*** karimb has quit IRC | 00:05 | |
*** jayc_ has quit IRC | 00:06 | |
*** pjm6 has quit IRC | 00:09 | |
*** BjoernT has quit IRC | 00:09 | |
*** busterswt has joined #openstack-ansible | 00:12 | |
openstackgerrit | Merged openstack/openstack-ansible-os_aodh: Clarify role documentation and remove duplication https://review.openstack.org/307315 | 00:21 |
---|---|---|
*** KiranV has joined #openstack-ansible | 00:41 | |
*** busterswt has quit IRC | 00:47 | |
*** busterswt has joined #openstack-ansible | 00:49 | |
*** ssl_ has joined #openstack-ansible | 01:01 | |
ssl_ | i'm trying to install osa, i'm getting the following error: - [ XEN Server Information ] ----------------------------------------- ---------------------------------------------------------------------- No xenstore Information +++ info_block 'Error Info - 262' 0 +++ echo ---------------------------------------------------------------------- ---------------------------------------------------------------------- +++ print_in | 01:01 |
cloudnull | ssl_: is that an all in one ? | 01:06 |
cloudnull | that is the diagnostic print out when the run has an error | 01:07 |
cloudnull | it looks to see if the node is running on XEN hypervisors | 01:07 |
cloudnull | your actual error is well above all that | 01:07 |
*** ssl__ has joined #openstack-ansible | 01:09 | |
*** fishcried has joined #openstack-ansible | 01:09 | |
ssl__ | yes.. it is on allinone, however, the installation failed after that? | 01:09 |
*** ssl_ has quit IRC | 01:10 | |
*** iceyao has joined #openstack-ansible | 01:11 | |
cloudnull | its using a bash trap to generate that data. | 01:14 |
cloudnull | the real error should be above | 01:14 |
*** fishcried has quit IRC | 01:18 | |
*** weezS has joined #openstack-ansible | 01:20 | |
*** alejandrito has joined #openstack-ansible | 01:26 | |
*** KiranV has quit IRC | 01:44 | |
*** busterswt has quit IRC | 01:45 | |
*** asettle has quit IRC | 01:52 | |
openstackgerrit | Merged openstack/openstack-ansible-galera_server: Decrease MariaDB wait timeout https://review.openstack.org/307231 | 01:57 |
*** keedya has quit IRC | 02:10 | |
*** phalmos has joined #openstack-ansible | 02:20 | |
*** iceyao has quit IRC | 02:24 | |
*** iceyao has joined #openstack-ansible | 02:24 | |
*** phalmos has quit IRC | 02:30 | |
*** phalmos has joined #openstack-ansible | 02:40 | |
*** alejandrito has quit IRC | 02:41 | |
*** thorst_ has quit IRC | 02:52 | |
*** thorst_ has joined #openstack-ansible | 02:53 | |
*** thorst_ has quit IRC | 03:01 | |
*** phalmos has quit IRC | 03:18 | |
*** iceyao_ has joined #openstack-ansible | 03:36 | |
*** iceyao has quit IRC | 03:36 | |
*** iceyao has joined #openstack-ansible | 03:39 | |
*** charz_ has quit IRC | 03:39 | |
*** persia has quit IRC | 03:40 | |
*** intr1nsic has quit IRC | 03:41 | |
*** iceyao_ has quit IRC | 03:42 | |
*** charz has joined #openstack-ansible | 03:42 | |
*** iceyao has quit IRC | 03:44 | |
*** persia has joined #openstack-ansible | 03:50 | |
*** thorst_ has joined #openstack-ansible | 03:59 | |
openstackgerrit | Merged openstack/openstack-ansible: Docs: Change invalid reference to FWaaS in VPNaaS documentation https://review.openstack.org/307322 | 04:00 |
*** thorst_ has quit IRC | 04:06 | |
*** intr1nsic has joined #openstack-ansible | 04:07 | |
*** saneax is now known as saneax_AFK | 04:12 | |
*** ssl__ has quit IRC | 04:13 | |
*** intr1nsic has quit IRC | 04:27 | |
*** mkrish004c has joined #openstack-ansible | 04:32 | |
*** intr1nsic has joined #openstack-ansible | 04:33 | |
*** asettle has joined #openstack-ansible | 04:38 | |
mkrish004c | hi all, i am trying out local repo set up for the OSA installation, facing lot of dependency conflicts on pip installation. | 04:40 |
mkrish004c | why the OSA is using pip installation for most of the package rather than apt-get installation ? | 04:41 |
mkrish004c | if i change all pip to apt get, would that affect my set up by any way ? | 04:41 |
prometheanfire | odyssey4me: if you are curious on the work being done for upstream image work... https://review.openstack.org/307553 and https://review.openstack.org/#/c/307493 | 04:42 |
mkrish004c | in openstack installation guide all the packages have been installed via apt-get, why not the same in OSA | 04:42 |
*** asettle has quit IRC | 04:54 | |
*** asettle has joined #openstack-ansible | 04:55 | |
*** czunker has joined #openstack-ansible | 04:55 | |
*** thorst_ has joined #openstack-ansible | 05:04 | |
*** ssl_ has joined #openstack-ansible | 05:12 | |
*** thorst_ has quit IRC | 05:12 | |
*** eric_lopez has joined #openstack-ansible | 05:12 | |
*** elo has quit IRC | 05:13 | |
*** asettle has quit IRC | 05:13 | |
*** asettle has joined #openstack-ansible | 05:13 | |
*** mkrish004c has quit IRC | 05:17 | |
ssl_ | how can i update the AIO to include Neutron LBaaS | 05:18 |
prometheanfire | checkout master> | 05:18 |
prometheanfire | ? | 05:18 |
*** saneax_AFK is now known as saneax | 05:23 | |
*** shausy has joined #openstack-ansible | 05:30 | |
*** asettle has quit IRC | 05:37 | |
*** asettle has joined #openstack-ansible | 05:38 | |
*** weezS has quit IRC | 05:40 | |
*** Mudpuppy has quit IRC | 05:43 | |
*** shausy has quit IRC | 05:44 | |
*** ssl_ has quit IRC | 05:44 | |
*** asettle has quit IRC | 05:51 | |
*** asettle has joined #openstack-ansible | 05:53 | |
*** thorst_ has joined #openstack-ansible | 06:09 | |
*** asettle has quit IRC | 06:15 | |
*** asettle has joined #openstack-ansible | 06:15 | |
*** thorst_ has quit IRC | 06:17 | |
*** jiteka has joined #openstack-ansible | 06:25 | |
*** jiteka has quit IRC | 06:26 | |
*** javeriak has joined #openstack-ansible | 06:37 | |
*** dmellado_ is now known as dmellado | 06:44 | |
joker_ | hi odyssey4me : I got this error https://gist.github.com/celikmustafa89/4c6600682d5c7f72898f5229409c72f9 | 06:44 |
joker_ | and I have solved this problem by downgrading pip version to 7.1.2. | 06:44 |
joker_ | what causes such a problem? thanx | 06:44 |
*** kiranv has joined #openstack-ansible | 06:48 | |
*** fawadkhaliq has joined #openstack-ansible | 06:49 | |
kiranv | Hi, I've been trying to setup an AIO node with OpenStack-Ansible since 3 days. When I bring up the node for the first time, everything boots up fine.. But when I try to change some config and re run run-playbooks.sh, I see a few failures and my horizon or keystone service is not accessible.. can anyone help me with this? | 06:52 |
mcarden | kiranv: I may not be able to help, but I think anyone who can would need more information. Is the AIO in a VM or on a 'bare metal' host? How much CPU/RAM/DISK? | 06:55 |
kiranv | It is on bare metal, with ubuntu 14.04 server | 06:55 |
kiranv | memory 32G and HDD 1TB | 06:56 |
mcarden | OK - that looks good. | 06:56 |
kiranv | I am trying to build AIO from liberty branch | 06:56 |
*** chhavi has joined #openstack-ansible | 06:56 | |
mcarden | So do you check out liberty as soon as you clone the openstack-ansible project? | 06:57 |
kiranv | yes.. while cloning, -b liberty | 06:57 |
mcarden | OK - I suspect you have already done anything that I might advise you of. You may need to wait for others to wake up and chime in with more experience. | 06:58 |
*** dalees` has quit IRC | 06:58 | |
*** bbmbx has quit IRC | 06:59 | |
*** dalees` has joined #openstack-ansible | 06:59 | |
mcarden | I've blogged what works for me (on a cloud VM) at http://www.michaelcarden.net but I think I have no clues that will point you in the right direction. | 06:59 |
kiranv | sure! I also noticed a few more issue.. 1. OSA takes entire control of the sshd_config file and modifies it.. blocking the root login #Ansible managed: /etc/ansible/roles/sshd/templates/sshd_config.j2 modified on "xyz" | 07:01 |
mcarden | Yep, you need to set up an ssh key login for root on your host before you start. | 07:02 |
kiranv | 2. if the machine is rebooted, after waiting for all the containers to come up, horizon isn't accessible and even if I re run run-playbooks.sh, it results in errors | 07:02 |
kiranv | point noted. Will do that from now on :) and I'll check out your blog. Thanks :) | 07:03 |
*** fishcried has joined #openstack-ansible | 07:06 | |
*** fawadkhaliq has quit IRC | 07:12 | |
*** fishcried has quit IRC | 07:12 | |
*** thorst_ has joined #openstack-ansible | 07:15 | |
*** pcaruana has joined #openstack-ansible | 07:16 | |
*** kiranv has quit IRC | 07:16 | |
*** thorst_ has quit IRC | 07:22 | |
*** pcaruana has quit IRC | 07:23 | |
*** Mudpuppy has joined #openstack-ansible | 07:28 | |
*** Mudpuppy has quit IRC | 07:33 | |
*** mikelk has joined #openstack-ansible | 07:37 | |
*** admin0 has joined #openstack-ansible | 07:41 | |
*** mariusv has quit IRC | 07:48 | |
openstackgerrit | Matt Thompson proposed openstack/openstack-ansible-os_designate: [WIP] Designate functional tests https://review.openstack.org/307189 | 07:50 |
*** Oku_OS-away is now known as Oku_OS | 07:53 | |
*** fishcried has joined #openstack-ansible | 07:54 | |
*** fishcried has quit IRC | 07:55 | |
*** javeriak has quit IRC | 07:59 | |
*** coolj has quit IRC | 08:01 | |
*** coolj has joined #openstack-ansible | 08:01 | |
*** javeriak has joined #openstack-ansible | 08:03 | |
*** javeriak has quit IRC | 08:19 | |
*** thorst_ has joined #openstack-ansible | 08:20 | |
*** javeriak has joined #openstack-ansible | 08:26 | |
*** gparaskevas has joined #openstack-ansible | 08:27 | |
*** thorst_ has quit IRC | 08:27 | |
*** pjm6 has joined #openstack-ansible | 08:28 | |
pjm6 | good morning :D | 08:28 |
admin0 | \o | 08:29 |
pjm6 | admin0: o/ | 08:29 |
admin0 | brb :D | 08:30 |
openstackgerrit | Pedro Magalhães (pjm) proposed openstack/openstack-ansible: Docs: Adding toctree to Configuring the Network Services (Optional) https://review.openstack.org/307640 | 08:38 |
*** javeriak has quit IRC | 08:39 | |
*** asettle has quit IRC | 08:41 | |
*** asettle has joined #openstack-ansible | 08:41 | |
*** tiagogomes has joined #openstack-ansible | 08:48 | |
*** asettle has quit IRC | 08:51 | |
*** asettle has joined #openstack-ansible | 08:52 | |
*** electrofelix has joined #openstack-ansible | 08:56 | |
odyssey4me | mcarden point to note - run-playbooks should only be run once... from then on the playbooks should be run using openstack-ansible <playbook name>, also the AIO docs cover what to do after a reboot - please point people at the AIO docs | 08:57 |
odyssey4me | pjm6 can you cherry-pick https://review.openstack.org/307322 to stable/mitaka please? you can do it through gerrit via a button | 08:58 |
odyssey4me | evrardjp can you backport https://review.openstack.org/305971 to stable/mitaka | 08:59 |
odyssey4me | evrardjp also https://review.openstack.org/306436 and https://review.openstack.org/306482 | 09:00 |
*** pjm6 has quit IRC | 09:01 | |
*** pjm6 has joined #openstack-ansible | 09:01 | |
pjm6 | odyssey4me: sure | 09:04 |
pjm6 | do you want that i git clone stable/mitaka | 09:04 |
pjm6 | do git cherry-pick | 09:04 |
pjm6 | and then git-review ? | 09:04 |
pjm6 | odyssey4me: its this https://review.openstack.org/#/c/307659/ ? | 09:11 |
*** karimb has joined #openstack-ansible | 09:11 | |
*** jiteka has joined #openstack-ansible | 09:17 | |
*** thorst_ has joined #openstack-ansible | 09:25 | |
*** lkoranda has joined #openstack-ansible | 09:26 | |
*** Oku_OS is now known as Oku_OS-away | 09:29 | |
*** thorst_ has quit IRC | 09:31 | |
*** johnmilton has joined #openstack-ansible | 09:47 | |
*** johnmilton has quit IRC | 09:51 | |
*** asettle has quit IRC | 09:56 | |
*** asettle has joined #openstack-ansible | 09:57 | |
odyssey4me | pjm6 it should have been cherry-pick -x but anyway - I'll fix up the commit msg | 09:57 |
