Thursday, 2015-07-16

openstackgerritMiguel Grinberg proposed stackforge/os-ansible-deployment: Keystone Federation Service Provider Configuration  https://review.openstack.org/19439500:03
*** galstrom_zzz is now known as galstrom00:13
openstackgerritMatthew Kassawara proposed stackforge/os-ansible-deployment: Document required repository hosts config info  https://review.openstack.org/20225800:25
*** britthouser has joined #openstack-ansible00:28
*** annashen has joined #openstack-ansible00:32
*** annashen has quit IRC00:33
openstackgerritKevin Carter proposed stackforge/os-ansible-deployment: Added in keystone reserved port  https://review.openstack.org/19670200:35
openstackgerritKevin Carter proposed stackforge/os-ansible-deployment: Updated master for new dev work - 07.07.2015  https://review.openstack.org/19912600:38
openstackgerritMiguel Grinberg proposed stackforge/os-ansible-deployment: Keystone Federation Service Provider Configuration  https://review.openstack.org/19439500:43
*** galstrom is now known as galstrom_zzz00:49
*** javeriak has quit IRC01:09
*** openstack has joined #openstack-ansible01:25
openstackgerritMerged stackforge/os-ansible-deployment: Adjust swift_rings.py to work on specified regions  https://review.openstack.org/20011401:37
openstackgerritMerged stackforge/os-ansible-deployment: Adjust swift_rings.py to work on specified regions  https://review.openstack.org/20011401:37
openstackgerritKevin Carter proposed stackforge/os-ansible-deployment: Implement Ceilometer  https://review.openstack.org/20124402:14
openstackgerritKevin Carter proposed stackforge/os-ansible-deployment: Upgrade the Keystone library to use v3  https://review.openstack.org/20224202:14
openstackgerritKevin Carter proposed stackforge/os-ansible-deployment: Add v3 calls for federation to keystone module  https://review.openstack.org/20224302:14
*** galstrom_zzz is now known as galstrom02:14
openstackgerritMiguel Grinberg proposed stackforge/os-ansible-deployment: [WIP] Keystone IdP configuration  https://review.openstack.org/19425902:17
*** markvoelker has quit IRC02:22
openstackgerritMiguel Grinberg proposed stackforge/os-ansible-deployment: [WIP] Keystone IdP configuration  https://review.openstack.org/19425902:22
*** galstrom is now known as galstrom_zzz02:46
*** sdake_ has joined #openstack-ansible02:53
openstackgerritKevin Carter proposed stackforge/os-ansible-deployment-specs: New spec for compartementalize-rabbitmq  https://review.openstack.org/20236302:57
*** sdake has quit IRC02:57
*** sacharya has joined #openstack-ansible03:02
openstackgerritKevin Carter proposed stackforge/os-ansible-deployment-specs: Added spec to enable systemd support within OSAD  https://review.openstack.org/20236803:13
openstackgerritKevin Carter proposed stackforge/os-ansible-deployment-specs: Added spec to enable systemd support within OSAD  https://review.openstack.org/20236803:21
*** annashen has joined #openstack-ansible03:23
*** galstrom_zzz is now known as galstrom03:24
openstackgerritKevin Carter proposed stackforge/os-ansible-deployment-specs: Cleaned up specs directory  https://review.openstack.org/20237303:27
*** annashen has quit IRC03:28
*** britthou_ has joined #openstack-ansible03:30
*** britthouser has quit IRC03:33
*** markvoelker has joined #openstack-ansible03:33
*** markvoelker has quit IRC03:34
*** markvoelker has joined #openstack-ansible03:34
*** markvoelker_ has joined #openstack-ansible03:37
*** markvoelker has quit IRC03:39
*** rward has quit IRC03:44
*** serverascode has quit IRC03:45
*** rackertom has quit IRC03:45
*** sdake_ has quit IRC03:55
openstackgerritMatthew Kassawara proposed stackforge/os-ansible-deployment: Fix repo section in example config file  https://review.openstack.org/20237703:55
