*** ukaynar has quit IRC | 00:36 | |
*** ukaynar has joined #openstack-sahara | 00:36 | |
*** ukaynar has quit IRC | 00:41 | |
*** caowei has joined #openstack-sahara | 01:01 | |
*** shuyingya has joined #openstack-sahara | 01:10 | |
*** shuyingya has quit IRC | 01:15 | |
*** shuyingya has joined #openstack-sahara | 01:36 | |
*** shuyingya has quit IRC | 01:41 | |
openstackgerrit | Merged openstack/puppet-sahara master: Prepare for Queens Milestone 2 https://review.openstack.org/523593 | 01:45 |
---|---|---|
*** shuyingya has joined #openstack-sahara | 01:48 | |
*** shuyingy_ has joined #openstack-sahara | 01:49 | |
*** shuyingya has quit IRC | 01:53 | |
openstackgerrit | Tuan Luong-Anh proposed openstack/sahara master: Fix the format command-line https://review.openstack.org/523003 | 01:53 |
openstackgerrit | Tuan Luong-Anh proposed openstack/sahara master: Fix the format command-line https://review.openstack.org/523003 | 02:42 |
*** dave-mccowan has quit IRC | 02:42 | |
openstackgerrit | caowei proposed openstack/sahara master: Update designate manual installation URL https://review.openstack.org/523662 | 02:50 |
*** raissa has quit IRC | 02:58 | |
openstackgerrit | Tuan Luong-Anh proposed openstack/sahara master: Fix the format command-line https://review.openstack.org/523003 | 03:15 |
openstackgerrit | Tuan Luong-Anh proposed openstack/sahara master: Fix the format command-line https://review.openstack.org/523003 | 03:16 |
*** ukaynar has joined #openstack-sahara | 03:29 | |
*** caowei has quit IRC | 03:40 | |
*** caowei has joined #openstack-sahara | 03:41 | |
*** links has joined #openstack-sahara | 03:42 | |
*** ukaynar has quit IRC | 04:33 | |
*** ukaynar has joined #openstack-sahara | 04:34 | |
*** pgadiya has joined #openstack-sahara | 04:43 | |
*** pgadiya has quit IRC | 04:45 | |
*** ukaynar has quit IRC | 05:01 | |
*** ukaynar has joined #openstack-sahara | 05:03 | |
*** caowei has quit IRC | 05:04 | |
*** caowei has joined #openstack-sahara | 05:25 | |
*** shuyingya has joined #openstack-sahara | 06:21 | |
*** shuying__ has joined #openstack-sahara | 06:22 | |
*** shuyingy_ has quit IRC | 06:24 | |
*** shuyingya has quit IRC | 06:25 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/sahara-dashboard master: Imported Translations from Zanata https://review.openstack.org/523699 | 06:36 |
*** shuyingya has joined #openstack-sahara | 06:39 | |
*** shuyingya has quit IRC | 06:39 | |
*** shuyingya has joined #openstack-sahara | 06:39 | |
*** shuying__ has quit IRC | 06:43 | |
*** rcernin has quit IRC | 07:43 | |
*** pcaruana has joined #openstack-sahara | 08:04 | |
*** rcernin has joined #openstack-sahara | 08:39 | |
*** spectr has joined #openstack-sahara | 09:03 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/sahara master: Updated from global requirements https://review.openstack.org/523796 | 09:21 |
*** caowei has quit IRC | 09:38 | |
*** caowei has joined #openstack-sahara | 09:50 | |
*** tosky has joined #openstack-sahara | 10:24 | |
*** caowei has quit IRC | 10:27 | |
*** spectr has quit IRC | 10:33 | |
*** tellesnobrega has quit IRC | 11:06 | |
*** shuyingy_ has joined #openstack-sahara | 11:52 | |
*** tellesnobrega has joined #openstack-sahara | 11:53 | |
*** shuyingya has quit IRC | 11:55 | |
*** raissa has joined #openstack-sahara | 12:12 | |
*** ukaynar has quit IRC | 13:00 | |
*** ukaynar has joined #openstack-sahara | 13:05 | |
*** ukaynar has quit IRC | 13:09 | |
*** links has quit IRC | 13:21 | |
*** dave-mccowan has joined #openstack-sahara | 13:36 | |
*** shuyingy_ has quit IRC | 13:39 | |
*** shuyingya has joined #openstack-sahara | 13:40 | |
*** openstackstatus has quit IRC | 13:43 | |
*** openstack has joined #openstack-sahara | 13:45 | |
*** ChanServ sets mode: +o openstack | 13:45 | |
openstackgerrit | Merged openstack/sahara master: Updated from global requirements https://review.openstack.org/523796 | 13:58 |
