*** witlessb has quit IRC | 00:07 | |
openstackgerrit | Andrew Lazarev proposed a change to openstack/sahara: Auth policy support implementation https://review.openstack.org/131609 | 00:22 |
---|---|---|
*** svetmy has quit IRC | 00:37 | |
*** Longgeek has joined #openstack-sahara | 00:47 | |
*** Longgeek has quit IRC | 00:48 | |
*** Longgeek has joined #openstack-sahara | 00:48 | |
*** Networkn3rd has quit IRC | 01:19 | |
*** Longgeek has quit IRC | 01:19 | |
*** tellesnobrega_ has joined #openstack-sahara | 02:36 | |
*** tellesnobrega_ has quit IRC | 02:49 | |
*** tellesnobrega_ has joined #openstack-sahara | 02:51 | |
*** witlessb has joined #openstack-sahara | 02:56 | |
*** chandankumar has joined #openstack-sahara | 02:57 | |
*** chandankumar has quit IRC | 02:58 | |
*** witlessb has quit IRC | 03:01 | |
*** drss_ is now known as drss | 03:46 | |
*** tellesnobrega_ has quit IRC | 03:51 | |
*** tellesnobrega_ has joined #openstack-sahara | 03:52 | |
*** chandankumar has joined #openstack-sahara | 04:05 | |
*** tellesnobrega_ has quit IRC | 04:22 | |
*** chandankumar has quit IRC | 04:32 | |
*** chandankumar has joined #openstack-sahara | 05:44 | |
*** tnovacik has joined #openstack-sahara | 06:15 | |
*** k4n0 has joined #openstack-sahara | 08:28 | |
*** IvanBerezovskiy has joined #openstack-sahara | 08:35 | |
*** stannie1 has joined #openstack-sahara | 08:44 | |
*** witlessb has joined #openstack-sahara | 09:03 | |
openstackgerrit | Andrey Pavlov proposed a change to openstack/python-saharaclient: Saharaclient tests for tempest https://review.openstack.org/130767 | 09:35 |
*** Timotey has joined #openstack-sahara | 09:55 | |
*** ylobankov has joined #openstack-sahara | 10:02 | |
*** boris-42 has quit IRC | 11:11 | |
*** tosky has joined #openstack-sahara | 11:24 | |
*** tellesnobrega_ has joined #openstack-sahara | 11:25 | |
*** tellesnobrega_ has quit IRC | 12:03 | |
*** tmckay is now known as tmckay_brb | 12:17 | |
*** Krast has joined #openstack-sahara | 12:48 | |
*** tmckay_brb is now known as tmckay | 12:54 | |
*** tosky has quit IRC | 12:57 | |
*** _crobertsrh is now known as crobertsrh | 13:05 | |
*** tellesnobrega_ has joined #openstack-sahara | 13:18 | |
*** miqui has joined #openstack-sahara | 13:32 | |
tmckay | crobertsrh, elmiko, if you have EDP ideas from your experience submitting jobs, please add comments to https://etherpad.openstack.org/p/kilo-summit-sahara-edp. I'll take a look at your pads, too. | 13:35 |
crobertsrh | will do | 13:36 |
tmckay | crobertsrh, it can touch on UI stuff too, or you can add a link to the UI pad if you have EDP specific stuff there | 13:36 |
elmiko | tmckay: i'll take a look | 13:36 |
crobertsrh | ok | 13:37 |
tmckay | thanks, I'm still pondering things to add. I should spend some time submitting jobs and see if anything grabs my attention | 13:37 |
*** Krast has quit IRC | 13:43 | |
*** Networkn3rd has joined #openstack-sahara | 13:48 | |
*** Networkn3rd has quit IRC | 13:48 | |
*** tnovacik is now known as tnovacik|gone | 14:43 | |
*** tnovacik|gone has quit IRC | 14:48 | |
*** tellesnobrega_ has quit IRC | 15:10 | |
*** tellesnobrega has quit IRC | 15:13 | |
tmckay | crobertsrh, the UX pad looks good. Plenty of stuff there for Kilo, I think | 15:21 |
crobertsrh | Yeah, plenty just with what is on the pad....who knows what others will have to bring up. | 15:21 |
crobertsrh | Or, if I get grouchy on the flight, I'll find more things to be annoyed at and add more | 15:22 |
elmiko | tmckay, crobertsrh, would you guys mind looking over https://etherpad.openstack.org/p/kilo-summit-sahara-integration-security ? | 15:24 |
