slyonsnotmyname: I don't suppose you're around and can try to help me a bit more with Swift?00:02
slyonsCan anyone give me some pointers on using swift's tempurl?00:31
geekyogiHi everyone.. It's a beautiful day!06:34
michael_1hi hi08:09
michael_1目前openstack 有在台灣的社群的相關資訊嗎?08:10
michael_1TWOSUG 算不算是社群呢?08:10
zynzelmichael_1: eng please.08:12
*** uksysadmin has joined #openstack08:14
michael_1is the openstack have in Taiwan community ?08:14
*** qazwsx has joined #openstack08:16
michael_1thank you08:16
*** Razique has joined #openstack08:19
uksysadminMadkiss, can I ask a couple of qs on HA for Glance? Just need to understand some concepts and solutions...08:37
Madkissuksysadmin: shoot, we'll see whether I know a meaningful answer ;)08:38
uksysadmin:) its Monday so I'll let you off if not ;-)08:38
MadkissActually, it's even a federal holiday in austria.08:39
uksysadminah, man - you're just dedicated08:39
Madkiss"I shouldn't even be here today!"08:39
Madkiss(If you've seen Clerks)08:39
Madkissanyway, shoot your questions please :)08:39
uksysadminok - so I'm looking at a couple of angles on this.  First, there are options in nova.conf for a list of glance servers... is this a good approach, or (I'm assuming you have a preference to this latter solution) use Pacemaker/Corosync set up here instead?08:41
uksysadminobviously the nova.conf approach doesn't involved setting up the cluster - but have you experience of it?08:41
Madkissthe one solution doesn't exclude the other.08:41
MadkissImagine you have ten servers dedicated to running Keystone and Glance08:42
*** tpot has quit IRC08:42
Madkissyou can use pacemaker to run keystone and glance on every single one of them08:42
Madkissmake sure they always talk to the same database, which can be done by MySQL, too08:42
Madkissand voila, you have ten glance-keystone nodes out of which 9 can fail08:43
Madkisswith such an amount of servers, btw., it's probably more elegant to run a load balancing software somewhere instead of letting nova try 10 servers (if 9 of themn happen to be down at a time)08:43
*** aa has joined #openstack08:46
uksysadminwhat do the nova.conf options look like for a pacemaker setup? (I've never set up pacemaker before -  going through the installs to understand it all this week)08:46
*** aa__ has quit IRC08:46
Falcon|Razique: Hi, got some new information regarding my issue with migration between multiple essex compute nodes. It seems like the dhcp server is giving out the wrong gateway for the migrated instance (giving out the same gateway as the compute node it was on before). Any idea on this?08:46
Madkissuksysadmin: possibly interested in pacemaker training? we do that kinda stuff. ;-)08:47
uksysadminMadkiss, I wouldn't rule it out - my job is architecting - the guys doing this get me telling them we should do this and they're the ones that need to the guru level08:47
Madkissglance_api_servers= needs comma separated IP:host-entries.08:48
Madkissso if you have ten possible glance servers, just add the ten addresses there.08:49
Madkissuksysadmin: and if you're dealing with a company that needs OpenStack and HA, please get in touch with us. It's not as easy as one would guess, and for a lot of things, HA is just impossible at the moment.08:49
uksysadminits a bit up in the air to say the least08:50
Raziquehey Falcon|08:50
Madkissfor a lot of things, right now it's just undoable.08:50
uksysadminI was at Florian's talk at the folsom openstack conference08:50
Raziquemmm you are in multi_host mode ?08:50
Madkisseven better :)08:50
Raziquehey uksysadmin :)08:51
Falcon|Razique: yes08:51
uksysadminput me down the route of pacemaker and corosync to solve these issues08:51
uksysadminhey Razique, how's it going?08:51
Raziqueuksysadmin I'm ok; liberating compute nodes :-) for essex08:52
Madkissuksysadmin: pacemaker and corosync won't protect you from the nova-volume disaster :)08:52
Raziquestill have a couple of VM to migrate first08:52
uksysadminMadkiss, indeed. Which is ok. There are some services that we don't need straight away for what we need to achieve.08:55
uksysadminRazique, awesome.08:55
Falcon|Razique: Is there a problem with using multi host with essex when it comes to the dhcp server?08:55
Madkissuksysadmin: I see. You spoke of many questions, which else are there? :)08:56
RaziqueFalcon| that is what I was looking at08:56
Raziquefor your nework, into the database the multi_host is enabled08:56
Raziqueso the flags on every compute inde ?08:56
*** davep_afk_coffee is now known as davepigott08:58
uksysadminMadkiss, I think I was reading too much into things... so a "fairly robust" set up would be: multiple glance servers supported by shared storage for images... is there any conflict of who gets to write to the datastore? e.g. there's no possiblity of data synchronisation issues (master/master)?08:59
