*** Swami has quit IRC | 00:06 | |
johnsom | Did the backup patch too now | 00:06 |
---|---|---|
openstackgerrit | Jacky Hu proposed openstack/octavia master: Able to set frontend network for loadbalancer https://review.openstack.org/529936 | 00:07 |
*** yamamoto has joined #openstack-lbaas | 00:12 | |
*** openstack has joined #openstack-lbaas | 00:17 | |
*** ChanServ sets mode: +o openstack | 00:17 | |
*** yamamoto has quit IRC | 00:17 | |
johnsom | rm_work do you still have the timeout patch running in a stack? | 00:23 |
rm_work | yes | 00:23 |
johnsom | can you paste me from mysql "show create table listener;"? | 00:23 |
johnsom | Out of time to do a stack, but want to finish this read through review based on how the migration came out in the DB. | 00:27 |
johnsom | slqalchemy adds a bit of chance to how it interprets things, so I don't trust it to do what I think it's going to do. | 00:27 |
*** yamamoto has joined #openstack-lbaas | 00:38 | |
*** yamamoto has quit IRC | 00:45 | |
rm_work | err k | 00:54 |
rm_work | one sec | 00:54 |
rm_work | johnsom: sorry am debugging things internally | 00:54 |
rm_work | http://paste.openstack.org/show/715635/ | 00:55 |
rm_work | johnsom: ^^ | 00:55 |
*** yamamoto has joined #openstack-lbaas | 00:56 | |
*** fnaval has quit IRC | 01:05 | |
*** yamamoto has quit IRC | 01:14 | |
*** PagliaccisCloud has quit IRC | 01:19 | |
*** PagliaccisCloud has joined #openstack-lbaas | 01:20 | |
*** Jeffrey4l has joined #openstack-lbaas | 01:31 | |
Jeffrey4l | for octavia house keeping spare_amphora_pool_size feature. if i have several octavia-housekeeping process, for example 3, it may create 3 * spare_amphora_pool_size vms, seems there is no any global locks to ensure this. is this expected? or should be fixed? | 01:34 |
rm_work | it should not do that | 01:36 |
johnsom | It is expected. We balanced to extra code and complexity against having a few extra spare amps | 01:37 |
rm_work | ah, yeah at the very start | 01:37 |
rm_work | it can build a few extra | 01:37 |
rm_work | but it will not STAY at a few extra | 01:37 |
rm_work | after the initial build, it should end up at or very close to the number | 01:37 |
johnsom | If it is really a problem for someone it can be fixed. | 01:39 |
Jeffrey4l | i expected it boot spare_amphora_pool_size vms. i think it is a bug | 01:42 |
Jeffrey4l | on the other hand, if i have more than spare_amphora_pool_size vms, hours keeping won't shrink the number of vms. and i hoping it cloud shrink the node too. | 01:43 |
*** atoth has quit IRC | 01:54 | |
rm_work | Jeffrey4l: you aren't *wrong*, it's a bug technically, and we could have a bug filed for it ... but it's a bug we knowingly introduced, because the fix is a LOT of work, and the result of the bug is ... not a big deal | 01:55 |
Jeffrey4l | rm_work, how about introduce tooz to add a global lock during creating vms. | 02:01 |
*** AlexeyAbashkin has joined #openstack-lbaas | 02:12 | |
*** yamamoto has joined #openstack-lbaas | 02:15 | |
*** AlexeyAbashkin has quit IRC | 02:16 | |
rm_work | i mean, we can do it without tooz also | 02:18 |
rm_work | it's just work | 02:18 |
rm_work | and relying on another service just to lock internally is a bit heavy <_< | 02:18 |
*** yamamoto has quit IRC | 02:21 | |
openstackgerrit | sapd proposed openstack/octavia master: Support create amphora instance from volume based. https://review.openstack.org/557111 | 02:31 |
Jeffrey4l | roger. btw, i create a story for tracking this https://storyboard.openstack.org/#!/story/2001748 | 02:32 |
*** yamamoto has joined #openstack-lbaas | 02:37 | |
*** yamamoto has quit IRC | 03:18 | |
*** kbyrne has quit IRC | 03:51 | |
*** kbyrne has joined #openstack-lbaas | 03:56 | |
openstackgerrit | Jacky Hu proposed openstack/octavia master: ACTIVE-ACTIVE: Initial distributor data model https://review.openstack.org/528850 | 04:05 |
openstackgerrit | Jacky Hu proposed openstack/octavia master: L3 ACTIVE-ACTIVE data model https://review.openstack.org/524722 | 04:05 |
openstackgerrit | Jacky Hu proposed openstack/octavia master: Make frontend interface attrs less vrrp specific https://review.openstack.org/521138 | 04:05 |
openstackgerrit | Jacky Hu proposed openstack/octavia master: Able to set frontend network for loadbalancer https://review.openstack.org/529936 | 04:05 |
*** yamamoto has joined #openstack-lbaas | 04:19 | |
*** yamamoto has quit IRC | 04:25 | |
*** links has joined #openstack-lbaas | 04:46 | |
*** Alex_Staf has joined #openstack-lbaas | 04:48 | |
*** yamamoto has joined #openstack-lbaas | 05:21 | |
*** yamamoto has quit IRC | 05:27 | |
*** velizarx has joined #openstack-lbaas | 05:51 | |
*** velizarx has joined #openstack-lbaas | 05:53 | |
*** velizarx has quit IRC | 06:02 | |
*** voelzmo has joined #openstack-lbaas | 06:18 | |
*** yamamoto has joined #openstack-lbaas | 06:23 | |
*** yamamoto has quit IRC | 06:28 | |
*** pcaruana has joined #openstack-lbaas | 06:38 | |
*** voelzmo has quit IRC | 06:55 | |
*** voelzmo has joined #openstack-lbaas | 06:55 | |
*** voelzmo has quit IRC | 07:08 | |
*** voelzmo has joined #openstack-lbaas | 07:10 | |
*** ianychoi has quit IRC | 07:10 | |
*** voelzmo has quit IRC | 07:11 | |
*** rcernin has quit IRC | 07:15 | |
*** voelzmo has joined #openstack-lbaas | 07:15 | |
*** yamamoto has joined #openstack-lbaas | 