Wednesday, 2015-10-14

*** BjoernT has quit IRC00:02
openstackgerritMerged openstack/openstack-ansible: Removed unnecessary comment in the user_secrets for ceph variable  https://review.openstack.org/23315200:03
*** scarlisle has quit IRC00:03
openstackgerritMerged openstack/openstack-ansible: Use inventory instead of hostfile parameter  https://review.openstack.org/23187000:08
openstackgerritMerged openstack/openstack-ansible: Updates the lint check to ignore templates  https://review.openstack.org/23110100:18
*** tlian2 has joined #openstack-ansible00:26
*** tlian has quit IRC00:28
*** darrenc_afk is now known as darrenc00:36
*** sdake has joined #openstack-ansible00:43
*** markvoelker has quit IRC00:47
*** tlian2 has quit IRC00:55
*** sdake has quit IRC00:58
*** sdake has joined #openstack-ansible01:02
*** tlian has joined #openstack-ansible01:03
*** markvoelker has joined #openstack-ansible01:48
openstackgerritBjoern Teipel proposed openstack/openstack-ansible: Implement Neutron LBAAS using haproxy  https://review.openstack.org/22036501:49
*** markvoelker has quit IRC01:53
*** daneyon has joined #openstack-ansible01:53
*** daneyon_ has joined #openstack-ansible01:56
*** daneyon has quit IRC01:59
openstackgerritMerged openstack/openstack-ansible: Update Cinder Configuration for Liberty  https://review.openstack.org/22720502:01
*** sdake has quit IRC02:06
*** sdake has joined #openstack-ansible02:08
*** sdake_ has joined #openstack-ansible02:29
*** sdake has quit IRC02:30
*** markvoelker has joined #openstack-ansible02:49
*** markvoelker has quit IRC02:53
*** spotz_zzz is now known as spotz02:57
*** woodard has quit IRC03:10
*** sdake_ has quit IRC03:14
*** sdake has joined #openstack-ansible03:23
openstackgerritKevin Carter proposed openstack/openstack-ansible: Updated the repo-build process  https://review.openstack.org/23071603:28
openstackgerritKevin Carter proposed openstack/openstack-ansible: Updated the repo-build process  https://review.openstack.org/23071603:39
*** markvoelker has joined #openstack-ansible03:50
*** markvoelker has quit IRC03:54
*** tlian has quit IRC04:21
openstackgerritMerged openstack/openstack-ansible: Added LC_ALL to openrc  https://review.openstack.org/23238804:26
*** markvoelker has joined #openstack-ansible04:50
*** markvoelker has quit IRC04:55
*** shausy has joined #openstack-ansible05:17
*** pellaeon has quit IRC05:18
*** jwitk0 has joined #openstack-ansible05:32
jwitk0Hey guys whats the latest OSAD release that should be used to deploy Kilo?05:32
jwitk011.2.3 ?05:32
stevellejwitk0: that looks like a pretty good choice05:35
*** shausy has quit IRC05:35
*** shausy has joined #openstack-ansible05:35
*** markvoelker has joined #openstack-ansible05:51
*** markvoelker has quit IRC05:56
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: Switch from MySQL-python to PyMySQL  https://review.openstack.org/23317206:18
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: Update Nova Configuration for Liberty  https://review.openstack.org/22783906:19
*** Mudpuppy has quit IRC06:26
*** spotz is now known as spotz_zzz06:37
*** sdake_ has joined #openstack-ansible06:43
*** neilus1 has joined #openstack-ansible06:45
*** sdake has quit IRC06:46
*** markvoelker has joined #openstack-ansible06:52
*** ashishjain has joined #openstack-ansible06:53
ashishjainHello06:54
ashishjainFinally I am able to stabilize my osad setup06:54
ashishjainI have a question on openrc file which refers to v3.0 of the openstack api06:55
ashishjainwhenever I run it says 404 not found06:56
ashishjainhowever when I modify to export OS_AUTH_URL=http://192.168.30.6:5000/v2.0/ it seems to be running fine06:56
*** markvoelker has quit IRC06:56
ashishjainWhat shall I do to make v3.0 of the api work?06:56
*** sdake_ has quit IRC06:57
*** subscope has joined #openstack-ansible06:59
*** openstackgerrit has quit IRC07:01
*** openstackgerrit has joined #openstack-ansible07:01
*** ggillies has quit IRC07:10
*** subscope has quit IRC07:26
odyssey4meI think you mean v3 of the Keystone API? OpenStack has many API's at different versions.07:27
odyssey4mejwitk0 yes, the latest tagged version07:28
odyssey4meashishjain if you can pastebin your openrc (feel free to edit the password) then I can look at that07:30
odyssey4meashishjain but it sounds to me like you have a misconfiguration07:30
ashishjainodyssey4me: here is the paste http://paste.openstack.org/show/476223/07:33
ashishjainodyssey4me: If I change the the export OS_AUTH_URL=http://192.168.30.6:5000/v3.0 to export OS_AUTH_URL=http://192.168.30.6:5000/v2.0/ I am able to make atleast neutron work07:34
ashishjainHowever their is another catch when I use the same setting(v2.0) with glance I am bombed with the message "glance image-list An auth plugin is required to fetch a token"07:35
ashishjainodyssey4me: Yes I mean v3.0 of keystone api07:37
odyssey4meashishjain can you also please pastebin your service catalogue07:38
odyssey4meexecute: openstack endpoint list07:38
odyssey4meok, the problem is that you have v3.0 instead of v3 in the URL07:39
odyssey4mehow did that happen?07:39
*** kerwin_bai has joined #openstack-ansible07:39
ashishjainodyssey4me: actually sorry ... I changed v3 to v2.0 and than forgot to remove .0 when changing it back to 307:43
ashishjainLooks like its working fine .... thanks a lot for your help07:44
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: Update rabbitmq-server to v3.5.6-1  https://review.openstack.org/23370007:45
*** markvoelker has joined #openstack-ansible07:53
*** markvoelker has quit IRC07:57
*** mgoddard has joined #openstack-ansible08:10
*** trash has left #openstack-ansible08:16
*** Mudpuppy has joined #openstack-ansible08:22
*** bapalm has quit IRC08:23
*** bapalm has joined #openstack-ansible08:26
*** Mudpuppy has quit IRC08:27
*** neilus1 has quit IRC08:33
*** neilus has joined #openstack-ansible08:33
*** finchd has quit IRC08:35
*** wabu has quit IRC08:35
*** wabu has joined #openstack-ansible08:35
*** spotz_zzz is now known as spotz08:37
*** finchd has joined #openstack-ansible08:38
*** spotz is now known as spotz_zzz08:47
*** gparaskevas has joined #openstack-ansible08:51
*** markvoelker has joined #openstack-ansible08:53
*** subscope has joined #openstack-ansible08:54
*** gparaskevas has quit IRC08:55
*** tiagogomes_ has joined #openstack-ansible08:57
*** harvy has joined #openstack-ansible08:58
*** markvoelker has quit IRC08:58
*** subscope has quit IRC09:01
*** subscope has joined #openstack-ansible09:01
ashishjainHello09:10
ashishjainHitting another issue while spawning a vm09:10
ashishjainThe error says "Unable to mount image /var/lib/nova/instances/5cb913f2-bdec-48c7-9507-741ac4250e41/disk with error libguestfs installed but not usable (cannot find any suitable libguestfs supermin, fixed or old-style appliance on LIBGUESTFS_PATH (search path: /usr/lib/guestfs)). Cannot resize.'09:11
ashishjainupdate-guestfs-appliance09:12
ashishjainUbuntu documentation says "http://manpages.ubuntu.com/manpages/trusty/man1/guestfs-faq.1.html"09:12
ashishjainWhen I try to run the command on my compute node I get the following "sudo apt-get install libguestfs-tools" which means libguestfs in not installed.09:12
ashishjainDoes Kilo expect to have this on the compute node?09:13
*** kerwin_bai has quit IRC09:23
matttashishjain: is that actually preventing the VM from spawning?09:23
