*** k_mouza has joined #openstack-kolla | 00:03 | |
*** jtriley has quit IRC | 00:06 | |
*** openstackgerrit has joined #openstack-kolla | 00:07 | |
openstackgerrit | Chuck Short proposed openstack/kolla master: Remove ceph-nfs support for ubuntu https://review.openstack.org/545980 | 00:07 |
---|---|---|
*** k_mouza has quit IRC | 00:09 | |
*** dardelean has joined #openstack-kolla | 00:12 | |
*** masber has joined #openstack-kolla | 00:21 | |
masber | good morning all | 00:22 |
masber | how can I tell kolla-build to create a specific image version? | 00:22 |
*** jrist has quit IRC | 00:24 | |
*** itlinux has joined #openstack-kolla | 00:29 | |
*** dave-mccowan has joined #openstack-kolla | 00:30 | |
*** jrist has joined #openstack-kolla | 00:36 | |
*** dave-mccowan has quit IRC | 00:53 | |
*** caowei has joined #openstack-kolla | 00:53 | |
*** dave-mccowan has joined #openstack-kolla | 01:18 | |
*** dave-mccowan has quit IRC | 01:29 | |
*** chrizl has quit IRC | 01:31 | |
*** chrizl has joined #openstack-kolla | 01:34 | |
*** dardelean has quit IRC | 01:36 | |
*** dardelean has joined #openstack-kolla | 01:36 | |
*** k_mouza has joined #openstack-kolla | 01:40 | |
*** dardelean has quit IRC | 01:41 | |
*** chrizl has quit IRC | 01:43 | |
*** k_mouza has quit IRC | 01:45 | |
*** geen02 has joined #openstack-kolla | 01:53 | |
*** chrizl has joined #openstack-kolla | 02:03 | |
*** salv-orlando has joined #openstack-kolla | 02:27 | |
*** salv-orl_ has quit IRC | 02:30 | |
masber | not many people here ... I still remember the old days | 02:30 |
*** geen02 has quit IRC | 02:35 | |
openstackgerrit | Merged openstack/kolla-ansible master: Use fernet in gates https://review.openstack.org/545758 | 02:38 |
*** yangyapeng has quit IRC | 02:47 | |
*** yangyapeng has joined #openstack-kolla | 02:47 | |
*** chmarkus has quit IRC | 02:51 | |
*** harlowja has quit IRC | 02:52 | |
*** chmarkus has joined #openstack-kolla | 02:52 | |
*** yangyape_ has joined #openstack-kolla | 03:00 | |
*** yangyapeng has quit IRC | 03:01 | |
*** dave-mccowan has joined #openstack-kolla | 03:09 | |
*** hongbin has joined #openstack-kolla | 03:10 | |
*** janki has joined #openstack-kolla | 03:33 | |
*** gkadam has joined #openstack-kolla | 03:39 | |
*** spsurya has joined #openstack-kolla | 03:47 | |
spsurya | morning guys | 03:47 |
*** janki has quit IRC | 03:56 | |
*** janki has joined #openstack-kolla | 03:57 | |
*** caoyuan has joined #openstack-kolla | 04:13 | |
*** caoyuan has quit IRC | 04:14 | |
*** janki has quit IRC | 04:27 | |
*** janki has joined #openstack-kolla | 04:28 | |
masber | spsurya, from where is kolla-build getting the images from? | 04:38 |
masber | I am running this command /root/kolla/.tox/genconfig/bin/kolla-build --registry localhost:5000 --push but it is not pushing 6.0.0 images | 04:39 |
*** caowei has quit IRC | 04:46 | |
*** harlowja has joined #openstack-kolla | 04:54 | |
*** hongbin has quit IRC | 05:01 | |
*** dave-mccowan has quit IRC | 05:02 | |
*** masahisa has quit IRC | 05:02 | |
*** chrizl has quit IRC | 05:05 | |
*** chrizl has joined #openstack-kolla | 05:06 | |
*** chrizl has quit IRC | 05:11 | |
*** dciabrin has quit IRC | 05:12 | |
*** dciabrin has joined #openstack-kolla | 05:12 | |
*** chrizl has joined #openstack-kolla | 05:15 | |
*** chrizl has quit IRC | 05:27 | |
*** chrizl has joined #openstack-kolla | 05:28 | |
*** lpetrut has joined #openstack-kolla | 05:33 | |
*** skramaja has joined #openstack-kolla | 05:41 | |
*** gkadam has quit IRC | 05:43 | |
*** gkadam has joined #openstack-kolla | 05:44 | |
*** unicell has joined #openstack-kolla | 05:46 | |
*** gfidente|afk has quit IRC | 05:48 | |
*** lpetrut has quit IRC | 06:01 | |
*** caoyuan has joined #openstack-kolla | 06:09 | |
*** unicell1 has joined #openstack-kolla | 06:11 | |
*** unicell has quit IRC | 06:12 | |
*** chrizl has quit IRC | 06:12 | |
*** chrizl has joined #openstack-kolla | 06:13 | |
*** lpetrut has joined #openstack-kolla | 06:19 | |
*** chrizl has quit IRC | 06:21 | |
*** chrizl has joined #openstack-kolla | 06:25 | |
spsurya | masber: did you setup local registry ..... after that this should work | 06:28 |
masber | spsurya, yes I have local registry | 06:29 |
*** lpetrut has quit IRC | 06:30 | |
spsurya | and building from source | 06:34 |
spsurya | masber: | 06:34 |
*** caoyuan_ has joined #openstack-kolla | 06:35 | |
*** caoyuan has quit IRC | 06:38 | |
*** lujinluo has joined #openstack-kolla | 06:40 | |
kolla-slack | <egonzalez> masber, by image version you mean kolla version or distro version? | 06:46 |
masber | spsurya, binary | 06:47 |
*** cah_link has joined #openstack-kolla | 06:49 | |
kolla-slack | <masber> @egonzalez kolla version, distro I am using centos binary | 06:49 |
kolla-slack | <egonzalez> masber, checkout to the version want to use, if using pip install the version, ie pip install kolla==5.0.1 | 06:50 |
kolla-slack | <masber> @egonzalez ahhh 6.0.0 is beta? | 06:53 |
*** dciabrin_ has joined #openstack-kolla | 06:56 | |
*** dciabrin has quit IRC | 06:56 | |
*** lvdombrkr has joined #openstack-kolla | 06:58 | |
kolla-slack | <egonzalez> Yep, 6.0.0 is not released yet afik | 07:00 |
*** egonzalez has joined #openstack-kolla | 07:01 | |
*** lpetrut has joined #openstack-kolla | 07:09 | |
*** threestrands has quit IRC | 07:10 | |
*** harlowja has quit IRC | 07:10 | |
*** dasTor_ has joined #openstack-kolla | 07:11 | |
lvdombrkr | morning folks | 07:12 |
lvdombrkr | what is last stable tag for kolla to deploy? | 07:12 |