*** serverascode has joined #openstack-ansible03:59
*** annashen has joined #openstack-ansible04:08
*** rward has joined #openstack-ansible04:11
*** dabernie has left #openstack-ansible04:12
*** britthouser has joined #openstack-ansible04:15
*** tlian has quit IRC04:15
*** britthou_ has quit IRC04:16
*** rackertom has joined #openstack-ansible04:18
*** annashen has quit IRC04:28
*** markvoelker has joined #openstack-ansible04:49
*** galstrom is now known as galstrom_zzz04:49
*** markvoelker_ has quit IRC04:53
*** grumpycat has quit IRC05:00
*** daneyon has joined #openstack-ansible05:24
*** sacharya has quit IRC05:35
*** jmccrory has quit IRC06:02
*** jmccrory has joined #openstack-ansible06:09
*** annashen has joined #openstack-ansible06:12
*** annashen has quit IRC06:37
openstackgerritHugh Saunders proposed stackforge/os-ansible-deployment: Wait until mongo responds after restart  https://review.openstack.org/20124506:43
openstackgerritJimmy McCrory proposed stackforge/os-ansible-deployment: Allow configuration of all default quota options  https://review.openstack.org/20240306:48
*** markvoelker has quit IRC08:04
*** markvoelker has joined #openstack-ansible08:11
*** markvoelker has quit IRC08:16
*** markvoelker has joined #openstack-ansible08:17
*** markvoelker has quit IRC08:25
*** markvoelker has joined #openstack-ansible08:29
*** markvoelker has quit IRC08:33
*** markvoelker has joined #openstack-ansible08:44
*** markvoelker has quit IRC08:48
*** markvoelker has joined #openstack-ansible08:58
*** markvoelker has quit IRC09:03
openstackgerritMerged stackforge/os-ansible-deployment: Upgrade the Keystone library to use v3  https://review.openstack.org/20224209:05
openstackgerritMerged stackforge/os-ansible-deployment: Add v3 calls for federation to keystone module  https://review.openstack.org/20224309:07
openstackgerritMerged stackforge/os-ansible-deployment: Parameterize galera slow/unindexed logging options  https://review.openstack.org/20162509:07
*** annashen has joined #openstack-ansible09:38
*** annashen has quit IRC09:42
openstackgerritgit-harry proposed stackforge/os-ansible-deployment: Target AIO swift vars at specific containers  https://review.openstack.org/20164409:54
*** Apsu has quit IRC10:15
*** grumpycat has joined #openstack-ansible10:15
openstackgerritMerged stackforge/os-ansible-deployment: Add openstackclient to the keystone containers  https://review.openstack.org/20218910:16
*** Apsu has joined #openstack-ansible10:17
openstackgerritJesse Pretorius proposed stackforge/os-ansible-deployment: Fix haproxy service config when ssl is enabled  https://review.openstack.org/20248510:26
openstackgerritJesse Pretorius proposed stackforge/os-ansible-deployment: Keystone Federation Service Provider Configuration  https://review.openstack.org/19439510:49
*** vdo has joined #openstack-ansible10:50
openstackgerritJesse Pretorius proposed stackforge/os-ansible-deployment-specs: Keystone Service Provider with ADFS Identity Provider Deployment  https://review.openstack.org/19425510:54
mancdazodyssey4me "AnsibleUndefinedVariable: One or more undefined variables: 'keystone_service_externalurl_v3' is undefined"12:20
odyssey4memancdaz yep, busy fixing that12:21
mancdazodyssey4me ok cool, lemme know when you have something and I can carry on testing it12:22
odyssey4memancdaz s/externalurl/publicurl/12:22
odyssey4mein the horizon local settings template12:22
mancdazthanks12:24
*** markvoelker has joined #openstack-ansible12:29
*** KLevenstein has joined #openstack-ansible12:33
*** markvoelker has quit IRC12:34
openstackgerritJesse Pretorius proposed stackforge/os-ansible-deployment: Keystone Federation Service Provider Configuration  https://review.openstack.org/19439512:35