07:25 | |
*** tesseract has joined #openstack-lbaas | 07:25 | |
*** yamamoto has quit IRC | 07:30 | |
*** voelzmo has quit IRC | 07:36 | |
*** Alex_Staf has quit IRC | 07:43 | |
*** velizarx has joined #openstack-lbaas | 07:43 | |
*** Alex_Staf has joined #openstack-lbaas | 07:45 | |
*** AlexeyAbashkin has joined #openstack-lbaas | 08:00 | |
*** kobis has joined #openstack-lbaas | 08:02 | |
*** kobis has quit IRC | 08:02 | |
*** kobis has joined #openstack-lbaas | 08:02 | |
*** voelzmo has joined #openstack-lbaas | 08:04 | |
*** Alex_Staf has quit IRC | 08:11 | |
*** voelzmo has quit IRC | 08:22 | |
*** voelzmo has joined #openstack-lbaas | 08:22 | |
*** voelzmo has quit IRC | 08:23 | |
*** voelzmo has joined #openstack-lbaas | 08:23 | |
*** voelzmo has quit IRC | 08:24 | |
*** voelzmo has joined #openstack-lbaas | 08:24 | |
*** rcernin has joined #openstack-lbaas | 08:24 | |
*** voelzmo has quit IRC | 08:24 | |
*** voelzmo has joined #openstack-lbaas | 08:25 | |
*** voelzmo has quit IRC | 08:25 | |
*** voelzmo has joined #openstack-lbaas | 08:25 | |
*** voelzmo has quit IRC | 08:26 | |
*** yamamoto has joined #openstack-lbaas | 08:26 | |
*** yamamoto has quit IRC | 08:30 | |
*** irenab has quit IRC | 08:33 | |
*** oanson has quit IRC | 08:34 | |
*** oanson has joined #openstack-lbaas | 08:36 | |
*** irenab has joined #openstack-lbaas | 08:40 | |
*** rcernin has quit IRC | 08:42 | |
*** salmankhan has joined #openstack-lbaas | 09:10 | |
*** yamamoto has joined #openstack-lbaas | 09:27 | |
*** Alex_Staf has joined #openstack-lbaas | 09:27 | |
*** salmankhan has quit IRC | 09:32 | |
*** yamamoto has quit IRC | 09:32 | |
*** salmankhan has joined #openstack-lbaas | 09:35 | |
*** kobis has quit IRC | 09:55 | |
*** kobis has joined #openstack-lbaas | 09:56 | |
*** kobis has quit IRC | 09:56 | |
*** ianychoi has joined #openstack-lbaas | 10:15 | |
*** Alex_Staf has quit IRC | 10:22 | |
*** yamamoto has joined #openstack-lbaas | 10:29 | |
*** yamamoto has quit IRC | 10:34 | |
openstackgerrit | Merged openstack/octavia master: Fix logging level for keystone auth bypass https://review.openstack.org/556970 | 10:47 |
*** Alex_Staf has joined #openstack-lbaas | 10:50 | |
*** atoth has joined #openstack-lbaas | 10:52 | |
*** links has quit IRC | 11:04 | |
*** chandankumar has quit IRC | 11:04 | |
*** links has joined #openstack-lbaas | 11:05 | |
*** chkumar246 has joined #openstack-lbaas | 11:20 | |
*** kobis has joined #openstack-lbaas | 11:24 | |
*** yamamoto has joined #openstack-lbaas | 11:31 | |
*** yamamoto has quit IRC | 11:35 | |
*** velizarx has quit IRC | 11:45 | |
*** velizarx has joined #openstack-lbaas | 11:56 | |
*** sapd__ has joined #openstack-lbaas | 12:06 | |
*** sapd_ has quit IRC | 12:09 | |
*** sapd__ has quit IRC | 12:17 | |
*** sapd_ has joined #openstack-lbaas | 12:17 | |
*** yamamoto has joined #openstack-lbaas | 12:22 | |
*** sapd_ has quit IRC | 12:27 | |
*** sapd_ has joined #openstack-lbaas | 12:27 | |
*** sapd_ has quit IRC | 12:32 | |
*** sapd_ has joined #openstack-lbaas | 12:32 | |
*** chkumar246 is now known as chandankumar | 12:43 | |
*** kobis has quit IRC | 12:48 | |
*** salmankhan has quit IRC | 12:50 | |
*** sapd__ has joined #openstack-lbaas | 12:52 | |
*** sapd_ has quit IRC | 12:52 | |
*** kobis has joined #openstack-lbaas | 12:53 | |
*** salmankhan has joined #openstack-lbaas | 12:59 | |
*** fnaval has joined #openstack-lbaas | 13:20 | |
openstackgerrit | Chuck Short proposed openstack/neutron-lbaas-dashboard master: Update tox.ini https://review.openstack.org/557343 | 13:57 |
*** velizarx has quit IRC | 14:00 | |
*** velizarx has joined #openstack-lbaas | 14:01 | |
*** ianychoi_ has joined #openstack-lbaas | 14:33 | |
*** ianychoi has quit IRC | 14:36 | |
*** sapd__ has quit IRC | 14:37 | |
*** sapd__ has joined #openstack-lbaas | 14:38 | |
*** sapd__ has quit IRC | 14:40 | |
*** sapd__ has joined #openstack-lbaas | 14:41 | |
*** sapd__ has quit IRC | 14:41 | |
*** sapd__ has joined #openstack-lbaas | 14:41 | |
*** sapd__ has quit IRC | 14:41 | |
*** sapd__ has joined #openstack-lbaas | 14:42 | |
*** velizarx has quit IRC | 14:56 | |
*** velizarx has joined #openstack-lbaas | 14:57 | |
*** kevinbenton has quit IRC | 14:58 | |
*** links has quit IRC | 15:03 | |
*** Alex_Staf has quit IRC | 15:04 | |
*** kobis has quit IRC | 15:05 | |
*** kevinbenton has joined #openstack-lbaas | 15:06 | |
*** pcaruana has quit IRC | 15:09 | |
*** velizarx has quit IRC | 15:18 | |
*** fnaval_ has joined #openstack-lbaas | 15:19 | |
*** fnaval_ has quit IRC | 15:20 | |
*** fnaval_ has joined #openstack-lbaas | 15:21 | |
*** fnaval has quit IRC | 15:21 | |
*** imacdonn has quit IRC | 15:26 | |
*** imacdonn has joined #openstack-lbaas | 15:27 | |
openstackgerrit | Merged openstack/octavia-tempest-plugin master: Updated from global requirements https://review.openstack.org/556314 | 15:28 |
*** vishyj has joined #openstack-lbaas | 16:36 | |
*** kobis has joined #openstack-lbaas | 16:36 | |
vishyj | hi, I am doing some research on using anycast routing for loadbalancers....was wondering if OpenStack neutron allowed specifiying same IP address for multiple VMs that had LBaaS running on those VMs...new to lbaas and in research mode, please pardon if my question is invalid | 16:38 |