elmiko | i'm not sure what else to add | 15:24 |
crobertsrh | sure | 15:24 |
elmiko | thanks | 15:25 |
tmckay | same here. My list for EDP is not super big, but as we saw in Juno a few large tasks can take up the whole cycle. | 15:26 |
elmiko | yea totally | 15:26 |
tmckay | elmiko, I can imagine that if we have security initiatives, that dovetails into EDP, too | 15:27 |
elmiko | tmckay: agreed, there is some overlap with the security topics to other areas as well | 15:27 |
crobertsrh | It might be good to have a shorter list anyways...the sessions are only 40 min | 15:29 |
crobertsrh | I think I recall the UX session for Juno feeling rushed | 15:30 |
elmiko | especially if SergeyLukjanov and i are splitting the session. maybe i should just prioritize what i have and then we'll see how far we get? | 15:30 |
crobertsrh | Yeah, definitely prioritize the list | 15:32 |
crobertsrh | I suspect my pad will get a workover in the next few days | 15:32 |
elmiko | when i first read the UX pad, i was impressed with your thoroughness | 15:33 |
crobertsrh | UX is a "target rich environment for improvement" | 15:33 |
elmiko | true | 15:33 |
crobertsrh | Some of the items might not require much discussion | 15:34 |
crobertsrh | Like some of the work items are, "fix this"...ok, next | 15:34 |
elmiko | right | 15:34 |
crobertsrh | I think 10% of the items will take 90% of the time | 15:34 |
crobertsrh | and the other 50% of the time will be a slugfest of brutality | 15:35 |
elmiko | probably true, just gotta make sure to not hit that 10% up front lol | 15:35 |
crobertsrh | Good thing we'll have time at the Friday meetup :) | 15:35 |
elmiko | yea | 15:36 |
tmckay | elmiko, security looks pretty good. I think the key items are documentation, and responding to the OSSG audit. The audit is likely to overlap and prioritize some of the other bullet points | 15:51 |
elmiko | tmckay: thanks! | 15:52 |
tmckay | elmiko, based on audits I've been through, they may return with a large list of previously uknown issues :) | 15:54 |
elmiko | tmckay: i'm counting on it =) | 15:54 |
*** k4n0 has quit IRC | 16:03 | |
*** chandankumar has quit IRC | 16:03 | |
*** IvanBerezovskiy has left #openstack-sahara | 16:19 | |
tmckay | elmiko, do you know much about Barbican? | 16:29 |
*** zhiyan has quit IRC | 16:36 | |
*** tosky has joined #openstack-sahara | 16:37 | |
*** saurabhs has joined #openstack-sahara | 16:41 | |
*** dboik has joined #openstack-sahara | 16:46 | |
*** dboik has quit IRC | 16:51 | |
*** Timotey has quit IRC | 16:54 | |
*** dboik has joined #openstack-sahara | 17:06 | |
*** dboik has quit IRC | 17:11 | |
*** dboik has joined #openstack-sahara | 17:12 | |
*** tmckay is now known as tmckay_brb | 17:40 | |
elmiko | tmckay_brb: i know some, i've read their docs and looked through the api to see if we could use it for storing secrets to the proxy users | 17:43 |
*** tellesnobrega has joined #openstack-sahara | 17:50 | |
*** tellesnobrega has quit IRC | 17:55 | |
*** miqui has quit IRC | 17:56 | |
*** dboik has quit IRC | 17:59 | |
*** dboik has joined #openstack-sahara | 18:00 | |
*** zhiyan has joined #openstack-sahara | 18:00 | |
jodah | curious, has anyone using nested VMs managed to setup their hadoop nodes to be accessible from the host OS? | 18:00 |
jodah | ...via neutron, or some other means? | 18:00 |
*** dboik has quit IRC | 18:01 | |
*** dboik has joined #openstack-sahara | 18:03 | |
*** dboik has joined #openstack-sahara | 18:04 | |
*** dboik_ has joined #openstack-sahara | 18:06 | |
*** dboik has quit IRC | 18:06 | |
elmiko | jodah: could you describe your setup a little more, i'm confused about the nested VMs part. | 18:07 |