odyssey4memancdaz ^ fixed, with extra handling for SSL stuff12:35
*** markvoelker has joined #openstack-ansible12:43
*** markvoelker has quit IRC12:48
*** markvoelker has joined #openstack-ansible12:57
*** tlian has joined #openstack-ansible12:58
*** markvoelker has quit IRC13:02
*** markvoelker has joined #openstack-ansible13:05
*** markvoelker_ has joined #openstack-ansible13:06
*** markvoelker has quit IRC13:10
*** Bjoern_ has joined #openstack-ansible13:19
*** jmckind has joined #openstack-ansible13:22
*** sdake has joined #openstack-ansible13:25
mancdazodyssey4me my galera keeps dying13:27
*** TheIntern has joined #openstack-ansible13:34
*** jaypipes has joined #openstack-ansible13:35
*** KLevenstein has quit IRC13:43
*** erikmwilson has left #openstack-ansible13:45
*** sigmavirus24_awa is now known as sigmavirus2414:02
openstackgerritAndy McCrae proposed stackforge/os-ansible-deployment: Remove {{ from "with_items" and "when" statements  https://review.openstack.org/20258114:12
*** jwagner_away is now known as jwagner14:14
openstackgerritMarc GariĆ©py proposed stackforge/os-ansible-deployment: Fix example configuration file for package repository hosts.  https://review.openstack.org/20258814:20
*** jwagner is now known as jwagner_away14:21
*** markvoelker_ has quit IRC14:24
openstackgerritHugh Saunders proposed stackforge/os-ansible-deployment: Implement Ceilometer  https://review.openstack.org/20124414:29
openstackgerritHugh Saunders proposed stackforge/os-ansible-deployment: Wait until mongo responds after restart  https://review.openstack.org/20124514:29
cloudnullmorning14:31
*** hiddentoken has joined #openstack-ansible14:32
*** jmckind has quit IRC14:34
mgariepygood morning.14:35
*** jwagner_away is now known as jwagner14:36
*** hiddentoken has quit IRC14:51
*** jmckind has joined #openstack-ansible14:52
*** sacharya has joined #openstack-ansible14:53
*** markvoelker has joined #openstack-ansible14:53
*** sacharya has quit IRC14:57
*** daneyon_ has joined #openstack-ansible15:02
*** daneyon has quit IRC15:04
*** sdake has quit IRC15:11
*** sdake has joined #openstack-ansible15:17
sigmavirus24o/ mgariepy15:20
mgariepyhey sigmavirus2415:26
*** stevelle_ is now known as stevelle15:27
sigmavirus24how's it going mgariepy15:28
*** galstrom_zzz is now known as galstrom15:28
mgariepynot too bad yourself ?15:28
sigmavirus24I'm okay15:32
*** ig0r_ has quit IRC15:40
*** jmckind has quit IRC15:50
*** Mudpuppy has joined #openstack-ansible15:50
*** sacharya has joined #openstack-ansible15:53
*** KLevenstein has joined #openstack-ansible15:53
cloudnullmeeting time cloudnull, mattt, andymccr, d34dh0r53, hughsaunders, b3rnard0, palendae, Sam-I-Am, odyssey4me, serverascode, rromans, mancdaz, dolphm, _shaps_, BjoernT, claco, echiu, dstanek, jwagner, ayoung16:02
cloudnullin #openstack-meeting-416:02
*** yaya has joined #openstack-ansible16:03
*** ccrouch has left #openstack-ansible16:03
*** Bjoern_ is now known as BjoernT16:04
*** TheIntern has quit IRC16:04
*** alop has joined #openstack-ansible16:06
*** sdake_ has joined #openstack-ansible16:07
*** yaya has quit IRC16:08
*** sdake has quit IRC16:10
lbragstadodyssey4me: I have another revision up that is going through check right now, here is a diff of the patch if you want to pull it locally to your environment - http://cdn.pasteraw.com/dekqu6j2r75kvo80ijw7mcrgajskee7 (curl http://cdn.pasteraw.com/dekqu6j2r75kvo80ijw7mcrgajskee7 | git apply)16:10
lbragstadodyssey4me: patch - https://review.openstack.org/#/c/202176/516:11
*** yaya has joined #openstack-ansible16:19
openstackgerritgit-harry proposed stackforge/os-ansible-deployment: Serialise rabbitmq playbook to allow upgrades  https://review.openstack.org/20268116:21