Falcon|Razique: yes, the networks in the database is set to multihost and nova.conf file contains --multi_host=True08:59
uksysadmin(and if a load balancer is used - do you need persistence to a server - if a client talked to one and flipped to the other, is that a problem?)09:01
uksysadminfor an install here we're looking at NFS for images [we don't have a big environment. Yet. So swift/ceph/gluster  isn't part of this. Yet...]09:02
*** bbcmicrocomputer has joined #openstack09:02
*** bbcmicrocomputer has joined #openstack09:02
sgranit took me a moment to realize - #debian-devel09:03
RaziqueFalcon| : I hope it's not a bug :-/09:04
*** cryptk is now known as cryptk|offline09:04
uksysadminMadkiss, but one last thing - can Glance just be put behind a load balancer without Pacemaker? It's just a web service...?09:05
Madkisshello sgran09:05
Raziquecan you check your version ?09:05
Madkissuksysadmin: master-master for glance you mean? Not sure about that, but as long as they all access the same mysql database, i would expect mysql to take care of this.09:06
Madkissafter all, it's part of the REST-interface's job description to allow this kind of scalability09:06
uksysadminyeah - just don't know why you need it all as a cluster... we have hundreds of web servers behind load balancers - none of them rely on state... why use Pacemaker for Glance when we can just have a single way into Glance through the LB and in the LB pool have multiple Glance instances?09:07
Falcon|Razique: 2012.1-0ubuntu2.109:08
Madkissuksysadmin: you can do that, too. You just won't have pacemaker recovered glance and keystone instances automatically that way. and for MySQL and RabbitMQ, you'll need Pacemaker anyway.09:09
zynzelMadkiss: why? you can use master-master replication in mysql09:10
zynzeland cluster with rabbitmq09:10
Madkissrabbitmq mirrored queues are broken.09:10
uksysadminFor MySQL was looking at Galera... for RabbitMQ - we've been looking at solutions... didn't involved Pacemaker... but I also think we don't have an ideal setup09:10
Madkissand mysql master-master-replication is something nobody actually wants.09:10
uksysadmin+1 on what you just said09:11
zynzelMadkiss: i test them, and i think they work...09:11
Madkisszynzel: wait until you see them in production them.09:11
uksysadminMadkiss, why not?09:11
RaziqueFalcon| I don't know much about the ubuntu packaging policy when it comes to openstack09:11
Raziquelet me check09:11
Madkissuksysadmin: not with the classy mysql cluster stuff, at least. galera is something I haven't tested yet to its outer extent, but the wsrep patch to the mysql source actually scares the shit out of me.09:11
uksysadmin(MySQL M/M/M Galera set up seems good enough)09:11
uksysadminhaha - fair enough09:11
sgranMadkiss: what's broken with mirrored queues?09:12
sgrandoes it just not mirror?09:12
uksysadminand yeah - I do *get it* about multiple writes and then having compliance with the row entries09:12
Madkisssgran: you#ve already been talking to florian about this, haven't you?09:12
uksysadminand to be fair I've got a chat with our dba team this week about this09:12
uksysadminMadkiss, you've been helpful and insightful - I'm going off to play09:13
sgranMadkiss: ish: he said someone else saw consistency issues09:13
Madkissuksysadmin: thanks. should you need professional support for this, you know where to find me :)09:13
RaziqueFalcon| ok the ubuntu package should contain the fix09:14
Raziquecheck your files against that commit09:14
sgranso I'm interested in details of the issue - eg, there may be some areas where it's worth trading off reliability/availability/etc and complexity09:14
Madkisssgran: I've tested both solutions when working out the initial pacemaker support stuff, and I've just noticed that when unter high load, some messages will get lost in the rabbitmq queues while other ones will be carried out two and three times.09:15
uksysadminMadkiss, cheers. And yes - will give you a shout if need be.09:15
sgranI see.  Thanks09:16
zynzelMadkiss: we want to use M-M mysql+cluster rabbit+LB as a frontend for glance, api, keystone. When we run it i will inform you about status ;)09:17
*** livemoon has quit IRC09:18
Madkisszynzel: Multi-Master MySQL with galera?09:18
kodapaRazique: the fix is in our files09:18
MadkissRazique: you will find in your inbox within the minute btw.09:18
zynzelMadkiss: nope, simple master-master with mysql09:19
RaziqueMadkiss thanks a ton :-)09:19
Raziquehello by the wat09:19
*** evanjfraser has quit IRC09:19
Madkisszynzel: isn't that one semi-synchronyous only?09:19