*** dasTor has quit IRC | 07:13 | |
openstackgerrit | Eduardo Gonzalez proposed openstack/kolla-ansible master: Test iptables keystone ssh https://review.openstack.org/546060 | 07:15 |
*** chrizl has quit IRC | 07:16 | |
*** chrizl has joined #openstack-kolla | 07:18 | |
egonzalez | lvdombrkr, 5.0.1, 6.0.0 comming in the next weeks | 07:18 |
*** b_bezak has joined #openstack-kolla | 07:19 | |
lvdombrkr | egonzalez: thanks! | 07:20 |
*** dasTor_ has quit IRC | 07:20 | |
*** janki has quit IRC | 07:20 | |
*** lpetrut has quit IRC | 07:23 | |
*** sai___ has quit IRC | 07:26 | |
*** gkadam has quit IRC | 07:34 | |
*** gkadam has joined #openstack-kolla | 07:34 | |
*** pcaruana has joined #openstack-kolla | 07:35 | |
*** dasTor has joined #openstack-kolla | 07:36 | |
*** masahisa has joined #openstack-kolla | 07:38 | |
*** dasTor_ has joined #openstack-kolla | 07:38 | |
*** dasTor has quit IRC | 07:38 | |
*** paken has joined #openstack-kolla | 07:44 | |
*** dasTor has joined #openstack-kolla | 07:45 | |
*** dasTor_ has quit IRC | 07:45 | |
*** dardelean has joined #openstack-kolla | 07:56 | |
openstackgerrit | Eduardo Gonzalez proposed openstack/kolla-ansible master: Test iptables keystone ssh https://review.openstack.org/546060 | 07:57 |
*** lujinluo has quit IRC | 08:02 | |
*** lujinluo has joined #openstack-kolla | 08:02 | |
*** chrizl has quit IRC | 08:06 | |
*** yangyape_ has quit IRC | 08:10 | |
*** chrizl has joined #openstack-kolla | 08:10 | |
egonzalez | anyone have any idea why fernet cannot connect to others keystone_ssh containers in gates? http://logs.openstack.org/60/546060/2/check/kolla-ansible-ubuntu-source-ceph/69fe816/primary/logs/docker_logs/keystone_fernet.txt.gz | 08:15 |
egonzalez | is working locally, but something changes in gates | 08:15 |
*** chrizl has quit IRC | 08:16 | |
*** yangyapeng has joined #openstack-kolla | 08:17 | |
*** chrizl has joined #openstack-kolla | 08:25 | |
*** serlex has joined #openstack-kolla | 08:25 | |
openstackgerrit | Merged openstack/kolla-ansible master: Fix murano authentication configuration options https://review.openstack.org/545833 | 08:26 |
*** unicell1 has quit IRC | 08:27 | |
*** yangyapeng has quit IRC | 08:27 | |
*** dardelean_ has joined #openstack-kolla | 08:27 | |
*** b_bezak has quit IRC | 08:28 | |
openstackgerrit | Merged openstack/kolla-ansible master: Add permission to notify dns server from worker https://review.openstack.org/538861 | 08:29 |
*** ArminderSingh has quit IRC | 08:33 | |
*** gfidente has joined #openstack-kolla | 08:36 | |
*** masahisa has quit IRC | 08:36 | |
*** yangyapeng has joined #openstack-kolla | 08:38 | |
*** ArminderSingh has joined #openstack-kolla | 08:41 | |
*** b_bezak has joined #openstack-kolla | 08:41 | |
santacloud | Hi | 08:42 |
santacloud | I am facing this issue: | 08:42 |
santacloud | https://bugs.launchpad.net/kolla-ansible/+bug/1721390 | 08:42 |
openstack | Launchpad bug 1721390 in kolla-ansible "nova-compute service don't go up" [Undecided,Invalid] | 08:42 |
santacloud | In fact my nova_compute container is still in a "restarting" state | 08:42 |
santacloud | so the task [nova : Waiting for nova-compute service up] is in failure | 08:43 |
santacloud | Do you have an idea? | 08:43 |
santacloud | I downgraded docker of my nodes to 2.6.0 | 08:44 |
santacloud | I am on the master branch | 08:44 |
santacloud | for kolla and kolla-ansible | 08:44 |
santacloud | and I can see this error in dmesg: | 08:45 |
santacloud | aufs au_opts_verify:1597:dockerd[3021]: dirperm1 breaks the protection by the permission bits on the lower branch | 08:45 |
santacloud | on my nodes | 08:45 |
*** chrizl has quit IRC | 08:49 | |
*** yangyape_ has joined #openstack-kolla | 08:49 | |
*** yangyapeng has quit IRC | 08:50 | |
*** chrizl has joined #openstack-kolla | 08:52 | |
*** dasTor_ has joined #openstack-kolla | 08:53 | |
*** dasTor has quit IRC | 08:56 | |
lvdombrkr | folks, why i cant use kolla_external_vip_address same as host ip? | 08:59 |
*** dasTor_ has quit IRC | 09:02 | |
*** chrizl has quit IRC | 09:02 | |
*** serlex has quit IRC | 09:03 | |
*** engel75 has joined #openstack-kolla | 09:03 | |
*** lpetrut has joined #openstack-kolla | 09:05 | |
egonzalez | lvdombrkr, because is going to be used by keepalived | 09:05 |
egonzalez | santacloud, any error in nova-compute logs? | 09:06 |
lvdombrkr | egonzalez: if a external and internal vip are the same ip can i activate ssl? | 09:08 |
*** shardy has joined #openstack-kolla | 09:09 | |
santacloud | egonzalez, only setting permission messages | 09:09 |
*** ktibi has joined #openstack-kolla | 09:10 | |
*** chrizl has joined #openstack-kolla | 09:11 | |
*** k_mouza has joined #openstack-kolla | 09:11 | |
*** chrizl has quit IRC | 09:17 | |
dardelean | how can I use this cannel on slack? | 09:18 |
kolla-slack | <dardelean> got it | 09:19 |
*** dardelean has quit IRC | 09:19 | |
*** mgoddard_ has joined #openstack-kolla | 09:30 | |
mgoddard_ | any plans for a kolla social at the PTG? | 09:36 |
kolla-slack | <dardelean> hah, good question | 09:42 |
*** jmccarthy has joined #openstack-kolla | 09:57 | |
*** chrizl has joined #openstack-kolla | 10:01 | |
*** ktibi has quit IRC | 10:02 | |
*** ktibi has joined #openstack-kolla | 10:04 | |
*** chrizl has quit IRC | 10:06 | |
jmccarthy | On docker hub, are the 'master' images still queens ? | 10:07 |
*** chrizl has joined #openstack-kolla | 10:07 | |
jmccarthy | For example, here, is master queens ? https://hub.docker.com/r/kolla/oraclelinux-binary-cron/tags/ | 10:12 |
