*** PerfectChaos has quit IRC | 00:07 | |
*** PerfectChaos has joined #openstack-operators | 00:07 | |
*** PerfectChaos has quit IRC | 00:16 | |
*** PerfectChaos has joined #openstack-operators | 00:17 | |
*** PerfectChaos has quit IRC | 00:29 | |
*** PerfectChaos has joined #openstack-operators | 00:30 | |
*** markvoelker has joined #openstack-operators | 00:39 | |
*** markvoelker has quit IRC | 00:43 | |
*** PerfectChaos has quit IRC | 01:03 | |
*** PerfectChaos has joined #openstack-operators | 01:04 | |
*** ducttape_ has joined #openstack-operators | 01:30 | |
*** ducttape_ has quit IRC | 01:34 | |
*** julim has quit IRC | 02:09 | |
*** PerfectChaos has quit IRC | 02:24 | |
*** PerfectChaos has joined #openstack-operators | 02:26 | |
*** julim has joined #openstack-operators | 02:44 | |
*** ducttape_ has joined #openstack-operators | 03:07 | |
*** julim has quit IRC | 03:11 | |
*** david-lyle has quit IRC | 03:11 | |
*** ducttape_ has quit IRC | 03:30 | |
*** elo has joined #openstack-operators | 03:39 | |
*** eric_lopez has quit IRC | 03:40 | |
*** PerfectChaos has quit IRC | 04:01 | |
*** PerfectChaos has joined #openstack-operators | 04:01 | |
*** markvoelker has joined #openstack-operators | 04:40 | |
*** hieulq has joined #openstack-operators | 04:43 | |
*** markvoelker has quit IRC | 04:45 | |
*** ducttape_ has joined #openstack-operators | 05:01 | |
*** dtrainor has joined #openstack-operators | 05:04 | |
*** ducttape_ has quit IRC | 05:06 | |
*** PerfectChaos has quit IRC | 05:26 | |
*** PerfectChaos has joined #openstack-operators | 05:26 | |
*** rcernin has joined #openstack-operators | 05:57 | |
*** david-lyle has joined #openstack-operators | 06:02 | |
*** ducttape_ has joined #openstack-operators | 06:02 | |
*** intr1nsic has quit IRC | 06:02 | |
*** PerfectChaos has quit IRC | 06:03 | |
*** intr1nsic has joined #openstack-operators | 06:04 | |
*** rcernin has quit IRC | 06:04 | |
*** PerfectChaos has joined #openstack-operators | 06:04 | |
*** ducttape_ has quit IRC | 06:06 | |
*** rcernin has joined #openstack-operators | 06:17 | |
*** intr1nsic has quit IRC | 06:19 | |
*** intr1nsic has joined #openstack-operators | 06:21 | |
*** saneax_AFK is now known as saneax | 06:27 | |
*** pcaruana has joined #openstack-operators | 06:29 | |
*** arcimboldo has joined #openstack-operators | 06:31 | |
*** eddima has joined #openstack-operators | 06:31 | |
*** bjolo_ has quit IRC | 06:31 | |
*** david-lyle has quit IRC | 06:32 | |
*** markvoelker has joined #openstack-operators | 06:41 | |
*** tesseract- has joined #openstack-operators | 06:45 | |
*** markvoelker has quit IRC | 06:46 | |
*** rcernin has quit IRC | 06:48 | |
*** pcaruana has quit IRC | 06:48 | |
*** belmoreira has joined #openstack-operators | 06:55 | |
*** pcaruana has joined #openstack-operators | 07:02 | |
*** rcernin has joined #openstack-operators | 07:02 | |
*** ducttape_ has joined #openstack-operators | 07:03 | |
*** liverpooler has joined #openstack-operators | 07:07 | |
*** ducttape_ has quit IRC | 07:07 | |
*** fawadkhaliq has joined #openstack-operators | 07:13 | |
*** paramite has joined #openstack-operators | 07:15 | |
*** christx2 has joined #openstack-operators | 07:26 | |
*** PerfectChaos has quit IRC | 07:26 | |
*** PerfectChaos has joined #openstack-operators | 07:27 | |
*** beddari has joined #openstack-operators | 07:28 | |
*** dtrainor has quit IRC | 07:31 | |
*** bjolo has joined #openstack-operators | 07:31 | |
*** bjolo has quit IRC | 07:41 | |
*** bjolo has joined #openstack-operators | 07:41 | |
*** pilgrimstack has joined #openstack-operators | 08:00 | |
*** bjolo_ has joined #openstack-operators | 08:02 | |
*** bjolo has quit IRC | 08:05 | |
*** dmsimard has quit IRC | 08:05 | |
*** dbecker has joined #openstack-operators | 08:06 | |
*** bjolo_ has quit IRC | 08:06 | |
*** bjolo_ has joined #openstack-operators | 08:06 | |
*** dbecker has quit IRC | 08:07 | |
*** dbecker has joined #openstack-operators | 08:08 | |
*** bjolo_ is now known as bjolo | 08:09 | |
*** PerfectChaos has quit IRC | 08:15 | |
*** PerfectChaos has joined #openstack-operators | 08:17 | |
*** beddari has quit IRC | 08:31 | |
*** beddari has joined #openstack-operators | 08:34 | |
*** bjolo has quit IRC | 08:53 | |
*** bjolo has joined #openstack-operators | 08:53 | |
*** dmsimard has joined #openstack-operators | 08:54 | |
*** simon-AS559 has joined #openstack-operators | 09:17 | |
*** simon-AS5591 has joined #openstack-operators | 09:20 | |
*** simon-AS559 has quit IRC | 09:23 | |
*** admin0 has joined #openstack-operators | 09:26 | |
*** eddima has quit IRC | 09:33 | |
*** fawadkhaliq has quit IRC | 09:34 | |
*** christx2 has quit IRC | 09:35 | |
*** admin0 has quit IRC | 09:47 | |
*** simon-AS5591 has quit IRC | 09:58 | |
*** bjolo_ has joined #openstack-operators | 10:00 | |
*** bjolo has quit IRC | 10:01 | |
*** admin0 has joined #openstack-operators | 10:02 | |
*** bjolo_ has quit IRC | 10:02 | |
*** bjolo_ has joined #openstack-operators | 10:03 | |
*** PerfectChaos has quit IRC | 10:03 | |
*** PerfectChaos has joined #openstack-operators | 10:04 | |
*** bjolo_ is now known as bjolo | 10:12 | |
*** arcimboldo has quit IRC | 10:24 | |
*** PerfectChaos has quit IRC | 10:29 | |
*** PerfectChaos has joined #openstack-operators | 10:31 | |
*** fawadkhaliq has joined #openstack-operators | 10:34 | |
*** fawadkhaliq has quit IRC | 10:40 | |
*** paramite is now known as paramite|afk | 10:41 | |
*** fawadkhaliq has joined #openstack-operators | 10:48 | |
*** arcimboldo has joined #openstack-operators | 10:58 | |
*** PerfectChaos has quit IRC | 11:08 | |
*** PerfectChaos has joined #openstack-operators | 11:09 | |
*** zeih has joined #openstack-operators | 11:10 | |
*** paramite|afk is now known as paramite | 11:10 | |
*** zeih has quit IRC | 11:11 | |
*** julim has joined #openstack-operators | 11:15 | |
*** admin0 has quit IRC | 11:26 | |
*** christx2 has joined #openstack-operators | 11:59 | |
*** PerfectChaos has quit IRC | 12:03 | |
*** PerfectChaos has joined #openstack-operators | 12:04 | |
*** ducttape_ has joined #openstack-operators | 12:06 | |
*** markvoelker has joined #openstack-operators | 12:10 | |
*** fawadkhaliq has quit IRC | 12:10 | |
*** permalac has joined #openstack-operators | 12:11 | |
*** admin0 has joined #openstack-operators | 12:17 | |
*** ducttape_ has quit IRC | 12:26 | |
*** derekjhyang has quit IRC | 12:32 | |
*** toMeloos has joined #openstack-operators | 12:33 | |
*** PerfectChaos has quit IRC | 12:43 | |
*** PerfectChaos has joined #openstack-operators | 12:44 | |
*** Zucan has joined #openstack-operators | 12:44 | |
*** PerfectChaos has quit IRC | 12:52 | |
*** PerfectChaos has joined #openstack-operators | 12:53 | |
*** admin0 has quit IRC | 12:57 | |
*** dminer has joined #openstack-operators | 12:59 | |
*** admin0 has joined #openstack-operators | 13:03 | |
*** dmsimard has quit IRC | 13:16 | |
*** dmsimard has joined #openstack-operators | 13:18 | |
*** julim has quit IRC | 13:19 | |
*** belmoreira has quit IRC | 13:33 | |
*** saneax is now known as saneax_AFK | 13:39 | |
*** ducttape_ has joined #openstack-operators | 13:42 | |
*** julim has joined #openstack-operators | 13:43 | |
*** ducttape_ has quit IRC | 13:45 | |
*** ducttape_ has joined #openstack-operators | 13:46 | |
*** ducttape_ has quit IRC | 13:46 | |
*** ducttape_ has joined #openstack-operators | 13:46 | |
*** saneax_AFK is now known as saneax | 13:46 | |
*** ducttape_ has quit IRC | 13:48 | |
*** jamesdenton has joined #openstack-operators | 13:50 | |
*** simon-AS559 has joined #openstack-operators | 13:58 | |
*** PerfectChaos has quit IRC | 13:58 | |
*** catintheroof has joined #openstack-operators | 14:03 | |
*** simon-AS5591 has joined #openstack-operators | 14:08 | |
*** simon-AS5591 has quit IRC | 14:09 | |
*** simon-AS559 has quit IRC | 14:10 | |
*** ducttape_ has joined #openstack-operators | 14:12 | |
*** saneax is now known as saneax_AFK | 14:15 | |
*** liverpooler has quit IRC | 14:15 | |
*** bjolo has quit IRC | 14:49 | |
catintheroof | quick question, do you know the technical reason on why the mysql connection string went from mysql to mysql+pymysql ? | 14:51 |
---|---|---|
dims_ | catintheroof http://markmail.org/message/6ujd3xcrk4ns256c | 14:56 |
dims_ | catintheroof : there's more in the mailing list http://openstack.markmail.org/search/?q=pymysql | 14:56 |
catintheroof | dims_, thanks so much ! nice info ! | 14:57 |
*** dtrainor has joined #openstack-operators | 14:58 | |
*** _ducttape_ has joined #openstack-operators | 15:01 | |
catintheroof | dims_, there i can search for all openstack mailing list's emails ?? | 15:01 |
dims_ | openstack-dev mailing list for sure | 15:02 |
*** ducttape_ has quit IRC | 15:02 | |
*** julim has quit IRC | 15:10 | |
*** armax has joined #openstack-operators | 15:10 | |
*** mriedem has quit IRC | 15:16 | |
*** Apoorva has joined #openstack-operators | 15:21 | |
*** julim has joined #openstack-operators | 15:36 | |
*** admin0 has quit IRC | 15:42 | |
*** _ducttape_ has quit IRC | 15:46 | |
*** ducttape_ has joined #openstack-operators | 15:46 | |
*** fawadkhaliq has joined #openstack-operators | 15:49 | |
*** fawadkhaliq has quit IRC | 15:53 | |
*** julim has quit IRC | 16:04 | |
*** emccormick has joined #openstack-operators | 16:05 | |
*** tesseract- has quit IRC | 16:10 | |
*** christx2 has quit IRC | 16:16 | |
*** fawadkhaliq has joined #openstack-operators | 16:20 | |
*** fawadkhaliq has quit IRC | 16:24 | |
*** julim has joined #openstack-operators | 16:28 | |
*** gyee has joined #openstack-operators | 16:29 | |
*** flaviodsr has joined #openstack-operators | 16:30 | |
*** piet has joined #openstack-operators | 16:35 | |
*** arcimboldo has quit IRC | 16:42 | |
*** kstev has joined #openstack-operators | 16:45 | |
*** rcernin has quit IRC | 16:53 | |
*** simon-AS559 has joined #openstack-operators | 16:58 | |
*** pcaruana has quit IRC | 16:59 | |
*** simon-AS5591 has joined #openstack-operators | 17:03 | |
*** peterjenkins has quit IRC | 17:04 | |
*** melwitt has quit IRC | 17:05 | |
*** peterjenkins has joined #openstack-operators | 17:05 | |
*** nikhil has quit IRC | 17:05 | |
*** amit213 has quit IRC | 17:05 | |
*** brainspackle has quit IRC | 17:05 | |
*** khappone has joined #openstack-operators | 17:05 | |
