Thursday, 2019-02-14

georgkmattmceuen in our case, barbican in fact tries to talk to keystone through the keystone ingress which gets tied to the d42.se domain. Please see https://hastebin.com/naxepoyahu.css00:01
georgkit might be a configuration problem on our side, however, not sure show to fix it00:02
evgenylgeorgk: sorry if you already answered this question, but have you configured certificates for this domain?00:04
georgkmattmceuen a part of the certification troube is caused by the certificate being self-signed, ie. there is no trust chain to a valid root CA. We are wondering if a cert signed by a CA is really needed, even for lab deployments00:05
georgkevgenyl does my last post answer your question?00:05
evgenylgeorgk: Oh, it does, this explains the error.00:05
georgkevgenyl we are currently waiting for getting a signed cert.00:06
evgenylgeorgk: there is a way to configure it without ssl (we strongly do not recommend doing that even for labs).  In order to configure it without ssl, you will need to change all these parameters from https to http and from 443 to 80 https://github.com/openstack/airship-treasuremap/blob/master/site/airship-seaworthy/software/config/endpoints.yaml#L72-L7800:07
georgkwhat domain names and certs are you using in lab deployments?00:07
georgkevgenyl ok, thanks00:08
evgenylWe are using valid certificates and domain names.00:08
evgenylHere is a place where you will need to put your certs, when you get them https://github.com/openstack/airship-treasuremap/blob/master/site/airship-seaworthy/secrets/certificates/ingress.yaml00:09
georgkevgenyl I don't mean the concrete domains and certs, but rather is every lab or CI deployment requires valid certs (I guess the answer is yes)00:09
georgkok, ok00:09
georgkwell, simple answer then and our approach was too simple then00:10
georgkthanks a lot00:10
evgenylYes, every lab requires a valid certs, but you can get a wildcard cert if all your labs are under same .subdomain00:10
evgenylgeorgk: Sure, let me know if you get any other questions, I will probably need to update treasuremap docs to explicitly specify that valid certificates are required for the deployment.00:13
georgkI will. Again, thanks a lot!00:13
*** aaronsheffield has quit IRC00:26
*** sthussey has quit IRC01:17
*** mbologna has quit IRC01:41
*** mbologna has joined #airshipit01:42
openstackgerritJared Miller proposed openstack/airship-treasuremap master: Disable weak tls ciphers for kube-apiserver  https://review.openstack.org/63675401:55
openstackgerritCraig Anderson proposed openstack/airship-divingbell master: Use common logger for consistent log output  https://review.openstack.org/63681602:31
*** mbologna has quit IRC03:04
*** mbologna has joined #airshipit03:06
*** mbologna has quit IRC03:25
*** mbologna has joined #airshipit03:26
openstackgerritMerged openstack/airship-treasuremap master: airskiff: Update OSH-infra pin  https://review.openstack.org/63674703:36
*** mbologna has quit IRC04:24
*** nishant_ has quit IRC04:24
*** mbologna has joined #airshipit04:25
*** jamesgu has quit IRC05:12
*** mbologna has quit IRC05:25
*** mbologna has joined #airshipit05:27
*** mbologna has quit IRC05:45
*** mbologna has joined #airshipit05:46
openstackgerritchittibabu proposed openstack/airship-pegleg master: Add CLI to create Salt Key  https://review.openstack.org/63608906:35
openstackgerritchittibabu proposed openstack/airship-pegleg master: Add CLI to create Salt Key  https://review.openstack.org/63608907:21
*** stefanb has joined #airshipit07:31
*** stefanb has left #airshipit07:50
openstackgerritchittibabu proposed openstack/airship-pegleg master: Add CLI to create Salt Key  https://review.openstack.org/63608907:54
openstackgerritDmitrii Kabanov proposed openstack/airship-maas master: Add package repositories  https://review.openstack.org/63684807:55
openstackgerritDmitrii Kabanov proposed openstack/airship-maas master: Add package repositories  https://review.openstack.org/63684807:59
openstackgerritDmitrii Kabanov proposed openstack/airship-maas master: Add package repositories  https://review.openstack.org/63684808:25
*** lemko has joined #airshipit09:11
*** rihbb has joined #airshipit09:50
*** rihbb has quit IRC10:44
*** roman_g has joined #airshipit11:12
*** vdrok has joined #airshipit11:49
openstackgerritRoman Gorshunov proposed openstack/airship-deckhand master: Embed UML generated diagrams into docs  https://review.openstack.org/63535711:49
openstackgerritRoman Gorshunov proposed openstack/airship-deckhand master: Embed UML generated diagrams into docs, fix docs build  https://review.openstack.org/63535713:12
*** pkaralis has quit IRC13:30
*** pkaralis has joined #airshipit13:36
*** aaronsheffield has joined #airshipit13:53
openstackgerritchittibabu proposed openstack/airship-pegleg master: Add CLI to create Salt Key  https://review.openstack.org/63608914:41
*** mbeierl has quit IRC15:04
*** roman_g has quit IRC15:16
*** peyunco has joined #airshipit15:30
*** michael-beaver has joined #airshipit15:32
*** rihbb has joined #airshipit15:33
*** peyunco has quit IRC15:39
*** rihbb has quit IRC15:39
openstackgerritKaspars Skels proposed openstack/airship-treasuremap master: Secret rotation and validation  https://review.openstack.org/63569415:47
*** michaelbeaver has joined #airshipit15:58
openstackgerritDrew Walters proposed openstack/airship-treasuremap master: airskiff: Pull rather than build Airship images  https://review.openstack.org/63523116:00