pbourke | jmccarthy: yes master is currently queens | 10:13 |
pbourke | mgoddard_: I reckon a few of us will be heading out :) | 10:14 |
jmccarthy | pbourke: ok, but I thought in the repo, for kolla-ansible, master is rocky now ? | 10:16 |
pbourke | no because we haven't released queens yet | 10:16 |
pbourke | kolla uses a 'trailing release' model | 10:16 |
jmccarthy | pbourke: kk my bad | 10:16 |
pbourke | which means we don't release till a little after the main projects | 10:16 |
mgoddard_ | pbourke: great. If it could not be Tuesday, that would be nice as the ironic social is then. I'm sure that won't be the only conflict though! | 10:19 |
lvdombrkr | folks, prechek fails on : TASK [haproxy : Checking if kolla_internal_vip_address is in the same network as api_interface on all nodes] ******************************************************************* | 10:23 |
lvdombrkr | fatal: [localhost]: FAILED! => {"msg": "The conditional check ''169.254.' not in kolla_internal_vip_address and kolla_internal_vip_address | ipaddr(ip_addr_output.stdout.split()[3]) is none' failed. The error was: ipaddr: unknown filter type: 78.46.87.169"} | 10:23 |
lvdombrkr | to retry, use: --limit @/usr/share/kolla-ansible/ansible/site.retry | 10:23 |
pbourke | mgoddard_: sure thing whatever suits :) | 10:23 |
egonzalez | lvdombrkr, ansible and jinja version? | 10:25 |
*** chrizl has quit IRC | 10:26 | |
lvdombrkr | egonzalez: Jinja2 - 2.10 , ansible: 2.4.2.0 | 10:27 |
*** robbbe has joined #openstack-kolla | 10:29 | |
*** n0isyn0ise has quit IRC | 10:36 | |
lvdombrkr | egonzalez | 10:39 |
lvdombrkr | any ideas? | 10:39 |
*** rmart04 has joined #openstack-kolla | 10:46 | |
*** n0isyn0ise has joined #openstack-kolla | 10:49 | |
*** lvdombrkr has quit IRC | 10:50 | |
*** lvdombrkr has joined #openstack-kolla | 10:51 | |
*** b_bezak has quit IRC | 10:52 | |
*** mdnadeem has joined #openstack-kolla | 10:56 | |
paken | Before pushing a new change for https://review.openstack.org/#/c/541700/ I have a question | 10:56 |
paken | I understand that for cinder-backup, you need both the keyrings for cinder-volume and cinder-backup | 10:57 |
paken | but for they key needed for cinder-volume is just client.ceph.cinder.keyring, right? | 10:58 |
paken | *the key needed… | 10:58 |
*** lujinluo has quit IRC | 11:02 | |
*** chrizl has joined #openstack-kolla | 11:03 | |
*** gkadam has quit IRC | 11:06 | |
*** gkadam has joined #openstack-kolla | 11:07 | |
*** chrizl has quit IRC | 11:08 | |
*** gkadam has quit IRC | 11:12 | |
*** gkadam has joined #openstack-kolla | 11:12 | |
*** chrizl has joined #openstack-kolla | 11:16 | |
egonzalez | lvdombrkr, im not sure if is something related to jinja/ansible or if the VIP is not in the same range of api_interface | 11:17 |
*** gkadam has quit IRC | 11:18 | |
lvdombrkr | egonzalez: if i use public ips, they should also been from one ip range? | 11:20 |
*** chrizl has quit IRC | 11:21 | |
egonzalez | lvdombrkr, only api_interface IP in same range of kolla_internal_vip_address | 11:21 |
lvdombrkr | egonzalez: thanks.. can i just add second ip to api interface from same ip range as api_interface IP..so my api_interface will contain 2ips one from internal_vip range and second not | 11:24 |
lvdombrkr | ? | 11:24 |
egonzalez | lvdombrkr, the second IP is added in keepalived | 11:25 |
egonzalez | lvdombrkr, just define that iP as kolla_internal_vip_address | 11:25 |
lvdombrkr | egonzalez: if i define this ip as kolla_internal vip, i failed on : | 11:29 |
lvdombrkr | TASK [haproxy : Checking if kolla_internal_vip_address and kolla_external_vip_address are not pingable from any node] ********************************************************** | 11:29 |
lvdombrkr | failed: [localhost] (item=178.63.120.51) => {"changed": false, "cmd": ["ping", "-c", "3", "178.63.120.51"], "delta": "0:00:02.002072", "end": "2018-02-20 12:28:26.171722", "fai | 11:29 |
egonzalez | lvdombrkr, the IP address should not be associated to any interface | 11:30 |
egonzalez | lvdombrkr, is an unused IP in the range | 11:30 |
*** gkadam has joined #openstack-kolla | 11:30 | |
egonzalez | lvdombrkr, as example: I have range 192.168.100.0/24 for internal net, i set the IP 192.168.100.10 for eth0 (api_interface). For kolla_internal_vip_address i would set 192.168.100.50 | 11:34 |
egonzalez | the IP shouldnt be pingable from any node before deployment | 11:34 |
*** pbourke has quit IRC | 11:39 | |
*** pbourke has joined #openstack-kolla | 11:40 | |
lvdombrkr | egonzalez: yes i understood... but my host ip right know is example 192.168.24.10, and i have only one free ip from this ip range. bet i have lot if ips from 192.168.25/0 range. so i want to my interface add second ip from range 192.168.25.0/0, for example 192.168.25.10, and set to internal and external vip 192.168.25.11 25.12 | 11:42 |
*** k_mouza has quit IRC | 11:44 | |
*** k_mouza has joined #openstack-kolla | 11:45 | |
*** k_mouza has quit IRC | 11:50 | |
*** vabada has joined #openstack-kolla | 11:50 | |
*** k_mouza has joined #openstack-kolla | 11:51 | |
hrw | mgoddard_: kolla social is one. kolla group photo would be second ;d | 11:53 |
*** zshi has joined #openstack-kolla | 11:54 | |
openstackgerrit | James McCarthy proposed openstack/kolla-ansible master: Update upgrade information in operating-kolla.rst https://review.openstack.org/546127 | 11:55 |
egonzalez | yeah, denver photo was funny | 11:55 |
jmccarthy | I stuck up an initial review there to at least try and get some updates in that guide - I'm sure it will need some picking at/suggestions to make it better ! | 11:56 |
