*** kgaillot has quit IRC | 01:01 | |
*** hfu has joined #openstack-ha | 01:27 | |
*** openstackgerrit has joined #openstack-ha | 02:05 | |
openstackgerrit | Adam Spiers proposed openstack/openstack-resource-agents-specs: add compute node monitoring spec https://review.openstack.org/406659 | 02:05 |
---|---|---|
*** g3ek has quit IRC | 05:33 | |
*** g3ek has joined #openstack-ha | 05:42 | |
*** pcaruana has joined #openstack-ha | 06:51 | |
*** nkrinner_afk has quit IRC | 06:59 | |
*** nkrinner has joined #openstack-ha | 06:59 | |
*** mjura has joined #openstack-ha | 07:12 | |
*** rmart04 has joined #openstack-ha | 08:21 | |
*** hfu has quit IRC | 08:29 | |
*** hfu has joined #openstack-ha | 08:35 | |
aspiers | hi | 09:00 |
aspiers | -> #openstack-meeting-alt | 09:00 |
aspiers | OK, everyone else still on vacation I guess | 09:26 |
ddeja | oh, wait | 09:26 |
ddeja | aspiers: it is Wednesday today | 09:27 |
ddeja | shieeet | 09:27 |
aspiers | :) | 09:27 |
* ddeja is confused all week long | 09:27 | |
ddeja | and there is holiday on Friday in Poland, to confuse me more | 09:27 |
ddeja | aspiers: I saw your comment about message context | 09:28 |
ddeja | we can talk about it if you want | 09:28 |
ddeja | so, basically you are right | 09:29 |
ddeja | what you've copied from fence_evacuate is all what matters from the user perspective | 09:29 |
aspiers | ok | 09:30 |
ddeja | but since we were talking about HTTP message, I thought that other things, like keystone context, also matters | 09:30 |
aspiers | yeah, when I thought about that I realised that the HTTP message should be verifiable | 09:30 |
aspiers | it should not be possible to spoof failure messages | 09:31 |
aspiers | otherwise we rely on the security of the L2 segment | 09:31 |
ddeja | yes | 09:31 |
aspiers | or maybe we already do? | 09:31 |
aspiers | can anyone send messages to Rabbit? presumably not | 09:31 |
ddeja | but, hm | 09:31 |
ddeja | it depends on about which approach we are talking right now | 09:32 |
ddeja | in using just fence agents, we rely on security provided by pacemaker | 09:32 |
ddeja | that noone would send 'false alarm' | 09:32 |
ddeja | on others (Masakari/Mistral), hmm, it just if user can send given HTTP message | 09:33 |
*** ushkalim has joined #openstack-ha | 09:33 | |
* ddeja is not sure if Masakari also uses HTTP message to start an recovery | 09:33 | |
aspiers | hmm | 09:34 |
ddeja | In case of mistral, we rely on security provided by keystone | 09:34 |
*** hfu has quit IRC | 09:37 | |
*** hfu has joined #openstack-ha | 09:40 | |
*** hfu has quit IRC | 09:47 | |
aspiers | ddeja: a fence agent could still use keystone credentials | 09:55 |
aspiers | and I think it should... | 09:56 |
ddeja | aspiers: but for which part it should use keystone? | 10:06 |
aspiers | for sending the message | 10:06 |
aspiers | so that the receiver can authenticate it | 10:07 |
ddeja | umm, I don't think it is needed | 10:07 |
ddeja | oh | 10:07 |
ddeja | well, as long as we use some pythonclient related to any openstack project it works this way, right? | 10:07 |
aspiers | I guess | 10:09 |
ddeja | yes, I've just checked with my teammate | 10:09 |
ddeja | client asks keystone for token, then sends the token with request to given service | 10:09 |
aspiers | that sounds right | 10:10 |
ddeja | and then service checks with keystone if token is valid before it proceeds the requests | 10:10 |
