*** dprince has quit IRC01:11
*** Ryan_Lane has joined #openstack01:11
*** bcwaldon has joined #openstack01:14
*** Ephur_ has joined #openstack02:07
*** rsampaio has joined #openstack03:17
*** obino has joined #openstack03:56
*** primeministerp2 has joined #openstack04:40
*** primeministerp1 has quit IRC04:40
*** reed has joined #openstack04:45
*** Ryan_Lane has joined #openstack05:37
eviscaresgood morning06:59
*** caribou has joined #openstack07:01
mandela123so far,there is not a way to know  which node an object has been placed on07:09
eviscaresgreat… thanks.07:09
redboThey're distributed in a random looking way among drives.  The only way to find out where they're at is to ask the ring.07:09
eviscaresI guess that is what happens if I do a swift download call, right?07:10
redboyeah, that's how the proxy server knows where they are07:10
eviscaresbugger all… I would like to test failure tolerance, but without knowing which nodes to shut down, that would be just guessing and testing07:11
redboif you just want to know where one object is, there's a command "swift-get-nodes [account] [container] [object]"07:12
eviscares ah, thank you. that was what I had been looking for.07:13
eviscaresand it returns an error. do I have to do a -A -K there?07:14
*** bengrue has joined #openstack07:32
*** mies has joined #openstack08:33
*** javiF has joined #openstack08:35
*** rustam has joined #openstack08:35
*** dirkx_ has quit IRC08:36
*** Ryan_Lane has quit IRC08:39
*** nati has quit IRC09:37
*** eviscares has joined #openstack10:21
eviscaresIs there a page where I can look up the different usergroups like .admin and what their permissions are? Preferably for 1.4. Thanks10:24
*** mfer has joined #openstack11:46
siwoshello all12:32
siwosanybody using SSD with compute nodes?12:32
siwosI came across a paper from dell (Openstack reference architecture)12:32
siwosdell recommends 10k RPM SAS drives for compute12:32
siwosfrom my experience the i/o is the first boundary you hit in the virtualization world12:33
siwoswhich one do you recommend ssd vs SAS?12:33
*** hggdh_ has joined #openstack12:36
reidracI've been very happy with 15k rpm SAS disks, but they're quite expensive12:36
reidracI agree with the io boundary :)12:36
siwosi tested ssd lately12:37
siwosworks better than sas definitely12:37
siwosdone some i/o benchmarks - ssd-s were 2 times faster than 10krpm sas12:38
siwos4 machines running simultaneously on one disk12:38
reidracI don't know if I would take into account Dell's recommendation on hw12:39
reidracif you know what I mean...12:39
siwosthey published their reference arch lately12:39
siwosbased on 610012:39
siwosfor me the nodes are way too huge to run vm-s effectively12:40
siwos16 cores , 96gb of ram per each node - this means potential problems with process scheduling12:40
siwosand i/o12:40
*** mattray has joined #openstack12:56
smoserok... lets say i did a crazy thing and ran a windows instance on  a public cloud12:57
smosersince this next 1 hour will entail about 50% of my windows usage in the past 10 years, i'm hoping someone here might be able to help me.12:57
smoserhow would I know what filesystem type was a on disk in windows?12:57
smoserie, in linux /proc/partitions or 'file --special-files /dev/XXX' would tell me.12:58
*** statik has joined #openstack12:58
mahogony@smoser are you currently booted up on the windows disk?12:59
larissamahogony: Error: "smoser" is not a valid command.12:59
*** hadrian has joined #openstack12:59
smoseri will be in 10 minutes or so13:00
smoseri'm wanting to know the FS of an ephemeral disk13:00
smoserbut knowing fs of all would be very appreciated13:00
*** rsampaio has quit IRC13:01
mahogonyif you have the disk in a mochine that is currently booted up to linux you can use parted or fdisk to scan the drive. it should report back the fs type. OR13:01
