*** jaypipes has quit IRC | 00:18 | |
*** chlong has joined #openstack-operators | 00:26 | |
*** SimonChung has quit IRC | 00:28 | |
*** saneax has quit IRC | 00:46 | |
*** alop has quit IRC | 00:55 | |
*** gyee has quit IRC | 02:11 | |
*** hakimo has joined #openstack-operators | 02:52 | |
*** hakimo_ has quit IRC | 02:55 | |
*** bhunter71 has quit IRC | 03:08 | |
*** SimonChung has joined #openstack-operators | 03:14 | |
*** SimonChung1 has joined #openstack-operators | 03:15 | |
*** SimonChung has quit IRC | 03:18 | |
*** maishsk has joined #openstack-operators | 04:47 | |
*** maishsk has quit IRC | 04:53 | |
*** fawadkhaliq has joined #openstack-operators | 05:14 | |
*** fawadk has joined #openstack-operators | 05:15 | |
*** fawadkhaliq has quit IRC | 05:18 | |
*** saneax has joined #openstack-operators | 05:27 | |
*** ig0r_ has joined #openstack-operators | 05:46 | |
*** ig0r_ has quit IRC | 06:04 | |
*** maishsk has joined #openstack-operators | 06:09 | |
*** ig0r_ has joined #openstack-operators | 06:11 | |
*** belmoreira has joined #openstack-operators | 06:31 | |
*** Marga_ has joined #openstack-operators | 06:46 | |
*** Marga_ has quit IRC | 06:46 | |
*** Marga_ has joined #openstack-operators | 06:47 | |
*** fawadkhaliq has joined #openstack-operators | 07:12 | |
*** fawadk has quit IRC | 07:14 | |
*** fawadk has joined #openstack-operators | 07:15 | |
*** Marga_ has quit IRC | 07:17 | |
*** fawadkhaliq has quit IRC | 07:18 | |
*** fawadk has quit IRC | 07:45 | |
*** Marga_ has joined #openstack-operators | 07:46 | |
*** chlong has quit IRC | 07:47 | |
*** fawadkhaliq has joined #openstack-operators | 07:57 | |
*** fawadkhaliq has quit IRC | 08:06 | |
*** Marga_ has quit IRC | 08:25 | |
*** Marga_ has joined #openstack-operators | 08:26 | |
*** Marga_ has quit IRC | 08:32 | |
*** SimonChung1 has quit IRC | 08:35 | |
*** crinkle has quit IRC | 08:35 | |
*** Marga_ has joined #openstack-operators | 08:37 | |
*** SimonChung1 has joined #openstack-operators | 08:37 | |
*** crinkle has joined #openstack-operators | 08:37 | |
*** Marga_ has quit IRC | 08:42 | |
*** maishsk has quit IRC | 08:56 | |
*** maishsk has joined #openstack-operators | 08:59 | |
*** fawadkhaliq has joined #openstack-operators | 09:31 | |
*** saneax has quit IRC | 09:38 | |
*** maishsk has quit IRC | 10:01 | |
*** maishsk has joined #openstack-operators | 10:02 | |
*** saneax has joined #openstack-operators | 10:08 | |
*** Marga_ has joined #openstack-operators | 10:17 | |
*** Marga_ has quit IRC | 10:20 | |
*** Marga_ has joined #openstack-operators | 10:20 | |
*** Marga_ has quit IRC | 10:31 | |
*** fawadk has joined #openstack-operators | 10:35 | |
*** fawadkhaliq has quit IRC | 10:37 | |
*** fawadkhaliq has joined #openstack-operators | 10:38 | |
*** fawadk has quit IRC | 10:43 | |
*** ToMiles has quit IRC | 10:44 | |
*** radez is now known as radez_g0n3 | 11:01 | |
*** Marga_ has joined #openstack-operators | 11:25 | |
*** fawadkhaliq has quit IRC | 11:48 | |
*** Marga_ has quit IRC | 11:54 | |
*** jaypipes has joined #openstack-operators | 11:59 | |
*** Marga_ has joined #openstack-operators | 12:11 | |
*** fawadkhaliq has joined #openstack-operators | 12:23 | |
*** VW_ has joined #openstack-operators | 12:24 | |
*** chlong has joined #openstack-operators | 12:41 | |
*** VW_ has quit IRC | 12:52 | |
*** VW_ has joined #openstack-operators | 12:52 | |
*** zul has joined #openstack-operators | 12:53 | |
*** zul has quit IRC | 12:53 | |
*** zul has joined #openstack-operators | 12:53 | |
*** VW__ has