*** abitha has joined #openstack-ansible | 00:00 | |
*** arbrandes has joined #openstack-ansible | 00:13 | |
*** sdake has joined #openstack-ansible | 00:20 | |
*** abitha has quit IRC | 00:27 | |
*** daneyon has joined #openstack-ansible | 00:41 | |
*** sdake_ has joined #openstack-ansible | 00:52 | |
*** sdake has quit IRC | 00:56 | |
*** daneyon_ has joined #openstack-ansible | 00:56 | |
*** daneyon has quit IRC | 00:59 | |
*** daneyon_ has quit IRC | 01:23 | |
*** sdake_ has quit IRC | 01:53 | |
openstackgerrit | Merged openstack/openstack-ansible: Adding docs for HAProxy SSL configuration https://review.openstack.org/224980 | 02:15 |
---|---|---|
pellaeon | cloudnull: got it, thanks! | 02:20 |
*** sdake has joined #openstack-ansible | 02:26 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Temporarily pins to unblock gating https://review.openstack.org/225156 | 02:28 |
*** Mudpuppy has quit IRC | 02:28 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Update master for past liberty-3 for testing https://review.openstack.org/225459 | 02:28 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Temporarily pins to unblock gating https://review.openstack.org/225156 | 02:33 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: [WIP] Run Cinder from a venv https://review.openstack.org/225463 | 02:33 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Update master for past liberty-3 for testing https://review.openstack.org/225459 | 02:33 |
*** sdake_ has joined #openstack-ansible | 02:34 | |
*** sdake has quit IRC | 02:38 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Temporarily pins to unblock gating https://review.openstack.org/225156 | 02:41 |
*** galstrom_zzz is now known as galstrom | 02:55 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Update master for past liberty-3 for testing https://review.openstack.org/225459 | 03:21 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: [WIP] Run Cinder from a venv https://review.openstack.org/225463 | 03:21 |
*** elo has joined #openstack-ansible | 03:33 | |
*** ashishjain has quit IRC | 03:34 | |
*** elo1 has joined #openstack-ansible | 03:34 | |
*** elo2 has joined #openstack-ansible | 03:35 | |
*** sdake_ has quit IRC | 03:35 | |
*** elo has quit IRC | 03:37 | |
*** elo1 has quit IRC | 03:38 | |
*** elo2 has quit IRC | 03:39 | |
*** galstrom is now known as galstrom_zzz | 03:41 | |
*** elo has joined #openstack-ansible | 03:41 | |
*** elo has quit IRC | 03:42 | |
*** fawadkhaliq has joined #openstack-ansible | 04:20 | |
*** shausy has joined #openstack-ansible | 05:25 | |
*** javeriak has joined #openstack-ansible | 06:11 | |
*** fawadkhaliq has quit IRC | 06:14 | |
*** fawadkhaliq has joined #openstack-ansible | 06:15 | |
*** fawadkhaliq has quit IRC | 06:19 | |
*** javeriak has quit IRC | 06:36 | |
*** shausy has quit IRC | 06:38 | |
*** shausy has joined #openstack-ansible | 06:38 | |
*** javeriak has joined #openstack-ansible | 06:47 | |
*** javeriak_ has joined #openstack-ansible | 06:50 | |
*** javeriak has quit IRC | 06:51 | |
*** fawadkhaliq has joined #openstack-ansible | 07:08 | |
*** gparaskekevasras has joined #openstack-ansible | 07:37 | |
*** willemgf has joined #openstack-ansible | 07:42 | |
tiagogomes | morning, after finishing deploying with OSAD, I can't launch VM instances with a binding_failed error. I noticed that I haven't got any neutron agent running on the compute hosts. Any ideas? | 07:52 |
*** sdake has joined #openstack-ansible | 07:54 | |
*** sdake_ has joined #openstack-ansible | 07:55 | |
*** gparaskekevasras has quit IRC | 07:56 | |
*** gparaskevas has joined #openstack-ansible | 07:58 | |
*** sdake has quit IRC | 07:58 | |
gparaskevas | i had problems with binding error and i changed my neutron conf | 07:59 |
gparaskevas | but i had linuxbridge agent on compute nodes running | 07:59 |
gparaskevas | can you post nova-comppute.log | 07:59 |
gparaskevas | and neutron/plugins/ml2/ml2.conf.ini | 08:00 |
gparaskevas | from the compute hosts | 08:00 |
*** ashishjain has joined #openstack-ansible | 08:04 | |
tiagogomes | ML2 configuration file: http://paste.openstack.org/show/472368/ . I don't have that eth12 interface on the compute nodes | 08:06 |
tiagogomes | I also don't have any service file for the agent | 08:07 |
gparaskevas | eth12 is on the neutron containers only | 08:09 |
gparaskevas | its weird | 08:09 |
gparaskevas | let me chec my installation | 08:10 |
*** ashishjain has quit IRC | 08:10 | |
gparaskevas | your compute hosts how many NICs? | 08:10 |
gparaskevas | is that configuration file from the compute hosts or from the neutron agent container? | 08:13 |
tiagogomes | from the compute hosts | 08:14 |
gparaskevas | looks wrong to me | 08:14 |
tiagogomes | the compute hosts physically has 2 NICs, but one is for external access and it is not being used for openstack | 08:15 |
gparaskevas | ok | 08:15 |
gparaskevas | so you have configured interfaces with vlans? | 08:15 |
gparaskevas | and then bridges? | 08:15 |
tiagogomes | yes | 08:15 |
gparaskevas | if the compute hosts dont have linuxbridge agent this is not going to work i thhink | 08:16 |
gparaskevas | can anyone else confirm that? | 08:16 |
gparaskevas | looks like you need to reconfigure neutron | 08:18 |
tiagogomes | how so? | 08:20 |
gparaskevas | did everything succeed? | 08:22 |
gparaskevas | from setup-openstack.yml | 08:22 |
tiagogomes | yes, as far as I can tell. But I am not seeing much OpenStack related tasks. I ran the setup-everything playbook | 08:25 |
