*** armax has joined #openstack-lbaas | 00:21 | |
*** eandersson has quit IRC | 00:44 | |
*** armax has quit IRC | 00:48 | |
*** yamamoto has joined #openstack-lbaas | 01:31 | |
*** yamamoto has quit IRC | 02:02 | |
*** goldyfruit___ has quit IRC | 02:02 | |
*** eandersson has joined #openstack-lbaas | 03:03 | |
*** psachin has joined #openstack-lbaas | 03:28 | |
*** yamamoto has joined #openstack-lbaas | 03:35 | |
*** eandersson has quit IRC | 03:56 | |
*** eandersson has joined #openstack-lbaas | 03:57 | |
*** eandersson has quit IRC | 03:57 | |
*** eandersson has joined #openstack-lbaas | 03:57 | |
*** yamamoto has quit IRC | 04:11 | |
*** yamamoto has joined #openstack-lbaas | 04:11 | |
*** yamamoto_ has joined #openstack-lbaas | 04:41 | |
*** yamamoto has quit IRC | 04:44 | |
*** ricolin has joined #openstack-lbaas | 04:54 | |
*** psachin has quit IRC | 05:10 | |
*** ramishra has joined #openstack-lbaas | 06:15 | |
*** langyal has joined #openstack-lbaas | 06:53 | |
*** yamamoto_ has quit IRC | 07:01 | |
*** yamamoto has joined #openstack-lbaas | 07:02 | |
*** yamamoto has quit IRC | 07:05 | |
*** yamamoto_ has joined #openstack-lbaas | 07:05 | |
*** rcernin has quit IRC | 07:08 | |
*** gcheresh_ has joined #openstack-lbaas | 07:43 | |
*** ccamposr__ has quit IRC | 07:59 | |
*** AlexStaf has joined #openstack-lbaas | 08:01 | |
*** yamamoto has joined #openstack-lbaas | 08:03 | |
*** maciejjozefczyk has joined #openstack-lbaas | 08:03 | |
*** yamamoto_ has quit IRC | 08:06 | |
*** ccamposr has joined #openstack-lbaas | 08:09 | |
*** tkajinam has quit IRC | 08:19 | |
*** ramishra has quit IRC | 08:27 | |
*** yamamoto has quit IRC | 08:28 | |
*** yamamoto has joined #openstack-lbaas | 08:32 | |
*** yamamoto_ has joined #openstack-lbaas | 08:43 | |
*** trident has quit IRC | 08:45 | |
*** yamamoto has quit IRC | 08:46 | |
*** yamamoto_ has quit IRC | 08:51 | |
*** yamamoto has joined #openstack-lbaas | 08:56 | |
*** yamamoto has quit IRC | 08:58 | |
*** yamamoto has joined #openstack-lbaas | 08:59 | |
*** trident has joined #openstack-lbaas | 08:59 | |
*** yamamoto has quit IRC | 09:01 | |
*** rcernin has joined #openstack-lbaas | 09:03 | |
*** maciejjozefczyk has quit IRC | 09:10 | |
*** maciejjozefczyk has joined #openstack-lbaas | 09:10 | |
*** trident has quit IRC | 09:16 | |
*** ivve has joined #openstack-lbaas | 09:17 | |
*** maciejjozefczyk has quit IRC | 09:17 | |
*** ramishra has joined #openstack-lbaas | 09:20 | |
*** trident has joined #openstack-lbaas | 09:24 | |
*** yamamoto has joined #openstack-lbaas | 09:33 | |
*** yamamoto has quit IRC | 09:39 | |
*** maciejjozefczyk has joined #openstack-lbaas | 09:44 | |
*** maciejjozefczyk has quit IRC | 09:49 | |
*** rcernin has quit IRC | 09:56 | |
*** yamamoto has joined #openstack-lbaas | 10:02 | |
*** yamamoto has quit IRC | 10:07 | |
*** luksky has joined #openstack-lbaas | 10:09 | |
*** yamamoto has joined #openstack-lbaas | 10:10 | |
*** yamamoto has quit IRC | 10:10 | |
*** rcernin has joined #openstack-lbaas | 10:12 | |
openstackgerrit | Ann Taraday proposed openstack/octavia master: Add option to set default ssl ciphers in haproxy https://review.opendev.org/685337 | 10:20 |
---|---|---|
*** rcernin has quit IRC | 10:49 | |
*** yamamoto has joined #openstack-lbaas | 11:44 | |
*** pcaruana has joined #openstack-lbaas | 11:47 | |
*** yamamoto has quit IRC | 11:48 | |
*** langyal has quit IRC | 11:53 | |
*** pcaruana has quit IRC | 12:09 | |
*** rcernin has joined #openstack-lbaas | 12:16 | |
*** numans has joined #openstack-lbaas | 12:24 | |
*** yamamoto has joined #openstack-lbaas | 12:24 | |
*** yamamoto has quit IRC | 12:28 | |
*** yamamoto has joined #openstack-lbaas | 12:28 | |
*** yamamoto_ has joined #openstack-lbaas | 12:29 | |
*** yamamoto has quit IRC | 12:33 | |
brtknr | johnsom: are these folks online today? | 12:38 |
