*** rstarmer has quit IRC | 00:00 | |
*** TicToc has quit IRC | 00:07 | |
*** TicToc has joined #openstack-ansible | 00:09 | |
*** guhcampos has quit IRC | 00:14 | |
*** kstev1 is now known as kstev | 00:30 | |
*** ianychoi has joined #openstack-ansible | 00:31 | |
*** pbandark has quit IRC | 00:33 | |
*** chyka has quit IRC | 00:34 | |
*** vnogin has joined #openstack-ansible | 00:40 | |
*** cjloader has joined #openstack-ansible | 00:43 | |
*** markvoelker has quit IRC | 00:43 | |
*** markvoelker has joined #openstack-ansible | 00:44 | |
*** vnogin has quit IRC | 00:46 | |
*** markvoelker has quit IRC | 00:48 | |
openstackgerrit | Merged openstack/openstack-ansible stable/pike: Add a return code check to the osa wrapper https://review.openstack.org/539027 | 00:51 |
---|---|---|
*** cjloader has quit IRC | 00:57 | |
*** TicToc has quit IRC | 01:09 | |
*** dave-mccowan has joined #openstack-ansible | 01:13 | |
*** Neptu_ has quit IRC | 01:13 | |
*** Neptu has joined #openstack-ansible | 01:16 | |
*** TicToc has joined #openstack-ansible | 01:19 | |
*** markvoelker has joined #openstack-ansible | 01:30 | |
*** woodard_ has joined #openstack-ansible | 01:33 | |
*** woodard has quit IRC | 01:33 | |
openstackgerrit | Nguyen Hung Phuong proposed openstack/openstack-ansible-tests master: Clean imports in code https://review.openstack.org/539400 | 02:19 |
*** kstev has quit IRC | 02:28 | |
*** akasurde has joined #openstack-ansible | 02:47 | |
*** akasurde has joined #openstack-ansible | 02:47 | |
*** Pramod has quit IRC | 03:05 | |
cloudnull | evenings | 03:14 |
*** mgagne has quit IRC | 03:22 | |
*** chris_hultin has quit IRC | 03:23 | |
*** mgagne has joined #openstack-ansible | 03:24 | |
*** chris_hultin|AWA has joined #openstack-ansible | 03:24 | |
*** mgagne is now known as Guest87240 | 03:24 | |
*** toan has quit IRC | 03:24 | |
*** chris_hultin|AWA is now known as chris_hultin | 03:24 | |
*** toan has joined #openstack-ansible | 03:26 | |
*** gkadam has quit IRC | 03:33 | |
*** ANKITA has joined #openstack-ansible | 03:50 | |
*** ANKITA has quit IRC | 04:13 | |
*** TicToc has quit IRC | 04:14 | |
mhayden | cloudnull: orly | 04:20 |
*** TicToc has joined #openstack-ansible | 04:23 | |
*** dave-mccowan has quit IRC | 04:32 | |
*** poopcat1 has joined #openstack-ansible | 04:34 | |
*** poopcat has quit IRC | 04:34 | |
*** taseer2 is now known as Taseer | 04:46 | |
openstackgerrit | Taseer Ahmed proposed openstack/openstack-ansible-os_congress master: Introduce os_congress role in gerrit https://review.openstack.org/522491 | 04:46 |
*** cjloader has joined #openstack-ansible | 04:48 | |
*** SONY_ has joined #openstack-ansible | 04:51 | |
*** SONY_ has quit IRC | 04:52 | |
*** cjloader has quit IRC | 04:53 | |
*** SON has joined #openstack-ansible | 04:53 | |
SON | HI | 04:53 |
SON | Am facing an issue while adding additional infrastructure node RUNNING HANDLER [haproxy_server : Restart haproxy] ***************************** Tuesday 30 January 2018 02:48:39 -0800 (0:00:00.805) 0:19:55.373 ******* fatal: [infra4]: FAILED! => {"changed": false, "failed": true, "msg": "Unable to restart service haproxy: Job for haproxy.service failed because the control process exited with error code. See \"systemctl | 04:55 |
SON | systemctl status haproxy.service says : haproxy.service: Control process exited, code=exited status=1 | 04:56 |
SON | haproxy.service: Start request repeated too quickly. | 04:57 |
SON | jojooo | 05:02 |
SON | file /etc/ssl/private/haproxy.pem is missing | 05:02 |
SON | instead the location has ssl-cert-snakeoil.key file | 05:04 |
*** markvoelker has quit IRC | 05:06 | |
*** hybridpollo has quit IRC | 05:08 | |
*** poopcat1 has quit IRC | 05:10 | |
SON | ExecStartPre=/usr/sbin/haproxy -f ${CONFIG} -c -q (code=exited, status=1/FAILURE) | 05:11 |
*** zerick_ has quit IRC | 05:13 | |
*** zerick has joined #openstack-ansible | 05:15 | |
SON | [ALERT] 029/200426 (20493) : Proxy 'rabbitmq_mgmt-front-1': no SSL certificate | 05:16 |
*** gkadam has joined #openstack-ansible | 05:23 | |
*** TicToc has quit IRC | 05:23 | |
*** TicToc has joined #openstack-ansible | 05:27 | |
*** hybridpollo has joined #openstack-ansible | 05:28 | |
*** hybridpollo has quit IRC | 05:35 | |
*** cjloader has joined #openstack-ansible | 05:48 | |
*** threestrands has quit IRC | 05:51 | |
*** cjloader has quit IRC | 05:53 | |
*** aruns__ has joined #openstack-ansible | 05:55 | |
*** indistylo has joined #openstack-ansible | 05:56 | |
*** aruns has joined #openstack-ansible | 05:57 | |
*** aruns__ has quit IRC | 06:00 | |
*** threestrands has joined #openstack-ansible | 06:01 | |
*** aruns__ has joined #openstack-ansible | 06:01 | |
*** indistylo has quit IRC | 06:01 | |
Taseer | evrardjp: do I need to add python-ceilometerclient in congress requirements ? http://logs.openstack.org/91/522491/69/check/openstack-ansible-functional-ubuntu-xenial/7f94033/logs/openstack/congress1/congress/congress-server.log.txt.gz | 06:06 |
*** TicToc has quit IRC | 06:28 | |
*** TicToc has joined #openstack-ansible | 06:31 | |
openstackgerrit | Merged openstack/openstack-ansible-os_neutron master: Add SELinux policies for bare metal agents https://review.openstack.org/532646 | 06:38 |
*** gkadam has quit IRC | 06:38 | |
openstackgerrit | Merged openstack/openstack-ansible-os_cinder master: Zuul: Remove project name https://review.openstack.org/538538 | 06:39 |
*** gkadam has joined #openstack-ansible | 06:42 | |
*** cjloader has joined #openstack-ansible | 06:48 | |
*** akasurde is now known as akasurde_afkk | 06:48 | |
*** gkadam has quit IRC | 06:52 | |
*** cjloader has quit IRC | 06:53 | |
*** gkadam has joined #openstack-ansible | 06:54 | |
jafeha | good morning | 06:58 |
*** akasurde_afkk has quit IRC | 07:00 | |
*** indistylo has joined #openstack-ansible | 07:08 | |
*** aruns has quit IRC | 07:08 | |
*** aruns__ has quit IRC | 07:08 | |
*** aruns has joined #openstack-ansible | 07:08 | |
*** markvoelker has joined #openstack-ansible | 07:11 | |
*** aruns has quit IRC | 07:15 | |
*** aruns has joined #openstack-ansible | 07:15 | |
*** aruns__ has joined #openstack-ansible | 07:15 | |
*** indistylo has quit IRC | 07:15 | |
*** pmannidi has quit IRC | 07:19 | |
*** aruns__ has quit IRC | 07:20 | |
*** indistylo has joined #openstack-ansible | 07:20 | |
*** TicToc has quit IRC | 07:30 | |
*** peri has joined #openstack-ansible | 07:42 | |
*** markvoelker has quit IRC | 07:42 | |
openstackgerrit | Markos Chandras (hwoarang) proposed openstack/openstack-ansible-os_neutron master: tasks: Ensure Open vSwitch is started for all providers that need it https://review.openstack.org/538933 | 07:46 |
*** TicToc has joined #openstack-ansible | 07:47 | |
*** cjloader has joined #openstack-ansible | 07:48 | |
*** pcaruana has joined #openstack-ansible | 07:51 | |
*** cjloader has quit IRC | 07:52 | |
*** gaudenz has quit IRC | 07:57 | |
*** akasurde_afkk has joined #openstack-ansible | 07:59 | |
*** akasurde_afkk is now known as akasurde | 08:01 | |
openstackgerrit | Merged openstack/openstack-ansible-ops master: Fix tftpd-hpa configuration issues https://review.openstack.org/539334 | 08:02 |