*** simon-AS559 has quit IRC | 17:05 | |
*** zigo has quit IRC | 17:06 | |
*** mjrichardson has quit IRC | 17:06 | |
*** RaginBajin has quit IRC | 17:06 | |
*** mgagne has quit IRC | 17:06 | |
*** kencjohnston has quit IRC | 17:06 | |
*** khappone_ has quit IRC | 17:06 | |
*** zigo has joined #openstack-operators | 17:06 | |
*** simon-AS5591 has quit IRC | 17:09 | |
*** amit213 has joined #openstack-operators | 17:09 | |
*** kencjohnston has joined #openstack-operators | 17:11 | |
*** mgagne has joined #openstack-operators | 17:11 | |
*** RaginBajin has joined #openstack-operators | 17:13 | |
*** melwitt has joined #openstack-operators | 17:14 | |
*** melwitt is now known as Guest35446 | 17:15 | |
*** nikhil has joined #openstack-operators | 17:19 | |
*** brainspackle has joined #openstack-operators | 17:19 | |
*** MVenesio has joined #openstack-operators | 17:20 | |
MVenesio | Hi guys, do you know if the functionality to bypass the images copy from a glance integrated with ceph and cinder also integrated with ceph works in the Juno version ? | 17:20 |
*** mjrichardson has joined #openstack-operators | 17:20 | |
*** rcernin has joined #openstack-operators | 17:37 | |
*** christx2 has joined #openstack-operators | 17:38 | |
*** ducttape_ has quit IRC | 17:39 | |
*** ducttape_ has joined #openstack-operators | 17:51 | |
*** julim_ has joined #openstack-operators | 18:02 | |
*** julim has quit IRC | 18:05 | |
*** bjolo has joined #openstack-operators | 18:10 | |
*** bjolo has quit IRC | 18:14 | |
*** bjolo has joined #openstack-operators | 18:14 | |
*** christx2 has quit IRC | 18:15 | |
*** julim_ has quit IRC | 18:15 | |
*** alaski has quit IRC | 18:17 | |
klindgren | I thought people had local patches for that | 18:19 |
klindgren | but unsure if anyone had that for the juno version | 18:19 |
*** permalac has quit IRC | 18:20 | |
*** alaski has joined #openstack-operators | 18:22 | |
*** bjolo has quit IRC | 18:30 | |
*** pcaruana has joined #openstack-operators | 18:34 | |
*** mjrichardson has quit IRC | 18:45 | |
*** mjrichardson has joined #openstack-operators | 18:46 | |
*** xavpaice has quit IRC | 18:47 | |
*** gyee has quit IRC | 18:48 | |
*** mriedem has joined #openstack-operators | 18:49 | |
*** xavpaice has joined #openstack-operators | 18:51 | |
*** rcernin has quit IRC | 18:57 | |
*** fawadkhaliq has joined #openstack-operators | 19:05 | |
*** rcernin has joined #openstack-operators | 19:15 | |
*** rcernin has quit IRC | 19:16 | |
*** rcernin has joined #openstack-operators | 19:16 | |
*** emccormick has quit IRC | 19:28 | |
*** MVenesio has quit IRC | 19:29 | |
*** gyee has joined #openstack-operators | 19:34 | |
*** simon-AS559 has joined #openstack-operators | 19:42 | |
*** kstev has quit IRC | 19:49 | |
*** fawadkhaliq has quit IRC | 19:52 | |
*** fawadkhaliq has joined #openstack-operators | 19:53 | |
*** fawadkhaliq has quit IRC | 19:57 | |
*** emccormick has joined #openstack-operators | 19:57 | |
*** kstev has joined #openstack-operators | 19:58 | |
*** nicodemus_ has joined #openstack-operators | 20:03 | |
nicodemus_ | hello | 20:03 |
nicodemus_ | Does anybody know a guide to configure neutron-api behind apache? (if it is possible) | 20:03 |
nicodemus_ | I'd like to deploy using SSL, and there seem to be two options for production: SSL termination on nginx/haproxy, or having the neutron API with apache | 20:03 |
jlk | Neutron API should support SSL | 20:06 |