openstackgerrit | Alexandra Settle proposed openstack/openstack-ansible: DOCS WIP: Adding Ironic configuration docs to Ansible install guide https://review.openstack.org/305586 | 10:00 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible: Add option to auto enable from VPNaaS in Horizon https://review.openstack.org/305433 | 10:00 |
odyssey4me | asettle lives? | 10:00 |
asettle | odyssey4me: yeah bro. Get reviewing. There's questions from back on patch set 1/2. | 10:00 |
asettle | :) | 10:00 |
asettle | HAPPY TUESDAY | 10:00 |
asettle | \o/ | 10:01 |
*** pjm6 has quit IRC | 10:01 | |
mattt | asettle: woohoo! | 10:04 |
*** pjm6 has joined #openstack-ansible | 10:05 | |
*** Oku_OS-away is now known as Oku_OS | 10:05 | |
asettle | Well hey mattt :) | 10:05 |
*** jiteka1 has joined #openstack-ansible | 10:05 | |
asettle | mattt - I believe you have andymccr back safe and sound | 10:05 |
*** jiteka has quit IRC | 10:07 | |
*** pjm6 has quit IRC | 10:09 | |
odyssey4me | asettle he's safe, not so sure about sound | 10:13 |
asettle | odyssey4me: I do that to people ;) | 10:13 |
odyssey4me | mattt would you mind reviewing this small backport? https://review.openstack.org/307240 | 10:15 |
mattt | odyssey4me: sure | 10:16 |
odyssey4me | mattt and this one https://review.openstack.org/307684 | 10:16 |
mattt | k | 10:17 |
*** electrofelix has quit IRC | 10:24 | |
mattt | odyssey4me: i don't know why but that first review just feels odd to me | 10:25 |
*** pjm6 has joined #openstack-ansible | 10:29 | |
*** thorst_ has joined #openstack-ansible | 10:29 | |
pjm6 | odyssey4me: -x ? What I did was executing the cherry pick command that were in the openstack | 10:30 |
odyssey4me | mattt it does pretty much nothing for any standard deploy - it'll make a lot more sense once we have OVS mixed in | 10:30 |
odyssey4me | pjm6 -x adds the 'cherry picked from commit xxxx' bit into the commit message, so we know where it came from | 10:31 |
pjm6 | ohh right, thanks :D | 10:31 |
pjm6 | didn't knew | 10:31 |
pjm6 | next time I will try not to forget | 10:31 |
pjm6 | btw: https://review.openstack.org/#/c/307640/ in this way is better? | 10:31 |
odyssey4me | pjm6 if you use the 'cherry pick' button in gerrit then it does that automatically once the master patch has merged | 10:32 |
pjm6 | That's the second change that i was doing | 10:32 |
pjm6 | odyssey4me: I copy pasted the 'cherry pick' command from the gerrit | 10:32 |
pjm6 | maybe did something wrong | 10:32 |
*** electrofelix has joined #openstack-ansible | 10:34 | |
odyssey4me | pjm6 next to 'rebase' do you see the 'cherry pick' button | 10:34 |
odyssey4me | I think you used the 'download' button instead | 10:35 |
pjm6 | ohhh forget it | 10:35 |
odyssey4me | 'cherry pick' is under the 'owner' 'project' 'branch' etc | 10:35 |
pjm6 | yes I did that | 10:35 |
pjm6 | Cherry Pick button | 10:35 |
pjm6 | left side of "Revert" | 10:35 |
pjm6 | ? | 10:35 |
odyssey4me | yeah, so the download links are for testing | 10:35 |
odyssey4me | yes, that button | 10:35 |
pjm6 | sorry my bad | 10:35 |
openstackgerrit | Merged openstack/openstack-ansible-os_aodh: Fail fast when required secrets are not present https://review.openstack.org/307426 | 10:36 |
pjm6 | I used from the download links yeah | 10:36 |
odyssey4me | next time use that to cherry pick - it'll do the right thing if it can do it cleanly | 10:36 |
pjm6 | Nice :D and more easy to | 10:36 |
pjm6 | *too | 10:36 |
*** thorst_ has quit IRC | 10:37 | |
*** markvoelker has joined #openstack-ansible | 10:37 | |
joker_ | odyssey4me : could you help me with this error https://gist.github.com/celikmustafa89/7326f9cf08364201cb1aa40ed4565e7d | 10:38 |
*** markvoelker has quit IRC | 10:42 | |
odyssey4me | joker_ don't use --limit or --retry, and clear your fact cache, then try and run the play again | 10:49 |
odyssey4me | joker_ hang, on do your hosts have /root/.ssh/id_rsa.pub keys which match your deployment host? | 10:51 |
*** johnmilton has joined #openstack-ansible | 10:59 | |
joker_ | odyssey4me : all hosts have " ~/.ssh/id_rsa.pub key of deployment host" in their ~/.ssh/authorized_keys file. Also containers has that public key too. Is this concept is correct? | 11:06 |
joker_ | odyssey4me: or should my repo container which, is "infra01_repo_container-d24349b7" , has infra01 hosts publickey under its authorized_keys file, too??? | 11:08 |
*** zhangjn has joined #openstack-ansible | 11:12 | |
*** admin0 has quit IRC | 11:13 | |
joker_ | odyssey4me: I have another question about pip version. while ansible is installing wheel, virtualenv, virtualenv-tools with pip_8.1.1 it throws this error https://gist.github.com/celikmustafa89/c91d85d1d76708803f89ccefb9332a55 . Do you know something about this error? thanx | 11:14 |
openstackgerrit | Merged openstack/openstack-ansible-os_keystone: Fail fast when required secrets are not present https://review.openstack.org/307477 | 11:18 |
odyssey4me | joker_ the containers will inherit that file if it was there when they were created - if they weren't then destroy the containers and rebuild them | 11:19 |
*** javeriak has joined #openstack-ansible | 11:20 | |
odyssey4me | joker_ as I've asked several time before, please post the complete play for that issue | 11:20 |
odyssey4me | the results of the complete play | 11:20 |
joker_ | odyssey4me : sorry, what you mean by complete play? | 11:21 |
odyssey4me | joker_ which play are you running? | 11:26 |
joker_ | setup-infrastructure.yml | 11:27 |
*** weshay has quit IRC | 11:28 | |
*** Mudpuppy has joined #openstack-ansible | 11:28 | |
*** Mudpuppy has quit IRC | 11:29 | |
joker_ | odyssey4me : setup-infrastructure.yml | 11:31 |
*** thorst_ has joined #openstack-ansible | 11:37 | |
*** markvoelker has joined #openstack-ansible | 11:38 | |
*** admin0 has joined #openstack-ansible | 11:41 | |
*** markvoelker has quit IRC | 11:42 | |
*** saneax is now known as saneax_AFK | 11:45 | |
*** karimb has quit IRC | 11:49 | |
*** karimb has joined #openstack-ansible | 11:49 | |
*** Oku_OS is now known as Oku_OS-away | 11:52 | |
*** karimb_ has joined #openstack-ansible | 11:52 | |
*** javeriak has quit IRC | 11:54 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-lxc_hosts: Ensure that role execution stops if there is no ssh public key configured https://review.openstack.org/307732 | 11:54 |
*** karimb has quit IRC | 11:54 | |
*** karimb_ has quit IRC | 11:54 | |
odyssey4me | joker_ ok, so can you share the output of the whole playbook execution from start to finish, preferably with the '-vv' CLI parameter added for verbose output | 11:55 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-lxc_hosts: Ensure that tasks fail early if there is no ssh public key configured https://review.openstack.org/307732 | 11:57 |
*** javeriak has joined #openstack-ansible | 11:59 | |
*** weshay has joined #openstack-ansible | 12:03 | |
*** pjm6 has quit IRC | 12:12 | |
*** schwicht has joined #openstack-ansible | 12:12 | |
*** iceyao has joined #openstack-ansible | 12:15 | |
*** chhavi has quit IRC | 12:16 | |
*** markvoelker has joined #openstack-ansible | 12:19 | |
openstackgerrit | Matt Thompson proposed openstack/openstack-ansible-memcached_server: Updated role using the Multi-Distro framework https://review.openstack.org/279608 | 12:19 |
*** Oku_OS-away is now known as Oku_OS | 12:19 | |
*** gparaskevas has quit IRC | 12:19 | |
*** rohanp has quit IRC | 12:19 | |
*** flaviosr has quit IRC | 12:19 | |
*** woodard has joined #openstack-ansible | 12:20 | |
*** chhavi has joined #openstack-ansible | 12:29 | |
*** javeriak has quit IRC | 12:35 | |
*** javeriak has joined #openstack-ansible | 12:36 | |
mhayden | buenos dias | 12:40 |
*** winggundamth has quit IRC | 12:48 | |
asettle | odyssey4me: is there a problem with the ansible gates? | 13:00 |
openstackgerrit | Andy McCrae proposed openstack/openstack-ansible: Add group_vars for swift_remote_all hosts https://review.openstack.org/307802 | 13:01 |
*** schwicht has quit IRC | 13:01 | |
odyssey4me | asettle the gate queues are very long there are issues in OpenStack-CI and have been for two days | 13:01 |
asettle | Oh gotcha, cheers odyssey4me | 13:01 |
odyssey4me | there are currentlyover 700 jobs in the queue | 13:02 |
odyssey4me | http://status.openstack.org/zuul/ | 13:02 |
asettle | Lucky zuul! | 13:02 |
asettle | I'll leave that to itself then :) | 13:02 |
cloudnull | morning | 13:02 |
mattt | morning2u cloudnull | 13:03 |
cloudnull | ohai mattt | 13:03 |
cloudnull | how are things ? | 13:03 |
odyssey4me | cloudnull automagically mattt I think that considering the number of failures we're getting queries that relate to this, perhaps https://review.openstack.org/307732 is a good course of action | 13:03 |
*** retreved has joined #openstack-ansible | 13:04 | |
*** klamath has joined #openstack-ansible | 13:04 | |
*** klamath has quit IRC | 13:04 | |
cloudnull | that seems like a good course of action | 13:04 |
*** klamath has joined #openstack-ansible | 13:05 | |
cloudnull | and matches some of the other preflight check things automagically has been working on | 13:05 |
*** keedya has joined #openstack-ansible | 13:05 | |
odyssey4me | yeah, we should do more of it | 13:06 |
*** b3rnard0_away is now known as b3rnard0\ | 13:08 | |
*** b3rnard0\ is now known as b3rnard0 | 13:09 | |
*** pjm6 has joined #openstack-ansible | 13:12 | |
evrardjp | good morning cloudnull | 13:14 |
evrardjp | testing your commit | 13:15 |
evrardjp | about ssl termination | 13:15 |
*** pjm6_ has joined #openstack-ansible | 13:16 | |
*** schwicht has joined #openstack-ansible | 13:17 | |
evrardjp | I think horizon and keystone should have an SSL passthrough but that's another topic. Having everything SSL without difficult wiring/configuration is a good thing | 13:17 |
*** pjm6 has quit IRC | 13:17 | |
* admin0 is waiting to pounce on cloudnull as well and hammer him with ssl certs :D | 13:17 | |
*** pjm6 has joined #openstack-ansible | 13:21 | |
cloudnull | hows it evrardjp | 13:21 |
*** pjm6_ has quit IRC | 13:21 | |
* cloudnull is ready | 13:22 | |
automagically | morning all | 13:22 |
evrardjp | morning automagically | 13:22 |
evrardjp | cloudnull I will give you feedback in around 10 minutes | 13:23 |
cloudnull | idk about ssl pass through for keystone and horizon we have that kinda now, and it works, but in the deployments i've overseen just about all of them want SSL termination at the LB . so i think we should support it however i dont know if it should be our primary usecase. | 13:23 |
cloudnull | that said, im open to it if we think it best | 13:23 |
cloudnull | morning automagically | 13:23 |
*** karimb has joined #openstack-ansible | 13:24 | |
admin0 | cloudnull: as a deployer, i just expect SSL to work ( via haproxy, or via passthrought to the direct containers ) is not something to look into pros and cons or about | 13:25 |
cloudnull | that has been the general sentiment on deployments i've done too | 13:25 |
admin0 | yeah .. because there are a lot of things to do .. SSL done, yes .. move on to next item .. | 13:26 |