uksysadminzynzel, I've been looking at MySQL + Galera... check out - great place to get M/M/M with CMON monitoring as well as other MySQL options for clustering09:19
zynzelMadkiss: i dont think, but when we run it i will have more info09:20
zynzeluksysadmin: i dont need multi master, we want to run only 2 available zone per DC, so master-master is reason enough09:20
uksysadminzynzel, fair enough :)09:21
zynzelreasonable* ;)09:21
uksysadminzynzel, whenever looking at HA/failover there's always something better - its whatever fits with your resources and acceptable limits that count. There's *always* a bigger fish. ;-)09:22
zynzeluksysadmin: yeah, but remember KISS ;)09:22
uksysadminyes - I'm agreeing with you09:23
Madkissthere's nothing easy about decent HA concepts.09:23
Madkissyou can safely forget that assumption.09:23
uksysadminhaha - indeed09:23
uksysadminOracle's clusterfcuk of a grid is an example of that ;-)09:23
zynzelsimple dont mean easy ;)09:23
Madkisszynzel: I'm not sure what you mean with "master-master" replication in MySQL, actually.09:24
*** willaerk has joined #openstack09:26
zynzelMadkiss: for example09:26
Madkisslemme know how it goes then09:26
zynzelno problem :)09:27
*** Guest50362 has quit IRC09:28
*** Guest50362 has joined #openstack09:29
*** songyan has quit IRC09:29
Falcon|Razique: I migrated a machine, the gateway was wrong but I was able to ssh into the machine on its floating ip. Restarted the network and all network was lost, I then rebooted the machine and got stuck with: cloud-init-nonet waiting 120 seconds for a network device.09:32
Falcon|any idea?09:32
*** qazwsx|2 has joined #openstack09:33
zynzelFalcon|: you use multi_host=True?09:33
Falcon|zynzel: yes09:34
zynzelif yes, check dnsmasq on src compute node and dst compute node09:34
zynzelin my env i must patch compute, to release fixed ip on src, and assign on dst ;)09:34
*** pasm has quit IRC09:35
*** qazwsx has quit IRC09:36
kodapazynzel: the machine does not exist in dnsmasq on any compute host09:36
zynzelkodapa: check /var/lib/nova/networks/nova-brXXX.conf on both nodes09:37
zynzelkodapa: == Falcon| ?;)09:37
* zynzel confused09:37
RaziqueFalcon| damn09:37
Raziqueyou restarted nova-network or the instance network ?09:38
kodapaRazique: instance networking09:38
Raziquein the dnsmasq process runing on the node ?09:39
Raziquetail -f /var/log/syslog09:39
kodapayes, it's running but the instance missing in the dnsmasq conf09:39
Raziquewhile you run a dhclient3 from the instance09:39
kodapai just restarted nova-network, nova-compute on the hosts09:39
kodapaand the instance is in correct dnsmasq now :S09:39
kodapazynzel: we're colleagues09:39
RaziqueThanks a lot Madkiss :-)09:41
Raziquekodapa : you don't have normally need to reboot the compute-node09:41
Raziqueit's weird09:41
kodapaRazique: not reboot, just restart the services :)09:41
Raziqueyes :-) but nova-compute restart shouldn't be necessary09:42
*** davepigott has quit IRC09:42
Raziquei'm still looking for that gateway transfer09:42
MadkissRazique: did it work? ;)09:42
RaziqueMadkiss : haven't tried yet :D09:42
Raziquelet me look at it09:42
kodapaRazique: yeah09:42
RaziqueMadkiss amazing script :)09:43
*** jackh has quit IRC09:47
kodapathe floating ip was still on the wrong host09:47
kodapaso i disassociated it and associated it again09:47
*** pasm has joined #openstack09:47
kodapanow the floating ip is on both hosts :P09:48
zynzelKarmaon: you can check this patch09:49
zynzelthis is our patch for update dhcp+move floating ip from one node to another+change vnc address09:50
zynzelyou can use what you want from this diff for yours purpose ;)09:50
kodapazynzel: you mean me? :P09:50
zynzelyeah, sorry ;)09:50
zynzelKarmaon: this was for kodapa sorry ;)09:51
kodapais this patch going into ubuntu soon?09:51
zykes-haven't gitten it upstream yet zynzel ?!09:51
zynzelkodapa: nope, i dont signed cla09:51
zykes-why not ?09:52
kodapawell it must be fixed :P09:52
kodapacan't have that bug in production really09:52
*** b1rkh0ff has joined #openstack09:52
*** rafaduran has quit IRC09:53
zynzelzykes-: real reason? i dont have time ;) maybe in june, when we will have 2 av zones09:53
*** cryptk is now known as cryptk|offline09:54
MadkissRazique: just a sec, I need to change something in it.09:55
zykes-zynzel: 2 racks or ?09:55
zynzelzykes-: for 1 half of june 2 racks09:56
zynzelin future 1 av = 3 racks09:56
*** msavy has joined #openstack09:57
MadkissRazique: okay, got it. need to add "export" before SERVICE_TOKEN and SERVICE_ENDPOINT to make it work.09:59
Madkissand then ./ -m -u keystone -t keystone -p Ue0Ud7ra -K -R RegionOne -E "http://localhost:35357/v2.0" -S -T hastexo will just do it09:59