mattt99% sure i've seen that before but it didn't stop the VM from coming up09:24
tiagogomes_Hi, I got this error with the kilo branch http://paste.openstack.org/show/476228/09:26
mattttiagogomes_: not rebuilt your repo server recently ?09:27
tiagogomes_I did a fresh install09:27
matttWUT09:27
tiagogomes_My openstackgit is always empty09:29
ashishjainmatt: Yes you are correct09:29
tiagogomes_Because I think it is being excluded on the rsync of the upstream repo09:29
ashishjainmattt: Shall I install libguestfs manually09:29
mattttiagogomes_: ah you have to build the repo not sync it09:29
ashishjainmattt: I can do it but I am just wokdering that if I did not run my playbooks properly09:29
ashishjain*wondering09:30
tiagogomes_but I did a fresh install09:30
mattttiagogomes_: ok one sec ... so you're running kilo right09:30
tiagogomes_matt yes09:30
ashishjainmattt: Is installing libguesfs on compute node one of parts of osad?09:30
mattttiagogomes_: this is a problem which someone hasn't accounted for09:31
mattttiagogomes_: repo-install.yml which you presumably ran does the clone, but i'm not sure the upstream repo has the git bits09:31
mattttiagogomes_: so what i'm proposing is you don't clone from the upstream repo but run the build of the python packages, etc. locally in your repo container instead09:32
tiagogomes_mattt `repo_mirror_excludes: /openstackgit`09:32
mattttiagogomes_: so instead of running repo-clone.yml you can run repo-build.yml, this is the default behaviour in master (liberty) now09:32
mattttiagogomes_: tbh i have no idea what the idea there is, perhaps odyssey4me knows09:33
ashishjaintiagogomes_: Are you using gitlab?09:33
mattttiagogomes_: but personally i'd always recommend repo-build.yml instead of repo-clone.yml, it's quite a long task to run but it will cause you less grief than cloning09:33
matttashishjain: sec, looking at your question now as i don't know :P09:33
* tiagogomes_ doesn't like the idea to monkeypatch the repo09:34
tiagogomes_I think will just revert the commit09:34
mattttiagogomes_: honestly repo-build.yml is the way forward09:34
mattttiagogomes_: that is also what our gate job does09:34
*** shausy has quit IRC09:34
*** shausy has joined #openstack-ansible09:35
mattttiagogomes_: only catch is if you previously ran repo-clone.yml i believe you have to wipe /var/www/repo on your repo containres otherwise you run into some issues09:35
ashishjaintiagogomes_:  Try this out http://10.3.0.100:8181/openstackgit/spice-html5.git09:35
ashishjainNot sure but I hit a similar issue and appending .git helped me09:35
ashishjainmattt: Sure09:35
tiagogomes_ashishjain my openstackgit is empty09:35
tiagogomes_mattt so the plan is to patch kilo to use repo-build instead of repo-clone?09:37
mattttiagogomes_: i didn't think so, it was a change in master and up09:37
mattttiagogomes_: but i think whoever backported the spice-html5 change didn't account for the fact that kilo still uses repo-clone.yml09:37
tiagogomes_well, the deployment right now is broken, so it needs to be fixed somehow09:38
matttyeah so you could start by filing a bug and we take it from there :)09:38
*** subscope has quit IRC09:39
ashishjainmattt: it indeed is part of os-nova-install.yml09:39
ashishjainI will rerun the playbook09:39
ashishjainmattt: thanks09:39
matttashishjain: ok cool, odd that it didn't get installed the first time around tho?09:40
ashishjainmattt: For me playbooks have failed many many times and so something would have lead it to skip stuff09:43
mattttiagogomes_: you creating the bug or shall i ?09:44
tiagogomes_mattt not at the moment, I can create it in 30m if you want09:44
mattttiagogomes_: i'll put it through, but if you want to move the build along nuke /var/www/repo on the repo containers and run repo-server.yml and repo-build.yml09:46
tiagogomes_mattt ok, thanks09:47
mattttiagogomes_: it may just be a case of removing that exclude from kilo so it can sync properly as http://rpc-repo.rackspace.com/openstackgit/ does exist09:49
tiagogomes_mattt I'll try that, because it should take less time09:50
mattttiagogomes_: i'll put that change through, it seems like the only option to me09:50
tiagogomes_mattt cool, so are you creating the bug?09:51
mattttiagogomes_: https://bugs.launchpad.net/openstack-ansible/+bug/150597809:52
openstackLaunchpad bug 1505978 in openstack-ansible "Kilo still defaults to repo-clone-mirror.yml but does not sync openstackgit" [Undecided,New]09:52
tiagogomes_mattt ta09:52
*** markvoelker has joined #openstack-ansible09:54
openstackgerritMatt Thompson proposed openstack/openstack-ansible: Remove /openstackgit from repo_mirror_excludes  https://review.openstack.org/23469809:57
*** markvoelker has quit IRC09:58
mattt^^^ tiagogomes_09:58
*** subscope has joined #openstack-ansible10:22
openstackgerritMerged openstack/openstack-ansible: Switch from MySQL-python to PyMySQL  https://review.openstack.org/23317210:26
*** spotz_zzz is now known as spotz10:38
odyssey4metiagogomes_ mattt sorry - was afk for a bit - yes, it would seem that we need to ensure that either the clone process also builds the git repo, or we need to have a copy of the bits upstream for the clone process10:45
odyssey4methat's a definite bug10:46
odyssey4meheh, oh nice mattt I see you have a review to fix? tiagogomes_ if you can feedback whether that works in the review it'd be great10:46
*** spotz is now known as spotz_zzz10:48
* tiagogomes_ already did10:50
*** markvoelker has joined #openstack-ansible10:55
*** markvoelker has quit IRC11:00
*** neilus has quit IRC11:04
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: Update stable/liberty SHA's to Liberty RC3  https://review.openstack.org/23473011:17
*** manas has joined #openstack-ansible11:21
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: Remove oslo.versionedobjects 0.11.0 block  https://review.openstack.org/23473311:23
*** gparaskevas has joined #openstack-ansible11:27
*** spotz_zzz is now known as spotz11:41
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: Remove WebOb 1.5.0 cap  https://review.openstack.org/23474211:41
odyssey4memattt are you still testing and reviewing https://review.openstack.org/#/q/status:open+project:openstack/openstack-ansible+branch:master+topic:bp/enable-venv-support-within-the-roles,n,z ?11:46
*** spotz is now known as spotz_zzz11:51
*** subscope has quit IRC11:54
*** markvoelker has joined #openstack-ansible11:56
*** subscope has joined #openstack-ansible11:57
*** markvoelker has quit IRC12:00
*** markvoelker has joined #openstack-ansible12:00
*** manas has quit IRC12:02
*** persia has quit IRC12:02
*** persia has joined #openstack-ansible12:03
*** manas has joined #openstack-ansible12:05
*** spotz_zzz is now known as spotz12:06
*** subscope has quit IRC12:07
matttodyssey4me: not at the minute not12:08
mattt*no12:08
odyssey4memattt how are you feeling about reviews generally?12:13
odyssey4meto me it seems good - they clearly work12:13
odyssey4medolph added a good query which applies to keystone & horizon which I think warrants an update, perhaps - cloudnull will need to check that out12:14
matttodyssey4me: well we found the bug yesterday, not had time to go back and retest everything since12:14
matttbut yesterday it didn't work12:14
matttnow why the gate was passign i have absolutely no idea12:14