*** sdake_ has quit IRC | 08:26 | |
*** fawadkhaliq has quit IRC | 08:26 | |
*** gparaskevas has quit IRC | 08:29 | |
tiagogomes | everything looks ok in ansilble; http://paste.openstack.org/show/472416/ . devhw7 and devhw8 are my compute hosts | 08:35 |
*** gparaskevas has joined #openstack-ansible | 08:35 | |
tiagogomes | mm, why is it skipping some machines : http://paste.openstack.org/show/472427/ | 08:45 |
evrardjp | good morning everyone | 08:52 |
openstackgerrit | venkatamahesh proposed openstack/openstack-ansible: Change the network from management to container https://review.openstack.org/225588 | 09:02 |
*** markvoelker has quit IRC | 09:27 | |
evrardjp | I have issue with the APIs since I moved them to https using openstack_service_publicuri_proto:https | 09:29 |
andymccr | tiagogomes: it sets up the appropriate init scripts - the first ones are for neutron-server containers by the looks of it, but in lines 62+ it sets up the agents containers's init scripts etc. | 09:31 |
tiagogomes | yes, but it is not setting up the scripts on the compute hosts for some reason | 09:36 |
andymccr | tiagogomes: it should be - on line 86+ | 09:45 |
javeriak_ | hey guys, am i missing something, for the last two openstack plays that i've run (keystone, glance), they are missing the *_rabbitmq_password variables in their parameter files | 09:52 |
evrardjp | javeriak_: you sure you started them by openstack-ansible and not ansible-playbook? | 09:53 |
evrardjp | ;) | 09:53 |
evrardjp | (just a quick question to be sure the play has run correctly) | 09:54 |
evrardjp | ran* | 09:54 |
andymccr | javeriak_: those vars are in the user_secrets.yml file and not the separate role's defaults file. | 09:55 |
javeriak_ | andymccr, i checked, they didnt get generated there either | 09:56 |
evrardjp | javeriak_: the user_secrets.yml isn't automatically generated | 09:56 |
andymccr | javeriak_: did you have an existing setup, and then updated the repo? It looks like the patch to change that happened recently. | 09:56 |
andymccr | so if you had an existing user_secrets they wouldn't have been added. | 09:56 |
javeriak_ | andymccr, no this is newish, but i cloned it last week so i may be missing the change if it came after | 09:57 |
evrardjp | andymccr: true, always check if there aren't new variables in the upstream user_secrets | 09:57 |
evrardjp | javeriak_: ^ | 09:57 |
javeriak_ | evrardjp, oh bummer, thanks guys | 09:58 |
*** fawadkhaliq has joined #openstack-ansible | 10:02 | |
*** javeriak_ has quit IRC | 10:11 | |
tiagogomes | andymccr sorry, what do you mean? | 10:13 |
andymccr | tiagogomes: for your compute hosts you should only get the linuxbridge-agent init script setup, it is being added but it loops through the required init scripts, so its skipped for all the other init scripts. in the paste that you put it gets dropped in like 86 (im guessing) which is where it isn't skipped. | 10:14 |
andymccr | *line 86 | 10:15 |
*** Ti-mo- has joined #openstack-ansible | 10:16 | |
*** Ti-mo has quit IRC | 10:17 | |
*** ashishjain has joined #openstack-ansible | 10:19 | |
ashishjain | hello | 10:19 |
odyssey4me | evrardjp which API's are you having issues with? | 10:20 |
odyssey4me | *SSL issues? | 10:20 |
evrardjp | keystone | 10:21 |
evrardjp | I'll show you what I have in debug | 10:21 |
odyssey4me | evrardjp are you using ssl at the LB and also at keystone - or just at the LB or just at Keystone | 10:21 |
evrardjp | I'm using the default, and I'll tell you in 5 sec what it is | 10:22 |
evrardjp | by default there seem to be an ssl termination on haproxy | 10:23 |
odyssey4me | there is no default | 10:23 |
odyssey4me | the proto has to be setup along with either haproxy_ssl or keystone_ssl set to true | 10:23 |
evrardjp | true! | 10:23 |
evrardjp | I'm using haproxy_ssl: true and openstack_service_publicuri_proto:https | 10:24 |
odyssey4me | ok, are you using a public ca to sign your certs, or an internal ca? | 10:24 |
evrardjp | http://paste.openstack.org/show/472544/ | 10:26 |
evrardjp | public ca | 10:26 |
evrardjp | the certificate is correct etc | 10:26 |
evrardjp | horizon seem to work fine | 10:26 |
evrardjp | I just get these kind of redirections, whatever my CLI is | 10:26 |
evrardjp | (cf. paste) | 10:26 |
odyssey4me | so it seems that you're being redirected to http from https | 10:27 |
evrardjp | yup | 10:27 |
odyssey4me | what entries do you have in your service catalogue? | 10:27 |
evrardjp | https in public | 10:27 |
odyssey4me | http internal? | 10:28 |
*** markvoelker has joined #openstack-ansible | 10:28 | |
evrardjp | yup | 10:28 |
odyssey4me | ok, and in your openrc you're likely to be setting the endpoint to use to be internal, right? (that's our default) | 10:28 |
evrardjp | the internal works fine with http, the deployment works | 10:29 |
odyssey4me | in the catalogue do the public and internal endpoints have the same ip? | 10:29 |
evrardjp | I'm not starting the command from the utility container | 10:29 |
evrardjp | nope | 10:29 |
evrardjp | I'm "like a client" | 10:29 |
evrardjp | he used horizon, downloaded his openrc file | 10:29 |
evrardjp | and bam, not working with his/her favorite CLI | 10:30 |
odyssey4me | oh I see - so the issue here is that you're outside and the internal ip/port is not accessible | 10:30 |
evrardjp | not sure | 10:30 |
odyssey4me | ok, there's a change you'll need to set... let me find the value | 10:30 |
evrardjp | wait I'm not sure it's that | 10:30 |
evrardjp | because keystone seem to redirect to the public endpoint without https | 10:30 |
odyssey4me | keystone_public_endpoint needs to be set to the value you want public clients to get when they query the api | 10:31 |