*** BjoernT has joined #openstack-ansible | 13:26 | |
admin0 | leaving pros and cons of where is the best place to use SSL to get some millisecond improvement to someone else :D | 13:26 |
admin0 | i mean directly to instances or via haproxy | 13:26 |
evrardjp | it's not only that admin0 | 13:26 |
evrardjp | it's about end to end ssl or not | 13:27 |
evrardjp | but that's another discussion I'll keep for later | 13:27 |
*** adreznec has quit IRC | 13:27 | |
evrardjp | having everything simple and already defined for the deployer is nice | 13:27 |
evrardjp | admin0 did you try the code already? | 13:27 |
admin0 | evrardjp: i get that, but the first thing is to get the public side secured ( adn then later worry about if we can also secure the internal traffic as well ) | 13:27 |
*** gfa_ has quit IRC | 13:28 | |
evrardjp | it could be nice if you could bring your input too | 13:28 |
*** czunker has quit IRC | 13:28 | |
admin0 | i am waiting for the output | 13:29 |
*** gfa_ has joined #openstack-ansible | 13:31 | |
*** jwitko has quit IRC | 13:32 | |
*** jwitko has joined #openstack-ansible | 13:33 | |
*** adreznec has joined #openstack-ansible | 13:33 | |
odyssey4me | admin0 but the output is waiting for your tests and for your to feedback the issues you found and how you solved them | 13:35 |
admin0 | yes . give me a few more minutes place | 13:36 |
*** openstackstatus has joined #openstack-ansible | 13:36 | |
*** ChanServ sets mode: +v openstackstatus | 13:36 | |
odyssey4me | open source solutions are delivered by a collective of people working on the same problems, not through a one-sided push mechanism | 13:36 |
evrardjp | +1 | 13:37 |
-openstackstatus- NOTICE: We have recovered one of our cloud providers, but there is a huge backlog of jobs to process. Please have patience until your jobs are processed | 13:39 | |
evrardjp | we want NAMES | 13:39 |
evrardjp | even if we know them | 13:39 |
evrardjp | quick question about https://review.openstack.org/#/c/306632 there is no scenario where ironic can access public swift but not internal swift network? | 13:42 |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible: Decrease MariaDB wait timeout https://review.openstack.org/307826 | 13:42 |
evrardjp | if it's a possible scenario, should we set OS_ENDPOINT_TYPE=internalURL ? | 13:43 |
*** javeriak has quit IRC | 13:43 | |
evrardjp | instead of using a variable | 13:43 |
cloudnull | evrardjp: im going to say no. | 13:44 |
evrardjp | because we already use something like openrc_os_endpoint_type as a variable, so I am thinking about variable proliferation | 13:44 |
cloudnull | ironic should only use the internalURL | 13:45 |
*** asettle has quit IRC | 13:45 | |
cloudnull | IMO | 13:45 |
cloudnull | i guess that could be debatable | 13:45 |
evrardjp | then it's fine for me | 13:45 |
cloudnull | but if it goes over public its essentially leaving the environment to download the image which may or may not be over SSL | 13:46 |
evrardjp | I don't want to start a debate, I'm trying to review your patch :D | 13:46 |
cloudnull | reviewing is a good time for a debate :) | 13:46 |
evrardjp | debate is good when it comes to result. Consensus avoid debate and skips steps :D | 13:46 |
admin0 | trying to start fresh, got a merge conflict on a newly cloned stable/mitaka | 13:47 |
admin0 | git fetch https://git.openstack.org/openstack/openstack-ansible refs/changes/99/277199/29 && git cherry-pick FETCH_HEAD | 13:47 |
admin0 | error: could not apply 971fd35... Enable SSL termination for all services | 13:47 |
admin0 | both modified: playbooks/haproxy-install.yml and playbooks/vars/configs/haproxy_config.yml | 13:48 |
evrardjp | admin0 try on master | 13:48 |
admin0 | ok | 13:48 |
*** saneax_AFK is now known as saneax | 13:50 | |
*** pjm6 has quit IRC | 13:51 | |
*** pjm6 has joined #openstack-ansible | 13:52 | |
*** pjm6 has quit IRC | 13:52 | |
*** pjm6 has joined #openstack-ansible | 13:54 | |
odyssey4me | admin0 the patch should be tested on master, as that is where the patch is currently targeted - it is premature to test it on older releases | 13:55 |
admin0 | i see all haproxy endpoints behind SSL | 13:56 |
admin0 | and responding to SSL | 13:56 |
*** pjm6 has joined #openstack-ansible | 13:56 | |
*** schwicht has quit IRC | 13:56 | |
admin0 | but i tested only the haproxy install now .. i am going to quick setup the full service and do proper testing ..(doing operations as a normal user wtih curl —debug and analyizing the headers) | 13:56 |
admin0 | odyssey4me: since i always start with haproxy-setup playbook, this will also allow me to test if it fails on haproxy like last time | 13:57 |
admin0 | and this time, i can do a bug report | 13:57 |
*** rohanp has joined #openstack-ansible | 13:58 | |
admin0 | cloudnull: +0.9 :) .1 after testing D: | 13:58 |
*** jthorne has joined #openstack-ansible | 13:58 | |
admin0 | :D | 13:58 |
odyssey4me | cloudnull FYI https://review.openstack.org/307831 | 13:59 |
cloudnull | nice! | 13:59 |
odyssey4me | request for mariadb mirror | 13:59 |
odyssey4me | mattt ^ | 13:59 |
odyssey4me | jmccrory ^ | 13:59 |
admin0 | can i donate a mirror ? | 13:59 |
odyssey4me | I have no idea whether my patch is right. I'll wait for review feedback, but at least the ball is rolling. | 13:59 |
odyssey4me | admin0 this is for a mirror in OpenStack-CI resources, which we are asked to use for CI purposes | 14:00 |
*** schwicht has joined #openstack-ansible | 14:00 | |
odyssey4me | admin0 if you wish to donate CI resources to OpenStack, then you may approach the -infra team and discuss the offer | 14:00 |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:01 | |
admin0 | ok | 14:02 |
*** psilvad has joined #openstack-ansible | 14:02 | |
admin0 | odyssey4me: i can give a +1 when i have at least one merged patch ? | 14:03 |
odyssey4me | admin0 anyone is able to vote on patches | 14:03 |
*** woodard has quit IRC | 14:04 | |
*** jayc_ has joined #openstack-ansible | 14:04 | |
*** woodard has joined #openstack-ansible | 14:04 | |
*** jayc_ is now known as jayc | 14:07 | |
*** KLevenstein has joined #openstack-ansible | 14:09 | |
evrardjp | cloudnull are there some variables I should change? | 14:09 |
evrardjp | for the ssl testing | 14:10 |
cloudnull | no | 14:10 |
cloudnull | its on by default | 14:10 |
cloudnull | and itll be on for all public endpoints | 14:11 |
cloudnull | additionally some basic ACLs are in place for services that should not be routable via haproxy on the public interfaces. | 14:12 |
evrardjp | yes that's cool | 14:14 |
evrardjp | I think there should be an acl like acl blacklist -- | 14:15 |
evrardjp | src -- | 14:15 |
evrardjp | but that's another topic | 14:15 |
evrardjp | for later | 14:15 |
sigmavirus24 | admin0: please don't just +1 without a comment though. Please make sure that you demonstrate that you've reviewed a patch and maybe tried it out. | 14:16 |
cloudnull | the interface will allow you to have a custom acl whitelist | 14:16 |
evrardjp | cloudnull does that allow to create a new acl ? | 14:17 |
admin0 | i am not going to +1 yet . but actually test it out and then provide those details as well ( summary) | 14:17 |
cloudnull | evrardjp: it does | 14:17 |
admin0 | like this is what i expected, what i got and what I tested, so +1 from my side kind of comment | 14:17 |
evrardjp | so you mean a REALLY new acl will be included live? | 14:17 |
evrardjp | I thought only a change of acl was doable | 14:17 |
evrardjp | that's cool news | 14:17 |
cloudnull | evrardjp: https://review.openstack.org/#/c/277199/29/playbooks/vars/configs/haproxy_config.yml@26 | 14:17 |
evrardjp | yes sure I saw that | 14:18 |
cloudnull | if you change that you can add / remove acls | 14:18 |
*** cloudtrainme has joined #openstack-ansible | 14:18 | |
evrardjp | let me try the web interface for haproxy once, I'm always using the socket for that | 14:18 |
*** asettle has joined #openstack-ansible | 14:18 | |
evrardjp | oh you mean networks in the acl | 14:18 |
cloudnull | ah ive not given the web interface a go | 14:19 |
cloudnull | evrardjp: yes | 14:19 |
evrardjp | so change the acl itself | 14:19 |
evrardjp | ok | 14:19 |
evrardjp | then yes | 14:19 |
evrardjp | I get it | 14:19 |
evrardjp | it was about new acls I'm talking about | 14:19 |
cloudnull | ok | 14:20 |
cloudnull | then no. not without changing the ACLs | 14:20 |
evrardjp | anyway that's for the future :D | 14:21 |
evrardjp | I have issues with horizon | 14:21 |
evrardjp | the rest seems fine | 14:21 |
cloudnull | did you pull in the rfc patches? | 14:23 |
*** asettle has quit IRC | 14:23 | |
cloudnull | like so https://review.openstack.org/#/q/status:open+branch:master+topic:ssl-updates | 14:24 |
evrardjp | the others are merged | 14:24 |
evrardjp | oh | 14:24 |
cloudnull | https://review.openstack.org/#/c/305912/ | 14:24 |
evrardjp | yes I see | 14:25 |
cloudnull | horizon will throw hostname lookup problems | 14:25 |
cloudnull | i should add https://review.openstack.org/#/c/305912/ to the dep list | 14:26 |
evrardjp | my browser cache had a glitch, I saw the Depends-On from patchset 27 | 14:26 |
evrardjp | :/ | 14:26 |
cloudnull | anyway, those rfc updates we're a result of all of the SSL testing | 14:27 |
*** bbmbx has joined #openstack-ansible | 14:29 | |
evrardjp | could you link all the appropriate patches? | 14:30 |
*** galstrom_zzz is now known as galstrom | 14:30 | |
cloudnull | not all of them are deps of the specific "SSL all the things" patch but all of them fix the same issue I found while testing "SSL all the things" | 14:30 |
cloudnull | evrardjp: i'd pull in https://review.openstack.org/#/q/status:open+branch:master+topic:ssl-updates | 14:30 |
evrardjp | pulling it all | 14:31 |
*** mbrou007 has joined #openstack-ansible | 14:34 | |
admin0 | what does the tick in workflow mean in the review system ? | 14:36 |
automagically | admin0: http://docs.openstack.org/infra/manual/developers.html#code-review | 14:37 |
*** pjm6 has quit IRC | 14:37 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible: Fix container hostname for RFC 1034/1035 https://review.openstack.org/306794 | 14:38 |
*** pjm6 has joined #openstack-ansible | 14:38 | |
admin0 | automagically: \o/ | 14:38 |
odyssey4me | mattt https://review.openstack.org/#/q/status:open+branch:master+topic:ssl-updates | 14:38 |
mattt | ok makes sense now | 14:38 |
evrardjp | cloudnull could you make the commit 277199 depend on the 306794? | 14:40 |
*** pjm6_ has joined #openstack-ansible | 14:40 | |
evrardjp | don't know if it's really necessary | 14:41 |
admin0 | fatal: [c14_rabbit_mq_container-fd76fc02] => Failed to template {{ hostvars[groups['rabbitmq_all'][0]]['rabbitmq_ssl_key_fact'] | — does this var needs to be present ? | 14:41 |
evrardjp | it just more readable | 14:41 |
cloudnull | evrardjp: i ca n | 14:41 |
evrardjp | thanks | 14:41 |
odyssey4me | admin0 clear your fact cache and re-run the rabbitmq play - the play should set the facts appropriately | 14:41 |
admin0 | odyssey4me: it was a brand new formatted machine where it failed ( like 1st time failed ) | 14:42 |
admin0 | same procedure still ? | 14:42 |
*** woodard has quit IRC | 14:43 | |
*** pjm6 has quit IRC | 14:43 | |
*** pjm6_ has quit IRC | 14:43 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Enable SSL termination for all services https://review.openstack.org/277199 | 14:43 |
*** woodard has joined #openstack-ansible | 14:43 | |
cloudnull | ^ evrardjp | 14:43 |