*** mbuil has joined #openstack-ansible | 08:06 | |
*** TicToc has quit IRC | 08:08 | |
*** aruns__ has joined #openstack-ansible | 08:09 | |
*** indistylo has quit IRC | 08:11 | |
*** aruns has quit IRC | 08:11 | |
*** sawblade6 has quit IRC | 08:11 | |
*** indistylo has joined #openstack-ansible | 08:12 | |
*** sxc731 has joined #openstack-ansible | 08:23 | |
*** sawblade6 has joined #openstack-ansible | 08:29 | |
*** markvoelker has joined #openstack-ansible | 08:39 | |
*** armaan has joined #openstack-ansible | 08:40 | |
*** cjloader has joined #openstack-ansible | 08:48 | |
*** cjloader has quit IRC | 08:52 | |
*** chyka has joined #openstack-ansible | 08:59 | |
*** gkadam has quit IRC | 09:03 | |
*** rstarmer has joined #openstack-ansible | 09:03 | |
*** chyka has quit IRC | 09:04 | |
*** gkadam has joined #openstack-ansible | 09:04 | |
openstackgerrit | Taseer Ahmed proposed openstack/openstack-ansible-os_congress master: Introduce os_congress role in gerrit https://review.openstack.org/522491 | 09:11 |
*** markvoelker has quit IRC | 09:12 | |
*** pbandark has joined #openstack-ansible | 09:13 | |
*** shardy has joined #openstack-ansible | 09:13 | |
SON | anyone faced similar issue while adding infra nodes? | 09:14 |
SON | TASK [rsyslog_client : Configure logrotate to compress logs by default] ****** ** Wednesday 31 January 2018 01:11:29 -0800 (0:00:00.028) 0:20:25.042 **** * ok: [infra5] RUNNING HANDLER [haproxy_server : Regenerate haproxy configuration] ********** ** Wednesday 31 January 2018 01:11:29 -0800 (0:00:00.22 | 09:14 |
evrardjp | SON: where is the issue? | 09:16 |
*** exodusftw has quit IRC | 09:17 | |
SON | evrardjp haproxy status inactive for new node | 09:20 |
SON | RUNNING HANDLER [haproxy_server : Restart haproxy] ***************************** Tuesday 30 January 2018 02:48:39 -0800 (0:00:00.805) 0:19:55.373 ******* fatal: [infra4]: FAILED! => {"changed": false, "failed": true, "msg": "Unable to restart service haproxy: Job for haproxy.service failed because the control process exited with error code. See \"systemctl status haproxy.service\" and \"journalctl -xe\" for details.\n" | 09:21 |
*** exodusftw has joined #openstack-ansible | 09:23 | |
SON | RUNNING HANDLER [haproxy_server : Restart haproxy] *************************** ** Wednesday 31 January 2018 01:11:30 -0800 (0:00:00.433) 0:20:25.704 **** * fatal: [infra5]: FAILED! => {"changed": false, "failed": true, "msg": "Unable to restart service haproxy: Job for haproxy.service failed because the | 09:23 |
SON | evrardjp on exe of openstack-ansible setup-everything.yml --limit @/root/add_host.limit | 09:24 |
SON | infra5 systemd[1]: Failed to start HAProxy Load Balancer. | 09:33 |
evrardjp | SON: which version of openstack-ansible? | 09:33 |
SON | ocata | 09:36 |
evrardjp | more precisely? | 09:39 |
evrardjp | if you could also paste the message somewhere that would be helpful. Also giving the value of your external_lb_vip_address and internal_lb_vip_address would help. | 09:40 |
SON | openstack --version openstack 3.8.1 | 09:41 |
evrardjp | no I mean your openstack-ansible version | 09:42 |
evrardjp | the tag you checked out? | 09:42 |
SON | external_lb_vip_address 10.40.100.10 & | 09:42 |
evrardjp | if you want to paste your error message on paste.openstack.org that would be nice. | 09:43 |
evrardjp | SON: ok, I suppose the & is just an issue while you typed it here :) | 09:43 |
evrardjp | what is internal_lb_vip_address? | 09:43 |
SON | external_lb_vip_address: 50.197.137.248 | 09:46 |
openstackgerrit | Merged openstack/openstack-ansible-os_magnum stable/newton: Zuul: Remove project name https://review.openstack.org/538633 | 09:46 |
*** cjloader has joined #openstack-ansible | 09:48 | |
openstackgerrit | Merged openstack/openstack-ansible stable/pike: Fix logic to check for insecure Keystone https://review.openstack.org/538297 | 09:51 |
openstackgerrit | Merged openstack/openstack-ansible master: Simplify memcached servers https://review.openstack.org/538235 | 09:51 |
*** cjloader has quit IRC | 09:53 | |
*** armaan has quit IRC | 09:53 | |
*** armaan has joined #openstack-ansible | 09:54 | |
*** SON has quit IRC | 09:55 | |
*** aruns has joined #openstack-ansible | 09:56 | |
Taseer | evrardjp: do you know what I might be missing => http://logs.openstack.org/91/522491/70/check/openstack-ansible-functional-ubuntu-xenial/7237659/logs/openstack/congress1/congress/congress-server.log.txt.gz | 09:58 |
*** aruns__ has quit IRC | 09:59 | |
*** indistylo has quit IRC | 09:59 | |
*** indistylo has joined #openstack-ansible | 09:59 | |
*** SON has joined #openstack-ansible | 10:01 | |
*** markvoelker has joined #openstack-ansible | 10:09 | |
*** aruns has quit IRC | 10:13 | |
*** aruns has joined #openstack-ansible | 10:14 | |
*** aruns__ has joined #openstack-ansible | 10:14 | |
*** indistylo has quit IRC | 10:14 | |
*** aruns has quit IRC | 10:18 | |
*** aruns has joined #openstack-ansible | 10:18 | |
*** gkadam has quit IRC | 10:19 | |
*** gkadam has joined #openstack-ansible | 10:20 | |
*** aruns__ has quit IRC | 10:20 | |
*** aruns__ has joined #openstack-ansible | 10:21 | |
*** aruns__ has quit IRC | 10:22 | |
*** aruns__ has joined #openstack-ansible | 10:22 | |
*** jwitko_ has quit IRC | 10:25 | |
*** aruns has quit IRC | 10:25 | |
*** aruns__ has quit IRC | 10:26 | |
evrardjp | SON: these are twice the same, or is that a typo? | 10:33 |
evrardjp | Taseer: ceilometer driver, from where it is. | 10:34 |
evrardjp | Taseer: I don't know what provides it, but it's missing | 10:34 |
*** jafeha__ has joined #openstack-ansible | 10:35 | |
*** jafeha has quit IRC | 10:35 | |
evrardjp | SON: I still don't know which ocata you have | 10:36 |
evrardjp | so I can't reproduce it right now | 10:36 |
odyssey4me | idlemind it sounds to me like you don't have the haproxy/keepalived config quite right then - apologies for wasting your time | 10:37 |
odyssey4me | o/ all | 10:38 |
evrardjp | odyssey4me: good morning | 10:39 |
*** markvoelker has quit IRC | 10:42 | |
*** cjloader has joined #openstack-ansible | 10:48 | |
*** cjloader has quit IRC | 10:53 | |
*** taseer1 has joined #openstack-ansible | 11:13 | |
*** Taseer has quit IRC | 11:14 | |
*** taseer2 has joined #openstack-ansible | 11:14 | |
*** taseer1 has quit IRC | 11:18 | |
*** sawblade_ has joined #openstack-ansible | 11:21 | |
*** taseer2 is now known as Taseer | 11:22 | |
*** sawblade6 has quit IRC | 11:24 | |
*** stuartgr has joined #openstack-ansible | 11:27 | |
openstackgerrit | Taseer Ahmed proposed openstack/openstack-ansible-os_congress master: Introduce os_congress role in gerrit https://review.openstack.org/522491 | 11:32 |
openstackgerrit | Merged openstack/openstack-ansible-os_cinder stable/newton: Zuul: Remove project name https://review.openstack.org/538540 | 11:33 |
*** rpittau has quit IRC | 11:35 | |
*** markvoelker has joined #openstack-ansible | 11:39 | |
*** cjloader has joined #openstack-ansible | 11:48 | |
*** sxc731 has quit IRC | 11:50 | |
mbuil | when will the stable/queens branch be created? | 11:50 |
*** cjloader has quit IRC | 11:52 | |
openstackgerrit | Merged openstack/openstack-ansible-os_cinder stable/ocata: Zuul: Remove project name https://review.openstack.org/538543 | 11:53 |
*** threestrands has quit IRC | 12:08 | |
*** dave-mccowan has joined #openstack-ansible | 12:08 | |
*** markvoelker has quit IRC | 12:12 | |
*** sxc731 has joined #openstack-ansible | 12:23 | |
*** indistylo has joined #openstack-ansible | 12:30 | |
*** bhujay has joined #openstack-ansible | 12:32 | |
*** chyka has joined #openstack-ansible | 12:35 | |
*** aruns has joined #openstack-ansible | 12:35 | |
bhujay | Hi all , I am experiencing a problem while running lxc-host-set up on a suse host . The Prepare cached image setup commands task fails with time out. | 12:37 |
