*** alikins has quit IRC | 00:12 | |
*** markvoelker has joined #openstack-ansible | 00:12 | |
*** jamesdenton has joined #openstack-ansible | 00:14 | |
*** markvoelker has quit IRC | 00:16 | |
*** klamath has quit IRC | 00:24 | |
*** Qiming has quit IRC | 00:24 | |
*** klamath has joined #openstack-ansible | 00:25 | |
openstackgerrit | Amy Marrich (spotz) proposed openstack/openstack-ansible-security: Docs: Update dev notes for Cat 3 controls https://review.openstack.org/318905 | 00:30 |
---|---|---|
*** jamesdenton has quit IRC | 00:53 | |
openstackgerrit | Merged openstack/openstack-ansible-repo_server: Removing unnecessary usage of with_items https://review.openstack.org/320639 | 00:56 |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible-os_nova: Cleanup spice HTML5 proxy git repo before updating it https://review.openstack.org/320650 | 00:56 |
*** BjoernT has joined #openstack-ansible | 00:57 | |
*** markvoelker has joined #openstack-ansible | 01:13 | |
*** alikins has joined #openstack-ansible | 01:17 | |
*** markvoelker has quit IRC | 01:17 | |
*** alikins has quit IRC | 01:19 | |
*** Qiming has joined #openstack-ansible | 01:26 | |
*** jamesdenton has joined #openstack-ansible | 01:30 | |
*** sdake has joined #openstack-ansible | 01:39 | |
*** alikins has joined #openstack-ansible | 01:44 | |
*** alikins has quit IRC | 01:44 | |
openstackgerrit | Merged openstack/openstack-ansible-os_keystone: Grammar: requires -> required https://review.openstack.org/320682 | 01:52 |
*** woodard has quit IRC | 01:52 | |
*** sdake_ has joined #openstack-ansible | 01:52 | |
*** sdake has quit IRC | 01:53 | |
*** sawblade_ has joined #openstack-ansible | 01:53 | |
*** schwicht has quit IRC | 01:53 | |
*** sawblade6 has quit IRC | 01:55 | |
*** jthorne_ has joined #openstack-ansible | 02:00 | |
*** jthorne has quit IRC | 02:00 | |
*** jamesdenton has quit IRC | 02:03 | |
*** thorst_ has quit IRC | 02:06 | |
*** thorst_ has joined #openstack-ansible | 02:06 | |
*** sdake_ has quit IRC | 02:09 | |
*** thorst_ has quit IRC | 02:15 | |
*** iceyao has joined #openstack-ansible | 02:28 | |
*** schwicht has joined #openstack-ansible | 02:31 | |
*** smatzek has quit IRC | 02:34 | |
*** schwicht has quit IRC | 02:35 | |
*** thorst_ has joined #openstack-ansible | 02:40 | |
*** jthorne_ has quit IRC | 02:44 | |
*** woodard has joined #openstack-ansible | 02:53 | |
prometheanfire | cloudnull: iirc, recheck works with comments, gate is just slow today | 02:57 |
palendae | yeah, real slow | 02:57 |
*** thorst_ has quit IRC | 02:58 | |
palendae | https://review.openstack.org/#/c/318917/ just finished for example | 02:58 |
*** woodard has quit IRC | 02:58 | |
palendae | ~5 hours | 02:58 |
prometheanfire | ya, https://review.openstack.org/320670 did too | 02:58 |
*** thorst_ has joined #openstack-ansible | 02:58 | |
*** thorst_ has quit IRC | 03:07 | |
prometheanfire | cloudnull: same error :| | 03:13 |
prometheanfire | palendae: if you have a sec... http://logs.openstack.org/24/320624/2/check/gate-openstack-ansible-os_nova-ansible-func-ubuntu-trusty/09493c2/console.html | 03:13 |
*** BjoernT has quit IRC | 03:14 | |
*** sdake has joined #openstack-ansible | 03:15 | |
cloudnull | prometheanfire: it would seem zuul-cloner is busted right now. | 03:15 |
cloudnull | folks in infra seem to be aware of it | 03:16 |
prometheanfire | ah, cool | 03:17 |
prometheanfire | I'll recheck before I go to bed then | 03:17 |
*** sdake has quit IRC | 03:27 | |
*** schwicht has joined #openstack-ansible | 03:43 | |
*** sdake has joined #openstack-ansible | 03:44 | |
*** schwicht has quit IRC | 03:47 | |
*** thorst_ has joined #openstack-ansible | 04:04 | |
*** thorst_ has quit IRC | 04:12 | |
*** sacharya has quit IRC | 04:16 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_keystone: Implement CentOS 7 support in os_keystone https://review.openstack.org/320216 | 04:17 |
*** sguduru has joined #openstack-ansible | 04:17 | |
*** sguduru has quit IRC | 04:28 | |
*** javeriak has joined #openstack-ansible | 04:37 | |
*** jamielennox is now known as jamielennox|away | 04:50 | |
*** jamielennox|away is now known as jamielennox | 05:04 | |
*** javeriak has quit IRC | 05:05 | |
*** sdake_ has joined #openstack-ansible | 05:11 | |
*** sdake has quit IRC | 05:13 | |
*** admin0 has joined #openstack-ansible | 05:17 | |
*** sacharya has joined #openstack-ansible | 05:17 | |
*** sguduru has joined #openstack-ansible | 05:18 | |
*** admin0 has quit IRC | 05:19 | |
*** chhavi has joined #openstack-ansible | 05:21 | |
*** sacharya has quit IRC | 05:22 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_keystone: Implement CentOS 7 support in os_keystone https://review.openstack.org/320216 | 05:26 |
prometheanfire | cloudnull: still failing | 05:27 |
prometheanfire | cloudnull: will recheck in the morning, nn | 05:27 |
prometheanfire | oh, you rechecked already | 05:28 |
*** schwicht has joined #openstack-ansible | 05:44 | |
*** deadnull has quit IRC | 05:48 | |
*** thorst_ has joined #openstack-ansible | 05:49 | |
*** schwicht has quit IRC | 05:50 | |
*** admin0 has joined #openstack-ansible | 05:50 | |
*** admin0 has quit IRC | 05:51 | |
*** jamielennox is now known as jamielennox|away | 05:54 | |
*** thorst_ has quit IRC | 05:57 | |
*** chhavi has quit IRC | 05:57 | |
*** ig0r_ has joined #openstack-ansible | 06:01 | |
*** deadnull has joined #openstack-ansible | 06:02 | |
*** sguduru has quit IRC | 06:04 | |
openstackgerrit | Merged openstack/openstack-ansible-os_swift: Add staticweb to the default middleware list https://review.openstack.org/320614 | 06:07 |
*** jamielennox|away is now known as jamielennox | 06:10 | |
*** chhavi has joined #openstack-ansible | 06:13 | |
*** jiteka has joined #openstack-ansible | 06:13 | |
*** joker_ has joined #openstack-ansible | 06:15 | |
*** jiteka has left #openstack-ansible | 06:15 | |
*** sguduru has joined #openstack-ansible | 06:16 | |
*** ig0r_ has quit IRC | 06:17 | |
*** sacharya has joined #openstack-ansible | 06:18 | |
*** jamielennox is now known as jamielennox|away | 06:21 | |
*** sacharya has quit IRC | 06:23 | |
*** jamielennox|away is now known as jamielennox | 06:28 | |
*** schwicht has joined #openstack-ansible | 06:47 | |
*** schwicht has quit IRC | 06:52 | |
*** oneswig has joined #openstack-ansible | 06:55 | |
*** asettle has joined #openstack-ansible | 06:59 | |
*** thorst_ has joined #openstack-ansible | 07:00 | |
*** admin0 has joined #openstack-ansible | 07:03 | |
*** sguduru has quit IRC | 07:07 | |
*** thorst_ has quit IRC | 07:09 | |
*** mikelk has joined #openstack-ansible | 07:17 | |
*** jiteka has joined #openstack-ansible | 07:23 | |
*** iceyao has quit IRC | 07:25 | |
*** iceyao has joined #openstack-ansible | 07:25 | |
evrardjp | good morning everyone | 07:34 |
*** daneyon has quit IRC | 07:50 | |
odyssey4me | o/ | 07:52 |
*** metral is now known as metral_zzz | 07:54 | |
*** sdake_ has quit IRC | 07:56 | |
*** asettle has quit IRC | 08:01 | |
*** oneswig has quit IRC | 08:03 | |
*** thorst_ has joined #openstack-ansible | 08:06 | |
*** thorst_ has quit IRC | 08:14 | |
*** jiteka has quit IRC | 08:19 | |
openstackgerrit | Merged openstack/openstack-ansible-security: Fix null password auth in CentOS https://review.openstack.org/318888 | 08:20 |
*** ig0r_ has joined #openstack-ansible | 08:20 | |
*** asettle has joined #openstack-ansible | 08:22 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_zaqar: Updating os_zaqar to use the Multi-Distro framework https://review.openstack.org/316332 | 08:28 |
*** _hanhart has quit IRC | 08:32 | |
*** brad[] has quit IRC | 08:36 | |
*** brad[] has joined #openstack-ansible | 08:37 | |
*** metral_zzz is now known as metral | 08:38 | |
*** sguduru has joined #openstack-ansible | 08:43 | |
*** sdake has joined #openstack-ansible | 08:43 | |
*** saneax_AFK is now known as saneax | 08:44 | |
*** schwicht has joined #openstack-ansible | 08:47 | |
*** sdake has quit IRC | 08:49 | |
*** sdake has joined #openstack-ansible | 08:51 | |
*** schwicht has quit IRC | 08:52 | |
*** daneyon has joined #openstack-ansible | 08:52 | |
*** daneyon has quit IRC | 08:55 | |
*** daneyon has joined #openstack-ansible | 08:56 | |
pjm6 | good morning | 08:56 |