cloudnull | updated . | 14:43 |
*** woodard has quit IRC | 14:43 | |
cloudnull | odyssey4me: is out depends-on things working ? | 14:43 |
*** eric_lopez has quit IRC | 14:43 | |
*** woodard has joined #openstack-ansible | 14:44 | |
cloudnull | evrardjp: idk if it'll gate yet because the deps aren't merged but the commit message has been updated | 14:44 |
*** mbrou007 has quit IRC | 14:45 | |
joker_ | could some one help me with this error: odyssey4me | 14:45 |
cloudnull | joker_: odyssey4me is an unrecoverable error | 14:46 |
cloudnull | :p | 14:46 |
joker_ | odyssey4me : I have ran setup-hosts.yml and it finished without any error. here is my vv output https://gist.github.com/celikmustafa89/ce5ab1617eb32a10e24b03668bfd25aa | 14:46 |
joker_ | yeah :D | 14:46 |
*** Brew has joined #openstack-ansible | 14:46 | |
joker_ | after that ı have ran setup-infrstructure-hosts.yml and I go this error https://gist.github.com/celikmustafa89/426f3b5c7adb34d10297bfd4718b7333 | 14:47 |
*** eric_lopez has joined #openstack-ansible | 14:47 | |
joker_ | cloudnull can you check the output? | 14:47 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-lxc_hosts: Changed for lxc-host setup/build for multi-distro https://review.openstack.org/307856 | 14:48 |
cloudnull | joker_: sure | 14:48 |
joker_ | cloudnull : than we can fix odyssey4me error :D | 14:48 |
* cloudnull looking now | 14:48 | |
odyssey4me | cloudnull nope, we have no instrumentation yet for zuul-cloner - working out other stuff, it's in the queue | 14:48 |
cloudnull | haha -- when will then be now!?!?!? | 14:48 |
cloudnull | :p | 14:48 |
odyssey4me | cloudnull in the year of the linux desktop :p | 14:49 |
*** mgoddard_ has joined #openstack-ansible | 14:49 | |
cloudnull | ive been using the linux desktop for years! | 14:49 |
*** pjm6 has joined #openstack-ansible | 14:49 | |
* cloudnull takes ball and goes home ... | 14:49 | |
admin0 | odyssey4me: that facts thing helped .. how does this work .. i mean why is this step required ? | 14:49 |
*** pjm6_ has joined #openstack-ansible | 14:50 | |
cloudnull | joker_: whats the error ? | 14:50 |
evrardjp | rebuilding my aio with all these dependencies | 14:50 |
evrardjp | easier to have a real test | 14:50 |
odyssey4me | admin0 http://docs.openstack.org/developer/openstack-ansible/install-guide/ops-troubleshooting.html#cached-ansible-facts-issues | 14:50 |
admin0 | :D | 14:51 |
admin0 | i will look into docs first before asking | 14:51 |
joker_ | cloudnull : it is at end of the second post. you can find it by typing "failed: [ansible01_repo_container-d24349b7] => (item={ ............" | 14:51 |
*** mgoddard_ has quit IRC | 14:51 | |
admin0 | joker_: is your haproxy running and answering on those ports | 14:51 |
admin0 | i faced those errors a lot before which is why i started to start with openstack-ansible haproxy-setup playbook first before even doing setup-hosts .. | 14:52 |
joker_ | admin0 yes | 14:52 |
joker_ | can you check again cloudnull. ı updated it | 14:53 |
cloudnull | joker_: the failed i see are ignored | 14:53 |
*** mgoddard has joined #openstack-ansible | 14:53 | |
admin0 | but your case is a bit diff | 14:53 |
admin0 | this file is incomplete ? | 14:53 |
cloudnull | nevermind i see it in the update | 14:53 |
joker_ | cloudnull : no that's about pip version. it fixed it automaticallt. I just updated it. please check again | 14:54 |
*** pjm6 has quit IRC | 14:54 | |
*** mgoddard_ has joined #openstack-ansible | 14:55 | |
joker_ | I have an emergency, I will be here in 30 minutes. sorry. | 14:55 |
*** mgoddard has quit IRC | 14:55 | |
*** phalmos has joined #openstack-ansible | 14:55 | |
cloudnull | np | 14:56 |
*** mgoddard__ has joined #openstack-ansible | 14:57 | |
*** joker__ has joined #openstack-ansible | 14:57 | |
*** mgoddard_ has quit IRC | 14:57 | |
*** mgoddard__ has left #openstack-ansible | 14:58 | |
admin0 | playbooks fails at: abbitmq_server | Enable queue mirroring | 15:01 |
*** pjm6_ is now known as pjm6 | 15:01 | |
admin0 | i redid the steps removing facts . runnig playbook again | 15:02 |
admin0 | same output | 15:02 |
*** joker__ has quit IRC | 15:04 | |
*** karimb has quit IRC | 15:04 | |
*** joker__ has joined #openstack-ansible | 15:04 | |
admin0 | https://gist.github.com/a1git/ac589606f422c4385beb32ad4912d29f — that is the error i get | 15:04 |
*** cloudtrainme has quit IRC | 15:06 | |
openstackgerrit | Merged openstack/openstack-ansible: make hostname,network and ip-address on all examples consistent https://review.openstack.org/303427 | 15:07 |
*** cloudtrainme has joined #openstack-ansible | 15:08 | |
*** spotz_zzz is now known as spotz | 15:08 | |
*** aludwar has quit IRC | 15:10 | |
*** weezS has joined #openstack-ansible | 15:10 | |
*** Mudpuppy has joined #openstack-ansible | 15:13 | |
cloudnull | odyssey4me: bug triage ? | 15:13 |
*** aludwar has joined #openstack-ansible | 15:13 | |
*** Mudpuppy has quit IRC | 15:14 | |
*** Mudpuppy has joined #openstack-ansible | 15:14 | |
odyssey4me | bug triage happens in 45 mins :) | 15:16 |
odyssey4me | admin0 it looks like your rabbitmq cluster is broken - fix that up, or shut them all down, or delete the containers | 15:17 |
* cloudnull hates time when it changes | 15:17 | |
odyssey4me | note that the log tells you what to try | 15:17 |
mattt | cloudnull: the changing meeting time is seriously annoying :( | 15:19 |
cloudnull | mattt +1 | 15:19 |
*** saneax is now known as saneax_AFK | 15:19 | |
cloudnull | the world should just run on UTC | 15:20 |
cloudnull | time zones are shit | 15:20 |
*** phalmos has quit IRC | 15:20 | |
spotz | +1 It's taken the WoO group a month to even semi get it right and we still ended up with people getting it wrong | 15:21 |
palendae | mattt: The meeting time didn't change, we did :V | 15:21 |
mattt | palendae: heh yeah | 15:22 |
* palendae liked it when his state ignored DST | 15:23 | |
admin0 | yes . did that and moved on :D | 15:23 |
mattt | palendae: i suppose all projects schedule meetings in UTC? | 15:23 |
palendae | mattt: Yep | 15:23 |
palendae | Supposed to, anyway | 15:23 |
evrardjp | cloudnull I agree | 15:27 |
*** phalmos has joined #openstack-ansible | 15:28 | |
joker_ | hi cloudnull , did you find something? | 15:29 |
admin0 | cloudnull: the setup scripts are running .. i will do a good test this evening and then put in the comments | 15:30 |
* admin0 heading out for 2 hours now | 15:30 | |
*** admin0 has quit IRC | 15:31 | |
*** karimb has joined #openstack-ansible | 15:31 | |
*** ssl_ has joined #openstack-ansible | 15:33 | |
ssl_ | getting the following error while installing aio: | 15:34 |
ssl_ | msg: fatal: unable to access 'https://git.openstack.org/openstack/tempest/': gnutls_handshake() failed: A TLS packet with unexpected length was received. | 15:34 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-lxc_hosts: Changed for lxc-host setup/build for multi-distro https://review.openstack.org/307856 | 15:35 |
*** weshay has quit IRC | 15:36 | |
cloudnull | joker_: no i've not | 15:36 |
odyssey4me | joker_ 'setuptools pip wheel failed with error code 1' what version of pip/setuptools/wheel are you using? | 15:36 |
joker_ | pip 7.1.2 but I downgrade it to install containers | 15:38 |
joker_ | during installation it upgrades pip to 8.1.1 | 15:38 |
odyssey4me | joker_ yeah, you can't downgrade the pip version | 15:39 |
odyssey4me | you must use the version that's pinned | 15:39 |
odyssey4me | joker_ try re-running the 'repo-install' playbook on its own and verify that it comepletes? | 15:40 |
joker_ | but It causes another problem without downgrading it. at the lxc_container-create step | 15:40 |
joker_ | ok I am running it again | 15:40 |
odyssey4me | joker_ then we need to isolate that problem and resolve it | 15:41 |
joker_ | I have found this bugs, and they suggest a quick fix which is downgrading pip https://bugs.launchpad.net/openstack-ansible/+bug/153599 | 15:41 |
openstack | Launchpad bug 153599 in xserver-xorg-video-ati (Ubuntu) "blank screen from Xserver - eMac G4 1.25GHz ppc " [High,Fix released] | 15:41 |
odyssey4me | joker_ are you going through an evaluation process? if this is a new evaluation then I would recommend testing with the head of stable/mitaka instead of liberty at this stage | 15:42 |
odyssey4me | joker_ I don't see what that bug has to do with a minimal ubuntu install | 15:42 |
odyssey4me | or pip for that matter | 15:42 |
stevelle | I'm +1 on moving to fixed UTC-based schedule on triage. mattt for triage dictator for life | 15:44 |
*** eil397 has joined #openstack-ansible | 15:45 | |
joker_ | odyssey4me sorry this solution https://bugs.launchpad.net/openstack-ansible/+bug/1535998 | 15:46 |
openstack | Launchpad bug 1535998 in openstack-ansible "unable to upgrade apt installed requests with pip 8.0.0" [Undecided,Fix released] | 15:46 |
odyssey4me | joker_ that situation has been resolved long ago, as is quite clearly noted in the bug status | 15:46 |
joker_ | odyssey4me : I know but without that quick fix I am getting this error https://gist.github.com/celikmustafa89/4c6600682d5c7f72898f5229409c72f9 | 15:48 |
odyssey4me | joker_ and my previous responses asking for more information have not yet been replied to | 15:48 |
odyssey4me | joker_ I asked you to provide a full verbose play output, and I asked you to try going into the host in question and doing the pip install manually with verbose output and to post the output | 15:49 |
palendae | stevelle: I thought they were UTC based? | 15:50 |
odyssey4me | I also asked you to post that info into a bug report so that we could help you go through a triage process as it seems that you're not always online in IRC | 15:51 |
palendae | It's just that DST moves *us* | 15:51 |
*** mikelk has quit IRC | 15:52 | |
joker_ | odyssey4me : ı passed that step by downgrading the pip, and to get what you want is starting all installation again. next time I will post it to you. now I am running repo-install.yml after that ı will try it again | 15:53 |
stevelle | palendae: DST doesn't mess us up, it's standard time that screws things. We should stay on DST :P | 15:55 |
palendae | stevelle: I think it's the shift ;) | 15:55 |
odyssey4me | joker_ hopefully repo-install will rebuild the packages properly with the right pip version | 15:55 |
palendae | Pick one, don't change! | 15:55 |
stevelle | I pick DST | 15:55 |
joker_ | odyssey4me : hopefully it is still running | 15:57 |
*** jmccrory_ has joined #openstack-ansible | 15:57 | |
*** ssl_ has quit IRC | 15:59 | |
joker_ | odyssey4me : it failed again here is the output https://gist.github.com/celikmustafa89/3769aa33d00ca447c7f99d95f3c70e98 | 16:00 |
joker_ | odyssey4me : I ran the command on related container and share the output under the gist as comment https://gist.github.com/celikmustafa89/3769aa33d00ca447c7f99d95f3c70e98 | 16:01 |
*** iceyao has quit IRC | 16:02 | |
odyssey4me | joker_ hmm, can you add --verbose to the pip install attempt ? | 16:03 |
spotz | ok cloudnull now we're late | 16:04 |
odyssey4me | bug triage here cloudnull, mattt, andymccr, d34dh0r53, hughsaunders, b3rnard0, palendae, Sam-I-Am, odyssey4me, serverascode, rromans, erikmwilson, mancdaz, _shaps_, BjoernT, claco, echiu, dstanek, jwagner, ayoung, prometheanfire, evrardjp, arbrandes, mhayden, scarlisle, luckyinva, ntt, javeriak, automagically, spotz, vdo, jmccrory, alextricity25, jasondotstar, KLevenstein, admin0, michaelgugino, ametts, v1k0d3n, | 16:04 |
