*** bcafarel has quit IRC | 00:06 | |
*** atoth has quit IRC | 00:12 | |
*** bcafarel has joined #openstack-lbaas | 00:15 | |
*** dayou has quit IRC | 00:31 | |
*** dayou has joined #openstack-lbaas | 01:40 | |
*** threestrands_ has joined #openstack-lbaas | 01:40 | |
*** threestrands has quit IRC | 01:43 | |
*** armax has joined #openstack-lbaas | 01:44 | |
*** annp has joined #openstack-lbaas | 02:54 | |
*** jappleii__ has joined #openstack-lbaas | 03:12 | |
*** jappleii__ has quit IRC | 03:13 | |
*** jappleii__ has joined #openstack-lbaas | 03:13 | |
*** threestrands_ has quit IRC | 03:15 | |
*** dayou has quit IRC | 03:21 | |
*** yamamoto has joined #openstack-lbaas | 04:05 | |
*** sanfern has joined #openstack-lbaas | 04:16 | |
openstackgerrit | Hengqing Hu proposed openstack/octavia master: Able to set frontend network for loadbalancer https://review.openstack.org/529936 | 04:20 |
---|---|---|
*** dayou has joined #openstack-lbaas | 04:22 | |
-openstackstatus- NOTICE: The logs.openstack.org filesystem has been restored to full health. We are attempting to keep logs uploaded between the prior alert and this one, however if your job logs are missing please issue a recheck. | 04:48 | |
*** ChanServ changes topic to "The logs.openstack.org filesystem has been restored to full health. We are attempting to keep logs uploaded between the prior alert and this one, however if your job logs are missing please issue a recheck." | 04:48 | |
*** ChanServ changes topic to "Welcome to LBaaS / Octavia - Queens development is now open." | 04:53 | |
*** links has joined #openstack-lbaas | 05:11 | |
*** pcaruana has joined #openstack-lbaas | 05:23 | |
*** pcaruana has quit IRC | 05:32 | |
openstackgerrit | Hengqing Hu proposed openstack/octavia master: Able to set frontend network for loadbalancer https://review.openstack.org/529936 | 05:53 |
*** yamamoto_ has joined #openstack-lbaas | 05:55 | |
*** yamamoto_ has quit IRC | 05:55 | |
*** yamamoto has quit IRC | 05:59 | |
*** yamamoto has joined #openstack-lbaas | 06:16 | |
openstackgerrit | huangshan proposed openstack/python-octaviaclient master: Add failover an amphora client support https://review.openstack.org/532424 | 06:57 |
*** gcheresh has joined #openstack-lbaas | 06:58 | |
*** jappleii__ has quit IRC | 07:02 | |
*** sapd_ has quit IRC | 07:16 | |
*** sapd has joined #openstack-lbaas | 07:17 | |
*** sapd_ has joined #openstack-lbaas | 07:20 | |
*** sapd has quit IRC | 07:22 | |
*** Alex_Staf has joined #openstack-lbaas | 07:25 | |
*** sapd has joined #openstack-lbaas | 07:34 | |
*** AlexeyAbashkin has joined #openstack-lbaas | 07:54 | |
*** rcernin has quit IRC | 07:59 | |
*** ivveh has joined #openstack-lbaas | 08:28 | |
ivveh | hi guys, i was wondering if anyone has time to look a bit at a lbaas v2 issue? basically everything is working but when i assign a floating ip to the lb it doesn't forward to the internal net. from the local (internal) subnet router i can curl via the namespace towards the internal lb-vip. i have modified default sec_group to allow all traffic for testing. ill supply some logs here in | 08:31 |
ivveh | a sec | 08:31 |
openstackgerrit | Eric Lei proposed openstack/neutron-lbaas-dashboard master: Fix the wrong urls in README.rst https://review.openstack.org/531985 | 08:33 |
ivveh | https://hastebin.com/ecesunafaj.bash | 08:41 |
ivveh | assigned floating ips to the httpd servers just for testing & verification | 08:41 |
ivveh | but no access to http://192.168.20.14 from the network 192.168.20.0/24 | 08:43 |
ivveh | forgot to add it but the LB has a complete arp table to the internal 3x httpd servers including the local router (10.167.35.1) | 08:46 |
ivveh | and communication works fine there | 08:46 |