*** asettle has quit IRC | 08:58 | |
*** markvoelker has joined #openstack-ansible | 09:03 | |
*** sdake has quit IRC | 09:05 | |
*** javeriak has joined #openstack-ansible | 09:06 | |
*** markvoelker has quit IRC | 09:08 | |
*** thorst_ has joined #openstack-ansible | 09:11 | |
*** thorst_ has quit IRC | 09:19 | |
*** javeriak has quit IRC | 09:22 | |
*** javeriak has joined #openstack-ansible | 09:31 | |
*** asettle has joined #openstack-ansible | 09:42 | |
*** asettle has quit IRC | 09:42 | |
*** tlbr has quit IRC | 09:49 | |
*** tlbr has joined #openstack-ansible | 09:52 | |
*** mummer has joined #openstack-ansible | 10:01 | |
*** markvoelker has joined #openstack-ansible | 10:04 | |
*** markvoelker has quit IRC | 10:09 | |
openstackgerrit | Merged openstack/openstack-ansible: Verbose option has been deprecated from oslo.log https://review.openstack.org/317580 | 10:12 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Update HAProxy for multi-OS support https://review.openstack.org/320160 | 10:15 |
cloudnull | morning | 10:15 |
*** al_loew has joined #openstack-ansible | 10:16 | |
*** thorst_ has joined #openstack-ansible | 10:17 | |
*** sacharya has joined #openstack-ansible | 10:19 | |
*** thorst_ has quit IRC | 10:24 | |
*** sacharya has quit IRC | 10:24 | |
odyssey4me | cloudnull you're up early... | 10:25 |
cloudnull | I am | 10:27 |
cloudnull | one of those days. | 10:27 |
cloudnull | also day before time away | 10:27 |
cloudnull | so taking care of things before im off | 10:27 |
mattt | cloudnull: headed anywhere nice ? | 10:28 |
cloudnull | back to sf | 10:29 |
mattt | nice! enjoy :) | 10:29 |
cloudnull | family reunion | 10:29 |
cloudnull | should be a good time. | 10:29 |
cloudnull | then back for a week then off to south america to visit wifes family | 10:29 |
cloudnull | which should be a better time :) | 10:30 |
*** Qiming has quit IRC | 10:30 | |
odyssey4me | oh nice - that'll be a nice break | 10:30 |
odyssey4me | not sure about family being much fun, but at least it'll keep you from computering :p | 10:30 |
*** smatzek has joined #openstack-ansible | 10:33 | |
evrardjp | good morning cloudnull | 10:35 |
*** electrofelix has joined #openstack-ansible | 10:35 | |
cloudnull | odyssey4me: I'll be ! computeing for sure. | 10:35 |
*** fxpester has quit IRC | 10:35 | |
openstackgerrit | Merged openstack/openstack-ansible-pip_install: Removing unnecessary usage of with_items https://review.openstack.org/320521 | 10:41 |
*** javeriak has quit IRC | 10:43 | |
*** schwicht has joined #openstack-ansible | 10:49 | |
mancdaz | what does the ansible trim filter do? | 10:49 |
*** arbrandes has quit IRC | 10:50 | |
mattt | mancdaz: is that different to the jinja2 filter? | 10:51 |
mancdaz | mattt sorry, I guess I mean the jinja2 filter | 10:51 |
*** arbrandes has joined #openstack-ansible | 10:52 | |
mancdaz | mattt and you helped me find the docs | 10:52 |
mancdaz | thanks! | 10:52 |
mattt | mancdaz: "Strip leading and trailing whitespace." | 10:52 |
*** schwicht has quit IRC | 10:53 | |
*** javeriak has joined #openstack-ansible | 10:54 | |
*** al_loew has quit IRC | 10:57 | |
*** fxpester has joined #openstack-ansible | 10:58 | |
*** _deadnull is now known as deadnull_ | 11:01 | |
mancdaz | odyssey4me how does this work https://github.com/openstack/openstack-ansible-os_horizon/blob/master/defaults/main.yml#L39 | 11:01 |
*** deadnull_ is now known as _deadnull | 11:01 | |
*** _deadnull is now known as deadnull_ | 11:01 | |
mancdaz | as in, what is hosting the venvs on localhost? | 11:02 |
evrardjp | mancdaz: we define the variable elsewhere | 11:03 |
evrardjp | in the playbook IIRC | 11:03 |
evrardjp | openstack-ansible/playbooks/os-horizon-install.yml | 11:04 |
evrardjp | horizon_venv_download_url: "{{ openstack_repo_url }}/venvs/{{ openstack_release }}/{{ ansible_distribution | lower }}/horizon-{{ openstack_release }}.tgz" | 11:04 |
odyssey4me | mancdaz https://github.com/openstack/openstack-ansible/blob/master/playbooks/os-horizon-install.yml#L110 | 11:04 |
evrardjp | it overrides the default | 11:04 |
mancdaz | evrardjp doh, thanks. I missed that | 11:04 |
*** markvoelker has joined #openstack-ansible | 11:05 | |
odyssey4me | mancdaz so in the case where the venv is enabled but the URL is not overridden by the play, the process will fail to download the venv and therefore fall back to installing the packages | 11:05 |
mancdaz | odyssey4me yep, gotcha thanks | 11:06 |
*** markvoelker has quit IRC | 11:10 | |
*** jiteka has joined #openstack-ansible | 11:11 | |
*** vnogin has joined #openstack-ansible | 11:14 | |
*** schwicht has joined #openstack-ansible | 11:16 | |
*** openstackgerrit has quit IRC | 11:18 | |
*** openstackgerrit has joined #openstack-ansible | 11:18 | |
*** Qiming has joined #openstack-ansible | 11:21 | |
*** thorst_ has joined #openstack-ansible | 11:22 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Update HAProxy for multi-OS support https://review.openstack.org/320160 | 11:24 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-pip_install: Enable CentOS support https://review.openstack.org/320913 | 11:27 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-pip_install: Enable CentOS support https://review.openstack.org/320913 | 11:27 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-pip_install: Enable CentOS support https://review.openstack.org/320913 | 11:28 |
*** chhavi has quit IRC | 11:29 | |
*** thorst_ has quit IRC | 11:29 | |
*** johnmilton has joined #openstack-ansible | 11:29 | |
*** retreved has joined #openstack-ansible | 11:33 | |
*** schwicht has quit IRC | 11:39 | |
*** iceyao has quit IRC | 11:40 | |
*** chhavi has joined #openstack-ansible | 11:42 | |
*** thorst_ has joined #openstack-ansible | 11:49 | |
*** thorst_ has quit IRC | 11:50 | |
*** thorst_ has joined #openstack-ansible | 11:51 | |
*** wadeholler has joined #openstack-ansible | 11:56 | |
wadeholler | hi all: I have a ceph target configured for nova, cinder, and glance; If I want to add a new compute node without ceph for nova, i.e. just regular local storage, where / how do I set that override ? | 11:58 |
*** jamielennox is now known as jamielennox|away | 11:58 | |
*** chhavi has quit IRC | 12:00 | |
*** psilvad has joined #openstack-ansible | 12:00 | |
openstackgerrit | Kyle L. Henderson proposed openstack/openstack-ansible-os_nova: Detect PowerNV environment https://review.openstack.org/319480 | 12:00 |
odyssey4me | wadeholler hmm, right now you'll have to move the overrides from user_variables to host-specific overrides in openstack_user_config I think... | 12:00 |
odyssey4me | wadeholler we don't have a neat way, right now, to do group-based overrides... but that would be more ideal | 12:00 |
wadeholler | odyssey4me: ok and thank you! | 12:04 |
vnogin | hi guys, does some one tested upgrade from stable/mitaka to newton? is it work? | 12:04 |
*** jamielennox|away is now known as jamielennox | 12:07 | |
*** markvoelker has joined #openstack-ansible | 12:10 | |
*** mummer has quit IRC | 12:12 | |
*** kylek3h has quit IRC | 12:12 | |
*** chhavi has joined #openstack-ansible | 12:13 | |
*** javeriak has quit IRC | 12:13 | |
odyssey4me | vnogin not much testing has been done yet, no - newtons nowhere close to release - however it is possible to test if you want to, we just merged a patch for the basic framework: http://docs.openstack.org/developer/openstack-ansible/upgrade-guide/index.html | 12:18 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Update HAProxy for multi-OS support https://review.openstack.org/320160 | 12:20 |
*** sguduru has quit IRC | 12:21 | |
*** sacharya has joined #openstack-ansible | 12:21 | |
*** gparaskevas has joined #openstack-ansible | 12:22 | |
evrardjp | nice hatop addition :D | 12:22 |
evrardjp | you still not won me over :p | 12:23 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible: Expose upgrade guide in base index https://review.openstack.org/320944 | 12:23 |
*** klamath has quit IRC | 12:24 | |
*** sacharya has quit IRC | 12:25 | |
*** klamath has joined #openstack-ansible | 12:25 | |
prometheanfire | evrardjp: I'll likely go with just forcing a link to be created, iirc it will remove what's there if needed | 12:36 |
odyssey4me | prometheanfire I still think that you should move the existing folder if it's not a link. There's no telling whether there is data in there or not. | 12:38 |
*** kylek3h has joined #openstack-ansible | 12:39 | |
prometheanfire | odyssey4me: if there's stuff there then that means it's in active use, so we shouldn't move it | 12:40 |