johnsom | vishyj Take a look at this doc: https://docs.openstack.org/octavia/latest/contributor/specs/version1.1/active-active-l3-distributor.html | 16:39 |
openstackgerrit | Murali Annamneni proposed openstack/neutron-lbaas master: Enable MySQL Cluster Support for neutron-lbaas https://review.openstack.org/513081 | 16:39 |
*** velizarx has joined #openstack-lbaas | 16:40 | |
vishyj | johnsom thanks a lot .... will take a look | 16:40 |
*** huseyin has joined #openstack-lbaas | 16:47 | |
huseyin | Hi guys, I can finally create a load-balancer under octavia after changing network, compute and amphora drivers to noop | 16:54 |
huseyin | Load balancer status is active, and it gets an IP address from the private subnet | 16:54 |
huseyin | I can access amphora images from controller nodes and vice versa | 16:55 |
huseyin | But the VIP address on the private subnet is not accessible | 16:55 |
huseyin | i assigned a floating IP to the LB, but i can not access members via this floating IP | 16:56 |
huseyin | the VIP address shown on the dashboard is not accessible from project VMs | 16:56 |
huseyin | On the amphora image, i can not see any namespace | 16:57 |
huseyin | amphora image has only IP address on the lb-mgmt-net | 16:57 |
huseyin | is it expected behavior? | 16:58 |
*** velizarx has quit IRC | 16:58 | |
huseyin | any idea? | 16:59 |
*** Swami has joined #openstack-lbaas | 17:08 | |
*** AlexeyAbashkin has quit IRC | 17:08 | |
*** kobis has quit IRC | 17:12 | |
*** velizarx has joined #openstack-lbaas | 17:14 | |
*** velizarx has quit IRC | 17:16 | |
openstackgerrit | Merged openstack/neutron-lbaas master: Updated from global requirements https://review.openstack.org/555574 | 17:16 |
*** velizarx has joined #openstack-lbaas | 17:16 | |
*** yamamoto has quit IRC | 17:29 | |
*** tesseract has quit IRC | 17:35 | |
johnsom | huseyin The no-op drivers don't actually do anything. They don't call out to neutron or nova for example. They are purely used for testing when the tests don't need to use those components. | 17:36 |
huseyin | i reverted back the config | 17:37 |
huseyin | on the amphora images, is it expected to see a namespace on the private subnet? | 17:37 |
*** velizarx has quit IRC | 17:38 | |
huseyin | i mean, amphora image has an IP address on the lb-mgmt-net, but nothing on the private subnet (tenant network) | 17:38 |
johnsom | huseyin Correct, the lb-mgmt-net is in the default namespace with the amphora-agent. The vip and member networks are inside the amphora-haproxy namespace with haproxy. This isolates the tenant networks from the lb-mgmt-net. | 17:41 |
huseyin | there is not any namespace in the amphora images | 17:41 |
huseyin | what can be the cause? | 17:41 |
huseyin | “sudo ip netns list” returns empty | 17:42 |
huseyin | any clue? | 17:42 |
*** velizarx has joined #openstack-lbaas | 17:43 | |
huseyin | amphora images reach octavia-worker nodes | 17:44 |
huseyin | and worker nodes can reach amphora images via lb-mgmt-net | 17:44 |
johnsom | huseyin And this amphora has a load balancer with a VIP? | 17:45 |
huseyin | ha ssure | 17:45 |
huseyin | yes sure | 17:45 |
huseyin | i can see the vip address on the dashboard | 17:45 |
huseyin | under the load balancer | 17:45 |
*** yamamoto has joined #openstack-lbaas | 17:46 | |
*** kobis has joined #openstack-lbaas | 17:46 | |
huseyin | this IP is in the private subnet | 17:46 |
johnsom | ummm, this is new to me, "sudo ip netns" should show the namespace. | 17:47 |
johnsom | This would only happen if the amphora driver is still no-op | 17:47 |
*** velizarx has quit IRC | 17:48 | |
huseyin | i tried everything | 17:50 |
huseyin | when i set the amphora driver to no-op load balancer is created successfully | 17:51 |
huseyin | when i set the driver to haproxy rest, its provisioning status turns to error | 17:51 |
huseyin | and at the backend several amphora images are built and deleted | 17:51 |
johnsom | Oh, so you are running network and compute with normal drivers, but amphora no-op. That makes sense. no-op won't actually configure the amphora instance. It doesn't call out to the VM. | 17:52 |
huseyin | i can see an amphora image in the build state, then in active state, and after a few seconds i can not see the same amphora image | 17:52 |
johnsom | Yeah, by default if we get a failure we clean up our resources. | 17:53 |
huseyin | Actually, at the moment amphora driver is set to haproxy rest but lb creation fails | 17:53 |
johnsom | So, when the LB goes into provisioning error, what do you see in the worker log on the controller? There should be an error message there | 17:53 |
huseyin | let me check again | 17:54 |
*** kobis has quit IRC | 17:55 | |
*** salmankhan has quit IRC | 17:55 | |
*** velizarx has joined #openstack-lbaas | 17:58 | |
huseyin | the only thing is octavia.amphorae.drivers.haproxy.rest_api_driver [-] Could not connect to instance. Retrying. | 17:58 |
*** kobis has joined #openstack-lbaas | 17:59 | |
huseyin | and an error message about dns integration | 17:59 |
*** jmccrory has quit IRC | 17:59 | |
johnsom | huseyin ok, those Could not connect to instance. Retrying. will eventually become ERROR. This means your worker cannot reach the amphora agent on the amphora VM using the lb-mgmt-net | 18:00 |
huseyin | i can ping the amphora image from the worker nodes | 18:00 |
huseyin | and ping worker nodes from amphora images | 18:01 |