*** yamamoto_ has quit IRC | 12:42 | |
*** goldyfruit___ has joined #openstack-lbaas | 12:44 | |
*** rcernin has quit IRC | 12:44 | |
*** goldyfruit___ has quit IRC | 12:49 | |
CobHead | Hi johnsom: Just so I understand correctly: This patch is to fix an issue with listeners being undeletable when the container reference is deleted: https://review.opendev.org/#/c/690984/ whereas this patch is to make it possible to update the actual reference: https://review.opendev.org/#/c/691987/ | 13:08 |
*** yamamoto has joined #openstack-lbaas | 13:18 | |
*** yamamoto has quit IRC | 13:26 | |
*** goldyfruit has joined #openstack-lbaas | 13:51 | |
*** maciejjozefczyk has joined #openstack-lbaas | 14:32 | |
ataraday_ | Hello everyone! I pushed small improvement to octaviaclient change some time ago https://review.opendev.org/#/c/693144/ may be someone have time for a quick look | 14:40 |
*** luksky has quit IRC | 14:41 | |
ataraday_ | johnsom, I posted comment on default cipher change https://review.opendev.org/685337 - if you have time let me know what you think about it. | 14:42 |
rm_work | ataraday_: yeah, that always bothered me too -- though I am not sure, what if someone uses a uuid as a name <_< | 14:52 |
rm_work | CobHead: that's correct | 15:01 |
CobHead | Allright. I will give a +1 on the Rocky backport for the first one, as I just tested it on a large cluster. As for the other one, I might have to cherry-pick it and pull it in order to try it out. | 15:04 |
CobHead | Thanks, rm_work :) | 15:05 |
rm_work | ok so my plan for today is to go through the PTG notes and make a summary email for the ML | 15:22 |
johnsom | rm_work: brtknr has Kolla Ansible questions. | 15:28 |
rm_work | hmm k | 15:29 |
rm_work | I can give it my best shot, it's been a while | 15:29 |
ataraday_ | rm_work, on our internal cloud when people check some loadbalancer's state - they use id. We got a lot of loadbalacers, so this improvement make show working really faster :) | 15:29 |
rm_work | yeah, i don't disagree :D | 15:29 |
johnsom | I have seen a few folks struggling with Kolla Ansible recently. I guess it doesn’t wire up the networks | 15:29 |
rm_work | yeah, it doesn't really... know how, I think | 15:29 |
rm_work | to be fair, neither do I :D | 15:30 |
rm_work | and I think it depends on a lot of factors | 15:30 |
johnsom | I think kong also uses it | 15:30 |
johnsom | ataraday_: yeah, that puzzled me about OSC as well. I will review today. | 15:31 |
*** TrevorV has joined #openstack-lbaas | 15:31 | |
brtknr | rm_work: it feels quite complicated to deploy octavia via kolla ansible atm, seems to require quite a few manual steps, including creation of network which could def be automated and cert generation, which i am okay with being manual but also would nice to have it automated | 15:32 |
johnsom | I am done with the cert patches, I just need to do some rebases to stack them all up so the new tempest tests pass | 15:32 |
brtknr | but i dont understand octavia well enough to kolla-ansiblise the various steps | 15:33 |
brtknr | at the moment, kolla-ansible only seems to support the single certificate scenario for client and server, not the dual certificate recommened for production use, which even the octavia devstack plugin deploys afaict | 15:36 |
brtknr | happy to do the leg work for this if someone out there is available to help me out a bit navigate the octavia-land | 15:37 |