joined #openstack-operators | 12:54 | |
*** VW_ has quit IRC | 12:54 | |
*** VW__ has quit IRC | 12:56 | |
*** VW_ has joined #openstack-operators | 12:56 | |
*** jaypipes has quit IRC | 12:57 | |
*** laron has joined #openstack-operators | 12:59 | |
*** jaypipes has joined #openstack-operators | 13:00 | |
*** VW_ has quit IRC | 13:00 | |
*** Marga_ has quit IRC | 13:08 | |
*** radez_g0n3 is now known as radez | 13:16 | |
*** ig0r_ has quit IRC | 13:27 | |
*** ig0r_ has joined #openstack-operators | 13:30 | |
*** chlong has quit IRC | 13:31 | |
*** VW_ has joined #openstack-operators | 13:31 | |
*** dminer has joined #openstack-operators | 13:35 | |
*** matrohon has joined #openstack-operators | 13:37 | |
*** kencjohnston has joined #openstack-operators | 13:41 | |
*** bhunter71 has joined #openstack-operators | 13:42 | |
*** laron has quit IRC | 13:42 | |
*** ferest has joined #openstack-operators | 13:45 | |
*** saneax has quit IRC | 13:47 | |
*** esker has joined #openstack-operators | 13:49 | |
*** Marga_ has joined #openstack-operators | 13:51 | |
*** kencjohnston has quit IRC | 13:53 | |
*** gfa is now known as gfa_ | 13:54 | |
*** gfa_ is now known as gfa | 13:54 | |
*** mdorman has joined #openstack-operators | 13:56 | |
*** ferest has quit IRC | 13:59 | |
*** ig0r_ has quit IRC | 14:00 | |
*** Marga_ has quit IRC | 14:01 | |
*** Marga_ has joined #openstack-operators | 14:02 | |
*** ferest has joined #openstack-operators | 14:18 | |
*** ferest has quit IRC | 14:21 | |
*** Marga_ has quit IRC | 14:21 | |
*** Piet has quit IRC | 14:26 | |
*** klindgren has joined #openstack-operators | 14:37 | |
*** emagana has joined #openstack-operators | 14:39 | |
*** emagana has quit IRC | 14:42 | |
*** emagana has joined #openstack-operators | 14:48 | |
*** Marga_ has joined #openstack-operators | 14:49 | |
*** Piet has joined #openstack-operators | 14:51 | |
*** bradjones has joined #openstack-operators | 14:54 | |
*** bradjones has quit IRC | 14:54 | |
*** bradjones has joined #openstack-operators | 14:54 | |
*** kencjohnston has joined #openstack-operators | 14:57 | |
*** maishsk has quit IRC | 14:59 | |
*** belmoreira has quit IRC | 15:01 | |
*** SimonChung1 has quit IRC | 15:15 | |
*** esker has quit IRC | 15:20 | |
*** Marga_ has quit IRC | 15:23 | |
*** Marga_ has joined #openstack-operators | 15:24 | |
*** emagana has quit IRC | 15:24 | |
*** gfa is now known as gfa_ | 15:24 | |
*** gfa_ is now known as gfa | 15:25 | |
*** cdelatte has joined #openstack-operators | 15:29 | |
*** alop has joined #openstack-operators | 15:48 | |
*** HenryG has quit IRC | 15:51 | |
*** esker has joined #openstack-operators | 15:55 | |
*** HenryG has joined #openstack-operators | 16:01 | |
*** gyee has joined #openstack-operators | 16:02 | |
*** esker has quit IRC | 16:04 | |
*** gyee has quit IRC | 16:06 | |
*** emagana has joined #openstack-operators | 16:07 | |
*** HenryG has quit IRC | 16:08 | |
*** SimonChung has joined #openstack-operators | 16:09 | |
*** HenryG has joined #openstack-operators | 16:18 | |
*** Marga_ has quit IRC | 16:23 | |
*** gyee has joined #openstack-operators | 16:33 | |
*** gfa is now known as gfa_ | 16:36 | |
*** matrohon has quit IRC | 16:38 | |
*** HenryG has quit IRC | 16:39 | |
*** kencjohnston has quit IRC | 16:51 | |
*** fawadkhaliq has quit IRC | 16:52 | |
*** gfa_ is now known as gfa | 16:52 | |
*** maishsk has joined #openstack-operators | 16:58 | |
*** kencjohnston has joined #openstack-operators | 17:00 | |
*** HenryG has joined #openstack-operators | 17:10 | |
*** maishsk has quit IRC | 17:16 | |
*** HenryG has quit IRC | 17:20 | |
*** VW_ has quit IRC | 17:25 | |
*** VW_ has joined #openstack-operators | 17:26 | |
*** VW_ has quit IRC | 17:31 | |
*** VW_ has joined #openstack-operators | 17:32 | |
*** david-lyle has quit IRC | 17:48 | |
*** radez is now known as radez_g0n3 | 18:01 | |
*** VW_ has quit IRC | 18:04 | |
*** VW_ has joined #openstack-operators | 18:05 | |
*** VW_ has quit IRC | 18:09 | |
*** VW_ has joined #openstack-operators | 18:12 | |
mgagne | klindgren: ping | 18:14 |
---|---|---|
klindgren | mgagne, pong | 18:15 |
mgagne | klindgren: mdorman told me you could explain me how to setup floating IPs with provider networks. would you mind sharing? | 18:16 |
klindgren | mgagne, short answer crazyness | 18:18 |
mgagne | klindgren: we do have private provider networks (no SDN coolaid so far, pure VLANs) and wishes to know how to setup floating IPs with eventually a driver of my own. Do I need to create routers and such? | 18:18 |
mgagne | klindgren: I'm used to crazyness =) | 18:18 |
klindgren | So we create a router in the API, but do not run an agent | 18:19 |
klindgren | and the reason is that unless you change the gateway of the vm's to be the router handling the floating_ip's you end up with unusable traffic | 18:19 |
mgagne | klindgren: so Neutron is satisfied | 18:19 |
klindgren | mgagne, yea | 18:19 |
mgagne | klindgren: do you need to create an ext network? | 18:20 |
klindgren | so that way you can associate floating ip's to a port | 18:20 |
mgagne | klindgren: and pump IPs into it right? | 18:20 |
klindgren | yea - we create a floating ip network | 18:20 |
klindgren | and assign ext-true | 18:20 |
klindgren | don't make it shared otherwise peopel can provision vm's on it | 18:20 |
mgagne | klindgren: oh, so it's not that crazy. you following the network guide but just don't start an L3 agent | 18:21 |
klindgren | then we add the ip's we want to use to it for as subnets, and we do as many subnets as we want | 18:21 |
mgagne | klindgren: is custom code used to provision the routes? | 18:21 |
klindgren | so.... crazyness comes | 18:21 |
klindgren | because we do route injection into the network | 18:21 |
mgagne | klindgren: I often use that one here: "go on..." | 18:22 |
klindgren | to route the ip to the vm, then we modify the allowed_address_pair stuff to alolow the floating_ip into/out of the vm | 18:22 |
mgagne | klindgren: that's not done by neutron alright? | 18:22 |
mgagne | already* | 18:22 |
klindgren | correct - thats an additional step | 18:23 |
mgagne | sad panda now | 18:23 |
klindgren | soooooo - that becuase of our specific network setup | 18:23 |
mgagne | and the routes are setup on a "real" router somewhere? | 18:23 |
klindgren | I think their is a way to do it without huge changes | 18:24 |
mgagne | klindgren: we are all snowflakes =) | 18:24 |
klindgren | we are adding them to the TOR switches | 18:24 |
mgagne | klindgren: any hooks in neutron or you happen to have a custom API/portal taking care of this orchestration? | 18:24 |
klindgren | but yea essentially add routes to a router to make the nexthop of the floating ip the fixed_ip of them | 18:24 |
klindgren | the vm* | 18:24 |
mgagne | klindgren: we are looking for a similar setup tbh | 18:25 |
klindgren | we implemented it all in neutron | 18:25 |
klindgren | >_> | 18:25 |
klindgren | <_< | 18:25 |
mgagne | klindgren: that's fine with me ;) | 18:25 |
klindgren | I think we even have patches out there | 18:25 |
klindgren | let me see if I can dig this stuff up | 18:25 |
