vishy | xenith: yes and yes | 00:03 |
---|---|---|
*** miclorb has joined #openstack | 00:11 | |
*** MarkAtwood has quit IRC | 00:25 | |
*** rogue780 has joined #openstack | 00:28 | |
*** MarkAtwood has joined #openstack | 00:40 | |
*** miclorb has quit IRC | 00:45 | |
*** rogue780 has quit IRC | 00:49 | |
*** rogue780 has joined #openstack | 00:57 | |
Xenith | vishy: Great, just wanted to make sure. | 01:07 |
*** rogue780 has quit IRC | 01:09 | |
*** jfluhmann__ has joined #openstack | 01:19 | |
*** jfluhmann has quit IRC | 01:23 | |
*** rogue780 has joined #openstack | 01:29 | |
uvirtbot | New bug: #700530 in nova "Doc make broken by rev530 nova version change " [Undecided,New] https://launchpad.net/bugs/700530 | 01:31 |
*** zul has quit IRC | 01:38 | |
*** jimbaker has joined #openstack | 01:43 | |
*** trin_cz has quit IRC | 02:01 | |
*** leted has quit IRC | 02:06 | |
*** rogue780 has quit IRC | 02:08 | |
*** opengeard has joined #openstack | 02:13 | |
*** leted has joined #openstack | 02:13 | |
*** rogue780 has joined #openstack | 02:23 | |
*** Xenith has quit IRC | 02:33 | |
*** Xenith has joined #openstack | 02:34 | |
*** reldan has quit IRC | 03:10 | |
*** rogue780 has quit IRC | 03:40 | |
*** leted has quit IRC | 04:11 | |
*** dovetaildan has quit IRC | 04:20 | |
*** dovetaildan has joined #openstack | 04:23 | |
*** joearnold has joined #openstack | 04:26 | |
*** reldan has joined #openstack | 04:27 | |
*** reldan has quit IRC | 04:30 | |
*** joearnold has quit IRC | 04:30 | |
*** jimbaker has quit IRC | 04:35 | |
*** joearnold has joined #openstack | 04:47 | |
*** joearnold has quit IRC | 04:52 | |
*** arcane has joined #openstack | 05:06 | |
*** joearnold has joined #openstack | 05:08 | |
*** rchavik has joined #openstack | 06:23 | |
*** ksteward has quit IRC | 06:36 | |
*** ksteward has joined #openstack | 06:51 | |
*** Abd4llA has joined #openstack | 07:06 | |
*** Abd4llA1 has joined #openstack | 07:27 | |
*** Abd4llA has quit IRC | 07:30 | |
*** Abd4llA1 is now known as Abd4llA | 07:35 | |
*** joearnold has quit IRC | 07:38 | |
*** allsystemsarego has joined #openstack | 07:51 | |
*** allsystemsarego has joined #openstack | 07:51 | |
*** leted has joined #openstack | 08:56 | |
*** reldan has joined #openstack | 09:49 | |
*** rchavik has quit IRC | 10:02 | |
*** miclorb has joined #openstack | 10:11 | |
*** reldan has quit IRC | 10:22 | |
*** reldan has joined #openstack | 10:27 | |
*** miclorb has quit IRC | 10:28 | |
*** leted has quit IRC | 10:29 | |
*** reldan has quit IRC | 10:29 | |
*** reldan has joined #openstack | 10:30 | |
*** anotherjesse has quit IRC | 10:31 | |
*** anotherjesse has joined #openstack | 10:31 | |
*** hky has joined #openstack | 10:35 | |
*** reldan has quit IRC | 10:35 | |
*** Abd4llA has quit IRC | 10:47 | |
*** reldan has joined #openstack | 10:48 | |
*** reldan has quit IRC | 10:52 | |
*** Abd4llA has joined #openstack | 10:59 | |
*** jfluhmann__ has quit IRC | 11:09 | |
*** cw has quit IRC | 11:09 | |
*** jfluhmann_ has quit IRC | 11:09 | |
*** filler has quit IRC | 11:09 | |
*** jeremyb has quit IRC | 11:09 | |
*** glenc_ has quit IRC | 11:09 | |
*** lool has quit IRC | 11:09 | |
*** chmouel has quit IRC | 11:09 | |
*** antonym has quit IRC | 11:09 | |
*** taihen has quit IRC | 11:09 | |
*** glenc_ has joined #openstack | 11:11 | |
*** lool has joined #openstack | 11:11 | |
*** chmouel has joined #openstack | 11:11 | |
*** antonym has joined #openstack | 11:11 | |
*** taihen has joined #openstack | 11:11 | |
*** zelazny.freenode.net sets mode: +v antonym | 11:11 | |
*** jfluhmann__ has joined #openstack | 11:11 | |
*** cw has joined #openstack | 11:11 | |
*** jfluhmann_ has joined #openstack | 11:11 | |
*** filler has joined #openstack | 11:11 | |
*** jeremyb has