*** indistylo has quit IRC | 12:38 | |
*** chyka has quit IRC | 12:39 | |
*** Taseer has quit IRC | 12:42 | |
*** cjloader has joined #openstack-ansible | 12:48 | |
*** cjloader has quit IRC | 12:53 | |
CobHead | In order for the people here to help you without asking too many questions, bhujay, is to run the playbook with verbose on (-vvvv) Paste the output from the failing part on e.g. pastebin and link it here. | 12:55 |
*** aruns__ has joined #openstack-ansible | 12:58 | |
evrardjp | probably -vv is enough :) | 12:59 |
evrardjp | but yeah :) | 12:59 |
evrardjp | bhujay: mmm these are the worst because it's a series of commands we run without ansible. Can you tap into the process? | 12:59 |
*** aruns has quit IRC | 13:00 | |
*** astellwag has joined #openstack-ansible | 13:01 | |
mhayden | buenos dias | 13:02 |
bhujay | evrardjp: yeah , it is going wrong with zypper --gpg-auto-import-keys -n dup --force-resolution -l | 13:02 |
bhujay | , some more interesting findings is the same step goes well with the host but fails when run with chroot. | 13:02 |
mnaser | https://review.openstack.org/#/c/538259/ can this get another +A to get it to go through gate without recheck | 13:03 |
bhujay | CobeHead: Thanks , will do so | 13:03 |
odyssey4me | evrardjp bhujay there is a log in /var/log/ on the host which will contain the output of what ran there | 13:03 |
*** sxc731 has quit IRC | 13:05 | |
bhujay | odyssey4me: that log shows zypper is stuck up while trying to download packages . Now manually i executed the command from a different mirror and it went through . Next I tired overriding the lxc_hosts_opensuse_mirror_url but the play book fails . I am trying to get an workaround . WIll update soon | 13:06 |
odyssey4me | bhujay is it failing, or timing out? | 13:06 |
odyssey4me | if it's timing out, there is a var to set which extends the timeout | 13:07 |
odyssey4me | https://github.com/openstack/openstack-ansible-lxc_hosts/blob/master/defaults/main.yml#L134-L138 | 13:07 |
*** markvoelker has joined #openstack-ansible | 13:09 | |
bhujay | i tried but that is not helping since with chroot the zypper update wont proceed even when run manually unless the mirror is changed . Have to figure out the correctway to oveerride that | 13:09 |
*** woodard_ has quit IRC | 13:10 | |
*** woodard has joined #openstack-ansible | 13:10 | |
odyssey4me | bhujay the process it does is to chroot, then setup a resolver, then do some things, then revert the resolver, then exit | 13:10 |
odyssey4me | if you need the mirror changed, there's a var for that too | 13:11 |
*** akasurde has quit IRC | 13:11 | |
*** astellwag has quit IRC | 13:12 | |
*** astellwag has joined #openstack-ansible | 13:17 | |
*** aruns has joined #openstack-ansible | 13:18 | |
*** aruns__ has quit IRC | 13:20 | |
*** santacloud__ has joined #openstack-ansible | 13:25 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-os_tempest master: Link SELinux python modules into tempest venv https://review.openstack.org/539257 | 13:28 |
mhayden | evrardjp: try that ^^ | 13:28 |
mhayden | thanks for the tip on linking in the modules evrardjp & mgariepy | 13:29 |
*** sxc731 has joined #openstack-ansible | 13:31 | |
*** kstev has joined #openstack-ansible | 13:32 | |
*** kstev has quit IRC | 13:32 | |
*** markvoelker has quit IRC | 13:37 | |
*** markvoelker has joined #openstack-ansible | 13:37 | |
mgariepy | morning | 13:38 |
*** tobberydberg has quit IRC | 13:41 | |
odyssey4me | cores - any chance for a re-review of https://review.openstack.org/537387 - it was only modified by hwoarang to add depends-on to another patch | 13:43 |
hwoarang | i will +2 it again since the context is the same. sorry i forgot to do it on time :) | 13:44 |
odyssey4me | no worries, thanks hwoarang | 13:44 |
*** cjloader has joined #openstack-ansible | 13:48 | |
sxc731 | Hi team, anything happening on the os_panko front (event storage API for Ceilometer)? This feature request was raised 15 months ago but doesn't seem to have moved much: https://bugs.launchpad.net/openstack-ansible/+bug/1629390 | 13:48 |
openstack | Launchpad bug 1629390 in openstack-ansible "Create an os_panko role" [Wishlist,Confirmed] - Assigned to Nish Patwa (nishpatwa) | 13:48 |
*** hw_wutianwei has joined #openstack-ansible | 13:49 | |
evrardjp | mhayden: I thought we couldn't install libselinux-python in venvs | 13:50 |
mhayden | we can install it on the host and link it in | 13:51 |
evrardjp | mhayden: what I mean is there is probably a file missing, or am I wrong? | 13:51 |
evrardjp | let me double check | 13:51 |
mhayden | it worked in my test in an aio | 13:52 |
evrardjp | mmm | 13:52 |
evrardjp | I think for a different reason | 13:52 |
mhayden | i'll go back and examine the venv to be sure | 13:52 |
evrardjp | I think the venv would have it | 13:52 |
*** cjloader has quit IRC | 13:53 | |
evrardjp | mmm let me think. I thought it would be using cache to get it and install it from site packages, but I don't think that would be the case after all | 13:53 |
*** aruns__ has joined #openstack-ansible | 13:53 | |
evrardjp | but am I tired? Where is tempest_install_python_libs.yml ? | 13:54 |
mhayden | ah crud, forgot to add it to the commit | 13:54 |
evrardjp | ok | 13:54 |
evrardjp | so now I understand better :) | 13:54 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-os_tempest master: Link SELinux python modules into tempest venv https://review.openstack.org/539257 | 13:54 |
evrardjp | that makes more sense :) | 13:55 |
mhayden | ah, there is a problem here | 13:56 |
* mhayden digs | 13:56 | |
*** aruns has quit IRC | 13:56 | |
*** kstev has joined #openstack-ansible | 13:57 | |
*** yolanda has quit IRC | 14:01 | |
*** santacloud__ has quit IRC | 14:01 | |
*** yolanda has joined #openstack-ansible | 14:03 | |
*** pcaruana has quit IRC | 14:05 | |
openstackgerrit | Andy McCrae proposed openstack/openstack-ansible stable/newton: Bump SHA for haproxy_server role https://review.openstack.org/539539 | 14:06 |
*** Taseer has joined #openstack-ansible | 14:08 | |
sxc731 | re: os_panko. If I wanted to take at stab at implementing this, what would be a good starting point? I guess os_gnocchi is similar enough? | 14:10 |
*** akasurde has joined #openstack-ansible | 14:11 | |
*** akasurde has joined #openstack-ansible | 14:11 | |
*** tobberydberg__ has joined #openstack-ansible | 14:15 | |
*** tobberydberg__ has quit IRC | 14:15 | |
*** tobberydberg__ has joined #openstack-ansible | 14:16 | |
bhujay | evrardjp, odyssey4me , CobHead lxc_hosts_opensuse_mirror_url: to a different mirror solved the problem . After overridde we have to run from setup-openstack-host so that the repo at base host also is updated. | 14:17 |
openstackgerrit | Merged openstack/openstack-ansible-repo_build master: Correct manifest index of openstack git folders https://review.openstack.org/537387 | 14:18 |
*** pcaruana has joined #openstack-ansible | 14:21 | |
*** sxc731_ has joined #openstack-ansible | 14:23 | |
*** mardim has quit IRC | 14:25 | |
*** sxc731_ has quit IRC | 14:28 | |
openstackgerrit | Maxime Guyot proposed openstack/openstack-ansible master: [WIP] Ceph RadosGW integration https://review.openstack.org/517856 | 14:29 |
*** esberglu has joined #openstack-ansible | 14:30 | |
odyssey4me | sxc, it's a little dated - but will serve as a good starting point I think | 14:32 |