openstackgerrit | James McCarthy proposed openstack/kolla-ansible master: Update upgrade information in operating-kolla.rst https://review.openstack.org/546127 | 12:00 |
jmccarthy | egonzalez: Thanks for feedback ! At line 113 tho, I am just pointing out that those files in /etc/kolla are still at the previous version, I do mention to use merge_passwords from tips and tricks further down | 12:04 |
jmccarthy | (at that stage in the upgrade) | 12:05 |
jmccarthy | What is the missing :: at 102 ? | 12:05 |
*** gkadam has quit IRC | 12:06 | |
hrw | Any idea about this? fatal: [192.168.122.247]: FAILED! => {"msg": "The conditional check '(keystone_bootstrap.stdout | from_json).changed' failed. The error was: Expecting ',' delimiter: line 1 column 417 (char 416)"} | 12:07 |
hrw | fresh all-in-one with master images | 12:07 |
egonzalez | hrw, sue fernet tokens | 12:08 |
egonzalez | uuid were removed from keystone | 12:08 |
egonzalez | *use | 12:08 |
hrw | egonzalez: so we need to update defaults and globals.yml | 12:08 |
egonzalez | jmccarthy, for render as shell | 12:08 |
egonzalez | only globals in your env | 12:08 |
egonzalez | currently we are using master for others projects which is rocky for them | 12:09 |
hrw | egonzalez: fresh master k-a says: # Valid options are [ uuid, fernet ] | 12:09 |
egonzalez | we cannot remove it yet until we release queens | 12:09 |
hrw | ok | 12:09 |
egonzalez | once we tag queens will be fine | 12:09 |
hrw | yep | 12:09 |
hrw | egonzalez: thx. deploy moves on | 12:09 |
jmccarthy | egonzalex: kk thanks ! | 12:11 |
openstackgerrit | James McCarthy proposed openstack/kolla-ansible master: Update upgrade information in operating-kolla.rst https://review.openstack.org/546127 | 12:12 |
openstackgerrit | James McCarthy proposed openstack/kolla-ansible master: Update upgrade information in operating-kolla.rst https://review.openstack.org/546127 | 12:16 |
ktibi | Hi, anyone had already use tempest and cephGW for swift unit tests ? | 12:17 |
openstackgerrit | James McCarthy proposed openstack/kolla-ansible master: Update upgrade information in operating-kolla.rst https://review.openstack.org/546127 | 12:19 |
jmccarthy | Is there a link, maybe from the review or somewhere to see operating-kolla.rst rendered ? | 12:21 |
*** gkadam has joined #openstack-kolla | 12:22 | |
hrw | jmccarthy: once zuul go through it | 12:23 |
jmccarthy | hrw: Thanks ! | 12:24 |
jmccarthy | Please give feedback, docs not my forte, but trying to improve that one at the moment | 12:25 |
*** chrizl has joined #openstack-kolla | 12:27 | |
*** chrizl has quit IRC | 12:32 | |
santacloud | I am still have nova_compute containter restarting all the time.... | 12:42 |
santacloud | any idea? | 12:42 |
openstackgerrit | James McCarthy proposed openstack/kolla-ansible master: Update upgrade information in operating-kolla.rst https://review.openstack.org/546127 | 12:42 |
santacloud | so "TASK [nova : Waiting for nova-compute service up]" always goes into failure | 12:43 |
egonzalez | jmccarthy, rendered version http://logs.openstack.org/27/546127/6/check/build-openstack-sphinx-docs/3625824/html/user/operating-kolla.html | 12:54 |
jmccarthy | egonzalez: Great - thanks ! | 12:55 |
*** gfidente has quit IRC | 12:57 | |
*** gfidente has joined #openstack-kolla | 12:58 | |
*** gfidente has quit IRC | 12:58 | |
*** gfidente has joined #openstack-kolla | 12:58 | |
openstackgerrit | James McCarthy proposed openstack/kolla-ansible master: Update upgrade information in operating-kolla.rst https://review.openstack.org/546127 | 13:02 |
*** masahisa has joined #openstack-kolla | 13:03 | |
*** dasTor has joined #openstack-kolla | 13:09 | |
*** salv-orlando has quit IRC | 13:12 | |
*** salv-orlando has joined #openstack-kolla | 13:12 | |
*** masahisa has quit IRC | 13:13 | |
*** salv-orlando has quit IRC | 13:17 | |
hrw | hm. neutron_openvswitch_agent restarts over and over again. br-ex :( | 13:21 |
*** rhallisey has joined #openstack-kolla | 13:22 | |
*** rhallisey has quit IRC | 13:25 | |
hrw | "Bridge br-ex for physical network physnet1 does not exist. Agent terminated!" - any idea why neutron_openvswitch_agent restarts again and again? all-in-one setup | 13:27 |
*** rhallisey has joined #openstack-kolla | 13:27 | |
hrw | let try without neutron-dvr | 13:29 |
*** skramaja has quit IRC | 13:32 | |
ktibi | egonzalez, hi you added that https://github.com/openstack/kolla-ansible/blame/master/ansible/roles/designate/templates/designate.conf.j2#L96 but no works with designate :/ make trace : https://bugs.launchpad.net/designate/+bug/1571644 | 13:33 |
openstack | Launchpad bug 1571644 in Designate "Error in sink neutron_floatingip handler" [Undecided,Invalid] | 13:33 |
*** chrizl has joined #openstack-kolla | 13:38 | |
*** chrizl has quit IRC | 13:43 | |
*** rmart04 has quit IRC | 13:47 | |
lvdombrkr | folks trying to deploy kolla tag "pike" , all-in-one but deployment fails on : TASK [mariadb : Running MariaDB bootstrap container] ************************************************************************************* | 13:50 |
lvdombrkr | fatal: [localhost]: FAILED! => {"changed": true, "msg": "Container exited with non-zero return code"} | 13:50 |
*** k_mouza has quit IRC | 13:52 | |
lvdombrkr | any ideas? | 13:55 |
kolla-slack | <dardelean> lvdombrkr if I remember correctly I had the same problem, it worked on the second redeploy (did a distroy before as I remember) | 13:55 |
lvdombrkr | kolla-slack: i will try, thanks ) | 13:57 |