matttsuper confusing12:14
matttso i'd like to just test them all together again and give it all a once-over before +2ing12:15
odyssey4memat it looks like the sha updates which include yesterday's fixes are good: https://review.openstack.org/23473012:17
odyssey4memattt ^12:17
matttodyssey4me: why not remove versionedobjects and WebOb in one review?12:20
odyssey4memattt the jury's still out on whether the updates resolve all the issues :)12:20
odyssey4meI split them up to test them properly.12:21
matttimagine you could have added them to the bump sha review to test :P12:21
odyssey4memattt if the sha bump works, which it did, I didn't want to delay that merge if the other pin removals didn't work12:23
*** woodard has joined #openstack-ansible12:23
odyssey4methe sha bump is more important to move along than the pins12:23
*** neilus has joined #openstack-ansible12:24
*** Mudpuppy has joined #openstack-ansible12:24
mattti didn't know we were racing against the clock12:24
matttodyssey4me: going to be circling back to the venv stuff in a few mins, had to look at some ceph stuff this morning12:25
matttso hopefully we can get those moving shortly12:25
odyssey4memattt ah, thanks12:26
odyssey4meideally I'd like to release our liberty branch as close as possible to upstream's release, and the venv work is part of that12:26
odyssey4meour planned release date is the end of next week, and I'd like the current stream of patches to have some basking time12:27
odyssey4me*baking12:27
matttyeah makes sense12:27
odyssey4mebesides - the next batch of work relates to the upgrading of kilo to liberty, and the gate split out... the sooner we can get onto that work, the better12:28
odyssey4memore gate tests will expose issues faster12:28
*** Mudpuppy has quit IRC12:29
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: Update Nova Configuration for Liberty  https://review.openstack.org/22783912:33
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: Update stable/liberty SHA's to Liberty RC3  https://review.openstack.org/23473012:33
*** spotz is now known as spotz_zzz12:35
*** vdo has joined #openstack-ansible12:36
odyssey4memattt it looks like https://review.openstack.org/234733 is good12:41
*** subscope has joined #openstack-ansible12:43
matttk12:45
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: [WIP] Check existing pip.conf in OpenStack-CI  https://review.openstack.org/23476812:48
cloudnullodyssey4me:  what should i go look at ?12:49
cloudnullmorning btw.12:49
odyssey4memorning cloudcull12:49
odyssey4medolphm raised a good question in https://review.openstack.org/229513 which will also apply to https://review.openstack.org/22922612:50
odyssey4meif his suggestion works, it may result in a bit more optimisation there (we don't need to hack the wsgi script)12:50
matttkeystone_bin: "{{ keystone_venv_bin }}"12:55
matttguess if his comment is true there then we have a good few updates to do12:56
matttbut i thought you could just run the bin like that12:56
odyssey4memattt I was talking about this comment, actually: https://review.openstack.org/#/c/229513/12/playbooks/roles/os_keystone/templates/keystone-wsgi.py.j2,cm12:57
matttyeah that i have absolutely no idea about :)12:58
*** javeriak has joined #openstack-ansible12:59
*** mgoddard has quit IRC13:03
*** tlian has joined #openstack-ansible13:07
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: [WIP] Check existing pip.conf in OpenStack-CI  https://review.openstack.org/23476813:09
*** subscope has quit IRC13:11
cloudnullopenstackgerrit:  i added responses in https://review.openstack.org/#/c/22951313:15
cloudnullmattt:  you are right you can simply run the bin and it will execute within the venv13:15
cloudnullthe installation within a venv has either #! to the venv python or an activate_this call which forces it to use the venv'd python13:16
odyssey4methanks cloudnull for responding to dolphm - my vote is back to +2 for keystone & horizon13:18
*** subscope has joined #openstack-ansible13:19
*** javeriak has quit IRC13:23
*** javeriak has joined #openstack-ansible13:23
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-3864{2,5,7,9}, V-38651: Umask adjustments  https://review.openstack.org/23312013:28
*** subscope has quit IRC13:28
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38623: rsyslog file permissions  https://review.openstack.org/23433113:29
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38546: Disable IPv6 system-wide  https://review.openstack.org/23433313:30
*** cloudtrainme has joined #openstack-ansible13:34
*** Mudpuppy has joined #openstack-ansible13:35
*** Mudpuppy has quit IRC13:35
*** Mudpuppy has joined #openstack-ansible13:36
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-51391: Initialize AIDE  https://review.openstack.org/23426413:38
mhaydenpalendae: added a configurable exclusion list in https://review.openstack.org/23426413:38
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38637, V-3866{3,4,5}: Verify auditd pkg contents  https://review.openstack.org/23276713:38
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-3857{4,6,7}: Password hashing algorithms  https://review.openstack.org/23307113:38
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38655: Mount w/noexec exception  https://review.openstack.org/23314713:39
*** subscope has joined #openstack-ansible13:39
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-386**: Disabling various unneeded services  https://review.openstack.org/23319813:39
mhaydenpardon the rebasing... ;)13:39
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-3865{6,7}: Samba  https://review.openstack.org/23321513:39
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38643: World writable files  https://review.openstack.org/23321613:39
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38658: Password reuse restrictions  https://review.openstack.org/23321913:39
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38659, V-38662, V-38693: Encrypted storage exception docs  https://review.openstack.org/23322113:40
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38660: SNMPv3  https://review.openstack.org/23322613:40
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-386{67,70,95,96,98}, V-38700: Run AIDE via cron  https://review.openstack.org/23323113:40
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38678: Auditd space_left size  https://review.openstack.org/23323713:40
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38671: Remove sendmail  https://review.openstack.org/23324213:40
mhaydenhad some fun merge conflicts ;)13:40
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38672: Remove netconsole service  https://review.openstack.org/23324313:40
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38680: Audit log capacity notifications  https://review.openstack.org/23324713:40
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-3869{2,4}: Lock inactive accounts  https://review.openstack.org/23325513:40
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-3867{4,6}: X windows  https://review.openstack.org/23325913:40
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38675: Restrict core dumps  https://review.openstack.org/23326113:41
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38679: Disable DHCP client docs  https://review.openstack.org/23326213:41