*** cereal_bars has joined #openstack13:02
smoserits really going to be in windows with no ooption to boot linux.13:02
mahogonyif booted to the disk right click my computer and select properties -> disk management -> right click boot partitiion and general tab will show fs type13:02
*** rsampaio has joined #openstack13:03
mahogonyie ntfs, fat32,...13:03
*** msivanes has joined #openstack13:04
*** Oneiroi has quit IRC13:06
smosermahogony, thank you.13:06
notmynameeviscares: http://programmerthoughts.com/openstack/swift-permissions/  <--- /very/ basic info on creating users and permissions in swift13:06
*** dirkx_ has joined #openstack13:07
*** Oneiroi has joined #openstack13:07
eviscaresnotmyname: thanks13:09
*** med_out is now known as medberry13:09
notmynameeviscares: what would be better?13:27
eviscaresnotmyname:  I would prefer a config file where I could assign Containers to users with permissions.13:28
reidraceviscares: but the users can create/delete containers at will13:30
*** mahogony has quit IRC13:30
eviscaresreidrac: actually, this doesn't work for me13:30
*** hggdh_ has joined #openstack13:30
eviscaresreidrac:  I created another user after the Admin, and he can't create folders13:31
reidracfolders? but does it have write permissions on the container?13:32
eviscaresI meant containers.13:32
reidracof course it cant13:33
eviscaresIf I have him upload something into a container that didn't exist before, it returns a 401 for Auth get.13:33
eviscaresSo then they can't create/delete at will.13:33
reidracthe point it's that the admin can create containers and assign users an ACL to containers13:33
eviscaresYes, and I consider these ACL unwieldy13:34
reidracdo you want the users to create containers too?13:34
reidracI can't understand, they can create folders inside the container13:34
eviscaresBecause I consider the ACL manipulation via Post very weird13:35
reidracit's like a file system in which the admin controls the root directory, and then creates user directories (containers)13:35
*** dirkx_ has quit IRC13:36
reidracin our implementation you can create an account, then create a container and enable a user to upload files there (and ONLY there)13:36
reidracthat's an extra access layer, I think is an advantage over other solutions13:36
reidracactually I think is one of the best features of swift13:36
eviscaresThen maybe I'm doing something wrong, because this fails me. I did a swift […] post -r 'system:trudat' -w 'system:trudat', and it doesn't work.13:37
reidracsystem is the account, trudat is the user13:38
reidracand you're doing that on an existing container of system account, aren't you?13:38
reidrachave you tried to retrieve the container ACLs to see if the POST worked?13:39
reidracdid work?13:39
reidracif it worked, then you need to check your auth server to see if it's returning the right ACL13:40
eviscareshow would I retrieve the container ACL?13:40
reidracsuch as X-Auth-Groups: system:trudat13:40
reidracif it's a minor version it will be OK13:42
statikdoes nova networking FlatDHCPMode always require 2 ethernet devices? I'm wondering whether it's possible to set up a test environment at home using some mac minis running ubuntu - they only have a single ethernet port. I'm interested in having multiple physical compute nodes but not too worried about security in this environment13:51
*** amccabe has joined #openstack13:51
eviscaresI got that token, but somehow I fail to understand how the request should be phrased13:52
eviscaresThis is all a bit overwhelming.13:52
reidracit's all right13:53
*** dirkx_ has joined #openstack13:53
reidracyou need to add a header to your curl request13:54
reidraccurl -I -H "X-Auth-Token: YOURTOKENHERE" http://yourproxy:port/whatever/system/container13:55
agystatik: 1 ethernet device will work with FlatDHCP for your compute nodes13:56
eviscaresah ok thank you13:56