ddeja | so, with mistralclient we are all set | 10:10 |
ddeja | not sure how it works with masakari thou | 10:10 |
aspiers | I imagine it would be the same. If not I guess there is a clear benefit from switching to that method | 10:22 |
aspiers | but I wonder how long the token would be valid for | 10:22 |
ddeja | by default token is valid for 1 hour | 10:23 |
aspiers | ok | 10:25 |
ddeja | if I remember correctly | 10:25 |
ddeja | but it can be set in keystone conf, and also per user/token (I'm not sure for which one) | 10:26 |
*** asettle has joined #openstack-ha | 10:27 | |
aspiers | right | 10:29 |
aspiers | hey asettle :) | 10:30 |
asettle | Morning yo :) | 10:30 |
asettle | Sorry for giving you some bugs there aspiers but my HA knowledge is peanuts | 10:32 |
aspiers | haha no probs :) | 10:32 |
aspiers | asettle: will you be in Atlanta? | 10:32 |
aspiers | I am coming and we could probably make a lot of progress on the HA guide there | 10:32 |
asettle | I think I will be :) we should plan a session. | 10:32 |
aspiers | great | 10:32 |
asettle | (At least, the grand plan is for me to be there) | 10:32 |
asettle | Do the HA team *do* sessions? | 10:33 |
aspiers | no, they didn't let us | 10:34 |
aspiers | since we're not an official team | 10:34 |
asettle | How rude :P | 10:35 |
ddeja | aspiers: but I guess there would be some time to talk, at least on first 2 days | 10:37 |
aspiers | ddeja: are you coming? I thought you weren't | 10:38 |
ddeja | aspiers: that's complicated | 10:39 |
aspiers | oh :) | 10:39 |
ddeja | remember Barcelona? | 10:39 |
ddeja | it will be same story | 10:39 |
aspiers | vaguely. ok :/ | 10:40 |
ddeja | not knowing if I'll go or not for a long time ;/ | 10:40 |
*** furlongm has quit IRC | 10:41 | |
*** furlongm_ has joined #openstack-ha | 10:41 | |
*** ushkalim has quit IRC | 11:33 | |
*** furlongm_ has quit IRC | 11:41 | |
*** furlongm has joined #openstack-ha | 11:43 | |
asettle | ddeja: that's kind of what happens with us too. We more or less find out a few weeks beforehand and then it's all "pack your bags, off you pop" | 11:46 |
*** ushkalim has joined #openstack-ha | 11:47 | |
*** hfu has joined #openstack-ha | 11:49 | |
aspiers | :/ | 11:50 |
*** hfu has quit IRC | 11:50 | |
asettle | Heh, yep. | 11:50 |
asettle | I've spoiled a lot of groceries as a result. | 11:51 |
aspiers | annoying | 11:51 |
aspiers | BTW if anyone's here who is interested in neutron L3 HA, please see the latest comments on https://bugs.launchpad.net/neutron/+bug/1375625 | 11:52 |
openstack | Launchpad bug 1375625 in neutron "Problem in l3-agent tenant-network interface would cause split-brain in HA router" [High,In progress] | 11:52 |
asettle | Quite. | 11:52 |
aspiers | asettle: you'll be pleased to note I'm trying to be diligent about the docs, e.g. 2nd para of https://bugs.launchpad.net/neutron/+bug/1375625/comments/34 :-) | 11:52 |
asettle | Hahaha naw, I'm a wee bit proud | 11:52 |
aspiers | :) | 11:53 |
asettle | I will get you one of the free alcoholic (or non-alcoholic) beverages at the summit | 11:53 |
asettle | I'm generous like that. | 11:53 |
aspiers | this bug is marked as In Progress with High importance, but Assaf seems to think it's a WONTFIX, so there is some disconnect here | 11:53 |
aspiers | deal! | 11:53 |
aspiers | biab | 11:53 |