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38684: Max concurrent sessions  https://review.openstack.org/23326413:41
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38682: Disable bluetooth modules  https://review.openstack.org/23327013:41
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38687: VPN connectivity (exception docs)  https://review.openstack.org/23327313:41
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-53481: Auditd disk space + single-user mode  https://review.openstack.org/23327613:41
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38702: FTP daemon logging  https://review.openstack.org/23327913:41
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-51337: Use an LSM at boot  https://review.openstack.org/23328413:41
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-51875: Symlink for docs  https://review.openstack.org/23328513:41
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38622: Restricted mail relaying  https://review.openstack.org/23420413:41
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38683: Check for non-unique usernames  https://review.openstack.org/23420913:41
*** evrardjp has quit IRC13:42
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38681: GID's in /etc/passwd & /etc/group  https://review.openstack.org/23421513:42
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-51739: LSM device labeling exception  https://review.openstack.org/23422713:42
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38699: Public directories exception  https://review.openstack.org/23423513:42
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-386{85,90}: Temporary/emergency accounts (exception)  https://review.openstack.org/23423713:42
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-58901: sudo requires auth  https://review.openstack.org/23423913:42
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38697: Sticky bit (exception)  https://review.openstack.org/23424913:42
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-51391: Initialize AIDE  https://review.openstack.org/23426413:42
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: Docs overhaul  https://review.openstack.org/23443913:42
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38496: Lock system accounts other than root  https://review.openstack.org/23201213:43
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38498: Audit log file permissions  https://review.openstack.org/23205613:43
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38500: No UID 0 accounts except root  https://review.openstack.org/23207013:43
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38501, V-38573: Disable accounts after failed logins  https://review.openstack.org/23207413:43
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-3851{1,2,3}, V-38686: IPv4 security controls  https://review.openstack.org/23208813:43
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-3851{4,5,6,7}: Disabling certain network protocols  https://review.openstack.org/23212913:43
*** subscope has quit IRC13:44
*** mnestheu1 has joined #openstack-ansible13:44
*** subscope has joined #openstack-ansible13:44
*** cloudtrainme has quit IRC13:44
*** mnestheu1 is now known as scarlisle13:44
*** evrardjp has joined #openstack-ansible13:45
*** javeriak_ has joined #openstack-ansible13:50
*** evrardjp has quit IRC13:51
*** javeriak has quit IRC13:53
*** javeriak has joined #openstack-ansible13:56
*** javeriak_ has quit IRC13:56
*** neilus has quit IRC13:58
*** evrardjp has joined #openstack-ansible13:58
*** KLevenstein has joined #openstack-ansible14:00
*** manas has quit IRC14:00
*** k_stev has joined #openstack-ansible14:01
*** jwagner_away is now known as jwagner14:01
*** sigmavirus24_awa is now known as sigmavirus2414:02
*** cloudtrainme has joined #openstack-ansible14:03
*** cloudtrainme has quit IRC14:06
palendaemhayden: Cool on the exclusion list - that may actually be a more general issue to resolve; is this role just for use with openstack-ansible, or ansible and openstack installs?14:06
*** gcivitella has joined #openstack-ansible14:11
*** k_stev has quit IRC14:16
matttcloudnull: sorry kevin, lots of trivialish comments in the glance venv review14:18
*** alop has joined #openstack-ansible14:19
*** k_stev has joined #openstack-ansible14:24
*** phalmos has joined #openstack-ansible14:43
odyssey4memhayden I would expect that the security role is for use for any host? why should it just be for openstack, or for openstack-ansible environments? it's pretty generic as far as I can see14:50
matttodyssey4me: was kinda thinking this too :P14:51
mattti didn't see what the overlap with openstack-ansible was14:51
palendae^14:51
odyssey4memattt I see openstack-ansible simply as a custodian.14:51
odyssey4meAnd openstack-ansible may consume the role at some point in time in the future.14:52
mhaydenthere are some things that are skipped for openstack envs14:53
mhaydenso it has some openstack specific configurations14:53
mhaydenmy goal was to make it drop in compatible with openstack-ansible14:54
mhaydendoes that make sense?14:55
odyssey4me:) a tool in the toolbox - it makes absolute sense14:55
palendaeSure. I think the goal of splitting out roles was to make them all more general14:55
mhaydenit could be used outsude of openstack ansiblr14:55
mhaydenwow phone keyboard fail14:55
*** cloudtrainme has joined #openstack-ansible14:56
matttnah, i think it's great if it can be designed ot not tear an openstack-ansible deploy apart :)14:56
matttbut it does seem to be very limiting making it only work on an openstack-ansible deploy14:56
bgmccollummhayden: could the openstack specific configs be controlled via role parametrization?14:57
mhaydenanother goal is to make it deployable to OS envs without disruptions14:57
mhaydenbgmccollum: possibly. what are you thinking?14:57
*** javeriak has quit IRC14:57
*** cloudtrainme has quit IRC14:58
bgmccollummhayden: you said some parts are skipped for openstack envs...so the parts being skipped could be controlled via role parameters14:58
mhaydenthats what i put in defaults/main.yml14:59
palendae^14:59
mhaydenand that yml is heavily docunented14:59
*** cloudtrainme has joined #openstack-ansible15:00
*** phalmos has quit IRC15:01
*** spotz_zzz is now known as spotz15:02
*** ashishjain has quit IRC15:03
cloudnullmattt: i've updated the glance venv review. let me know what you think and ill hope to getting the changes in15:04
matttcloudnull: ok will have a peek, thanks !15:12
cloudnullno thank you sir15:12
*** cloudtrainme has quit IRC15:23
*** jwagner is now known as jwagner_away15:23
*** cloudtrainme has joined #openstack-ansible15:24
*** spotz is now known as spotz_zzz15:24
*** spotz_zzz is now known as spotz15:25
*** mgoddard has joined #openstack-ansible15:26
mhaydenbgmccollum / palendae: would you suggest having openstack-ansible-security outside of openstack somewhere?15:28
*** sdake has joined #openstack-ansible15:29
palendaemhayden: Maybe just on galaxy...though to me it seems a bit bizarre not putting security measures directly in relevant roles, honestly15:29
odyssey4mepalendae it's an experiment of sorts15:29
bgmccollummhayden: just depends on the scope...its its meant to be a general role...then maybe yes? and OSA can source it...and pass in its desired config...15:29