*** markvoelker has quit IRC | 10:32 | |
odyssey4me | hmm, that's possibly for the same reason - the keystone service itself thinks it's being served via http (which it is) and the content of its payload doesn't seem to reflect the switch in protocol when going via haproxy | 10:33 |
ashishjain | hello | 10:35 |
ashishjain | I am seeing some issue with osad | 10:35 |
ashishjain | http://paste.openstack.org/show/472547/ | 10:36 |
ashishjain | when I run the openstack-ansible setup-infrastrucutre.yml | 10:36 |
ashishjain | I hit the above error | 10:36 |
ashishjain | to get rid of this error I do the following | 10:37 |
ashishjain | lxc-attach -n ansible01_keystone_container-02aaa591 | 10:37 |
ashishjain | Modify line number #4 and #23 in /etc/apache2/sites-enabled/keystone-httpd.conf and set threads>0. i used threads=1 | 10:38 |
ashishjain | now manually start apache2 | 10:38 |
ashishjain | it starts fine. | 10:38 |
ashishjain | I think fix has to probbaly go to /opt/os-ansible-deploymemt/playbooks/roles/os_keystone/templates/keystone-httpd.conf.j2 | 10:39 |
odyssey4me | ashishjain what version are you running? | 10:40 |
ashishjain | odyssey4me: kilo | 10:40 |
ashishjain | how is this value being set /opt/os-ansible-deploymemt/playbooks/roles/os_keystone/templates/keystone-httpd.conf.j2 | 10:40 |
odyssey4me | ashishjain https://github.com/openstack/openstack-ansible/blob/master/playbooks/roles/os_keystone/defaults/main.yml#L134-L135 | 10:40 |
odyssey4me | you may notice that the repo url has changed and I would suggest that you update your remotes if you haven't already | 10:41 |
odyssey4me | ashishjain also note this change in review at the moment: https://review.openstack.org/225145 | 10:42 |
ashishjain | odyssey4me: All this is fine. Let me tell you my problem | 10:43 |
odyssey4me | ashishjain so all you need to do is set 'keystone_wsgi_threads: 1' and 'keystone_wsgi_processes' to an appropriate value in your user_variables.yml | 10:44 |
ashishjain | odyssey4me: user_yariables.yml in /etc/openstack_deploy? | 10:45 |
odyssey4me | ashishjain yes, all overrides of defaults should be done in user_variables | 10:45 |
ashishjain | odyssey4me:I donot have any section for keystone in my user_variables | 10:45 |
ashishjain | odyssey4me: great thanks for this. | 10:45 |
ashishjain | I will try this out | 10:45 |
odyssey4me | ashishjain you don't need any section - user_variables.yml can contain any value that you find in a role/defaults/main.yml file | 10:46 |
ashishjain | odyssey4me: I hope I only have to run setup-infra...yml? | 10:46 |
odyssey4me | for changes in the keystone config for apache, just run setup-keystone.yml | 10:46 |
odyssey4me | or was it os-keystone-install.yml... need more coffee :p | 10:47 |
openstackgerrit | Merged openstack/openstack-ansible-specs: Renamed os-ansible-deployment to OpenStackAnsible https://review.openstack.org/223785 | 10:47 |
ashishjain | :) ... thanks | 10:48 |
ashishjain | odyssey4me: One question - osad itself is completely automated. Is it possible to invoke this complete process using ansible python api? | 10:59 |
ashishjain | odyssey4me: This would probably include all the manual operations which a user has to for example user_config, openstack-anisble setup-hosts, install-haproxy,setup-infra,setup-openstac | 11:00 |
ashishjain | is it possible to invoke all of these using ansible python api? | 11:01 |
*** Mudpuppy has joined #openstack-ansible | 11:02 | |
odyssey4me | ashishjain the appropriate setup of the host networking, host repositories and the openstack_user_config, user_variables and user_secrets would need to be manually done by the deployer as they are all customisable based on choices made by the deployer in terms of the design of the environment | 11:02 |
odyssey4me | I'm not sure what you feel could be automated? | 11:02 |
ashishjain | odyssey4me: yes you are correct, only things whcih can probably be automated would be creation of these yaml files and thei invocation which definitely can be done using any programming language | 11:06 |
*** Mudpuppy has quit IRC | 11:06 | |
ashishjain | odyssey4me: The idea was to automate say environment provisioning and than osad installation together | 11:06 |
ashishjain | by EP I mean baremetal or vm provisioning on which osad will be installed | 11:07 |
ashishjain | this EP will also include setting up appropriate network interfaces, volumes for osad installation | 11:08 |
odyssey4me | ashishjain the compilation of the files could be done by a bare metal provisioning tool combined with some sort of library which understands the source tool - openstack-ansible is deliberately staying away from going into the bare metal provisioning space, but is considering making it easier to consume data from it in https://blueprints.launchpad.net/openstack-ansible/+spec/dynamic-inventory-lib | 11:08 |
*** arbrandes has quit IRC | 11:09 | |
odyssey4me | one of the OpenStack projects looking into this is Compass, another is OpenCrowbar | 11:09 |