joined #openstack | 11:11 | |
*** adiantum has joined #openstack | 11:45 | |
*** Abd4llA has quit IRC | 12:06 | |
*** fabiand_ has joined #openstack | 12:43 | |
*** trin_cz has joined #openstack | 12:50 | |
*** fabiand_ has quit IRC | 12:57 | |
*** jfluhmann has joined #openstack | 13:21 | |
*** jfluhmann__ has quit IRC | 13:23 | |
*** charlvn has joined #openstack | 14:40 | |
*** bhulver has joined #openstack | 14:46 | |
*** bhulver has left #openstack | 14:48 | |
*** bhulver has joined #openstack | 14:52 | |
*** burris has quit IRC | 16:02 | |
*** michaeldreamhost has quit IRC | 16:08 | |
*** burris has joined #openstack | 16:08 | |
*** dendrobates is now known as dendro-afk | 16:24 | |
*** dendro-afk is now known as dendrobates | 16:31 | |
*** skrusty has quit IRC | 16:53 | |
*** skrusty has joined #openstack | 17:06 | |
*** dendrobates is now known as dendro-afk | 17:10 | |
*** adiantum has quit IRC | 17:28 | |
*** dendro-afk is now known as dendrobates | 17:46 | |
*** rogue780 has joined #openstack | 17:57 | |
*** fabiand_ has joined #openstack | 17:57 | |
*** fabiand_ has quit IRC | 18:03 | |
*** fabiand_ has joined #openstack | 18:04 | |
*** bhulver has quit IRC | 18:04 | |
*** dendrobates is now known as dendro-afk | 18:04 | |
*** joearnold has joined #openstack | 18:19 | |
*** hggdh has quit IRC | 18:46 | |
*** joearnold has quit IRC | 19:07 | |
*** dendro-afk is now known as dendrobates | 19:10 | |
*** cruciform has quit IRC | 19:20 | |
*** Abd4llA has joined #openstack | 19:34 | |
*** dendrobates is now known as dendro-afk | 19:36 | |
*** leted has joined #openstack | 19:38 | |
*** WonTu has joined #openstack | 19:39 | |
*** WonTu has left #openstack | 19:39 | |
*** leted has quit IRC | 20:01 | |
*** rdw has quit IRC | 20:03 | |
*** rdw has joined #openstack | 20:04 | |
*** leted has joined #openstack | 20:04 | |
*** rogue780 has quit IRC | 20:10 | |
*** rogue780 has joined #openstack | 20:11 | |
*** hggdh has joined #openstack | 20:12 | |
*** jt_zg has joined #openstack | 20:18 | |
jt_zg | hey all | 20:18 |
openstackhudson | Yippie, build fixed! | 20:19 |
openstackhudson | Project nova build #372: FIXED in 1 min 19 sec: http://hudson.openstack.org/job/nova/372/ | 20:19 |
jt_zg | What would cause me to get the following error message, "Update failed: 503 Service Unavailable" when running "swift-auth-add-user -K devauth -a system root testpass" (with the proper values subbed in)? | 20:20 |
jt_zg | I've checked that all my IPs are right and file-permissions correct | 20:20 |
*** dovetaildan has quit IRC | 20:41 | |
*** dovetaildan has joined #openstack | 20:44 | |
*** dovetaildan has quit IRC | 20:51 | |
*** leted has quit IRC | 20:52 | |
*** dovetaildan has joined #openstack | 20:53 | |
*** opengeard has quit IRC | 20:58 | |
*** damon__ has joined #openstack | 20:59 | |
notmyname | jt_zg: check syslog (or wherever you have logs going, if you customized it) | 21:05 |
*** rogue780 has quit IRC | 21:05 | |
jt_zg | notmyname, Here is my output: http://paste.openstack.org/show/448/ | 21:05 |
notmyname | so it looks like the error is not in the auth-server but in the account server. grep for account-server instead | 21:06 |
jt_zg | Perhaps I'm mixing the terms up? Is the account server not relegated to reside on the auth server? | 21:07 |
notmyname | are you running the saio or a multi-machne setup? | 21:08 |
jt_zg | multi-machine | 21:08 |
jt_zg | grepping for account-server produced nothing on the auth server syslog | 21:08 |
notmyname | ok. can you describe your cluster? | 21:09 |
jt_zg | Sure, I have 5 storage servers, 1 auth server, 1 proxy server as per the instructions at http://swift.openstack.org/howto_installmultinode.html#prerequisites | 21:10 |