ivveh | the internal router has full communication with other floating ips such as the testing floating ips assigned from the lbaas-[1..3] or other test instances | 08:47 |
ivveh | routing tables & routing works with the external network as well | 08:48 |
ivveh | i can't spot any errors in iptables, but that was my first guess :) | 08:48 |
ivveh | lbaas logs are empty :( | 08:49 |
ivveh | nothing particular in any of the other agents logs either | 08:50 |
ivveh | added some additional logs | 08:58 |
ivveh | https://hastebin.com/inowoxugaf.bash | 08:58 |
*** aojea has joined #openstack-lbaas | 09:11 | |
ndanl4 | hi | 09:35 |
ndanl4 | if I want to us LB | 09:35 |
ndanl4 | with DVR setup, do I need to modify anything on the compute hosts ? | 09:36 |
*** sapd has quit IRC | 09:46 | |
*** sapd has joined #openstack-lbaas | 09:59 | |
openstackgerrit | Ganpat Agarwal proposed openstack/octavia master: [WIP] ACTIVE-ACTIVE ExaBGP rest api driver https://review.openstack.org/527009 | 10:01 |
*** salmankhan has joined #openstack-lbaas | 10:04 | |
*** salmankhan1 has joined #openstack-lbaas | 10:12 | |
*** salmankhan has quit IRC | 10:15 | |
*** salmankhan1 is now known as salmankhan | 10:15 | |
*** aojea has quit IRC | 10:39 | |
*** aojea has joined #openstack-lbaas | 10:44 | |
*** aojea_ has joined #openstack-lbaas | 10:44 | |
*** sapd has quit IRC | 10:45 | |
*** aojea has quit IRC | 10:49 | |
*** annp has quit IRC | 10:51 | |
*** sanfern has quit IRC | 10:51 | |
*** gans has joined #openstack-lbaas | 11:05 | |
*** yamamoto has quit IRC | 11:11 | |
*** yamamoto has joined #openstack-lbaas | 11:11 | |
*** gans has quit IRC | 11:16 | |
openstackgerrit | Lingxian Kong proposed openstack/octavia-tempest-plugin master: Create floating ip by normal user https://review.openstack.org/533615 | 11:24 |
*** yamamoto_ has joined #openstack-lbaas | 11:26 | |
*** yamamoto has quit IRC | 11:29 | |
openstackgerrit | Lingxian Kong proposed openstack/octavia-tempest-plugin master: Add basic tests for listeners https://review.openstack.org/492311 | 11:35 |
*** pcaruana has joined #openstack-lbaas | 11:44 | |
*** sanfern has joined #openstack-lbaas | 12:08 | |
*** tesseract has joined #openstack-lbaas | 12:15 | |
*** beagles is now known as beagles_mtg | 13:01 | |
*** openstackgerrit has quit IRC | 13:18 | |
*** beagles_mtg is now known as beagles | 13:55 | |
*** ndanl4 has quit IRC | 14:10 | |
*** atoth has joined #openstack-lbaas | 14:27 | |
*** fishbone_ has quit IRC | 14:32 | |
*** gcheresh has quit IRC | 15:03 | |
*** yamamoto_ has quit IRC | 15:06 | |
*** armax has quit IRC | 15:17 | |
*** links has quit IRC | 15:20 | |
*** irenab has quit IRC | 15:26 | |
*** irenab has joined #openstack-lbaas | 15:29 | |
*** armax has joined #openstack-lbaas | 15:47 | |
*** longstaff has joined #openstack-lbaas | 15:48 | |
*** aojea_ has quit IRC | 16:04 | |
*** aojea has joined #openstack-lbaas | 16:04 | |
*** yamamoto has joined #openstack-lbaas | 16:07 | |
*** yamamoto has quit IRC | 16:14 | |
*** ivve has quit IRC | 16:35 | |
*** AlexeyAbashkin has quit IRC | 16:39 | |
*** AlexeyAbashkin has joined #openstack-lbaas | 16:39 | |
*** tesseract has quit IRC | 16:40 | |
*** AlexeyAbashkin has quit IRC | 16:47 | |
*** ivve has joined #openstack-lbaas | 16:50 | |
*** longstaff has quit IRC | 17:00 | |
*** longstaff has joined #openstack-lbaas | 17:11 | |
*** Alex_Staf has quit IRC | 17:19 | |
*** links has joined #openstack-lbaas | 17:21 | |
*** links has quit IRC | 17:50 | |
*** longstaff has quit IRC | 18:14 | |
*** ivve has quit IRC | 18:16 | |
*** Swami_ has joined #openstack-lbaas | 18:20 | |
-openstackstatus- NOTICE: Zuul has been restarted and has lost queue contents; changes in progress will need to be rechecked. | 18:23 | |
