*** jamesbenson has joined #openstack-keystone | 00:16 | |
*** chlong has joined #openstack-keystone | 00:20 | |
*** jamesbenson has quit IRC | 00:20 | |
*** edmondsw has quit IRC | 00:22 | |
*** thorst has joined #openstack-keystone | 00:26 | |
*** edmondsw has joined #openstack-keystone | 00:46 | |
*** jamesbenson has joined #openstack-keystone | 00:49 | |
*** edmondsw has quit IRC | 00:50 | |
*** jamesbenson has quit IRC | 00:54 | |
*** thorst has quit IRC | 01:27 | |
*** jamesbenson has joined #openstack-keystone | 01:30 | |
*** jamesbenson has quit IRC | 01:34 | |
*** itlinux has joined #openstack-keystone | 01:48 | |
*** jamesbenson has joined #openstack-keystone | 01:51 | |
*** rajalokan has joined #openstack-keystone | 01:52 | |
*** jamesbenson has quit IRC | 01:56 | |
*** chlong has quit IRC | 02:03 | |
*** jamesbenson has joined #openstack-keystone | 02:12 | |
*** jamesbenson has quit IRC | 02:16 | |
*** jamesbenson has joined #openstack-keystone | 02:33 | |
*** dave-mccowan has quit IRC | 02:35 | |
*** jamesbenson has quit IRC | 02:37 | |
*** itlinux has quit IRC | 02:37 | |
*** Shunli has joined #openstack-keystone | 02:40 | |
-openstackstatus- NOTICE: Gerrit is being restarted to feed its insatiable memory appetite | 02:40 | |
*** jamesbenson has joined #openstack-keystone | 02:53 | |
*** jamesbenson has quit IRC | 02:58 | |
*** jamesbenson has joined #openstack-keystone | 03:11 | |
*** jamesbenson has quit IRC | 03:15 | |
*** thorst has joined #openstack-keystone | 03:28 | |
*** thorst has quit IRC | 03:33 | |
*** jamesbenson has joined #openstack-keystone | 03:43 | |
*** jamesbenson has quit IRC | 03:55 | |
*** jamesbenson has joined #openstack-keystone | 04:00 | |
*** itlinux has joined #openstack-keystone | 04:02 | |
*** thorst has joined #openstack-keystone | 04:29 | |
*** thorst has quit IRC | 04:34 | |
*** itlinux has quit IRC | 04:36 | |
*** jamesbenson has quit IRC | 04:44 | |
*** aojea has joined #openstack-keystone | 04:48 | |
*** aojea has quit IRC | 04:53 | |
*** gyee has quit IRC | 04:58 | |
*** Shunli has quit IRC | 05:02 | |
*** Suramya has joined #openstack-keystone | 05:15 | |
*** Suramya has quit IRC | 05:24 | |
*** zhurong has joined #openstack-keystone | 05:24 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Clarify backlog instructions and add ideas dir https://review.openstack.org/505057 | 05:25 |
---|---|---|
*** Suramya has joined #openstack-keystone | 05:30 | |
*** thorst has joined #openstack-keystone | 05:30 | |
*** thorst has quit IRC | 05:34 | |
*** Suramya has quit IRC | 05:40 | |
*** Suramya has joined #openstack-keystone | 05:42 | |
*** lbragstad has quit IRC | 05:44 | |
*** aojea has joined #openstack-keystone | 05:46 | |
*** jamesbenson has joined #openstack-keystone | 05:47 | |
*** aojea has quit IRC | 05:52 | |
*** aojea has joined #openstack-keystone | 05:56 | |
*** jamesbenson has quit IRC | 05:57 | |
*** aojea has quit IRC | 06:05 | |
*** aloga has quit IRC | 06:05 | |
*** mwheckmann has quit IRC | 06:05 | |
*** afazekas has quit IRC | 06:05 | |
*** mancdaz has quit IRC | 06:05 | |
*** harlowja has quit IRC | 06:05 | |
*** _d34dh0r53_ has quit IRC | 06:05 | |
*** dstanek has quit IRC | 06:05 | |
*** Krenair has quit IRC | 06:05 | |
*** jamespage has quit IRC | 06:05 | |
*** jmccrory has quit IRC | 06:05 | |
*** amito-infinidat has quit IRC | 06:05 | |
*** diablo_rojo_phon has quit IRC | 06:05 | |
*** cmurphy has quit IRC | 06:05 | |
*** melwitt has quit IRC | 06:05 | |
*** melwitt has joined #openstack-keystone | 06:05 | |
*** dstanek has joined #openstack-keystone | 06:05 | |
*** d34dh0r53 has joined #openstack-keystone | 06:05 | |
*** afazekas has joined #openstack-keystone | 06:05 | |
*** cmurphy has joined #openstack-keystone | 06:05 | |
*** aloga has joined #openstack-keystone | 06:05 | |
*** melwitt is now known as Guest36641 | 06:06 | |
*** diablo_rojo_phon has joined #openstack-keystone | 06:06 | |
*** jamespage has joined #openstack-keystone | 06:06 | |
*** amito-infinidat has joined #openstack-keystone | 06:07 | |
*** Krenair has joined #openstack-keystone | 06:08 | |
*** aojea has joined #openstack-keystone | 06:10 | |