*** rcernin has quit IRC | 14:27 | |
*** tellesnobrega has quit IRC | 14:38 | |
*** ukaynar has joined #openstack-sahara | 14:40 | |
*** openstack has quit IRC | 14:46 | |
*** openstack has joined #openstack-sahara | 14:51 | |
*** ChanServ sets mode: +o openstack | 14:51 | |
*** ukaynar has quit IRC | 14:59 | |
*** ukaynar has joined #openstack-sahara | 14:59 | |
*** tellesnobrega has joined #openstack-sahara | 16:10 | |
*** jeremyfreudberg has joined #openstack-sahara | 17:32 | |
jeremyfreudberg | tellesnobrega, you might have missed this backport proposal from a while ago, but I *think* it's ok to merge https://review.openstack.org/#/c/515313/ | 17:33 |
tellesnobrega | jeremyfreudberg, thanks, i did miss it. I recently looked for open on branches and it didn't show up | 17:33 |
tellesnobrega | I have to check my search skills | 17:34 |
jeremyfreudberg | tellesnobrega, ha, don't worry about it | 17:34 |
tellesnobrega | jeremyfreudberg, I have a question for you. Do you know if you will make it to Dublin? | 17:34 |
jeremyfreudberg | tellesnobrega, I can't say 100% right now. But it does look hopeful again that I will make it to PTG | 17:35 |
tellesnobrega | jeremyfreudberg, great | 17:35 |
tellesnobrega | I vaguely remember while talking to you boss, she saying that you would be there | 17:36 |
jeremyfreudberg | tellesnobrega, hmm, it's possible. we haven't really discussed it yet... | 17:38 |
tellesnobrega | cool | 17:38 |
tellesnobrega | I signed up sahara, so it would be great to have you again | 17:39 |
jeremyfreudberg | yep | 17:40 |
jeremyfreudberg | I also wanted to mention that right now we are almost at queens-2... | 17:40 |
jeremyfreudberg | ...but no plugin upgrades done | 17:40 |
jeremyfreudberg | Not blaming anyone, since we really all have been working hard, but it's a bit unfortunate that our plan to get that done early didn't happen | 17:41 |
tellesnobrega | jeremyfreudberg, I agree with you | 17:41 |
tellesnobrega | this next meeting we can take some time to discuss the versions we want to upgrade to | 17:42 |
tellesnobrega | and see how soon we can get it done | 17:42 |
jeremyfreudberg | cool, i'll remember to bring it up at the meeting | 17:43 |
*** jeremyfreudberg has quit IRC | 17:51 | |
*** tosky has quit IRC | 18:24 | |
*** ukaynar has quit IRC | 18:27 | |
openstackgerrit | Merged openstack/sahara stable/ocata: Use non corrupted libext from image. https://review.openstack.org/515313 | 18:45 |
*** shuyingya has quit IRC | 18:53 | |
*** jeremyfreudberg has joined #openstack-sahara | 19:18 | |
*** tosky has joined #openstack-sahara | 19:18 | |
tellesnobrega | jeremyfreudberg, tosky, what is the right way to run just one unit test? | 19:25 |
tellesnobrega | keep forgetting it | 19:25 |
jeremyfreudberg | basically I do python -m testtools.run package.whatever.tests.module, I guess you might have to source the tox env manually first | 19:26 |
jeremyfreudberg | like `source .tox/py27/bin/activate` first | 19:26 |
tellesnobrega | thanks | 19:26 |
jeremyfreudberg | it gets tricky because sometimes that module name ends up being relative (current directory) and sometime it refers to the installed package | 19:27 |
jeremyfreudberg | hence why I'm unsure about the tox thing | 19:28 |
tellesnobrega | it worked | 19:30 |
tellesnobrega | do we have that documented? | 19:30 |
tellesnobrega | how to run single tests? | 19:30 |
tellesnobrega | if not, we probably should | 19:30 |