reidracif I'm not wrong, that's a curl HEAD request using the token in the X-Auth-Token header13:56
*** mrjazzcat has joined #openstack13:56
statikagy: thanks!13:56
statiki've been confused by reading about the bridges that are required13:57
*** Capashen has joined #openstack13:57
statikagy: does the "compute controller" or device running nova-network require multiple nics?13:58
agystatik: nova-network should work with one interface, but i've not tried it tbh13:59
*** pfibiger has joined #openstack14:00
statikagy: thanks for suffering my newbie questions - so with a single interface, would I still need to configure a bridge, and then I'm basically just forgoing having a private network and all network traffic from the VMs is on the same net?14:00
eviscaresreidrac: thanks, but this doesn't seem to be working eiher.14:02
reidracwhat's the answer you get?14:02
agystatik: something like that. the nova-* packages are pretty good and will create the bridged interfaces for you. you may need to add an aliased address for your "private" networks14:02
*** bcwaldon has joined #openstack14:02
*** ldleworker has joined #openstack14:02
eviscaresI get nothing. I sent the request and it is taking a long time now.14:03
*** shentonfreude has joined #openstack14:03
eviscaresreidrac: the public auth service request is this? curl -k -v -H 'X-Storage-User: system:root' -H 'X-Storage-Pass: testpass' https://[MyProxiesIP]:8080/auth/v1.0?14:23
reidracno sure, are you running an auth service on that IP/port? can you paste the response headers? (add -D -)14:24
reidracI mean, first you should validate your installations: create an account/admin user, get a token, perform a HEAD request in the account, that sort of things ;)14:26
eviscaresYeah, did all that and It worked. Now I get an AUTH_[longthingie] back14:27
reidracthat's your storage token, kewl14:28
*** zigo has quit IRC14:29
eviscaresok… when I run the second command from the paste, I get a 50314:29
eviscarescurl -k -I -H "X-Auth-Token: AUTH_tk934dbbea9fca4b46a741ae7b45696364" https://[MyProxiesIP]:8080/v1/AUTH_system/timosfiles/14:30
reidracservice unavailable, that may mean your storage node(s) aren't there14:30
*** zigo has joined #openstack14:30
reidraccheck the proxy server logs, you'll find something there14:31
reidracor may be the proxy server failed to contact the private auth service to validate your token14:31
eviscaresProxyserver logs are in /var/log?14:31
reidracdefinitely, you need to check the proxy logs14:31
reidracswift uses syslog, it depends on your conf... but /var/log/syslog it's a safe bet14:32
eviscaresyeah… the connection times out...14:33
*** vladimir3p has joined #openstack14:33
eviscaressomething is rotten in the state of denmark...14:33
reidracwhen speaking with?14:33
*** daysmen has joined #openstack14:33
reidracthe private auth service or the storage nodes?14:33
eviscareswhen speaking with the container server on the storage nodes14:33
reidracso you got it :)14:34
reidracnow you know what to fix14:34
eviscaresthanks for walking me through this.14:34
reidracyou're welcome14:34
eviscaresCould this be a problem due to an older python version?14:36
reidrachow old? :D14:37
eviscaresUbuntu 10.10 install14:37
reidracdon't know, I guess other services would fail too... not only the container-server14:37
eviscaresRunning it on freshly installed Ubuntu 10.10 VM's14:38
reidracwhat does python --version say?14:38
reidracprobably not the problem, it should be 2.6.something, and that's OK14:38
*** code_franco has joined #openstack14:50
*** eviscares has quit IRC15:19
*** Ephur has joined #openstack15:20
*** javiF has joined #openstack15:20
undertreeHello, I am trying to figure out why my compute nodes will not assign addresses to the VM's.  I get a NoMoreAddresses error like: http://pastebin.com/C51bZ3J9 but I have not assigned any.  I have a class C available for fixed addresses.  Any ideas on where to look to find the issue?16:06