odyssey4me | prometheanfire so instead we delete it? that doesn't sound safe at all | 12:40 |
prometheanfire | odyssey4me: nova doesn't use it, but creates it anyway | 12:41 |
prometheanfire | qemu devs couldn't figure out why | 12:41 |
prometheanfire | I think it's a hacky way to not have to freeze the vm for backup | 12:42 |
odyssey4me | as I recall from the recent operators thread on the topic, his is something used by the older versions of qemu - but I only skim-read it | 12:42 |
*** markvoelker has quit IRC | 12:42 | |
mhayden | morning | 12:42 |
evrardjp | we should use stat | 12:43 |
odyssey4me | isn't it only supposed to be the memory save anyway? | 12:43 |
evrardjp | stat can help you say if it's a folder, if it has content, etc. | 12:43 |
prometheanfire | mhayden: welcome, you at castle aready? | 12:43 |
evrardjp | content -> stop, empty folder -> do stuff | 12:43 |
vnogin | odyssey4me: actually doing it right now :) tnx | 12:43 |
evrardjp | morning mhayden | 12:43 |
prometheanfire | odyssey4me: ya, it's used by older | 12:43 |
prometheanfire | odyssey4me: problem is the workaround causes a freeze, which we don't want either | 12:44 |
prometheanfire | iirc | 12:44 |
prometheanfire | odyssey4me: it's a diff of the memory state I think | 12:44 |
prometheanfire | so acively changing memory | 12:44 |
prometheanfire | my 8G VM only took up 107M when saving | 12:44 |
*** asettle has joined #openstack-ansible | 12:47 | |
odyssey4me | prometheanfire and once a snapshot or migration is complete, are the files removed from there? | 12:47 |
prometheanfire | yes | 12:48 |
*** markvoelker has joined #openstack-ansible | 12:48 | |
odyssey4me | prometheanfire in that case I would prefer something like evrardjp's idea - check that the folder is not a link, check that it's empty, and link it if both conditions are true | 12:49 |
prometheanfire | worksforme | 12:49 |
prometheanfire | that sounds like it'll be some integrated bash | 12:49 |
prometheanfire | odyssey4me: that alright? | 12:50 |
odyssey4me | prometheanfire no need for any bash - use the stat module as evrardjp suggested | 12:50 |
prometheanfire | ah | 12:51 |
prometheanfire | thought he was talking about system 'stat' | 12:51 |
evrardjp | it's the same, but as a module | 12:52 |
*** asettle has quit IRC | 12:52 | |
evrardjp | :p | 12:52 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: [WIP] Improve gate testing for security role https://review.openstack.org/320649 | 12:53 |
prometheanfire | evrardjp: yarp, I'll integrate the changes before lunch local time | 12:54 |
*** asettle has joined #openstack-ansible | 12:54 | |
mhayden | evrardjp / mattt: would y'all like to see AppArmor and SELinux enabled in the role? https://review.openstack.org/#/c/320649/ | 12:56 |
mhayden | i can do that, but i avoided it since it felt like a big change | 12:56 |
*** psilvad has quit IRC | 12:56 | |
mhayden | to be fair though, our production deployments would have apparmor enabled already | 12:56 |
prometheanfire | ya, thought apparmor was done already | 12:57 |
*** javeriak has joined #openstack-ansible | 12:57 | |
mhayden | we could certainly flip those tasks to ensure it's running | 12:58 |
evrardjp | so let me resume what I think: if centos/redhat behavior is far from ubuntu/debian behavior, then it's worth making 2 roles. Simply as that | 12:58 |
*** iceyao has joined #openstack-ansible | 12:58 | |
evrardjp | if it's just a few tasks, then making them conditional on the os is fine for me | 12:59 |
mattt | mhayden: it just looks super weird having all that gating stuff jammed into the role, code smell if you ask me | 12:59 |
evrardjp | but in all the cases, we should have a test coverage as big as possible | 12:59 |
evrardjp | I agree with mattt | 12:59 |
*** javeriak has quit IRC | 12:59 | |
mhayden | mattt: my code has that old car smell | 12:59 |
mattt | mhayden: can you not update the tox.ini to skip stuff depending on distro? | 12:59 |
mhayden | it's possible | 12:59 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Update HAProxy for multi-OS support https://review.openstack.org/320160 | 13:00 |
evrardjp | you could have a variable file that is gating_centos gating_ubuntu, and includes the tests to skip | 13:00 |
mattt | mhayden: i think all that sort of stuff should be dealt w/ in tox.ini or in the tests themselves | 13:00 |
mhayden | but i'm wondering if i should make the tasks a little more assertive so that they're available for more generic deployments | 13:00 |
evrardjp | and you include the vars | 13:00 |
prometheanfire | cloudnull: one thing at a time | 13:01 |
prometheanfire | cloudnull: how many roles are multi-os now? | 13:01 |
cloudnull | what? | 13:01 |
prometheanfire | cloudnull: you keep working at the multios stuff, was just commenting on it | 13:01 |
evrardjp | prometheanfire: there is a etherpad for following this | 13:02 |
odyssey4me | mhayden designing the role tasks based on gating is a very bad idea, I agree with mattt there - the primary goal is to make it work for production environments, and the gate must test as well as possible with the resources available | 13:02 |
mhayden | odyssey4me: then i think my best bet is to follow the STIG a bit more closely and enable, rather than check, these things | 13:02 |
prometheanfire | ah | 13:02 |
cloudnull | prometheanfire: what "one thing at a time"? | 13:02 |
prometheanfire | one role at a time | 13:03 |
evrardjp | prometheanfire: parallel mode ! | 13:03 |
odyssey4me | prometheanfire I think that most of the 'infrastructure' roles are done - we're moving on to doing the openstack service roles now | 13:03 |
evrardjp | decreases resistance | 13:03 |
odyssey4me | prometheanfire see https://etherpad.openstack.org/p/openstack-ansible-newton-ubuntu16-04 | 13:03 |
evrardjp | or not really but whatever | 13:03 |
*** javeriak has joined #openstack-ansible | 13:05 | |
*** mikelk has quit IRC | 13:05 | |
*** mikelk has joined #openstack-ansible | 13:06 | |
*** ig0r__ has joined #openstack-ansible | 13:06 | |
odyssey4me | mattt this is weird - do you have any ideas why the mitaka (only) branch would fail 'pip install tempest' http://logs.openstack.org/25/318925/2/check/gate-openstack-ansible-dsvm-commit/d5d0718/console.html#_2016-05-25_11_54_04_650 ? | 13:06 |
mattt | odyssey4me: just updated that review :) | 13:06 |
odyssey4me | ah ok, silly me | 13:07 |
mattt | odyssey4me: literally the moment you said that | 13:07 |
prometheanfire | now, how to check if a dir is empty... | 13:07 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Update HAProxy for multi-OS support https://review.openstack.org/320160 | 13:07 |
mattt | odyssey4me: this actually raises a concern, because i removed that --isolated junk from os_tempest master | 13:07 |
odyssey4me | hmm, we can't bump requirements - maybe we should do what we did in master and just remove them? | 13:07 |
cloudnull | sorry for the spam , that should make all the distro happy now. | 13:07 |
*** psilvad has joined #openstack-ansible | 13:08 | |
mattt | odyssey4me: or maybe we lock on a tempest version in a release and don't bump it unless we have a known reason to | 13:08 |
*** ig0r_ has quit IRC | 13:08 | |
odyssey4me | mattt hmm, so you're basically suggesting that we never update openstack_other.yml once a branch goes stable | 13:10 |
prometheanfire | https://github.com/ansible/ansible-modules-core/issues/902 | 13:10 |
prometheanfire | well, that's reassuring | 13:10 |
*** schwicht has joined #openstack-ansible | 13:10 | |
mattt | odyssey4me: well, tempest_git_install_branch specifically | 13:10 |
mattt | odyssey4me: i mean you can try, but if tempest requirements have moved beyond what our branch supports then we have to keep it locked on a working SHA | 13:10 |
odyssey4me | mattt sure, but our branch requirements are only there for ansible itself | 13:11 |
mattt | odyssey4me: i more mean the openstack requirements we use for that branch, not local requirements.txt | 13:11 |
odyssey4me | I would rather pin or remove the requirements than stop updating the tempest sha personally | 13:12 |
odyssey4me | mattt yeah, but the whole reason the right paramiko version isn't available is due to the requirements.txt | 13:12 |