*** tpot has joined #openstack10:00
*** clopez has joined #openstack10:00
*** Grimdin has left #openstack10:00
*** saju_m has joined #openstack10:03
*** aspiers has quit IRC10:03
saju_mcan not access openstack server using openvpn
kodapaRazique: the dnsmasq conf moves to correct host at confirm10:12
kodapaRazique: when I restarted compute services it got confirmed automatically10:12
*** bourke_ has quit IRC10:13
*** bourke has joined #openstack10:13
*** bencherian has quit IRC10:16
*** aspiers has joined #openstack10:16
*** saju_m has quit IRC10:16
*** michael_1 has quit IRC10:20
*** tpot has quit IRC10:21
MadkissRazique: that's the latest revision of the script along with some short documentation.10:21
*** ozstacker has quit IRC10:23
*** davepigott has joined #openstack10:23
*** Trixboxer has joined #openstack10:25
*** tpot has joined #openstack10:30
*** flaviamissi has quit IRC10:34
*** ovidwu has quit IRC10:43
*** ozstacker has joined #openstack10:51
*** semyazz has joined #openstack10:51
kodapaMadkiss: we use endpoints in template file, is that recommended or not?11:34
kodapaRazique: ^11:34
*** aspiers has joined #openstack11:45
saju_mi can not access openstack server using openvpn12:38
uksysadminsaju_m, nmap the ip and see what is actually running on that ip12:44
Madkisskodapa: not anymore12:44
*** dachary has quit IRC12:49
*** dachary has joined #openstack12:51
kodapaMadkiss: why not12:55
*** melmoth has joined #openstack12:56
Madkisskodapa: because it doesn't scale13:01
kodapaexplain more please13:02
*** aa has quit IRC13:07
Madkisskodapa: well, if you have your endpoints in a database, you can just access them with every keystone instance flying around13:07
*** Glacee has joined #openstack13:09
*** deshantm has quit IRC13:09
kodapaMadkiss: hehe yes, but is there any other reason than that?13:11
kodapabecause when I tested in lab i was recommended to use template because dashboard didn't work13:11
kodapawith mysql13:11
kodapaendpoint store :P13:11
MadkissIt does by now for sure. And the officially recommended method is mysql storage, too. catalog file is recommended for development environments only.13:12
Madkissi updated about three hours ago.13:13
*** iryoung has joined #openstack13:13
MadkissYou'll find a script there to create the endpoints in mysql :)13:13
*** aspiers has joined #openstack13:15
notmynamemtaylor: LinuxJedi: thanks for unsticking it last night. same issue this morning, though:
LinuxJedinotmyname: thanks for letting me know.  _something_ is wrong with the gerrit trigger plugin but we have no debug messages from anything to find out what so it is a tricky one.  I'll push that one through shortly for you.  Going to be hard to properly debug with the US away today13:19
kodapahmmm what we see when migrating instances: in resize_verify the instance ip is in dnsmasq conf on the from host; when verified is it removed on the from host but is not added to the new host. The result is missing dnsmasq entries on both hosts13:19
kodapaIs this a known bug?13:19
kodapaRazique: ^13:19
kodapazynzel: ^^13:20
Glaceenotmyname: does that mean that 1.5.0 is coming out soon? :)13:20
*** QwertyM has joined #openstack13:20
kodapawhen restarting nova-network, the dnsmasq entry is added again13:20
zynzelkodapa: i dont know if it is patched in official repo ;)13:21
kodapahow do we apply the patch13:21
notmynameLinuxJedi: thanks13:22
notmynameGlacee: ya. going to RAX QA this week and scheduled for official release on thursday (assuming nothing comes up that would delay it)13:23
notmynameLinuxJedi: this is the only one that needs to get through today. it "unsticks" dev for the next release. once this gets in, we can deal with the rest tomorrow13:23
ttxnotmyname: yo13:24
*** paulmillar has quit IRC13:24
Madkissi guess I should get the swift part for my howto online, then13:24
ttxnotmyname: 576be4d77e looks like something I could cut milestone-proposed from ?13:26
notmynamettx: ya, I was going to give it to you as soon as the 1.5.1 version bump went through13:27
*** osier_ has joined #openstack13:27
notmynamejust to make sure nothing weird happened13:27
LinuxJedinotmyname: re-triggered the swift patch, should be in shortly13:27
notmynameLinuxJedi: thanks13:27
notmynamettx: once the retriggered patch gets in, that's the commit to use13:28
ttxnotmyname: I'll wait for your email.13:28
ttx(will probably do it in tomorrow's european morning anyway)13:28
notmynamettx: ok, it went through. consider this my official notification :-)13:30
LinuxJedinotmyname: merged13:31
souzaHello guys13:31
notmynameLinuxJedi: thanks13:31
notmynamettx: 576be4d77efc57b7ee20f0207845349de9960b1b is the commit id13:31
ttxnotmyname: ack13:31