odyssey4me | there are some finer points which we can work out in review | 14:32 |
evrardjp | odyssey4me: could you vote on https://review.openstack.org/#/c/539128/ ? | 14:32 |
odyssey4me | or patch after the initial set | 14:32 |
*** jwitko has joined #openstack-ansible | 14:32 | |
dcdamien | https://review.openstack.org/#/c/538056/ <- guys, can we discuss it? | 14:37 |
*** SerenaFeng has joined #openstack-ansible | 14:37 | |
*** santacloud has quit IRC | 14:37 | |
*** sxc731_ has joined #openstack-ansible | 14:38 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible master: Add SELinux python support to ansible-runtime venv https://review.openstack.org/539552 | 14:41 |
*** sxc731_ has quit IRC | 14:42 | |
mhayden | cloudnull: https://review.openstack.org/532863 is passing now! | 14:42 |
sxc731 | odyssey4me: thanks! Anything else I should use in preference? Seems there are common patterns - such as standing a mod_wsgi server - that could be factored as re-usable pieces (sorry not super-familiar with how this is done with Ansible. But happy to copy-paste if that's the accepted way | 14:43 |
xdfil | is there a summarized list of all the OSA roles to make it easier to clone them all? | 14:43 |
*** mardim has joined #openstack-ansible | 14:46 | |
*** sxc731_ has joined #openstack-ansible | 14:47 | |
*** cjloader has joined #openstack-ansible | 14:48 | |
sxc731 | xdfil: does ansible-role-requirements.yml fulfil that requirement? | 14:48 |
*** pcaruana has quit IRC | 14:48 | |
xdfil | sxc731: yeah, that will do | 14:49 |
xdfil | I've got a couple things I'm stuck on | 14:51 |
openstackgerrit | Periyasamy Palanisamy proposed openstack/openstack-ansible master: add networking-bgpvpn into openstack services https://review.openstack.org/539559 | 14:51 |
xdfil | my glance container doesn't mount NFS on reboot | 14:52 |
xdfil | I have to manually type mount -a | 14:52 |
evrardjp | odyssey4me: you got a patch yet for novnc? | 14:52 |
xdfil | and then it mounts | 14:52 |
evrardjp | and/or a bug reference? I think we might have that in our bugs let me check | 14:52 |
odyssey4me | evrardjp nope - working on an improvement which doesn't just fix the bug, but also makes it idempotent | 14:52 |
odyssey4me | working on it as we speak | 14:52 |
evrardjp | ok | 14:52 |
*** cjloader has quit IRC | 14:53 | |
*** sxc731 has quit IRC | 14:53 | |
evrardjp | hughsaunders: was the issue https://bugs.launchpad.net/openstack-ansible/+bug/1746523 linked to this issue? | 14:53 |
openstack | Launchpad bug 1746523 in openstack-ansible "Nova vnc proxy fails on redeploy" [Undecided,New] | 14:53 |
*** sxc731_ has quit IRC | 14:53 | |
*** aruns has joined #openstack-ansible | 14:54 | |
*** aruns__ has quit IRC | 14:55 | |
*** sxc731 has joined #openstack-ansible | 14:55 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible master: [WIP] Test CentOS 7 with package_state: present https://review.openstack.org/539561 | 14:56 |
xdfil | if I want to add/modify the bind mounts of a single container, how would I go about that? | 14:56 |
*** kstev has quit IRC | 14:58 | |
*** sxc731 has quit IRC | 14:59 | |
openstackgerrit | Periyasamy Palanisamy proposed openstack/openstack-ansible master: Make Opendaylight as the BGP speaker using Quagga https://review.openstack.org/523907 | 15:01 |
*** sxc731 has joined #openstack-ansible | 15:02 | |
xdfil | so lxc_container_bind_mounts looks promising | 15:04 |
xdfil | where would I define that exactly in the inventory? | 15:05 |
xdfil | I only want to do this for glance containers | 15:05 |
*** sxc731 has quit IRC | 15:05 | |
mgariepy | hmm. is there something funky about gerrit this morning ? i don't have the vote option in the reply... menu.. :S | 15:08 |
*** aruns has quit IRC | 15:09 | |
mgariepy | ha nevermind.. | 15:09 |
mgariepy | abandonned patch hehe | 15:09 |
xdfil | ahh glance_container_bind_mounts: | 15:10 |
hwoarang | does anyone know why this table is empty https://docs.openstack.org/openstack-ansible/latest/admin/troubleshooting.html#restarting-services ? :) | 15:10 |
*** sxc731 has joined #openstack-ansible | 15:11 | |
*** cmart has joined #openstack-ansible | 15:11 | |
*** pcaruana has joined #openstack-ansible | 15:14 | |
*** sxc731 has quit IRC | 15:14 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-os_nova master: Fix SELinux file contexts for nova's ssh keys https://review.openstack.org/534891 | 15:16 |
xdfil | Oh now... hold on a sec. If there is already a bind mount defined in group_vars for /var/lib/glance/images... could it be that it is over-writing the NFS mount from the container fstab | 15:16 |
xdfil | Lets find out! :) | 15:16 |
*** sxc731 has joined #openstack-ansible | 15:17 | |
cloudnull | mornings | 15:18 |
mhayden | evrardjp / mgariepy: trying to fix the selinux shenanigans in the venv -> https://review.openstack.org/#/c/539552/ | 15:19 |
mhayden | i forgot that tempest downloads on the host first and then ships the file out :/ | 15:19 |
cloudnull | mornings | 15:20 |
idlemind | odyssey4me no worries, it actually might be some more missing patches that should be cherry-picked into stable/pike related to the xinetd service for mysqlchk that's causing the error i'm seeing (mysql works but the check fails so haproxy marks it as down) | 15:20 |
idlemind | i'll be tidying up my notes from stumbling around the repo's last night and trying 1 or 2 patches | 15:20 |
idlemind | i'll post anything i find out | 15:20 |
*** kstev has joined #openstack-ansible | 15:21 | |
mgariepy | mhayden, did you try to symlink the directory ? | 15:23 |
mgariepy | instead of rsync | 15:23 |
*** ndusek has joined #openstack-ansible | 15:23 | |
ndusek | hey all - having some issues with networking on my osa aio deployment | 15:24 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible master: Add scaffolding for multiple container techs https://review.openstack.org/527749 | 15:25 |
mhayden | mgariepy: i tried, but the import failed | 15:25 |
mgariepy | ok | 15:25 |
mhayden | the rsync seems to work quite well | 15:26 |
mhayden | and it fixed the tempest stuff for sure | 15:26 |
odyssey4me | idlemind hmm, if haproxy is doing that then your ansible-role-requirements should have the right galera_server repo sha too, are you sure you executed bootstrap-ansible.sh after changing branch/tag ? | 15:26 |
mgariepy | here you go you get my vote :D | 15:26 |
*** Guest87240 is now known as mgagne | 15:27 | |
*** mgagne has joined #openstack-ansible | 15:27 | |
odyssey4me | xdfil you can implement any group_vars/host_vars of your own in /etc/openstack_deploy/{group_vars,host_vars} - those will get merged over the top of the defaults in the git tree | 15:28 |
xdfil | OMG, that was it! | 15:28 |
xdfil | so if you configure glance_nfs_client | 15:29 |
xdfil | you have to also add glance_container_bind_mounts: [] | 15:29 |
xdfil | otherwise the bind mount that is defined in group_vars will break the nfs mount | 15:29 |
mhayden | mgariepy: tu es le vent sous mes ailes, monsieur | 15:29 |
mgariepy | lol | 15:30 |
odyssey4me | xdfil honestly, that sounds like a bug - can you write it up in launchpad please? | 15:30 |
xdfil | yes sir | 15:30 |
odyssey4me | tyvm - good find! | 15:30 |
cloudnull | xdfil: ++ that sounds like a bug | 15:31 |
*** armaan has quit IRC | 15:32 | |
cloudnull | xdfil: is this master or pike ? | 15:32 |
xdfil | 16.0.6 | 15:32 |
