Friday, 2018-01-05

*** salmankhan has quit IRC00:00
rm_workjohnsom: err can you pastebin me your command?00:03
johnsomopenssl pkcs12 -export -nodes -inkey testcert.key -in testcert.pem -certfile ca_cert.pem -out testcert.p1200:03
rm_workin the patch in the cookbook section is the exact command i ran00:03
johnsomEnter Export Password:00:04
johnsomVerifying - Enter Export Password:00:04
rm_workhmmmmmmmm00:04
rm_workwhat version of openssl are you running00:04
johnsomI tried with both -nodes and without00:04
johnsomOpenSSL 1.0.2g  1 Mar 201600:04
rm_workerg mine may just be stupid old00:05
johnsomUbuntu 16.0400:05
rm_worki'm using 0.9.8zh on OSX T_T00:05
rm_worki looked for a way to do the passphrases for a while, never found it (on OSX)00:05
rm_worki may have to look at that again00:05
rm_workugh00:05
johnsomOk, I commented on the patch so I could move on to other patch reviews00:06
rm_workkk00:06
rm_workAmphora Failover API could use a +A :P00:06
rm_workwhenev00:06
rm_work^_^00:06
johnsomWorking my way there00:06
*** sanfern has joined #openstack-lbaas01:48
*** threestrands_ has joined #openstack-lbaas02:14
*** threestrands_ has quit IRC02:14
*** threestrands_ has joined #openstack-lbaas02:14
*** threestrands has quit IRC02:16
*** sanfern has quit IRC02:34
*** harlowja has quit IRC02:36
openstackgerrithuangshan proposed openstack/octavia master: Check if it is used when creating a load balancer using vip_port_id  https://review.openstack.org/52506902:41
openstackgerritMerged openstack/octavia master: Improve user error messages for duplicate objects  https://review.openstack.org/52837003:15
openstackgerritMerged openstack/octavia master: Fix exception when querying for non-existing items  https://review.openstack.org/53088603:15
*** yamamoto has joined #openstack-lbaas03:28
*** links has joined #openstack-lbaas03:29
*** gans has joined #openstack-lbaas03:32
*** links has quit IRC03:34
*** reedip has joined #openstack-lbaas03:34
*** annp has joined #openstack-lbaas03:56
*** links has joined #openstack-lbaas03:56
openstackgerritMerged openstack/octavia master: Add VIP qos into our cookbook  https://review.openstack.org/53031804:03
*** dayou has quit IRC04:45
*** dayou has joined #openstack-lbaas04:46
*** ianychoi has quit IRC05:52
*** threestrands_ has quit IRC06:13
*** dayou has quit IRC06:43
*** fnaval has joined #openstack-lbaas06:55
*** dayou has joined #openstack-lbaas07:03
*** fnaval has quit IRC07:06
openstackgerritMerged openstack/octavia master: TrivialFix: remove redundant import alias  https://review.openstack.org/52979707:14
*** armax has quit IRC07:29
*** b_bezak has joined #openstack-lbaas07:49
*** tesseract has joined #openstack-lbaas08:12
openstackgerritMerged openstack/octavia master: Minimize the effect overloaded Health Manager processes  https://review.openstack.org/53100608:17
*** rcernin has quit IRC08:28
*** armax has joined #openstack-lbaas08:55
*** armax has quit IRC09:14
*** cristicalin has joined #openstack-lbaas09:34
*** cristicalin has quit IRC09:39
*** aojea has joined #openstack-lbaas10:07
*** aojea_ has joined #openstack-lbaas10:13
*** aojea has quit IRC10:16
*** aojea has joined #openstack-lbaas10:18
*** aojea_ has quit IRC10:22
*** aojea_ has joined #openstack-lbaas10:23
*** salmankhan has joined #openstack-lbaas10:25
*** aojea has quit IRC10:26
*** aojea has joined #openstack-lbaas10:29
*** aojea_ has quit IRC10:31
*** aojea has quit IRC10:37
*** reedip has quit IRC10:39
*** sanfern has joined #openstack-lbaas10:40
*** salmankhan has quit IRC10:47
openstackgerritSanthosh Fernandes proposed openstack/octavia master: [WIP] L3 ACTIVE-ACTIVE Data model impact  https://review.openstack.org/52472210:49