*** mwheckmann has joined #openstack-keystone | 06:10 | |
*** mancdaz has joined #openstack-keystone | 06:10 | |
*** jmccrory has joined #openstack-keystone | 06:10 | |
*** mnaser has quit IRC | 06:12 | |
*** guoshan has joined #openstack-keystone | 06:18 | |
*** mnaser has joined #openstack-keystone | 06:24 | |
*** thorst has joined #openstack-keystone | 06:31 | |
*** thorst has quit IRC | 06:35 | |
*** jamesbenson has joined #openstack-keystone | 06:50 | |
*** Suramya_ has joined #openstack-keystone | 06:52 | |
*** Suramya has quit IRC | 06:53 | |
*** zhurong has quit IRC | 06:54 | |
*** jamesbenson has quit IRC | 06:54 | |
*** Suramya has joined #openstack-keystone | 06:56 | |
*** Suramya_ has quit IRC | 06:57 | |
*** Suramya has quit IRC | 07:04 | |
*** Suramya has joined #openstack-keystone | 07:06 | |
*** ioggstream has joined #openstack-keystone | 07:13 | |
*** Suramya has quit IRC | 07:16 | |
*** Suramya has joined #openstack-keystone | 07:16 | |
*** rcernin has joined #openstack-keystone | 07:18 | |
*** zhurong has joined #openstack-keystone | 07:19 | |
-openstackstatus- NOTICE: Post jobs are not executed currently, do not tag any releases | 07:22 | |
*** ChanServ changes topic to "Post jobs are not executed currently, do not tag any releases" | 07:22 | |
*** pcaruana has joined #openstack-keystone | 07:22 | |
*** tesseract has joined #openstack-keystone | 07:24 | |
*** Suramya has quit IRC | 07:25 | |
*** jamesbenson has joined #openstack-keystone | 07:26 | |
*** jamesbenson has quit IRC | 07:30 | |
*** thorst has joined #openstack-keystone | 07:32 | |
*** Suramya has joined #openstack-keystone | 07:32 | |
*** thorst has quit IRC | 07:36 | |
openstackgerrit | Chenghui Yu proposed openstack/keystone master: Update os-api-ref>=1.4.0 https://review.openstack.org/505094 | 07:41 |
*** Suramya has quit IRC | 07:42 | |
*** jamesbenson has joined #openstack-keystone | 07:47 | |
*** Suramya has joined #openstack-keystone | 07:48 | |
*** jamesbenson has quit IRC | 07:51 | |
*** Suramya has quit IRC | 07:52 | |
*** Suramya has joined #openstack-keystone | 07:54 | |
*** d0ugal has quit IRC | 08:01 | |
*** Suramya has quit IRC | 08:04 | |
*** d0ugal has joined #openstack-keystone | 08:09 | |
*** Suramya has joined #openstack-keystone | 08:12 | |
*** mvk has quit IRC | 08:21 | |
*** zhurong has quit IRC | 08:24 | |
*** Suramya has quit IRC | 08:26 | |
*** Suramya has joined #openstack-keystone | 08:30 | |
*** thorst has joined #openstack-keystone | 08:33 | |
*** jaosorior has quit IRC | 08:33 | |
*** jaosorior has joined #openstack-keystone | 08:34 | |
*** Suramya has quit IRC | 08:35 | |
*** thorst has quit IRC | 08:37 | |
*** Suramya has joined #openstack-keystone | 08:37 | |
*** jamesbenson has joined #openstack-keystone | 08:41 | |
*** jamesbenson has quit IRC | 08:45 | |
*** Suramya has quit IRC | 08:48 | |
openstackgerrit | Shan Guo proposed openstack/keystone master: Fix releasenotes indent for consistency https://review.openstack.org/505115 | 08:49 |
*** mvk has joined #openstack-keystone | 08:50 | |
*** Suramya has joined #openstack-keystone | 08:51 | |
*** Suramya has quit IRC | 09:01 | |
*** zhurong has joined #openstack-keystone | 09:06 | |
*** Suramya has joined #openstack-keystone | 09:26 | |
openstackgerrit | Suramya proposed openstack/keystone master: Reorganize api-ref: v3 domains https://review.openstack.org/505135 | 09:31 |
*** mvk has quit IRC | 09:32 | |
*** thorst has joined #openstack-keystone | 09:33 | |
*** thorst has quit IRC | 09:38 | |
*** szahers has joined #openstack-keystone | 09:44 | |
*** mvk has joined #openstack-keystone | 09:45 | |
*** jamesbenson has joined #openstack-keystone | 10:08 | |
*** nicolasbock has joined #openstack-keystone | 10:09 | |
*** jamesbenson has quit IRC | 10:12 | |
*** Suramya_ has joined #openstack-keystone | 10:18 | |
*** thorst has joined #openstack-keystone | 10:18 | |
*** thorst has quit IRC | 10:19 | |
*** Suramya has quit IRC | 10:19 | |
*** guoshan has quit IRC | 10:37 | |
*** timothyb89 has quit IRC | 10:48 | |
*** thorst has joined #openstack-keystone | 11:19 | |
*** thorst has quit IRC | 11:26 | |
*** Suramya_ has quit IRC | 11:35 | |
*** ygl has joined #openstack-keystone | 11:41 | |
ygl | hi all; | 11:41 |