mgagne | klindgren: why not leveraging l3 agent with custom driver to proxy the calls to your TOR? too complex? | 18:25 |
klindgren | the L# agent stuff bascially gets called to do a full sync | 18:26 |
klindgren | querry the DB and apply everything | 18:26 |
klindgren | so it doesn't jsut add/remove an IP it rebuilds the whole config | 18:26 |
mgagne | klindgren: I don't know why I thought you would answer something else :P | 18:26 |
klindgren | so we made our own L3 extension that implements the base L3 extenstions | 18:27 |
mgagne | klindgren: yea, that's what I kind of expected. I thought you would have come up with a super magic thing to avoid this router/ext-net mess I don't care bout | 18:27 |
klindgren | and then either on create - after the base class does it thing - we call our static route client to add the route to the network | 18:28 |
klindgren | and on delete, before the base class does its thing, we call our client to remove the route | 18:28 |
klindgren | mgagne, nope - its builds the db relationships | 18:28 |
klindgren | but what I was talking about to carl was back when this frontnet-backnet thing was hpaening | 18:29 |
klindgren | was associating a front net ot the router | 18:29 |
klindgren | so we didn't have to add each "backnet" to the routers | 18:29 |
mgagne | oh... | 18:29 |
mgagne | yea, that's the bad part for me | 18:29 |
mgagne | I do not fully control the network provisioning part | 18:30 |
mgagne | so I'll have to explain to an other team this router concept and what they need to do | 18:30 |
klindgren | are customers creating the networks? | 18:30 |
mgagne | klindgren: they are not | 18:30 |
klindgren | kk | 18:30 |
mgagne | klindgren: we provision them for them (for now) | 18:30 |
klindgren | front the end user XP - this stuff all works api wise exactly the same as neutron does today | 18:31 |
mgagne | yea | 18:31 |
klindgren | we also have some custom patches to allow assigning more than one floating_ip to fixed_ip | 18:31 |
mgagne | klindgren: but we only care about WAN networks in that case and we might never let them create WAN networks by themselves anyway | 18:31 |
klindgren | which is really removal of some code | 18:31 |
mgagne | klindgren: oh, you can't assign more than one? | 18:31 |
mgagne | klindgren: dying panda now | 18:31 |
klindgren | not by default | 18:31 |
klindgren | (removal of 7 lines of code) | 18:32 |
klindgren | and also worked on how to get differnt types of floating ip's onto the same router | 18:32 |
klindgren | IE a router in neutron can only be attached to one upstream "network" | 18:33 |
klindgren | so if you had say - public_floating_ips and private_floating_ip | 18:33 |
mgagne | hmm why would you mix public and private IPs? | 18:34 |
klindgren | you can't attach both of those networks to the same router | 18:34 |
klindgren | interally in specific security zones all vm's have are rfc1918 ip's | 18:34 |
klindgren | including floating ip's that can be moved from vm to vm | 18:34 |
klindgren | reasons are: LB's are configured by another team and are manual - so assigning a floating-private ip allows people to not let that team slow htem down | 18:35 |
klindgren | from replacing vm's | 18:35 |
klindgren | also - some endpoints people want to talk to are locked down to only allow specific ip's | 18:36 |
klindgren | and those have to have all sorts of specificrequests and other crap | 18:36 |
klindgren | IE talking into pci or pki environments | 18:36 |
mgagne | ok it's mostly for business specific reasons | 18:36 |