*** deadnull_ is now known as _deadnull | 13:12 | |
*** psilvad has quit IRC | 13:13 | |
mattt | odyssey4me: not exactly, https://github.com/openstack/requirements/blob/stable/mitaka/upper-constraints.txt#L235 and https://github.com/openstack/tempest/blob/master/requirements.txt#L8 | 13:13 |
odyssey4me | oh bother | 13:14 |
odyssey4me | how the heck is upstream passing tests then? | 13:14 |
odyssey4me | lemme check in with the stable team | 13:14 |
odyssey4me | thanks! | 13:14 |
prometheanfire | odyssey4me: looks like I will need bash to check if a dir is empty | 13:15 |
odyssey4me | prometheanfire sure | 13:16 |
prometheanfire | [ "$(ls -A {{ path_goes_here }})" ] | 13:16 |
prometheanfire | that will exit 1 when fail, causing ansible to fail, so that'll work | 13:17 |
mattt | odyssey4me: let me know what they say ? | 13:17 |
*** thorst_ has quit IRC | 13:18 | |
odyssey4me | mattt yeah, will do - for now I've reduced the tempest SHA to the last one that still has the older requirements | 13:21 |
*** javeriak has quit IRC | 13:22 | |
*** javeriak has joined #openstack-ansible | 13:22 | |
mattt | odyssey4me: excellent, thanks! | 13:22 |
*** thorst_ has joined #openstack-ansible | 13:25 | |
openstackgerrit | Matthew Thode proposed openstack/openstack-ansible-os_nova: Create symlink for libvirt save directory https://review.openstack.org/320624 | 13:31 |
prometheanfire | odyssey4me: evrardjp ^ | 13:31 |
evrardjp | prometheanfire: why not using stat.size ? | 13:32 |
prometheanfire | evrardjp: .size doesn't work for dirs | 13:33 |
*** asettle has quit IRC | 13:33 | |
prometheanfire | mkdir foo, stat foo, size is 4096 for me because that's my block size | 13:34 |
prometheanfire | zfs is diferent though, it's size is 2 | 13:35 |
prometheanfire | so it varries | 13:35 |
*** al_loew has joined #openstack-ansible | 13:35 | |
*** al_loew has quit IRC | 13:35 | |
evrardjp | didn't know | 13:35 |
evrardjp | nlink | 13:35 |
evrardjp | ? | 13:35 |
evrardjp | not gonna work either | 13:36 |
*** smatzek has quit IRC | 13:37 | |
prometheanfire | don't think so | 13:37 |
*** al_loew has joined #openstack-ansible | 13:37 | |
prometheanfire | it's diferent across file systems as well | 13:37 |
prometheanfire | ext4 empty is 2, zfs is 1 | 13:37 |
*** javeriak has quit IRC | 13:37 | |
evrardjp | we need to fix that in upstream ansible :D | 13:38 |
prometheanfire | evrardjp: the request for isempty has been around forever :P | 13:38 |
prometheanfire | https://github.com/ansible/ansible-modules-core/issues/902 | 13:38 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Enable LSM instead of checking status https://review.openstack.org/320993 | 13:38 |
prometheanfire | I was using the OS's stat btw | 13:38 |
evrardjp | the other way would be to do a simple find pattern=* register the content | 13:39 |
evrardjp | if you have content.matched | int > 0 you have content | 13:40 |
prometheanfire | I think this way is cleaner | 13:40 |
prometheanfire | but now we are getting into opinion | 13:40 |
odyssey4me | mattt devstack installs tempest into a venv - I guess we'll have to go back to using --isolated for mitaka for the tempest venv | 13:41 |
odyssey4me | mattt ideally we should use --isolated, but also feed it the infra pypi mirror and infra wheel mirror :/ | 13:41 |
evrardjp | prometheanfire: the remove when isdir is already fine, because you have idempotency on the remove | 13:42 |
odyssey4me | mattt unless there's a way of making the tempest install ignore the user config file and only use the global pip.conf in /etc/ | 13:42 |
evrardjp | but we added a shell task without idempotency, which is not great | 13:42 |
*** BjoernT has joined #openstack-ansible | 13:42 | |
*** BjoernT is now known as Bjoern_zZzZzZzZ | 13:42 | |
prometheanfire | evrardjp: true, but the shell task is just listing a dir and returning true/false | 13:43 |
evrardjp | that's why I think it's fine | 13:43 |
prometheanfire | not actually changing state | 13:43 |
prometheanfire | ya | 13:43 |
evrardjp | it's not great but it's fine | 13:43 |
prometheanfire | evrardjp: I remove on isdir because we don't want to remove the symlink every run just to replace it again | 13:44 |
prometheanfire | ya, agreed on not great | 13:44 |
evrardjp | prometheanfire: yes I know for the isdir :) | 13:44 |
evrardjp | I can read :) | 13:44 |
mattt | odyssey4me: so my change that removes --isolated wasn't backported | 13:44 |
mattt | odyssey4me: which leads me to believe that because tempest venv exists, it's building on the repo server | 13:45 |
prometheanfire | thought you wanted me to remove it | 13:45 |
* prometheanfire hasn't had much sleep | 13:45 | |
mattt | odyssey4me: is there any harm in locking tempest SHA? | 13:45 |
*** cloader89 has joined #openstack-ansible | 13:45 | |
odyssey4me | mattt the harm is that our tests don't match the upstream tests, which we have put a lot of effort into avoiding thus far | 13:46 |
*** tlbr has quit IRC | 13:47 | |
*** tlbr has joined #openstack-ansible | 13:49 | |
*** phalmos has quit IRC | 13:49 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Automatically enable neutron ha router capabilities https://review.openstack.org/313042 | 13:50 |
automagically_ | Morning all | 13:51 |
cloudnull | morning | 13:51 |
*** ametts has joined #openstack-ansible | 13:51 | |
*** asettle has joined #openstack-ansible | 13:53 | |
Adri2000 | so I have a bad issue which is not OSA's fault :( when deploying tempest, the playbook creates cirros images in glance, that uses the glance API v1 and the --copy-from feature. it seems that copy-from feature doesn't know how to use a proxy, so if your glance container needs a proxy to fetch the image, it will fail. ... I was told in #openstack-glance that such a bug won't be fixed because glan | 13:54 |
Adri2000 | ce api v1 is deprecated / somewhat frozen, and I learnt that glance api v2 doesn't have a --copy-from feature anyway | 13:54 |
*** xek has quit IRC | 13:54 | |
cloudnull | so whats the temp on this ever being accepted https://review.openstack.org/#/c/304840 -- asking because I want push on the Ansible 2.1 work and if we dont think we'll ever move on the isolated ansible (at least not in that way) then I need to pivot my 2.1 work | 13:55 |
mattt | odyssey4me: that throws a ratchet in my master commit :) | 13:55 |
cloudnull | Adri2000: you can skin that cat manually for now using something like so: https://github.com/os-cloud/osic-ref-impl/blob/master/post-deployment-setup.sh#L46-L54 | 13:56 |
cloudnull | just download the Cirros image and add it into glance | 13:57 |
Adri2000 | cloudnull: yep I was going to try this, as a workaround. but any idea how to fix that properly long term? | 13:58 |
Adri2000 | I'm surprised that such a feature doesn't exist anymore in glance v2 | 13:59 |
odyssey4me | cloudnull I'm not a fan of increasing the scope of the openstack-ansible command line, nor do I think that we need to be facilitating multiple venvs on anyone's behalf. It'd be useful to have ansible in a venv purely to isolate its requirements from the other requirements on the host. I would rather have it implement the venv, then optionally do a forced symlink for the CLI commands to the venv versions... then if | 13:59 |
odyssey4me | someone wants to switch versions they can simply change the version via the env var and re-bootstrap | 13:59 |
odyssey4me | Adri2000 we'll need to adjust our tempest plays to make it use v2, and probably some other places | 13:59 |
*** jthorne has joined #openstack-ansible | 14:00 | |
cloudnull | Adri2000: something like http://cdn.pasteraw.com/jqd87wx1u70b402ex62tt1f0lbw1ikp should work | 14:00 |
*** Bjoern_zZzZzZzZ is now known as BjoernT | 14:00 | |
cloudnull | which will short circut the module | 14:00 |
cloudnull | as for the long term | 14:00 |
cloudnull | I think we're going to need to adjust the module | 14:01 |
cloudnull | or use a shell command | 14:01 |
cloudnull | which isn't an awesome solution | 14:01 |
odyssey4me | cloudnull once we've flipped to ansible 2 there should be a module to do it for us | 14:01 |
Adri2000 | it seems this is the new module in ansible 2: https://docs.ansible.com/ansible/os_image_module.html | 14:02 |
cloudnull | odyssey4me: thats in shade and its still using v1 at last check | 14:02 |
Adri2000 | I don't see anything about passing an url instead of a file | 14:02 |
cloudnull | looks like its fully removed the image fetch | 14:03 |