JoseBravoOpenStack compute uses a SAN/NAS to storage the VM volumes or use the disks of each hardware node?16:07
medberryundertree, I'd look at your database and see what's going on. Did you do a nova-manage create network somewhere along the way?16:08
*** marrusl has joined #openstack16:08
*** galthaus_ has quit IRC16:08
DuncanTJoseBravo: Yes.16:08
*** huslage has quit IRC16:08
DuncanTJoseBravo: It can be set up either way16:08
*** maplebed has joined #openstack16:08
*** maplebed has quit IRC16:09
*** maplebed has joined #openstack16:10
*** mnour has quit IRC16:10
*** ejat- has joined #openstack16:11
JoseBravoDuncanT, thanks16:11
JoseBravoIs OpenStack offering commercial support and training?16:12
*** ejat has quit IRC16:12
*** ejat- is now known as ejat16:12
*** ejat has joined #openstack16:12
DuncanTJoseBravo: No idea on the support front16:13
reedJoseBravo, google found this for training http://www.rackspace.com/cloudbuilders/openstack/training/16:13
reedJoseBravo, and support is also mentioned on http://www.rackspace.com/cloudbuilders/services/16:14
undertreeJoseBravo, nova-manage network list shows http://pastebin.com/e10HYHsp16:14
reedI think there are also other companies that offer both16:14
*** Capashen has quit IRC16:16
*** mattray has joined #openstack16:18
*** dendro-afk is now known as dendrobates16:19
JoseBravoLast question, If I need to deploy a minimal test cloud with OpenStack how many servers I need?16:20
DuncanTJoseBravo: You can run it on as few as one16:20
DuncanTJoseBravo: More realistically, one infrastructure node and a couple of compute hosts might give a more realistic feel for the system16:21
WormManI found seeing the interactions and stuff, 3 is nice(2 compute, 1 for everything else)16:23
JoseBravoinfraestrcuture node is like the "controller" ?16:23
*** stewart has joined #openstack16:24
*** hisaharu has joined #openstack16:24
*** adjohn has quit IRC16:25
*** aliguori has quit IRC16:25
*** nacx has quit IRC16:25
*** Ephur has quit IRC16:26
DuncanTJoseBravo: Yes.16:26
*** Ephur has joined #openstack16:27
*** mszilagyi has joined #openstack16:29
*** zigo has quit IRC16:31
*** alandman has joined #openstack16:31
undertreemedberry, nova-manage network list shows http://pastebin.com/e10HYHsp as the available networks16:50
*** errr_ has joined #openstack16:50
*** errr has quit IRC16:51
*** shentonfreude has joined #openstack16:57
*** mfer is now known as mfer-lunch17:20
*** msinhore has joined #openstack17:30
*** jaypipes has joined #openstack17:30
*** jaypipes has quit IRC17:31
*** Cyns has quit IRC17:48
*** alekibango has quit IRC17:48
*** rustam has joined #openstack17:49
*** Ryan_Lane has quit IRC17:50
*** Ryan_Lane has joined #openstack17:52
*** bengrue has joined #openstack17:56
*** dendrobates is now known as dendro-afk17:57
*** obino has quit IRC17:58
*** chriswong has quit IRC17:58
*** obino has joined #openstack17:58
*** dendro-afk is now known as dendrobates18:00
vishychriswong: it was renamed to "swift"18:15
vishysome time ago18:15
*** fabiand__ has joined #openstack18:36
*** rustam has quit IRC18:37
*** adjohn has joined #openstack18:48
*** _adjohn has joined #openstack18:52
*** huslage has quit IRC18:52
*** adjohn has quit IRC18:52
*** _adjohn is now known as adjohn18:52
Gmignu111: check the "euca-describe-group" output and make sure you added rules to allow ssh18:56
*** caribou has quit IRC18:58
*** ecarlin has quit IRC19:06
*** ecarlin_ is now known as ecarlin19:06
gnu111Gmi: I did this. not sure if this was needed " route add -host <public_ip> gw <eth1_Ip>" eth1 is my --public_interface19:06
jsavakhi leob - what seems to be the problem?19:10
leobwell i can't login into dashboard even though i'm fairly sure that user/pwd are correct but i'm not sure how to analyze the problem maybe anyone has some useful pointers19:12