openstackgerrit | Merged openstack/openstack-ansible: Temporarily pins to unblock gating https://review.openstack.org/225156 | 11:10 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Change the network from management to container https://review.openstack.org/225588 | 11:10 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Fix for keystone LDAP pkg missing https://review.openstack.org/225469 | 11:10 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Adds group support to inventory-manage.py https://review.openstack.org/224977 | 11:11 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Add SSL/TLS listener to RabbitMQ https://review.openstack.org/223717 | 11:11 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Update cached LXC image in place https://review.openstack.org/224304 | 11:11 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Changed the Diffie Hellman parameter maximum size https://review.openstack.org/224760 | 11:11 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Implementation of keepalived for haproxy https://review.openstack.org/218818 | 11:11 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: adds the config_template to nova https://review.openstack.org/223329 | 11:12 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: adds the config_template to galera_client https://review.openstack.org/223349 | 11:12 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: adds the config_template to tempest https://review.openstack.org/223342 | 11:13 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: adds the config_template to neutron https://review.openstack.org/223314 | 11:13 |
ashishjain | odyssey4me: thanks for these pointers | 11:13 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Adds the config_template to heat https://review.openstack.org/223299 | 11:13 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Adds the config_template to cinder https://review.openstack.org/223209 | 11:13 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Support base64 padding in federated tokens https://review.openstack.org/223888 | 11:13 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: adds the config_template to pip_lock_down https://review.openstack.org/223350 | 11:14 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Adds the config_template to keystone https://review.openstack.org/223307 | 11:14 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Adds the config_template to glance https://review.openstack.org/223288 | 11:15 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: adds the config_template to galera_server https://review.openstack.org/223348 | 11:15 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Adjust default Keystone httpd processes and threads https://review.openstack.org/225145 | 11:16 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Adjust default Keystone httpd processes and threads https://review.openstack.org/225145 | 11:16 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Add auth version for legacy OpenStack clients https://review.openstack.org/223296 | 11:17 |
*** javeriak has joined #openstack-ansible | 11:17 | |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Add neutron_migrations_facts module https://review.openstack.org/219759 | 11:18 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Change recon_lock_path to /var/lock https://review.openstack.org/224060 | 11:18 |
mattt | do i need to do any manual steps upgrading from 11.0 -> 11.2 wrt keystone ? | 11:27 |
odyssey4me | mattt not to my knowledge, although you should probably set the keystone_wsgi_threads to 1 as per https://review.openstack.org/225145 | 11:28 |
*** markvoelker has joined #openstack-ansible | 11:29 | |
odyssey4me | mattt the only thing I can think of that may affect things would be the service catalogue change where 11.0.0-11.0.4 were using keystone v2 for the admin endpoint, and 11.1.0 is using keystone v3 | 11:29 |
odyssey4me | but an existing environment shouldn't be affected as the endpoints will already be there | 11:30 |
odyssey4me | it'd be good to know though | 11:30 |
mattt | odyssey4me: yeah this is what i'm hitting i believe | 11:32 |
*** javeriak has quit IRC | 11:32 | |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Install nfs-common with nova-compute https://review.openstack.org/223604 | 11:32 |
mattt | odyssey4me: the odd thing is that my openrc is still getting created w/ OS_IDENTITY_API_VERSION=2 | 11:32 |
mattt | ah, user_group_vars.yml :( | 11:33 |
*** markvoelker has quit IRC | 11:33 | |
odyssey4me | mattt yep, https://github.com/openstack/openstack-ansible/blob/master/playbooks/roles/openstack_openrc/templates/openrc#L23 | 11:34 |
odyssey4me | hmm, oh yes - if you have user_group_vars in /etc/openstack_deploy/ then remove it | 11:34 |
odyssey4me | I forgot about that | 11:34 |
odyssey4me | we should probably add a section into the docs for these things | 11:35 |
mattt | yeah! | 11:37 |
mattt | that was kinda confusing :P | 11:37 |
mattt | but all sorted, my cluster is back up | 11:37 |
tiagogomes | I discovered why the linuxbridge agent was not running: http://paste.openstack.org/show/472652/ . This is in the compute host so eth12 doesn't | 11:53 |
tiagogomes | How can I prevent that? On the other hand, shouldn't the linuxbridge agent run in a container on the compute host? | 11:53 |
odyssey4me | tiagogomes the agent needs to set networks up for nova to use, so no - both the nova and the neutron agents run on the host for compute hosts | 11:54 |
mhayden | happy monday | 11:55 |
tiagogomes | ah ok, but how do I avoid having a flat: eth12 mapping for the compute hosts? | 11:55 |
odyssey4me | tiagogomes it seems odd to me that the flat network is needed on the compute - you may have an ordering issue in your list of interfaces | 11:55 |
odyssey4me | as I recall the order is important | 11:56 |
tiagogomes | `physical_interface_mappings = {{ neutron_provider_networks.network_mappings }}`, does this mean that it is not possible to have different mappings for infrastructure and compute hosts? | 12:00 |
odyssey4me | o/ mhayden nice work on the local image updates - almost there :) | 12:00 |
mhayden | odyssey4me: ah, the gate checks kept killing me all wekeend | 12:01 |