jlk | like, terminated on Neutron, but yeah it's not the best in production | 20:06 |
*** vinsh_ is now known as Vinsh | 20:09 | |
nicodemus_ | jlk, yes the API supports it... but since most other projects recommend against it | 20:13 |
nicodemus_ | perhaps someone had the chance to test Neutron + apache | 20:14 |
xavpaice | you talking about using mod_wsgi, or just a proxy? | 20:20 |
xavpaice | we're an nginx/uwsgi shop mostly, but fwiw swift wasn't running well like that so we termiate the ssl on nginx and proxy to swift listening on localhost | 20:21 |
xavpaice | plenty of ways to cut it :) | 20:21 |
nicodemus_ | xavpaice, I was thinking about mod_wsgi | 20:29 |
nicodemus_ | but, I guess I would go with the recommended / more stable way | 20:30 |
xavpaice | can't comment on what that is :) | 20:30 |
*** rcernin has quit IRC | 20:38 | |
*** simon-AS559 has quit IRC | 20:55 | |
*** piet has quit IRC | 21:00 | |
*** Zucan has quit IRC | 21:11 | |
*** mriedem has quit IRC | 21:25 | |
*** krot_vaca_jul19 is now known as krotscheck | 21:30 | |
*** paramite has quit IRC | 21:30 | |
*** catintheroof has quit IRC | 21:30 | |
*** toMeloos has quit IRC | 21:36 | |
*** jamesdenton has quit IRC | 21:44 | |
*** emccormick has quit IRC | 21:44 | |
*** rcernin has joined #openstack-operators | 21:49 | |
*** rcernin has quit IRC | 21:49 | |
*** nicodemus_ has quit IRC | 21:58 | |
*** amit213 has quit IRC | 22:13 | |
*** amit213 has joined #openstack-operators | 22:13 | |
klindgren | anyone with public use the QEMU guest agent? | 22:16 |
klindgren | to make snapshots something better than crash consistent | 22:16 |
klindgren | hell - I will even open it up more. Anyone here use openstack + qemu guest agent + the stuff tht was done in kilo for using the guest agent for snapshots | 22:17 |
klindgren | https://blueprints.launchpad.net/nova/+spec/quiesced-image-snapshots-with-qemu-guest-agent | 22:17 |
*** ducttape_ has quit IRC | 22:20 | |
klindgren | jlk xavpaice sorrison clayton ping on the above re: qemu-agent | 22:32 |
jlk | We do not use the agent | 22:33 |
clayton | NickServ: neutron doesn't support an external wsgi server in mitaka, I think some of the work for that is scheduled for newton | 22:51 |
clayton | klindgren: we don't, it seems like a good idea though | 22:51 |
xavpaice | klindgren: I think we've informally suggested to clients that they can use it, but afaik noone has | 22:52 |
klindgren | xavprince did you do any looking at the warning re: should only be used with trusted hosts? | 22:53 |
xavpaice | clayton: is there a list of which services do support an external wsgi? | 22:54 |
klindgren | xavpaice, even | 22:54 |
xavpaice | I quite like that typo, might use it | 22:54 |
clayton | not that I know of, I just remeber this being discussed in austin in one of the sessions | 22:54 |
clayton | the issue is that right now neutron server hosts both the wsgi stuff for the api, but also a bunch of stuff that with other services would be more of like a neutron-engine service | 22:55 |
clayton | and those things have to be split apart | 22:55 |
xavpaice | cool - I'm keen to move more services to external wsgi, but not all work particularly well so the benefits are lost | 22:55 |
xavpaice | klindgren: warning? Nah, this is NZ, "no worries, mate!" | 22:55 |
klindgren | MPORTANT | 23:00 |