odyssey4melbragstad great stuff, thanks - I'll see if I can spin a test up a little later... I've got to work through something else first - if not today, then tomorrow16:21
lbragstadodyssey4me: no worries, the review is very subject to criticism, just wanted to see if the path we're going down works for you. keep me posted if you run into anything16:22
lbragstadthe federation + fernet tests pass locally16:24
*** spotz_zzz is now known as spotz16:26
*** shaleh has joined #openstack-ansible16:29
*** alop has quit IRC16:32
*** alop has joined #openstack-ansible16:33
miguelgrinbergodyssey4me hughsaunders looks like neither of you did anything on the IdP side, correct? Let me know if I should wait for some new changes from you.16:42
hughsaundersmiguelgrinberg: nope, nothing new today16:42
miguelgrinbergokay, I'll keep moving along with that patch then16:43
*** annashen has joined #openstack-ansible16:45
* cloudnull lunching16:49
odyssey4memiguelgrinberg I've been moving on with testing the SP with ADFS and have hit an issue with SSL offloading at a load balancer - essentially the URL's don't match up with what Shibboleth expects. I've got one more thing to try out before we have to declare that Keystone will have to do its own SSL... which isn't particularly desirable.16:49
miguelgrinbergodyssey4me: what is the mismatch? The catalog has the https endpoint for public url right?16:55
odyssey4memiguelgrinberg the saml assertion posted back to shibboleth goes to https:// but shibboleth thinks it should be http://16:56
miguelgrinbergah, right, that makes sense16:56
miguelgrinbergI can take a look at the shibd code to see if there are any options to skip the check of the URL scheme16:57
odyssey4memiguelgrinberg sure, although I'm not sure that we should - but it'd be useful to know16:58
*** galstrom is now known as galstrom_zzz16:58
stevelleseems like shibboleth should have a config switch to tell it to observe the other headers to notice the ssl termination occurred16:59
odyssey4mestevelle there are ways to do it, eg we can set the servername to include https - but then we break our internal endpoint17:00
odyssey4mewe can also just make keystone's apache do ssl for the internal endpoint and make the lb do ssl passthrough17:01
*** dabernie has joined #openstack-ansible17:01
odyssey4meneither are ideal17:01
stevelleodyssey4me: in spite of the non-desirability the most secure configuration is to not do premature termination for keystone17:01
odyssey4meif there is another option, I'm all ears17:01
odyssey4mestevelle I would agree, however it appears that a lot of people are doing it17:01
*** TheIntern has joined #openstack-ansible17:03
stevelleI think setting the servername to include https is just plain wrong, and passing-through is better if those two are the only options but IIRC shib is a bit difficult17:03
stevelleso it may be17:04
*** yaya has quit IRC17:04
clacobig pile of shib?17:04
* claco drops mic17:05
miguelgrinbergodyssey4me: this page seems to indicate it is possible to have SSL terminated at a proxy/lb: https://wiki.shibboleth.net/confluence/display/SHIB2/SPReverseProxy17:05
miguelgrinbergall I can see is that the handlerSSL needs to be set to False17:06
odyssey4memiguelgrinberg yep, notice that they indicate that you need to change the ServerName and set UseCanonicalName17:06
odyssey4meyep, with handlerSSL true, shibboleth refuses to respond17:06
miguelgrinbergah yes17:07
*** yaya has joined #openstack-ansible17:07
miguelgrinbergwhat error do you get? let me find that in the code to see what's going on17:07
odyssey4meopensaml::BindingException at (http://104.130.175.111:5000/Shibboleth.sso/SAML2/POST)17:10