elmiko | for example, when i run devstack, my hadoop nodes are able to communicate with the host | 18:09 |
elmiko | i'm using neutron, but it's not required, you could use nova-networking if preferred | 18:09 |
tmckay_brb | I'm using nova, although I have used neutron. Also confused about "nested" | 18:11 |
*** tmckay_brb is now known as tmckay | 18:11 | |
tmckay | elmiko, yeah, I saw a Barbican blurb on the schedule, I think I signed up for it | 18:11 |
jodah | elmiko i'm running devstack on an ubuntu VM with neutron enabled. by nested, i meant when i boot a hadoop cluster those VMs are running within my ubuntu VM :) | 18:11 |
elmiko | tmckay: barbican is interesting, i just wasn't sure if it was at the point we could use. i want to see more about nodes using keys to aquire barbican access. | 18:12 |
jodah | i boot them on my internal neutron network and assign a floating IP. both are accessible from within my ubuntu VM but not from my host OS | 18:12 |
elmiko | jodah: i think that should work | 18:12 |
elmiko | ahh | 18:12 |
elmiko | jodah: that's a tricky issue | 18:12 |
jodah | elmiko: i assumed nested VMs is how you guys are testing things too? would be nice to access the nested VMs from anywhere though | 18:12 |
elmiko | jodah: if you want to have access from the host -> devstack vm -> node vm, you will need to ensure that the route from the host are directed at the devstack vm for the nested floating ip pool | 18:13 |
tmckay | using devstack, I just launch VMs directly on my host. | 18:13 |
jodah | tmckay ah you're not running devstack in a vm? | 18:14 |
elmiko | jodah: also, you will need to dig into the iptables configurations on the devstack vm, as by default it won't let the "nested" vms out past the devstack vm. i've used post route filtering on the nat table to masquerade the traffic, i think that is a commonly accepted workaround | 18:14 |
tmckay | no. It might be better if I did :) I occasionally have issues with package updates, but it's usually not too bad. | 18:15 |
elmiko | jodah: fwiw i don't run devstack in a vm either | 18:15 |
jodah | elmiko thanks for the pointers. right now i'm using bridged networking, but can look into that | 18:15 |
tmckay | and, I was worried about performance of VMs in a VM on my little Lenovo | 18:15 |
jodah | what OS do you guys run? | 18:15 |
elmiko | fedora | 18:15 |
tmckay | me too | 18:15 |
elmiko | jodah: the main issue to look at is the routing from the host os to the floating ip pools through the devstack vm, and then also check the iptables routes for that pool coming out of the devstack vm | 18:16 |
jodah | ah, the nested VMs do OK on my macbook via vmware fusion. it has some particular support for running nested VMs. | 18:16 |
*** tosky has quit IRC | 18:16 | |
jodah | but i'm interested to try running the hadoop nodes with the nova docker hypervisor. has anyone tried that? | 18:17 |
elmiko | crobertsrh had been looking at it, i've been meaning to try it.... | 18:17 |
jodah | elmiko i don't really know where to start with that but i'll look into it. thanks for the pointer | 18:17 |
elmiko | i was just gonna say, nested vms would be way better with the docker back end | 18:17 |
crobertsrh | Yeah, I've been meaning to get back to it. | 18:18 |
*** tosky has joined #openstack-sahara | 18:18 | |
elmiko | jodah: yea, it can get very tricky with the routing | 18:18 |