*** woodard has quit IRC | 15:33 | |
*** tobberydberg has joined #openstack-ansible | 15:34 | |
*** armaan has joined #openstack-ansible | 15:34 | |
*** armaan has quit IRC | 15:34 | |
*** armaan has joined #openstack-ansible | 15:35 | |
cloudnull | xdfil: we did this in master. | 15:35 |
cloudnull | https://review.openstack.org/#/c/526930/ | 15:35 |
cloudnull | maybe it needs to be backported | 15:35 |
*** esberglu_ has joined #openstack-ansible | 15:36 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_glance stable/pike: Update glance NFS for systemd https://review.openstack.org/539577 | 15:39 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-openstack_hosts master: Use async distro package installation https://review.openstack.org/539578 | 15:39 |
cloudnull | xdfil: IDK if this is something we want to backport however if folks working on stable could take a look, it'd be appreciated. | 15:40 |
*** esberglu has quit IRC | 15:40 | |
*** phalmos has joined #openstack-ansible | 15:45 | |
*** flaviosr has quit IRC | 15:45 | |
idlemind | odyssey4me ya, it appears to be a bug that was fixed but not brought back to stable/pike | 15:45 |
odyssey4me | idlemind orly? | 15:46 |
*** flaviosr has joined #openstack-ansible | 15:47 | |
*** SerenaFeng has quit IRC | 15:47 | |
xdfil | cloudnull: so no bug report then? | 15:48 |
*** cjloader has joined #openstack-ansible | 15:48 | |
*** esberglu_ is now known as esberglu | 15:48 | |
cloudnull | no I think it's worth raising the issue | 15:49 |
cloudnull | it may very well still be a problem | 15:50 |
cloudnull | it's worth looking into | 15:50 |
cloudnull | IMHO | 15:50 |
*** bhujay has quit IRC | 15:50 | |
*** gkadam has quit IRC | 15:52 | |
*** cjloader has quit IRC | 15:53 | |
*** openstacking_123 has joined #openstack-ansible | 15:56 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_nova master: Improve console install and restart services appropriately https://review.openstack.org/539583 | 15:56 |
odyssey4me | evrardjp ^ that's the bug fix for the issue we found earlier today | 15:57 |
*** cjloader has joined #openstack-ansible | 16:08 | |
ndusek | running an all-in-one deployment and can't ping my instances. I can ping the router and can ping the internal net via `ip netns exec qrouter-UUID ...` but that's it | 16:09 |
ndusek | any suggestions on what to try next? | 16:09 |
lbragstad | ndusek: are you running with the defaults from an AIO? | 16:10 |
mbuil | ndusek: can you execute 'openstack network agent list'? | 16:11 |
mgariepy | ndusek, add a security rule to allow ping to get through ? | 16:11 |
*** phalmos has quit IRC | 16:11 | |
openstackgerrit | Merged openstack/openstack-ansible master: Unfreeze roles after milestone 3 https://review.openstack.org/539128 | 16:11 |
ndusek | yep, running with defaults | 16:11 |
ndusek | network agent list shows everything up | 16:12 |
lbragstad | mgariepy: that was going to be my next guess :) | 16:12 |
ndusek | I have a security group that allows icmp and tcp on port 22 for ssh | 16:12 |
ndusek | networks were set up using the openstack-ansible-ops repo | 16:13 |
lbragstad | i've had to tinker with security groups to get vm -> vm traffic working | 16:13 |
mbuil | ndusek: after pinging your VMs from the network namespace, if you run 'arp -na', can you see the MAC address of the VM? | 16:13 |
idlemind | i need help confirming if this commit (https://github.com/openstack/openstack-ansible-galera_server/commit/f2bfbd38513ac8d61ba4e02a4d5ef6cbbca259cc) is present in stable/pike ... i don't think it is. as soon as i made the change manually in my my.cnf of the galera container whalla my health checks stopped failing for galera in haproxy and confirmed by telnet | 16:14 |
ndusek | no, `arp -na` does not list a mac for the IP that I am pinging via the net ns | 16:15 |
idlemind | and os-keystone-install is moving along (past db errors i was hitting) as expected now | 16:16 |
mbuil | ndusek, when you are in the controller, can you list the processes and look for a dnsmasq process? | 16:17 |
idlemind | my checks on github show f2bfbd38513ac8d61ba4e02a4d5ef6cbbca259cc is missing from stable/pike ... we'll need that for a functional rhel (centos) install to get past any of the os-* plays that require db work (probably all) | 16:18 |
ndusek | yep, I see a couple of dnsmasq processes, one owned by lxc-dns+ and the other owned by nobody | 16:18 |
*** mamitchl has left #openstack-ansible | 16:18 | |
mbuil | ndusek: last week we fixed a bug. apparmor was breaking dnsmasq, just wanted to check if you were hitting it | 16:19 |
ndusek | mbuil: oh ok, I am running centos7 by the way | 16:20 |
mbuil | ndusek: can you check if your VMs got an IP lease in this log /var/log/neutron/neutron-dnsmasq.log? | 16:21 |
ndusek | mbuil: hmm, I don't have a log with that name | 16:21 |
*** woodard has joined #openstack-ansible | 16:23 | |
ndusek | mbuil: dhcp is enabled on the private subnet, but not on the public | 16:23 |
mbuil | ndusek: that's fine | 16:24 |
mbuil | Not sure what is going on, sorry :(. Can you access the VM through console and check if it got any IP? | 16:25 |
*** rstarmer has quit IRC | 16:27 | |
*** woodard has quit IRC | 16:27 | |
ndusek | mbuil: yeah, in the console logs, it shows eth0 being assigned the IP that openstack is giving it | 16:28 |
*** woodard has joined #openstack-ansible | 16:28 | |
ndusek | mbuil: but none of my VMs can hit the metadata service | 16:28 |
ndusek | and I can ping the router from both the controller node and a different physical non-openstack machine on the same network | 16:28 |
ndusek | so I'm wondering if the router is somehow misconfigured? do I need to add some routes to hit the different subnets? | 16:29 |
mbuil | ndusek: you should be able to ping the VM from the network namespace with or without a router. It is weird that you don't get the ARP resolution though | 16:31 |
mbuil | ndusek: I need to leave for a while, sorry | 16:31 |
ndusek | mbuil: no problem, thanks for your help though | 16:33 |
lbragstad | cloudnull: have you seen issues like that with your AIOs? ^ | 16:37 |
*** pcaruana has quit IRC | 16:39 | |
*** akasurde has quit IRC | 16:42 | |
idlemind | cloudnull odyssey4me another issue on centos7 from stable/pike of openstack-ansible https://bugs.launchpad.net/openstack-ansible/+bug/1746547 | 16:42 |
openstack | Launchpad bug 1746547 in openstack-ansible "stable/pike of openstack-ansible-galera_server fails haproxy health check on rhel7" [Undecided,New] | 16:42 |
odyssey4me | orly? I wonder if mhayden has seen that in his env? | 16:43 |
cloudnull | lbragstad: no i've not. | 16:43 |
cloudnull | in our normal AIO we test VMs via tempest | 16:43 |
cloudnull | and we enable the basic ops test | 16:44 |
cloudnull | which would mean the VMs would have to get meta-data | 16:44 |
lbragstad | huh - interesting | 16:45 |
lbragstad | i wonder if it is hardware specific | 16:52 |
ndusek | I am running on some pretty old hardware | 16:53 |
ndusek | I might just try on some VMs and see if I have the same issues | 16:53 |
*** chyka has joined #openstack-ansible | 16:54 | |
*** SerenaFeng has joined #openstack-ansible | 16:55 | |
*** rstarmer has joined #openstack-ansible | 16:56 | |
idlemind | i'm puzzled how stable/pike isn't failing gate checks or is that not checked per commit (or is centos7 not a voting platform) | 16:56 |
peri | hi, i'm trying to setup a container using osa lxc-hosts and lxc_container_create roles, but the following error is throws while executing TASK [lxc_hosts : Place container metadata] | 16:59 |