souzai'm having a problem to install a remote compute node in essex with ubuntu 12.04, in logs i got "error: [Errno 111] ECONNREFUSED" and looking above i saw this message "AMQP server on localhost:5672 is unreachable", i've installed rabbitmq, but it doesn't solve the problem.13:33
Madkisswrong endpoint configuration in keystone?13:33
souzaMadkiss: sorry, i don't understand.13:35
*** shaon has quit IRC13:36
Madkisshow did you set up keystone?13:37
*** salgado is now known as salgado-brb13:38
*** roge has joined #openstack13:38
*** leifmadsen has quit IRC13:39
*** fukushima has quit IRC13:40
souzaMadkiss: humm, let me see ...13:41
*** dachary has joined #openstack13:44
*** salgado-brb has quit IRC13:45
souzaMadkiss: look here >
zynzelsouza: grep rabbit /etc/nova/nova.conf on new compute node13:49
souzazynzel: grep? This > ?13:51
zynzelsouza: 'grep rabbit /etc/nova/nova.conf' check this command ;)13:51
*** SplasPood has quit IRC13:52
*** sstent has quit IRC13:52
souzazynzel: humm, works, but its showing the controller node ip >> "--rabbit_host="13:52
*** sstent has joined #openstack13:52
souzazynzel: must to be working not?13:52
zynzelsouza: you have any working compute node?13:53
zynzelmaybe on controller node?13:53
souzazynzel: i have some VM's in controller node.13:54
zynzelsouza: so run 'grep rabbit /etc/nova/nova.conf' on controller node13:54
souzai got the same: "--rabbit_host="13:54
souzazynzel: i got the same: "--rabbit_host="13:55
zynzelsouza: try 'telnet 5672' on controller node13:55
souzai can enter in telnet, it shows "Conected to ... ", "Escape char is ^]"13:56
zynzelsouza: great, now try this from new compute node13:57
Madkisshaha, i love it when a plan comes together.13:57
souzazynzel: i'm in too.13:57
souzazynzel: i got a "Connection closed by foreign host."13:58
zynzelsouza: immediately affter connection? or after some time/you write smth?14:00
keruspeIs there a place where the dependencies of each of the openstack components are listed exhaustively ?14:01
souzazynzel: not immediately, after five seconds ou more, maybe14:01
souzaor *14:01
zynzelsouza: so rabbit probably is working14:01
zynzelplz paste all log from nova-compute14:02
souzazynzel: ok, this a moment14:02
keruspe(I'm trying to package it for my distro)14:03
souzazynzel: here it is >
zynzelsouza: strange, nova-compute try to connect to localhost14:07
zynzelnot to
zynzelcan you paste config && restart nova-compute service?14:08
souzazynzel: yeah, i saw this, this got myself confused14:08
souzazynzel: the conf files, or the log?14:09
zynzelconf file14:09
souzazynzel: nova compute has only this line > "--libvirt_type=kvm"14:11
zynzelsouza: and nova.conf?14:11
souzazynzel: here >
*** dwcramer has joined #openstack14:12
zynzelsouza: plz paste full log of nova-compute restart14:13
souzazynzel: >>
souzai can't paste it in paste bin, because its too big14:15
*** davidha has quit IRC14:15
*** davidha has joined #openstack14:16
zynzel"It seems you don't belong here! You should probably sign in. Check out our"14:16
souzazynzel: fu*k just a momment.14:17
souzazynzel: try this >
*** SplasPood has joined #openstack14:18
zynzel"2012-05-28 09:17:26 DEBUG nova.service [-] rabbit_host : localhost from (pid=14662) wait /usr/lib/python2.7/dist-packages/nova/"14:20
zynzelyou sure you paste goot config? from good node? ;)14:20
souzawell, i think yes, no?14:21
souzai post the config to remote node14:21
zynzelsouza: you use ubuntu?14:22
souzayes, 12.0414:22
zynzelsouza: "grep 'rabbit_host' /etc/nova/nova.conf ; su -c nova-compute --flagfile=/etc/nova/nova.conf --flagfile=/etc/nova/nova-compute.conf nova"14:23
zynzelon this node14:23
souzai got this >>
zynzelgrep 'rabbit_host' /etc/nova/nova.conf; su -c "nova-compute --flagfile=/etc/nova/nova.conf --flagfile=/etc/nova/nova-compute.conf" nova14:25
souzaits asking for a password14:26
souzai tried the machine password, but i got a Authentication failure14:27
zynzellog as a root14:27
souzait just print > "--rabbit_host="14:27
souzazynzel: using sudo user14:27
zynzelsouza: log as a root, and try again.14:27
souzai got that print logged as root: "--rabbit_host="14:28
zynzelnow check log file ;)14:29
*** littleidea has joined #openstack14:30
praefectHey guys, we are scaling up! we will get a /21 and I was wondering if any of you define more than one floating network to address a larger space (can you run multiple "nova-manage floating create" to extend the floating range) ? will openstack automatically use the next available CIDR range when he gets there?14:30
souzazynzel: the log file keep the same, any changes14:30
praefectwe're talking 2000+ IPs14:30
souzai tried start the compute again, but if i try get status, it returns stopped14:31
zynzelsouza: "grep rabbit_host /var/log/nova/nova-compute.log" returns always localhost?14:32