odyssey4me | tiagogomes unfortunately I'm dumb when it comes to getting the networking right :/ | 12:01 |
tiagogomes | odyssey4me no worries :) | 12:02 |
mhayden | i may send an email about the security hardening spec to the ML | 12:02 |
odyssey4me | tiagogomes I'm not sure if mattt or andymccr are still around. They know better than me. | 12:02 |
odyssey4me | tiagogomes it would seem that something in the openstack_user_config might be mapped incorrectly, or there's an ordering issue | 12:03 |
odyssey4me | mhayden do it :) | 12:03 |
mhayden | odyssey4me: i like your ideas about moving some more of those multi-container adjustments into the main image | 12:08 |
mhayden | err cached image | 12:08 |
mattt | tiagogomes: is this of use at all ? https://bugs.launchpad.net/openstack-ansible/+bug/1399432 | 12:09 |
openstack | Launchpad bug 1399432 in openstack-ansible trunk "Flat network type seems broken on un-containerized compute nodes" [Low,Fix released] - Assigned to Matt Kassawara (ionosphere80) | 12:09 |
mattt | tiagogomes: i'm hopeless at networking, but i remember reading that one in the past | 12:09 |
odyssey4me | mhayden yeah, the more the merrier in my view - anything that can be expected to be static | 12:09 |
mhayden | mattt: but you're so good with networking in person | 12:09 |
mhayden | odyssey4me: gotcha | 12:09 |
mhayden | i'll take a look now | 12:09 |
mgariepy | good morning | 12:09 |
odyssey4me | I can do a follow-on which will use an entirely different image (which is more up to date and standard) which will take some of the magic out of the image itself, then also have an option for a deployer to use their own image, or the upstream one which we will set as a default. That, I think, will be far better. :) | 12:10 |
*** markvoelker has joined #openstack-ansible | 12:11 | |
mhayden | odyssey4me: totally agree | 12:12 |
evrardjp | odyssey4me: FYI, setting keystone_public_endpoint broke my horizon | 12:21 |
mattt | mhayden: LIES | 12:23 |
*** mgariepy has left #openstack-ansible | 12:24 | |
*** mgariepy has joined #openstack-ansible | 12:24 | |
evrardjp | (only because of my haproxy config, that I'll fix and probably send a commit) | 12:28 |
evrardjp | good morning mgariepy | 12:29 |
*** woodard has joined #openstack-ansible | 12:29 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: Update cached LXC image in place https://review.openstack.org/224304 | 12:38 |
* mhayden winks at odyssey4me | 12:38 | |
*** woodard has quit IRC | 12:39 | |
mhayden | odyssey4me: holy crap -- gate checks succeeded for the update-in-place stuff in 59m | 12:40 |
*** woodard has joined #openstack-ansible | 12:40 | |
mhayden | wow, upstream lint checking is stringent ;) | 12:42 |
*** tiagogomes has quit IRC | 12:52 | |
gparaskevas | cant wait to chery-pick that -> https://review.openstack.org/224304 | 12:53 |
gparaskevas | :P | 12:53 |
*** tiagogomes has joined #openstack-ansible | 12:53 | |
*** woodard has quit IRC | 12:53 | |
*** woodard has joined #openstack-ansible | 12:54 | |
mhayden | mancdaz: https://twitter.com/majorhayden/status/645943821650386944 | 12:55 |
evrardjp | :) | 12:55 |
mancdaz | mhayden lols | 12:55 |
mancdaz | mhayden I was going to quickly fix that up for you this morning, but locally flake8 was passing for me, so I immediately gave up and went to look at something else | 12:56 |
mhayden | mancdaz: it requires an additional pkg | 12:56 |
mhayden | pip install flake8-pep257 | 12:56 |
mhayden | just figured that out | 12:57 |
mancdaz | oh my | 12:57 |
mhayden | well hell, i fixed PEP 0257 errors but now i broke some other PEP | 12:57 |
mhayden | :| | 12:57 |
*** woodard has quit IRC | 13:02 | |
*** woodard has joined #openstack-ansible | 13:03 | |
*** woodard has quit IRC | 13:03 | |
*** woodard has joined #openstack-ansible | 13:04 | |
mancdaz | mhayden http://i1.wp.com/openstackreactions.enovance.com/wp-content/uploads/2013/08/tumblr_mo6cbbPhuN1sp6r04o1_4001.gif | 13:05 |
mhayden | We cannot complete this request, remote data could not be fetched | 13:06 |
mancdaz | the internet has failed | 13:07 |
*** fawadkhaliq has quit IRC | 13:10 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: Adds group support to inventory-manage.py https://review.openstack.org/224977 | 13:12 |
mhayden | mancdaz: ^^ crossing fingers | 13:13 |
*** mfisch has quit IRC | 13:18 | |
*** Mudpuppy has joined #openstack-ansible | 13:18 | |
*** pradk has joined #openstack-ansible | 13:19 | |
*** mfisch has joined #openstack-ansible | 13:19 | |
*** fawadkhaliq has joined #openstack-ansible | 13:19 | |
*** mfisch is now known as Guest61243 | 13:19 | |
*** javeriak has joined #openstack-ansible | 13:21 | |
*** Mudpuppy has quit IRC | 13:23 | |
*** arbrandes has joined #openstack-ansible | 13:29 | |
*** tlian has joined #openstack-ansible | 13:36 | |
*** javeriak_ has joined #openstack-ansible | 13:42 | |
*** javeriak has quit IRC | 13:44 | |
evrardjp | first "in-place" upgrade of the openstack cloud in front of client: check | 13:44 |
evrardjp | expected result: working | 13:44 |
evrardjp | actual result: fail | 13:44 |
evrardjp | woops :) | 13:44 |
evrardjp | 30 minutes later: fixed | 13:44 |
evrardjp | not really a success story, but still a good story | 13:45 |
evrardjp | so, thank everyone for this good product | 13:45 |
mattt | evrardjp: what did you upgrade from to ? | 13:46 |
evrardjp | kilo to kilo | 13:46 |
evrardjp | not really a large upgrade | 13:46 |
evrardjp | just re-running all the playbooks | 13:47 |
mattt | what failed? | 13:47 |