*** dave-mccowan has joined #openstack-kolla | 13:58 | |
lvdombrkr | kolla-slack: no luck ( | 14:01 |
*** k_mouza has joined #openstack-kolla | 14:01 | |
lvdombrkr | folks, any other ideas? | 14:02 |
lvdombrkr | maybe need to use other tag not "pike"? | 14:04 |
kolla-slack | <dardelean> what version of kolla-ansible do you have? | 14:04 |
kolla-slack | <dardelean> pip freeze | grep kolla-ansible | 14:05 |
lvdombrkr | kolla-slack: 5.0.1 | 14:06 |
kolla-slack | <dardelean> did you build the images or pulled them? | 14:06 |
kolla-slack | <dardelean> images needs to match the kolla-ansible version | 14:07 |
kolla-slack | <dardelean> is it HA? https://bugs.launchpad.net/kolla-ansible/+bug/1747217 | 14:10 |
openstack | Launchpad bug 1746748 in kolla-ansible pike "duplicate for #1747217 python docker 3.0 package break the kolla-ansible" [Critical,Fix committed] - Assigned to Jeffrey Zhang (jeffrey4l) | 14:10 |
lvdombrkr | kolla-slack: no its all on one deployments, i pulled images not build | 14:13 |
lvdombrkr | folks someone can assist? | 14:24 |
*** rhallisey_ has joined #openstack-kolla | 14:33 | |
*** caoyuan_ has quit IRC | 14:33 | |
*** david-lyle has quit IRC | 14:38 | |
*** k_mouza has quit IRC | 14:38 | |
*** salv-orlando has joined #openstack-kolla | 14:40 | |
*** jtriley has joined #openstack-kolla | 14:46 | |
*** salv-orlando has quit IRC | 14:55 | |
*** salv-orlando has joined #openstack-kolla | 14:56 | |
*** chrizl has joined #openstack-kolla | 14:57 | |
*** salv-orlando has quit IRC | 15:00 | |
openstackgerrit | Harald Jensås proposed openstack/kolla master: Add networking-baremetal - ironic-neutron-agent https://review.openstack.org/546173 | 15:01 |
lvdombrkr | folks i have same problem as : https://bugs.launchpad.net/kolla-ansible/+bug/1748194 | 15:03 |
openstack | Launchpad bug 1748194 in kolla-ansible ""Running MariaDB bootstrap container" fails" [Undecided,New] | 15:03 |
lvdombrkr | any ideas about it? | 15:03 |
*** k_mouza has joined #openstack-kolla | 15:04 | |
santacloud | lvdombrkr: try the master branch | 15:04 |
santacloud | lvdombrkr: it works for me....until task nova compute... | 15:05 |
lvdombrkr | santacloud: openstack_release: "pike" replace with master? | 15:06 |
*** chrizl has quit IRC | 15:07 | |
santacloud | lvdombrkr: how do you install kolla-ansible? | 15:07 |
lvdombrkr | santacloud: step by step following this doc https://docs.openstack.org/kolla-ansible/latest/user/quickstart.html | 15:08 |
santacloud | lvdombrkr: so with pip? | 15:08 |
santacloud | lvdombrkr: try pip uninstall kolla/kolla-ansible, and try git clone ( development way) | 15:09 |
*** k_mouza has quit IRC | 15:11 | |
kolla-slack | <dardelean> santaclout yes, | 15:13 |
kolla-slack | <dardelean> once you cloned, cd kolla-ansible and “pip install .” | 15:13 |
kolla-slack | <dardelean> it will install kolla-ansible from the clone | 15:14 |
kolla-slack | <dardelean> same goes for kolla | 15:14 |
*** itlinux has quit IRC | 15:16 | |
openstackgerrit | Harald Jensås proposed openstack/kolla master: Add networking-baremetal - ironic-neutron-agent https://review.openstack.org/546173 | 15:21 |
lvdombrkr | santacloud kolla-slack : thanks its looks bater | 15:28 |
*** rhallisey_ has quit IRC | 15:31 | |
*** rhallisey_ has joined #openstack-kolla | 15:32 | |
*** mdnadeem has quit IRC | 15:33 | |
santacloud | lvdombrkr: ok, tell me if you also have a nova_compute problem | 15:34 |
*** rhallisey has quit IRC | 15:34 | |
*** rhallisey has joined #openstack-kolla | 15:34 | |
*** paken has quit IRC | 15:34 | |
santacloud | kolla-slack: what about noca_compute container restarting all the time, and task nova compute in failure? | 15:34 |
*** rhallisey_ has quit IRC | 15:34 | |
*** ktibi_ has joined #openstack-kolla | 15:42 | |
*** ktibi has quit IRC | 15:46 | |
*** salv-orlando has joined #openstack-kolla | 15:47 | |
*** david-lyle has joined #openstack-kolla | 15:47 | |
hrw | https://marcin.juszkiewicz.com.pl/2018/02/19/hotplug-in-vm-easy-to-say/ - a story about pcie based VM instances | 15:48 |
lvdombrkr | santacloud: now my deployment fails on : | 15:53 |
lvdombrkr | TASK [keystone : Creating admin project, user, role, service, and endpoint] **************************************************************************************************** | 15:53 |
lvdombrkr | fatal: [localhost]: FAILED! => {"msg": "The conditional check '(keystone_bootstrap.stdout | from_json).changed' failed. The error was: Expecting ',' delimiter: line 1 column 417 (char 416)"} | 15:53 |
santacloud | lvdombrkr: I have not encounter this error... | 15:54 |
*** robbbe has quit IRC | 16:01 | |
*** itlinux has joined #openstack-kolla | 16:06 | |
santacloud | lvdombrkr: I have to leave. See you tomorrow maybe | 16:09 |
openstackgerrit | James McCarthy proposed openstack/kolla-ansible master: Update upgrade information in operating-kolla.rst https://review.openstack.org/546127 | 16:13 |
*** k_mouza has joined #openstack-kolla | 16:14 | |
*** cah_link has quit IRC | 16:15 | |
*** jtriley has quit IRC | 16:20 | |
*** pcaruana has quit IRC | 16:21 | |
*** lvdombrkr has quit IRC | 16:28 | |
*** rhallisey_ has joined #openstack-kolla | 16:35 | |
*** rhallisey has quit IRC | 16:35 | |
*** rhallisey has joined #openstack-kolla | 16:35 | |
*** rhallisey_ has quit IRC | 16:35 | |
*** jtriley has joined #openstack-kolla | 16:36 | |
*** k_mouza has quit IRC | 16:42 | |
*** k_mouza has joined #openstack-kolla | 16:42 | |
*** k_mouza has quit IRC | 16:47 | |
*** k_mouza has joined #openstack-kolla | 16:57 | |
*** k_mouza has quit IRC | 16:57 | |
*** k_mouza has joined #openstack-kolla | 16:57 | |
*** robbbe has joined #openstack-kolla | 16:58 | |
*** itlinux has quit IRC | 17:02 | |
*** itlinux has joined #openstack-kolla | 17:05 | |
*** chrizl has joined #openstack-kolla | 17:17 | |
*** harlowja has joined #openstack-kolla | 17:23 | |
*** lpetrut has quit IRC | 17:30 | |
fungi | inc0: did you manage to make any headway with filtering memcached for bug 1749326? | 17:31 |
