the pool_id in [service:pool_manager] section with the PDNS pool I'm able to have a zone working | 16:41 |
*** FlorianFa has quit IRC | 16:41 | |
mugsie | weird | 16:42 |
mugsie | Successful CREATE zone pouet16.com. on <PoolTarget id:' ... | 16:42 |
mugsie | and in the powerdns DB, is there any rows in the domains table/ | 16:43 |
mugsie | ?* | 16:43 |
goldyfruit | Yep it's in the database | 16:44 |
*** faridda has quit IRC | 16:44 | |
goldyfruit | pdnsutils list-all-zones | 16:44 |
goldyfruit | pouet16.com | 16:44 |
goldyfruit | All zonecount: 1 | 16:45 |
goldyfruit | But pdnsutil list-zone pouet16.com. said no serial | 16:45 |
goldyfruit | Mar 13 16:45:16 No serial for 'pouet16.com' found - zone is missing? | 16:45 |
mugsie | yeah - those masters are different - do you have different mdns servers for each pool? | 16:46 |
*** faridda has joined #openstack-dns | 16:46 | |
goldyfruit | mugsie: nop, just public and private IPS but they are the same | 16:47 |
goldyfruit | PDNS pool are DNS outside the platform | 16:47 |
mugsie | and can you dig @<public IP> -p 5354 pouet16.com SOA | 16:48 |
goldyfruit | Pasted in DM | 16:49 |
goldyfruit | Same, I got REFUSED | 16:49 |
*** eandersson_ is now known as eandersson | 16:54 | |
*** faridda has quit IRC | 16:54 | |
*** FlorianFa has joined #openstack-dns | 16:54 | |
*** faridda has joined #openstack-dns | 17:14 | |
*** faridda has quit IRC | 17:39 | |
frickler | mugsie: seems there is a new or missing filter on the pdns api webserver, adding "webserver-allow-from=$HOSTIP" fixed the node. maybe you can come up with a patch for that, otherwise I'll continue tomorrow | 17:40 |
frickler | mugsie: this was repeting itself in the log before: pdns_server[25355]: Webserver closing socket: remote (162.209.77.54) does not match 'webserver-allow-from' | 17:41 |
*** faridda has joined #openstack-dns | 17:43 | |
*** goldyfruit has quit IRC | 17:46 | |
mugsie | frickler: Oh, OK, I can look at that now | 17:47 |
*** ginopc has quit IRC | 17:47 | |
mugsie | frickler: https://doc.powerdns.com/authoritative/settings.html#setting-webserver-allow-from | 17:49 |
mugsie | > Changed in version 4.1.0: Default is now 127.0.0.1,::1, was 0.0.0.0/0,::/0 before. | 17:50 |
*** goldyfruit has joined #openstack-dns | 17:50 | |
*** ianychoi has quit IRC | 17:55 | |
openstackgerrit | Graham Hayes proposed openstack/designate master: Allow non localhost connections to pdns api https://review.openstack.org/643119 | 18:03 |
openstackgerrit | Graham Hayes proposed openstack/designate master: DNM: Testing PDNS Fix https://review.openstack.org/643127 | 18:11 |
*** abaindur has quit IRC | 18:18 | |
*** faridda has quit IRC | 18:18 | |
*** abaindur has joined #openstack-dns | 18:19 | |
*** abaindur has quit IRC | 18:20 | |
*** rektide has joined #openstack-dns | 18:20 | |
*** abaindur has joined #openstack-dns | 18:26 | |
*** pcaruana has quit IRC | 18:29 | |
*** abaindur has quit IRC | 18:31 | |
*** Emine has joined #openstack-dns | 18:33 | |
*** faridda has joined #openstack-dns | 18:36 | |
*** gmann is now known as gmann_afk | 18:48 | |
*** faridda has quit IRC | 18:58 | |
*** emine__ has joined #openstack-dns | 19:12 | |
*** Emine has quit IRC | 19:13 | |
*** faridda has joined #openstack-dns | 19:22 | |
*** salmankhan has joined #openstack-dns | 19:27 | |
*** faridda has quit IRC | 19:30 | |
*** abaindur has joined #openstack-dns | 19:36 | |
*** faridda has joined #openstack-dns | 19:37 | |
*** faridda has quit IRC | 19:50 | |
mugsie | frickler: eandersson: can we get https://review.openstack.org/#/c/643119/ merged asap? If fails on grenade (because grenade takes HEAD^1 and runs tempest against it before upgrading - and when we move to bionic in a few hours we will be blocked - see https://review.openstack.org/643119 ) | 19:51 |
*** salmankhan has quit IRC | 19:59 | |
*** faridda has joined #openstack-dns | 20:06 | |
*** ivve has joined #openstack-dns | 20:15 | |
goldyfruit | mugsie: does the pool manager is disable when producer is running ? | 20:16 |
goldyfruit | how could we disable pool-manager ? | 20:16 |