peri | "msg": "Failed to find handler for \"/tmp/meta.tar.xz\". Make sure the required command to extract the file is installed. Command \"/bin/tar\" could not handle archive. Command \"/usr/bin/unzip\" could not handle archive." | 16:59 |
peri | i do have unzip installed on the host | 17:00 |
peri | hwoarang^ fdegir^ | 17:01 |
openstackgerrit | Marc Gariépy (mgariepy) proposed openstack/openstack-ansible-galera_server stable/pike: Fix Galera socket for RedHat https://review.openstack.org/539601 | 17:02 |
mgariepy | the backport has been forgotten.. | 17:03 |
idlemind | mgariepy np i figured that happens a lot ... seems maybe running master might be safer than stable/pike lol | 17:04 |
idlemind | worst case i find the bugs and report 'em | 17:04 |
idlemind | and we're all better off | 17:04 |
mgariepy | well mhayden is running master i think | 17:05 |
idlemind | #brave | 17:06 |
*** ndusek has quit IRC | 17:06 | |
mgariepy | haha | 17:06 |
mgariepy | yep | 17:06 |
mgariepy | mhayden, how often to you upgrade ? | 17:06 |
idlemind | also, w/the pull into the specific repo of stable/pike do you have submit a second change to update the hashs in openstack-ansible proper? | 17:06 |
idlemind | (segway) | 17:07 |
*** phalmos has joined #openstack-ansible | 17:08 | |
mgariepy | idlemind, https://github.com/openstack/openstack-ansible/blob/stable/pike/ansible-role-requirements.yml | 17:09 |
mgariepy | you can either change the sha in that file on your server then re-run the bootstrap-ansible.sh | 17:10 |
mgariepy | or update manually the /etc/ansible/roles/galera_server with the cherry-pick of the correct patch | 17:10 |
idlemind | right that's the file but it would seem like the change you submited to update stable/pike of the underlying role (openstack-ansible-galera_server) a sister change should be to update the sha in openstack-ansible (*requirements.yml) so that any new pulls of openstack-ansible on a "fresh" basis get the fix for themselves | 17:11 |
*** indistylo has joined #openstack-ansible | 17:11 | |
odyssey4me | idlemind ye, that can only be done once the role patch merges | 17:11 |
idlemind | ahh | 17:11 |
mgariepy | once it's merged we can update the patch is merged. | 17:11 |
idlemind | sure makes sense | 17:11 |
idlemind | otherwise you won't have the new sha w/o the merge | 17:12 |
idlemind | i know it seems like housekeeping stuff which is always not fun | 17:12 |
odyssey4me | yep, we bump the sha's every two weeks as a routine, to give a two week period of testing whatever's changed | 17:13 |
odyssey4me | that gives enough time to detect new issues, get them resolved, etc | 17:13 |
idlemind | to make sure the person that pulled the fix like this galera issue or the lxc-hosts issue i found and cherry-picked don't cause knock-on issues | 17:14 |
odyssey4me | yep, that's the idea | 17:14 |
idlemind | is that mass hash-update then gated to ensure it produces a valid build? | 17:14 |
odyssey4me | it doesn't always work out, but it does help limit the effects of new patches being merged which cause knock-on effect most often | 17:14 |
odyssey4me | yep, nothing changes in a repo without passing tests twice in a row | 17:15 |
odyssey4me | the only trouble for centos is that it's too slow to gate the integrated build, so it's only tested in daily tests | 17:15 |
odyssey4me | so sometimes things fall through the cracks | 17:15 |
mhayden | idlemind: i did see a healthcheck failure, but it's not centos related | 17:16 |
*** phalmos has quit IRC | 17:16 | |
mhayden | IIRC | 17:16 |
mhayden | you have to specify the addresses that are okay for haproxy to use to talk to xtrabackup | 17:16 |
mhayden | via xinetd | 17:16 |
odyssey4me | our ubuntu integrated build tests run from 60-90 mins, centos runs more like 3 hours IIRC | 17:16 |
mhayden | odyssey4me: it's about 1 hr 45 on a Rax cloud perf1-8 | 17:16 |
* mhayden is still trying to figure out what makes centos so slow in the gate | 17:17 | |
mhayden | some of it is the package manager differences -- yum + apt operate differently | 17:17 |
idlemind | wow ya seems odd for such a significant difference that said i can totally agree my centos build process is pretty slow overall lol | 17:17 |
*** cjloader has quit IRC | 17:17 | |
odyssey4me | sure, and for ubuntu we use an infra mariadb mirror - whereas for centos/suse I don't think that's being done | 17:17 |
*** cjloader has joined #openstack-ansible | 17:18 | |
odyssey4me | given that galera_client is installed almost everywhere, I expect that slows things down a bit | 17:18 |
mhayden | that one does take a lot | 17:18 |
mhayden | os_nova takes ~ 6 minutes to install distro pkgs on centos :/ | 17:18 |
mgariepy | arent the pkg cached in the repo server ? | 17:18 |
idlemind | could be a difference in what the package is doing compared to the ubuntu one tho | 17:19 |
mhayden | mgariepy: well, those pkgs aren't cached yet | 17:19 |
idlemind | ahh | 17:19 |
mhayden | since most of them are first seen when os_nova installs | 17:19 |
*** rstarmer has quit IRC | 17:19 | |
idlemind | so the first hit to install doesn't get cached and the cache doesn't provide any benefit to a single install of nova only on additional hosts | 17:19 |
odyssey4me | I'm still thinking that some fundamental changes in how we do the deployment is really the only way to get that resolved - hence https://github.com/openstack/openstack-ansible-specs/blob/master/specs/queens/python-build-install-simplification.rst and https://github.com/openstack/openstack-ansible-specs/blob/master/specs/queens/deployment-stages.rst which unfortunately I've not managed to make enough time to progress as far as I'd have | 17:19 |
odyssey4me | liked... so it'll have to wait for the next cycle | 17:19 |
*** pbandark has quit IRC | 17:20 | |
idlemind | speaking of nova ... that's where my install is at for the moment :) 49:15.614 of setup-openstack.yml | 17:20 |
mhayden | but it's weird, because for nova, if you consider the 6 minutes eaten up by distro package install, the actual *install* process takes < 10 sec | 17:22 |
mhayden | which makes me think it's the downloading that is painful | 17:22 |
odyssey4me | doing the deploy in stages would also mean we could pre-stage all the software in parallel, then execute the service configs in serial... rather than doing it all in serial as it does now (to make upgrades safer and less disruptive). | 17:22 |
odyssey4me | wow, that's weird - because in the gate those downloads are from a local mirror - or should be | 17:22 |
mhayden | true | 17:23 |
mhayden | more things i'd like to poke at :/ | 17:23 |
odyssey4me | mhayden did ja break it all again? http://logs.openstack.org/83/539583/1/check/openstack-ansible-functional-centos-7/4278647/logs/ara/result/e6e50287-48c4-433e-b510-c7d2e581a1cc/ | 17:24 |
mhayden | sigh, i'll go back and look again | 17:26 |
* mhayden has too many irons in the fire | 17:26 | |
*** SerenaFeng has quit IRC | 17:30 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-repo_build stable/pike: Correct manifest index of openstack git folders https://review.openstack.org/539611 | 17:32 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-repo_build stable/pike: Correct manifest index of openstack git folders https://review.openstack.org/539611 | 17:32 |
openstackgerrit | Jimmy McCrory proposed openstack/openstack-ansible-rsyslog_client master: Correct task tag https://review.openstack.org/539614 | 17:34 |