ygl | i need some help with keystone | 11:41 |
*** zhurong has quit IRC | 11:49 | |
*** Drankis has joined #openstack-keystone | 11:50 | |
*** jaosorior has quit IRC | 12:02 | |
*** thorst has joined #openstack-keystone | 12:04 | |
*** jamesbenson has joined #openstack-keystone | 12:09 | |
*** edmondsw has joined #openstack-keystone | 12:09 | |
*** raildo has joined #openstack-keystone | 12:13 | |
*** jamesbenson has quit IRC | 12:13 | |
*** lucasxu has joined #openstack-keystone | 12:15 | |
*** ygl has quit IRC | 12:17 | |
*** dave-mccowan has joined #openstack-keystone | 12:46 | |
*** Suramya has joined #openstack-keystone | 12:46 | |
*** catintheroof has joined #openstack-keystone | 12:49 | |
*** dave-mcc_ has joined #openstack-keystone | 12:51 | |
*** dave-mccowan has quit IRC | 12:51 | |
*** szahers has quit IRC | 12:54 | |
*** panbalag has joined #openstack-keystone | 12:57 | |
*** StefanPaetowJisc has joined #openstack-keystone | 13:14 | |
*** chlong has joined #openstack-keystone | 13:19 | |
*** markvoelker has joined #openstack-keystone | 13:30 | |
*** chrisshattuck has joined #openstack-keystone | 13:32 | |
*** chrisshattuck has quit IRC | 13:39 | |
*** jamesbenson has joined #openstack-keystone | 13:40 | |
*** jamesbenson has quit IRC | 13:44 | |
*** Suramya has quit IRC | 13:49 | |
*** Drankis has quit IRC | 13:51 | |
*** jamesbenson has joined #openstack-keystone | 14:01 | |
*** Guest36641 is now known as melwitt | 14:03 | |
*** erlon has joined #openstack-keystone | 14:05 | |
*** jamesbenson has quit IRC | 14:06 | |
*** admin0 has joined #openstack-keystone | 14:16 | |
knikolla | o/ | 14:16 |
hrybacki | o/ | 14:16 |
knikolla | hrybacki: i'll look at the etherpad later today | 14:17 |
hrybacki | knikolla: thanks! | 14:17 |
admin0 | how are catalogs created/advertised ? | 14:18 |
*** jamesbenson has joined #openstack-keystone | 14:39 | |
*** jrist has quit IRC | 14:41 | |
*** chrissha_ has joined #openstack-keystone | 14:43 | |
*** jamesbenson has quit IRC | 14:44 | |
*** raildo has quit IRC | 14:44 | |
*** marst has joined #openstack-keystone | 14:46 | |
samueldmq | morning keystone | 14:48 |
*** jaosorior has joined #openstack-keystone | 14:48 | |
*** szahers has joined #openstack-keystone | 14:49 | |
samueldmq | admin0: the service catalog is created in keystone and is advertised by keystone too | 14:49 |
samueldmq | individual services may retrieve the catalog when doing token validation | 14:50 |
admin0 | does one actually do catalog create .. or is it built from endpoints added | 14:50 |
samueldmq | cmurphy: this is all true for fernet token too, correct? | 14:50 |
samueldmq | admin0: no catalog create call. catalog is built from services, regions and endpoints created | 14:51 |
samueldmq | those have CRUD APIs | 14:51 |
*** StefanPaetowJisc has quit IRC | 14:52 | |
admin0 | samueldmq: thanks | 14:53 |
*** david-lyle has joined #openstack-keystone | 14:53 | |
hrybacki | panbalag: `sudo keystone-manage fernet_rotate --keystone-user keystone --keystone-group keystone` | 14:56 |
gagehugo | o/ | 14:56 |
*** StefanPaetowJisc has joined #openstack-keystone | 14:56 | |
panbalag | hrybacki: ok. let me try that | 14:57 |
*** lbragstad has joined #openstack-keystone | 14:59 | |
*** ChanServ sets mode: +o lbragstad | 14:59 | |
*** szahers has quit IRC | 15:00 | |
*** jamesbenson has joined #openstack-keystone | 15:00 | |
lbragstad | o/ | 15:03 |
lbragstad | just a heads up that i'll be in orientation all day today and tomorrow | 15:03 |
lbragstad | (i won't be around for the keystone meeting or office hours) | 15:04 |
*** jamesbenson has quit IRC | 15:05 | |
*** gyee has joined #openstack-keystone | 15:05 | |
*** StefanPaetowJisc has quit IRC | 15:05 | |
samueldmq | admin0: sure, np | 15:08 |
*** StefanPaetowJisc has joined #openstack-keystone | 15:08 | |
*** lbragstad has quit IRC | 15:11 | |
*** Suramya has joined #openstack-keystone | 15:16 | |
*** jamesbenson has joined #openstack-keystone | 15:21 | |
*** raildo has joined #openstack-keystone | 15:24 | |
*** jamesbenson has quit IRC | 15:25 | |
*** jaosorior has quit IRC | 15:32 | |
*** raildo has quit IRC | 15:39 | |
*** raildo has joined #openstack-keystone | 15:55 | |
kmalloc | o/ | 16:01 |