klindgren | so having a private floating_ip that can move between vm's allows new vm's to take place of old ones without to go through that request process all over | 18:37 |
klindgren | well and end-users asks | 18:37 |
klindgren | :-) | 18:37 |
mgagne | =) | 18:37 |
*** radez_g0n3 is now known as radez | 18:37 | |
klindgren | anyway - I thik without code changes - if you wanted to do floating_ips with poriver networks you could | 18:38 |
mgagne | I really appreciate sharing your info with me. it more or less confirmed what I expected ;) | 18:38 |
klindgren | run an l3 agent | 18:38 |
klindgren | do all the standard stuff | 18:38 |
klindgren | but change the gateway of the vm to use the router - vs's the real network | 18:38 |
mgagne | klindgren: yea, I was wondering if I had to model a router or not. and it looks like neutron expects a router to exist to allow use of floating ips | 18:38 |
klindgren | when a floating ip was assigned | 18:38 |
klindgren | mgagne, yea - I didn't even want to take a look at what it would take to remove that asumption | 18:39 |
klindgren | I assume it would also be totally possible to gut the existing l3 extension and just do that stuff yo ucare about | 18:39 |
klindgren | you care* | 18:39 |
mgagne | klindgren: I read (in diagonal) the thread about representing L2 segments and everything is tightly coupled so not much hope in that aspect | 18:40 |
klindgren | then its time for quark (not rackspaces quark) to replace neutron | 18:41 |
mgagne | hehe | 18:41 |
klindgren | honestly something is going to have to change | 18:42 |
klindgren | tunneling all the things to provide a huge L2 domain - is jsut not how large companys build scaleable networks | 18:42 |
klindgren | we all build networks where we clumb multiple constrained L2 segments together into a larger L3 network | 18:43 |
mgagne | yep | 18:43 |
mgagne | yes, I'm tired of people pushing SDN or policy-based networking whenever they can like it's the holy grail and like we are just not enlightened yet. I still haven't heard an answer to a guy asking: "What about my legacy networks and existing hardware? How do I hook it up to OpenStack" in a Neutron feedback session in Atlanta IIRC. | 18:45 |
*** HenryG_ has joined #openstack-operators | 18:46 | |
mgagne | sometimes I feel like we just don't speak the same language or some just don't grasp the reality (of production/scale) in which some operators/providers are | 18:47 |
*** SimonChung1 has joined #openstack-operators | 18:47 | |
*** SimonChung has quit IRC | 18:47 | |
*** SimonChung1 has quit IRC | 18:47 | |
*** SimonChung has joined #openstack-operators | 18:47 | |
mgagne | btw, someone just mentioned the akanda project to me. anyone with feedback on it? there is a lot of interesting keywords in the project description but don't know if I should trust them. :P | 18:48 |
mgagne | https://github.com/stackforge/akanda | 18:48 |
klindgren | I kinda have the same feeling RE: big tent projects | 19:01 |
*** esker has joined #openstack-operators | 19:02 | |
klindgren | seems like their is a project for just about everything - but not enough time to see whats actually viable | 19:02 |
klindgren | and by viable I mean - someone actually run it, at scale. Where scale is something more than say 10-20 compute nodes | 19:03 |
klindgren | :-) | 19:03 |
*** SimonChung1 has joined #openstack-operators | 19:03 | |
*** SimonChung has quit IRC | 19:03 | |
logan2 | i think akanda is a dreamhost spinoff | 19:06 |