*** ChanServ sets mode: +o johnsom | 18:29 | |
*** ivve has joined #openstack-lbaas | 18:29 | |
*** ChanServ changes topic to "Welcome to LBaaS / Octavia - Queens priority review etherpad https://etherpad.openstack.org/p/Octavia-Queens-Priority-Review" | 18:31 | |
*** ChanServ sets mode: -o johnsom | 18:32 | |
johnsom | FYI, I have started a Queens priority review/bug etherpad for Queens. The URL is in the channel topic. https://etherpad.openstack.org/p/Octavia-Queens-Priority-Review | 18:32 |
*** sanfern has quit IRC | 18:34 | |
*** sanfern has joined #openstack-lbaas | 18:34 | |
*** sanfern has quit IRC | 18:34 | |
*** aojea has quit IRC | 18:36 | |
*** salmankhan has quit IRC | 18:41 | |
*** AlexeyAbashkin has joined #openstack-lbaas | 18:50 | |
*** aojea has joined #openstack-lbaas | 18:51 | |
*** AlexeyAbashkin has quit IRC | 18:55 | |
*** aojea_ has joined #openstack-lbaas | 18:57 | |
*** aojea has quit IRC | 18:59 | |
*** aojea has joined #openstack-lbaas | 19:02 | |
*** aojea_ has quit IRC | 19:05 | |
*** longstaff has joined #openstack-lbaas | 19:06 | |
*** longstaff has joined #openstack-lbaas | 19:06 | |
*** aojea_ has joined #openstack-lbaas | 19:08 | |
*** openstackgerrit has joined #openstack-lbaas | 19:08 | |
openstackgerrit | Michael Johnson proposed openstack/octavia-dashboard master: Update the installation and contributors documents https://review.openstack.org/533760 | 19:08 |
*** aojea has quit IRC | 19:11 | |
*** aojea has joined #openstack-lbaas | 19:12 | |
*** aojea_ has quit IRC | 19:15 | |
*** aojea_ has joined #openstack-lbaas | 19:18 | |
*** aojea has quit IRC | 19:20 | |
*** aojea has joined #openstack-lbaas | 19:23 | |
*** aojea_ has quit IRC | 19:26 | |
*** fnaval has joined #openstack-lbaas | 19:27 | |
*** fnaval_ has joined #openstack-lbaas | 19:28 | |
*** aojea_ has joined #openstack-lbaas | 19:29 | |
*** fnaval_ has quit IRC | 19:29 | |
*** aojea has quit IRC | 19:31 | |
*** fnaval has quit IRC | 19:32 | |
*** fnaval has joined #openstack-lbaas | 19:33 | |
*** fnaval has quit IRC | 19:33 | |
*** aojea has joined #openstack-lbaas | 19:34 | |
*** aojea_ has quit IRC | 19:36 | |
*** aojea_ has joined #openstack-lbaas | 19:39 | |
*** aojea has quit IRC | 19:42 | |
*** aojea has joined #openstack-lbaas | 19:46 | |
*** aojea_ has quit IRC | 19:47 | |
*** atoth has quit IRC | 19:47 | |
*** AlexeyAbashkin has joined #openstack-lbaas | 19:51 | |
*** aojea has quit IRC | 19:53 | |
*** AlexeyAbashkin has quit IRC | 19:55 | |
*** salmankhan has joined #openstack-lbaas | 19:57 | |
*** salmankhan has quit IRC | 20:01 | |
*** aojea has joined #openstack-lbaas | 20:04 | |
*** barch has joined #openstack-lbaas | 20:08 | |
ivve | are l7 rules/policies required in lbaas v2? | 20:08 |
barch | We are getting some stevedore WARNINGs in neutron logs saying can't load OctaviaDriver and LoadBalancerPluginv2 | 20:09 |
barch | Loading Plugin: neutron_lbaas.services.loadbalancer.plugin.LoadBalancerPluginv2 | 20:09 |
*** aojea_ has joined #openstack-lbaas | 20:09 | |
barch | WARNING stevedore.named [req-670b57cb-195b-4aea-a1e3-c6b9fc92c8fb - - - - -] Could not load neutron_lbaas.services.loadbalancer.plugin.LoadBalancerPluginv2 | 20:09 |
johnsom | ivve No, they are optional features, not all drivers support it | 20:09 |
barch | WARNING stevedore.named [req-670b57cb-195b-4aea-a1e3-c6b9fc92c8fb - - - - -] Could not load neutron_lbaas.drivers.octavia.driver.OctaviaDriver | 20:10 |
barch | But then we see... | 20:10 |
barch | INFO neutron_lbaas.drivers.octavia.octavia_messaging_consumer [-] Starting octavia consumer... | 20:10 |
barch | What do these errors mean? | 20:10 |