*** jamesbenson has joined #openstack-keystone | 16:03 | |
*** sbezverk has quit IRC | 16:03 | |
openstackgerrit | Merged openstack/keystone master: Remove keystone-all doc https://review.openstack.org/502423 | 16:03 |
*** jamesbenson has quit IRC | 16:07 | |
*** itlinux has joined #openstack-keystone | 16:12 | |
*** jamesbenson has joined #openstack-keystone | 16:23 | |
*** StefanPaetowJisc has quit IRC | 16:27 | |
*** jamesbenson has quit IRC | 16:28 | |
*** StefanPaetowJisc has joined #openstack-keystone | 16:29 | |
*** StefanPaetowJisc has quit IRC | 16:33 | |
*** pcaruana has quit IRC | 16:38 | |
*** aselius has joined #openstack-keystone | 16:44 | |
*** rcernin has quit IRC | 16:52 | |
*** tesseract has quit IRC | 16:52 | |
*** mvk has quit IRC | 17:01 | |
hrybacki | who runs the keystone mtg in lieu of lbragstad? | 17:02 |
gagehugo | are we having it today? the agenda is empty | 17:04 |
*** admin0 has left #openstack-keystone | 17:05 | |
hrybacki | gagehugo: lance is out which is what prompted me to ask | 17:08 |
*** szahers has joined #openstack-keystone | 17:08 | |
hrybacki | do the cores want to hold a meeting / office hours? | 17:08 |
gagehugo | ah | 17:09 |
*** szahers has quit IRC | 17:10 | |
*** ygl has joined #openstack-keystone | 17:11 | |
ygl | hi all | 17:11 |
ygl | i need some help with keystone | 17:12 |
hrybacki | ygl: can you provide us with some more info? | 17:14 |
ygl | hyakuhei: i have two regions. but a common keystone. | 17:17 |
ygl | hrybacki: i have two regions. but a common keystone. | 17:17 |
ygl | hrybacki: when I try to run nova list for second region it is trying to access the internal keystone endpoint of first region eventhough I pointed the second region to public endpoint of first region | 17:19 |
ygl | hrybacki: and the internal endpoint is a private network not reachable from second region | 17:20 |
ygl | hrybacki: but I am able to get openstack token using this public endpoint. but not nova list | 17:20 |
hrybacki | (I haven't deployed this type of environment before so keep that in mind) -- how did you point the second region at the public endpoint of the first? | 17:21 |
*** jamesbenson has joined #openstack-keystone | 17:22 | |
ygl | using the auth_uri in nova.conf to point to keystone public endpoint of first region | 17:22 |
ygl | hrybacki: using the auth_uri in nova.conf to point to keystone public endpoint of first region | 17:23 |
* cmurphy on planes all day, won't be at the meeting | 17:24 | |
*** jamesbenson has quit IRC | 17:26 | |
hrybacki | ygl: I'll be slow to respond (meetings) | 17:28 |
ygl | hrybacki: ok | 17:30 |
*** ygl has quit IRC | 17:38 | |
openstackgerrit | Chris Friesen proposed openstack/keystone-specs master: Restrict Service Catalog in Auth Response https://review.openstack.org/505345 | 17:39 |
*** cfriesen has joined #openstack-keystone | 17:39 | |
*** jamesbenson has joined #openstack-keystone | 17:43 | |
*** StefanPaetowJisc has joined #openstack-keystone | 17:46 | |
*** ygl has joined #openstack-keystone | 17:47 | |
ygl | hrybacki: i want some information | 17:47 |
*** jamesbenson has quit IRC | 17:47 | |
*** harlowja has joined #openstack-keystone | 17:49 | |
ygl | can someone tell me, if I execute nova list command form a remote client machine , which keystone urls will the nova service internally uses ? is it admin, or internal or public keystone endpoint ? which one ? | 17:49 |
hrybacki | ygl it may be awhile before I can respond (I'd need to research your issue). If you want to raise visibility quickly I'd recommend creating a bug in LP -- https://bugs.launchpad.net/keystone -- and adding as much information (env, version of OS, logs, config) so that I (or someone else with free time sooner) can best assist you | 17:49 |
ygl | hrybacki: if I execute nova list command form a remote client machine , which keystone urls will the nova service internally uses ? is it admin, or internal or public keystone endpoint ? which one ? | 17:50 |