cloudnull | it was here https://docs.ansible.com/ansible/glance_image_module.html | 14:04 |
cloudnull | but not in the updated one | 14:04 |
*** _deadnull is now known as deadnull_ | 14:04 | |
*** smatzek has joined #openstack-ansible | 14:05 | |
pjm6 | hey | 14:06 |
pjm6 | anyone here knows why | 14:07 |
pjm6 | https://github.com/openstack/openstack-ansible-os_neutron/blob/b4537e2618adaee4e6fe7d2087e15182c779482f/defaults/main.yml#L331 | 14:07 |
pjm6 | neutron_external_bridge are empty? | 14:07 |
cloudnull | odyssey4me: so your suggesting to create a venv and then link "ansible ansible-doc ansible-galaxy ansible-playbook ansible-pull ansible-vault" back into /usr/loca/bin ? | 14:08 |
pjm6 | if i understood well, if we don't put empty, by default he will be using br-ex (from OVS) | 14:08 |
pjm6 | but for VPNaaS working i think we need to give a interface | 14:08 |
pjm6 | because I got "no public interface found" | 14:08 |
prometheanfire | cloudnull: jenkins still broken? https://review.openstack.org/320624 | 14:08 |
odyssey4me | cloudnull yeah, but optionally - just make it true by default | 14:09 |
prometheanfire | ansible 2.1.0.0 is out | 14:10 |
odyssey4me | w00t https://pypi.python.org/pypi/ansible/2.1.0.0 | 14:11 |
prometheanfire | got the alert/task on upstream's tag | 14:11 |
cloudnull | odyssey4me / prometheanfire: thats why im asking about the rest of the isolation work | 14:12 |
odyssey4me | ah | 14:12 |
odyssey4me | for now cloudnull I'd suggest that we simply revision the master branch for each role's test-requirements to ensure that each role works as it stands, once those are all merged then we rev the integrated repo | 14:13 |
odyssey4me | the patch to isolate ansible into a venv can come later | 14:13 |
cloudnull | right now 2.1 works for the most part https://review.openstack.org/#/c/317224/ -- looks like there's a bad loop in cinder right now which 2.1 is unhappy about | 14:14 |
cloudnull | but we're on the right track | 14:15 |
cloudnull | so I'll pivot that PR and abandon the other. | 14:15 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Enable LSM instead of checking status https://review.openstack.org/320993 | 14:19 |
mattt | odyssey4me: wait, so we actually removed --isolated in os_tempest? i thought i inadvertently did this but it looks like this already happened | 14:21 |
*** sacharya has joined #openstack-ansible | 14:21 | |
odyssey4me | mattt yeah, I did it some time ago because all the requirements at the time were fulfilled by the repo | 14:21 |
odyssey4me | it seems that was not a long term guarantee | 14:22 |
mattt | odyssey4me: ok, that makes me feel slightly less bad :) | 14:22 |
mattt | odyssey4me: well, we can slip that flag back in if we need to i guess | 14:22 |
pjm6 | cloudnull, neutron is your speciality, right? :D | 14:24 |
* cloudnull leaves | 14:24 | |
pjm6 | loool | 14:25 |
prometheanfire | pjm6: nah, that's Apsu | 14:25 |
pjm6 | prometheanfire, thanks | 14:25 |
pjm6 | anyone here had used vpnaas with linux bridge? xD | 14:26 |
*** al_loew has quit IRC | 14:26 | |
*** sacharya has quit IRC | 14:26 | |
*** woodard has joined #openstack-ansible | 14:27 | |
*** javeriak has joined #openstack-ansible | 14:27 | |
*** woodard has quit IRC | 14:27 | |
*** woodard has joined #openstack-ansible | 14:28 | |
*** brad[] has quit IRC | 14:30 | |
openstackgerrit | Merged openstack/openstack-ansible-os_nova: Removed the db create tasks https://review.openstack.org/314850 | 14:33 |
*** Mudpuppy has joined #openstack-ansible | 14:33 | |
*** phalmos has joined #openstack-ansible | 14:35 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Search for unlabeled device files https://review.openstack.org/319448 | 14:36 |
wadeholler | is it possible to undefine / omit a var definition with a host override ? (example undefine nova_libvirt_images_rbd_pool for a specific host) sorry still an ansible n00b i guess | 14:41 |
*** iceyao has quit IRC | 14:41 | |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible: Migrate keystone v2 images to v3 during Liberty upgrade https://review.openstack.org/317070 | 14:42 |
*** Brew has joined #openstack-ansible | 14:45 | |
Apsu | pjm6: I have not poked at VPNaaS much yet professionally. What's up? | 14:47 |
prometheanfire | wadeholler: you are the second person to ask that | 14:47 |
pjm6 | Apsu, when i create the VPN Site-To-Site connnection | 14:47 |
pjm6 | the link is down | 14:47 |
pjm6 | and in the logs | 14:47 |
pjm6 | I get the following error | 14:47 |
pjm6 | "003 no public interface" | 14:48 |
pjm6 | i though that could be because the "external_network_bridge" was empty, but in the docs say it must be that way for making sure that we could have multiple networks | 14:48 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Enable LSM instead of checking status https://review.openstack.org/320993 | 14:50 |
pjm6 | Apsu, http://pastebin.com/fjBHt6qL | 14:50 |
pjm6 | its not much details :\ | 14:50 |
openstackgerrit | Merged openstack/openstack-ansible-security: Disable the rdisc service (if present) https://review.openstack.org/319442 | 14:51 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Isolate Ansible from the deployment host https://review.openstack.org/321036 | 14:51 |
*** galstrom_zzz is now known as galstrom | 14:53 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Update ansible to version 2.1 https://review.openstack.org/321042 | 14:53 |
*** jvalente has joined #openstack-ansible | 14:57 | |
odyssey4me | wadeholler I think you can just set it to '' ? | 14:57 |
prometheanfire | odyssey4me: but the variable still exists, just set to '' right? | 14:59 |
odyssey4me | prometheanfire not sure, haven't really looked too deep - whether it works for the purpose would depend on how the var is used | 15:01 |
prometheanfire | true | 15:02 |
*** gparaskevas has quit IRC | 15:02 | |
pjm6 | well when i do ipsec verify in the agents containers | 15:03 |
pjm6 | says me that | 15:03 |
pjm6 | "Linux OpenSwan (no kernel code presently loaded) | 15:04 |
pjm6 | Checking for ipsec support in kernel: failed | 15:04 |
pjm6 | maybe lxc container don't like openswan? | 15:04 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Enable LSM instead of checking status https://review.openstack.org/320993 | 15:06 |
Apsu | pjm6: Sounds like you need to load the ipsec modules | 15:06 |
pjm6 | yeah i'm trying to figure it out how to do it | 15:06 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Isolate Ansible from the deployment host https://review.openstack.org/321036 | 15:06 |
pjm6 | Apsu, and then try to search how can I test the pluto configs that are in the net namespace of the router | 15:07 |
*** sdake has joined #openstack-ansible | 15:09 | |
*** Qiming has quit IRC | 15:09 | |
*** eric_lopez has quit IRC | 15:12 | |
*** sdake_ has joined #openstack-ansible | 15:13 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Update ansible to version 2.1 https://review.openstack.org/321042 | 15:13 |
*** sdake has quit IRC | 15:13 | |
Apsu | pjm6: Seems like there's a fair number of potentially needed modules. Presumably they're all supposed to be load on demand | 15:13 |
pjm6 | Apsu, yeah, i tried to do | 15:14 |
pjm6 | ip netns exec qrouter-* ipsec verify | 15:14 |
pjm6 | and he fails, but probably i'm doing it wrong | 15:14 |
*** deadnull_ has quit IRC | 15:16 | |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible-os_nova: Cleanup Nova console proxy git repos before updating it https://review.openstack.org/320650 | 15:17 |
openstackgerrit | Travis Truman (automagically) proposed openstack/openstack-ansible: Ensure all role dependencies are consistently specified https://review.openstack.org/321063 | 15:18 |
pjm6 | Apsu, do you have OSA with VPNaaS installed? | 15:20 |
*** kstev has joined #openstack-ansible | 15:21 | |
Adri2000 | looks like the tempest role assumes the public network is called "public". and it doesn't seem to be configurable. am I right? | 15:23 |
*** berendt has quit IRC | 15:23 | |
automagically_ | Correct Adri2000 | 15:23 |
Adri2000 | automagically_: I though it'd be easy to make it a variable, but then I hit {{ neutron_networks.public.id }} | 15:25 |
Adri2000 | how do I transform that when "public" should be a var? | 15:25 |
Adri2000 | {{ neutron_networks.{{ tempest_public_net_name }}.id }} doesn't work of course :) | 15:26 |