klindgren | Note that it is only safe to rely on the QEMU guest agent when run by trusted guests. An untrusted guest may maliciously ignore or abuse the guest agent protocol, and although built-in safeguards exist to prevent a denial of service attack on the host, the host requires guest co-operation for operations to run as expected. | 23:00 |
xavpaice | ooh - got a link for that warning? | 23:01 |
xavpaice | would be good to share with the team | 23:01 |
klindgren | https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Virtualization_Deployment_and_Administration_Guide/chap-QEMU_Guest_Agent.html#idp9487712 | 23:01 |
xavpaice | thanks | 23:02 |
klindgren | http://wiki.libvirt.org/page/Qemu_guest_agent | 23:03 |
klindgren | However, guest agent (GA) is not bullet proof, and hostile guest OS can send spurious replies. | 23:03 |
*** saneax_AFK is now known as saneax | 23:03 | |
* xavpaice hopes those 'built-in safeguards' are enough | 23:04 | |
*** pcaruana has quit IRC | 23:05 | |
klindgren | http://wiki.qemu.org/Features/QAPI/GuestAgent | 23:05 |
klindgren | Security Considerations | 23:05 |
klindgren | The following security issues need to be resolved in QMP: | 23:05 |
klindgren | The JSON parser uses a recursive decent parser. Malicious input could potentially cause a stack overflow. Either implement a recursion depth counter, or switch the parser to only use tail recursion. | 23:05 |
klindgren | The JSON parser may not handle premature EOI all that well. I think I've worked out most of these issues but more rigorous testing is needed. | 23:05 |
klindgren | unsure if that documentation is actually updated or not - possible that things have been fixed and like all docs - its out of date | 23:06 |
sticker | that warning there is what concerns me about allowing our customers to upload their own images. I haven't investigated it fully but I think they can enable that socket by setting hw_qemu_agent=yes in the metadata for an image. would be good to be able to globally disable it :/ | 23:07 |
xavpaice | that page is from 2013, not sure if things have changed since | 23:10 |
klindgren | sticker, yep thats how you enable it | 23:10 |
xavpaice | good posting at https://www.sebastien-han.fr/blog/2015/02/09/openstack-perform-consistent-snapshots-with-qemu-guest-agent/ | 23:11 |
xavpaice | but without the warnings | 23:11 |
*** zul has joined #openstack-operators | 23:17 | |
klindgren | interesting that it has wanrings about possible security problems, and yet doesn't provide the cloud operator a way from disabling it | 23:17 |
klindgren | seems like thats a miss | 23:17 |
*** Rodrigo_BR has joined #openstack-operators | 23:23 | |
sticker | if i get a second to spare, i might take a look. i've been wanting to see if I can contribute and that might be way to start | 23:24 |
klindgren | sticker have you opened a thread on the dev mailing list about that? | 23:26 |
klindgren | as seems like a valid concern? | 23:26 |
sticker | no, i'm not on the dev mailing list at the moment. I'll sign up and send something now | 23:27 |
klindgren | cool - I shall +1 that - because I have similar concerns as people internally are asking how can I get better than crash consistent backups in our public cloud - without having to shutdown the vm. | 23:29 |
*** dminer has quit IRC | 23:33 | |
*** ducttape_ has joined #openstack-operators | 23:45 | |
sticker | cool, have sent something, feel free to amend and clarify! :) | 23:47 |
*** ducttape_ has quit IRC | 23:52 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!