knikolla | ygl: by default it should be public | 17:50 |
ygl | knikolla: but internally does it still use internal endpoint ? | 17:50 |
ygl | knikolla: i mean it is the nova service which has to interact with the keystone internally . So I am suspecting it will be internal still | 17:51 |
*** Suramya_ has joined #openstack-keystone | 17:52 | |
knikolla | ygl: this blog post from a while ago should help http://blog.dolphm.com/openstack-keystone-service-catalog/ | 17:52 |
ygl | knikolla: eventhough the public endpoint takes the request, the nova service internally uses internal endpoint | 17:52 |
knikolla | ygl: here's the workflow | 17:52 |
*** panbalag has quit IRC | 17:53 | |
*** Suramya has quit IRC | 17:53 | |
*** mvk has joined #openstack-keystone | 17:53 | |
knikolla | ygl: 1. user gets a token from keystone via the keystone public interface, 2. user sends the request with the token to the nova public interface, 3. nova talks to keystone to validate the token, which interface nova uses for talking to keystone is configurable in the nova configuration for keystonemiddleware | 17:53 |
ygl | knikolla: for me eventhough I configured nova to use public keystone endpoint, it is still querying internal endpoint in the debug output | 17:54 |
ygl | knikolla: openstack --debug server list | 17:55 |
*** spilla has joined #openstack-keystone | 17:55 | |
knikolla | ygl: the debug output of that will be of openstackclient, not nova | 17:55 |
*** ioggstream has quit IRC | 17:56 | |
ygl | knikolla: the openstack client is querying internal endpoint eventhough I mentioned public endpoint. thats my doubt | 17:56 |
knikolla | ygl: is it querying the internal endpoint for keystone or the internal endpoint for nova? | 17:57 |
ygl | knikolla: it is querying internal endpoint of keystone first and then it is going to nova. but my query is why is it querying internal keystone, eventhough I mentioned public keystone in the openrc file | 17:58 |
knikolla | ygl: for keystone, openstackclient will query whatever is your AUTH_URL in your openrc file. there is no other way to figure out which keystone to query, since the catalog is fetched after getting a token from keystone itself | 17:59 |
ygl | knikolla: but I mentioned publick keystone endpoint in the openrc file | 17:59 |
samueldmq | hrybacki: well, it's not official we don't have a meeting | 18:01 |
knikolla | samueldmq: lance is on orientation day, so unless someone want to host the meeting, i guess not | 18:01 |
samueldmq | and I do have a 1 topic, I think we can do a quick meeting if people show up | 18:01 |
samueldmq | I can do it | 18:01 |
hrybacki | samueldmq: let's do it | 18:01 |
knikolla | ygl: paste on paste.opentsack.org and send me a link (remove passwords) | 18:02 |
ygl | knikolla: ok | 18:02 |
*** jamesbenson has joined #openstack-keystone | 18:04 | |
*** Suramya has joined #openstack-keystone | 18:04 | |
*** Suramya_ has quit IRC | 18:06 | |
ygl | knikolla: http://paste.openstack.org/show/621464/ | 18:07 |
*** jamesbenson has quit IRC | 18:08 | |
ygl | knikolla: it is timing out because i see these logs in the nova-api: http://paste.openstack.org/show/621465/ | 18:09 |
knikolla | ygl: that looks like it's correctly working to get a token from keystone, but it's talking to the wrong nova | 18:09 |
ygl | knikolla: no the nova url is correct | 18:09 |
knikolla | ygl: oh i see. nova can't talk to keystone | 18:09 |
ygl | knikolla: because keystone-internal is not reachable | 18:09 |
knikolla | ygl: the url of the keystone that nova should use is in the nova.conf file | 18:10 |
knikolla | there is a keystone_authtoken section | 18:10 |
knikolla | for keystonemiddleware | 18:10 |
ygl | knikolla: yes it is pointing to public keystone url | 18:10 |
ygl | knikolla: in nova.conf | 18:10 |
knikolla | can i see that section? blank out the passwords | 18:10 |
ygl | knikolla: ok | 18:11 |
*** spilla has quit IRC | 18:11 | |
ygl | knikolla: http://paste.openstack.org/show/621466/ | 18:12 |
ygl | knikolla: keystone.mycloud.wtl.com is reachable\ | 18:12 |
knikolla | ygl: the entire section please. i think i know the issue, i just want to make sure. | 18:13 |