odyssey4me | severion, bgmccollum | 16:04 |
odyssey4me | one new bug: https://bugs.launchpad.net/openstack-ansible/+bug/1472295 | 16:04 |
openstack | Launchpad bug 1472295 in python-glanceclient "Cinder and glance client have endpoint selection issues" [Undecided,New] | 16:04 |
joker_ | odyssey4me ı added it as comment under gist | 16:04 |
prometheanfire | woo | 16:05 |
joker_ | odyssey4me is that what u want? | 16:05 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Fix container hostname for RFC 1034/1035 https://review.openstack.org/306794 | 16:05 |
cloudnull | o/ | 16:05 |
spotz | \o/ | 16:06 |
joker_ | odyssey4me I have to catch the bus :/ u need anything else? | 16:06 |
rromans | . | 16:06 |
odyssey4me | joker_ we have a bug triage meeting now, I'll look again later | 16:07 |
*** asettle has joined #openstack-ansible | 16:07 | |
joker_ | odyssey4me : ok, thank you | 16:07 |
cloudnull | BjoernT: that looks like its fixed? | 16:08 |
cloudnull | looking at the multi-region change for glance client | 16:08 |
*** busterswt has joined #openstack-ansible | 16:10 | |
evrardjp | cloudnull would the big ssl change impact this? | 16:10 |
cloudnull | it would show you if you had a client issue | 16:11 |
cloudnull | the clients and services are all supposed to talk over the internalURL | 16:11 |
cloudnull | and if the client is ignoring that instruction because its broken | 16:11 |
cloudnull | itll be trying to talk over public | 16:11 |
cloudnull | which will have ssl using a selfsigned cert | 16:12 |
*** asettle has quit IRC | 16:12 | |
cloudnull | causing test and service breakage | 16:12 |
cloudnull | evrardjp: so in the gate we'd be able to find this issue a lot sooner. | 16:12 |
evrardjp | so what's the importance? | 16:14 |
*** cfarquhar has quit IRC | 16:14 | |
evrardjp | odyssey4me is busy :p | 16:14 |
*** sdake has joined #openstack-ansible | 16:14 | |
cloudnull | medium / low ? | 16:15 |
openstackgerrit | Nolan Brubaker proposed openstack/openstack-ansible: Add coverage reporting to inventory testing https://review.openstack.org/307906 | 16:15 |
odyssey4me | so I don't think we can do much about this except track it | 16:16 |
evrardjp | yup | 16:16 |
evrardjp | it seems quite low for us | 16:16 |
odyssey4me | this is not directly related to openstack-ansible, it's a glance and client client issue | 16:16 |
stevelle | invalid then? | 16:17 |
odyssey4me | yeah, I'm inclined to mark it invalid - it's very possible that the openstackclient resolves this anyway | 16:17 |
odyssey4me | I don't see why the service CLI's should be fixing this when they're meant to be deprecating their CLI's | 16:18 |
evrardjp | true | 16:18 |
odyssey4me | the other items in https://bugs.launchpad.net/openstack-ansible/+bugs?search=Search&field.status=New are waiting for validation | 16:19 |
odyssey4me | is there anything there that anyone has an update on? | 16:19 |
*** cfarquhar has joined #openstack-ansible | 16:19 | |
*** cfarquhar has quit IRC | 16:19 | |
*** cfarquhar has joined #openstack-ansible | 16:19 | |
stevelle | I still don't like the workaround for 1557682 :) | 16:20 |
odyssey4me | stevelle yeah, and cloudnull hasn't done the typey typey :) | 16:21 |
cloudnull | whats that ? | 16:21 |
odyssey4me | he keeps seeing squirrels | 16:21 |
odyssey4me | https://bugs.launchpad.net/openstack-ansible/+bug/1557682 | 16:21 |
openstack | Launchpad bug 1557682 in openstack-ansible "repo_build cannot refer to variables in Creating OSA requirement wheels " [Wishlist,New] - Assigned to Kevin Carter (kevin-carter) | 16:21 |
stevelle | it's wishlist, just gave me more grief in getting the role to test convergence | 16:21 |
cloudnull | oh i had forgotten about that one. | 16:22 |
stevelle | its not any higher priority; | 16:23 |
cloudnull | ah. | 16:23 |
*** Mudpuppy has quit IRC | 16:23 | |
cloudnull | it looks like it needs to be post processed by a jinja template | 16:23 |
*** phalmos has quit IRC | 16:23 | |
stevelle | yeah, that's all it would take | 16:23 |
*** jayc has quit IRC | 16:23 | |
cloudnull | bah. that might be hard. | 16:24 |
stevelle | I'm busy shaving other yaks right now though so havn't scratched that itch | 16:24 |
cloudnull | because its jinja rendering the list | 16:24 |
cloudnull | which needs jinja to render the jinja | 16:24 |
evrardjp | I already reached that issue but din't solve that, so I'd be happy to see it fixed for me to learn | 16:25 |
odyssey4me | luckily we have a jinja ninja :p | 16:25 |
*** sdake_ has joined #openstack-ansible | 16:25 | |
cloudnull | lol | 16:26 |
evrardjp | for this line, maybe having everything in jinja would be fine | 16:26 |
odyssey4me | that issue was filed before the repo build process was re-done (again) | 16:26 |
cloudnull | bah. this is fugly. | 16:26 |
evrardjp | or would it, jinja ninja? | 16:26 |
odyssey4me | is it still a current issue stevelle ? | 16:26 |
* cloudnull going to take a hard look at that today | 16:27 | |
stevelle | odyssey4me: I reverified it last week | 16:27 |
*** joker__ has quit IRC | 16:27 | |
stevelle | or to be honest, I stubbed my toe again on it because I forgot | 16:27 |
evrardjp | cloudnull, you are not allowed to use filters | 16:27 |
evrardjp | just for the fun | 16:27 |
* cloudnull goes to write a module | 16:27 | |
odyssey4me | ok cool, then I guess that means that this should be solved as it may come up as a need for other things | 16:28 |
palendae | cloudnull: write it in go | 16:28 |
odyssey4me | palendae don't tempt him | 16:28 |
cloudnull | palendae: obviously | 16:28 |
*** Mudpuppy has joined #openstack-ansible | 16:28 | |
palendae | odyssey4me: If I was tempting I'd tell him to write it in swift ;) | 16:28 |
cloudnull | statically compiled, for speed | 16:28 |
evrardjp | rust? | 16:29 |
stevelle | or for a challenge, write it only using the keys on the right half of the keyboard | 16:29 |
odyssey4me | ah cloudnull for speed nothing beats ASM | 16:29 |
evrardjp | lol | 16:29 |
cloudnull | now thats just crazy talk | 16:29 |
*** phalmos has joined #openstack-ansible | 16:29 | |
*** karimb has quit IRC | 16:29 | |
cloudnull | we're trying to have a serious discussion ... | 16:29 |
cloudnull | :p | 16:29 |
odyssey4me | be sure to cater for x86, amd64, ppc and ARM of course | 16:29 |
*** sdake has quit IRC | 16:29 | |
evrardjp | we are talking about the ninja... sure it's real? | 16:29 |
cloudnull | odyssey4me: cant forget mips | 16:31 |
odyssey4me | ah, of course - because everyone uses mips | 16:31 |
cloudnull | obviously | 16:33 |
cloudnull | the future ! | 16:33 |
pjm6 | I remember using mips when learning Assembly xD | 16:33 |
evrardjp | that's what I heard about public transportation with horses | 16:33 |
evrardjp | the future! | 16:33 |
stevelle | this seems relevant http://www.realultimatepower.net/index4.htm | 16:33 |
evrardjp | :D classic | 16:34 |
spotz | Don't pick on horses!:) | 16:35 |
odyssey4me | and apparently, just for funsies, mips has warrior-class processors | 16:35 |
odyssey4me | https://imgtec.com/mips/warrior/i-class-i6400-multiprocessor-core/ | 16:35 |
eil397 | it would be cool to use energy-aware technologies : - ) especially for automation | 16:38 |
LiftedKilt | when running the setup-hosts.yml playbook, I get "msg: Failed to lock apt for exclusive operation" errors and then it fails out seemingly randomly - any ideas? | 16:39 |
BjoernT | cloudnull: in regards to https://review.openstack.org/#/c/306794/ | 16:39 |
odyssey4me | LiftedKilt do you have anything else that\s using apt at the same time on the same hosts? | 16:39 |
LiftedKilt | odyssey4me: I shouldn't - they aren't doing anything else | 16:40 |
odyssey4me | LiftedKilt eg are you running the playbook multiple times through multiple shells against the same hosts | 16:40 |
cloudnull | LiftedKilt: ive also seen that issue when your inventory has the same host listed (ip address) with a different name | 16:40 |
odyssey4me | heh, that would do it | 16:40 |
cloudnull | ansible things they're different hosts | 16:40 |
LiftedKilt | cloudnull: that sounds probable | 16:40 |
cloudnull | BjoernT: yes? | 16:40 |
andymccr | +1 cloudnull, done that many times :D | 16:40 |
odyssey4me | oh dear | 16:40 |
* odyssey4me sends LiftedKilt to the sinbin | 16:41 | |
LiftedKilt | I used the same three nodes for all the infra roles | 16:41 |
cloudnull | me too | 16:41 |
odyssey4me | LiftedKilt as long as they all use the same name in the inventory, that's fine | 16:41 |
cloudnull | its fine to reuse the same nodes over and over again | 16:41 |
cloudnull | just make sure they have the same name | 16:41 |
odyssey4me | the name-ip must match everywhere in the inventory | 16:41 |
cloudnull | ++ ^ | 16:41 |
odyssey4me | in fact, perhaps raddaoui should add a check for multiple hosts with different IP's :) | 16:42 |
LiftedKilt | where does the inventory live? I assumed it was dynamically generated based on the openstack_user_config.yml | 16:42 |
odyssey4me | or maybe that'll be up palendae's alley :) | 16:42 |
odyssey4me | LiftedKilt it is - you can inspect it in the json file in /etc/openstack_deploy/ | 16:42 |
palendae | LiftedKilt: It is - it lives in /etc/openstack_deploy/openstack_inventory.json | 16:43 |
palendae | That file is basically env.d + conf + dynamic_inventory.py | 16:43 |
palendae | odyssey4me: Totally open to adding tests, yeah | 16:43 |
LiftedKilt | gotcha - should I edit it statically? | 16:43 |
palendae | A list here wouldn't be remiss: https://etherpad.openstack.org/p/openstack-ansible-newton-dynamic-inventory | 16:43 |
LiftedKilt | or do I need to rework the openstack_user_config | 16:44 |
palendae | odyssey4me: I'm not grokking your statement "add a check for multiple hosts with different IP's" | 16:44 |
palendae | Oh | 16:44 |
palendae | Got it | 16:44 |
*** Oku_OS is now known as Oku_OS-away | 16:45 | |
*** fawadkhaliq has joined #openstack-ansible | 16:45 | |
odyssey4me | palendae :) it would seem that a run-time check would be more appropriate to catch this issue | 16:45 |
palendae | Right | 16:45 |
palendae | Runtime check + a test | 16:45 |
palendae | test(s) | 16:45 |
evrardjp | I'm off! | 16:45 |
*** cfarquhar has quit IRC | 16:45 | |
odyssey4me | of course | 16:45 |
eil397 | https://bugs.launchpad.net/openstack-ansible/+bug/1442823 "Tempest failures after run_ssh = True" Anyone know status for it ? I would like to check current state with tempest and different config options for tempest. | 16:47 |
openstack | Launchpad bug 1442823 in openstack-ansible trunk "Tempest failures after run_ssh = True" [Medium,Incomplete] - Assigned to Tom Cameron (drdabbles) | 16:47 |
*** cfarquhar has joined #openstack-ansible | 16:47 | |
*** cfarquhar has quit IRC | 16:47 | |
*** cfarquhar has joined #openstack-ansible | 16:47 | |
odyssey4me | LiftedKilt you could inspect the json file to identify the cause, but it'll be easier to start with verifying that you don't have a mistake in the user_config and conf.d files | 16:47 |
odyssey4me | LiftedKilt you can also use the inventory-manage script in the scripts directory to list all known hosts from the inventory | 16:48 |
odyssey4me | eil397 that bug is old an invalid, ad the status says :) | 16:48 |
odyssey4me | *as | 16:48 |
LiftedKilt | odyssey4me: Looking back through the config again I see what you mean about the multiple names. I'm re-writing it | 16:48 |