johnsom | brtknr: we are happy to help on the Octavia side. I am just not familiar with Kolla | 15:38 |
brtknr | not sure how openstack-ansible handle this but probably something that we can adapt from there | 15:38 |
johnsom | OSA also lags a bit last time I looked at it. But it is at least functional out of the box. Lol | 15:39 |
brtknr | johnsom: so kolla already builds containers for all the octavia services... its the default configuration parts where the details are a bit fuzzy | 15:39 |
brtknr | would be nice to incorporate the octavia best practices as the default in kolla-ansible | 15:40 |
johnsom | If you want, we can setup an etherpad for questions. Just mention it here and someone from Octavia can answer | 15:40 |
brtknr | johnsom: sounds good to me | 15:40 |
johnsom | Yeah, I have done some of that recently for tripleo | 15:41 |
*** ccamposr has quit IRC | 15:42 | |
johnsom | brtknr https://etherpad.openstack.org/p/kolla-ansible-octavia | 15:42 |
*** ccamposr has joined #openstack-lbaas | 15:43 | |
johnsom | brtknr: don’t be shy bugging us in this channel for answers either. | 15:45 |
rm_work | brtknr: I think johnsom would be the go-to on the cert stuff :D | 15:47 |
rm_work | but for networks... i don't really know how we would be able to do that sanely | 15:48 |
johnsom | Yeah. I wrote a guide for the certs | 15:48 |
brtknr | Ok cool, I will put in some silly questions on the ether pad | 15:48 |
rm_work | a lot of that stuff is dependent on what can actually reach various HVs and such | 15:48 |
rm_work | how your physical net is set up | 15:48 |
rm_work | and we prefer provider style networks for the management layer which is kinda outside of neutron usually | 15:49 |
brtknr | Any idea what the network creation defaults are for OSA? | 15:51 |
johnsom | They setup a provider network as I remember | 15:52 |
johnsom | At one point OSA was a bit complicated with all of the bridges they added, but I think someone cleaned that up | 15:52 |
*** gcheresh_ has quit IRC | 15:54 | |
*** yamamoto has joined #openstack-lbaas | 16:00 | |
*** yamamoto has quit IRC | 16:06 | |
brtknr | johnsom: okay so i see that in devstack, octavia creates a vxlan for the lb-mgmt-net | 16:12 |
brtknr | is that for convenience? | 16:12 |
johnsom | Yes. The lb-mgmt-net is simply a neutron network. The tricky part is how you give the controller processes (containers in your case) access to that neutron network. | 16:13 |
CobHead | OSA relies on a bridge that needs to be setup manually before deploying Octavia, FYI. | 16:13 |
johnsom | As long as neutron can see the network and attach it to VMs, it is fine for Octavia use. | 16:13 |
*** gcheresh_ has joined #openstack-lbaas | 16:16 | |
brtknr | So for a default configuration, we could create a vxlan based neutron network and provide this network ID to octavia config correct? | 16:17 |
johnsom | Yes, then you need to make sure the worker, health manager, and housekeeping processes have access to that network. | 16:18 |
brtknr | johnsom: ah that explains why a vlan approach is easier | 16:21 |
*** maciejjozefczyk has quit IRC | 16:22 | |
*** armax has joined #openstack-lbaas | 16:30 | |
*** servagem has joined #openstack-lbaas | 16:31 | |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Fix update API when barbican secret is missing https://review.opendev.org/691987 | 16:31 |
*** ivve has quit IRC | 16:32 | |
*** ricolin has quit IRC | 16:34 | |
*** devfaz has quit IRC | 16:38 | |
*** devfaz has joined #openstack-lbaas | 16:38 | |
*** maciejjozefczyk has joined #openstack-lbaas | 16:43 | |
*** pcaruana has joined #openstack-lbaas | 16:45 | |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Fix multi-listener LB with missing certificate https://review.opendev.org/692208 | 16:46 |
openstackgerrit | Merged openstack/octavia stable/train: Fix issues with unavailable secrets https://review.opendev.org/690984 | 16:47 |