souzait returns "localhost from (pid=14662) wait /usr/lib/python2.7/dist-packages/nova/"!14:33
*** cooper has joined #openstack14:33
zynzelsouza: 'ls -la /etc/nova'14:33
souzazynzel: >>
zynzelchown nova:nova /etc/nova/nova.conf and restart service14:35
souzazynzel: WOW14:36
souzazynzel: it works now14:36
zynzelgreat ;)14:37
*** avoine has joined #openstack14:37
souzazynzel: thanks i'll lunch now, thank you very much really!14:37
*** rnorwood has joined #openstack14:37
zynzelno problem :)14:38
keruspeNoone knows what openstack requirements are ?14:58
*** maploin has quit IRC14:59
*** littleidea has quit IRC15:02
*** nmistry has joined #openstack15:26
*** littleidea has joined #openstack15:27
GlaceeAnyone had the problem that a  swift proxy server in a starting states really affects the overall performance of the system until it starts back properly?16:06
*** hunglin has joined #openstack16:39
*** mindpixel has quit IRC16:39
Madkiss Error uploading image: (BackendException): Failed to add object to Swift. Got error from Swift: put_object('glance', 'f6663ab7-73c6-4435-829a-bfa415074839', ...) failure and no ability to reset contents for reupload.16:43
*** primozf has quit IRC16:43
*** hunglin has quit IRC16:47
*** aspiers has quit IRC17:32
*** b1rkh0ff has joined #openstack17:44
*** aspiers has joined #openstack17:45
*** hunglin has joined #openstack17:45
*** maplebed has joined #openstack17:53
manu1I'm currently getting this error via the OpenStack dashboard: Unable to fetch volumes: n/a - I think it's because the dashboard code is attempting to get the volume details from the compute API port (8774) and not the volume API port (8776)18:03
manu1This is the call that is failing: curl -i http://10.y.y.y:8774/v2/ZZZ/volumes/detail -X GET -H "X-Auth-Project-Id: ZZZ" -H "User-Agent: python-novaclient" -H "Accept: application/json" -H "X-Auth-Token: XXX"18:04
manu1Note port 8774 instead of 8776. If I use port 8774 I get a 404... if I change the port to 8776 I get a "HTTP/1.1 300 Multiple Choices" response...18:05
manu1I'm trying to figure out where I need to change this variable... as the value in the keystone database for the service catalog for the volume service is: http://10.y.y.y:8776/v1/%(tenant_id)s18:07
manu1(note the version numbers don't match either)18:07
manu1It's as if the endpoints in the keystone service catalog are being ignored entirely...18:08
*** jedi4ever has joined #openstack18:09
*** dtroyer_zzz is now known as dtroyer18:14
*** warik has joined #openstack18:17
*** matwood has joined #openstack18:19
*** _ozstacker_ has quit IRC18:44
*** bzzz has joined #openstack18:48
bzzzcan some one help with a question?18:49
manu1hi bzzz, I can try.18:49
bzzzhow can i add multiple projects?18:49
bzzzi mean, i added them on dashboard18:49
bzzzbut everytime i want to start a vm on a project (different from main one) i get the nomorenetworks error18:50
*** ozstacker has quit IRC18:50
bzzzi see in sql that the current fixed ip range is assigned only to the main project..18:50
*** warik has quit IRC18:50
bzzzis there a way to make all projects use the same network?18:50
bzzzthe main project works perfectly18:51
manu1It's a bit out of my depth, bzzz - but I imagine that you need to assign a network range to each project.18:51
manu1I'd try that first to ensure that isn't the issue.18:51
bzzzusing nova-manage network add ... right?18:52
manu1bzzz - are you using the Essex release?18:55
*** dtroyer_zzz is now known as dtroyer18:56
bzzzhmm, yes, think so... i got it from ubuntu repos18:56
*** dtroyer is now known as dtroyer_zzz18:58
bzzzyes, essex18:58
manu1Then yes, use nova-manage network add18:58
bzzzok, thank you!18:59
manu1bzzz, not guaranteed to work - but may fix your issue... if that doesn't work, you might try tweaking the num_networks setting19:02
bzzzright, i will check, thx19:02
*** Free_maN has quit IRC19:03
*** aspiers has quit IRC19:03
*** dtroyer_zzz is now known as dtroyer19:04
*** notmyname has quit IRC19:07
*** garyk has joined #openstack19:08
*** notmyname has joined #openstack19:08
*** ChanServ sets mode: +v notmyname19:08
bzzzthx again for the tip manu1, it worked ;)19:11
manu1glad to hear :)19:12
*** nati_ueno has joined #openstack19:12
*** aspiers has joined #openstack19:15
*** zul has joined #openstack19:36
dingdengdoes security group have any effect on private/fixed interfaces? e.g. instances in security groups A can not ping instances in the default security group.20:15
manu1dingdeng: I don't know the exact answer to your question, but have you looked at the iptables rules? That will give you a more direct answer to your question... (look at the source / destination fields - if they say 'anywhere' - the secgroup A and default should be able to communicate...)20:21