*** reedip has joined #openstack-lbaas10:52
*** sanfern has quit IRC10:56
*** gans has quit IRC10:59
*** pcaruana has joined #openstack-lbaas11:01
*** aojea has joined #openstack-lbaas11:10
*** aojea_ has joined #openstack-lbaas11:14
*** aojea has quit IRC11:16
*** aojea has joined #openstack-lbaas11:19
*** aojea_ has quit IRC11:22
*** aojea_ has joined #openstack-lbaas11:25
*** aojea has quit IRC11:28
*** aojea has joined #openstack-lbaas11:29
*** aojea_ has quit IRC11:32
*** aojea_ has joined #openstack-lbaas11:34
*** aojea has quit IRC11:37
*** aojea has joined #openstack-lbaas11:40
*** aojea_ has quit IRC11:42
*** aojea_ has joined #openstack-lbaas11:45
*** aojea has quit IRC11:47
*** aojea has joined #openstack-lbaas11:49
*** salmankhan has joined #openstack-lbaas11:49
*** aojea_ has quit IRC11:52
*** aojea_ has joined #openstack-lbaas11:55
*** aojea has quit IRC11:57
*** aojea has joined #openstack-lbaas12:00
*** annp has quit IRC12:00
*** aojea_ has quit IRC12:03
*** aojea has quit IRC12:07
*** salmankhan has quit IRC12:13
*** kong has quit IRC12:23
*** numans has joined #openstack-lbaas12:24
*** numans has quit IRC12:25
*** numans has joined #openstack-lbaas12:30
*** salmankhan has joined #openstack-lbaas12:52
*** salmankhan has quit IRC12:58
*** atoth has joined #openstack-lbaas13:29
*** salmankhan has joined #openstack-lbaas13:40
*** dayou has quit IRC13:45
*** links has quit IRC13:47
*** dayou has joined #openstack-lbaas13:54
*** dayou has quit IRC14:00
*** dayou has joined #openstack-lbaas14:02
*** dayou has quit IRC14:08
*** dayou has joined #openstack-lbaas14:22
*** KeithMnemonic has joined #openstack-lbaas14:31
*** longstaff has joined #openstack-lbaas15:20
*** fnaval has joined #openstack-lbaas15:29
*** fnaval has quit IRC15:34
openstackgerritBernard Cafarelli proposed openstack/octavia master: Rework amphora agent installation element  https://review.openstack.org/52262615:34
openstackgerritBernard Cafarelli proposed openstack/octavia master: Allow setting full mandatory access control in amphora  https://review.openstack.org/52638015:34
*** b_bezak has quit IRC15:41
*** longstaf_ has joined #openstack-lbaas15:57
*** longstaff has quit IRC16:01
*** longstaf_ has left #openstack-lbaas16:09
*** longstaf_ has joined #openstack-lbaas16:09
*** sanfern has joined #openstack-lbaas16:11
*** yamamoto has quit IRC16:26
*** fnaval has joined #openstack-lbaas16:35
*** b_bezak has joined #openstack-lbaas16:36
*** fnaval has quit IRC16:37
*** armax has joined #openstack-lbaas16:39
*** openstackstatus has quit IRC16:40
*** openstackstatus has joined #openstack-lbaas16:41
*** ChanServ sets mode: +v openstackstatus16:41
sanfernHi johnsom,16:43
*** yamamoto has joined #openstack-lbaas16:50
johnsomHi sanfern, in a meeting so my response might be late16:55
*** pcaruana has quit IRC17:21
*** sanfern has quit IRC17:31
*** salmankhan has quit IRC17:44
*** yamamoto has quit IRC17:47
*** kbyrne has joined #openstack-lbaas17:47
*** yamamoto has joined #openstack-lbaas18:03
*** yamamoto has quit IRC18:07
*** harlowja has joined #openstack-lbaas18:09
*** sanfern has joined #openstack-lbaas18:10
openstackgerritSanthosh Fernandes proposed openstack/octavia master: [WIP] L3 ACTIVE-ACTIVE Data model impact  https://review.openstack.org/52472218:13
*** sanfern has quit IRC18:20
*** leitan has joined #openstack-lbaas18:21
leitanHi guys, hope you had a great holidays, been running octavia on prod for almost a year now, very happy, i have a question related the default flavor for the amphoraes18:22
leitani configured a flavor based on the consumption of the legacy haproxy we had18:22
leitanbut now i realized the flavor is oversized18:22
leitanand i want to reclaim some memory and vcpus18:22
leitantwo questions18:22
leitan1 - if i change the default flavor id for amphorae, something breaks on the existing load balancers ?18:23
leitan2 - i was thinking to change de fault flavor, create new LBs, and replace the oversized with new ones, with same backends etc, and claim the resources from the cloud that way, sounds logical ?18:24