mhaydenpalendae: i suggested that but it was shot down quickly ;)15:29
odyssey4meperhaps some stuff belongs in roles, but perhaps not - until they're expressed fully we won't know15:29
odyssey4mealso, we can (and I'd like to) register this role into galaxy15:30
palendaeodyssey4me: Security seems important enough to me to not be directly in roles, but it's already going down this road15:30
mhaydenhowever, i'd like to review the openstack security guide and begin applying some of those recommendations in openstack-ansible via configurables15:30
odyssey4meit is pretty much as applicable as the galera role15:30
*** KLevenstein has quit IRC15:30
mhaydenlike communicating between services over ssl, etc15:30
palendaeEr, that was worded poorly15:30
odyssey4methe point is that just because it's there now, doesn't mean that it can't be implemented differently in the future15:31
odyssey4mefor now the scope was to do it thusly15:31
palendaeI understand. Just saying, I'm not sure I see security as a thing that should be a separate role15:31
odyssey4memhayden you should definitely work on doing the security guide thing in the roles during the mitaka cycle15:32
odyssey4mesomething you could also propose is for the security role to be consumed by the playbooks with the appropriate switches turned on or off15:32
bgmccollumare there scenarios that one wouldnt want security for free?15:32
palendae^15:33
odyssey4me?15:34
palendaeIf I understand the question - why would you want a (for example) galera role that doesn't include any security measures?15:34
bgmccollumif its hassle free from the deployers perspective...then by all means...make it as secure as humanly possible15:35
*** KLevenstein has joined #openstack-ansible15:36
mhaydenodyssey4me: it's on my list ;)15:36
*** sdake has quit IRC15:36
*** KLevenstein has quit IRC15:36
odyssey4methat's a broad question15:37
odyssey4mewhy would you not want to use ssl comms for all web services?15:37
mhaydenwell i did add an SSL/TLS listener to rabbitmq... ;)15:37
*** KLevenstein has joined #openstack-ansible15:37
*** sdake has joined #openstack-ansible15:37
odyssey4meyou wouldn't want it as a developer because it makes debugging hell, and creates an extra layer of complexity15:38
odyssey4meit's fine to be layered on top, but not as a base15:38
odyssey4methe same applies to many security things15:38
odyssey4memost of the stuff in the role could probably be implemented by default as it's not in the same category15:39
odyssey4mebut some of it most definitely is a hinder to the development process, and some to the operational process - they're things you want to opt-in to15:39
palendaeSure, but then you opt in on the specific service15:39
palendaee.g. on the galera role15:40
odyssey4meexactly, but then that gets done by the playbook15:40
palendaeRight...and then I don't see a reason for a separate role to exist15:40
palendaePut things where they're used15:41
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: Update Nova Configuration for Liberty  https://review.openstack.org/22783915:42
odyssey4methe purpose of the role is specific15:43
odyssey4methe security role is to apply security best practises15:43
odyssey4meon a general host level15:43
odyssey4meif we take those tasks and put them into other roles, we'll be duplicating code all over the place - and maintaining that will become very unwieldy15:44
palendaeSo galera securing will be duplicated everywhere?15:44
odyssey4mekeeping it in a purpose specific role simplifies its use, and its maintenance15:44
bgmccollumi can see there being a separate role for host security best practices...generic to be used outside the confines of OSA...15:45
odyssey4meif the task is galera server specific, then perhaps it does belong in the galera role15:45
*** mgoddard_ has joined #openstack-ansible15:45
bgmccollumthere there is the securing of OS bits...which should be in their relevant OSA roles15:45
*** gparaskevas has quit IRC15:45
bgmccollum*then15:45
palendaeI can see locking things down along those lines15:45
odyssey4meright, so openstack-ansible is simply a custodian of ansible roles which are used in an openstack environment - and a publisher of playbooks to consume those roles in specific use-cases which are common to its consumers15:46
odyssey4methere is no reason why the project can't host roles that aren't specifically openstack related15:47
palendaeI don't think anyone's disagreeing there15:47
mhaydeni look at security on two levels here: 1) host security and 2) openstack services security15:47
palendaeWhat I'm saying is, if that role grows service-specific security, like galera, or rabbit, or whatever, I think that's the incorrect place15:47
mhayden#1 is where openstack-ansible-security comes in15:47
*** mgoddard has quit IRC15:48
mhayden#2 is the openstack security guide15:48
bgmccollumseems pretty clear cut to me15:48
bgmccollum+115:48
odyssey4mepalendae I agree with you there.15:48
odyssey4memhayden also agreed15:48
bgmccollummy only point was that openstack-ansible-security shouldn't have any bias towards being applied to an openstack environment...if the intent is that it could be used outside OSA15:50
mhaydenbgmccollum: i'm 100% in agreement15:51
bgmccollumor is the intent that its supposed to be used in an openstack environment, but not necessarily a OSA deployed environment?15:51
mhaydenbut i'm in a bit of a hard place here with this many reviews in flight ;)15:51
bgmccollumthe good news is...code is malleable...and time in infinite15:52
palendaemhayden: It is a lot, and you don't really have established reviewers on that repo, do you?15:53
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: Don't require latest auditd version  https://review.openstack.org/23485615:53
mhaydenpalendae: right, and no15:54
mhaydenthere are 7 reviews with a +1, one with a +2 and +115:55
mhaydenthe rest are empty15:55
palendaeHow does one get a +2?15:56
mhaydenbut i'm trying to be as responsive as possible when folks suggest changes ;) wink wink15:56
mhaydenpalendae: i normally buy cloudnull beer for that15:56
palendaeAnd what is your merge criteria?15:56
palendaemhayden: I mean, how does one get core reviewer status on that repo?15:57
mhaydenpalendae: it's attached to openstack-ansible15:57
palendaeNothing's going to merge if it needs 2 +2s and there's < 215:57
palendaeMm15:57
palendaeOk15:57
mhaydenpalendae: https://review.openstack.org/#/q/status:open+project:openstack/openstack-ansible-security,n,z15:57
mhaydenpalendae: i put some suggested criteria here -> http://lists.openstack.org/pipermail/openstack-dev/2015-October/076929.html15:58
odyssey4meright now the core is shared - if the need arises in the future for that to change, it can change15:58
matttpalendae: you should be able to +2 stuff15:58
palendaemattt: I removed myself from core15:58
mhaydenthat's hardcore15:58
matttwell there's that.15:58
mhaydensomehow mattt has the ability for a -3.14 ;)15:58
*** mgoddard_ has quit IRC15:59
odyssey4meI'm certainly pro the idea of having role-specific cores.16:00
*** sdake_ has joined #openstack-ansible16:00
palendaeodyssey4me: I was more asking to see where the bottle neck for mhayden getting his reviews16:00
* mhayden assumes everyone is busy16:01
mhayden:)16:01
*** sdake has quit IRC16:01
mhaydenand usually when i mention security at the office, people think of this: https://41.media.tumblr.com/1721e235dbe9f5af7ee331c74e739655/tumblr_nj8bb5TKYs1u2qrtko1_500.jpg16:01