asettle | Ugh there's so much reading. | 11:54 |
asettle | :p | 11:54 |
*** ushkalim has quit IRC | 12:01 | |
*** ushkalim has joined #openstack-ha | 12:13 | |
*** catintheroof has joined #openstack-ha | 12:14 | |
*** openstackgerrit has quit IRC | 12:33 | |
*** rmart04_ has joined #openstack-ha | 13:05 | |
*** rmart04 has quit IRC | 13:06 | |
*** rmart04_ is now known as rmart04 | 13:06 | |
*** rmart04_ has joined #openstack-ha | 13:14 | |
*** rmart04 has quit IRC | 13:15 | |
*** rmart04_ is now known as rmart04 | 13:15 | |
*** aasmith has joined #openstack-ha | 13:44 | |
*** furlongm has quit IRC | 14:09 | |
*** furlongm has joined #openstack-ha | 14:10 | |
*** kgaillot has joined #openstack-ha | 14:38 | |
*** cleong has joined #openstack-ha | 14:46 | |
*** bogdando has quit IRC | 14:50 | |
*** bogdando has joined #openstack-ha | 14:58 | |
*** rmart04 has quit IRC | 15:03 | |
*** rmart04 has joined #openstack-ha | 15:06 | |
*** corey_ has joined #openstack-ha | 15:09 | |
*** corey_ is now known as Guest41147 | 15:09 | |
*** cleong has quit IRC | 15:11 | |
*** g3ek has quit IRC | 15:13 | |
*** g3ek has joined #openstack-ha | 15:14 | |
*** g3ek has quit IRC | 15:27 | |
*** mjura has quit IRC | 15:30 | |
*** rmart04 has quit IRC | 15:31 | |
*** g3ek has joined #openstack-ha | 15:37 | |
*** asettle has quit IRC | 15:45 | |
*** asettle has joined #openstack-ha | 15:46 | |
*** furlongm has quit IRC | 15:53 | |
*** furlongm has joined #openstack-ha | 15:53 | |
*** cleong has joined #openstack-ha | 16:02 | |
*** Guest41147 has quit IRC | 16:03 | |
*** corey_ has joined #openstack-ha | 16:08 | |
*** corey_ is now known as Guest48309 | 16:09 | |
*** cleong has quit IRC | 16:09 | |
*** furlongm_ has joined #openstack-ha | 16:10 | |
*** furlongm has quit IRC | 16:10 | |
*** nkrinner is now known as nkrinner_afk | 16:11 | |
*** furlongm_ has quit IRC | 16:34 | |
*** furlongm_ has joined #openstack-ha | 16:34 | |
*** furlongm_ has quit IRC | 17:17 | |
*** furlongm has joined #openstack-ha | 17:17 | |
*** Guest48309 has quit IRC | 17:40 | |
*** cleong has joined #openstack-ha | 17:40 | |
*** asettle has quit IRC | 17:58 | |
*** ushkalim has quit IRC | 18:01 | |
*** pcaruana has quit IRC | 18:52 | |
*** asettle has joined #openstack-ha | 18:53 | |
*** furlongm has quit IRC | 19:29 | |
*** furlongm has joined #openstack-ha | 19:30 | |
*** raginbajin has quit IRC | 19:36 | |
*** v12aml has quit IRC | 19:36 | |
*** ddeja has quit IRC | 19:36 | |
*** NostawRm has quit IRC | 19:36 | |
*** v12aml has joined #openstack-ha | 19:36 | |
*** ddeja has joined #openstack-ha | 19:36 | |
*** raginbajin has joined #openstack-ha | 19:38 | |
*** corey_ has joined #openstack-ha | 19:50 | |
*** corey_ is now known as Guest3745 | 19:51 | |
*** cleong has quit IRC | 19:53 | |
*** asettle has quit IRC | 20:10 | |
*** Guest3745 is now known as cleong | 20:33 | |
*** cleong has quit IRC | 21:12 | |
*** asettle has joined #openstack-ha | 21:14 | |
*** aasmith has quit IRC | 21:36 | |
*** furlongm_ has joined #openstack-ha | 21:40 | |
*** furlongm has quit IRC | 21:41 | |
*** furlongm has joined #openstack-ha | 22:13 | |
*** furlongm_ has quit IRC | 22:14 | |
*** asettle has quit IRC | 22:15 | |
*** openstack has joined #openstack-ha | 22:57 | |
*** kgaillot has quit IRC | 23:42 | |
*** masahito has joined #openstack-ha | 23:57 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!