jeremyfreudberg | it's mentioned implicitly in the ostestr docs | 19:31 |
jeremyfreudberg | but you have to know to look there and also to understand their implication (they don't say directly, "this is how to do it") | 19:32 |
tellesnobrega | maybe this is something we need to improve | 19:32 |
tellesnobrega | you know, test running takes sometime, we need to make peoples lives easier | 19:32 |
jeremyfreudberg | well, it's not sahara specific. but it should probably be on some contributor guide somewhere | 19:32 |
jeremyfreudberg | yes | 19:32 |
tellesnobrega | jeremyfreudberg, tosky just got decommission of specific node running and fixed tests | 19:42 |
tosky | \o/ | 19:42 |
tellesnobrega | only thing left to do is add some tests for specific nodes deletion | 19:42 |
tellesnobrega | I'm planning on a couple actually | 19:42 |
jeremyfreudberg | congratulations | 19:42 |
tellesnobrega | 1) We delete one instance selecting the one and check it is removed | 19:43 |
tellesnobrega | 2) We delete N, N>1, and select M, M < N, and see the selected ones deleted + the N - M last instances removed | 19:43 |
tellesnobrega | and we keep the current that doesn't select | 19:44 |
tellesnobrega | which are already working | 19:44 |
tellesnobrega | does that make sense to you both? | 19:44 |
tosky | yep | 19:44 |
jeremyfreudberg | yes, that makes sense | 19:48 |
jeremyfreudberg | anyway, I had actually logged into IRC to ping elmiko with a question about trusts | 19:53 |
jeremyfreudberg | so, ping elmiko | 19:53 |
tellesnobrega | jeremyfreudberg, let me try to get his attention | 19:59 |
jeremyfreudberg | it's not super urgent, but it was on my brain today. I'm patient | 20:00 |
elmiko | jeremyfreudberg: hi | 20:01 |
jeremyfreudberg | hey elmiko, just a quick question about the whole proxy-users-domain thing | 20:01 |
elmiko | shoot | 20:01 |
jeremyfreudberg | so, when we enable the proxy users thing, it makes new credentials every job execution, | 20:02 |
jeremyfreudberg | but | 20:02 |
jeremyfreudberg | there's also some code out there, which was intended for the more finicky Hive, which creates new credentials once and they last the entire life of the cluster | 20:03 |
jeremyfreudberg | (I can link that code if needed) | 20:03 |
jeremyfreudberg | my actual question is | 20:03 |
jeremyfreudberg | is there any forseeable issue of extending the use of that code to happen for all clusters, not just hive ones? | 20:03 |
elmiko | the main issue is that you extend the window of vulnerability for those stores | 20:04 |
elmiko | although we have tried to make the cluster->store access as tight as possible, the longer the cluster lives, the longer the window of time that an attacker has to learn the temporary secret and exploit the trust | 20:04 |
elmiko | otherwise, i think you would be ok extending the lifetime of those trusts | 20:04 |
elmiko | i can't see a technical reason why it wouldn't work | 20:05 |
jeremyfreudberg | I see what you mean | 20:06 |
jeremyfreudberg | this change would be only downstream to begin with, so I can use more lax standards regarding security. but it sounds like it's not so much worse from a security perspective | 20:07 |
elmiko | it really depends on the situation, but yeah if someone has owned your cluster boxes then you are trouble either way | 20:07 |
jeremyfreudberg | yes, I was going to say on the Sahara-side we have barbican. but the proxy password stored on the cluster itself is just as vulnerable as any other credentials stored on the cluster itself | 20:08 |
elmiko | yup | 20:09 |
elmiko | imo, this is more a failing with hadoop storing sensitive info in plaintext | 20:09 |