*** Piet has quit IRC | 19:07 | |
klindgren | has anyone seen issues re: urllib3 and connection pool and EPIPE errors? | 19:16 |
klindgren | out of the blue starting to get a number of them - seems like its a bug in urllib3 1.10.0 fixed in 1.11.0 | 19:17 |
*** Marga_ has joined #openstack-operators | 19:21 | |
*** Marga_ has quit IRC | 19:24 | |
*** Marga_ has joined #openstack-operators | 19:25 | |
klindgren | specifically: 2015-08-04 12:15:00.432 32371 TRACE neutron.notifiers.nova File "/usr/lib/python2.7/site-packages/OpenSSL/SSL.py", line 1178, in _raise_ssl_error | 19:25 |
klindgren | 2015-08-04 12:15:00.432 32371 TRACE neutron.notifiers.nova raise SysCallError(errno, errorcode.get(errno)) | 19:25 |
klindgren | 2015-08-04 12:15:00.432 32371 TRACE neutron.notifiers.nova SysCallError: (32, 'EPIPE') | 19:25 |
klindgren | full error: http://paste.ubuntu.com/12002236/ | 19:26 |
klindgren | but seeing it in a number of spots | 19:26 |
*** gyee has quit IRC | 19:29 | |
*** godp1301 has joined #openstack-operators | 19:34 | |
*** dminer has quit IRC | 19:38 | |
*** britthouser has joined #openstack-operators | 19:39 | |
*** britthou_ has joined #openstack-operators | 19:40 | |
*** britthouser has quit IRC | 19:43 | |
*** samueldmq has joined #openstack-operators | 19:48 | |
*** bhunter71 has quit IRC | 19:56 | |
*** VW__ has joined #openstack-operators | 20:01 | |
*** VW__ has quit IRC | 20:03 | |
*** VW__ has joined #openstack-operators | 20:04 | |
*** VW_ has quit IRC | 20:05 | |
*** VW__ has quit IRC | 20:06 | |
*** VW_ has joined #openstack-operators | 20:07 | |
*** esker has quit IRC | 20:09 | |
*** Piet has joined #openstack-operators | 20:10 | |
*** esker has joined #openstack-operators | 20:11 | |
*** esker has quit IRC | 20:11 | |
*** esker has joined #openstack-operators | 20:11 | |
*** Marga_ has quit IRC | 20:21 | |
*** emagana has quit IRC | 20:45 | |
*** emagana has joined #openstack-operators | 20:48 | |
*** godp1301 has quit IRC | 20:52 | |
*** jmckind has joined #openstack-operators | 20:56 | |
*** Marga_ has joined #openstack-operators | 21:01 | |
*** esker has quit IRC | 21:01 | |
*** HenryG_ is now known as HenryG | 21:17 | |
*** dmsimard has quit IRC | 21:21 | |
*** Marga_ has quit IRC | 21:21 | |
*** Marga_ has joined #openstack-operators | 21:22 | |
*** kencjohnston has quit IRC | 21:23 | |
*** jmckind has quit IRC | 21:24 | |
*** jmckind has joined #openstack-operators | 21:26 | |
*** VW_ has quit IRC | 21:31 | |
*** VW_ has joined #openstack-operators | 21:32 | |
*** VW_ has quit IRC | 21:37 | |
*** dmsimard has joined #openstack-operators | 21:40 | |
*** jmckind has quit IRC | 22:02 | |
*** chlong has joined #openstack-operators | 22:07 | |
*** VW_ has joined #openstack-operators | 22:16 | |
*** zul has quit IRC | 22:23 | |
*** jaypipes has quit IRC | 22:35 | |
*** VW_ has quit IRC | 22:39 | |
*** VW_ has joined #openstack-operators | 22:39 | |
*** VW_ has quit IRC | 22:44 | |
*** j05hk has quit IRC | 22:58 | |
*** Marga_ has quit IRC | 23:01 | |
*** jmckind has joined #openstack-operators | 23:22 | |
*** jmckind has quit IRC | 23:23 | |
*** jmckind has joined #openstack-operators | 23:24 | |
*** cdelatte has quit IRC | 23:28 | |
*** kencjohnston has joined #openstack-operators | 23:46 | |
*** cdelatte has joined #openstack-operators | 23:51 | |
*** delattec has joined #openstack-operators | 23:51 | |
*** emagana has quit IRC | 23:56 | |
*** kencjohnston has quit IRC | 23:58 | |
*** kencjohnston has joined #openstack-operators | 23:58 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!