odyssey4meSAML message delivered with POST to incorrect server URL.17:10
odyssey4me ERROR OpenSAML.MessageDecoder.SAML2POST [6]: POST targeted at (https://104.130.175.111:5000/Shibboleth.sso/SAML2/POST), but delivered to (http://104.130.175.111:5000/Shibboleth.sso/SAML2/POST)17:11
*** JonathanD has joined #openstack-ansible17:18
miguelgrinbergodyssey4me: so there is no way to skip the http vs https checking, it checks the entire URL up to the query string start17:32
miguelgrinbergso I think for some reason apache is still reporting the http:// address to shibboleth17:33
miguelgrinbergand the only way to make this work is to make apache report https://17:33
odyssey4memiguelgrinberg yeah, I'm seeing if I can rewrite it or something like that17:33
miguelgrinbergstill haven't figured out exactly how shib gets the server address from apache, you would think it gets it from an env var, but can't find it17:34
dstanekmiguelgrinberg: what address?17:36
miguelgrinbergdstanek: the address where the service is listening17:37
miguelgrinbergwe have a shibd service listeining on http://, behind a haproxy that terminates SSL17:37
miguelgrinbergso shibd errors on that mismatch17:37
dstanekmiguelgrinberg: isn't it in the shibboleth2.xml?17:38
miguelgrinbergI don't think so, the only possible source can be the entityID value, but I don't think it cames from that17:39
*** annashen has quit IRC17:40
miguelgrinbergdstanek: this is actually not even shibboleth proper, the failure is in the opensaml library17:40
odyssey4menope, this is directly between apache and shibd and is an issue when apache is not doing ssl, but a remote ssl offloader is17:40
*** annashen has joined #openstack-ansible17:41
*** yaya has quit IRC17:44
*** annashen has quit IRC17:47
*** annashen has joined #openstack-ansible17:49
miguelgrinbergodyssey4me: have you done anything with the ShibURLScheme option in the apache config?17:50
dstanekwhen you say apache do you mean mod_shib?17:50
miguelgrinbergdstanek: yes17:50
miguelgrinbergodyssey4me: if ShibURLScheme is set, then that will replace the actual scheme used in the request17:51
odyssey4memiguelgrinberg that looks interesting - let me check that\17:51
miguelgrinbergfunny that the only way to find it is by reading code!17:51
odyssey4memiguelgrinberg hmm, different error now - but this may be a time related thing17:54
odyssey4melet me retry17:54
dstanekmarek is coming in17:56
odyssey4meinteresting, that also sets all the locations correctly now without having to use substitution17:57
*** marekd has joined #openstack-ansible17:57
marekddstanek: i am here.17:57
dstanekmiguelgrinberg: odyssey4me: are you guys still having the problem? marekd can help17:57
odyssey4menot quite sure yet - hang a minute17:57
*** jwitko has joined #openstack-ansible17:58
odyssey4menope, a whole new issue now...17:59
odyssey4meopensaml::FatalProfileException at (https://104.130.175.111:5000/Shibboleth.sso/SAML2/POST)17:59
odyssey4meA valid authentication statement was not found in the incoming message.17:59
marekdodyssey4me: which testshib?17:59
odyssey4memarekd this is with ADFS this time, but only using a SAML2 configuration18:00
odyssey4mehere's the shibd log: http://paste.openstack.org/show/381419/18:01
marekdodyssey4me: is it configured by ansible or still trying to configure it manually?18:01
odyssey4memarekd it was originally built by ansible - it's the same basic config as we used for TestShib, the difference being that SSL is now involved18:02
marekdodyssey4me: not really, for adfs you need shared lib to be loaded.18:03
odyssey4meah, that may explain the issue here - I've been testing to see if the extra libraries and stuff really are required18:03