automagically_ | I believe there is a concat filter | 15:26 |
*** admin0 has quit IRC | 15:26 | |
automagically_ | But that may not work either | 15:26 |
palendae | In Jinja, '~' is a string concatenation operator | 15:27 |
palendae | http://jinja.pocoo.org/docs/dev/templates/ | 15:27 |
mhayden | evrardjp: one step towards removing some things from tox.ini -> https://review.openstack.org/#/c/320993/ | 15:27 |
*** Mudpuppy_ has joined #openstack-ansible | 15:30 | |
*** Mudpuppy has quit IRC | 15:30 | |
*** Mudpuppy_ has quit IRC | 15:33 | |
*** Mudpuppy has joined #openstack-ansible | 15:33 | |
*** sdake_ has quit IRC | 15:34 | |
*** javeriak has quit IRC | 15:35 | |
*** weezS has joined #openstack-ansible | 15:35 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Isolate Ansible from the deployment host https://review.openstack.org/321036 | 15:40 |
*** mikelk has quit IRC | 15:41 | |
*** alikins has joined #openstack-ansible | 15:45 | |
automagically_ | cloudnull and any other cores - would appreciate a review on a simple consistency change https://review.openstack.org/#/q/topic:ansible_role_requirements_consistency <— That is related to some work I’m doing to perform an OSA bootstrap and repo build using all internal mirrors of git repository dependencies | 15:45 |
cloudnull | lookin | 15:46 |
automagically_ | thx | 15:46 |
*** cloader89 has quit IRC | 15:48 | |
cloudnull | automagically_: idk if i shared this with you before, if so sorry for the repeat, but this is something I've been using the gather the repos recursively -- https://gist.github.com/cloudnull/6e76897f27a2225821c7bc26535e261b | 15:49 |
*** SamYaple has quit IRC | 15:50 | |
*** sacharya has joined #openstack-ansible | 15:51 | |
automagically_ | cloudnull, you did and I ended up using a bit of it | 15:51 |
automagically_ | Appreciate that, it ended up being very useful | 15:51 |
* cloudnull has a bad memory | 15:51 | |
*** javeriak has joined #openstack-ansible | 15:52 | |
cloudnull | i think we need to do the same for all .*packages, | 15:52 |
automagically_ | When I’m done with the work I’m doing, I’ll likely push it to my personal Github account and drop a link to it in: http://docs.openstack.org/developer/openstack-ansible/install-guide/app-no-internet-connectivity.html for those who may face similar challenges | 15:52 |
cloudnull | cool | 15:52 |
automagically_ | atm, I am also mirroring the get-pip.py, the trusty container image, and the percona and rabbitmq debs | 15:53 |
openstackgerrit | Merged openstack/openstack-ansible-security: Docs: Update dev notes for Cat 1 controls https://review.openstack.org/319429 | 15:53 |
automagically_ | Finally, I’m adapting the way the repo play runs so I can host my mirror and the OSA repo on the same host and then distribute the whole thing across my infra | 15:53 |
cloudnull | anyone available to give this a nudge https://review.openstack.org/#/c/320175/ ? | 15:54 |
* automagically_ looking | 15:54 | |
cloudnull | automagically_: thats kinda awesome ! | 15:55 |
cloudnull | I'd like to see us make better use of the repo -infa | 15:55 |
cloudnull | i think it can do a lot more . | 15:55 |
automagically_ | Yeah, agreed. | 15:55 |
cloudnull | jmccrory: was looking into making it a legit git server instead of using the fcgi wrapper. | 15:56 |
automagically_ | I saw that. I’m just using the dumb http mode to serve the git repos, using `git update-server-info` | 15:56 |
*** Mudpuppy has quit IRC | 15:57 | |
automagically_ | But I may adapt, once I marry up how repo_server wants the world to looks with how my current git mirror works | 15:57 |
cloudnull | maybe we can adapt | 15:58 |
cloudnull | to make it easier for your current git mirror | 15:59 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible: Set AIO to use an OpenStack-Infra wheel mirror https://review.openstack.org/321091 | 15:59 |
automagically_ | I’m almost to the point where I’ll mash them together, so I’ll definitely propose a review or two if needed | 15:59 |
*** Mudpuppy has joined #openstack-ansible | 16:00 | |
logan- | sounds interesting. i think i've shared the plays i'm using to do apt/deb/gpg/pip mirroring but if that's of any value and you don't have them let me know | 16:02 |
automagically_ | logan-: I’d love to see those | 16:03 |
odyssey4me | automagically_ cloudnull if you could take a peek at https://review.openstack.org/321091 I'd appreciate it - it shaves around 5 mins of a non-gate AIO repo build | 16:05 |
logan- | sure, ill get a gist together | 16:05 |
automagically_ | odyssey4me: I just did | 16:05 |
automagically_ | Thanks logan- | 16:05 |
openstackgerrit | Merged openstack/openstack-ansible-os_keystone: Implement 16.04 support in Keystone https://review.openstack.org/320175 | 16:07 |
odyssey4me | automagically_ cloudnull another quick doc update too: https://review.openstack.org/320944 | 16:08 |
openstackgerrit | Merged openstack/openstack-ansible: Expose upgrade guide in base index https://review.openstack.org/320944 | 16:15 |
*** admin0 has joined #openstack-ansible | 16:16 | |
openstackgerrit | Merged openstack/openstack-ansible-rabbitmq_server: Upgrade RabbitMQ Server to 3.6.2 https://review.openstack.org/320084 | 16:20 |
openstackgerrit | Merged openstack/openstack-ansible-os_zaqar: Updating os_zaqar to use the Multi-Distro framework https://review.openstack.org/316332 | 16:25 |
logan- | automagically_: https://gist.github.com/Logan2211/b3217f7fa2f6e6cb12837e13603e8988 | 16:25 |
automagically_ | Much appreciated logan- | 16:25 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Adding audit rule for SELinux policy modifications https://review.openstack.org/319438 | 16:27 |
logan- | np. if i missed anything just ping me. i just overlay that and don't override any of the shas inside the osa roles, so if one of the .debs updates in osa, the updated osa sha won't match the out-of-date mirror .deb and you'll know to update it. not very smooth but it works. | 16:28 |
*** sdake has joined #openstack-ansible | 16:29 | |
v1k0d3n | so cloudnull if i'm trying to fudge around with using a single nic, i'm assuming i will need a route or something for these bridge interfaces to communicate over the single nic, right? or do i need to add the interface (in this case eth2) to bridge? | 16:29 |
v1k0d3n | i am so sorry i'm slamming you with questions man. | 16:30 |
v1k0d3n | at some point i'm going to reach my quota! :) | 16:30 |
v1k0d3n | haven't set multi-node over a single nic like this (haven't really needed to fudge it like this). | 16:31 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Ensure V-38574 works reliably on CentOS https://review.openstack.org/321112 | 16:35 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Docs: Update dev notes for Cat 2 controls https://review.openstack.org/318954 | 16:38 |
evrardjp | cloudnull: I double checked I'm using the same PPA, and I was | 16:38 |
cloudnull | I was not using the PPA. | 16:38 |
evrardjp | haha! I understand now | 16:39 |
cloudnull | v1k0d3n: if you have a single nic the easiet way to make it all go would be to plug the nic into an integration bridge | 16:41 |
cloudnull | then create several vlan tagged devices off of that bridge | 16:41 |
cloudnull | then create additional bridges for br-mgmt, br-vlan, etc... using the tagged interfaces. | 16:41 |
*** admin0 has quit IRC | 16:42 | |
*** galstrom is now known as galstrom_zzz | 16:42 | |
cloudnull | v1k0d3n: example https://gist.github.com/cloudnull/e81115119dddee5e2a06 | 16:43 |
cloudnull | just cut the bond config out | 16:43 |
v1k0d3n | ah, yes...was rewriting it just like that when you replied. | 16:44 |
v1k0d3n | ok, think i'm down the same path. | 16:44 |
cloudnull | cool | 16:44 |
*** asettle has quit IRC | 16:46 | |
*** Brew has quit IRC | 16:48 | |
*** asettle has joined #openstack-ansible | 16:51 | |
*** weezS has quit IRC | 16:56 | |
*** jvalente has quit IRC | 16:58 | |
*** psilvad has joined #openstack-ansible | 17:01 | |
*** asettle has quit IRC | 17:04 | |
*** Brew has joined #openstack-ansible | 17:07 | |
openstackgerrit | Wang Qing wu proposed openstack/openstack-ansible-os_nova: Implement Nova PowerVM Virt Driver https://review.openstack.org/319022 | 17:10 |