leobso in the webserver/dashboard logs i first see auth_api connection created using url "http://localhost:5000/v2.0/"19:13
leobthat is the Nova API endpoint i think so it's not keystone yet, maybe it doesnt even reach keystone19:13
gnu111vishy: I can access it from the controller which runs nova-network. But outside of that machine, i can't access that instance with the public ip.19:13
vishygnu111: is the ip routable on the interface from other machines?19:14
jsavakleob - a couple people had similar problems in the past few days and resolved it by updating nova & keystone from trunk - are you up to date?19:14
leobthen i see a Python stacktrace ending in openstackx/api/connection.py and then the message Unauthorized (HTTP 401), it suppose that's the HTTP response from Nova API19:14
*** tryggvil__ has joined #openstack19:15
leobright well that is very useful info, it's exactly what this forum is so useful for19:15
leobi installed from the bazaar/lp repo a few days ago, should i update only dashboard or everything? i.e. just rerun the install from source19:16
leobright, nova and keystone you said19:16
*** arun_ has joined #openstack19:16
gnu111vishy: probably not, that's the part I am confused about. is my nova network. I assigned the public ip to
vishywhat is the public ip?19:18
*** tryggvil has quit IRC19:18
*** chrism has joined #openstack19:18
*** andy-hk1 has quit IRC19:19
chrismi've got a bit of a weird one here19:19
*** mszilagyi has quit IRC19:20
gnu111vishy: i have two nics, flat_interface=eth0 and public_interface=eth1.19:20
chrismpreviously working configuration, fairly standard, 2 compute nodes, 1 controller node (scheduler/api/network).   This was working fine until a reboot happened on the controller this morning.    Now I can ping the fixed_ip of the instances, but I can't SSH to them from outside of the openstack servers19:20
leobi have a very general question about openstack, it's about current or planned features - are "advanced" features in the planning like dynamically moving VM workloads from one physical host to another or would that be thord party stuff built on top of Openstack19:20
chrismit should be noted that if i'm on either of the compute nodes or the controller node, i can ssh to the instances fixed_ip.    Also if i bind a floating IP tot he instance, I can get to that from outside of the openstack cluster just fine19:22
*** cereal_bars has joined #openstack19:22
vishygnu111: and is that 149. an address that if you gave it to the network host on eth1, it would be routable?19:24
vishyleob: right now it is on top, hopefully that stuff moves down into openstack eventually19:25
vishychrism: how were you getting to them before?19:25
leobokay but the architecture would allow it19:25
gnu111vishy: no, eth1 has a different address.19:26
leobjust curious, i'm still noob at all of this19:26
chrismI could route to them from outside of the cluster.  Our office layout has several vlans, and you can route between the vlans fine.19:26
vishygnu111: hmm but if you added it there19:26
vishyis it routable?19:26
gnu111vishy: ip addr show eth1 shows that public ip address. how do I make it routeable? :D19:27
*** undertree has quit IRC19:27
*** undertree has joined #openstack19:27
*** mdomsch has joined #openstack19:28
vishygnu111: is that an ip you own?19:28
vishyis it assigned to you by your isp, etc?19:28
gnu111vishy: yes.19:28
gnu111vishy: yes. i own it and it's free.19:28
*** Ryan_Lane has quit IRC19:28
*** undertree has joined #openstack19:36
gnu111vishy: yes. sorry. DNAT       all  --  anywhere        to:
vishyif you do it with a -L -n -v, does it show packets hiding that rule?19:43
vishyok this autocorrect is starting to piss me off, time to disable it19:44
gnu111vishy: yes. only 84 byes....19:46
vishyso start off a ping19:46
*** andyb has joined #openstack19:46
vishyand start tcpdumping for icmp traffic19:46