openstack | bug 1749326 in kolla-ansible "Exploitable services exposed on community test nodes" [Undecided,New] https://launchpad.net/bugs/1749326 | 17:31 |
*** chrizl has quit IRC | 17:31 | |
*** pcaruana has joined #openstack-kolla | 17:36 | |
*** egonzalez has quit IRC | 17:36 | |
mgoddard_ | shameless plug of my summit proposal on kayobe & kolla: https://www.openstack.org/summit/vancouver-2018/vote-for-speakers/#/20979 | 17:43 |
mgoddard_ | plus a related one on hardware discovery & provisioning: https://www.openstack.org/summit/vancouver-2018/vote-for-speakers/#/21146 | 17:44 |
*** devananda has joined #openstack-kolla | 17:46 | |
*** Denniz has joined #openstack-kolla | 17:46 | |
*** robbbe has quit IRC | 17:47 | |
*** mtsv has quit IRC | 17:54 | |
*** gfidente is now known as gfidente|afk | 17:55 | |
*** mgoddard_ has quit IRC | 18:03 | |
*** openstackgerrit has quit IRC | 18:03 | |
*** k_mouza has quit IRC | 18:04 | |
mchlumsky | Hello, I am trying to build the kolla-toolbox image while adding some certificates to the docker image however I cannot seem to be able to get this to work. I tried this: https://docs.openstack.org/kolla/pike/admin/image-building.html#additions-functionality however I am building a binary centos image and there's a not about this only working with source build types. I also tried using Dockerfile jinja2 customisation with a {% block ... %} | 18:06 |
mchlumsky | and an ADD statement however I'm not sure what to put for the source as kolla-build uses a temp directory. Is there a variable I can use? | 18:06 |
*** robbbe has joined #openstack-kolla | 18:07 | |
*** dklyle has joined #openstack-kolla | 18:08 | |
*** lpetrut has joined #openstack-kolla | 18:10 | |
*** david-lyle has quit IRC | 18:12 | |
*** pcaruana has quit IRC | 18:16 | |
*** harlowja has quit IRC | 18:23 | |
*** robbbe has quit IRC | 18:36 | |
*** mgoddard_ has joined #openstack-kolla | 18:41 | |
*** shardy has quit IRC | 18:43 | |
*** hamzy has quit IRC | 18:44 | |
*** hamzy has joined #openstack-kolla | 18:48 | |
*** dklyle has quit IRC | 18:53 | |
*** harlowja has joined #openstack-kolla | 18:55 | |
*** hamza21 has joined #openstack-kolla | 18:57 | |
*** harlowja_ has joined #openstack-kolla | 18:59 | |
*** david-lyle has joined #openstack-kolla | 18:59 | |
*** harlowja has quit IRC | 18:59 | |
*** sai___ has joined #openstack-kolla | 19:02 | |
*** david-lyle has quit IRC | 19:04 | |
*** david-lyle has joined #openstack-kolla | 19:04 | |
*** paken has joined #openstack-kolla | 19:13 | |
*** athomas has quit IRC | 19:16 | |
*** hamzy has quit IRC | 19:19 | |
*** chrizl has joined #openstack-kolla | 19:20 | |
*** dardelean_ has quit IRC | 19:24 | |
kolla-slack | <dardelean> I also have a presentation on kolla :) https://www.openstack.org/summit/vancouver-2018/vote-for-speakers#/21022 | 19:25 |
kolla-slack | <dardelean> kolla prez ftw | 19:25 |
*** hamzy has joined #openstack-kolla | 19:25 | |
inc0 | fungi: negative :( | 19:28 |
*** chrizl has quit IRC | 19:29 | |
*** mgoddard_ has quit IRC | 19:31 | |
fungi | inc0: looks like it's just the oraclelinux jobs (or at least those were the only nodes which turned up in the provider's scans)... are those critical or can they be temporarily disabled? | 19:33 |
inc0 | fungi: it's very...strange tho | 19:33 |
inc0 | as code is exactly the same as centos jobs | 19:33 |
inc0 | is centos affected or not? | 19:33 |
* fungi wonders if oraclelinux does different firewalling things or includes any extra services in their base image | 19:34 | |
inc0 | pbourke: ^ | 19:34 |
inc0 | it doesn't need anything in base, but default firewall might be more open (?) | 19:34 |
fungi | https://etherpad.openstack.org/p/wpy5XvRYWu is my analysis from the hits the provider reported and the only ones which had memcached show up were oraclelinux | 19:35 |
inc0 | pbourke: can you check https://launchpad.net/bugs/1749326 when you're back please? | 19:35 |
openstack | Launchpad bug 1749326 in kolla-ansible "Exploitable services exposed on community test nodes" [High,Confirmed] | 19:35 |
fungi | so that's not conclusive of course, but a surprising coincidence | 19:35 |
inc0 | well it might be case for all the kolla-ansible gates tho | 19:37 |
fungi | sure, it might | 19:38 |
*** salv-orlando has quit IRC | 19:39 | |
fungi | just odd that over the course of several days the 6 instances their scan picked up were all kolla-ansible-oraclelinux -.* jobs exclusively (and several different variants of them) | 19:40 |
*** salv-orlando has joined #openstack-kolla | 19:40 | |
fungi | are those run more frequently than similar jobs for your other platforms? | 19:41 |
inc0 | no, exactly the same as centos or ubuntu | 19:41 |
fungi | yeah, so statistically this is strange, but 6 hits in 3 days is of course not a statistically significant sample either so could just be an unlikely coincidence | 19:41 |
inc0 | well, it makses sense that all kolla jobs are affected | 19:42 |
inc0 | or multinode jobs at leasy | 19:42 |
inc0 | least | 19:42 |
fungi | unless there's something specific about that platform which is not correctly filtering/blocking access to memcached | 19:42 |