manu1if they specify a source and destination IP range, then only those IPs will be able to speak to the machines in question.20:22
dingdengmanu1: the default secgroup allows nothing, but it seems i am able to communicate instances in the default secgroup from instances in other secgroups.20:26
*** nati_ueno has quit IRC20:26
*** aa has joined #openstack20:27
manu1dingdeng: What does this show - nova secgroup-list-rules default ?20:27
manu1mine shows this:20:28
manu1| IP Protocol | From Port | To Port |  IP Range | Source Group |20:28
manu1| icmp        | -1        | -1      | |              |20:28
manu1| tcp         | 22        | 22      | |              |20:28
manu1That means allow all ICMP (ping) traffic and allow SSH20:28
manu1dingdeng: You may be able to communicate with instances in the default secgroup due to a bug in essex (that I've seen)20:29
*** natea|afk is now known as natea20:29
*** ryanpetrello has joined #openstack20:29
dingdengmanu1: do you remember the bug id?20:29
manu1I don't know if the bug has been reported.20:29
manu1I just saw this bug last week.20:29
manu1actually, now that I look at it again, the firewall rules are still wrong on the main cloud controller node... but correct on the other compute nodes20:30
*** aspiers has quit IRC20:33
manu1dingdeng: Look here for an example (although the exact command line is wrong, you'll have to remove the '-s' flag I think from the secgroup-add-rule commands at the top):
dingdengmanu1: i want to restrict access from instances in other secgroups :(20:33
manu1by default: no instances should be able to communicate... default is DENY, I believe.20:34
manu1keep in mind that you can communicate /out/... just not /in/20:34
manu1that is, if one machine pings another machine, that should go through because the openstack instance initiated the ping (I think this is right, but I may be wrong)20:35
*** Razique has joined #openstack20:35
zykes-Razique: .20:35
zykes-working late20:35
Raziquegotta finish some kvm stuff20:35
Raziquefor the diablo -> essex migration20:36
RaziqueI need to migrate all the running instances20:36
*** cooper has quit IRC20:36
*** tpot has joined #openstack20:37
dingdengmanu1: yes, the default is deny, but it seems i still can access instances in other secgroups...20:38
*** matwood has quit IRC20:38
*** PiotrSikora has quit IRC20:40
*** aspiers has joined #openstack20:45
*** matwood has joined #openstack20:46
zykes-where can I find puppet manifests for openstack ?20:46
alekibangohi. ubuntu 12.4 contains essex?20:47
zykes-alekibango: yes :p20:47
alekibangozykes-: ...20:47
zykes-alekibango: I thought you where the openstack guru ?20:47
dingdengmanu1: there is an iptables rule which allow access from the whole private network (which i created with nova-manage network create), is this the expected behavior?20:47
alekibangozykes-: i was forced to stop openstacking for a year, and i written my own nova and swift clone during that time :)20:48
alekibangonow i would like to join the openstack again20:48
zykes-alekibango: why ? :/20:48
alekibangozykes-: special customer requirements20:48
zykes-that openstack didn't support or ?20:49
zykes-sounds weeeeird20:49
alekibangoexample: specifying number of copies in swift20:49
alekibangolowering number of copies in time20:49
zykes-number of replicas ?20:49
alekibangoi ended up writing my own and i learned a lot by the time :)20:50
*** koolhead17 has joined #openstack20:50
manu1dingdeng: There should be IP tables rules for every instance... they look something like this:20:50
zykes-alekibango: sounds kinda sad20:50
alekibangozykes-: and i am not really using ubuntu, so i do not know :)20:50
alekibangozykes-: it was fun20:50
alekibangoand it was paid20:50
*** pixelbeat has joined #openstack20:50
zykes-alekibango: what company you working for ?20:51
manu1dingdeng: sending it to you in a private message20:51
alekibangonot sure i can tell,  a provider in czech republic20:51
alekibango~500-700 servers20:51
*** oubiwann has quit IRC20:52
*** jedi4ever has quit IRC20:52
*** ryanpetrello has quit IRC20:52
alekibangobut now i would like to use openstack again, so i am looking around for a fine way to install essex20:53
zykes-ubuntu is really easy20:54
alekibangoi will prolly use saltstack for configuration management20:54
zykes-or fairly20:54
alekibangozykes-: not really, ubuntu is not systematic20:54
alekibangoits just hack which might work20:54
zykes-why not puppet ?20:54
alekibangoi somehow fail to love ruby that muhc20:54
alekibangopython = love20:55
zykes-alekibango: yeah20:55
zykes-but check out EMC Razor (Puppetlabs now) and Puppet20:55
zykes-seems really cool20:55
alekibangoi have seen it and its nice20:55