ygl | knikolla: but in the debug output it is pointing to keystone-internal.mycloud.wtl.com | 18:13 |
ygl | knikolla: ok | 18:13 |
ygl | knikolla: http://paste.openstack.org/show/621467/ | 18:14 |
ygl | knikolla: this is actually a second region talking to keystone urls of first region since both share a common keystone | 18:15 |
ygl | knikolla: hope u got the picture now | 18:16 |
ygl | knikolla: u there ? | 18:18 |
knikolla | ygl: yeah, give me a sec. checking something | 18:18 |
ygl | knikolla: ok | 18:18 |
ygl | knikolla: this is mitaka version | 18:18 |
ygl | knikolla: in ubuntu | 18:19 |
knikolla | ygl: based on that configuration, keystonemiddleware should have talked to the correct keystone. :/ | 18:21 |
knikolla | try auth_plugin instead of auth_type | 18:21 |
knikolla | that's the wrong option name. | 18:22 |
ygl | knikolla: it is showing public endpoint in debug output but it is failing because nova-api log shows that it is querying internal keystone though | 18:22 |
*** StefanPaetowJisc has quit IRC | 18:22 | |
*** itlinux has quit IRC | 18:22 | |
ygl | knikolla: did u get my point ? | 18:23 |
knikolla | i do get your point. also it doesn't matter what is internal or external, because nova will not use the catalog to query keystone | 18:23 |
knikolla | it will use a configuration setting in nova.conf | 18:23 |
*** Suramya has quit IRC | 18:23 | |
ygl | knikolla: but my command is failing eventually because internal endpoint is unreachable from second region | 18:24 |
ygl | knikolla: only if I add the public ip of the same host to point to internal keystone in /etc/hosts file ten it is working | 18:24 |
*** jamesbenson has joined #openstack-keystone | 18:24 | |
ygl | knikolla: it is weird though. why is it not using public keystone | 18:25 |
knikolla | ygl: as i said above. the keystone endpoint is hardcoded in nova. | 18:25 |
*** Suramya has joined #openstack-keystone | 18:25 | |
knikolla | ygl: so the internal endpoint is somewhere in the nova.conf file | 18:25 |
ygl | knikolla: but I used public endpoint in nova | 18:25 |
ygl | knikolla: no it is not there at all | 18:25 |
knikolla | do a grep on the url of the internal endpoint | 18:25 |
ygl | knikolla: i double-checked it | 18:25 |
ygl | knikolla: | 18:25 |
ygl | knikolla: ok | 18:26 |
ygl | knikolla: root@blrlab-hyper-2:~# cat /etc/nova/nova.conf | grep keystone-internal root@blrlab-hyper-2:~# | 18:26 |
ygl | knikolla: no output | 18:26 |
ygl | knikolla: i think it is a bug with multi regions in mitaka | 18:26 |
ygl | knikolla: it is searching for internal keystone endpoint on the first region eventhough I specify public keystone endpoint | 18:27 |
knikolla | ygl: it shouldn't be. because it doesn't search, because it doesn't know how to search "yet". | 18:28 |
ygl | knikolla: but my logs show otherwise | 18:28 |
ygl | knikolla: i hope u got my point | 18:28 |
*** ayoung has joined #openstack-keystone | 18:28 | |
*** jamesbenson has quit IRC | 18:29 | |
ygl | knikolla: can u send your findings and thoughts about this to my mail id 'ygk.kmr@gmail.com' please | 18:29 |
ygl | knikolla: it is only working if I make the internal endpoint resolvable from second region | 18:29 |
knikolla | ygl: i'd rather keep this here since more folks can jump in and help. | 18:30 |
ygl | knikolla: i am done for the day | 18:30 |
ygl | it is close to midnight here | 18:30 |
knikolla | ygl: ping me on irc when you're on tomorrow. | 18:30 |
ygl | knikolla: can u remember me ? | 18:31 |
ygl | knikolla: what time u will be available tomorrow ? | 18:31 |
knikolla | ygl: i'm good at names, terrible with faces. so you're in luck. | 18:31 |
ygl | knikolla: ok, send ur findings or thoughts to my mail id above | 18:32 |
*** StefanPaetowJisc has joined #openstack-keystone | 18:32 | |
knikolla | ygl: i'm on EST, but i can spare some time tonight, wich will be morning at you. | 18:32 |
ygl | knikolla: ok | 18:32 |
ygl | knikolla: thanks | 18:32 |
knikolla | ygl: np | 18:32 |