huseyin | isn’t it enough? | 18:01 |
johnsom | Ok, get the IP address on the amphora lb-mgmt-net | 18:01 |
huseyin | 172.16.0.2 | 18:01 |
huseyin | but as i said before it changes priodically due to clean up process | 18:02 |
rm_work | you should get a long series of those Retrying messages | 18:03 |
huseyin | it is now 172.16.0.6 | 18:03 |
rm_work | but eventually they will *stop* | 18:03 |
johnsom | Then try "openssl s_client -connect 172.16.0.2:9443" | 18:03 |
rm_work | the error right when they stop is the part we are probably interested in | 18:03 |
rm_work | though probably it is just hitting the max timeout | 18:03 |
huseyin | hmm, we have to wait a bit more | 18:04 |
johnsom | You should see some output like: | 18:04 |
johnsom | https://www.irccloud.com/pastebin/1qfCfjkc/ | 18:04 |
johnsom | You will have to ctrl-c out of that as it waits for data. | 18:04 |
huseyin | ok i will try | 18:04 |
*** jmccrory has joined #openstack-lbaas | 18:06 | |
*** yamamoto has quit IRC | 18:12 | |
*** velizarx has quit IRC | 18:13 | |
*** sshank has joined #openstack-lbaas | 18:14 | |
*** kobis1 has joined #openstack-lbaas | 18:15 | |
*** kobis has quit IRC | 18:16 | |
*** yamamoto has joined #openstack-lbaas | 18:21 | |
openstackgerrit | Merged openstack/octavia-dashboard master: Add package-lock.json https://review.openstack.org/555270 | 18:24 |
*** yamamoto has quit IRC | 18:26 | |
openstackgerrit | Michael Johnson proposed openstack/octavia-dashboard master: List children pools on LB details page https://review.openstack.org/551305 | 18:27 |
johnsom | FYI, I am going to add release notes to a bunch of these dashboard patches as an example. So that will be all of these dashboard patches | 18:28 |
*** voelzmo has joined #openstack-lbaas | 18:33 | |
openstackgerrit | Michael Johnson proposed openstack/octavia-dashboard master: Being able to edit default pool of listener https://review.openstack.org/551436 | 18:36 |
*** yamamoto has joined #openstack-lbaas | 18:36 | |
rm_work | k lol | 18:39 |
rm_work | i'm starting to *hate* the pecan wsme model return code SO MUCH | 18:41 |
rm_work | it is blocking me on two patches where i try to do things intelligently | 18:41 |
rm_work | and the code is so dumb | 18:41 |
rm_work | i may have to spend some time making a PR against wsme_pecan | 18:41 |
*** yamamoto has quit IRC | 18:41 | |
*** sshank has quit IRC | 18:43 | |
openstackgerrit | Michael Johnson proposed openstack/octavia-dashboard master: Add l7 support https://review.openstack.org/551947 | 18:44 |
*** ssmith has joined #openstack-lbaas | 18:45 | |
johnsom | Hmm, this is to return full single-call creates? | 18:45 |
rm_work | or i dunno, maybe trying to use wsme_pecan is just not right for me | 18:45 |
rm_work | maybe I should just be constructing the return value myself | 18:45 |
rm_work | also for usage | 18:45 |
rm_work | i want to do this: | 18:45 |
johnsom | Personally I kind of like the types stuff we use, but it can be a bit constraining. Which can also be good. | 18:46 |
johnsom | Cool stuff, the L7 support in dashboard works great. | 18:46 |
*** velizarx has joined #openstack-lbaas | 18:48 | |
*** voelzmo has quit IRC | 18:48 | |
rm_work | http://paste.openstack.org/show/716351/ | 18:49 |
rm_work | ^^ I want that | 18:49 |
rm_work | I don't want to type a bunch of BS static code for no reason | 18:49 |
rm_work | it constructs the object perfectly | 18:49 |
rm_work | and then nulls the whole thing out inside the wsme_pecan return code, because it can't deal with dynamic *anything* | 18:49 |
rm_work | but honestly, the DB query already gave me a perfectly formatted json response | 18:50 |
rm_work | so this is literally just converting from json, to model, so it can be converted back to json | 18:50 |
rm_work | and it makes me want to die inside | 18:51 |
*** yamamoto has joined #openstack-lbaas | 18:52 | |
johnsom | rm_work So why not just not inherit from our cooked BaseType? | 18:53 |
rm_work | ? | 18:53 |
johnsom | You are inheriting from this: https://github.com/openstack/octavia/blob/master/octavia/api/common/types.py#L77 | 18:53 |
*** AlexeyAbashkin has joined #openstack-lbaas | 18:54 | |
rm_work | oh from octavia.api.common import types | 18:54 |
johnsom | yeah | 18:54 |
rm_work | i don't think it's ours | 18:54 |
rm_work | but yeah sure i don't need to | 18:54 |
rm_work | i mean i don't think our stuff is the problem | 18:54 |
rm_work | the place where it gets wrecked is inside the pecan code (i've traced it through) | 18:54 |
johnsom | Wouldn't that get you around the data model mapping stuffs? | 18:55 |
rm_work | that isn't the issue | 18:55 |
johnsom | Ah, ok, maybe I didn't understand the issue | 18:56 |
johnsom | Going to grab lunch | 18:56 |
*** yamamoto has quit IRC | 18:56 | |
rm_work | oh, but | 18:57 |
rm_work | they have a different thing called DynamicBase | 18:57 |
* rm_work looks | 18:57 | |
rm_work | nope didn't help | 18:57 |
*** AlexeyAbashkin has quit IRC | 18:59 | |
*** velizarx has quit IRC | 19:01 | |
*** kobis1 has quit IRC | 19:08 | |
*** atoth has quit IRC | 19:10 | |
*** kobis has joined #openstack-lbaas | 19:15 | |
*** yamamoto has joined #openstack-lbaas | 19:17 | |
*** yamamoto has quit IRC | 19:17 | |
*** vishyj has quit IRC | 19:24 | |
*** yamamoto has joined #openstack-lbaas | 19:28 | |
*** yamamoto has quit IRC | 19:32 | |
*** yamamoto has joined #openstack-lbaas | 19:43 | |
*** yamamoto has quit IRC | 19:47 | |
*** jniesz has joined #openstack-lbaas | 19:49 | |
*** yamamoto has joined #openstack-lbaas | 19:57 | |
*** yamamoto has quit IRC | 19:57 | |
johnsom | #startmeeting Octavia | 20:00 |