notmyname | and the more general answer is that no, the account servers don't have to live on the auth server (or vice versa) | 21:10 |
jt_zg | Gotcha, good to knw | 21:10 |
jt_zg | know* | 21:10 |
notmyname | is that 6 separate machines? | 21:10 |
jt_zg | 7 | 21:10 |
jt_zg | And yup, all separate...that was fun to setup :S | 21:10 |
notmyname | err, ya. math fail | 21:10 |
jt_zg | haha, no judgement | 21:11 |
notmyname | so the storage servers are running the account, container, and object servers? | 21:11 |
jt_zg | yes sir | 21:11 |
notmyname | ok | 21:11 |
notmyname | from your paste, check the logs on 192.168.143.47 | 21:11 |
jt_zg | for account-server? | 21:12 |
notmyname | is that a storage node or your proxy? | 21:12 |
jt_zg | proxy | 21:12 |
notmyname | grep for proxy-server | 21:13 |
notmyname | and you have allow_account_management = true set in the proxy config? | 21:13 |
jt_zg | yup | 21:13 |
jt_zg | and proxy-server yielded nothing of concern. I can pastebin it if you'd like | 21:14 |
notmyname | ya, I would guess that would give a 400 error not 500 | 21:14 |
notmyname | sure | 21:14 |
jt_zg | http://paste.openstack.org/show/449/ | 21:14 |
notmyname | ya, that's rather boring | 21:14 |
notmyname | but it seems that you have no connections received there | 21:15 |
jt_zg | Right | 21:15 |
notmyname | if you make a request to the proxy do you get a 404 with somethng in the logs? | 21:15 |
jt_zg | I'm wondering if its a mix up between me using internal and external IPs int he wrong place? I used the proxy's internal IP for the auth servers configs | 21:15 |
notmyname | if the auth server can access it, should be no problem | 21:16 |
jt_zg | fair | 21:16 |
jt_zg | auth173.255.233.89192.168.162.246 | 21:16 |
jt_zg | proxy173.255.233.9 192.168.143.47 | 21:16 |
jt_zg | host ext-IP int-IP | 21:17 |
notmyname | make a request to the proxy | 21:17 |
notmyname | curl -i http://173.255.233.9/healthcheck | 21:17 |
jt_zg | using this string: swift-auth-add-user -K *mysecretkey* -a system root *myrootpass* ? | 21:18 |
jt_zg | couldn't connect to host | 21:18 |
jt_zg | used internal and external IP with curl | 21:19 |
notmyname | so that's the first place to look | 21:19 |
notmyname | oh | 21:19 |
notmyname | add :8080 | 21:19 |
notmyname | if that's what you're running for the proxy | 21:19 |
jt_zg | hangs | 21:20 |
notmyname | anything in the proxy logs? | 21:20 |
jt_zg | nothing new/different | 21:20 |
notmyname | are you using ssl or not? | 21:21 |
jt_zg | I am | 21:21 |
notmyname | ok, htn https | 21:21 |
notmyname | s/htn/then | 21:21 |
notmyname | curl -i https://173.255.233.9:8080/healthcheck | 21:21 |
notmyname | perhaps with the -k if needed | 21:21 |
jt_zg | sorry about that | 21:21 |
*** miclorb has joined #openstack | 21:22 | |
jt_zg | ooh | 21:22 |
jt_zg | root@auth:/etc/swift# curl -i -k https://173.255.233.9:8080/healthcheck | 21:22 |
jt_zg | HTTP/1.1 200 OK | 21:22 |
jt_zg | Content-Type: text/plain; charset=UTF-8 | 21:22 |
jt_zg | Content-Length: 2 | 21:22 |
jt_zg | Date: Sun, 09 Jan 2011 21:22:33 GMT | 21:22 |
notmyname | good | 21:23 |
jt_zg | internal and external both work | 21:23 |
notmyname | now, if you do something like "curl -i -k https://173.255.233.9:8080/v1/blah" you should get a 404 | 21:23 |
jt_zg | yup | 21:24 |
jt_zg | 404 is in the proxy syslogs too | 21:24 |
notmyname | also, you can add log_level = DEBUG to /etc/swift/proxy-server.conf under the [app:proxy-server] section | 21:24 |
notmyname | good | 21:24 |
notmyname | are you running those commands from the auth server? | 21:24 |
jt_zg | Those last few? Yup | 21:25 |
jt_zg | added the debug option | 21:25 |
notmyname | good. that means there is no network issues between the servers. one less thing to worry about | 21:25 |
notmyname | restart the proxy to make sure the config is updated | 21:25 |