LiftedKilt | odyssey4me: cloudnull thanks for the heads up | 16:48 |
*** weezS has quit IRC | 16:48 | |
eil397 | odessey4me: thanks | 16:49 |
odyssey4me | eil397 we test every commit in the integrated build using tempest, so it works | 16:49 |
eil397 | odessey4me: yes. I know. "test_list_summary='scenario heat_api cinder_backup ceilometer_api (25 tests)'" | 16:50 |
eil397 | odessey4me: last time when I was working with tempest and osa on mulihost deployment it was not working for me with my configuration because of floating_ips ( by default it was trying to use floating_ips to reach instances) | 16:51 |
odyssey4me | eil397 tempest has plenty of horrible assumptions made as it's made for the development community, not for real deployments | 16:53 |
odyssey4me | eil397 you can always just exluce the test that attempts the connection via the floating IP for your purposes | 16:53 |
eil397 | odysset4me: agree. is there anything that can be used for QA and healthcheck automated testing ? | 16:54 |
eil397 | odessey4me: I would like to use some basic test scenarios , and I think such scenario like "launch instance and terminate" should work without testing floating_ips | 16:55 |
odyssey4me | eil397 that's a topic that could take days - every environment has different opinions and it may be best to ask on the operator mailing list to see what people are doing | 16:57 |
odyssey4me | but tempest is very likely to be a bad choice for that sort of thing | 16:57 |
odyssey4me | personally I'd probably rather have a set of nagios (or similar) checks that do some basic actions in a test client which provide enough coverage to identify problems and give performance stats on a continuous basis | 16:58 |
eil397 | odyssey4me: do you know something better ? except monitoring tools. I'm sure operators usually relay on monitoring tools | 16:59 |
odyssey4me | tempest would raid your API and probably overwhelm your environment if you ran it often | 16:59 |
eil397 | odyssey4me: yes. I agree, of course QA and monitoring tools like nagios are different things. | 17:01 |
eil397 | odyssey4me: but if I | 17:02 |
eil397 | odessye4me: if I'm checking logs of nova-api, it should like simillar : - ) | 17:03 |
*** zhangjn has quit IRC | 17:06 | |
*** b3rnard0 is now known as b3rnard0_away | 17:07 | |
*** zhangjn has joined #openstack-ansible | 17:09 | |
*** javeriak has joined #openstack-ansible | 17:10 | |
*** kiranv has joined #openstack-ansible | 17:12 | |
raddaoui | odyssey4me, I am trying to catch in here, you mean add a check for hosts with different hostnames and same IPs in the user config | 17:12 |
openstackgerrit | Ala Raddaoui proposed openstack/openstack-ansible: modify how services are configured in haproxy https://review.openstack.org/301343 | 17:14 |
palendae | raddaoui: Yeah, so if you define (for example) aio1 with x.x.x.100 and x.x.x.101, the one seen last in the config will win | 17:15 |
palendae | Actually I'm talking about a slightly different thing :) | 17:15 |
palendae | But working on a patchset for mine which I will upload after lunch | 17:16 |
palendae | But yeah, having both would be good | 17:16 |
*** eil397 has left #openstack-ansible | 17:16 | |
raddaoui | I was thinking haproxy x.x.x.100 and then keystone x.x.x.100 different hostnames but same Ips | 17:17 |
raddaoui | example | 17:17 |
palendae | raddaoui: Yeah, that may have been the original example | 17:17 |
palendae | I'm gonna do lunch, but I have code for mine, will need to write a test | 17:19 |
raddaoui | okay | 17:20 |
palendae | raddaoui: Quickly before I leave, If you have thoughts on https://etherpad.openstack.org/p/openstack-ansible-newton-dynamic-inventory that'd be awesome | 17:20 |
automagically | raddaoui: Would definitely appreciate your thoughts there | 17:21 |
palendae | Trying to add content for discussion before we actually meet | 17:21 |
odyssey4me | raddaoui yes, one host with two IP's in the inventory - or two hosts with the same IP... either is bad | 17:21 |
palendae | And automagically/raddaoui I added https://review.openstack.org/#/c/307906/ to that pad, but reviews appreciated | 17:21 |
automagically | palendae: Awesome! Will review | 17:21 |
palendae | odyssey4me: So 1 host can't have 2 IPs I just found - last one read in will win. But I found the section and have an error | 17:22 |
palendae | Just need to write a test/submit | 17:22 |
odyssey4me | cool, thanks palendae | 17:22 |
odyssey4me | raddaoui if you like you can work out the other one | 17:22 |
palendae | I started down the path of that first one, but got lead to this :p | 17:22 |
palendae | But also feel free to tackle that too | 17:23 |
raddaoui | sure odyssey4me. Ill do that | 17:23 |
palendae | My main focus for the next ~month I think will be to increase test coverage | 17:23 |
palendae | I'd like to see us get to some reasonable level of coverage before we do heavy duty refactoring, personall | 17:23 |
*** olivier427 has joined #openstack-ansible | 17:24 | |
automagically | Always a safer approach | 17:24 |
raddaoui | and palendae I will look at that etherpad and see what I can add | 17:25 |
odyssey4me | dolphm dstanek lbragstad in doing some tests we've discovered that for some reason keystone is redirecting queries from port 5000 to port 35357... setting public_endpoint makes it not do that, but it seems weird that it would do that by default | 17:25 |
automagically | Now that we are measuring coverage, will be nice to get an idea of how much of a safety net we’ve got | 17:25 |
palendae | automagically: Yeah, and given we have people relying on this now, I'm far more comfortable building up a nice safety net before going nuts | 17:25 |
palendae | Yeah, my runs on my laptop showed 10% coverage currently. I think getting up to 75-80% would be a reasonable place to turn on enforcement in the gate | 17:26 |
palendae | But for now, we can just report | 17:26 |
palendae | Alright, lunch | 17:28 |
palendae | For real | 17:28 |
odyssey4me | stevelle mattt cloudnull FYI, we now have higher timeouts on the role jobs: https://review.openstack.org/306573 | 17:30 |
evrardjp | nova testing just got easier | 17:31 |
*** weshay has joined #openstack-ansible | 17:32 | |
stevelle | odyssey4me: #winning | 17:33 |
stevelle | pabelanger: thx for ^ | 17:34 |
*** javeriak_ has joined #openstack-ansible | 17:41 | |
*** olivier427 has quit IRC | 17:42 | |
*** javeriak has quit IRC | 17:43 | |
*** javeria__ has joined #openstack-ansible | 17:43 | |
*** electrofelix has quit IRC | 17:44 | |
openstackgerrit | Travis Truman (automagically) proposed openstack/openstack-ansible-rsyslog_client: Ansible 2.x - Address deprecation warning of bare variables https://review.openstack.org/307950 | 17:45 |
*** javeriak_ has quit IRC | 17:46 | |
cloudnull | odyssey4me: awesome ! | 17:48 |
automagically | odyssey4me and cloudnull - Was there discussion of getting an Ansible 2.x experimental check setup? | 17:48 |
automagically | Didn’t see it mentioned here: https://etherpad.openstack.org/p/openstack-ansible-taking-advantage-ansible2 | 17:48 |
cloudnull | no i dont think so | 17:49 |
cloudnull | but I'd be +1 | 17:49 |
automagically | Actually, it appears that line 106 does mention it | 17:49 |
javeria__ | hey cloudnull; i think you shared some script of yours a while back that checked for problematic services and tried restarting them? | 17:49 |
cloudnull | https://gist.github.com/cloudnull/d9c9a85bdfeccbbe5b93 <- javeria__ | 17:49 |
kiranv | Hello all.. I've been trying to setup an AIO node on a bare metal server with 32G memory and 1TB HDD.. When I set it up for the first time, everything comes up fine.. but, when I make a change to the config and rerun run-playbooks.sh, it always exits out with an error/failure.. can anyone help me understand why this is happenign? | 17:50 |
javeria__ | cloudnull perfect thanks; would this help with an aio thats been restarted? as things seem to be in a bad shape usually then | 17:50 |
odyssey4me | automagically I think that I'd like us to get Liberty->Mitaka upgrades done before we get too much of the Ansible 2 work done... otherwise fixes we need won't be so easy to backport | 17:50 |
automagically | kiranv: Can you share a gist/paste of the error you are getting? | 17:51 |
javeria__ | no actually there was another one cloudnull ...? | 17:51 |
odyssey4me | kiranv you shouldn't really run run-playbooks more than once... it's better to run the playbooks themselves directly | 17:51 |
odyssey4me | although run-playbooks is not as bad as it used to be | 17:52 |
automagically | odyssey4me: Well, assuming we keep the 1.9 and 2.x gates running on liberty, we should be fine | 17:52 |
kiranv | I am trying to set up liberty.. I changed the password for keystone and re ran run-playbooks.. it gives me the following error | 17:52 |
kiranv | changed keystone_auth_password in /opt/openstack-ansible/ r failed: Broken pipe\r\ndebug2: Received exit status from master 1\r\n', 'failed': True, 'attempts': 10, 'parsed': False}failed: [aio1_galera_container-0d2ed55b] => (item={'priv': '*.*:USAGE', 'state': 'present', 'password': u'', 'host': 'localhost', 'name': u'monitoring'}) => {"attempts": 10, "failed": true, "item": {"host": "localhost", "name": "monitoring", "pa | 17:52 |
cloudnull | javeria__: nothing that i can think of ? | 17:52 |
odyssey4me | kiranv if you change the password, stuff won't work - the user creation steps for the admin user will not change the password | 17:52 |
automagically | odyssey4me: Hmm, fun. We should definitely document that, if it isn’t documented already | 17:53 |
odyssey4me | kiranv you have to set the password before you build, or you should change the password through keystone before reconfiguring the services | 17:53 |
kiranv | http://pastebin.com/4cXzPsAB | 17:53 |
automagically | I’ll check if its documented anywhere | 17:53 |
javeria__ | cloudnull okay :(, it was one that went thru services and checked which ones were down; anyway thanks for looking | 17:53 |
kiranv | In my previous trial, I made changes to the hosts file and ran run-playbooks.. and it exited with an error as well | 17:54 |
odyssey4me | automagically so the trouble is that if we introduce backward incompatible changes into master, then we can't backport them to mitaka - considering that the upgrade work typically finds bugs which will need implementation in both master and mitaka I think we should maintain compatibility across both branches until the upgrade work is complete | 17:54 |
odyssey4me | kiranv as stated before - you can't make password changes after the env is build by simply editing the secrets... it's more involved | 17:55 |
automagically | I hear what you are saying. It would complicate backport | 17:55 |
openstackgerrit | Jimmy McCrory proposed openstack/openstack-ansible-rabbitmq_server: Multi-distro framework for rabbitmq_server role https://review.openstack.org/286282 | 17:55 |
odyssey4me | kiranv if it's a test env and you change secrets, you're best advised to tear down and rebuild unless you know openstack well enough to understand the effects of the change | 17:56 |
automagically | My concern is that I’ve seen more Ansible 2.x work patchs come in than Liberty -> Mitaka upgrade work | 17:56 |