odyssey4meyeah, it's the same problem we're all having - people are allocated to work and don't seem to have time to do them16:01
palendaemhayden: I'm not sure how many people who have core were aware. Maybe that's my own detachment though16:01
matttthe upside is that mhayden's changes are small16:02
matttthere's just a lot of them :P16:02
mhaydenyeah some changes are docs only16:02
bgmccollummhayden: is the best way to run this...add to role dependencies...then build a playbook to apply the roles to all hosts (and containers?) ?16:02
mhaydenshould i funnel the docs only stuff to folks like KLevenstein and Sam-I-Am that are docs wizards? :)16:02
matttpalendae: guess you didn't see this16:02
mhaydenbgmccollum: that would work find16:02
mhaydens/find/fine/16:02
matttpalendae: https://goo.gl/03qZPi16:02
mhaydeni built an AIO box, then rsynced up the role16:03
mhaydenran it against localhost16:03
mhaydeni've also run it from my laptop with a server via ssh16:03
mattti did the same16:03
palendaemattt: I did, but also not core. I didn't know that his repo got added there, though16:03
palendaeI wasn't sure if it was communicated that OSA cores are needed to help those reviews along16:03
matttpalendae: well they are in teh queue, so i'd imagine people know :P16:03
KLevensteinmhayden: there’s an rpcdocs launchpad group. we get some things where it’s not clear what docs changes need to be made, so any clarity you can provide when assigning will help a lot.16:03
palendaemattt: ¯\_(ツ)_/¯16:04
bgmccollummhayden: should the role be applied to the containers as well?16:04
mhaydenKLevenstein: sweet16:04
palendaeAssumptions )16:04
mhaydenbgmccollum: hosts only16:04
*** mgoddard has joined #openstack-ansible16:05
mhaydenanother option might be to hop on a hangout and i can take questions on the commits and/or go over each super-briefly16:05
mhaydeni'm willing to do whatever's needed on my end16:05
odyssey4memhayden you can get anyone to review them16:07
mhaydencool -- the openstack security team was eager to review some16:08
mhaydeni hopped in their mtg last week16:08
odyssey4mewith two or more +1's on it (ideally with a substantive comment), I don't give it much more than a cursory review16:08
*** javeriak has joined #openstack-ansible16:08
odyssey4methe role is not being actively used by anything yet, so there's no real impact when mistakes are made16:09
*** subscope has quit IRC16:09
*** gcivitella has quit IRC16:09
mhaydeni could mark the "docs only" reviews as such16:12
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38655: Mount w/noexec exception [docs only]  https://review.openstack.org/23314716:13
mhaydenlike that ^^ (if it helps)16:13
odyssey4memhayden the reality is that most of that stuff needs reviews by people who understand their purpose16:13
mhaydengotcha16:13
matttodyssey4me: i'll fire through some of those changes tonight to review16:13
mattts/odyssey4me/mhayden/16:13
palendaeYeah, even if I had +2 power, I'd feel reeeeeeally uncomfortable without others more knowledgeable weighing in16:13
matttpalendae: there is no one more knowledgeable16:14
matttmajor can't review his own stuff :P16:14
odyssey4meyup16:15
palendaemattt: People from openstack security maybe?16:15
odyssey4meyeah, ideally the reviewers need to come from the broader community16:15
matttyeah but they're not openstack-related stuff16:15
mattti think most sys admins can agree what is sensible and not16:15
palendaeThat's why i don't have +2 - I don't feel comfortable saying "Well, no one else can review it so I might as well"16:15
odyssey4memhayden perhaps you should frame it more generally so that people don't think it's specific to openstack-ansible16:15
odyssey4methey need to know that it's primarily the STIG documentation, and an ansible role which then deploys the recommendations16:16
mhaydenodyssey4me: not sure if i should send more mail quite yet :)16:16
mhaydenunless you mean place that information elsewhere16:16
odyssey4memhayden there was a suggestion to use the [security] tag in the ML, instead of the [openstack-ansible] tag16:17
odyssey4meas the role is generic, I would recommend that16:17
mhaydeni did that here: http://lists.openstack.org/pipermail/openstack-dev/2015-October/076929.html16:17
matttmhayden: could query the ansible community in general16:17
odyssey4meperhaps the operatory community would be keen too - so perhaps give it a bit and send one there too16:17
*** sdake_ is now known as sdake16:18
mhaydenmattt: i do owe robyn some markdown for a blog post...16:18
matttalso a great way for someone on the openstack fringes get involved w/ an openstack project16:18
mhaydenmattt: quite true16:19
matttmhayden: let it rain16:20
*** kukacz has joined #openstack-ansible16:20
*** cloudtrainme has quit IRC16:20
stevelleso much energy and words this morning16:22
*** cloudtrainme has joined #openstack-ansible16:26
stevelleThe OSAS stuff is a pretty large stack of reviews and it won't get done in a day.  I'm trying to make sure I'm putting a vote on at least a couple a day.  The MTA related ones are earmarked for today, for instance.16:27
*** cloudtra_ has joined #openstack-ansible16:29
cloudnullon an aside https://review.openstack.org/#/q/starredby:cloudnull+status:open,n,z these need to get reviewed and specifically when ready we need to think about backporting the L3HA commits16:31
*** javeriak has quit IRC16:32
*** cloudtrainme has quit IRC16:32
palendaestevelle: You and your scheduled approach to stuff16:36
*** javeriak has joined #openstack-ansible16:38
mhaydenthanks, stevelle !16:39
*** jasondotstar_ has joined #openstack-ansible16:39
*** sdake has quit IRC16:43
*** another_larsks has joined #openstack-ansible16:44
mhaydenthanks as well, palendae  ;)16:44
palendaemhayden: Welcome.16:44
openstackgerritKevin Carter proposed openstack/openstack-ansible: Implement glance venv support  https://review.openstack.org/22922116:46
cloudnullmattt:  i updated that pr if you can have a look i'd appreciate it16:46
cloudnullif good then ill apply it to all of the patches16:47
*** tlian has quit IRC16:48
*** finchd-also has joined #openstack-ansible16:49
*** sdake has joined #openstack-ansible16:49
openstackgerritMerged openstack/openstack-ansible: Update stable/liberty SHA's to Liberty RC3  https://review.openstack.org/23473016:50
*** vdo has quit IRC16:50
*** finchd has quit IRC16:50
*** jaypipes has quit IRC16:50
*** robak has quit IRC16:50
*** lkoranda has quit IRC16:50
*** larsks has quit IRC16:50
*** toddnni has quit IRC16:50
*** metral has quit IRC16:50
*** jasondotstar has quit IRC16:50
*** dstanek has quit IRC16:50
*** bapalm has quit IRC16:50
openstackgerritMerged openstack/openstack-ansible: Redirect "apt-get install -y" stdin to /dev/null  https://review.openstack.org/23333116:50
openstackgerritMerged openstack/openstack-ansible: Only wait for SSH if the container config has changed  https://review.openstack.org/23137916:50
odyssey4memattt cloudnull there was a bug in the api-paste.ini leftover from the ec2/s3 excise - it's fixed now and has passed the gate: https://review.openstack.org/22783916:53
*** another_larsks is now known as larsks16:53
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: Only wait for SSH if the container config has changed  https://review.openstack.org/23489016:53