openstackgerrit | Merged openstack/octavia stable/stein: Fix issues with unavailable secrets https://review.opendev.org/691693 | 16:47 |
*** maciejjozefczyk has quit IRC | 17:25 | |
openstackgerrit | Merged openstack/octavia master: Fix typo in doc agent.py->agent https://review.opendev.org/690884 | 17:43 |
*** goldyfruit has quit IRC | 17:52 | |
*** goldyfruit has joined #openstack-lbaas | 17:53 | |
*** gcheresh_ has quit IRC | 17:55 | |
*** AlexStaf has quit IRC | 17:56 | |
*** maciejjozefczyk has joined #openstack-lbaas | 18:26 | |
colin- | thanks for the summary on the ML, rm_work | 18:46 |
colin- | a whole ptg came and went without containers or active/active coming up?! | 18:47 |
rm_work | ah, so, uhh | 18:47 |
rm_work | active-active came up | 18:47 |
rm_work | and we were like | 18:47 |
rm_work | yeah ... do that, sounds good | 18:47 |
colin- | haha, great we have consensus! | 18:47 |
rm_work | so it didn't really warrant being in the summary lol | 18:47 |
*** ivve has joined #openstack-lbaas | 18:55 | |
*** pcaruana has quit IRC | 18:57 | |
*** pcaruana has joined #openstack-lbaas | 18:58 | |
*** maciejjozefczyk has quit IRC | 19:02 | |
*** gcheresh_ has joined #openstack-lbaas | 19:08 | |
*** ataraday_ has quit IRC | 19:10 | |
*** henriqueof has joined #openstack-lbaas | 19:35 | |
xgerman | Yeah, active-active is a mirage… I don;t think we will ever have it :-) | 19:50 |
*** yamamoto has joined #openstack-lbaas | 20:03 | |
*** yamamoto has quit IRC | 20:08 | |
rm_work | i'm supposed to be working on it this cycle <_< | 20:38 |
rm_work | we'll see if i ever actually get the time | 20:39 |
rm_work | other things keep being "higher priority" :D | 20:39 |
xgerman | Lol - yeah, I worked on that as well once and so did johnsom... | 20:40 |
xgerman | and IBM and... | 20:40 |
*** gcheresh_ has quit IRC | 20:42 | |
johnsom | Os-ken is ready now, so probably a good time to start it up again | 20:46 |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Fix multi-listener LB client auth/re-encryption https://review.opendev.org/693586 | 21:28 |
*** pcaruana has quit IRC | 21:42 | |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Fix a potential race condition with certs-ramfs https://review.opendev.org/693591 | 21:45 |
*** AlexStaf has joined #openstack-lbaas | 22:07 | |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Update flavor guide to be cut/paste friendly https://review.opendev.org/693751 | 22:07 |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Stop allowing the deletion of an in-use flavor https://review.opendev.org/692427 | 22:25 |
*** yamamoto has joined #openstack-lbaas | 22:31 | |
johnsom | rm_work Did we never get API filtering working???? | 22:51 |
johnsom | Hmm, ok, so maybe it's just some of the APIs that aren't working.... | 22:53 |
*** rcernin has joined #openstack-lbaas | 22:58 | |
*** tkajinam has joined #openstack-lbaas | 23:01 | |
*** TrevorV has quit IRC | 23:02 | |
*** ccamposr has quit IRC | 23:15 | |
*** ccamposr__ has joined #openstack-lbaas | 23:15 | |
*** goldyfruit has quit IRC | 23:22 | |
*** ivve has quit IRC | 23:32 | |
*** yamamoto has quit IRC | 23:33 | |
*** maciejjozefczyk has joined #openstack-lbaas | 23:38 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!