javeria__ | also wanted to ask you guys; the slowing down behaviour i was experiencing on our osic cluster would go away for a few hours after running nova playbooks. once it came back, i just ran the nova plays again and things would go back to normal. any idea what was going on? were some buffers getting filled up in the meantime? | 17:56 |
kiranv | ok.. I understand that.. but in my previous trial, I did not make any password changes. I changed the hosts file and re ran run-playbooks.sh .. and it exited out with a similar error | 17:56 |
odyssey4me | automagically yeah, but the patches are all compatible right now - so that's ok... we can maintain that... and we'll need someone to pick up the torch to lead the upgrade work | 17:56 |
odyssey4me | the sooner the better | 17:56 |
automagically | Fair point | 17:57 |
kiranv | could you point me to any documentation on teardown? I've been trying the commands listed in rebuild-stack section of https://github.com/jolsenatx/openstack-ansible-lxc | 17:57 |
odyssey4me | kiranv I have no idea where you got that link | 17:57 |
kiranv | and it is resulting me having to re install host os | 17:57 |
odyssey4me | kiranv the AIO docs are here: http://docs.openstack.org/developer/openstack-ansible/developer-docs/quickstart-aio.html | 17:57 |
odyssey4me | the general docs are here: http://docs.openstack.org/developer/openstack-ansible/ | 17:58 |
kiranv | should I just run the teardown.sh scripts as descrived in http://docs.openstack.org/developer/openstack-ansible/developer-docs/quickstart-aio.html | 17:59 |
javeria__ | odyssey4me btw whats the best way to put an aio back into an operational state after a reboot; i know they arent meant to be rebooted but still? | 17:59 |
odyssey4me | kiranv the docs describe how to do it | 17:59 |
odyssey4me | javeria__ check the AIO docs ;) | 18:00 |
odyssey4me | javeria__ http://docs.openstack.org/developer/openstack-ansible/developer-docs/quickstart-aio.html#rebooting-an-aio | 18:00 |
javeria__ | odyssey4me ah okay :) | 18:00 |
odyssey4me | that query comes in often enough to warrant its own heading :p | 18:00 |
kiranv | ok. thanks. | 18:00 |
pabelanger | stevelle: np | 18:01 |
javeria__ | hey has anyone ever seen the issue where you cant create a project from horizon, it gives you a danger type error; but it works from cli? i cant seem to see anything in the logs | 18:03 |
*** tiagogomes has quit IRC | 18:03 | |
openstackgerrit | Travis Truman (automagically) proposed openstack/openstack-ansible: DOC - Adding warning about changing passwords/secrets https://review.openstack.org/307961 | 18:04 |
automagically | kiranv: Would appreciate your review on ^ | 18:05 |
odyssey4me | javeria__ horizon logs are fully muted by default - as I recall you have to do quite a bit of editing of the local_settings to make them show up in the logs | 18:05 |
odyssey4me | there's a section at the end where you can customise which logs should show | 18:05 |
odyssey4me | thanks automagically - small comment | 18:07 |
javeria__ | odyssey4me yea theres nothing there that would help; okay let me try and figure that out | 18:07 |
odyssey4me | automagically maybe a note should be in the AIO docs too? | 18:07 |
automagically | odyssey4me: Could duplicate it there, but I tend to think of the AIO docs as specific to the AIO, whereas everything in the install guide applies to AIO as well as other configs | 18:07 |
javeria__ | also odyssey4me, my question above about the nova plays solving the cluster slowness, ^; any idea what migtve been happening? | 18:07 |
odyssey4me | automagically fair enough | 18:08 |
odyssey4me | javeria__ I'm not sure if this perhaps has something to do with it? https://review.openstack.org/307231 | 18:09 |
openstackgerrit | Travis Truman (automagically) proposed openstack/openstack-ansible: DOC - Adding warning about changing passwords/secrets https://review.openstack.org/307961 | 18:09 |
kiranv | I think a small comment warning the user not to change the passwords after deploying in the /etc/openstack_deploy/user_secrets file should do it | 18:09 |
automagically | Good call kiranv, I’ll add a comment there as well | 18:09 |
javeria__ | odyssey4me would that only be apparent at scale though? ive seen the same behaviour with smalller installations | 18:10 |
*** weezS has joined #openstack-ansible | 18:10 | |
odyssey4me | javeria__ based on the comment in the commit message, I expect that any long running install would end up with mariadb memory wastage due to dangling connections | 18:11 |
odyssey4me | but I don't actually know - I would way prefer to actually put together a decent test proposal to figure out a proper set of settings to scale nicely | 18:11 |
openstackgerrit | Travis Truman (automagically) proposed openstack/openstack-ansible: DOC - Adding warning about changing passwords/secrets https://review.openstack.org/307961 | 18:11 |
javeria__ | odyssey4me it was only a few hours though for the large one; that it would start getting slow | 18:13 |
*** kvemuri has joined #openstack-ansible | 18:18 | |
*** jmccrory_ has quit IRC | 18:19 | |
*** kvemuri has quit IRC | 18:22 | |
*** kiranv_ has joined #openstack-ansible | 18:24 | |
*** kiranv has quit IRC | 18:24 | |
*** kiranv_ has left #openstack-ansible | 18:24 | |
*** kiranv_ has joined #openstack-ansible | 18:24 | |
*** olivier427 has joined #openstack-ansible | 18:27 | |
kiranv_ | @automagically is there any way I can deploy a multi region setup with OSA? I found documentation on how to deploy federation.. but is there any way I can have my AIO point to keystone on another server? | 18:28 |
odyssey4me | kiranv_ yes it's completely possible | 18:28 |
automagically | kiranv_: I know that some folks in the community have tried, and its something that my team is actively pursuing. I believe you could set a bunch of keystone vars and do it | 18:28 |
odyssey4me | kiranv_ we have no docs ready though | 18:28 |
odyssey4me | but we have instrumented the ability to point any service at an external DB, and all the service registrations can be done against another keystone - but you'll have to unwind all the vars that have to be set | 18:29 |
automagically | kiranv_: Overriding vars in https://github.com/openstack/openstack-ansible-os_keystone/blob/master/defaults/main.yml#L132 - https://github.com/openstack/openstack-ansible-os_keystone/blob/master/defaults/main.yml#L154 should get you most of the way there | 18:29 |
odyssey4me | it's not trivial, and we hope to simplify it in the next cycle or two | 18:30 |
odyssey4me | automagically yep, those will be the main ones | 18:30 |
automagically | Perhaps some additional stuff to override in openrc as well | 18:30 |
cloudnull | kiranv_: i did a simple multi-region test which can be found here https://github.com/cloudnull/osad-regions | 18:31 |
cloudnull | thats way out of date | 18:31 |
cloudnull | but a good example of how it can be done | 18:31 |
automagically | cloudnull: Nice! I need to spend more time reading through your Github repos | 18:31 |
cloudnull | lots of old crusty BS there. :) | 18:31 |
cloudnull | i put everything in os-cloud or my github | 18:32 |
cloudnull | that way when i get an itch to destroy my laptop i dont lose things | 18:32 |
kiranv_ | thanks for the links.. If I change the keystone config and re run the keystone playbook, that should reset every service to point to the new server? or do I have to do this during the initial setuo? | 18:32 |
kiranv_ | setup* | 18:32 |
automagically | You’d re-run the non-Keystone playbooks | 18:33 |
automagically | But, you are probably better off starting fresh | 18:33 |
kiranv_ | ok.. I'll try that | 18:33 |
*** pjm6 has quit IRC | 18:40 | |
*** sdake_ has quit IRC | 18:41 | |
openstackgerrit | Travis Truman (automagically) proposed openstack/openstack-ansible-galera_server: Ansible 2.x - Address deprecation warning of bare variables https://review.openstack.org/307989 | 18:41 |
*** sdake has joined #openstack-ansible | 18:48 | |
*** b3rnard0_away is now known as b3rnard0 | 18:54 | |
*** admin0 has joined #openstack-ansible | 18:54 | |
openstackgerrit | Merged openstack/openstack-ansible: Add option to auto enable from VPNaaS in Horizon https://review.openstack.org/305433 | 18:54 |
openstackgerrit | Travis Truman (automagically) proposed openstack/openstack-ansible-ironic: Ansible 2.x - Address deprecation warning of bare variables https://review.openstack.org/307997 | 18:56 |
odyssey4me | cores - backport reviews for the mitaka 13.0.1 release: https://review.openstack.org/307998 / https://review.openstack.org/307691 / https://review.openstack.org/307683 / https://review.openstack.org/307681 / https://review.openstack.org/307659 | 18:58 |
*** fawadkhaliq has quit IRC | 19:00 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 19:06 | |
*** ChrisBenson has quit IRC | 19:12 | |
odyssey4me | jmccrory automagically cloudnull d34dh0r53 stevelle mattt hughsaunders andymccr ^ | 19:16 |
javeria__ | odyssey4me i just noticed that the user_variables.yml in the newer liberty tags is all commented out; don't we provide the basic settings that need to be in place? | 19:17 |
odyssey4me | javeria__ all required settings are already in role defaults or group_vars | 19:17 |
odyssey4me | role defaults for defaults, and group_vars for 'glue' | 19:17 |
javeria__ | odyssey4me they werent before? | 19:17 |
odyssey4me | javeria__ they were all, but we found a few strays - user_vars as provided was always meant to just be a sample of configs that are commonly set - but it got out of hand | 19:18 |
odyssey4me | and people got the wrong impression | 19:18 |
odyssey4me | it became a dumping ground for duplicated settings | 19:18 |
LiftedKilt | all of the lxc containers are failing to start - they are created, but they sit there and say that | 19:18 |
LiftedKilt | msg: The container [ %s ] failed to start. Check to lxc is available and that the container is in a functional state. | 19:18 |
LiftedKilt | failed: [controller_1_nova_console_container-e0e6669f -> controller_1] => {"error": "Failed to start container [ controller_1_nova_console_container-e0e6669f ]", "failed": true, "lxc_container": {"init_pid": -1, "interfaces": [], "ips": [], "state": "stopped"}, "rc": 1} | 19:18 |
javeria__ | odyssey4me oh i see... an installation of mine seems to be in a bad shape, i was wondering if i was missing the configs | 19:19 |
odyssey4me | LiftedKilt it's likely that one of the config changes that relate to them have broken the start - maybe something like the net configs | 19:19 |
LiftedKilt | odyssey4me: hmmm - I used the sample openstack_user_config.yml and just tweaked it slightly - http://pastebin.com/BqyZ3swW | 19:23 |
odyssey4me | LiftedKilt best would be to inspect the startup logs for the containers and see what they're saying | 19:23 |
LiftedKilt | odyssey4me: good call - "failed to attach 'c9e81e56_eth1' to the bridge 'br-mgmt': No such device | 19:24 |
LiftedKilt | " | 19:24 |
odyssey4me | yep, you gotta have the bridges you're using present | 19:24 |
LiftedKilt | do I need to manually create the bridges on all the target machines? I know the AIO script does it for you | 19:25 |
odyssey4me | all hosts will need br-mgmt | 19:25 |
odyssey4me | LiftedKilt yep, we cover it here: http://docs.openstack.org/developer/openstack-ansible/install-guide/targethosts-network.html | 19:26 |
cloudnull | LiftedKilt: we create all that on the aio however in prod the assumption is you will need to make them due it being very likely your kick system / internal automation will do most of that for you | 19:26 |