jodah | would be nice to boot some sizable hadoop clusters, but without docker i'm limited with what i can do with VMs on one machine | 18:18 |
crobertsrh | I set it up to run with nova-docker, but didn't quite get to the sahara parts. Regular VMs were snappy though. | 18:18 |
elmiko | yea | 18:18 |
jodah | i plan to give it a try soon. if i get it working i'll share my notes | 18:18 |
jodah | ...get it working with sahara that is | 18:19 |
elmiko | awesome | 18:19 |
elmiko | jodah: also checkout the kolla project, i know they are about to start adding sahara support | 18:19 |
crobertsrh | Great. If I come up with anything, I'll be sure to share it here as well. | 18:19 |
jodah | elmiko very interesting... | 18:19 |
elmiko | jodah: this may help a little with the networking stuff. https://ask.openstack.org/en/question/44266/connect-vm-in-devstack-to-external-network/ | 18:20 |
jodah | great pointer! | 18:20 |
*** dboik_ has quit IRC | 18:58 | |
*** dboik has joined #openstack-sahara | 18:58 | |
*** dboik has quit IRC | 19:03 | |
*** dboik has joined #openstack-sahara | 19:04 | |
*** tosky has quit IRC | 19:14 | |
*** dboik has quit IRC | 19:32 | |
*** dboik has joined #openstack-sahara | 19:36 | |
*** dboik has quit IRC | 19:37 | |
*** dboik has joined #openstack-sahara | 19:39 | |
elmiko | tmckay, crobertsrh, i restructured the session topics a little. would you guys mind checking it again? https://etherpad.openstack.org/p/kilo-summit-sahara-integration-security | 19:39 |
elmiko | i tried to focus more on topics to discuss and the time frame we'll have | 19:40 |
tmckay | sure, no problem | 19:40 |
elmiko | tmckay: i added a note for Spark-Swift integration, thinking of you =) | 19:40 |
tmckay | I may want to do the same | 19:40 |
tmckay | thanks | 19:40 |
crobertsrh | That seems good. It's hard to tell how long any given item will take. | 19:41 |
*** dboik has quit IRC | 19:41 | |
elmiko | yea... it will be doubly tough if manage to gather some experts on one or more of the topics | 19:42 |
*** dboik has joined #openstack-sahara | 19:42 | |
tmckay | elmiko, did you see the OSSG session on the schedule? | 19:51 |
tmckay | and there is a threat analysis one, too | 19:51 |
elmiko | tmckay: yea, i plan on attending | 19:51 |
tmckay | I checked them off | 19:52 |
elmiko | tmckay: i also warned the OSSG group in their last irc meeting lol | 19:52 |
tmckay | design session looks good, more interesting than EDP :) | 19:52 |
elmiko | lol | 19:52 |
elmiko | i'd like to hit up one of the barbican sessions too | 19:52 |
tmckay | yeah, I think I marked one of those | 19:54 |
*** tmckay has quit IRC | 19:58 | |
*** tmckay1 has joined #openstack-sahara | 19:58 | |
openstackgerrit | A change was merged to openstack/sahara: Added ability to launch jobs on fake plugin https://review.openstack.org/130804 | 20:03 |
openstackgerrit | A change was merged to openstack/sahara: Fix Cloudera plugin with CDH packages < 5.2.0 https://review.openstack.org/131421 | 20:09 |
crobertsrh | I've switched back over to use the nova-docker driver. Docker can load/run my image (tarred version from DIB), but OS can't seem to launch it, I get "Error: No valid host was found. There are not enough hosts available." Currently in head-scratching mode. | 20:36 |
crobertsrh | OS *can* launch the cirros docker image just fine though | 20:36 |
elmiko | weird... | 20:36 |
elmiko | wonder if something is just missing from the image you want to use? | 20:37 |
crobertsrh | Possibly, but if I run it from docker directly, it's all happy and stuff | 20:37 |
elmiko | huh | 20:37 |