openstack | Meeting started Wed Mar 28 20:00:02 2018 UTC and is due to finish in 60 minutes. The chair is johnsom. Information about MeetBot at http://wiki.debian.org/MeetBot. | 20:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 20:00 |
*** openstack changes topic to " (Meeting topic: Octavia)" | 20:00 | |
openstack | The meeting name has been set to 'octavia' | 20:00 |
johnsom | Hi folks | 20:00 |
jniesz | hi | 20:00 |
johnsom | #topic Announcements | 20:00 |
*** openstack changes topic to "Announcements (Meeting topic: Octavia)" | 20:00 | |
johnsom | We have a new core reviewer Jacky Hu (dayou)! | 20:00 |
nmagnezi | o/ | 20:00 |
xgerman_ | o/ | 20:01 |
xgerman_ | Congrats!! | 20:01 |
jniesz | congrats | 20:01 |
nmagnezi | congrats :-) | 20:01 |
johnsom | Yes, congratulations are in order. It is great to expand our core reviewer team | 20:01 |
johnsom | Other than that, I don't have any more announcements. Anyone else? | 20:02 |
johnsom | The summit schedule is now published and includes all of the sessions. I think we have three. | 20:02 |
johnsom | I plan to do an on-boarding session this time. If anyone else is attending and would like to help, let me know. | 20:03 |
johnsom | #topic Brief progress reports / bugs needing review | 20:03 |
*** openstack changes topic to "Brief progress reports / bugs needing review (Meeting topic: Octavia)" | 20:03 | |
rm_work | o/ | 20:03 |
rm_work | yeah i can help | 20:04 |
johnsom | I have been busy looking at gate issues, fixing bugs, reviewing patches, and trying to make some progress on my patches. | 20:04 |
johnsom | We saw a nasty little bug in health manager when nova goes out to lunch. When we were deleting amps nova would acknowledge, we would mark it DELETED, then move on. However, in nova the amp was stuck in "deleting" and was still running. It would post a health heartbeat, we would expect it to be deleted and delete it again. | 20:05 |
johnsom | The cycle continued.... | 20:06 |
johnsom | This eventually pushes the process CPU usage up and then memory as the failover backlog grows. | 20:06 |
johnsom | So, anyway, unique situation. I pushed a patch to stop the cycle. I think there is another patch up that would help here too. | 20:07 |
johnsom | Today I am working through our dashboard patch review backlog. Then back to tempest fun. | 20:07 |
johnsom | Any other updates from folks? | 20:07 |
johnsom | #topic Other OpenStack activities of note | 20:08 |
*** openstack changes topic to "Other OpenStack activities of note (Meeting topic: Octavia)" | 20:08 | |
johnsom | #link https://review.openstack.org/#/c/523973/ | 20:08 |
johnsom | Keystone is working on a common RBAC policies spec | 20:08 |
johnsom | I have commented there once, but this might be of interest to others. | 20:09 |
johnsom | It's very similar to the current Octavia default RBAC config | 20:09 |
johnsom | #topic Octavia deleted status vs. 404 | 20:09 |
*** openstack changes topic to "Octavia deleted status vs. 404 (Meeting topic: Octavia)" | 20:09 | |
johnsom | This was from last week. | 20:10 |
johnsom | The patch is still up for review. It looks like it needs a rebase. | 20:10 |
johnsom | I had a quick look at the SDK and I think it will be ok. | 20:10 |
johnsom | Any other updates here? | 20:10 |
johnsom | #topic Open Discussion | 20:11 |
*** openstack changes topic to "Open Discussion (Meeting topic: Octavia)" | 20:11 | |
johnsom | Ok, either a quiet bunch or netsplit... ha | 20:11 |
johnsom | Other topics for this week? | 20:11 |
johnsom | Please remember to add release notes to you patches if they warrant one. | 20:12 |
xgerman_ | hi | 20:12 |
xgerman_ | still here — just. not much news | 20:12 |
nmagnezi | likewise | 20:12 |
johnsom | Ok, then we can have a quick meeting and get back to work. | 20:13 |
nmagnezi | I'm still making progress in Rally, but no news just yet | 20:13 |
johnsom | Nice. | 20:13 |
nmagnezi | I wanted to raise something about storyboard in general but I want cgoncalves to also be around | 20:13 |
nmagnezi | so will wait for next week | 20:13 |
johnsom | Ok | 20:13 |
cgoncalves | I am actually | 20:14 |
nmagnezi | haha | 20:14 |
nmagnezi | okay.. | 20:14 |
nmagnezi | so | 20:14 |
*** kobis has quit IRC | 20:15 | |
nmagnezi | we kinda looked into it again in the past week, in the context of finding stories we would like to mark for backport potentials | 20:15 |
johnsom | release team recently moved over, requirements team is moving soon. FYI | 20:15 |
nmagnezi | but since storyboard has no option (to the best of my knowledge) to mark priority / severity | 20:15 |
nmagnezi | that.. can't of a problem.. | 20:15 |
nmagnezi | s/can't/kind | 20:15 |
nmagnezi | sorry | 20:15 |
nmagnezi | was a long day. | 20:16 |
johnsom | Yeah, the "storyboard" way of doing priority is to create a worklist or board and prioritize by sort order. | 20:16 |
nmagnezi | so the question / rant is: what do we think of the results of that migration? aren't we missing features we just to have in LP? | 20:16 |