jt_zg | indeed! | 21:25 |
jt_zg | done | 21:26 |
notmyname | you can add the log_level option to the auth server too | 21:26 |
jt_zg | done and restarted | 21:27 |
notmyname | ok, rerun the add user command and see what happens in the logs | 21:27 |
jt_zg | 403 error returned, no syslog update on proxy server | 21:28 |
notmyname | 403? can you paste it? last time it was 503 | 21:28 |
jt_zg | Update failed: 403 Forbidden | 21:28 |
jt_zg | yup, last time was a 503 | 21:28 |
jt_zg | Its a 503 again. The add user command I used was incorrect. Giving me 503's again | 21:33 |
notmyname | and no change in the auth server logs? | 21:35 |
jt_zg | none | 21:35 |
jt_zg | http://paste.openstack.org/show/450/ most recent /var/log/syslog on auth server | 21:36 |
notmyname | looking | 21:39 |
*** reldan has joined #openstack | 21:40 | |
jt_zg | Appreciate it :D | 21:40 |
jt_zg | Almost tempted to rebuild the auth and proxy servers to rule out any sloppy configs I may have setup :S | 21:41 |
notmyname | give me a moment | 21:48 |
jt_zg | Absolutely | 21:48 |
*** reldan has quit IRC | 21:49 | |
*** reldan has joined #openstack | 21:52 | |
notmyname | i see a 503 on my saio, so something is similar in our configs. I haven't looked at this part in a while, so I'm trying to figure out why I can't add accounts either | 21:52 |
jt_zg | I really appreciate the effort. I literally only made my first efforts in using/testing Openstack last night so I'm a little lost | 21:53 |
jt_zg | What is saio anyways? | 21:54 |
notmyname | swift all in one | 21:55 |
jt_zg | gotcha. So, basically a just more compressed setup? | 21:55 |
notmyname | http://swift.openstack.org/development_saio.html | 21:55 |
notmyname | not really, just all running on one VM or one machine | 21:55 |
jt_zg | thats pretty cool | 21:56 |
*** reldan has quit IRC | 21:57 | |
notmyname | ok, I got mine to work | 22:01 |
jt_zg | How did you pull that off? | 22:01 |
notmyname | I had to change the default_storage_url in auth-server.conf | 22:02 |
notmyname | it may not be related to your setup. let me check one more thing | 22:02 |
*** reldan has joined #openstack | 22:03 | |
notmyname | in your proxy conf, what's in the pipeline? | 22:04 |
jt_zg | pipeline = healthcheck cache auth proxy-server | 22:04 |
notmyname | ya, ok. different issue. I was running some additional middleware that didn't like my mismatch of default_storage_url in auth-server.conf and in the middleware for the proxy-server (the middleware is the cname and domain remap ones--not really important here) | 22:05 |
*** rlucio has joined #openstack | 22:05 | |
*** fabiand_ has quit IRC | 22:06 | |
jt_zg | hmm, I wonder what is causing this then | 22:07 |
*** reldan has quit IRC | 22:07 | |
*** dendro-afk is now known as dendrobates | 22:07 | |
notmyname | so you've checked permissions on /etc/swift/auth.db | 22:07 |
notmyname | ? | 22:07 |
jt_zg | yup, its set to swift and I restarted | 22:08 |
notmyname | and you have user=swift everywhere (like in auth-server.conf) | 22:08 |
jt_zg | yup | 22:08 |
*** joearnold has joined #openstack | 22:09 | |
notmyname | since you can talk to the proxy from the auth server (our previous curl commands), I suspect that it is related to passwords or permissions somewhere | 22:12 |
jt_zg | I thought so too | 22:13 |
jt_zg | Could this string be the problem: | 22:13 |
jt_zg | swift-auth-add-user -K devauth -a system root testpass | 22:13 |
jt_zg | I sub in my key for devauth and testpass for my root users password | 22:13 |
notmyname | "devauth" is the only key there | 22:13 |
jt_zg | so I don't sub my pass into testpass? | 22:14 |
notmyname | the system/root/password have nothing to do with anything outside of swift | 22:14 |