cloudnull | we used to have a thing that did it/could do it, but it was miserable and caused more problems than it solved. | 19:26 |
LiftedKilt | odyssey4me cloudnull: that makes sense - well, off to figure out how to write a playbook for target dpeloyment haha | 19:27 |
odyssey4me | LiftedKilt yeah, we might revisit that with Ansible 2.x as there's a nifty module for network configs now | 19:27 |
cloudnull | ++ | 19:27 |
odyssey4me | but at the moment we specifically need the hosts prepped | 19:28 |
LiftedKilt | odyssey4me: is there an eta for the ansible 2 migration? | 19:28 |
cloudnull | LiftedKilt: if you know the device layout and dont mind a template doing things for you | 19:28 |
cloudnull | you can do something like this https://github.com/os-cloud/osic-ironic-impl/blob/master/templates/os-refimpl-devices.cfg.j2 | 19:28 |
odyssey4me | LiftedKilt also make sure to either set lxc_container_ssh_key or to ensure the lxc hosts have your pub key in the right place - I've added https://review.openstack.org/307732 to make sure there's a hard fail before touching the hosts in the future | 19:28 |
cloudnull | i've used that with great success | 19:29 |
odyssey4me | LiftedKilt we'll do it for Newton and no earlier | 19:29 |
cloudnull | itll ip the nodes all off the last octet of the ssh host address. | 19:29 |
odyssey4me | this dev cycle is Newton | 19:29 |
cloudnull | but like i said its making some fairly strong assumptions about the devices you have | 19:30 |
LiftedKilt | odyssey4me: I'm using maas for ssh key insertion, and then running an ansible playbook that installs the dependencies and moves the authorized_keys file to the root user on the targets as well | 19:30 |
LiftedKilt | thanks for the links - that will definitely be helpful | 19:31 |
cloudnull | LiftedKilt: Bofu2U may have some pointers on MaaS ? | 19:31 |
odyssey4me | LiftedKilt ah ok, I just thought I'd call it out - note that we expect the is_rsa.pub file on the lxc hosts to push the key into the containers... what you're doing is good but may not be enough | 19:31 |
* cloudnull doesnt know much about maas | 19:31 | |
odyssey4me | it'd be really nice to have a blog post about using MaaS to deploy OSA :) | 19:32 |
* LiftedKilt doesn't know much about maas either | 19:32 | |
*** admin0 has quit IRC | 19:32 | |
openstackgerrit | Hector I Gonzalez Mendoza proposed openstack/openstack-ansible-os_barbican: Updated role using the Multi-Distro framework https://review.openstack.org/304209 | 19:32 |
cloudnull | izaakk: ++ | 19:32 |
odyssey4me | cloudnull izaakk FYI, don't forget that you can add a 'check experimental' comment to any role to get Ubuntu Xenial and CentOS7 jobs to execute | 19:33 |
odyssey4me | to any review for a role I mean | 19:33 |
*** admin0 has joined #openstack-ansible | 19:35 | |
*** admin0 has quit IRC | 19:36 | |
*** phiche has joined #openstack-ansible | 19:40 | |
odyssey4me | javeria__ cloudnull FYI - a question was posed in https://review.openstack.org/299761 | 19:41 |
*** admin0 has joined #openstack-ansible | 19:42 | |
izaakk | odyssey4me: will do | 19:42 |
cloudnull | thats a good question odyssey4me evrardjp, | 19:42 |
cloudnull | this was like the other task | 19:43 |
cloudnull | that when was never processed . so does it count as removing it | 19:43 |
cloudnull | by adding it we're changing the task | 19:43 |
admin0 | cloudnull: setup finished .. horizon does not work | 19:44 |
admin0 | 503 service unavailable | 19:44 |
cloudnull | admin0: yup did you pull in the deps within that task ? | 19:44 |
admin0 | hmm .. how :D | 19:44 |
cloudnull | w/out the RFC dependencies horizon wont work | 19:44 |
cloudnull | https://review.openstack.org/#/c/305912/ | 19:45 |
admin0 | i just did a cherry pick | 19:45 |
cloudnull | the external dependencies https://review.openstack.org/#/c/277199/ | 19:45 |
odyssey4me | admin0 yep, the roles need patches too - it's a pain right now but we'll make that easier soon | 19:45 |
cloudnull | in the commit message there are several Depends-On entries | 19:45 |
admin0 | so i need ot cherry pick that also ? | 19:45 |
cloudnull | kinda | 19:46 |
admin0 | :D | 19:46 |
cloudnull | you have to have the changes in the roles | 19:46 |
cloudnull | the roles are located in /etc/ansible/roles | 19:46 |
odyssey4me | cloudnull did you see evrardjp's feedback on the patch - we hit a pre-existing issue, but one that we actually need to figure out as it's important... it might be a keystone bug | 19:46 |
*** raddaoui has quit IRC | 19:47 | |
*** weezS has quit IRC | 19:47 | |
cloudnull | odyssey4me: which one is that? | 19:47 |
cloudnull | ...keystone bug ? | 19:48 |
odyssey4me | cloudnull https://review.openstack.org/277199 see the last review comment | 19:48 |
cloudnull | ah yea | 19:48 |
odyssey4me | for some reason external queries get redirected to the admin port | 19:48 |
odyssey4me | I've seen this before, but in reviewing various bugs and online reference apparently this is supposed to have been fixed | 19:49 |
odyssey4me | so maybe we're configuring something wrong somewhere, or maybe keystone still has a bug | 19:49 |
odyssey4me | force setting keystone_public_endpoint is a workaround at best | 19:50 |
admin0 | i do not want to make mistakes :D shall i just cherry pick that role ? | 19:57 |
*** gouthamr has joined #openstack-ansible | 19:59 | |
*** gouthamr has left #openstack-ansible | 19:59 | |
*** elo has joined #openstack-ansible | 20:00 | |
*** eric_lopez has quit IRC | 20:00 | |
odyssey4me | ok, I'm out for the night - cheerio all | 20:02 |
palendae | Night | 20:02 |
*** weezS has joined #openstack-ansible | 20:05 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 20:06 | |
spotz | night odyssey4me | 20:09 |
*** fawadkhaliq has joined #openstack-ansible | 20:14 | |
*** johnmilton has quit IRC | 20:16 | |
cloudnull | night odyssey4me | 20:16 |
*** fawadkhaliq has quit IRC | 20:22 | |
*** fawadkhaliq has joined #openstack-ansible | 20:22 | |
*** rohanp_ has joined #openstack-ansible | 20:23 | |
*** javeria__ has quit IRC | 20:28 | |
*** weezS has quit IRC | 20:29 | |
*** jayc_ has joined #openstack-ansible | 20:35 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-lxc_hosts: Changed for lxc-host setup/build for multi-distro https://review.openstack.org/307856 | 20:58 |
*** chhavi has quit IRC | 21:00 | |
openstackgerrit | Travis Truman (automagically) proposed openstack/openstack-ansible-lxc_container_create: Ansible 2.x - Address deprecation warning of bare variables https://review.openstack.org/308034 | 21:05 |
*** psilvad has quit IRC | 21:05 | |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible-os_swift: Remove XFS filesystem from the daily mlocate cron job https://review.openstack.org/308036 | 21:06 |
*** thorst_ has quit IRC | 21:08 | |
*** admin0 has quit IRC | 21:09 | |
*** BjoernT has quit IRC | 21:12 | |
openstackgerrit | Travis Truman (automagically) proposed openstack/openstack-ansible-memcached_server: Ansible 2.x - Address deprecation warning of bare variables https://review.openstack.org/308041 | 21:13 |
cloudnull | automagically: ++ awesome! | 21:16 |
cloudnull | have you been giving 2.1 a spin ? | 21:16 |
*** woodard_ has joined #openstack-ansible | 21:16 | |
*** retreved has quit IRC | 21:17 | |
*** woodard has quit IRC | 21:20 | |
*** woodard_ has quit IRC | 21:21 | |
*** fawadkhaliq has quit IRC | 21:23 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Enable SSL termination for all services https://review.openstack.org/277199 | 21:23 |
*** fawadkhaliq has joined #openstack-ansible | 21:24 | |
spotz | waiting for jenkins to verify but got reviews pulled up | 21:25 |
*** phiche has quit IRC | 21:26 | |
cloudnull | thanks spotz | 21:26 |
cloudnull | if you have a moment would you mind giving https://review.openstack.org/#/c/305586/ a go? | 21:26 |
spotz | cloudnull you're welcome feel guilty was busy the last few days | 21:26 |
spotz | cloudnull got it | 21:26 |
cloudnull | no guilt life happens | 21:27 |
cloudnull | thanks again :) | 21:27 |
*** thorst_ has joined #openstack-ansible | 21:28 | |
*** fawadkhaliq has quit IRC | 21:28 | |
*** Mudpuppy has quit IRC | 21:30 | |
*** Mudpuppy_ has joined #openstack-ansible | 21:30 | |
*** sdake_ has joined #openstack-ansible | 21:30 | |
*** thorst_ has quit IRC | 21:31 | |
*** thorst_ has joined #openstack-ansible | 21:31 | |
openstackgerrit | Nolan Brubaker proposed openstack/openstack-ansible: Refactor main inventory function for testability https://review.openstack.org/308047 | 21:31 |
*** phiche has joined #openstack-ansible | 21:32 | |
*** sdake has quit IRC | 21:33 | |
*** admin0 has joined #openstack-ansible | 21:34 | |
*** cloudtrainme has quit IRC | 21:51 | |
*** eric_lopez has joined #openstack-ansible | 21:51 | |
*** busterswt has quit IRC | 21:52 | |
*** elo has quit IRC | 21:54 | |
*** thorst_ has quit IRC | 21:56 | |
*** ametts has quit IRC | 21:57 | |
*** johnmilton has joined #openstack-ansible | 21:58 | |
openstackgerrit | Nolan Brubaker proposed openstack/openstack-ansible: Check for two IP addresses assigned to same host https://review.openstack.org/308052 | 22:01 |
*** sigmavirus24 is now known as sigmavirus24_awa | 22:02 | |
openstackgerrit | Nolan Brubaker proposed openstack/openstack-ansible: Refactor main inventory function for testability https://review.openstack.org/308047 | 22:03 |
openstackgerrit | Nolan Brubaker proposed openstack/openstack-ansible: Check for two IP addresses assigned to same host https://review.openstack.org/308052 | 22:03 |
*** Mudpuppy_ has quit IRC | 22:03 | |
*** phalmos has quit IRC | 22:04 | |
*** spotz is now known as spotz_zzz | 22:12 | |
*** fawadkhaliq has joined #openstack-ansible | 22:14 | |
*** KLevenstein has quit IRC | 22:18 | |
*** intr1nsic has quit IRC | 22:20 | |
*** Brew has quit IRC | 22:21 | |
*** furlongm has joined #openstack-ansible | 22:21 | |
*** galstrom is now known as galstrom_zzz | 22:24 | |
*** intr1nsic has joined #openstack-ansible | 22:26 | |
*** sdake_ is now known as sake | 22:26 | |
*** thorst has joined #openstack-ansible | 22:30 | |
*** klamath has quit IRC | 22:34 | |
*** asettle has joined #openstack-ansible | 22:39 | |
*** phiche has quit IRC | 22:45 | |
*** persia has quit IRC | 22:46 | |
*** gfa_ has quit IRC | 22:47 | |
*** admin0 has quit IRC | 22:50 | |
*** admin0 has joined #openstack-ansible | 22:52 | |
*** johnmilton has quit IRC | 22:54 | |
*** thorst has quit IRC | 22:58 | |
*** admin0 has quit IRC | 22:58 | |
*** admin0 has joined #openstack-ansible | 23:00 | |
*** saneax_AFK is now known as saneax | 23:00 | |
*** gfa_ has joined #openstack-ansible | 23:04 | |
*** persia has joined #openstack-ansible | 23:04 | |
*** admin0 has quit IRC | 23:16 | |
*** johnmilton has joined #openstack-ansible | 23:18 | |
*** fawadkhaliq has quit IRC | 23:19 | |
*** fawadkhaliq has joined #openstack-ansible | 23:19 | |
*** sake is now known as sdake | 23:22 | |
*** fawadkhaliq has quit IRC | 23:24 | |
*** asettle has quit IRC | 23:26 | |
*** asettle has joined #openstack-ansible | 23:28 | |
*** elo has joined #openstack-ansible | 23:39 | |
*** eric_lopez has quit IRC | 23:39 | |
*** jayc_ has quit IRC | 23:48 | |
*** jthorne has quit IRC | 23:52 | |
*** olivier427 has quit IRC | 23:57 | |
*** thorst has joined #openstack-ansible | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!