johnsomleitan Hello, so if the flavor ID is updated on the control plane, if the amphora gets rebuilt for any reason it will use the updated flavor ID.  This is to allow you to make changes like this and do failovers, etc.18:24
johnsomleitan Yes, if you are running active/standby you can do it in a rolling way. No problem.18:25
johnsomIf you have recent code, we added the LB failover API for this reason18:25
leitanjohnsom: thats great, so if i update the deafault amp_flavor_id on the octavia conf, and destroy the active LB, it will create a new one with the updated flavor18:25
leitanjohnsom: no, i have old code18:25
leitanbut im using active passive18:25
johnsomhttps://developer.openstack.org/api-ref/load-balancer/v2/index.html#failover-a-load-balancer18:25
johnsomleitan Yes, but remember to restart the controller processes so it picks up the config change18:26
leitanyes, i was planning on restarting the api housekeeper worker and health manager18:27
leitanjust FYI im using octavia-0.10.1.dev106 johnsom18:27
johnsomOk, so Ocata release.18:28
johnsomDon't forget the controller worker process.  It is important here18:28
johnsomYou might consider building a fresh amphora image and uploading it before you do these failovers to pick up an OS patches, etc.18:30
johnsomOf course test out the image and process on a non-critical LB first just to make sure you have everything in order18:30
leitanjohnsom: sure thing ! thanksss18:37
johnsomNP18:37
leitanill try it out and let you know18:37
*** salmankhan has joined #openstack-lbaas18:44
*** yamamoto has joined #openstack-lbaas18:48
*** numans has quit IRC18:50
johnsomFYI, I am asking around about a new openstacksdk release for the fix we need for the octavia-dashboard patches.18:51
*** numans has joined #openstack-lbaas18:51
*** yamamoto has quit IRC18:52
openstackgerritMichael Johnson proposed openstack/octavia master: VIP port is created with port_security_enabled: False  https://review.openstack.org/52944918:56
*** openstack has joined #openstack-lbaas21:17
*** ChanServ sets mode: +o openstack21:17
*** fnaval has joined #openstack-lbaas21:23
*** fnaval has quit IRC21:25
*** numans has quit IRC21:25
*** numans has joined #openstack-lbaas21:28
johnsomlongstaff Hi21:54
longstaffHi -- I want to finish the provider driver spec. Do you have anything in flight, or should I just go ahead and address the remaining comments?21:55
johnsomPlease go ahead, I was holding off as I thought you mentioned you were working on an update21:56
longstaffGreat. I'll go ahead and post a new patch with requested changes. Thanks.21:57
johnsomPerfect, thanks!21:57
*** yamamoto has joined #openstack-lbaas22:04
*** yamamoto has quit IRC22:17
rm_workanyone know how using rabbitmq in a cluster with HA queues works?22:26
rm_workre: configuring it in octavia.conf22:26
rm_workthere's a nice guide here but it's a little sparse with regard to reasoning: https://docs.openstack.org/ha-guide/shared-messaging.html22:26
johnsomI did at one point, I think there is a small discussion in oslo messaging docs22:27
rm_worklike... if i already configured rabbit to HA all the queues, do I *need* `rabbit_ha_queues=true` in my config?22:27
rm_workand are they recommending `rabbit_max_retries=0` for a reason? like, it needs to give up immediately to cycle to the next server in the list? or can i leave it with higher retries?22:27
johnsomhttps://docs.openstack.org/oslo.messaging/latest/reference/transport.html#oslo_messaging.TransportURL22:29
rm_workright22:29
rm_worki have that line22:29
rm_workwith the commas22:29
rm_worktransport_url = rabbit://octavia:****@oct-rbt-z1-01,octavia:****@oct-rbt-z2-01,octavia:****@oct-rbt-z3-01/22:30
rm_workbut the other options ... i could just copy them but i don't like to cargo-cult, kinda want to know WHY they disabled retries22:30