johnsom | barch Yes, this is an issue with neutron, it is issuing these warnings but then later loads the driver | 20:10 |
ivve | johnsom: i see | 20:10 |
ivve | so strange, i can't get the loadbalancer to forward traffic to pool members | 20:11 |
ivve | it should be pretty straight forward | 20:11 |
johnsom | Agreed | 20:11 |
ivve | i did apply a any to any sec group to the port | 20:11 |
johnsom | So, this is with the namespace driver? What cloud version do you have? Do you have DVR enabled in the neutron router? | 20:11 |
ivve | when i tcpdump the loadbalancer it gets the request but doesn't forward it | 20:12 |
ivve | DVR, not sure | 20:12 |
ivve | its an OSA pike/stable | 20:12 |
ivve | namespace driver is ok now | 20:12 |
*** aojea has quit IRC | 20:12 | |
ivve | lbaas logs are totally quiet | 20:12 |
johnsom | Hmm, well the issues I knew of with DVR were supposed to be fixed in Pike, so that may not be it | 20:12 |
ivve | but so are tcpdumps instances :( | 20:13 |
ivve | can i verify? | 20:13 |
johnsom | ivve an you are dumping in the namespaces the namespace driver creates? | 20:13 |
ivve | ah | 20:13 |
ivve | distributed router | 20:13 |
ivve | that was probabbly the bug i had | 20:13 |
ivve | abbrevations and me :P | 20:13 |
ivve | anyways all my routers went standby is that the bug? | 20:14 |
ivve | johnsom: im tcpdumping on the tap in the loadbalancer namespace | 20:14 |
johnsom | No, it was an issue where ports would not be setup in the DVR tables so traffic would not flow. I'm not familiar with routers going standby, that must be some other issue | 20:14 |
ivve | alright | 20:15 |
*** aojea__ has joined #openstack-lbaas | 20:15 | |
*** slaweq has joined #openstack-lbaas | 20:15 | |
ivve | well i have so far checked different types of traffic to the loadbalancer vip | 20:15 |
ivve | everything works, but not forwarded | 20:15 |
ivve | the iptables is more or less empty | 20:15 |
ivve | not sure if that is correct | 20:15 |
ivve | (unlike a router or dhcp namespace) | 20:16 |
ivve | its my first go on neutron troubleshooting in lbaas | 20:16 |
johnsom | That is unusual, it should at least have deny all, and accept for the listener ports | 20:16 |
ivve | it struck me | 20:16 |
ivve | but i have nothing proper to compare with | 20:16 |
ivve | https://hastebin.com/rulufujohe.bash | 20:17 |
ivve | tried recreating it a few times but always ends up like that | 20:17 |
johnsom | These are logs from the namespace driver gate test. It shows configs, but I don't think neutron dumps the IPtables anywhere: http://logs.openstack.org/00/527600/5/check/neutron-lbaasv2-dsvm-scenario-namespace/3b16ce6/logs/ | 20:17 |
ivve | to be honest im not really sure how the iptables are created in the namespace.. i tried looking for info but came out emptyhanded :( | 20:18 |
*** aojea_ has quit IRC | 20:18 | |
johnsom | iptables is all managed through neutron, we don't manipulate them directly in neutron-lbaas. It could be they are just putting them somewhere else, outside that namespace | 20:19 |
ivve | im using linuxbridge if thats any help | 20:19 |
johnsom | Shouldn't matter | 20:19 |
ivve | its just that i was under the impression its using haproxy and not iptables to loadbalance | 20:20 |
ivve | due to the haproxy nsdriver :) | 20:20 |
ivve | so i was like, maybe it should be empty? | 20:20 |
johnsom | So you are getting traffic to haproxy, just not the members? So if you setup a load balanancer with no members, do you get the 503 back? | 20:20 |
johnsom | Yeah, it's not using iptables for load balancing, just security | 20:21 |
ivve | okay, since i just applied a new sec_group and now the VIP started to accept traffic | 20:21 |
ivve | the healthmonitor is spewing traffic to the instances | 20:22 |