inc0 | https://github.com/openstack/kolla-ansible/blob/master/tests/pre.yml#L37 | 19:42 |
inc0 | yeah | 19:43 |
inc0 | memcached is not protected in any way because well...it's memcached | 19:43 |
fungi | like maybe iptables has to get configured with a different utility or something? | 19:43 |
* fungi knows basically nothing about oraclelinux other than that it was once a fork of rhel) | 19:43 | |
*** salv-orlando has quit IRC | 19:44 | |
inc0 | on the flipside, I don't think we'll need memcached starting Rocky - since keystone is deprecating uuid | 19:45 |
inc0 | fungi: I'll put this into tomorrows meeting agenda | 19:47 |
fungi | thanks for the attention to that issue inc0! | 19:47 |
inc0 | yeah, sorry I didn't touch it before - I'm a bit swamped at the moment | 19:47 |
inc0 | also, Jeffrey4l is our new leader:) | 19:48 |
fungi | i would hate to have a provider threaten to pull their donated resources over exploitable nodes due to risky configuration in a handful of projects | 19:48 |
fungi | so getting this cleaned up quickly will be appreciated | 19:49 |
inc0 | yeah, I know | 19:51 |
inc0 | we're in middle of Chinese new year celebration so bunch of people are off | 19:51 |
*** dave-mccowan has quit IRC | 19:57 | |
*** unicell has joined #openstack-kolla | 19:58 | |
*** david_chou has joined #openstack-kolla | 20:00 | |
david_chou | Hi All, my name is David Chou from Intel Corp. | 20:02 |
inc0 | hey it's Michal | 20:03 |
*** chrizl has joined #openstack-kolla | 20:03 | |
david_chou | Hi Michal. | 20:04 |
inc0 | david_chou: looking at error quickly, can you confirm ansible is 2.3.*? | 20:04 |
inc0 | ansible --version | 20:04 |
david_chou | ansibile --version in my system gave me: | 20:06 |
david_chou | ansible 2.3.3.0 | 20:06 |
david_chou | config file = /etc/ansible/ansible.cfg | 20:06 |
david_chou | configured module search path = Default w/o overrides | 20:06 |
david_chou | python version = 2.7.12 (default, Dec 4 2017, 14:50:18) [GCC 5.4.0 20160609] | 20:06 |
*** jtriley has quit IRC | 20:06 | |
inc0 | are you using virtualenv? | 20:07 |
david_chou | No | 20:07 |
david_chou | JUst baremetal. | 20:08 |
inc0 | can you paste deploy error again please? paste.openstack.org | 20:08 |
*** jtriley has joined #openstack-kolla | 20:10 | |
david_chou | I already open http://paste.openstack.org/ page, just paste the error, or should I put some note? | 20:12 |
inc0 | error log please | 20:12 |
inc0 | or whole execution | 20:12 |
david_chou | Paste #679162 | 20:14 |
inc0 | link please | 20:14 |
david_chou | http://paste.openstack.org/show/679162/ | 20:15 |
*** chrizl has quit IRC | 20:15 | |
inc0 | try to run kolla-ansible destroy --yes-i-really-really-mean-it | 20:16 |
inc0 | and then run deploy again | 20:16 |
david_chou | Do you mean run "sudo ./kolla-ansible destroy -i ./all-in-one --yes-i-really-really-mean-it | 20:18 |
inc0 | yes | 20:18 |
*** mgoddard_ has joined #openstack-kolla | 20:19 | |
david_chou | Sorry. Do you mean run " | 20:19 |
david_chou | sudo ./kolla-ansible destroy --yes-i-really-really-mean-it | 20:20 |
inc0 | yes, you can add -i | 20:20 |
inc0 | it's the same in aipo | 20:20 |
inc0 | aio | 20:20 |
david_chou | what aio mean? | 20:20 |
inc0 | all in one | 20:20 |
*** lpetrut has quit IRC | 20:20 | |
david_chou | Got it. | 20:21 |
david_chou | After " | 20:21 |
david_chou | sudo ./kolla-ansible destroy --yes-i-really-really-mean-it" | 20:21 |
*** signed8bit has joined #openstack-kolla | 20:23 | |
david_chou | Then, I just run "sudo ./kolla-ansible -i ./all-in-one deploy" ? No need to run boot-server and precheck? | 20:23 |
inc0 | just deploy | 20:23 |
david_chou | Got it. Will do. | 20:24 |
david_chou | Same error at same task: | 20:27 |
*** kbaegis has joined #openstack-kolla | 20:27 | |
*** mgoddard_ has quit IRC | 20:27 | |
inc0 | hmm | 20:27 |
kbaegis | Hey- has anyone had an issue where the stack commands aren't populated in the client? | 20:27 |
inc0 | try changing "openstack_release" to queens | 20:27 |
david_chou | Do you mean changing openstack_release from master to queens in /etc/kolla/globals.yml? | 20:31 |
inc0 | yes | 20:32 |
inc0 | or wait | 20:32 |
inc0 | it might not work yet | 20:32 |
david_chou | I will wait. | 20:32 |
kbaegis | seeing: openstack: 'stack' is not an openstack command. | 20:32 |
kbaegis | And I did deploy with heat | 20:33 |
inc0 | kbaegis: you might need to install python-heatclient | 20:33 |
inc0 | david_chou: try openstack_release: "pike" | 20:33 |
*** lpetrut has joined #openstack-kolla | 20:34 | |
david_chou | Will do. | 20:34 |
inc0 | and do pip install --upgrade kolla-ansible==5.* | 20:34 |
*** dave-mccowan has joined #openstack-kolla | 20:37 | |
*** dtk has quit IRC | 20:37 | |
*** marian_tudosoiu has quit IRC | 20:37 | |
*** dtk has joined #openstack-kolla | 20:38 | |
*** marian_tudosoiu has joined #openstack-kolla | 20:38 | |
*** pcaruana has joined #openstack-kolla | 20:40 | |
kbaegis | inc0: ty | 20:40 |
*** salv-orlando has joined #openstack-kolla | 20:40 | |
*** salv-orlando has quit IRC | 20:45 | |
kolla-slack | <dardelean> what's the state of kolla-k8s nowadays? | 20:52 |