*** Mudpuppy has quit IRC18:06
marekdodyssey4me: i can help with our cern internal tutorial18:07
marekdodyssey4me: http://linux.web.cern.ch/linux/scientific6/docs/shibboleth.shtml it starts here but the most intersting stuff is here: http://linux.web.cern.ch/linux/scientific6/docs/shibboleth/shibboleth2.xml | grep adfs.so18:08
*** KLevenstein is now known as KL-away18:08
*** yaya has joined #openstack-ansible18:09
*** sdake has joined #openstack-ansible18:13
odyssey4memarekd ok, this appears to be something to do with my bad ssl encryption - not the actual config18:15
odyssey4melet me relocate and continue when I get home - I think this may be resolved18:15
odyssey4methanks for the help marekd miguelgrinberg stevelle dstanek - chat again a bit later18:16
stevelleodyssey4me: sounds like good news18:16
stevellelaters18:16
*** sdake_ has quit IRC18:16
marekdodyssey4me: ok, good luck.18:19
odyssey4memarekd thanks for the pointers at those docs - there're a few tweaks there that'll be useful :)18:20
marekdodyssey4me: happy to help.18:21
openstackgerritKevin Carter proposed stackforge/os-ansible-deployment: Adds retries and Container create/system tuning  https://review.openstack.org/20226818:26
*** TheIntern has quit IRC18:27
*** jwagner is now known as jwagner_away18:37
*** jwagner_away is now known as jwagner18:59
*** annashen has quit IRC19:00
*** galstrom_zzz is now known as galstrom19:01
*** claco has left #openstack-ansible19:02
*** TheIntern has joined #openstack-ansible19:04
cloudnullwe need backport reviews on the following https://review.openstack.org/#/c/201245 https://review.openstack.org/#/c/20124419:05
*** sdake_ has joined #openstack-ansible19:08
odyssey4mecloudnull done :)19:10
cloudnulltyvm odyssey4me19:11
*** sdake has quit IRC19:11
*** Mudpuppy has joined #openstack-ansible19:30
*** bogeyon18 has joined #openstack-ansible19:33
*** annashen has joined #openstack-ansible19:33
*** harlowja has joined #openstack-ansible19:49
*** harlowja_ has quit IRC19:49
*** harlowja has quit IRC19:52
*** harlowja has joined #openstack-ansible19:53
*** KL-away is now known as KLevenstein19:58
openstackgerritIan Cordasco proposed stackforge/os-ansible-deployment: Add default keystone role and task to create it  https://review.openstack.org/20219420:00
*** jwagner is now known as jwagner_away20:39
*** KLevenstein has quit IRC20:46
odyssey4memarekd interestingly I have a successful auth without the adfs library loads in shibboleth - probably because I'm using ADFS v3 which can handle SAML220:56
marekdodyssey4me: cool!20:57
marekdodyssey4me: so, what was wrong previously?20:57
odyssey4meI think it was the way I created the SSL cert for the SP - it's key was too low, so Shibboleth refused to trust it - well, I saw something about blacklisted ciphers20:58
odyssey4methis round I did better20:59
marekdodyssey4me: ok, so what's left is ansiblizing it? :-)20:59
odyssey4memost of that's already done - I just have a few more tests to do before I upload the final tweaks21:00
*** metral is now known as metral_zzz21:25
*** mattt1 is now known as mattt21:26
*** mattt has quit IRC21:26
*** mattt has joined #openstack-ansible21:26
*** TheIntern has quit IRC21:31
*** yaya has quit IRC21:32
palendaecloudnull: Isn't there an ansible-playbook command I can run that'll generate an inventory file from teh user config, but not actually do the plays?21:33
cloudnullno, however you can run the inventory/dynamic_inventory.py script21:33
palendaeOk, was doing that21:33
cloudnullfrom the playbooks directory21:33
palendaeYeah21:33
cloudnullthat should render / create the inventory21:34
palendaeHrm21:34
palendaeDo I need to explicitly pass the file as an arg?21:34
palendaeGetting a type error, might have a typo in my file21:34