evrardjp | During os-cinder-install playbook, it checks on cinder-volumes if cinder api is publicly available, which failed on my side, because I tried to improve my haproxy | 13:48 |
evrardjp | entirely my fault | 13:48 |
evrardjp | but doing upgrades on such large systems and expect it to be working is already a success in itself | 13:50 |
evrardjp | (IMHO) | 13:50 |
*** fawadkhaliq has quit IRC | 13:51 | |
mattt | evrardjp: we will be spending a lot more time on this going forward, so expect to see the experience get better and better | 13:51 |
evrardjp | other discussion: is someone interested by having a distribution system of the policy.json files from the components to horizon? | 13:51 |
evrardjp | I need to have it, I don't know if it interests someone | 13:52 |
evrardjp | if it has some interest for other ppl* | 13:52 |
*** arbrandes has quit IRC | 13:52 | |
*** woodard has quit IRC | 13:55 | |
*** sdake has joined #openstack-ansible | 13:56 | |
*** galstrom_zzz is now known as galstrom | 13:57 | |
*** woodard has joined #openstack-ansible | 13:58 | |
*** arbrandes has joined #openstack-ansible | 14:00 | |
*** KLevenstein has joined #openstack-ansible | 14:01 | |
*** javeriak_ has quit IRC | 14:01 | |
*** galstrom is now known as galstrom_zzz | 14:02 | |
*** willemgf has quit IRC | 14:03 | |
*** kerwin_bai has joined #openstack-ansible | 14:04 | |
*** spotz_zzz is now known as spotz | 14:04 | |
*** jlvillal has joined #openstack-ansible | 14:05 | |
*** javeriak has joined #openstack-ansible | 14:05 | |
*** galstrom_zzz is now known as galstrom | 14:07 | |
*** Mudpuppy has joined #openstack-ansible | 14:08 | |
*** elo has joined #openstack-ansible | 14:11 | |
*** javeriak_ has joined #openstack-ansible | 14:11 | |
odyssey4me | evrardjp svg did you see http://lists.openstack.org/pipermail/openstack-operators/2015-September/008169.html ? | 14:12 |
odyssey4me | and http://lists.openstack.org/pipermail/openstack-operators/2015-September/008136.html | 14:12 |
*** javeriak has quit IRC | 14:13 | |
evrardjp | yeah I saw that in my digest, still don't know how/when to repl | 14:13 |
evrardjp | I missed the etherpad though, so thanks | 14:15 |
*** javeriak_ has quit IRC | 14:20 | |
*** jwagner_away is now known as jwagner | 14:24 | |
bgmccollum | tiagogomes: check in your openstack_user_config.yml for the flat network definition - you probably have a "host_bind_override" set to eth12. this means uncontainerized services will expect and use eth12 on the host. | 14:29 |
bgmccollum | tiagogomes: you can do something similar in your network config for br-vlan to ensure an eth12 interface is available - https://github.com/openstack/openstack-ansible/blob/master/etc/network/interfaces.d/aio_interfaces.cfg#L53-L59 | 14:30 |
tiagogomes | bgmccollum ah thanks, so what should I do remove the host_bind_override or add the veth pair ? | 14:32 |
bgmccollum | tiagogomes: if you dont need flat network types, remove that network type from openstack_user_config.yml -- otherwise, bring up a veth pair for the flat network to use | 14:34 |
mhayden | cloudnull / odyssey4me: if y'all get a moment to make sure i didn't miss anything here, i'd be much obliged -> https://review.openstack.org/#/c/224304/ | 14:35 |
*** galstrom is now known as galstrom_zzz | 14:36 | |
odyssey4me | mhayden I was wondering why you opted to use the sed approach instead of a template for sshd_config? cc cloudnull | 14:38 |
tiagogomes | thanks bgmccollum, I am not very familiar using Neutron with Linux bridge, but I think I need the flat network to connect the VMs to the external network | 14:39 |
odyssey4me | it keeps the current convention, so I'm fine with it - I'm just wondering whether we shouldn't just wholesale replace it with something templated - perhaps that's better done as a follow-up patch | 14:39 |
odyssey4me | tiagogomes typically a flat network is used for something like the public network, which only needs to be present on the neutron-agent container as that's the only place whether floating ip's are added | 14:40 |
odyssey4me | but it largely depends on your environment, of course | 14:40 |
openstackgerrit | Merged openstack/openstack-ansible: Adds the config_template to heat https://review.openstack.org/223299 | 14:46 |
*** woodard has quit IRC | 14:49 | |
*** woodard has joined #openstack-ansible | 14:49 | |
cloudnull | morning | 14:50 |
mhayden | odyssey4me: a template would work but i was hoping to make the least number of changes possible in case users wanted to tinker with sshd configs and/or sshd configs change upstream | 14:52 |
mhayden | that's why i went with lineinfile | 14:53 |
mhayden | palendae: good call on tags | 14:53 |
odyssey4me | mhayden yeah, I think it's fine as-is :) other improvements can follow on if need be - but yeah, tags could be useful | 14:53 |
ashishjain | cloudnull: good morning | 14:54 |
ashishjain | cloudnull: I am still doing installation :) | 14:55 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: Update cached LXC image in place https://review.openstack.org/224304 | 14:55 |
openstackgerrit | Merged openstack/openstack-ansible: adds the config_template to galera_server https://review.openstack.org/223348 | 14:56 |
openstackgerrit | Merged openstack/openstack-ansible: adds the config_template to pip_lock_down https://review.openstack.org/223350 | 14:56 |
openstackgerrit | Merged openstack/openstack-ansible: Adds the config_template to glance https://review.openstack.org/223288 | 14:56 |
openstackgerrit | Merged openstack/openstack-ansible: Adds the config_template to keystone https://review.openstack.org/223307 | 14:56 |
openstackgerrit | Merged openstack/openstack-ansible: Install nfs-common with nova-compute https://review.openstack.org/223604 | 14:56 |
