*** mithilarun has joined #openstack-lbaas | 00:59 | |
*** mithilarun has quit IRC | 01:00 | |
*** mithilarun has joined #openstack-lbaas | 01:01 | |
*** mithilarun has quit IRC | 01:30 | |
*** mithilarun has joined #openstack-lbaas | 01:33 | |
*** mithilar_ has joined #openstack-lbaas | 01:36 | |
*** mithilarun has quit IRC | 01:38 | |
*** mithilar_ has quit IRC | 01:41 | |
*** yamamoto has quit IRC | 02:29 | |
*** yamamoto has joined #openstack-lbaas | 03:12 | |
*** yamamoto has quit IRC | 03:18 | |
*** yamamoto has joined #openstack-lbaas | 03:48 | |
*** psachin has joined #openstack-lbaas | 04:23 | |
*** yamamoto has quit IRC | 04:47 | |
*** AlexStaf has joined #openstack-lbaas | 05:00 | |
*** yamamoto has joined #openstack-lbaas | 05:02 | |
*** yamamoto has quit IRC | 05:29 | |
*** yamamoto has joined #openstack-lbaas | 05:41 | |
*** yamamoto has quit IRC | 05:46 | |
*** yamamoto has joined #openstack-lbaas | 05:47 | |
*** AlexStaf has quit IRC | 05:55 | |
*** yamamoto has quit IRC | 06:06 | |
*** yboaron has joined #openstack-lbaas | 06:08 | |
*** yamamoto has joined #openstack-lbaas | 06:31 | |
*** gcheresh has joined #openstack-lbaas | 06:34 | |
*** yamamoto has quit IRC | 06:36 | |
*** yamamoto has joined #openstack-lbaas | 07:10 | |
*** pcaruana has joined #openstack-lbaas | 07:14 | |
*** yboaron has quit IRC | 07:21 | |
*** numans has joined #openstack-lbaas | 07:47 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/neutron-lbaas-dashboard stable/stein: Imported Translations from Zanata https://review.opendev.org/656620 | 07:54 |
---|---|---|
zigo | nmagnezi: johnsom rm_workm: What am I suppose to see in the Amphora /var/lib/octavia/certs folder? Because for me, it's empty there ... | 07:59 |
zigo | In the amphora-agent.log, I get this: | 07:59 |
zigo | [2019-05-01 07:58:35 +0000] [694] [DEBUG] Invalid request from ip=::ffff:192.168.104.1: [SSL: TLSV1_ALERT_UNKNOWN_CA] tlsv1 alert unknown ca (_ssl.c:2488) | 07:59 |
zigo | [2019-05-01 07:58:35 +0000] [694] [DEBUG] Failed to send error message. | 07:59 |
zigo | and in octavia-worker.log, this: | 08:00 |
zigo | 2019-05-01 07:59:55.952 4976 WARNING octavia.amphorae.drivers.haproxy.rest_api_driver [-] Could not connect to instance. Retrying.: requests.exceptions.SSLError: HTTPSConnectionPool(host='192.168.104.248', port=9443): Max retries exceeded with url: /0.5/info (Caused by SSLError(SSLError("bad handshake: Error([('SSL routines', 'tls_process_server_certificate', 'certificate verify failed')])"))) | 08:00 |
zigo | This happened with both the Ubuntu image created with DIB, and the Amphora image I created with my own script. | 08:00 |
zigo | How can I check further what's going on? | 08:00 |
zigo | (note: I'm running with Debian Buster and Stein) | 08:00 |
*** AlexStaf has joined #openstack-lbaas | 08:00 | |
*** yamamoto has quit IRC | 08:08 | |
*** psachin has quit IRC | 08:20 | |
*** yboaron has joined #openstack-lbaas | 08:25 | |
*** yamamoto has joined #openstack-lbaas | 08:25 | |
*** yboaron_ has joined #openstack-lbaas | 08:28 | |
*** yamamoto has quit IRC | 08:28 | |
*** yboaron has quit IRC | 08:31 | |
*** yamamoto has joined #openstack-lbaas | 09:12 | |
*** yamamoto has quit IRC | 09:18 | |
*** yamamoto has joined #openstack-lbaas | 09:24 | |
*** yamamoto has quit IRC | 09:31 | |
*** yamamoto has joined #openstack-lbaas | 10:12 | |
*** yamamoto has quit IRC | 10:17 | |
*** mithilarun has joined #openstack-lbaas | 11:53 | |
*** mithilarun has quit IRC | 12:12 | |
*** mithilarun has joined #openstack-lbaas | 12:12 | |
*** mithilarun has quit IRC | 12:17 | |
*** ianychoi_ has quit IRC | 12:35 | |
*** ianychoi_ has joined #openstack-lbaas | 12:35 | |
*** pcaruana has quit IRC | 12:49 | |
*** yamamoto has joined #openstack-lbaas | 12:52 | |
*** pcaruana has joined #openstack-lbaas | 12:54 | |
*** ccamposr has quit IRC | 12:58 | |
*** ianychoi_ has quit IRC | 13:00 | |
*** yamamoto has quit IRC | 13:31 | |
*** AlexStaf has quit IRC | 13:36 | |
*** ianychoi has joined #openstack-lbaas | 13:42 | |
*** mithilarun has joined #openstack-lbaas | 13:49 | |
*** yamamoto has joined #openstack-lbaas | 14:09 | |
*** AlexStaf has joined #openstack-lbaas | 14:13 | |
*** yamamoto has quit IRC | 14:17 | |
*** yamamoto has joined #openstack-lbaas | 14:18 | |
*** AlexStaf has quit IRC | 14:18 | |
*** Vorrtex has joined #openstack-lbaas | 14:20 | |
openstackgerrit | Merged openstack/octavia master: Make amphora cert validity time configurable https://review.opendev.org/656404 | 14:47 |