*** rstarmer has joined #openstack-ansible | 17:35 | |
*** rstarmer has quit IRC | 17:39 | |
openstackgerrit | Merged openstack/openstack-ansible-galera_server stable/pike: Zuul: Remove project name https://review.openstack.org/538889 | 17:41 |
*** zenirc369 has joined #openstack-ansible | 17:42 | |
*** ivve has quit IRC | 17:50 | |
idlemind | side-note ... i wonder if this makes more sense to use than the clustercheck script via xinet.d ... https://github.com/leoleovich/clusterhc | 18:01 |
idlemind | (galera_server) | 18:02 |
*** ivve has joined #openstack-ansible | 18:02 | |
*** peri has quit IRC | 18:07 | |
openstackgerrit | Merged openstack/openstack-ansible-ops master: Uses a dedicated telegraf role https://review.openstack.org/524593 | 18:08 |
openstackgerrit | Merged openstack/openstack-ansible-ops master: Updates the last update date https://review.openstack.org/524594 | 18:08 |
*** woodard has quit IRC | 18:10 | |
*** woodard has joined #openstack-ansible | 18:11 | |
*** mbuil has quit IRC | 18:12 | |
*** indistylo has quit IRC | 18:17 | |
*** rstarmer has joined #openstack-ansible | 18:20 | |
*** phalmos has joined #openstack-ansible | 18:24 | |
*** mbuil has joined #openstack-ansible | 18:28 | |
openstackgerrit | James E. Blair proposed openstack/openstack-ansible-os_monasca-agent master: Zuul: Remove project name https://review.openstack.org/539629 | 18:28 |
idlemind | i wonder if part of the problem w/yum caching is that apt-cacher-ng only grabs it for each mirror that is requested so when using fastestmirror at various times you might get a new mirror and the proxy has to cache that package for that proxy ... maybe disabling fastestmirror might help or possibly there is a way to tell apt-cacher-ng to rewrite all centos requests to a standard directory? | 18:35 |
mgariepy | idlemind, there is | 18:37 |
mgariepy | i though we already did that tho. | 18:37 |
idlemind | Ya, it looks that way. the extra entries seem to be mirror specific repodata for epel | 18:38 |
idlemind | (in my case) | 18:38 |
idlemind | so false alarm there | 18:38 |
*** pbandark has joined #openstack-ansible | 18:39 | |
idlemind | sigh ... error on image upload after setup-openstack ... i seem to remember an issue w/horizon configuration in stable/pike back in the day ... time to fish that one out | 18:41 |
mgariepy | idlemind, first try cli to filter out glace | 18:44 |
mgariepy | idlemind, first try cli to filter out glance** | 18:44 |
idlemind | ya i'll re-verify that | 18:44 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-os_neutron master: Fix SELinux policy filenames https://review.openstack.org/539635 | 18:46 |
*** peri has joined #openstack-ansible | 18:48 | |
*** germs has joined #openstack-ansible | 18:52 | |
*** openstacking_123 has quit IRC | 18:52 | |
*** shardy has quit IRC | 18:53 | |
*** peri has quit IRC | 18:58 | |
evrardjp | odyssey4me: just reviewed | 19:02 |
*** sxc731 has quit IRC | 19:07 | |
*** poopcat has joined #openstack-ansible | 19:08 | |
*** tobberydberg__ has quit IRC | 19:14 | |
*** tobberydberg__ has joined #openstack-ansible | 19:15 | |
*** tobberydberg__ has quit IRC | 19:19 | |
idlemind | odyssey4me changing HORIZON_IMAGES_UPLOAD_MODE to 'legacy' in horizon's local_settings.py allowed the upload to start without an error and upload ... seems to be this bug: https://bugs.launchpad.net/openstack-ansible/+bug/1639080 | 19:22 |
openstack | Launchpad bug 1639080 in OpenStack Dashboard (Horizon) "Image uploads fail in Horizon if upload mode is set to direct if endpoint set to internal." [Medium,Fix released] - Assigned to Paulo Matias (paulo-matias) | 19:22 |
idlemind | looking at commit history to see if there might be something to it | 19:22 |
idlemind | yup that's the bug affecting whatever commit is in stable/pike of openstack-ansible for openstack-ansible-os_horizon ... i'll dig some more | 19:23 |
mgariepy | shiny : http://paste.openstack.org/show/658219/ :D | 19:26 |
idlemind | mgariepy i'll take that off your hands | 19:27 |
mgariepy | it will be taken off my hand soon enough :P | 19:27 |
idlemind | so you got my address and packing slip excellent | 19:28 |
*** stuartgr has quit IRC | 19:29 | |
mgariepy | the sad part is : no nvme in it ;( | 19:33 |
*** cjloader has quit IRC | 19:33 | |
*** rstarmer has quit IRC | 19:38 | |
*** tobberydberg__ has joined #openstack-ansible | 19:53 | |
ivve | idlemind: running ceph? | 19:54 |
idlemind | ivve nope just good ole lvm atm | 19:54 |
idlemind | ceph eventually | 19:54 |
*** tobberydberg__ has quit IRC | 19:54 | |
ivve | ok, you'll run into the same thing with ceph | 19:55 |
ivve | legacy works, direct not so much | 19:55 |
*** tobberydberg__ has joined #openstack-ansible | 19:55 | |
idlemind | ya it seems like a bug ... horizon/glance uploading images should just work out of the box | 19:55 |
idlemind | hence the launchpad report | 19:55 |
ivve | aye | 19:55 |
idlemind | just not sure how that one gets solved in stable/pike | 19:55 |
idlemind | need the masters to look at it and see how to tackle | 19:55 |
ivve | its been like that since mitaka | 19:55 |
ivve | i have one more thing that i change as well | 19:56 |
ivve | sec | 19:56 |
idlemind | in the mean time the last thing i have to figure out is what's going on w/attaching volumes to instances and i'll have an operable cloud | 19:56 |
ivve | i think its image_allow_location | 19:57 |
idlemind | ya right now that's False on mine i think that toggles url based loading right? | 19:57 |
ivve | aye | 19:57 |
ivve | image_allow_location = true instead of false | 19:57 |
idlemind | it seems stable/pike has that part fixed so you can override that in user_config.yml now | 19:58 |
idlemind | i didn't try though | 19:58 |
ivve | oh really? | 19:58 |
idlemind | ya seems the patches for it have wondered in | 19:58 |
idlemind | * wandered into the branch | 19:58 |
ivve | its been a requested feature to be able to do overrides in local_settings.py | 19:58 |
ivve | :) | 19:58 |
ivve | well i've learned to fix that post deploy/post running horizon playbooks for upgrades/changes | 19:59 |
ivve | maybe no more! | 20:00 |
idlemind | or at least 1 less thing to manually do | 20:00 |
ivve | aye | 20:02 |
ivve | you don't happen to know anything about nested heat stacks? | 20:02 |
*** armaan has quit IRC | 20:02 | |
ivve | as in multiple resources inside a resourcegroup / autoscalinggroup | 20:03 |
idlemind | negative cap'n | 20:03 |
*** armaan has joined #openstack-ansible | 20:03 | |
*** mbuil has quit IRC | 20:03 | |
ivve | seems like a tough topic | 20:04 |
ivve | although i don't understand why not everybody wants to use it :) | 20:04 |
idlemind | i want to get there | 20:04 |
idlemind | have to get deployments squared away first | 20:05 |
ivve | check | 20:05 |
ivve | btw i would recommend running ubuntu, i have done some deployment on centos. not so much fun :P | 20:06 |
idlemind | lol ya centos is proving to be a challenge lol | 20:06 |
ivve | i had to do a FEW modifications | 20:06 |
idlemind | but actually not too bad; once i get this lvm thing figured out i'm sure i'll be up and running at least until i move to ceph | 20:06 |
ivve | pretty much not possible to use playbooks to upgrade... at least with the setups i tried | 20:07 |
idlemind | thankfully cloudnull odyssey4me and a few others promptly proposed review's to get the stuff going | 20:07 |
ivve | aye they are great guys :) | 20:07 |
ivve | but i think the problem is the general support centos gets | 20:07 |