crobertsrh | I wonder if there is some sort of resource thing going on....it seems to be failing in the nova scheduler | 20:38 |
elmiko | what kind of resource thing though, i have a hard time believing your system is starved | 20:38 |
crobertsrh | pasting log.... | 20:39 |
crobertsrh | http://paste.openstack.org/show/126703/ | 20:41 |
elmiko | could there be something with the hostname in the container? | 20:42 |
jodah | crobertsrh i've seen that nova error when memory/disk space is constrained | 20:42 |
elmiko | (i don't know how, just throwing stuff out) | 20:42 |
jodah | crobertsrh if you look in the nova logs, somewhere you'll see the actual reason logged... can't remember which nova process it's in, but in the past when i've seen that the underlying error, which is actually logged, is limited RAM | 20:43 |
jodah | not sure if that would be the case with docker | 20:43 |
crobertsrh | Right...I think it should be in nova-scheduler's log (where my paste was from), but I don't see it there | 20:43 |
crobertsrh | I am trolling other logs right now though | 20:44 |
crobertsrh | Hmm...I also see this.... | 20:46 |
crobertsrh | 2014-10-29 16:45:20.959 DEBUG nova.compute.utils [-] [instance: e5b89d57-9d1f-4bf8-856a-a0e0334e9cac] create_container() got an unexpected keyword argument 'Cmd' from (pid=19222) notify_about_instance_usage /opt/stack/nova/nova/compute/utils.py:310 | 20:46 |
elmiko | that seems pretty debugable | 20:47 |
crobertsrh | Hmm...http://ur1.ca/ilptk | 20:48 |
crobertsrh | because paste.openstack.org fails 9 out of 10 times for me :) | 20:48 |
elmiko | yea, i've had that issue as well | 20:48 |
elmiko | so, is it complaining that create_container was called with a Cmd arg? | 20:49 |
elmiko | it's weird that your image wouldn't work but the built-in does if there is an error in the code | 20:50 |
elmiko | i would think this means it some sort of config issue | 20:50 |
crobertsrh | Right | 20:50 |
elmiko | does the nova-docker driver do anything with dockerfiles? there is a CMD command in there... | 20:51 |
crobertsrh | I was about to take a look there | 20:51 |
elmiko | maybe just need to capitalize in that file, sorry but i don't know much about how it generates those containers | 20:52 |
*** stannie1 has quit IRC | 20:52 | |
crobertsrh | Yeah, it's a bit of a black box....I was happy to have it work at all really :) | 20:52 |
elmiko | i hear ya =) | 20:52 |
SergeyLukjanov | I'm restarting review.o.o | 20:56 |
elmiko | wow, didn't realize you had the keys to the corvette ;) | 20:59 |
crobertsrh | ah, there is something about a glance command-line and args['Cmd'] in the spawn method of the nova-docker driver | 21:00 |
crobertsrh | maybe I need to adjust how I upload my image to glance | 21:00 |
elmiko | interesting | 21:00 |
elmiko | yea | 21:00 |
SergeyLukjanov | elmiko, yeah, I'm infra team member | 21:00 |
elmiko | neat | 21:02 |
elmiko | SergeyLukjanov: i updated our pad for the integration/security session. i think i'm done adjusting my part | 21:02 |
*** crobertsrh is now known as _crobertsrh | 21:08 | |
SergeyLukjanov | elmiko, great | 21:17 |
openstackgerrit | Sergey Reshetnyak proposed a change to openstack/sahara: Refactoring integration tests for Vanilla 1 plugin https://review.openstack.org/131155 | 21:37 |
*** openstackgerrit has quit IRC | 21:50 | |
jodah | has anyone used heat to deploy sahara? | 22:04 |
elmiko | jodah: i think some of the mirantis folks might have experience with that. i haven't. | 22:06 |
elmiko | i'm out for a few, take care all | 22:10 |
*** dboik has quit IRC | 22:52 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!