johnsomYou are going beyond my experience on this one.  All I can say is dig through this: https://docs.openstack.org/oslo.messaging/latest/configuration/opts.html#oslo-messaging-rabbit22:31
johnsomThere might be something in the HA guide too22:31
johnsomLet me look in the HA guide too22:31
rm_worki linked the page on this from the HA guide :P22:32
*** fnaval has joined #openstack-lbaas22:32
johnsomhttps://docs.openstack.org/ha-guide/shared-messaging.html22:32
johnsomAh, yeah, so you did22:32
johnsomSorry, context switching with fixing the openstacksdk gates that just dropped testing octavia....22:32
johnsomugh22:32
rm_worklol well22:32
rm_workrabbit_max_retries is deprecated22:33
rm_workso whatever22:33
johnsomopenstack.tests.functional.load_balancer.v2.test_load_balancer.TestLoadBalancer.test_health_monitor_find ... SKIPPED: Service load-balancer not found in cloud22:33
rm_workah and yeah actually22:33
rm_workrabbit_ha_queues question is answered via your conf link too22:33
rm_workit's ignored in rabbit 3.x22:33
rm_workso, woo. thanks :P22:33
rm_workdidn't expect to find answers in there, but glad i read it anyway :P22:33
rm_workthanks for the link22:33
johnsomNP22:34
rm_workdo you run rabbit in SSL mode?22:34
*** fnaval has quit IRC22:34
johnsomNo, I don't think so (for dev work)22:34
johnsomnope22:35
rm_worki am thinking about prod work22:35
rm_workthough we don't store anything sensitive right?22:35
johnsomYeah, you probably should22:35
johnsomNot really, but you don't want injection either22:36
rm_workah22:36
rm_work:/22:36
*** fnaval has joined #openstack-lbaas22:37
johnsomThe rabbit creds probably go over it in the clear too, not sure though22:37
rm_work>_<22:37
johnsomHey, I didn't write ampq22:38
johnsomgrin22:38
johnsomSo, TLS, yes, have some22:38
*** fnaval has quit IRC22:40
*** slaweq_ has quit IRC22:48
*** ltomasbo has quit IRC23:11
*** fnaval has joined #openstack-lbaas23:12
rm_workOH johnsom now that I have been back for a little bit, i remembered the deal with pkcs12 and passphrases23:12
rm_workwhat you found was *passphrase protecting the pkcs12 file*23:12
rm_worknot "storing the passphrase for the key you're bundling"23:13
johnsomWell, I ran the command in the cookbook.  I also tried -nodes23:13
rm_workpkcs12 doesn't have a slot by default for a passphrase for a key that's inside it23:13
rm_workbecause honestly storing a key and its passphrase in the same object would be really dumb23:14
rm_workso the command actually didn't execute?23:14
rm_worki thought you were just saying that it said it would let you use a passphrase23:14
*** fnaval has quit IRC23:15
johnsomNo, it forces me to enter an "export passphrase23:16
rm_workoh23:16
rm_workjust hit enter twice23:16
rm_worki may need to document that23:16
johnsomand it's not just for the key, it asks to confirm the passphrase23:16
johnsomYeah, it seemed to conflict with the release notes comment, etc.  So confused me, meaning we will get questions23:17
*** fnaval has joined #openstack-lbaas23:22
*** fnaval has quit IRC23:24
*** slaweq has joined #openstack-lbaas23:39
rm_worklet me know for sure if just pressing enter twice works for you23:42
openstackgerritMichael Johnson proposed openstack/python-octaviaclient master: Update new documentation PTI jobs  https://review.openstack.org/53038423:44
*** slaweq has quit IRC23:44
johnsomYeah, it will be a bit before I circle back around to that. I still have a capable stack, just working on a few other patches at the moment.23:44
rm_worknp23:48
rm_worktrying to figure out where/how we generate a client cert for amp communication23:49
rm_workin like... devstack23:49
rm_workah nm it was where i thought it should be, just missed it the first time23:50
*** longstaff has quit IRC23:56

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!