palendaeAh, network_hosts is empty21:35
Mudpuppydamn yml21:35
palendaeWait, no21:35
palendaeO.o21:35
*** alop has quit IRC21:36
*** aerisosteam has joined #openstack-ansible21:42
palendaeMissing colon, woo21:43
*** annashen has quit IRC21:57
*** TheIntern has joined #openstack-ansible22:01
*** aerisosteam has quit IRC22:02
jwitkohey guys, on http://openstack-ansible-deployment.readthedocs.org/en/latest/install-guide/configure-glance.html  -- is there where I would add netapp configuration if I want to use a netapp NFS mount for glance?22:03
jwitkoi only see netapp config if i have a storage server.  but I don't want to use storage servers as I have the netapp22:04
cloudnulljwitko:  you can define nfs mounts like this https://github.com/stackforge/os-ansible-deployment/blob/master/playbooks/roles/os_glance/defaults/main.yml#L118-L127 which might get you there.22:05
palendaeInteresting - that RTD project isn't associated with anyone working on the project that I'm aware of22:06
palendaehttp://osad.readthedocs.org/en/latest/ is us22:06
cloudnullthis assumes that the containers have a route to your netapp ofcourse, but that it should work in master/kilo .22:06
jwitkocloudnull, so I shouldn't be doing anything to configure netapp in the /etc/openstack_deploy/openstack_user_config.yml ?22:07
cloudnullyou can define glance_nfs_mounts as a host variable in the openstack_user_config.yml or you can set it in user_variable.yml either will work.22:07
*** aerisosteam_ has joined #openstack-ansible22:08
cloudnullas  a host_var it would be set like this https://github.com/stackforge/os-ansible-deployment/blob/master/etc/openstack_deploy/openstack_user_config.yml.aio#L111-L11722:08
cloudnullbut within the os-infra_hosts section.22:08
jwitkocloudnull, but that assumes you have a storage server22:09
jwitkobecause I have a netapp I thought I would not need storage servers ?22:09
cloudnullIE http://cdn.pasteraw.com/sg3t3lajxgo7fyb288jhs69vgns7ucb22:10
cloudnullyour netapp has to be able to do nfs essentially.22:10
jwitkoit is22:10
jwitkoi see in your pasteraw example it is just configured via the infra_hosts22:11
jwitkothat is more along the lines of what i was hoping for22:11
jwitkodoes that mount point given there need to be created ahead of time?22:11
jwitkoor will the glance playbook create that?22:11
openstackgerritJesse Pretorius proposed stackforge/os-ansible-deployment: Keystone Federation Service Provider Configuration  https://review.openstack.org/19439522:11
cloudnullit should create it if its doesnt exist already. in this case its the glance image location which the pre-install task does create.22:11
* cloudnull looking if its auto creating the mount point.22:12
cloudnullyes itll create it if it doesnt exist22:12
odyssey4memiguelgrinberg are you around?22:12
cloudnullhttps://github.com/stackforge/os-ansible-deployment/blob/master/playbooks/roles/os_glance/tasks/glance_post_install.yml#L86-L9522:12
miguelgrinbergodyssey4me: yeah22:13
miguelgrinbergodyssey4me: success?22:13
odyssey4memiguelgrinberg the last patch set simplified the keystone apache config, removing the nasty substitution stuff - but with adfs I'm getting a keystone failure - it's not allowing me into the project related ot the group22:14
miguelgrinbergare you naming the group by name or by id in the rules?22:14
odyssey4meI might just be tired and not thinking straight. :/22:14
odyssey4meby name22:14
miguelgrinbergI found that you need to add the domain when you refer to the group by name22:14
odyssey4meI've verified the rules on my previously working adfs box, and it works as-is22:15
odyssey4memiguelgrinberg yep, the domain is also there22:15
odyssey4methe assignment of the project-group-role is there22:15