*** michael-beaver has quit IRC16:01
*** mbeierl has joined #airshipit16:01
mbeierlIs there a meeting at this time today?16:01
dwaltmbeierl: Airship Design call! Starts now: https://attcorp.webex.com/meet/rp272316:02
mbeierlthanks, dwalt16:02
*** michael-beaver has joined #airshipit16:02
*** michaelbeaver has quit IRC16:05
*** michael-beaver has quit IRC16:06
*** michaelbeaver has joined #airshipit16:06
mbeierlwhere's the etherpad?  Sorry for being so scatterbrained.16:07
*** michael-beaver has joined #airshipit16:09
*** michaelbeaver has quit IRC16:10
openstackgerritBryan Strassner proposed openstack/airship-shipyard master: User context tracing through logging  https://review.openstack.org/63387316:43
*** aagate has joined #airshipit17:04
*** sreejithp has joined #airshipit17:05
*** sthussey has joined #airshipit17:05
*** michael-beaver has quit IRC17:05
*** ianychoi has joined #airshipit17:06
*** dustinspecker has joined #airshipit17:08
openstackgerritBryan Strassner proposed openstack/airship-shipyard master: User context tracing through logging  https://review.openstack.org/63387317:22
*** mbeierl has quit IRC17:48
openstackgerritJagan Mohan Kavva proposed openstack/airship-promenade master: UCP: Enable pod priority feature gate in K8s  https://review.openstack.org/63478017:54
*** michael-beaver has joined #airshipit18:00
*** mbeierl has joined #airshipit18:02
*** shoaibwr has quit IRC18:26
*** shoaibwr has joined #airshipit18:26
*** dims has quit IRC18:47
dwaltmbeierl: sorry, I didn’t see this earlier. It’s https://etherpad.openstack.org/p/Airship_OpenDesignDiscussions for future reference!18:55
mbeierlya, I got it from the Webex screen18:55
mbeierlwas easy to read/paste, thanks dwalt!18:56
dwaltsure thing mbeierl!18:56
dwaltI am looking for the best way to add certificates to nodes deployed by drydock. Would the best way to accomplish this be using a bootaction? I have not been able to find anything that says maas allows for this, so I’m assuming this is not a supported feature in drydock.18:59
dwaltI should clarify, though: I need the cert to be present during commissioning19:02
*** mbologna has quit IRC19:13
*** mbologna has joined #airshipit19:14
*** sreejithp_ has joined #airshipit19:22
*** sreejithp has quit IRC19:24
openstackgerritchittibabu proposed openstack/airship-pegleg master: Add CLI to create Salt Key  https://review.openstack.org/63608919:25
openstackgerritdiwakar thyagaraj proposed openstack/airship-promenade master: UCP: Enable Audit Logging feature gate in K8s  https://review.openstack.org/63556819:42
*** rihbb has joined #airshipit19:47
*** michael-beaver has quit IRC19:49
rihbbHello, While deploying site with shipyard the following command throws an error: + sudo docker run -t --rm --net=host -e http_proxy= -e https_proxy= -e no_proxy= -e OS_AUTH_URL=http://keystone.ucp.svc.cluster.local:80/v3 -e OS_USERNAME=shipyard -e OS_USER_DOMAIN_NAME=default -e OS_PASSWORD=password -e OS_PROJECT_DOMAIN_NAME=default -e OS_PROJECT_NAME=service quay.io/airshipit/shipyard:6bd02eea8477bba077848463e7e740efe12fa782 commit19:56
rihbbError: Validations failed Reason: Validation - Error: Required substitution source document [deckhand/CertificateAuthority/v1] kubernetes was not found, yet is referenced by [armada/Chart/v1] kubernetes-scheduler19:56
rihbbAny hints on what could be throwing this error? Thanks19:57
*** michael-beaver has joined #airshipit19:59
*** dustinspecker has quit IRC20:00
*** lemko has quit IRC20:09
openstackgerritJenkins Uplifter proposed openstack/airship-treasuremap master: Auto chart/image uplift to latest  https://review.openstack.org/63704020:12
dwaltrihbb: is this in Airship-in-a-Bottle, treasuremap, or for a site you are authoring?20:50
*** mbologna has quit IRC21:06
rihbbdwalt: Its a multinode site using the instructions which we are setting up using instructions described in https://airship-treasuremap.readthedocs.io/en/latest/authoring_and_deployment.html21:06
rihbbHowever shipyard throws validation errors. Any idea about the reason for this issue? The genesis install was successful.21:09
sthusseyIt looks like you aren't including the certificates you generated for genesis in the site definition21:12
*** mbologna has joined #airshipit21:15
*** mbologna has quit IRC21:19
openstackgerritMerged openstack/airship-in-a-bottle master: Disable start of local docker registry  https://review.openstack.org/63598521:29
-openstackstatus- NOTICE: Jobs are failing due to ssh host key mismatches caused by duplicate IPs in a test cloud region. We are disabling the region and will let you know when jobs can be rechecked.21:30
*** mbologna has joined #airshipit21:53
*** lemko has joined #airshipit21:57
-openstackstatus- NOTICE: The test cloud region using duplicate IPs has been removed from nodepool. Jobs can be rechecked now.22:12
*** mbeierl has quit IRC22:18
*** rihbb has quit IRC22:20
openstackgerritMerged openstack/airship-treasuremap master: Auto chart/image uplift to latest  https://review.openstack.org/63704022:33
*** shoaibwr has quit IRC22:37
*** sreejithp_ has quit IRC22:39
openstackgerritMichael Beaver proposed openstack/airship-armada master: Support in Armada for locking Tiller  https://review.openstack.org/63248323:08
*** mbeierl has joined #airshipit23:13
*** michaelbeaver has joined #airshipit23:42
*** michael-beaver has quit IRC23:45
*** michaelbeaver has quit IRC23:46

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!