cgoncalves | one of many things where storyboard falls short | 20:17 |
johnsom | That said, it's a pain so I haven't really done that yet. | 20:17 |
johnsom | Yeah, I kind of liked LP better myself. But.... | 20:17 |
johnsom | We can give the storyboard team feedback. You can open stories for them. They have IRC meetings (it was earlier today). | 20:18 |
cgoncalves | people are neglecting opening bugs in storyboard and linking that to commit msgs, me included | 20:18 |
johnsom | As for backport potential there are a couple of options: | 20:18 |
johnsom | 1. Create a worklist and add the stories there. | 20:19 |
johnsom | 2. Use the tags feature to add a "backport potential" tag to the story | 20:19 |
rm_work | i mean... i find it takes me longer to deal with opening a story and linking it, than actually fixing the bugs, in many instances :P | 20:19 |
rm_work | or maybe I just hate dealing with it for trivial stuff | 20:19 |
johnsom | 3. Ignore storyboard and mark it on the patch commit message. | 20:19 |
rm_work | so I normally don't >_> | 20:19 |
johnsom | You can also have the worklist automatic and pull in all stories with the "backport" tag | 20:20 |
nmagnezi | johnsom, the things is (this might add more context): in Neutron we created a proactive backport process, in which we pull the list of high severity bugs from LP so humans can manually triage an backport | 20:21 |
johnsom | If it would be a benefit for you guys I can set that up | 20:21 |
nmagnezi | in storyboard.. it's more difficult to do that.. | 20:21 |
xgerman_ | I would like some more robust backport ptocesses, too | 20:21 |
xgerman_ | I though last week we elected cgoncalves to be our stabel team lead | 20:22 |
xgerman_ | so he should set that up | 20:22 |
johnsom | Yeah, I think the best option for a workflow like that is to use the tags. If we think it's high priority and should be backported, add the backport tag to the story. Then work against the worklist to do the backports. | 20:22 |
xgerman_ | +1 | 20:22 |
cgoncalves | xgerman_: storyboard does not provide the means to accurately retrieve relevant data | 20:22 |
nmagnezi | johnsom, +1. worth the try. worst case we contact the storyboard team to add stuff if that does not work for us | 20:23 |
xgerman_ | +1 | 20:23 |
nmagnezi | cgoncalves, what do you think? | 20:24 |
johnsom | Yeah, it looks like other teams are doing it this way, there are already tags for release backports. | 20:24 |
cgoncalves | nmagnezi: tags would be a workaround | 20:24 |
nmagnezi | johnsom, to me it looks like tags are kind of a workaround | 20:24 |
nmagnezi | haha | 20:24 |
nmagnezi | yeah | 20:24 |
nmagnezi | LP had both tags and bug severity metadata | 20:25 |
johnsom | Well, I don't disagree. It's a short term solution until you get the storyboard team to add the feature you want. | 20:25 |
cgoncalves | johnsom: ... or we could move back to LP :P | 20:25 |
johnsom | So, let me ask, are you advocating moving back to LP? | 20:25 |
cgoncalves | at this point in time I don't believe it would be well received/accepted by TC | 20:26 |
johnsom | That would be something you would need to bring up with the foundation. | 20:26 |
nmagnezi | well, it worked well for us. if we can sort things out in storyboard that would be okay too | 20:27 |
johnsom | There are a couple of reasons they are moving everyone off launchpad | 20:27 |
cgoncalves | but I am personally not happy with storyboard as I can't find a single feature that I prefer over LP | 20:27 |
nmagnezi | cgoncalves, +1 | 20:27 |
johnsom | One, it's not really supported and has some big bugs that people can't fix. | 20:27 |
johnsom | Two, they want to have other ways to authenticate people that isn't one vendor | 20:27 |
johnsom | Three, people wanted a more "agile/scrum/kanban" like tool. (a former Octavia PTL was in that camp) | 20:28 |
johnsom | So, we as a team need to make a choice: | 20:29 |
johnsom | 1. We work with the storyboard team (and/or submit patches) to improve it in a way that works for us. | 20:29 |
johnsom | 2. We approach the foundation and ask to move back. | 20:30 |
xgerman_ | 3. We use trello | 20:30 |
*** sapd__ has quit IRC | 20:30 | |
cgoncalves | 99. We propose Bugzilla | 20:30 |
nmagnezi | lol | 20:30 |
* johnsom glares at xgerman. | 20:30 | |
johnsom | I am not a fan of trello | 20:30 |
*** sapd__ has joined #openstack-lbaas | 20:31 | |
nmagnezi | johnsom, I would say that 2 is probably less likely to actually happen. so for 1 lets start maybe something like an etherpad and write down everything we are missing from storyboard | 20:31 |
nmagnezi | when we finish we can communicate that to them.. | 20:31 |
johnsom | Ok | 20:31 |
johnsom | There is a #stroyboard IRC channel too BTW | 20:32 |
nmagnezi | If we start stories for things we miss there may be a change they will miss them (since the search engine of storyboard is sooooooooo lacking) | 20:32 |
johnsom | Yeah, and broken IMO. I keep getting stories for other projects | 20:33 |
johnsom | I opened a story on that.... | 20:33 |
nmagnezi | </rant> | 20:33 |
nmagnezi | johnsom, how did they react you the story you submitted? | 20:33 |
nmagnezi | s/you/to | 20:33 |
johnsom | #link https://storyboard.openstack.org/#!/story/2001468 | 20:34 |
cgoncalves | you have to raise priority/severity on your stories. oh, wait.... xD | 20:34 |