vishysee where it disappears19:46
gnu111vishy: ping from outside?19:47
vishytcpdump -i eth1 icmp19:48
vishyverify it makes it onto the bridge19:48
vishyand onto the compute host19:48
vishykeep dumping interfaces until you see it disappear19:48
*** mdaubs has quit IRC19:49
gnu111vishy: when I ping the eth1 address i see stuff in tcpdump but nothing when I ping the other address.19:49
*** dirkx_ has joined #openstack19:49
*** dirkx_ has quit IRC19:50
*** BK_man has joined #openstack19:50
*** andyb has quit IRC19:50
*** BK_man has quit IRC19:50
*** johnpur has joined #openstack19:50
*** ChanServ sets mode: +v johnpur19:50
vishyso it sounds like you have an issue in your router config then19:50
gnu111vishy: when I ping from the controller node. it responds to the ping but nothing on the dump.19:50
vishypackets aren't actually getting to the controller on that ip19:51
*** Gmi has quit IRC19:51
vishyif you fix that part, the rest should work :)19:51
gnu111vishy: ok. is it using the route add to fix this?19:52
*** marrusl has quit IRC19:52
*** rwsu has joined #openstack19:52
rwsuhi, I have a question on hardware requirements: http://docs.openstack.org/cactus/openstack-compute/admin/content/compute-system-requirements.html19:53
*** andyb has joined #openstack19:53
rwsu2x2TB disks is listed for volume storage, is that the bare minimum, or is there a smaller size one could get by in a dev environment?19:54
notmynamesusanb: but for just the storage, that is a great use case for swift20:00
susanbhmm... ok.20:00
susanbbut what happens when a transcoder attempts to access a media file?20:01
rwsuvishy, annegentle: thanks, that's helpful, trying to size a hardware order20:01
susanbwhatever's local will be local but whatever's remote will be shipped over the LAN?20:01
susanbtransparent to the transcoder?20:01
susanbright now we're severely IO bound from the NAS20:01
notmynamesusanb: right now you'd have to accept the data going over the network between a swift cluster and a nova cluster. a long-term ideal would be to have nova spawn a VM on the same box where the data is living20:02
notmynamesusanb: IO bound by disk or by network?20:02
susanbrather... both!20:02
susanbnetwork we can fix I think (RDMA or Infiniband or smth similar)20:03
susanbdisk IO is more difficult20:03
notmynamesusanb: depending on why you are limited, the swift architecture may be able to allow you to have higher throughput in and out of your storage cluster20:03
susanb(or 10G ethernet even)20:03
*** mattrobinson has quit IRC20:03
*** nerdstein has quit IRC20:03
notmynameswift scales horizontally as the cluster grows and is designed to handle many streams at once20:03
susanbbut even the in future, a large file will be spread out throughout the cluster, right?20:04
susanbor does swift have a notion where it "clusters" a given file geograhically closer? pieces closer to each other?20:04
chrismso seeing what vishy was talking abotu earlier, I ran some traces on SSH connections to the instance from my workstation.   I can see the instance respond with the SSH banner, but the responses never make it past the nova-network host20:05
notmynamesusanb: data is spread across the cluster, but each object is stored as one file on disk20:05
chrismany ideas?20:05
susanbwhat if file exceeds the disk space?20:05
notmynamesusanb: the objects are limited* to 5GB (*just a constant in the code). but it's possible to tie many objects together into one logical object20:06
notmynamesusanb: so split your 100GB file into 100 1GB chunks and tie them together into one logical object20:06
susanbwho does the splitting?20:06
susanbswift itself?20:06
notmynamesusanb: the client20:07
notmynamesusanb: (but we provide a smart client that can do it for you)20:07
chrismare there outbound iptables rules that need to be in place for an instance to send a response packet?20:07