openstackgerrit | Merged openstack/openstack-ansible: Add auth version for legacy OpenStack clients https://review.openstack.org/223296 | 14:56 |
odyssey4me | cloudnull woohoo! ^^ | 14:57 |
openstackgerrit | Merged openstack/openstack-ansible: Change the network from management to container https://review.openstack.org/225588 | 14:57 |
cloudnull | hahaha its a thing of beauty :) | 14:58 |
cloudnull | ashishjain: did you get past the infra bits ? | 14:58 |
*** daneyon has joined #openstack-ansible | 14:58 | |
ashishjain | cloudnull: na na ... my ssh stopeed working because of insufficient RAM | 14:59 |
ashishjain | just increasing the RAM and about to restart infra | 14:59 |
cloudnull | ah. | 14:59 |
ashishjain | sorry install-openstack | 14:59 |
ashishjain | ya I passed infra | 14:59 |
ashishjain | haproxy etc, this probably is the last leg | 14:59 |
ashishjain | wohooo :) | 15:00 |
cloudnull | yipie ! | 15:00 |
*** phalmos has joined #openstack-ansible | 15:01 | |
*** devlaps has joined #openstack-ansible | 15:02 | |
*** KLevenstein has quit IRC | 15:03 | |
*** elo has quit IRC | 15:05 | |
*** gparaskevas has quit IRC | 15:05 | |
*** cloudtrainme has joined #openstack-ansible | 15:06 | |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Removes over zealous net cache flushing https://review.openstack.org/225367 | 15:07 |
*** KLevenstein has joined #openstack-ansible | 15:09 | |
*** woodard has quit IRC | 15:15 | |
*** devlaps has quit IRC | 15:19 | |
tiagogomes | ok I can now launch a VM \o/ But I can't ping the outside world. I noticed that the router namespace is in only the neutron agent containers. Shoudn't it be in everyone? | 15:23 |
mattt | tiagogomes: i believe only in neutron agents container | 15:24 |
tiagogomes | yes, I meant every agent container. Right now it is in only one | 15:25 |
*** pradk has quit IRC | 15:27 | |
*** devlaps has joined #openstack-ansible | 15:28 | |
*** pradk has joined #openstack-ansible | 15:29 | |
*** woodard has joined #openstack-ansible | 15:29 | |
*** daneyon has left #openstack-ansible | 15:30 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-specs: Adding security hardening spec https://review.openstack.org/222619 | 15:32 |
*** woodard has quit IRC | 15:33 | |
*** tlian has quit IRC | 15:34 | |
openstackgerrit | Merged openstack/openstack-ansible: adds the config_template to tempest https://review.openstack.org/223342 | 15:37 |
*** tlian has joined #openstack-ansible | 15:38 | |
*** woodard has joined #openstack-ansible | 15:59 | |
*** alejandrito has joined #openstack-ansible | 16:03 | |
*** alop has joined #openstack-ansible | 16:03 | |
prometheanfire | mattt: you still want that image? | 16:08 |
prometheanfire | I don't have time to sign it yet, but I can get you the unsigned one | 16:08 |
*** phalmos has quit IRC | 16:10 | |
openstackgerrit | Merged openstack/openstack-ansible: Change recon_lock_path to /var/lock https://review.openstack.org/224060 | 16:13 |
*** phalmos has joined #openstack-ansible | 16:14 | |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Add auth version for legacy OpenStack clients https://review.openstack.org/223692 | 16:14 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Support base64 padding in federated tokens https://review.openstack.org/223888 | 16:15 |
*** javeriak has joined #openstack-ansible | 16:18 | |
*** shausy has quit IRC | 16:18 | |
*** e-vad has left #openstack-ansible | 16:19 | |
*** javeriak has quit IRC | 16:19 | |
odyssey4me | tiagogomes the router namespace shouldn't be on every neutron agents container afaik as neutron can only schedule routers to one agent at a time | 16:20 |
*** javeriak has joined #openstack-ansible | 16:23 | |
*** tlian has quit IRC | 16:31 | |
*** tlian has joined #openstack-ansible | 16:43 | |
*** javeriak has quit IRC | 16:45 | |
*** metral is now known as metral_zzz | 16:50 | |
*** kerwin_bai has quit IRC | 16:52 | |
*** javeriak has joined #openstack-ansible | 16:54 | |
*** abitha has joined #openstack-ansible | 17:04 | |
*** javeriak has quit IRC | 17:08 | |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Adjust default Keystone httpd processes and threads https://review.openstack.org/225145 | 17:10 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: adds the config_template to galera_client https://review.openstack.org/223349 | 17:10 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Adds the config_template to cinder https://review.openstack.org/223209 | 17:10 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Update cached LXC image in place https://review.openstack.org/224304 | 17:10 |
*** metral_zzz is now known as metral | 17:11 | |
*** devlaps has quit IRC | 17:12 | |
*** javeriak has joined #openstack-ansible | 17:13 | |
*** elo has joined #openstack-ansible | 17:15 | |
*** Bjoern_ has joined #openstack-ansible | 17:35 | |
*** subscope has joined #openstack-ansible | 17:37 | |
*** harlowja has joined #openstack-ansible | 17:46 | |
*** gparaskevas has joined #openstack-ansible | 17:58 | |
*** jhesketh has joined #openstack-ansible | 18:01 | |
openstackgerrit | Christopher H. Laco proposed openstack/openstack-ansible: Change recon_lock_path to /var/lock https://review.openstack.org/225965 | 18:04 |
*** fawadkhaliq has joined #openstack-ansible | 18:11 | |
*** javeriak has quit IRC | 18:13 | |
*** ashishjain has quit IRC | 18:15 | |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible: Enable basic ansible fact caching for 24h. https://review.openstack.org/225967 | 18:15 |
*** fawadkhaliq has quit IRC | 18:15 | |
*** javeriak has joined #openstack-ansible | 18:22 | |
*** fawadkhaliq has joined #openstack-ansible | 18:25 | |
openstackgerrit | Merged openstack/openstack-ansible: adds the config_template to neutron https://review.openstack.org/223314 | 18:29 |