ivve | and if i use a local router i can curl on port 80 which listener is on | 20:22 |
ivve | and it forwards traffic correctly | 20:22 |
ivve | basically i have just setup httpd on port 80 with hostname in the /var/www/html/index.html | 20:23 |
ivve | on the instances | 20:23 |
*** aojea__ has quit IRC | 20:23 | |
ivve | https://hastebin.com/axofaqetom.pl | 20:25 |
ivve | tried checking for package size as well | 20:26 |
ivve | seems ok | 20:26 |
*** fnaval has joined #openstack-lbaas | 20:27 | |
ivve | so i.e. icmp requests go there, but not back | 20:28 |
johnsom | ICMP is not enabled by default | 20:28 |
johnsom | Only the listener ports should work | 20:29 |
ivve | this is what i get on curls | 20:29 |
ivve | https://hastebin.com/ugijemoxas.pl | 20:29 |
ivve | which it should forward | 20:30 |
ivve | here is a successful one on the vxlan | 20:30 |
ivve | https://hastebin.com/mebuviqobu.pl | 20:32 |
ivve | i tried removing and readding the poolmembers after reapplying the security group | 20:32 |
johnsom | members should not change the SG, only LB and Listener actions | 20:33 |
ivve | perhaps the listener should be recreated? | 20:33 |
ivve | any-any | ingress | IPv4 | 1-65535/tcp | 0.0.0.0/0 (CIDR) | 20:34 |
ivve | oh wait | 20:34 |
ivve | no thought i was missing egress | 20:35 |
ivve | one could hope it would be such a simple mistake | 20:35 |
openstackgerrit | Lingxian Kong proposed openstack/octavia-tempest-plugin master: Add basic tests for listeners https://review.openstack.org/492311 | 20:35 |
ivve | but then internal router shouldn't get responses | 20:35 |
ivve | jees what an annoying problem! | 20:35 |
ivve | any-any | egress | IPv4 | any | any | 20:36 |
ivve | icmp also in there | 20:36 |
ivve | for testing sake | 20:36 |
kong | johnsom: sorry to chime in, but could you please take a look at this patch: https://review.openstack.org/#/c/533615/ fix the basic scenario test using normal user. | 20:37 |
johnsom | kong Hi, sure | 20:37 |
kong | johnsom: thx | 20:37 |
ivve | this is a bit interesting though | 20:39 |
ivve | user_group = haproxy | 20:40 |
ivve | in /etc/neutron/lbaas_agent.ini | 20:40 |
ivve | nobody 26633 1 0 21:24 ? 00:00:00 haproxy -f /var/lib/neutron/lbaas/v2/916cf926-00be-463f-8b34-e379de294fd0/haproxy.conf | 20:40 |
ivve | https://hastebin.com/ixeyasuhij.bash | 20:42 |
ivve | conf in all its glory | 20:42 |
ivve | user says nobody | 20:43 |
johnsom | Yeah, that all looks good | 20:43 |
ivve | user nobody group haproxy? | 20:43 |
johnsom | yes | 20:43 |
ivve | kk | 20:43 |
ivve | i did change that | 20:43 |
ivve | that solved some problem | 20:43 |
johnsom | Are you on RedHat? | 20:43 |
ivve | centos | 20:43 |
johnsom | Yeah, ok, that is probably an issue on CentOS | 20:43 |
ivve | perhaps i should have mentioned | 20:43 |
ivve | :P | 20:43 |
johnsom | It's haproxy package is different than the others. | 20:43 |
ivve | i also have an ubuntu but havn't changed that | 20:44 |
ivve | i've ran into some haproxy issues there on the controller side | 20:44 |
ivve | actually now that i think about it | 20:44 |
ivve | it couldn't properly read headers i think | 20:44 |
ivve | GOSH gotdamn centos :D | 20:45 |
ivve | but config looks good to you? | 20:45 |
johnsom | Yeah, that haproxy config looks ok to me. | 20:48 |
ivve | haproxy-1.5.18-6.el7.x86_64 | 20:49 |
ivve | this is the bugger | 20:49 |
johnsom | Yeah, ok, found it. Most packages use USER_GROUP=nobody, but RHEL/CENTOS use USER-GROUP=haproxy | 20:49 |
*** AlexeyAbashkin has joined #openstack-lbaas | 20:50 | |
johnsom | Yeah, again an issue with CentOS | 20:50 |
ivve | you mean /etc/neutron/lbaas_agent.ini config? | 20:50 |