*** shausy has quit IRC16:53
*** phschwartz is now known as phschwartz_aw16:54
*** tlian has joined #openstack-ansible16:54
tiagogomes_Hi, right now am I am setting up a flat and a vlan network like this: http://paste.openstack.org/show/476286/ . I wounder if I really need eth11 and eth12, isn't one interface enough? They are both connected to the same bridge16:56
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: Remove oslo.versionedobjects 0.11.0 block  https://review.openstack.org/23473316:57
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: Remove WebOb 1.5.0 cap  https://review.openstack.org/23474216:58
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: Update rabbitmq-server to v3.5.6-1  https://review.openstack.org/23370016:59
*** Bjoern_ has joined #openstack-ansible16:59
*** metral has joined #openstack-ansible16:59
*** bapalm has joined #openstack-ansible16:59
*** metral has quit IRC17:07
*** bapalm has quit IRC17:07
*** robak has joined #openstack-ansible17:07
*** jaypipes has joined #openstack-ansible17:07
*** toddnni has joined #openstack-ansible17:07
*** lkoranda has joined #openstack-ansible17:08
*** vdo has joined #openstack-ansible17:08
*** metral has joined #openstack-ansible17:10
*** bapalm has joined #openstack-ansible17:10
*** manas has joined #openstack-ansible17:13
openstackgerritMerged openstack/openstack-ansible: Archive Keystone to Keystone Federation rst content  https://review.openstack.org/21174717:17
openstackgerritBjoern Teipel proposed openstack/openstack-ansible: Adding missing vfat packages for the nova config_drive  https://review.openstack.org/23380917:20
*** javeriak has quit IRC17:21
*** javeriak has joined #openstack-ansible17:22
*** dstanek_ has joined #openstack-ansible17:22
*** phschwartz_aw is now known as phschwartz17:23
*** dstanek_ has quit IRC17:23
*** dstanek has joined #openstack-ansible17:24
openstackgerritMerged openstack/openstack-ansible-security: V-38671: Remove sendmail  https://review.openstack.org/23324217:24
*** Bjoern_ is now known as BjoernT17:27
*** javeriak has quit IRC17:31
*** javeriak_ has joined #openstack-ansible17:31
bgmccollumcloudnull: running new upgrade out of kilo branch...nova install failes...no space-html5 in repo...seeing the following -- http://paste.openstack.org/show/476293/17:38
bgmccollum*spice-html517:38
odyssey4mebgmccollum you want this: https://review.openstack.org/23469817:39
*** jasondotstar_ is now known as jasondotstar17:39
bgmccollumodyssey4me: thx...17:39
*** sdake has quit IRC17:39
odyssey4mebgmccollum that was reported earlier today by tiagogomes_17:40
bgmccollumnod17:40
*** javeriak_ has quit IRC17:40
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: Archive Keystone to Keystone Federation rst content  https://review.openstack.org/23490817:41
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-386**: Disabling various unneeded services  https://review.openstack.org/23319817:43
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-3867{4,6}: X windows  https://review.openstack.org/23325917:44
*** phalmos has joined #openstack-ansible17:47
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: Remove /openstackgit from repo_mirror_excludes  https://review.openstack.org/23469817:52
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-38622: Restricted mail relaying  https://review.openstack.org/23420417:54
*** javeriak has joined #openstack-ansible17:55
mhaydenstevelle: just added docs and made that one configurable ^^17:55
stevellelooking again.  Not sure that you can readily assert that mynetworks is reasonably restrictive which is the hard part of this one.17:56
*** javeriak_ has joined #openstack-ansible18:36
*** sdake has joined #openstack-ansible18:38
*** sdake has joined #openstack-ansible18:39
mhaydenstevelle: right, but if inet_interfaces = localhost, mynetworks isn't so important18:40
mhaydensince postfix will be listening for mail only on lo18:40
*** javeriak has quit IRC18:40
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: Update Neutron Configuration for Liberty  https://review.openstack.org/23492618:40
*** sdake_ has joined #openstack-ansible18:43
*** sdake has quit IRC18:43
*** jwagner_away is now known as jwagner18:46
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: Update Neutron Configuration for Liberty  https://review.openstack.org/23492618:46
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: Update Neutron Configuration for Liberty  https://review.openstack.org/23492618:49
stevellemhayden: I understand that, and inet_interfaces should present a lower surface area than mynetworks, just wanted to ensure the play didn't prevent someone from intended behavior.18:50
stevelleyour fix is better than meddling with mynetworks18:50
mhaydeni see what you're saying18:50
*** sdake_ has quit IRC18:51
*** sdake has joined #openstack-ansible18:51
*** javeriak_ has quit IRC18:52
openstackgerritKevin Carter proposed openstack/openstack-ansible: Implement keystone venv support  https://review.openstack.org/22951318:59
cloudnulld34dh0r53 odyssey4me mattt ^ that was updated to ensure the keystone-install tag was there and that the venv ownership was root instead of the keystone user.19:01
*** KLevenstein_ has joined #openstack-ansible19:01
d34dh0r53ahh, cool19:01
d34dh0r53cloudnull: are you going to update the others?19:01
*** KLevenstein has quit IRC19:01
*** KLevenstein_ is now known as KLevenstein19:01
cloudnullyes19:01
cloudnullim making the same change to the others too19:01
cloudnullthat was based on feedback on the glance venv pr19:01
*** KLevenstein has quit IRC19:02
cloudnullhowever i wont do it for the horizon venv because horizon needs to own most of the files .19:02
d34dh0r53ok, in the process of testing them so I'll hold off till you're done19:03
cloudnullat this point glance keystone and horizon are good to go19:03
lbragstadcloudnull bug report - http://openstack-weekly-reports.lbragstad.com/weekly-bug-reports/openstack-ansible-weekly-bug-report.html19:05
d34dh0r53cloudnull: cool, thanks19:05
openstackgerritKevin Carter proposed openstack/openstack-ansible: Implement neutron venv support  https://review.openstack.org/23072619:05
cloudnulld34dh0r53: neutron is good19:05
cloudnull:)19:05
cloudnulllbragstad:  thats awesome19:05
cloudnull-cc openstackgerrit19:05
cloudnullbah...19:05
cloudnull-cc odyssey4me19:05
lbragstadcloudnull it scrubs LP every 15 minutes for new bugs19:07
lbragstadcloudnull if you'd like it to be more often, let me know19:07
cloudnullthats probably good :)19:07
openstackgerritKevin Carter proposed openstack/openstack-ansible: Implement swift venv support  https://review.openstack.org/23073319:08
openstackgerritKevin Carter proposed openstack/openstack-ansible: Implement ceilometer venv support  https://review.openstack.org/22921219:09
openstackgerritKevin Carter proposed openstack/openstack-ansible: Implement heat venv support  https://review.openstack.org/22922519:10
openstackgerritKevin Carter proposed openstack/openstack-ansible: Implement cinder venv support  https://review.openstack.org/22546319:11
*** cloudtra_ has quit IRC19:12
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-3867{4,6}: X windows  https://review.openstack.org/23325919:13
mhaydenstevelle / odyssey4me: flipped this to use fail module -> https://review.openstack.org/#/c/233259/19:14