xgerman_ | just put [URGENT] in the title | 20:34 |
johnsom | Please don't do this for octavia stories... | 20:35 |
cgoncalves | [++URGENT] | 20:35 |
nmagnezi | xgerman_, feels like we moved back in time :D | 20:35 |
johnsom | #link https://etherpad.openstack.org/p/storyboard-issues | 20:35 |
johnsom | There you go | 20:35 |
xgerman_ | some approaches are timeless | 20:35 |
johnsom | Who wants to take the lead on this with the storyboard team? | 20:36 |
nmagnezi | I need to drop. will catch up with the log later guys | 20:36 |
* xgerman_ takes step back | 20:36 | |
nmagnezi | johnsom, I don't mind | 20:36 |
nmagnezi | *but* | 20:36 |
* johnsom steps back | 20:36 | |
nmagnezi | we do need to start an etherpad | 20:36 |
johnsom | I just did | 20:36 |
johnsom | #link https://etherpad.openstack.org/p/storyboard-issues | 20:36 |
xgerman_ | we let nmagnezi drop and then assign him - problem solvd | 20:36 |
cgoncalves | johnsom: I can add a few issues to the list and ask other folks to do the same | 20:37 |
xgerman_ | +100 | 20:37 |
johnsom | Also, do you want to try the backport tag? I will volunteer to set that up | 20:37 |
cgoncalves | aren't tags a free-form text thing everyone could create? | 20:37 |
johnsom | Yes, but I meant setting up the work list based on the tag. (plus adding the tag as I review at stories) | 20:38 |
johnsom | We also need to agree to the tag, something like backport-candidate? | 20:39 |
cgoncalves | sure, why not :) thanks! | 20:39 |
cgoncalves | I fear, though, we will not have many stories to tag since people don't use storyboard that much | 20:40 |
johnsom | Oh, they do | 20:40 |
johnsom | I think we got ~12 in the last week | 20:40 |
cgoncalves | ok, I was not aware of | 20:41 |
johnsom | You can "favorite" projects and setup e-mail notifications for stories like we had in LP | 20:42 |
johnsom | I try to look through those and comment. In fact I fixed one from Alex that was reported recently about the log level issue | 20:42 |
cgoncalves | I thought I had set that. checking | 20:42 |
cgoncalves | I'm aware of that story. thanks for the patch! | 20:43 |
johnsom | Alex seems perfectly happy to add stories... Grin | 20:43 |
johnsom | Ok, any other items today? | 20:44 |
xgerman_ | #link http://tarballs.openstack.org/octavia/test-images/ | 20:45 |
xgerman_ | our images are building | 20:45 |
johnsom | Ah, nice | 20:45 |
cgoncalves | centos image size is smaller than ubuntu's \o/ | 20:46 |
johnsom | lol | 20:46 |
xgerman_ | I haven’t tested those images (yet) | 20:46 |
johnsom | Ok, thanks folks! | 20:47 |
johnsom | #endmeeting | 20:47 |
*** openstack changes topic to "Discussion of OpenStack Load Balancing (Octavia) | https://etherpad.openstack.org/p/octavia-priority-reviews" | 20:47 | |
openstack | Meeting ended Wed Mar 28 20:47:39 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 20:47 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/octavia/2018/octavia.2018-03-28-20.00.html | 20:47 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/octavia/2018/octavia.2018-03-28-20.00.txt | 20:47 |
openstack | Log: http://eavesdrop.openstack.org/meetings/octavia/2018/octavia.2018-03-28-20.00.log.html | 20:47 |
*** fnaval_ has quit IRC | 20:47 | |
cgoncalves | dayou: you may be happy to see https://review.openstack.org/#/c/556888/ | 20:48 |
*** fnaval has joined #openstack-lbaas | 20:52 | |
*** yamamoto has joined #openstack-lbaas | 20:57 | |
johnsom | Here is the backport-candidate worklist: https://storyboard.openstack.org/#!/worklist/268 | 20:58 |
huseyin | michael, here is the error log from worker node after exhausting retries https://justpaste.it/1iwd7 | 20:59 |
*** beisner is now known as beisner-afk | 20:59 | |
johnsom | huseyin Yep, the amphora was not reachable via the lb-mgmt-net from that controller | 21:00 |
huseyin | there is not an active amphora image after the error | 21:00 |
huseyin | what is the correct way to test connectivity? | 21:01 |
huseyin | when an amphora image is fired up, i log in to that image and i can ping worker node | 21:01 |
huseyin | i can also ping amphora image from the workers | 21:02 |
*** velizarx has joined #openstack-lbaas | 21:02 | |
huseyin | during these retries, amphora image id and IP address changes repeatedly | 21:02 |
johnsom | huseyin If you want the amp to stay after a failure you can set this setting in the config: https://docs.openstack.org/octavia/latest/configuration/configref.html#task_flow.disable_revert | 21:03 |
*** yamamoto has quit IRC | 21:03 | |
johnsom | It disables the automatic clean up | 21:03 |
huseyin | ok, and what about the connectivity? | 21:04 |
johnsom | huseyin The "openssl s_client -connect<ip>:9443 is the exact connection the controller makes to the amphora that is failing for you | 21:04 |
johnsom | huseyin I'm not understanding the part about the image id changing and the IP changing. | 21:04 |
huseyin | i check the images with “openstack server list” with admin credentials | 21:05 |
huseyin | during retries | 21:05 |
johnsom | huseyin is your health manager failing these over? Is there log entries in the health manager log? | 21:05 |
huseyin | here you are https://justpaste.it/1iwdj | 21:07 |
*** fnaval has quit IRC | 21:07 | |
*** fnaval has joined #openstack-lbaas | 21:07 | |
johnsom | Ok, that is probably confusing things a bit. Until we get the worker fixed let's stop the health manager process. | 21:08 |