*** ygl has quit IRC | 18:32 | |
*** jamesbenson has joined #openstack-keystone | 18:45 | |
*** StefanPaetowJisc has quit IRC | 18:46 | |
*** jamesbenson has quit IRC | 18:50 | |
*** itlinux has joined #openstack-keystone | 18:59 | |
*** jamesbenson has joined #openstack-keystone | 19:06 | |
*** StefanPaetowJisc has joined #openstack-keystone | 19:06 | |
*** jamesbenson has quit IRC | 19:10 | |
*** lucasxu has quit IRC | 19:26 | |
*** jrist has joined #openstack-keystone | 19:26 | |
*** StefanPaetowJisc has quit IRC | 19:28 | |
*** Suramya has quit IRC | 19:34 | |
*** StefanPaetowJisc has joined #openstack-keystone | 19:35 | |
*** StefanPaetowJisc has quit IRC | 19:56 | |
*** raildo has quit IRC | 19:57 | |
*** StefanPaetowJisc has joined #openstack-keystone | 19:58 | |
openstackgerrit | Kristi Nikolla proposed openstack/keystonemiddleware master: Document endpoint interface and region behavior https://review.openstack.org/505396 | 19:59 |
knikolla | hrybacki: ^^ | 19:59 |
*** StefanPaetowJisc has quit IRC | 20:02 | |
*** StefanPaetowJisc has joined #openstack-keystone | 20:06 | |
*** StefanPaetowJisc has quit IRC | 20:13 | |
*** rcernin has joined #openstack-keystone | 20:14 | |
*** raildo has joined #openstack-keystone | 20:17 | |
marst | Hello. Apologies for trivial question, I'm trying to follow this: https://docs.openstack.org/keystone/pike/install/keystone-install-rdo.html guide and I'm stuck getting "Can't connect to MySQL server on 'controller'" errors. http://paste.openstack.org/show/621443/ - after keystone db_sync command. http://paste.openstack.org/show/621476/ - configuration for keystone, I guess I'm missing some fields? I can connect to | 20:20 |
marst | this DB from another host, it's not firewall issue. Any ideas on what else to check? | 20:20 |
*** jamesbenson has joined #openstack-keystone | 20:22 | |
knikolla | marst: is controller pingable? | 20:23 |
marst | knikilla: yes, it's "all-in-one" setup. | 20:23 |
marst | *knikolla, apologies | 20:24 |
knikolla | marst: what i mean is, does `ping controller` work? | 20:25 |
*** jamesbenson has quit IRC | 20:26 | |
marst | knikolla: yes. "controller" is defined in /etc/hosts file as "127.0.0.1". | 20:26 |
-openstackstatus- NOTICE: Zuul and Gerrit are being restarted to address issues discovered with the Gerrit 2.13 upgrade. review.openstack.org will be inaccessible for a few minutes while we make these changes. Currently running jobs will be restarted for you once Zuul and Gerrit are running again. | 20:26 | |
marst | I can replace "controller with IP and see if that helps, I guess. | 20:26 |
knikolla | marst: can you connect to mysql with the user and password specified? | 20:27 |
marst | knikolla: yes. both from localhost and from another host too. | 20:27 |
knikolla | marst: and i assume you've replaced `KEYSTONE_DBPASS` in the configuration file with the actual database password for the user | 20:29 |
knikolla | in the `mysql+pymysql://keystone:KEYSTONE_DBPASS@controller/keystone` line | 20:29 |
marst | knikolla: I did better. I setup my password as KEYSTONE_DBPASS. Perhaps I should change it and remove underscore? | 20:30 |
knikolla | marst: the underscore shouldn't matter. | 20:31 |
knikolla | so you have a `keystone` user with a `KEYSTONE_DBPASS`, and permissions on a database named `keystone` | 20:32 |
knikolla | that database is accessible from outside hosts, but not from keystone when running db_sync | 20:33 |
marst | knikolla: yes, that's correct. | 20:33 |
knikolla | marst: give me a sec, testing something. | 20:34 |
marst | knikolla: sure, thanks a lot for taking time! Appreciate any and all help. For now I've replaced "controller" with 127.0.0.1 in connection string, restarted httpd, but still same error: Can't connect to MySQL server on '127.0.0.1' | 20:35 |
marst | and just realized that I should've probably asked for help in oslo channel. | 20:37 |
knikolla | marst: connection is all you really need for the db connection. | 20:39 |
marst | knikolla: "easy" problems are always most painful. I've spent 2 days fighting this and still can't figure out what's wrong. :) | 20:41 |
knikolla | marst: i can believe that! | 20:41 |
marst | knikolla: promised docs team I'll check install guide by Thursday. Looks like I'll be late. :( | 20:41 |
knikolla | marst: so `keystone db_sync` is failing with the error you pasted, right? | 20:42 |