notmynamesusanb: more advantages of splitting objects are that you can upload and download the parts concurrently20:08
susanbas long as i dont have to do the splitting myself that's ok i guess20:08
susanbi was thinking of HDFS type setup where HDFS chunks the file by itself20:08
leobsounds like something for hadoop ?20:08
*** galthaus_ has quit IRC20:08
susanbleob: exactly... that's what i'm more familiar with20:08
*** mattray1 has quit IRC20:08
susanbbut will hadoop allow me to send compute to where the data is?20:09
leobthat is the idea of hadoop and hdfs20:09
leobit tries to optimize for data locality20:09
susanbbasically, i'm looking f or a way to avoid footballing 100gb files back & forth20:09
leobfits the bill for you if you ask me20:09
susanbthat's what i'm starting to think also..20:10
leobwell you need to upload your files into hdfs once and download them once processed20:10
leobwhat kind of processing you need to do on the video files?20:11
susanbwe get super HQ quality from studios20:11
susanbProRes 4444  type files20:11
susanband we need to transcode in a large variety20:11
susanbmobile, etc..20:11
susanbstandard HD for consumers..20:12
leobwell yes it sounds like something for hadoop20:12
susanbok.. thank you everybody VERY MUCH.20:13
leoblarge scale parallellizable massive batch file processing that's really the thing for hadoop20:13
chrismanyone in here knowledgable about nova-network?20:16
*** susanb has quit IRC20:20
chrismmind if i bug you for a minute on this routing issue I'm seeing since a reboot this morning of the network controller?20:21
*** mdomsch has quit IRC20:22
chrismlong story made super short.    3 servers.   2 compute/volume nodes, 1 network/scheduler/api.  Vlan networking config.  eth1 on all boxes are tied to trunk ports, eth0 are the "public" ips of th emachines.20:23
chrismThis was working fine until a reboot on the controller this morning20:23
vishywhat isn't working anymore20:23
vishycontroller has ip_forward set?20:24
chrismi can ping an instance, and get a response.   When I try to SSH, I can see the packets get to the instance, and the instance reply back with the SSH banner.  The banner makes it to the nova-network controller, but the response packets never make it past there20:24
chrismroot@os-controller:~# cat /proc/sys/net/ipv4/ip_forward20:24
vishyare you pinging over floating ip?20:24
chrismfixed IP20:24
vishyare you running trunk code?20:24
chrismif I tie a floating IP to it, it's fine20:24
chrismnah, not trunk20:25
chrismwhatever ubuntu ships now under stable20:25
vishyso where are you pinging from?20:25
chrismbut yeah, if I assign a floating IP, I can route to that just fine, ssh into the instance, etc20:25
chrismworkstation here at the office20:25
chrismwe have multiple vlans which can route between eachother20:25
vishyand that machine is using the controller as the gateway for the fixed range?20:26
*** michael_ is now known as michael20:26
chrismwell actually tbh i'm not 100% sure20:26
*** michael is now known as scalability_junk20:27
chrismI believe so, yes.20:27
vishyso it should be ipconntracking the connection on the controller20:28
vishycan you make sure you can ping your workstation from controller20:28
vishymaybe it has no route back20:28
chrismyeah from the controller back is fine20:28
chrismfrom the compute/volume nodes, i can ping/connect back to the workstation fine20:29
vishyon the ip that it is showing the packets coming from?20:29
vishyso probably your traffic is getting snatted to the public ip20:29
chrismI have seen a few odd instances of the public ip fo the controller responding back20:30
vishyand if you have routing rules set up, you don't really want that traffic to be snatted20:30
chrismI should open up the snaplength and see if those are the packets i'm expecting20:30
vishyso there is a flag to skip snatting to range20:30