johnsom | There is actually a fix for that behavior (failing over a amp in PENDING_*) under review. It's not the cause of the trouble, but making it confusing for sure | 21:09 |
*** fnaval_ has joined #openstack-lbaas | 21:09 | |
huseyin | what is the suggested way of implementing and testing lb-mgmt-net ? | 21:10 |
johnsom | Testing is using the openssl command. Implementing there are a bunch of ways to do it. | 21:10 |
huseyin | let me explain my way | 21:11 |
huseyin | the subnet that worker nodes are running is also a provider network on openstack | 21:11 |
johnsom | In devstack we create a port using OVS or linux bridge as seen here: https://github.com/openstack/octavia/blob/master/devstack/plugin.sh#L328 | 21:11 |
*** fnaval has quit IRC | 21:12 | |
johnsom | Many deployments use a provider network for the lb-mgmt-net. | 21:12 |
huseyin | and the lb-mgmt-net has a router on that provider network | 21:13 |
huseyin | this router ip on the lb-mgmt-net is the default gw for lb-mgmt-net | 21:14 |
huseyin | so all amphora images use this router to access worker nodes | 21:14 |
*** velizarx has quit IRC | 21:15 | |
johnsom | ok, yeah, that should work. I assume the worker has a route through this router to the amphora? | 21:15 |
huseyin | worker nodes are running on the same network with this router, and there is a route for lb-mgmt-net with next hop | 21:15 |
huseyin | so why they can not reach amphora image? | 21:15 |
johnsom | Is there a security group getting in the way? Can you tcpdump -nli eth0 and see the packets from the worker? | 21:16 |
huseyin | is there any possible reason like the amphora-image itself that can cause the problem? | 21:17 |
johnsom | are there errors in the /var/log/syslog from the amphora-agent of why it might reject the packet? maybe a bad certificate setup? | 21:17 |
huseyin | ok ican try with disable_revert | 21:17 |
johnsom | Yes, the amphora-agent must be running in the amp and listening on 9443 | 21:18 |
johnsom | huseyin Don't forget to stop your health-manager | 21:18 |
huseyin | ok, got it | 21:18 |
huseyin | michael, you are right | 21:34 |
huseyin | systemd[1]: amphora-agent.service: Main process exited, code=exited, status=1/FAILURE | 21:34 |
huseyin | ValueError: certfile "/etc/ssl/private/uyum.in.crt" does not exist | 21:34 |
johnsom | Hmm, now that is an odd error. | 21:35 |
huseyin | but disable_revert did not work | 21:36 |
huseyin | it deletes the images after finishing retries | 21:36 |
*** sticker has joined #openstack-lbaas | 21:40 | |
johnsom | huseyin So, I suspect the [certificates] section of your octavia.conf has some issue. | 21:45 |
huseyin | now i try to use auto generated certificates | 21:46 |
huseyin | i got the error Error: [('PEM routines', 'PEM_read_bio', 'no start line'), ('SSL routines', 'SSL_CTX_use_certificate_file', 'PEM lib')] | 21:46 |
johnsom | The "-----BEGIN CERTIFICATE-----" is missing from the pem file | 21:47 |
huseyin | i used auto generate script in the github | 21:47 |
johnsom | Maybe you have DER certs? | 21:47 |
huseyin | https://github.com/openstack/octavia/blob/master/bin/create_certificates.sh | 21:47 |
huseyin | https://justpaste.it/1iwez | 21:49 |
johnsom | huseyin Here are the configs and example certs used in the gates: http://logs.openstack.org/89/548989/4/check/octavia-v1-dsvm-scenario/90dc6c6/logs/etc/octavia/ | 21:49 |
johnsom | huseyin https://github.com/openstack/octavia/blob/master/devstack/plugin.sh#L294 | 21:51 |
*** ssmith has quit IRC | 21:51 | |
johnsom | That is the script that sets it up | 21:51 |
johnsom | That line and the config file settings below it | 21:51 |
-openstackstatus- NOTICE: the zuul web dashboard will experience a short downtime as we roll out some changes - no job execution should be affected | 21:52 | |
huseyin | thanks michael, i will try it | 21:53 |
*** harlowja has joined #openstack-lbaas | 21:53 | |
*** huseyin has quit IRC | 21:54 | |
*** yamamoto has joined #openstack-lbaas | 21:59 | |
*** yamamoto has quit IRC | 22:04 | |
johnsom | Can one of the cores review/approve this? https://review.openstack.org/#/c/555965 Once it's merged I can propose the governance tag for it. | 22:12 |
*** aojea has joined #openstack-lbaas | 22:23 | |
*** rcernin has joined #openstack-lbaas | 22:28 | |
xgerman_ | done | 22:30 |
*** fnaval_ has quit IRC | 22:40 | |
johnsom | Thanks | 22:52 |
*** yamamoto has joined #openstack-lbaas | 23:00 | |
openstackgerrit | Michael Johnson proposed openstack/octavia-dashboard master: Add rbac support for octavia service apis https://review.openstack.org/550319 | 23:05 |
*** yamamoto has quit IRC | 23:06 | |
*** beisner-afk is now known as beisner | 23:14 | |
*** aojea has quit IRC | 23:33 | |
openstackgerrit | Merged openstack/octavia master: add lower-constraints job https://review.openstack.org/555965 | 23:48 |
openstackgerrit | Adam Harwell proposed openstack/octavia master: WIP: Add usage admin resource https://review.openstack.org/557548 | 23:52 |
-openstackstatus- NOTICE: Zuul has been restarted to update to the latest code; existing changes have been re-enqueued, you may need to recheck changes uploaded in the past 10 minutes | 23:58 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!