*** dave-mccowan has quit IRC | 20:56 | |
*** gfidente|afk has quit IRC | 20:56 | |
*** dmellado has quit IRC | 20:58 | |
*** hamza21 has quit IRC | 21:02 | |
*** salv-orlando has joined #openstack-kolla | 21:03 | |
*** marian_tudosoiu has quit IRC | 21:12 | |
*** dtk has quit IRC | 21:12 | |
*** dtk has joined #openstack-kolla | 21:14 | |
*** marian_tudosoiu has joined #openstack-kolla | 21:14 | |
*** kbaegis has quit IRC | 21:21 | |
*** rhallisey has quit IRC | 21:21 | |
*** Denniz has quit IRC | 21:33 | |
david_chou | inc0: Good news, with "sudo ip install --upgrade kolla-ansible==5.*" and openstack_release = "pike", "sudo ./kolla-ansible -i ./all-in-one deploy" completed without error: | 21:34 |
david_chou | TASK [blazar : include] ******************************************************** | 21:34 |
david_chou | skipping: [localhost] | 21:34 |
david_chou | PLAY RECAP ********************************************************************* | 21:34 |
david_chou | localhost : ok=224 changed=140 unreachable=0 failed=0 | 21:34 |
hogepodge | Is any one from kolla-k8s going to the helm summit in Portland tomorrow? | 21:35 |
hogepodge | I'll be there, and am happy to bring up any items you'd like me to talk about. | 21:35 |
inc0 | hogepodge: jascott and kfox will be there | 21:35 |
*** pcaruana has quit IRC | 21:37 | |
hogepodge | ah great, excellent | 21:39 |
*** ktibi_ has quit IRC | 21:44 | |
*** chrizl has joined #openstack-kolla | 21:54 | |
kolla-slack | <dardelean> inc0 still not coming to the PTG? :( | 22:00 |
*** jtriley has quit IRC | 22:02 | |
*** chrizl has quit IRC | 22:06 | |
*** chrizl has joined #openstack-kolla | 22:08 | |
*** devananda has quit IRC | 22:09 | |
*** dciabrin has joined #openstack-kolla | 22:14 | |
*** dciabrin_ has quit IRC | 22:15 | |
*** dmellado has joined #openstack-kolla | 22:18 | |
*** chrizl has quit IRC | 22:18 | |
*** dciabrin has quit IRC | 22:19 | |
*** dciabrin has joined #openstack-kolla | 22:19 | |
*** paken has quit IRC | 22:19 | |
*** dciabrin_ has joined #openstack-kolla | 22:22 | |
*** dciabrin has quit IRC | 22:22 | |
*** threestrands has joined #openstack-kolla | 22:23 | |
*** k_mouza has joined #openstack-kolla | 22:28 | |
*** kolla-slack has quit IRC | 22:44 | |
*** kolla-slack has joined #openstack-kolla | 22:44 | |
*** itlinux has quit IRC | 22:49 | |
david_chou | inc0: I followed the instruction in "Using OpenStack" section in "https://docs.openstack.org/kolla-ansible/latest/user/quickstart.html" | 22:54 |
david_chou | inc0: It seems that I could completed all steps successfully in this "Using OpenStack" section. | 22:56 |
SpamapS | hrm.. more security questions.. it seems that kolla-ansible configures internal APIs to listen on not-TLS | 22:56 |
SpamapS | which seems like.. a bad idea. | 22:56 |
david_chou | inc0: | 22:56 |
david_chou | inc0: The last step: ". . kolla-ansible/tools/init-runonce", I run in two steps: | 22:57 |
inc0 | SpamapS: well there is story to that | 22:58 |
david_chou | inc0: 1. cd ~/kolla-ansible 2. sudo ./init-runonce | 22:58 |
SpamapS | inc0: do tell | 22:58 |
inc0 | that revolves around memcached | 22:59 |
SpamapS | because.. between that and assuming keepalived.. I'm bending over backward trying to make kolla-ansible work for us. | 22:59 |
inc0 | and it goes like that: we can't make memcached secure | 22:59 |
SpamapS | (we have external non-TLS terminating load balancers that we use) | 22:59 |
inc0 | so we assume that whoever has access to your internal net, has access to your tokens (including admin) | 22:59 |
inc0 | you can use TLS easily tho | 23:00 |
inc0 | well you'll need to make few changes in globals, but should be fine | 23:00 |
SpamapS | memcached is encrypted.. so.. ? | 23:01 |
inc0 | traffic to memcached isn't | 23:01 |
inc0 | https://github.com/openstack/kolla-ansible/blob/d474987ad9722c63bf6bf964ca80d810b89a313e/ansible/roles/heat/defaults/main.yml#L66 | 23:01 |
inc0 | check this out | 23:01 |
SpamapS | and we can't https://github.com/memcached/memcached/wiki/SASLHowto ? | 23:02 |
inc0 | https://github.com/openstack/kolla-ansible/blob/master/ansible/group_vars/all.yml#L325 | 23:02 |
inc0 | override this with https | 23:02 |
inc0 | and make sure your kolla_internal_fqdn will point to your load balancers, which will terminate https | 23:03 |
SpamapS | inc0: but that won't make haproxy actually listen on https. | 23:03 |
SpamapS | no my lb's do not terminate https | 23:03 |
inc0 | so you have lb that will then point to haproxy? | 23:04 |
SpamapS | yeah | 23:04 |
inc0 | ok, so I guess you have same issue as mgoddard, we need better way to include custom confs in haproxy | 23:04 |
inc0 | https://review.openstack.org/#/c/534834/ | 23:05 |
inc0 | then you can inject https termination there | 23:05 |
SpamapS | Yeah I'm patching haproxy.cfg.j2 right now to add tls_bind to the internal ones, and disabling my external vip. | 23:05 |
inc0 | only thing would be to add some logic to lay down ssl certs | 23:05 |
SpamapS | that's already there for the external vip | 23:06 |
inc0 | talk to mgoddard (he's in GB, so mornings) and you two could try to figure out better way to make configs in haproxy | 23:06 |
inc0 | I believe there will be topic about that in PTG | 23:06 |
SpamapS | I may just let this go for now.. | 23:06 |
SpamapS | already almost 2 weeks late :-P | 23:06 |
*** santacloud has quit IRC | 23:07 | |
inc0 | well if you handcraft your haproxy.cfg that's fine | 23:07 |
inc0 | (you can also just copy default with all the jinja2 stuff and edit it there) | 23:07 |
inc0 | not ideal, but will get you there | 23:07 |
*** lpetrut has quit IRC | 23:11 | |
*** chrizl has joined #openstack-kolla | 23:12 | |
*** chrizl has quit IRC | 23:30 | |
*** spiette has quit IRC | 23:51 | |
*** masahisa has joined #openstack-kolla | 23:52 | |
*** k_mouza has quit IRC | 23:57 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!