jeremyfreudberg | which also reminds me that we should start looking into that new-fangled Hadoop CredentialProvider thing (perhaps a Hadoop 3 exclusive) | 20:09 |
jeremyfreudberg | https://hadoop.apache.org/docs/current/hadoop-project-dist/hadoop-common/CredentialProviderAPI.html | 20:10 |
jeremyfreudberg | ^secret storage within the hadoop cluster itself | 20:10 |
*** shuyingya has joined #openstack-sahara | 20:11 | |
jeremyfreudberg | anyways, thanks elmiko, always good to have someone to talk at | 20:12 |
elmiko | jeremyfreudberg: no worries, hope it was helpful =) | 20:13 |
*** tellesnobrega has left #openstack-sahara | 20:15 | |
*** tellesnobrega has joined #openstack-sahara | 20:15 | |
*** shuyingya has quit IRC | 20:15 | |
*** jeremyfreudberg has quit IRC | 20:17 | |
*** spectr has joined #openstack-sahara | 20:18 | |
*** spectr has quit IRC | 20:20 | |
tellesnobrega | tosky, I'm not sure the way the tests are set up, it will really test what I want to | 20:25 |
tellesnobrega | It uses fake plugin manager, fake ops and so on | 20:25 |
*** tellesnobrega has left #openstack-sahara | 20:25 | |
*** tellesnobrega has joined #openstack-sahara | 20:26 | |
tosky | tellesnobrega: even if fake plugin, it uses heat anyway, so it may be enough to see if the right node is removed | 20:37 |
tellesnobrega | tosky, problem is, the cluster create has no instances | 20:37 |
tellesnobrega | when I print the cluster, it shows all info, but under node_groups, the instances list are all empty | 20:38 |
tellesnobrega | because it is only checks count number here | 20:39 |
tellesnobrega | that has to be tests on clusters with instances | 20:39 |
tosky | oh, unit tests | 20:41 |
tellesnobrega | yes | 20:41 |
tellesnobrega | maybe this is better tested on scenarios | 20:42 |
tosky | ok, so either you mock a lot more things, or it could be a scenario | 20:42 |
tellesnobrega | I truly believe scenario test works better for this case | 20:42 |
tellesnobrega | and it gives me a chance to play with scenario tests | 20:43 |
tellesnobrega | but I value your opinion on tests more than mine, what do you think it is best? | 20:43 |
tosky | what if we can have both? at least some unit tests for the new code, and a more complete targeted removal | 20:45 |
tosky | on scenario | 20:45 |
tellesnobrega | that is better, I was thinking that would be your answer | 20:45 |
tellesnobrega | I will try to figure out how to that | 20:46 |
tellesnobrega | I'm sending a first patch so you guys can take a look | 20:47 |
openstackgerrit | Telles Mota Vidal Nóbrega proposed openstack/sahara master: Decommission of an specific node https://review.openstack.org/523981 | 20:47 |
tellesnobrega | while I'm writing the tests | 20:47 |
tellesnobrega | this still needs, saharaclient code and dashboard | 20:47 |
tellesnobrega | tosky, I will ping you tomorrow for help with the unit tests | 20:50 |
tellesnobrega | I have to drop for the day | 20:50 |
tellesnobrega | and you should drop for the day | 20:50 |
tellesnobrega | see you tomorrow | 20:51 |
tosky | I technically already dropped :) | 20:51 |
tosky | see you o/ | 20:51 |
*** shuyingya has joined #openstack-sahara | 20:52 | |
*** shuyingya has quit IRC | 20:56 | |
*** pcaruana has quit IRC | 21:00 | |
*** rcernin has joined #openstack-sahara | 22:03 | |
*** shuyingya has joined #openstack-sahara | 22:41 | |
*** shuyingya has quit IRC | 22:46 | |
*** hoonetorg has joined #openstack-sahara | 23:10 | |
*** shuyingya has joined #openstack-sahara | 23:22 | |
*** shuyingya has quit IRC | 23:27 | |
*** tesseract has joined #openstack-sahara | 23:48 | |
*** tesseract has quit IRC | 23:49 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!