johnsom | Not sure where it is for that driver. It's automatic in octavia | 20:51 |
ivve | device_driver = neutron_lbaas.drivers.haproxy.namespace_driver.HaproxyNSDriver | 20:52 |
ivve | user_group = haproxy | 20:52 |
johnsom | yep, there you go | 20:52 |
ivve | are you kidding me? :D | 20:52 |
*** fnaval has quit IRC | 20:52 | |
ivve | im hoping its not case-sensitive | 20:53 |
johnsom | ha, don't know | 20:53 |
*** AlexeyAbashkin has quit IRC | 20:54 | |
ivve | user haproxy | 20:54 |
ivve | group haproxy | 20:54 |
ivve | in the /etc/haproxy/haproxy.cfg | 20:54 |
ivve | however the pid gets created with nobody:haproxy | 20:55 |
ivve | the thing is i changed from user_group = nobody to: user_group = haproxy due to reading the redhat manuals on lbaas lol | 20:59 |
ivve | have you got any link on that info? | 20:59 |
johnsom | On what exactly? not sure I understand the question? | 21:00 |
ivve | well you said: Yeah, ok, found it. Most packages use USER_GROUP=nobody, but RHEL/CENTOS use USER-GROUP=haproxy | 21:00 |
ivve | im just not sure which config we are talking about | 21:00 |
ivve | perhaps it was a typo | 21:01 |
ivve | - _ | 21:01 |
johnsom | yeah, typo | 21:01 |
johnsom | Sorry | 21:01 |
ivve | okay well yea its already confed like that in lbaas-agent.ini | 21:02 |
ivve | #user_group = nobody | 21:02 |
ivve | user_group = haproxy | 21:02 |
ivve | thats what solved my driver issues, among other things :P | 21:02 |
*** fnaval has joined #openstack-lbaas | 21:03 | |
johnsom | Bummer, the next ubuntu LTS (18/Bionic) only has haproxy 1.7.9 in it. Why don't they do 1.8 since it's released? | 21:05 |
ivve | no difference using http vs tcp/80 on the listener | 21:07 |
ivve | im guessing i could try install lbaas on my ubuntu openstack | 21:07 |
ivve | see if it works better/worse | 21:07 |
ivve | :D | 21:07 |
ivve | this centos install has been giving me headaches | 21:07 |
ivve | tried tcp health monitor | 21:09 |
ivve | same exact | 21:09 |
ivve | request gets in on FIP but no reply, on fixed it works | 21:09 |
ivve | fixed vip | 21:09 |
*** aojea has joined #openstack-lbaas | 21:13 | |
ivve | got this now | 21:15 |
ivve | 2018-01-15 22:06:34.924 484 ERROR neutron.agent.linux.utils [req-5f33fb3b-2933-4f7f-8033-1c885711d763 0a305a0f2d5d4217bb71c3a85449b416 25f88312eb794ea78e79d136c6573a95 - - -] Exit code: 99; Stdin: ; Stdout: ; Stderr: /openstack/venvs/neutron-16.0.6/bin/neutron-rootwrap: Unauthorized command: ip netns exec qlbaas-916cf926-00be-463f-8b34-e379de294fd0 route add default gw 10.167.35.1 (no filter matched) | 21:15 |
ivve | 2018-01-15 22:06:35.620 484 WARNING neutron_lbaas.drivers.haproxy.namespace_driver [-] Stats socket not found for loadbalancer 916cf926-00be-463f-8b34-e379de294fd0 | 21:15 |
johnsom | The first one is a problem. That is a neutron config issue. | 21:16 |
johnsom | The second one is normal, it will give you those until a listener or pool is created on the LB | 21:16 |
*** aojea_ has joined #openstack-lbaas | 21:18 | |
johnsom | Feel free to up vote my Ubuntu bug lobbying for 1.8 in the next LTS instead of 1.7: https://bugs.launchpad.net/ubuntu/+source/haproxy/+bug/1743465 | 21:18 |
openstack | Launchpad bug 1743465 in haproxy (Ubuntu) "Bionic should have haproxy 1.8-stable" [Undecided,New] | 21:18 |
ivve | well net-utils isn't installed | 21:19 |
ivve | would that pose a problem? | 21:19 |
*** aojea has quit IRC | 21:21 | |
ivve | i mean it doesn't have a default route, which would mean NAT issues? | 21:22 |
*** Alex_Staf has joined #openstack-lbaas | 21:23 | |
ivve | lol | 21:23 |
ivve | that did it | 21:23 |
*** aojea has joined #openstack-lbaas | 21:23 | |
ivve | ill report some bugs | 21:25 |
ivve | among them the net-utils package & user_group: haproxy | 21:25 |