*** Brew has left #openstack-ansible | 17:12 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Disable graphical interface instead of checking https://review.openstack.org/321130 | 17:12 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Update ansible to version 2.1 https://review.openstack.org/321042 | 17:16 |
mhayden | automagically_: what's your take on hughsaunders's comment here? https://review.openstack.org/320993 | 17:17 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Enable LSM instead of checking status https://review.openstack.org/320993 | 17:18 |
*** brad[] has joined #openstack-ansible | 17:18 | |
v1k0d3n | cloudnull: still seem to be running into issues. | 17:21 |
v1k0d3n | exploring...but kind of lost...should just...*work* | 17:21 |
automagically_ | mhayden: I think if I’m a CentOS user who has chosen to apply the security role, that I want SELinux running | 17:22 |
mhayden | i'd tend to agree | 17:22 |
automagically_ | Added that comment to the issue | 17:22 |
mhayden | perhaps i could adjust the docs to have a "must read" section | 17:23 |
palendae | Hrm | 17:24 |
mhayden | thanks automagically_ | 17:25 |
palendae | Found a nasty global var dependency in the dynamic inventory, which I fixed...and now the duplicate IP test fails on the 45th run (of 100) every time | 17:25 |
palendae | I think I shall pause this and go to lunch | 17:25 |
cloudnull | v1k0d3n: whats up? | 17:25 |
*** berendt has joined #openstack-ansible | 17:28 | |
v1k0d3n | cloudnull: this is what i have | 17:30 |
v1k0d3n | https://gist.github.com/v1k0d3n/06245da552d2655c70d9d15ed131d7ff | 17:30 |
v1k0d3n | pretty basic. traffic should default to eth2 | 17:31 |
v1k0d3n | eth2 is defined in /etc/network/interfaces | 17:31 |
v1k0d3n | route is out that interface etc. normal. | 17:31 |
*** sdake_ has joined #openstack-ansible | 17:33 | |
*** jiteka has quit IRC | 17:34 | |
*** sdake has quit IRC | 17:35 | |
pjm6 | this image is up-to-date http://docs.openstack.org/developer/openstack-ansible/_images/environment-overview.png ? | 17:36 |
pjm6 | i'm asking because in the logging host i think i didn't see the logstash, elasticsearch+ kibana | 17:36 |
*** BjoernT is now known as Bjoern_zZzZzZzZ | 17:36 | |
pjm6 | and the RPC Respository are the openstack ansible playbooks? | 17:36 |
*** Bjoern_zZzZzZzZ is now known as BjoernT | 17:40 | |
*** fawadkhaliq has joined #openstack-ansible | 17:43 | |
*** cloader89 has joined #openstack-ansible | 17:43 | |
*** kstev has quit IRC | 17:44 | |
*** rahulait has joined #openstack-ansible | 17:49 | |
*** rahuls has left #openstack-ansible | 17:49 | |
*** rahulait is now known as Guest48704 | 17:49 | |
*** Guest48704 has quit IRC | 17:49 | |
*** Min_Cai has joined #openstack-ansible | 17:49 | |
*** rahuls has joined #openstack-ansible | 17:50 | |
Min_Cai | I'm here. | 17:50 |
*** ig0r__ has quit IRC | 17:51 | |
openstackgerrit | Andy McCrae proposed openstack/openstack-ansible-os_nova: Allow metadata_host to be different to LB VIP https://review.openstack.org/321148 | 17:52 |
*** javeriak has quit IRC | 17:55 | |
*** saneax is now known as saneax_AFK | 17:55 | |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible-os_nova: Cleanup Nova console proxy git repos before updating it https://review.openstack.org/320650 | 17:55 |
*** aslaen has joined #openstack-ansible | 18:02 | |
*** asettle has joined #openstack-ansible | 18:04 | |
*** asettle has quit IRC | 18:09 | |
*** admin0 has joined #openstack-ansible | 18:11 | |
*** boogibugs has quit IRC | 18:12 | |
hughsaunders | pjm6: the logging bits are in RPC (Rackspace Prviate Cloud) https://github.com/rcbops/rpc-openstack | 18:12 |
*** Min_Cai has quit IRC | 18:13 | |
hughsaunders | well, not all the logging bits, OSA configures rsyslog.. RPC adds beaver & ELK | 18:13 |
hughsaunders | so I guess the answer to your question is no, the image needs updating because it implies that OSA configures ELK. | 18:14 |
*** admin0 has quit IRC | 18:19 | |
*** electrofelix has quit IRC | 18:21 | |
*** sdake_ is now known as sdake | 18:23 | |
*** fawadkhaliq has quit IRC | 18:23 | |
openstackgerrit | Nolan Brubaker proposed openstack/openstack-ansible: Reduce reliance on global state for testing https://review.openstack.org/321172 | 18:32 |
*** sdake_ has joined #openstack-ansible | 18:34 | |
*** sdake has quit IRC | 18:37 | |
*** kstev has joined #openstack-ansible | 18:37 | |
openstackgerrit | Merged openstack/openstack-ansible: Create ceph python library symlinks https://review.openstack.org/317901 | 18:38 |
*** gonzalo2kx has joined #openstack-ansible | 18:42 | |
pjm6 | thanks hughsaunders | 18:47 |
openstackgerrit | Merged openstack/openstack-ansible-pip_install: Enable CentOS support https://review.openstack.org/320913 | 18:47 |
pjm6 | so besides ELK | 18:47 |
pjm6 | all its good? | 18:47 |
*** omiday has joined #openstack-ansible | 18:47 | |
pjm6 | oh i was seeing that repo, if i understand, the RPC will handle about the ELK, right? | 18:48 |
*** sdake_ is now known as sdake | 18:48 | |
prometheanfire | cloudnull: is gate still broken? | 18:53 |
*** javeriak has joined #openstack-ansible | 18:59 | |
*** Mudpuppy has quit IRC | 19:02 | |
*** Mudpuppy has joined #openstack-ansible | 19:04 | |
*** galstrom_zzz is now known as galstrom | 19:06 | |
*** aslaen has quit IRC | 19:09 | |
*** javeriak_ has joined #openstack-ansible | 19:09 | |
*** javeriak has quit IRC | 19:10 | |
openstackgerrit | Matt Thompson proposed openstack/openstack-ansible-os_designate: Test designate w/ designate tempest plugins https://review.openstack.org/319941 | 19:13 |
*** chhavi has quit IRC | 19:13 | |
*** elopez has joined #openstack-ansible | 19:16 | |
pjm6 | guys anyone knows if in OSA there is a rule to modprobe kernel modules? | 19:22 |
*** Mudpuppy has quit IRC | 19:25 | |
*** daneyon has quit IRC | 19:26 | |
openstackgerrit | Nolan Brubaker proposed openstack/openstack-ansible: Test _ensure_inventory_uptodate function https://review.openstack.org/321197 | 19:30 |
*** daneyon has joined #openstack-ansible | 19:33 | |
*** Mudpuppy has joined #openstack-ansible | 19:33 | |
*** Mudpuppy has quit IRC | 19:34 | |
*** Mudpuppy has joined #openstack-ansible | 19:36 | |
*** wadeholler has quit IRC | 19:39 | |
openstackgerrit | Nolan Brubaker proposed openstack/openstack-ansible: Test _ensure_inventory_uptodate function https://review.openstack.org/321197 | 19:52 |
*** javeriak_ has quit IRC | 19:54 | |
*** admin0 has joined #openstack-ansible | 19:54 | |
*** jayc has joined #openstack-ansible | 19:56 | |
palendae | I realize 2 of them haven't run through the gate yet, but would appreciate eyes on https://review.openstack.org/#/q/topic:inventory-tests+status:open when people get the chance | 20:07 |
*** galstrom is now known as galstrom_zzz | 20:07 | |
*** admin0 has quit IRC | 20:11 | |
*** raddaoui has joined #openstack-ansible | 20:12 | |
*** admin0 has joined #openstack-ansible | 20:13 | |
*** jamesdenton has joined #openstack-ansible | 20:18 | |
*** jamesdenton has quit IRC | 20:18 | |
hughsaunders | pjm6: https://github.com/openstack/openstack-ansible-openstack_hosts/blob/master/tasks/openstack_kernel_modules.yml | 20:26 |
*** johnmilton has quit IRC | 20:28 | |
*** smatzek has quit IRC | 20:30 | |
*** Zucan has quit IRC | 20:31 | |
*** v1k0d3n has left #openstack-ansible | 20:33 | |
*** v1k0d3n has joined #openstack-ansible | 20:33 | |
*** brunofurtado has joined #openstack-ansible | 20:35 | |
*** mummer has joined #openstack-ansible | 20:41 | |
*** flaviodsr has quit IRC | 20:41 | |
*** Zucan has joined #openstack-ansible | 20:44 | |
*** admin0 has quit IRC | 20:46 | |
*** sdake_ has joined #openstack-ansible | 20:46 | |
*** gonzalo2kx has quit IRC | 20:47 | |
v1k0d3n | cloudnull: are you guys throwing a party over there? this room's been super quiet. lol | 20:48 |
*** sdake has quit IRC | 20:48 | |
v1k0d3n | crickets. unless i've been banished for too many questions in one day. | 20:48 |
*** admin0 has joined #openstack-ansible | 20:48 | |
palendae | No party that I know of | 20:50 |
palendae | Though I've been working around town today, and I'm not based in SAT either | 20:50 |
v1k0d3n | wondering if anyone can help me with some linux bridging...i'm still having issues. | 20:55 |
v1k0d3n | :( | 20:55 |