openstackgerrit | Merged openstack/openstack-ansible: adds the config_template to nova https://review.openstack.org/223329 | 18:30 |
*** galstrom_zzz is now known as galstrom | 18:32 | |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible: This caching will store all ansible facts inside the redis database and can easily be retrieved via the redis-cli using get ansible_facts+<hostname> or listing all keys via "keys ansible*" The behavior can be turned off by removing the parameter fact_cach https://review.openstack.org/225967 | 18:35 |
*** fawadkhaliq has quit IRC | 18:41 | |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible: This caching will store all ansible facts inside the redis database. https://review.openstack.org/225967 | 18:42 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: [WIP] Run Cinder from a venv https://review.openstack.org/225463 | 18:42 |
openstackgerrit | Christopher H. Laco proposed openstack/openstack-ansible: Change recon_lock_path to /var/lock https://review.openstack.org/225981 | 18:45 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Update master for past liberty-3 for testing https://review.openstack.org/225459 | 18:45 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Update master for past liberty-3 for testing https://review.openstack.org/225459 | 18:46 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: [WIP] Run Cinder from a venv https://review.openstack.org/225463 | 18:46 |
*** javeriak has quit IRC | 18:57 | |
*** gparaskevas has quit IRC | 18:57 | |
*** KLevenstein has quit IRC | 19:35 | |
*** KLevenstein has joined #openstack-ansible | 19:45 | |
*** KLevenstein has quit IRC | 19:59 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Break apart and document the upgrade process https://review.openstack.org/224137 | 20:01 |
*** KLevenstein has joined #openstack-ansible | 20:05 | |
mhayden | haha, jenkins has to be getting tired of checking that LXC update in place commit :P | 20:06 |
palendae | mhayden: Jenkins is like Alfred Pennyworth - always there to help, no matter how much crap you give it | 20:07 |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible: Fact caching will store all ansible facts inside the redis database once enabled. https://review.openstack.org/225967 | 20:19 |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible: Fact caching will store all ansible facts inside the redis database once enabled. https://review.openstack.org/225967 | 20:28 |
*** elo has quit IRC | 20:32 | |
prometheanfire | cloudnull: you're welcome | 20:36 |
*** elo has joined #openstack-ansible | 20:38 | |
*** markvoelker has quit IRC | 20:41 | |
*** jwagner is now known as jwagner_lunch | 20:48 | |
*** elo has quit IRC | 20:48 | |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible: Implement Neutron LBAAS using haproxy https://review.openstack.org/220365 | 20:49 |
*** Mudpuppy has quit IRC | 20:52 | |
*** pradk has quit IRC | 20:55 | |
*** woodard has quit IRC | 20:58 | |
*** jwagner_lunch is now known as jwagner | 21:19 | |
*** markvoelker has joined #openstack-ansible | 21:20 | |
openstackgerrit | Merged openstack/openstack-ansible: Adds group support to inventory-manage.py https://review.openstack.org/224977 | 21:42 |
*** prometheanfire has quit IRC | 21:43 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Break apart and document the upgrade process https://review.openstack.org/224137 | 21:44 |
mhayden | yay inventory-manage.py ;) | 21:44 |
*** tlian2 has joined #openstack-ansible | 21:48 | |
openstackgerrit | Merged openstack/openstack-ansible: Adds the config_template to cinder https://review.openstack.org/223209 | 21:50 |
openstackgerrit | Merged openstack/openstack-ansible: Change recon_lock_path to /var/lock https://review.openstack.org/225965 | 21:50 |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible: Implement Neutron LBAAS using haproxy https://review.openstack.org/220365 | 21:50 |
*** KLevenstein has quit IRC | 21:50 | |
*** tlian has quit IRC | 21:51 | |
*** elo has joined #openstack-ansible | 21:54 | |
openstackgerrit | Merged openstack/openstack-ansible: Support base64 padding in federated tokens https://review.openstack.org/223888 | 21:58 |
openstackgerrit | Merged openstack/openstack-ansible: Changed the Diffie Hellman parameter maximum size https://review.openstack.org/224760 | 22:03 |
*** alejandrito has quit IRC | 22:05 | |
openstackgerrit | Merged openstack/openstack-ansible: Add auth version for legacy OpenStack clients https://review.openstack.org/223692 | 22:09 |
*** elo has quit IRC | 22:20 | |
*** elo has joined #openstack-ansible | 22:20 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Break apart and document the upgrade process https://review.openstack.org/224137 | 22:26 |
*** spotz is now known as spotz_zzz | 22:32 | |
openstackgerrit | Merged openstack/openstack-ansible: adds the config_template to galera_client https://review.openstack.org/223349 | 22:39 |
*** galstrom is now known as galstrom_zzz | 22:46 | |
*** markvoelker has quit IRC | 22:48 | |
*** cloudtrainme has quit IRC | 23:06 | |
*** elo has quit IRC | 23:23 | |
*** brice_ has joined #openstack-ansible | 23:42 | |
*** phalmos has quit IRC | 23:53 | |
*** markvoelker has joined #openstack-ansible | 23:56 | |
*** abitha has quit IRC | 23:57 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!