ivve | net-utils is kinda stupid but the user_group = haproxy (sorry my typo this time) can be fixed via overrides in OSA but should be default if centos | 21:26 |
*** aojea_ has quit IRC | 21:26 | |
*** aojea_ has joined #openstack-lbaas | 21:28 | |
*** aojea has quit IRC | 21:30 | |
*** pcaruana has quit IRC | 21:30 | |
*** jappleii__ has joined #openstack-lbaas | 21:32 | |
*** aojea__ has joined #openstack-lbaas | 21:33 | |
xgerman_ | ivve: please submit a patch | 21:36 |
*** aojea_ has quit IRC | 21:36 | |
*** aojea_ has joined #openstack-lbaas | 21:38 | |
*** aojea__ has quit IRC | 21:41 | |
*** aojea__ has joined #openstack-lbaas | 21:43 | |
*** aojea_ has quit IRC | 21:46 | |
*** aojea_ has joined #openstack-lbaas | 21:48 | |
*** AlexeyAbashkin has joined #openstack-lbaas | 21:50 | |
*** aojea__ has quit IRC | 21:51 | |
kong | xgerman_: hi, could you please take a look at this patch: https://review.openstack.org/#/c/533615/? | 21:53 |
*** aojea__ has joined #openstack-lbaas | 21:53 | |
kong | our octavia monitoring is broken | 21:54 |
*** AlexeyAbashkin has quit IRC | 21:54 | |
xgerman_ | so? | 21:54 |
kong | we need that patch ;-) | 21:54 |
kong | thanks a lot | 21:55 |
*** aojea_ has quit IRC | 21:57 | |
*** aojea has joined #openstack-lbaas | 21:58 | |
*** aojea__ has quit IRC | 22:01 | |
*** aojea has quit IRC | 22:07 | |
*** aojea has joined #openstack-lbaas | 22:07 | |
barch | Not sure if this is correct place to ask, but had some questions regarding setting up neutron lbaasv2 with AVI: https://avinetworks.com/docs/17.1/installing-avi-vantage-for-openstack/#Deploying_Avi-managed_LBaaS_Mode | 22:10 |
barch | we want to try the "OpenStack-managed LBaaS mode". Where we use theur lbaas v2 APIs to interact with AVI (instead of directly using the AVI apis/gui on controller VM) | 22:11 |
barch | avi says they have an lbaas plugin driver to install | 22:11 |
barch | I am confused if this is to replace the neutron-lbaas plugin, or are we to first install the neutron-lbaas plugin, then install the avi driver? | 22:11 |
barch | FYI we already have AVI working directly using the "Avi-managed LBaaS mode". Here there is no neutron's lbaas-plugin or lbaasv2 APIs | 22:12 |
*** aojea_ has joined #openstack-lbaas | 22:12 | |
johnsom | barch You should be able to get the neutron-lbaas (v2 of course) driver package from them and install it. In your neutron configuration files you would just define the drivers you want available as providers in a comma separated list like you would do for other drivers. | 22:15 |
*** aojea has quit IRC | 22:15 | |
barch | Correct, i downloaded their avi driver package. I was just wondering if this *replaces* the neutron lbaas plugin | 22:15 |
barch | or whether both need to be installed | 22:15 |
barch | their driver also doesn't appear to have any openstack versioning (compatible with newton?) | 22:16 |
johnsom | I hope not, but I don't know. We haven't had any AVI participation here and their driver is not gate testing with our code, so can't really tell you. | 22:16 |
barch | "Avi Networks provides a script for installing or upgrading the LBaaS plugin driver (v1 or v2). The script makes the necessary OpenStack configuration changes automatically. Download the Avi LBaaS driver installation package (avi_openstack_package.tar.gz) from the Avi Networks portal website " | 22:17 |
johnsom | It's this configuration in your neutron_lbaas.conf you would add additional drivers to: | 22:17 |
johnsom | [service_providers] | 22:17 |
johnsom | service_provider = LOADBALANCERV2:Octavia:neutron_lbaas.drivers.octavia.driver.OctaviaDriver:default | 22:17 |
barch | hmm ok | 22:17 |