knikolla | keystone-manage | 20:42 |
knikolla | err. | 20:42 |
marst | knikolla: it doesn't fail, it just silently quites. the error messages appear only in /var/log/keystone/keystone.log file t | 20:42 |
marst | *quits | 20:42 |
*** jrist has quit IRC | 20:43 | |
knikolla | marst: try increasing the logging level to debug by setting `debug = True` in the `[DEFAULT]` section of the config. | 20:45 |
marst | knikolla: just did. One question, is there a difference between running keyston-manage db_sync as root user or as in guide: "su -s /bin/sh -c "keystone-manage db_sync" keystone" ? | 20:49 |
*** catintheroof has quit IRC | 20:50 | |
*** catintheroof has joined #openstack-keystone | 20:50 | |
knikolla | marst: there shouldn't be. | 20:50 |
*** catintheroof has quit IRC | 20:51 | |
marst | knikolla: yeah, same error in both cases: http://paste.openstack.org/show/621480/ | 20:51 |
knikolla | marst: i didn't expect a different error, but hoped for more info before the error. it seems to load the migrations and everything correctly, so only the connection is failing. | 20:54 |
marst | knikolla: I guess I'll try to do everything again from scratch and if it fails again will comeback. :) | 20:54 |
knikolla | try asking oslo first. | 20:55 |
marst | knikolla: will do. thank you! | 20:55 |
*** itlinux has quit IRC | 20:56 | |
*** itlinux has joined #openstack-keystone | 20:57 | |
*** itlinux has quit IRC | 20:58 | |
*** itlinux has joined #openstack-keystone | 20:59 | |
*** StefanPaetowJisc has joined #openstack-keystone | 21:06 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Handle latest changes to os-testr https://review.openstack.org/504442 | 21:06 |
*** StefanPaetowJisc has quit IRC | 21:10 | |
*** jose-phillips has joined #openstack-keystone | 21:11 | |
*** thorst has quit IRC | 21:14 | |
*** StefanPaetowJisc has joined #openstack-keystone | 21:16 | |
*** thorst has joined #openstack-keystone | 21:16 | |
*** thorst has quit IRC | 21:20 | |
*** itlinux has quit IRC | 21:21 | |
*** StefanPaetowJisc has quit IRC | 21:21 | |
*** itlinux has joined #openstack-keystone | 21:25 | |
*** raildo has quit IRC | 21:40 | |
*** jistr has quit IRC | 21:41 | |
*** panbalag has joined #openstack-keystone | 21:48 | |
*** aahh has joined #openstack-keystone | 21:51 | |
*** panbalag has quit IRC | 21:58 | |
*** jistr has joined #openstack-keystone | 22:01 | |
*** chrissha_ has quit IRC | 22:02 | |
*** jamesbenson has joined #openstack-keystone | 22:10 | |
*** jamesbenson has quit IRC | 22:14 | |
*** aojea has quit IRC | 22:16 | |
*** chlong has quit IRC | 22:21 | |
*** aahh has quit IRC | 22:24 | |
-openstackstatus- NOTICE: Gerrit is being restarted to address some final issues, review.openstack.org will be inaccessible for a few minutes while we restart | 22:33 | |
*** dave-mcc_ has quit IRC | 22:33 | |
*** catintheroof has joined #openstack-keystone | 22:45 | |
*** openstackgerrit has quit IRC | 22:47 | |
*** itlinux has quit IRC | 22:49 | |
*** edmondsw has quit IRC | 22:50 | |
*** jamesbenson has joined #openstack-keystone | 22:51 | |
*** nkinder has quit IRC | 22:52 | |
*** chrisshattuck has joined #openstack-keystone | 22:55 | |
*** edmondsw has joined #openstack-keystone | 22:55 | |
*** jamesbenson has quit IRC | 22:55 | |
*** edmondsw has quit IRC | 22:59 | |
*** nkinder has joined #openstack-keystone | 23:07 | |
*** rcernin has quit IRC | 23:11 | |
*** chrisshattuck has quit IRC | 23:19 | |
*** edmondsw has joined #openstack-keystone | 23:23 | |
*** hoonetorg has quit IRC | 23:23 | |
*** edmondsw has quit IRC | 23:27 | |
*** hoonetorg has joined #openstack-keystone | 23:36 | |
*** ChanServ changes topic to "Queens release schedule: https://releases.openstack.org/queens/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h" | 23:39 | |
-openstackstatus- NOTICE: Gerrit is once again part of normal puppet config management. Problems with Gerrit gitweb links and Zuul post jobs have been addressed. We currently cannot create new gerrit projects (fixes in progress) and email sending is slow (being debugged). | 23:39 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!