goldyfruit | we don't have services running as designate-pool-manager | 20:16 |
mugsie | what services do you have running? | 20:16 |
goldyfruit | designate_backend_bind9 designate_sink designate_worker designate_mdns designate_producer designate_central designate_api | 20:18 |
goldyfruit | bind9 backend is for the first pool | 20:18 |
mugsie | that looks right | 20:20 |
goldyfruit | so having TSIG is a requirement when you have external dns servers ? | 20:21 |
mugsie | when you have 2 pools | 20:21 |
mugsie | it is how minidns knows how pool it should look for results from | 20:22 |
mugsie | s/how/what/ | 20:22 |
goldyfruit | so mdns is running tsigkey list command et get the id of resource_id ? | 20:23 |
mugsie | kind of, there is an internal API it uses | 20:23 |
goldyfruit | so mdns doens't need any configuration about tsig ? | 20:24 |
mugsie | no, it should get if from the DB each time it gets a request | 20:30 |
goldyfruit | So which component is using attributes ? | 20:36 |
goldyfruit | We are already using attributes like "service_tier:pdns" to request a zone creation on a specific pool | 20:37 |
mugsie | just the API and the scheduler | 20:39 |
goldyfruit | Ok | 20:40 |
goldyfruit | scheduler is part of which component ? | 20:40 |
*** gmann_afk is now known as gmann | 20:41 | |
goldyfruit | With producer and worker do need to have the information in designate.conf about pool_manager_cache:sqlalchemy, pool_manager_cache:memcache, service:pool_manager ? | 20:42 |
mugsie | nope | 20:43 |
mugsie | scheduler is in the central service I think | 20:43 |
goldyfruit | With multipool, is it ok to have default_pool_id = 6799d8f3-3064-4213-8aa5-d2295b8f4c29 in service:central section ? | 20:44 |
goldyfruit | (I'm asking a lot of questions, thanks for your help !!!) | 20:45 |
mugsie | yeh, we load that fro when there is no attributes | 20:45 |
mugsie | https://opendev.org/openstack/designate/src/branch/master/designate/central/service.py#L856 | 20:45 |
mugsie | we use thee two by default - https://opendev.org/openstack/designate/src/branch/master/designate/scheduler/filters/default_pool_filter.py | 20:45 |
mugsie | https://opendev.org/openstack/designate/src/branch/master/designate/scheduler/filters/attribute_filter.py | 20:46 |
goldyfruit | I running out of idea ^^ | 20:48 |
goldyfruit | Thanks for your help mugsie | 20:48 |
goldyfruit | I'll continue to check | 20:48 |
mugsie | goldyfruit: can you try to add an extra log line in this function- https://opendev.org/openstack/designate/src/branch/master/designate/mdns/handler.py#L176 ? | 20:50 |
mugsie | see if it is being called | 20:50 |
goldyfruit | Doing that | 20:51 |
mugsie | https://opendev.org/openstack/designate/src/branch/master/designate/dnsutils.py#L146 is a good candidate as well | 20:51 |
mugsie | sorry, it has been so long since I looked at some of this code | 20:52 |
mugsie | and kiall made spread out all over the place -_- | 20:52 |
mugsie | made it* | 20:52 |
mugsie | goldyfruit: I am leaving the office, so leave a comment here, of on the mailing list, and I will look at it when I get online lter | 20:54 |
mugsie | later* | 20:54 |
goldyfruit | mugsie: thanks again :) | 20:54 |
mugsie | np | 20:54 |
*** faridda has quit IRC | 21:08 | |
*** ivve has quit IRC | 21:20 | |
*** faridda has joined #openstack-dns | 21:25 | |
*** faridda has quit IRC | 21:38 | |
openstackgerrit | Merged openstack/designate master: Allow non localhost connections to pdns api https://review.openstack.org/643119 | 22:16 |
*** goldyfruit has quit IRC | 22:36 | |
*** salmankhan has joined #openstack-dns | 22:55 | |
*** goldyfruit has joined #openstack-dns | 22:56 | |
*** faridda has joined #openstack-dns | 23:02 | |
*** ianychoi has joined #openstack-dns | 23:06 | |
*** faridda has quit IRC | 23:17 | |
*** abaindur has quit IRC | 23:41 | |
*** abaindur has joined #openstack-dns | 23:42 | |
*** abaindur has quit IRC | 23:47 | |
*** faridda has joined #openstack-dns | 23:55 | |
*** faridda has quit IRC | 23:56 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!