notmyname | so you can use test tester testing or jt_zg jt_zg hunter2 | 22:15 |
jt_zg | gotcha | 22:15 |
jt_zg | I tried again with swift-auth-add-user -K *MYKEY* -a system root testpass - still getting 503 | 22:15 |
notmyname | it will be what you use to get an auth token before you make authenticated requests to the proxy server | 22:15 |
notmyname | and you are running that command as the system user swift? | 22:16 |
jt_zg | no...su swift you mean? | 22:16 |
notmyname | ah. I think that's your problem | 22:16 |
notmyname | what are the permissions on /ets/swift/auth.db? | 22:16 |
notmyname | etc | 22:16 |
jt_zg | -rw-r--r-- 1 swift swift 9216 2011-01-09 17:14 auth.db | 22:17 |
notmyname | if only the "swift" user can write to it, you need to run swift-auth-add-user as swift | 22:17 |
notmyname | ok, ya | 22:17 |
notmyname | swift-auth-add-user does the work of updating the db and calling the proxy server to create the account in the storage cluster | 22:17 |
notmyname | so sudo -u swift should fix everything | 22:18 |
jt_zg | hmm | 22:19 |
jt_zg | no swift user | 22:19 |
*** fabiand_ has joined #openstack | 22:19 | |
notmyname | based on the permissions you have on auth.db there is :-) | 22:20 |
jt_zg | strange.. | 22:20 |
jt_zg | yup, it exists. Just checked... | 22:20 |
jt_zg | using sudo -u swift just spits out the sudo usage instructions | 22:21 |
jt_zg | ok, I sorted out my confusion. 503 error | 22:22 |
notmyname | just for fun, chmod it to 666 and try again | 22:23 |
jt_zg | the auth.db? | 22:23 |
notmyname | ya | 22:23 |
jt_zg | no luck, 503 | 22:24 |
notmyname | hmm | 22:24 |
notmyname | still using your key, not devauth in the -K flag, right? | 22:25 |
jt_zg | right | 22:25 |
notmyname | ya, that wouldn't give a 503 | 22:25 |
*** whaley has quit IRC | 22:26 | |
jt_zg | At a loss. Curl is playing nicely but adding a user isn't | 22:26 |
jt_zg | and I've checked my configs far too many times | 22:26 |
notmyname | I think the issue is on your auth server somwhere | 22:27 |
jt_zg | *nod* I think so too | 22:27 |
notmyname | nothing weird like you have https in the cluster url but no certs defined? | 22:30 |
*** dragondm has joined #openstack | 22:30 | |
jt_zg | nope | 22:30 |
jt_zg | certs are there | 22:30 |
notmyname | you are using IP addresses not hostnames? so no lookup issues | 22:31 |
jt_zg | yup | 22:31 |
jt_zg | IPs only | 22:31 |
*** whaley has joined #openstack | 22:32 | |
notmyname | oh, if you got the user issues figured out, you should probably set the auth.db permissions back to 644 | 22:34 |
jt_zg | oh ya, thanks :P | 22:35 |
notmyname | are you running the latest code or one of the 1.1 release? | 22:36 |
notmyname | s/one of// | 22:36 |
jt_zg | most recent | 22:36 |
*** dendrobates is now known as dendro-afk | 22:36 | |
*** fabiand_ has quit IRC | 22:37 | |
notmyname | the auth server is pretty basic. not much to mess up in the configs | 22:38 |
jt_zg | could it be the proxy server, not starting correctly? | 22:39 |
notmyname | perhaps. do you see a "proxy-server started" line in syslog | 22:40 |
jt_zg | Yup, quite a few | 22:40 |
notmyname | can you paste your auth-server.conf? (obfuscate the admin key, if you want) | 22:41 |
jt_zg | http://paste.openstack.org/show/451/ | 22:43 |
notmyname | and your proxy-server.conf? | 22:43 |
jt_zg | http://paste.openstack.org/show/452/ | 22:45 |
*** lionel has joined #openstack | 22:48 | |
notmyname | jt_zg: sorry. I've been a single parent for the last 4 days and my wife just got home. I'm out | 22:50 |
jt_zg | I understand. Thanks for the help so far though | 22:50 |
*** dragondm has quit IRC | 23:02 | |
*** allsystemsarego has quit IRC | 23:04 | |
*** chilts has joined #openstack | 23:16 | |
*** joearnold has quit IRC | 23:41 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!