barch | I assume their script/installer would set the correct service provider | 22:17 |
*** aojea__ has joined #openstack-lbaas | 22:18 | |
barch | i couldn't find anywhere what the exact value/line is to manually set this to for avi | 22:18 |
johnsom | Yeah, no idea. I wish they participated with us. | 22:18 |
johnsom | My best answer for you is to call their support | 22:18 |
*** aojea_ has quit IRC | 22:20 | |
*** rcernin has joined #openstack-lbaas | 22:21 | |
*** longstaff has quit IRC | 22:22 | |
*** aojea has joined #openstack-lbaas | 22:22 | |
*** slaweq has quit IRC | 22:24 | |
*** slaweq has joined #openstack-lbaas | 22:24 | |
*** aojea__ has quit IRC | 22:25 | |
*** aojea_ has joined #openstack-lbaas | 22:28 | |
*** slaweq has quit IRC | 22:29 | |
*** aojea has quit IRC | 22:30 | |
*** aojea has joined #openstack-lbaas | 22:32 | |
*** aojea_ has quit IRC | 22:35 | |
*** aojea_ has joined #openstack-lbaas | 22:38 | |
*** slaweq has joined #openstack-lbaas | 22:39 | |
*** aojea has quit IRC | 22:40 | |
*** aojea__ has joined #openstack-lbaas | 22:43 | |
*** slaweq has quit IRC | 22:44 | |
*** aojea_ has quit IRC | 22:45 | |
*** aojea__ has quit IRC | 22:48 | |
xgerman_ | johnsom: so how do we feel for Octavia specific functions (e.g. amphora failover in the client)? | 22:59 |
johnsom | I think the plan is to add them | 23:00 |
xgerman_ | ok, but loadbalancer amphora failover? | 23:00 |
johnsom | They are part of the API. Though, probably a good discussion item. | 23:00 |
xgerman_ | that sounds like it might apply to other drivers as well… | 23:00 |
johnsom | Yeah, that is a bit odd | 23:01 |
johnsom | Though amps are part of a load balancer | 23:02 |
*** ivve has quit IRC | 23:02 | |
xgerman_ | I am not denying that but this could confuse a user, e.g. trying to do it on an F5 | 23:02 |
johnsom | Well, they will get rejected with permission denied before it gets to the "not implemented" error | 23:03 |
johnsom | Since it's RBAC admin only | 23:03 |
xgerman_ | ok, I will comment and we can pick it up in our meeting | 23:04 |
johnsom | Sounds good | 23:04 |
openstackgerrit | Merged openstack/octavia-tempest-plugin master: Create floating ip by normal user https://review.openstack.org/533615 | 23:10 |
*** ivve has joined #openstack-lbaas | 23:17 | |
xgerman_ | what’s the use case for https://review.openstack.org/#/c/533331/4 ? | 23:26 |
xgerman_ | and why can;t it always run against all amps? | 23:27 |
johnsom | It's mostly failover situations, but probably in expand amps as well. | 23:27 |
johnsom | I thought he put that in the commit or bug, if both amps failover, the second update fails if the first is ahead | 23:28 |
johnsom | as an example | 23:28 |
xgerman_ | mmh, I don’t liek the complexity of selective updates since then things can get out of sync | 23:29 |
johnsom | It seems to me we should make the driver act on one amp and put the iteration in the flows if it needs it | 23:29 |
johnsom | That would lead to better parallel opportunities anyway. | 23:30 |
xgerman_ | that’s orthogonal | 23:31 |
johnsom | And retries as well.... Yeah, I think I'm really going to push to move that up to the flows | 23:31 |
xgerman_ | one of our tenants is that we push everyhting out in every change so w ecan be dumb about amps | 23:31 |
johnsom | Well, in that case it would just abort the failover as the update to the second failed | 23:32 |
xgerman_ | mmh, I thinbk I need to see it to believe it… -1 | 23:38 |
xgerman_ | @team there are a lot of dashboard reviews on our etherpad — this is a good way for somebody new to start reviewing… install the patch, click around, comment <hint><hint> | 23:48 |
*** armax has quit IRC | 23:54 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!