openstackgerritKevin Carter proposed openstack/openstack-ansible: Implement aodh venv support  https://review.openstack.org/23340119:14
openstackgerritKevin Carter proposed openstack/openstack-ansible: Implement nova venv support  https://review.openstack.org/23072719:16
cloudnulld34dh0r53 mattt odyssey4me all updated19:17
d34dh0r53bon19:17
cloudnullty sir19:19
*** scarlisle has quit IRC19:21
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: V-386{67,70,95,96,98}, V-38700: Run AIDE via cron  https://review.openstack.org/23323119:23
openstackgerritMajor Hayden proposed openstack/openstack-ansible-security: Replace debug with fail  https://review.openstack.org/23494219:29
*** manas has quit IRC19:30
odyssey4melbragstad that bug report is quite useful19:35
*** KLevenstein has joined #openstack-ansible19:35
odyssey4meare they updated regularly?19:35
*** sdake has quit IRC19:35
openstackgerritKevin Carter proposed openstack/openstack-ansible: Seperated out Telemetry Alarming (Aodh)  https://review.openstack.org/23222419:35
*** sdake has joined #openstack-ansible19:36
lbragstadodyssey4me the bug reports are rebuilt every 15 minutes, for each project.19:38
openstackgerritKevin Carter proposed openstack/openstack-ansible: Implement aodh venv support  https://review.openstack.org/23340119:38
lbragstadodyssey4me they only every publish bugs that are in "workable" status... so things that aren't "fix committed", "fix released", "invalid", etc...19:42
odyssey4melbragstad cool - I'd like a lot more than that, but this is a start.19:42
odyssey4mesigmavirus24 weren't you also working on some data extraction stuff?19:42
sigmavirus24hm?19:43
sigmavirus24for GitHub a bit yeah19:43
sigmavirus24not quite like that19:43
odyssey4melbragstad ideally I'd like to have a way of catching orphaned bugs - either by not being allocated, or by being old19:43
lbragstadodyssey4me this is the code - https://github.com/lbragstad/openstack-infra-scripts/blob/master/recent_bugs.py19:44
lbragstadodyssey4me i stole it from jogo a long time ago...19:44
odyssey4mehah, awesome :)19:45
*** KLevenstein has quit IRC20:01
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: Update Heat Configuration for Liberty  https://review.openstack.org/23495920:05
odyssey4mestevelle sigmavirus24 d34dh0r53 would you mind briefly reviewing this one - https://review.openstack.org/23474220:10
d34dh0r53looks good to me20:10
odyssey4methanks d34dh0r53 & sigmavirus2420:11
*** KLevenstein has joined #openstack-ansible20:12
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: Allow configuration of config_drive_format inside nova.conf  https://review.openstack.org/23380620:12
odyssey4med34dh0r53 sigmavirus24  would you mind voting this backport through the door too - it's only docs: https://review.openstack.org/23490820:14
openstackgerritMerged openstack/openstack-ansible: Remove oslo.versionedobjects 0.11.0 block  https://review.openstack.org/23473320:27
*** cloudtrainme has joined #openstack-ansible20:51
*** spotz is now known as spotz_zzz20:51
*** sdake_ has joined #openstack-ansible20:57
*** sdake has quit IRC20:59
*** ggillies has joined #openstack-ansible21:01
*** sdake_ has quit IRC21:02
openstackgerritJesse Pretorius proposed openstack/openstack-ansible-specs: Add Liberty Release spec  https://review.openstack.org/22118921:03
d34dh0r53cloudnull: no aodh in the repo server21:06
odyssey4med34dh0r53 what do you mean?21:08
d34dh0r53testing the venv patches and I'm thinking that I'm missing a patch for aodh21:08
odyssey4med34dh0r53 you may be missing this pre-requisite: https://review.openstack.org/23222421:08
*** kukacz has quit IRC21:09
odyssey4memhayden so let me explain how the current role tests for openstack-ansible-security work for background21:09
mhaydenodyssey4me: ducking out for a bit, will be back on later -- sorry!21:10
odyssey4memhayden ah ok, tomorrow then21:10
*** woodard has quit IRC21:12
*** ggillies has quit IRC21:14
*** spotz_zzz is now known as spotz21:16
*** k_stev has quit IRC21:23
*** thingee has joined #openstack-ansible21:34
thingeeodyssey4me: ping21:34
*** KLevenstein has quit IRC21:34
*** spotz is now known as spotz_zzz21:38
openstackgerritMerged openstack/openstack-ansible-security: V-38622: Restricted mail relaying  https://review.openstack.org/23420421:40
*** phalmos has quit IRC21:43
*** k_stev has joined #openstack-ansible21:47
openstackgerritMerged openstack/openstack-ansible: Remove /openstackgit from repo_mirror_excludes  https://review.openstack.org/23469821:58
openstackgerritMerged openstack/openstack-ansible-security: V-38496: Lock system accounts other than root  https://review.openstack.org/23201221:58
openstackgerritMerged openstack/openstack-ansible-security: V-3851{4,5,6,7}: Disabling certain network protocols  https://review.openstack.org/23212921:58
*** sigmavirus24 is now known as sigmavirus24_awa22:02
*** cloudtrainme has quit IRC22:05
openstackgerritBjoern Teipel proposed openstack/openstack-ansible: Allow configration of config_drive_format inside nova.conf  https://review.openstack.org/23380622:07
*** k_stev has quit IRC22:07
openstackgerritMerged openstack/openstack-ansible: Implement glance venv support  https://review.openstack.org/22922122:09
openstackgerritMerged openstack/openstack-ansible: Adding missing vfat packages for the nova config_drive  https://review.openstack.org/23380922:09
openstackgerritMerged openstack/openstack-ansible: Remove WebOb 1.5.0 cap  https://review.openstack.org/23474222:09
openstackgerritMerged openstack/openstack-ansible: Archive Keystone to Keystone Federation rst content  https://review.openstack.org/23490822:09
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: Implement nova venv support  https://review.openstack.org/23072722:10
openstackgerritJesse Pretorius proposed openstack/openstack-ansible: Update rabbitmq-server to v3.5.6-1  https://review.openstack.org/23370022:11
*** k_stev has joined #openstack-ansible22:30
openstackgerritMerged openstack/openstack-ansible: Implement keystone venv support  https://review.openstack.org/22951322:36
*** markvoelker has quit IRC22:43
*** ggillies has joined #openstack-ansible22:45
*** openstackgerrit has quit IRC22:46
*** openstackgerrit has joined #openstack-ansible22:46
openstackgerritBjoern Teipel proposed openstack/openstack-ansible: Correct OS_IDENTITY_API_VERSION as introduced with #1495685  https://review.openstack.org/23500822:50
openstackgerritBjoern Teipel proposed openstack/openstack-ansible: Correct OS_IDENTITY_API_VERSION   https://review.openstack.org/23500822:52
*** markvoelker has joined #openstack-ansible22:53
openstackgerritMerged openstack/openstack-ansible: Implement cinder venv support  https://review.openstack.org/22546322:54
*** jhesketh has quit IRC23:00
*** jhesketh has joined #openstack-ansible23:01
*** k_stev has quit IRC23:12
thingeeodyssey4me: ping23:13
*** cloudtrainme has joined #openstack-ansible23:35
*** markvoelker has quit IRC23:38
*** jwagner is now known as jwagner_away23:38
*** elo has quit IRC23:42
*** elo has joined #openstack-ansible23:44
*** agireud has quit IRC23:51
*** agireud has joined #openstack-ansible23:57
*** mgoddard_ has joined #openstack-ansible23:57
*** mgoddard has quit IRC23:57
*** alop has quit IRC23:59

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!