miguelgrinbergodyssey4me: unfortunately keystone swallows all the exceptions during the mapping process22:16
miguelgrinbergI figure stuff out by adding logging directly in the keystone code22:16
jwitkocloudnull, can i do the same with cinder_backends?22:17
jwitkoadd them as a container_vars sub-item to the os-infra_hosts ?22:17
*** Mudpuppy has quit IRC22:17
openstackgerritJesse Pretorius proposed stackforge/os-ansible-deployment: Keystone Federation Service Provider Configuration  https://review.openstack.org/19439522:18
odyssey4memiguelgrinberg I think I'll revisit it tomorrow. How's the IdP going?22:19
cloudnullif all of your cinder storage is going to be powered by netapp I'd create a storage_host entry but use the same hosts as that of your infra. and set the netapp config accordingly.22:19
cloudnullwhich is outlined here https://github.com/stackforge/os-ansible-deployment/blob/master/etc/openstack_deploy/openstack_user_config.yml.example#L523-L55222:20
miguelgrinbergodyssey4me: I'm only starting on that now, had to debug another RPC heat install that went wrong this morning22:20
odyssey4memiguelgrinberg ah, bother :/22:20
miguelgrinbergsomehow this lab ended up with the Liberty version of the heat schema in the db, but heat code was kilo22:20
odyssey4mealright, will see your update in the morning and figure it out from there - night22:20
miguelgrinbergyes, hopefully I'll get the IdP done today, fingers crossed22:21
odyssey4methanks for the help earlier, that extra little setting for https eally helped22:21
odyssey4me*really22:21
miguelgrinbergodyssey4me: yeah, glad it helped!22:22
cloudnulljwitko:  so a complete config might look like this http://cdn.pasteraw.com/ewi4adra0q5k6nip2y1f74fmh0674br22:23
*** sacharya has quit IRC22:29
*** spotz is now known as spotz_zzz22:34
openstackgerritKevin Carter proposed stackforge/os-ansible-deployment: Change to ensure container networks are up  https://review.openstack.org/20282122:35
cloudnullBjoernT: https://review.openstack.org/#/c/202821/122:35
openstackgerritKevin Carter proposed stackforge/os-ansible-deployment: [WIP] Compartmentalizing RabbitMQ  https://review.openstack.org/20282222:36
BjoernTok thanks22:36
openstackgerritKevin Carter proposed stackforge/os-ansible-deployment: [WIP] Compartmentalizing RabbitMQ  https://review.openstack.org/20282222:37
*** javeriak has joined #openstack-ansible22:39
*** defrag has quit IRC22:40
openstackgerritKevin Carter proposed stackforge/os-ansible-deployment-specs: New spec for compartementalize-rabbitmq  https://review.openstack.org/20236322:42
jwitkocloudnull, sorry to bother you again but do you have any examples of Swift being setup via OSAD with NetApp ?22:42
cloudnullno.22:42
*** metral_zzz is now known as metral22:43
jwitkofrom what I'm reading i'm not even sure its possible22:43
cloudnulli guess you could predefine the mount points22:43
cloudnulland then tell swift to use them22:43
cloudnullbut i've never done that, nor do i know if it works.22:43
*** alop has joined #openstack-ansible22:43
cloudnullbut thers no tooling built for something like that at this point within the OSAD project.22:44
* cloudnull going home22:44
cloudnulltake care guys22:44
jwitkothanks22:44
*** aerisosteam_ has left #openstack-ansible22:51
*** aerisosteam_ has quit IRC22:51
*** BjoernT has quit IRC22:59
*** sdake_ has quit IRC23:12
*** daneyon_ has left #openstack-ansible23:15
*** galstrom is now known as galstrom_zzz23:16
*** openstackstatus has joined #openstack-ansible23:33
*** ChanServ sets mode: +v openstackstatus23:33
*** britthouser has quit IRC23:47
*** britthouser has joined #openstack-ansible23:50
*** jaypipes has quit IRC23:50

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!