*** smatzek has joined #openstack-ansible | 20:57 | |
*** admin0 has quit IRC | 20:59 | |
*** woodard_ has joined #openstack-ansible | 20:59 | |
*** asettle has joined #openstack-ansible | 20:59 | |
*** schwicht has quit IRC | 21:01 | |
*** bsv has joined #openstack-ansible | 21:01 | |
*** woodard has quit IRC | 21:03 | |
*** woodard_ has quit IRC | 21:04 | |
*** smatzek has quit IRC | 21:08 | |
*** retreved has quit IRC | 21:08 | |
*** psilvad has quit IRC | 21:11 | |
*** Mudpuppy has quit IRC | 21:13 | |
*** mummer has quit IRC | 21:13 | |
*** mummer has joined #openstack-ansible | 21:23 | |
*** asettle has quit IRC | 21:23 | |
*** thorst_ has quit IRC | 21:24 | |
*** thorst_ has joined #openstack-ansible | 21:24 | |
*** ametts has quit IRC | 21:28 | |
*** thorst_ has quit IRC | 21:29 | |
*** thorst_ has joined #openstack-ansible | 21:30 | |
*** johnmilton has joined #openstack-ansible | 21:31 | |
*** gonzalo2kx has joined #openstack-ansible | 21:33 | |
dolphm | anyone ever seen this before? TypeError: __init__() got an unexpected keyword argument 'allow_no_value' in _v1_config_template http://cdn.pasteraw.com/9he87vw1o99kfkkhtj1utimj6sneo66 | 21:35 |
*** thorst_ has quit IRC | 21:35 | |
dolphm | this is on 13.1.0 | 21:37 |
*** bsv has quit IRC | 21:37 | |
openstackgerrit | Merged openstack/openstack-ansible-security: Docs: Update dev notes for Cat 2 controls https://review.openstack.org/318954 | 21:38 |
hughsaunders | palendae: does https://review.openstack.org/#/c/318917/5 check if the provided cidr/gateway are routable? | 21:39 |
openstackgerrit | Merged openstack/openstack-ansible-security: Disable the netconsole service (if present) https://review.openstack.org/319445 | 21:39 |
hughsaunders | dolphm: new one on me. | 21:42 |
*** kstev has quit IRC | 21:43 | |
hughsaunders | dolphm: which version of ansible? | 21:43 |
*** sdake_ has quit IRC | 21:45 | |
*** gonzalo2kx has quit IRC | 21:47 | |
*** daneyon has quit IRC | 21:49 | |
*** daneyon has joined #openstack-ansible | 21:50 | |
*** sdake has joined #openstack-ansible | 21:50 | |
*** thorst_ has joined #openstack-ansible | 21:52 | |
*** thorst_ has quit IRC | 21:57 | |
*** jayc has quit IRC | 21:57 | |
*** cloader89 has quit IRC | 21:58 | |
*** aslaen has joined #openstack-ansible | 22:02 | |
*** jayc has joined #openstack-ansible | 22:09 | |
*** kylek3h has quit IRC | 22:13 | |
dolphm | hughsaunders: 1.9.6 | 22:17 |
dolphm | hughsaunders: but we gave up, and moved to a different ansible host :( | 22:17 |
dolphm | hughsaunders: now have a new problem, where ansible-galaxy install --role-file is trying to treat every line of a yaml file as a discrete requirement? | 22:18 |
dolphm | so, it's failing to download a role called '---' to kick things off | 22:18 |
stevelle | ... wat | 22:19 |
dolphm | the ansible-role-requirements.yml file in question: https://github.com/rackerlabs/capstone/blob/master/deploy/ansible-role-requirements.yml | 22:21 |
dolphm | and the actual failure: http://cdn.pasteraw.com/1l08i4n5jevya4l1htr507jku0bbkms | 22:21 |
stevelle | Checking my initial response, no I am not entirely surprised that ansible-galaxy isn't properly parsing yaml documents. Probably will work if you drop the document delimiter dolphm. | 22:23 |
stevelle | https://github.com/openstack/openstack-ansible/blob/master/ansible-role-requirements.yml | 22:23 |
*** sdake has quit IRC | 22:25 | |
dolphm | stevelle: trying ... | 22:25 |
dolphm | stevelle: but there was a similar error message for every line in the yml file, not just the --- | 22:25 |
dolphm | aaaand it's doing the same thing | 22:25 |
dolphm | can you update ansible-galaxy independently from ansible? (which is already 1.9.6) | 22:25 |
stevelle | I don't know abt that | 22:25 |
stevelle | I recall palendae mentioning that ansible rolled their own yaml parser so fun adventure | 22:26 |
stevelle | dolphm: looks like it isn't expecting yaml. | 22:28 |
stevelle | it seems to want something that looks like a pip requirements file | 22:29 |
dolphm | stevelle: yeah =( but i don't see how we can make it look any more like yaml | 22:29 |
dolphm | stevelle: ansible-galaxy used to support (maybe still does?) .txt files that look like pip requirements.txt | 22:29 |
stevelle | no no, less like yaml | 22:29 |
stevelle | dolphm: https://docs.ansible.com/ansible/galaxy.html#installing-multiple-roles-from-a-file | 22:29 |
stevelle | though versions are not well handled on those docs | 22:30 |
stevelle | guessing the "advanced control over requirements files" isn't working in 1.9 | 22:30 |
*** schwicht has joined #openstack-ansible | 22:38 | |
*** weezS has joined #openstack-ansible | 22:42 | |
*** weezS has quit IRC | 22:44 | |
*** afred312_ has joined #openstack-ansible | 22:45 | |
*** afred312 has quit IRC | 22:47 | |
*** rahuls has quit IRC | 22:57 | |
*** phalmos has quit IRC | 23:01 | |
mgagne | is there a way to query Ansible for a variable for external consumption? | 23:03 |
mgagne | or would it be tricky since variables could be dynamically defined/registered from a role or task? | 23:04 |
*** jayc has quit IRC | 23:08 | |
dmsimard | mgagne: so, like, registering a variable based on the results of a http request ? | 23:08 |
dmsimard | What's external consumption ? | 23:09 |
mgagne | like: should I run a playbook with those variables files based on inventory and such, what would be the variable value? | 23:09 |
mgagne | a bash script for example | 23:09 |
mgagne | but I guess writing a playbook which executes similar tasks to what bash would have done would be much more simple | 23:09 |
dmsimard | Hmm, yeah, I don't know of a way to fetch ansible variables from outside the scope of an ansible run. Either doing what your bash script would do through ansible tasks or templating a bash script (and running it) could be two possible options. | 23:13 |
stevelle | mgagne: if you are willing to accept that variables (esp. defined through "register" hooks) are off-limits, you can get facts about the inventory and values for defined variables with adhoc ansible commands. | 23:15 |
stevelle | getting them out and parsing them from cmd line output of ansible adhoc commands will be an exercise though | 23:16 |
mgagne | yea. talking with a coworker, we came to the conclusion that running a playbook would be way better. | 23:16 |
stevelle | mgagne: that is partly why we converted bootstrap-aio.yml from a bash script | 23:17 |
mgagne | :D | 23:17 |
mgagne | basically, we wish to validate a config syntax in gate (zuul) we don't want to install the whole software so we used to use tox to install Zuul and run config validation from there. until the version used in Ansible is different from the one used in tox and one fail but not the other :D | 23:18 |
stevelle | I will note that at some points (see https://github.com/openstack/openstack-ansible-repo_build) we do generate bash scripts with templating for execution in a playbook | 23:18 |
stevelle | we did that for speed, however. | 23:19 |
mgagne | right, that's an other idea I guess | 23:19 |
stevelle | that had more to do with execution of tasks having very long with_items: lists | 23:20 |
stevelle | mgagne: I'm pretty sure we're working on isolating our ansible in a venv, and it sounds like that may be the direction you're going to be headed as well | 23:22 |
*** kylek3h has joined #openstack-ansible | 23:23 | |
stevelle | and because why not, I know cloudnull and I and likely others here have used ansible playbooks to run ansible playbooks as a task. | 23:23 |
stevelle | I don't think we liked that in practice very much though | 23:23 |
mgagne | stevelle: I'm installing Zuul in a venv already. The script I'm trying to adapt is the one running in check/gate to validate the config. So far, I was using tox.ini to install Zuul and test the config. Problem is version pinning is not in sync with Ansible. That's why I'm thinking about moving the check to Ansible and/or use Ansible to invoke tox or the shell script with the correct version. | 23:25 |
*** schwicht_ has joined #openstack-ansible | 23:26 | |
mgagne | I found sharing values/configs across configuration management systems to be a common issue | 23:27 |
*** schwicht has quit IRC | 23:28 | |
*** sdake has joined #openstack-ansible | 23:28 | |
stevelle | mgagne: as much as I understand that, yeah you might be on the right track going with a playbook | 23:29 |
*** kylek3h has quit IRC | 23:29 | |
*** kylek3h has joined #openstack-ansible | 23:30 | |
*** BjoernT has quit IRC | 23:30 | |
*** kylek3h has quit IRC | 23:34 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!