*** gcheresh has quit IRC | 14:57 | |
*** dims has quit IRC | 15:09 | |
*** yamamoto has quit IRC | 15:09 | |
*** dims has joined #openstack-lbaas | 15:17 | |
*** mithilarun has quit IRC | 15:27 | |
*** mithilarun has joined #openstack-lbaas | 15:27 | |
*** mithilarun has quit IRC | 15:32 | |
*** mithilarun has joined #openstack-lbaas | 15:36 | |
*** yamamoto has joined #openstack-lbaas | 15:52 | |
*** yamamoto has quit IRC | 15:56 | |
*** sapd1_x has joined #openstack-lbaas | 16:01 | |
*** yboaron_ has quit IRC | 16:16 | |
johnsom | zigo The certs in /var/lib/octavia/certs are generated automatically by the controller and loaded via config driver/cloud-init. That directory should be a an encrypted ram-fs mounted to /var/lib/octavia/certs | 16:21 |
*** ccstone has quit IRC | 16:34 | |
*** AlexStaf has joined #openstack-lbaas | 16:57 | |
*** cbrumm has quit IRC | 17:04 | |
*** sapd1_x has quit IRC | 17:16 | |
*** AlexStaf has quit IRC | 17:44 | |
*** ramishra has joined #openstack-lbaas | 19:39 | |
*** ramishra has quit IRC | 19:45 | |
*** gcheresh has joined #openstack-lbaas | 20:03 | |
*** gcheresh has quit IRC | 20:17 | |
*** gcheresh has joined #openstack-lbaas | 20:23 | |
*** Vorrtex has quit IRC | 20:32 | |
*** pcaruana has quit IRC | 20:42 | |
*** mithilarun has quit IRC | 20:52 | |
*** mithilarun has joined #openstack-lbaas | 20:52 | |
*** rcernin has quit IRC | 20:53 | |
*** mithilarun has quit IRC | 20:57 | |
rm_work | we don't run any of the tempest stuff that's in-tree with octavia, right? it's all dead? | 21:09 |
rm_work | (for v2) | 21:09 |
rm_work | johnsom / cgoncalves ^^ | 21:10 |
johnsom | Yeah, the in-tree tempest should all be v1 related | 21:10 |
rm_work | yeah k | 21:10 |
rm_work | there's one v2 thing for quotas but i don't think it's used | 21:10 |
openstackgerrit | Adam Harwell proposed openstack/octavia master: Remove v1 API and associated code https://review.opendev.org/656707 | 21:13 |
*** gcheresh has quit IRC | 21:19 | |
*** mithilarun has joined #openstack-lbaas | 22:05 | |
*** mithilarun has quit IRC | 22:10 | |
openstackgerrit | Adam Harwell proposed openstack/octavia master: Remove v1 API and associated code https://review.opendev.org/656707 | 22:34 |
rm_work | nmagnezi: is this still a thing? https://review.opendev.org/#/c/558194/ | 22:45 |
rm_work | I never understood it | 22:45 |
rm_work | and it's a year old | 22:46 |
rm_work | nmagnezi: I think I'm going to abandon it, you can restore it if you think it's still necessary | 22:46 |
*** rcernin has joined #openstack-lbaas | 23:10 | |
*** yamamoto has joined #openstack-lbaas | 23:18 | |
lxkong | johnsom: hi, a follow-up question to the one of yesterday, if it will cause any problem if we keep the existing sgs on the vip port? | 23:23 |
lxkong | rm_work ^^ | 23:24 |
johnsom | Yes, it creates conflicts and potential vulnerabilities. | 23:24 |
lxkong | conflict? | 23:25 |
lxkong | could you please tell me more? | 23:25 |
johnsom | For example, if we need to rebuild it, we don’t want to store and manage tenant sgs | 23:25 |
lxkong | for `rebuild`, do you mean failover? | 23:26 |
lxkong | why we need to store the tenant's sgs? | 23:26 |
johnsom | Right, port rebuild | 23:26 |
lxkong | hmm...it's still not very clear to me :-( let me check the code to see if i can understand | 23:27 |
johnsom | The lb is a managed service, if we let users open ports we can no longer say we manage it. Likewise, if it is a user visible sg they can delete them, etc. | 23:28 |
lxkong | thanks johnsom, i will dig more | 23:35 |
lxkong | johnsom: btw, if we have someone who is going to lead the acl design and implementation, I am very happy to help coding/review/test | 23:37 |
johnsom | Ok, thanks lxkong | 23:38 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!