alekibangobut i cant love it20:55
zykes-pfft ;p20:55
alekibangoyou know, its like asking me to write java code... i might, maybe, but it would suck20:56
alekibangojava always does suck20:56
alekibangolast time i was using it (around 1.1 release)20:57
alekibangosmall app was eating all available memory of my sgi indy workstation20:57
zykes-I think that really depends on who writes it :p20:58
zykes-RedHat does alot of cool Java stuff20:58
alekibangoyes they does20:58
zykes-RHEV-M 3.0 for one20:58
alekibangothey do* :)20:59
alekibangolol  ineed some tea20:59
manu1I'm currently getting this error via the OpenStack dashboard: Unable to fetch volumes: n/a - I think it's because the dashboard code is attempting to get the volume details from the compute API port (8774) and not the volume API port (8776)20:59
manu1This is the call that is failing: curl -i http://10.y.y.y:8774/v2/ZZZ/volumes/detail -X GET -H "X-Auth-Project-Id: ZZZ" -H "User-Agent: python-novaclient" -H "Accept: application/json" -H "X-Auth-Token: XXX"20:59
manu1Note port 8774 instead of 8776. If I use port 8774 I get a 404... if I change the port to 8776 I get a "HTTP/1.1 300 Multiple Choices" response...20:59
manu1I'm trying to figure out where I need to change this variable... as the value in the keystone database for the service catalog for the volume service is: http://10.y.y.y:8776/v1/%(tenant_id)s (note the version numbers don't match either)20:59
manu1It's as if the endpoints in the keystone service catalog are being ignored entirely...20:59
alekibangozykes-: in the page i linked to you, search for puppet20:59
alekibangoand you will find some20:59
alekibangozykes-: but i am more like fai and python :)21:00
alekibangoand fabric (
alekibango-> is imho really good for pythonists21:00
alekibangozykes-: and i do have my own automated installer -- ~ 100 kb)21:00
alekibangono need for getting in touch with puppet21:01
zykes-fai ?21:01
*** h0cin has quit IRC21:01
*** rmartinelli has quit IRC21:01
alekibangoautomated installation of debian21:01
*** esm_ has joined #openstack21:01
alekibango(and ubuntu, and also others)21:02
zykes-I'm gonna do Razor21:02
zykes-or dell crowbar for bigger deployment21:02
alekibangofreedom is good21:02
*** lborda has joined #openstack21:03
*** qazwsx has joined #openstack21:06
*** lborda has quit IRC21:08
dingdengmanu1: $ instead of %.21:14
zykes-alekibango: why not make some of the stuff you did coding into swit?21:14
zykes-and nova21:14
alekibangozykes-: you know, havin small environment you can controll is easier when you code21:15
alekibangobut do not worry, i will try in this year21:15
zykes-what company you working for ?21:15
alekibangofor myself21:15
manu1dingdeng: I'm using the Essex release 2012.121:15
manu1dingdeng: Are you on Essex 2012.1 as well?21:16
dingdengmanu1: yes, /v1/$(tenant_id)s on port 8776 works fine here.21:17
*** flaviamissi has quit IRC21:17
manu1thanks dingdeng - I'll look into it to see if that works.21:18
dingdengmanu1: :)21:19
Madkissdingdeng: % and $ shouldn't make a difference, btw. both work equally well here, just ftr.21:24
*** davidha has quit IRC21:29
*** davidha has joined #openstack21:30
*** fukushima has joined #openstack21:37
evanjfraserHey guys, I have a VM that is stuck in Task: "Deleting".21:40
evanjfraserhow may I fix it?21:40
manu1evanjfraser: You will want to check to see if the instance is still around via virsh list --all21:44
evanjfraserhi manu1 thanks, it's not.  that hypervisor is no longer available either.21:44
manu1if it's not, you can safely remove it from the mysql database via a DELETE where instance='instance-foo' LIMIT 1; (or something like that)21:44
evanjfraserthanks heaps21:44
manu1or you can just update it's status instead of deleting it in the mysql database (this would be safer)21:45
*** b1rkh0ff has quit IRC21:45
evanjfraserok thanks again manu121:48
*** hunglin has joined #openstack22:02
*** arosen1 has joined #openstack22:03
arosen1How can I figure out what the tenant_id is for the default tenant?22:03
*** msavy has quit IRC22:10
*** aspiers has joined #openstack22:15
*** leifmadsen has quit IRC22:19
evanjfraserso the /var/lib/nova/instances dir on hypervisor systems...22:53
evanjfraserthat holds base images and any persistent writes correct?22:53
evanjfraserbase "deployed" images that is.22:54
evanjfraserif I delete all VM's, why doesn't the _base directory get cleaned up?22:54
evanjfraserstill trying to get my brain around how the storage in openstack works.22:55
evanjfrasergoing by this article: it looks like we have to manually cleanup unused base images?23:01
*** lborda has quit IRC23:04
*** lborda has quit IRC23:11
*** flaviamissi has joined #openstack23:34
*** aspiers has joined #openstack23:45