chrismoh yeah/20:30
chrismer ?20:30
*** ccustine has quit IRC20:30
chrismaah gotcha20:31
vishywhich will tell nova-network not to snat packets to that cidr20:31
chrismI'll give that a shot20:31
vishyyou might try that20:31
vishykill nova network flush tables20:31
vishyand restart20:31
*** Ephur has quit IRC20:32
*** msinhore1 has joined #openstack20:33
leobjust installed latest Openstack version using "nova.sh branch/nova.sh install" with USE_GIT=0, but still getting django_openstack.auth:Error authenticating Unauthorized (HTTP 401) when trying to log into Dashboard while i'm sure that user/pwd must be right, does anyone have an idea how i could go about analyzing the problem? look in certain logfiles, try to log details of the service request (keystone?) which dashboard is issuing when20:33
*** Ryan_Lane has joined #openstack20:33
*** mszilagyi has quit IRC20:34
*** pfibiger` is now known as pfibiger20:35
*** maplebed has quit IRC20:35
leobjust looking, i might change something in keystone/etc/logging.cnf to get more detailed logging20:36
*** cole has quit IRC20:36
*** jmckenty_ has joined #openstack20:37
*** msinhore has quit IRC20:37
*** msinhore1 has quit IRC20:37
*** aaagirl has joined #openstack20:38
*** msinhore has joined #openstack20:38
*** termie has joined #openstack20:51
*** mies has quit IRC20:52
*** mies has joined #openstack20:53
andybHi, need help solving installation problem. See http://paste.openstack.org/show/2261/20:54
chrismshould I disperse that dmz option to the nova.conf on the compute nodes as well?21:01
chrismnot at all right now21:01
vishyyou might need to update nfconntrack limit21:01
vishychrism: computes shouldn't need it21:01
chrismk, it's the default 65k value now21:02
chrismhr but net.netfilter.nf_conntrack_count is only at 12421:03
*** mdomsch has joined #openstack21:03
vishychrism: nasty, not sure why it would be blowing up21:04
chrismyeah tbh i'm kind of lost here right now21:04
chrismthis has been fine for like a week until this reboot21:05
chrismmind if I do the generic pasting of configs/iptables rules/routes and see if you can spot something that maybe I'm missing?21:06
chrismvishy: http://paste.openstack.org/show/2263/21:11
chrismor whoever wants to take a stab at it21:11
*** daysmen has joined #openstack21:31
*** bcwaldon has quit IRC21:32
*** clauden has quit IRC21:39
bszaCan anyone one tell me the swift superadmin account:user under swauth?  tnx22:05
*** miclorb_ has joined #openstack22:50
*** asomya has quit IRC22:50
*** jfluhmann has quit IRC22:52
JoseBravoI also tried to ping from the controller and it's not respondig..23:23
*** cereal_bars has quit IRC23:24
*** joearnold has quit IRC23:25
*** jj0hns0n has quit IRC23:28
*** jj0hns0n has joined #openstack23:28
*** rnirmal has quit IRC23:29
JoseBravokpepple_, in the log file it appears to start ok, and with euca-describe-instances it show is running23:29
*** maplebed has joined #openstack23:29
JoseBravokpepple_, I lanched with euca-tools but I gave SSH and ICMP to the group "default"23:30
*** mfer has joined #openstack23:31
*** undertree has quit IRC23:31
*** huslage has joined #openstack23:31
*** tryggvil has quit IRC23:31
*** mfer has quit IRC23:34
kpepple_JoseBravo: does it have a public, routable IP address ?23:36
*** dendro-afk is now known as dendrobates23:39
JoseBravokpepple_, yes23:41
*** martine has quit IRC23:42
*** Cyns has joined #openstack23:45
kpepple_JoseBravo: hmmmm ... what do you get with a euca-get-console ?23:50
*** ejat has joined #openstack23:51
*** ecarlin has quit IRC23:54
*** huslage has quit IRC23:55
*** huslage has joined #openstack23:57
*** worstadmin has joined #openstack23:57
*** Eyk is now known as Eyk^off23:57
*** worstadmin has quit IRC23:59
JoseBravowget: cant't connect to remote host Network is unreachable23:59
JoseBravokpepple_,  it's the error I'm getting23:59