*** sxc731 has joined #openstack-ansible | 20:09 | |
ivve | the osa is an amazing clockwork | 20:09 |
mgariepy | the more user there will on centos the better it will get. | 20:16 |
mgariepy | i've working on it a lot on past cycle, but right now I have other stuff to focus on, I have a couple colleague that should deploy centos for prod on pike ""soonish"". | 20:17 |
mgariepy | http://paste.openstack.org/show/658229/ << that took a long time. | 20:27 |
*** chyka has quit IRC | 20:29 | |
openstackgerrit | James E. Blair proposed openstack/openstack-ansible-ceph_client master: Zuul: Remove project name https://review.openstack.org/539672 | 20:29 |
*** chyka has joined #openstack-ansible | 20:30 | |
*** hw_wutianwei has quit IRC | 20:31 | |
*** chyka_ has joined #openstack-ansible | 20:33 | |
*** chyka has quit IRC | 20:34 | |
*** chyka_ has quit IRC | 20:42 | |
*** chyka has joined #openstack-ansible | 20:42 | |
*** ivve has quit IRC | 20:46 | |
*** chyka has quit IRC | 20:48 | |
*** chyka has joined #openstack-ansible | 20:49 | |
*** DanyC has joined #openstack-ansible | 20:51 | |
idlemind | woot well neutron works and i can get access to vms via qinq over my br-vlan so that's fun | 20:52 |
idlemind | k now to cinder / lvm / iscsi boring ness | 20:52 |
*** tobberydberg__ has quit IRC | 20:58 | |
*** tobberydberg__ has joined #openstack-ansible | 20:58 | |
*** zenirc369 has quit IRC | 20:59 | |
*** hybridpollo has joined #openstack-ansible | 21:07 | |
*** armaan has quit IRC | 21:07 | |
*** tobberydberg__ has quit IRC | 21:08 | |
mhayden | ah, so i'm making progress on centos slowness with os_nova | 21:08 |
*** tobberydberg__ has joined #openstack-ansible | 21:08 | |
mhayden | the package install is slowed a bunch by the container-selinux and openstack-selinux packages | 21:08 |
idlemind | 3 cheers | 21:08 |
mhayden | i need to see what policies we have in there | 21:08 |
mhayden | because we may not need it with the way we deploy openstack | 21:09 |
*** ivve has joined #openstack-ansible | 21:13 | |
idlemind | anyone familiar with using cinder lvm on a basic one node host? | 21:15 |
*** rstarmer has joined #openstack-ansible | 21:16 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-os_nova master: Remove openstack-selinux package from os_nova https://review.openstack.org/539688 | 21:19 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-os_neutron master: [TEST] Test os_neutron with SELinux enforcing https://review.openstack.org/539690 | 21:23 |
mhayden | mgariepy / cloudnull: if y'all are around -> https://review.openstack.org/539635 | 21:26 |
mhayden | that will help clean up my mess ;) | 21:26 |
*** sxc731 has quit IRC | 21:30 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-os_nova master: Fix SELinux file contexts for nova's ssh keys https://review.openstack.org/534891 | 21:32 |
*** rstarmer has quit IRC | 21:34 | |
*** poopcat1 has joined #openstack-ansible | 21:40 | |
*** poopcat has quit IRC | 21:40 | |
idlemind | hmmm might be selinux messing w/me iscsiadm is complaining but works fine locally | 21:42 |
idlemind | as root | 21:42 |
*** mamitchl has joined #openstack-ansible | 21:43 | |
idlemind | https://imgur.com/a/zAbnl | 21:47 |
idlemind | not sure where you'd put a fix for selinux and cinder ... is that typically part of the openstack-ansible-os_* part or in the upstream item? | 21:53 |
*** rstarmer has joined #openstack-ansible | 21:56 | |
idlemind | turning off selinux let me mount a volume | 21:57 |
openstackgerrit | Shannon Mitchell proposed openstack/openstack-ansible-ops master: Fixed Suse Image to use link without build information https://review.openstack.org/539699 | 21:57 |
*** pbandark has quit IRC | 21:58 | |
idlemind | (side-note) rsyslogd is complaining in the selinux audit.log too so i'll learn more about that soon (tm) i'm sure | 21:58 |
idlemind | for now selinux is off | 21:58 |
*** armaan has joined #openstack-ansible | 21:59 | |
*** woodard has quit IRC | 22:06 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-os_neutron master: [TEST] Test os_neutron with SELinux enforcing https://review.openstack.org/539690 | 22:12 |
*** kstev has quit IRC | 22:18 | |
mhayden | idlemind: typically we put those into the cinder role itself | 22:28 |
mhayden | idlemind: if you're doing pike/master, i'd recommend putting selinux into permissive for now | 22:28 |
* mhayden is still hacking through selinux policies | 22:28 | |
idlemind | mhayden you mean the openstack-ansible-os_cinder role right? and ya i'm stable/pike of openstack-ansible but i scanned master and didn't see anything selinux related so it's probably a new thing for the cinder role | 22:32 |
mhayden | right | 22:32 |
mhayden | i'd like to start tracking AVC's in the gate jobs, but i've gotta finish stabilizing centos 7 first :/ | 22:32 |
idlemind | lol i feel ya | 22:33 |
mhayden | there are very few of us insterested in that work ;) | 22:33 |
idlemind | i was seeing rsyslogd selinux errors as well for the metal neutron and nova logs so more fun there too | 22:33 |
prometheanfire | evrardjp: sure you want to jump on that grenade? | 22:41 |
evrardjp | which one? | 22:41 |
prometheanfire | evrardjp: ptl | 22:42 |
evrardjp | I have the impression I got a few ones in my belly already :p | 22:42 |
evrardjp | haha | 22:42 |
prometheanfire | fair enough | 22:42 |
evrardjp | yeah, I have endured the pain, I am ready now. | 22:42 |
evrardjp | :d | 22:42 |
prometheanfire | :D | 22:42 |
evrardjp | you? | 22:42 |
prometheanfire | ya, I'm sending it friday (by my current schedule) though may have time tonight | 22:42 |
evrardjp | so you're ready for that grenade too then? :p | 22:45 |
idlemind | mhayden are their others than neutron that i could look at for how you did the selinux work? | 22:46 |
idlemind | neutron scares me | 22:46 |
mhayden | i did that recently and i have a patch in the works to fix my horrible file naming | 22:47 |
mhayden | idlemind: https://github.com/openstack/openstack-ansible-os_neutron/commit/261a789342a4f33542de7d1336807141f30e5d94 | 22:47 |
*** jwitko has quit IRC | 22:48 | |
mhayden | there is some simpler stuff for nova -> https://review.openstack.org/#/c/534891/8/tasks/nova_selinux.yml | 22:48 |
prometheanfire | evrardjp: I'm juggling at least two | 22:49 |
mhayden | sometimes you can write a file context rule and be done with it | 22:49 |
idlemind | sweet i'll start safely with nova see if i can make any sense of it | 22:49 |
mhayden | but sometimes you need new policy | 22:49 |
prometheanfire | gentoo foundation presidency and reqs | 22:49 |
prometheanfire | I'm up for election there too in july (if I run) | 22:49 |
*** woodard has joined #openstack-ansible | 22:49 | |
*** woodard has quit IRC | 22:51 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-os_neutron master: [TEST] Test os_neutron with SELinux enforcing https://review.openstack.org/539690 | 22:53 |
evrardjp | prometheanfire: oh interesting | 22:58 |
prometheanfire | two year terms there | 22:58 |
prometheanfire | bigger grenade too, way more politics | 22:58 |
evrardjp | you have more time to do things. | 22:58 |
evrardjp | yeah | 22:58 |
prometheanfire | recently it's just been trying to get the foundation (admin side) and council (tech side) to work together. | 22:59 |
idlemind | selinux is something i have to more firmly master myself like when to just change the context of a file or when you create a module to encompass the needed items and that kind of stuff | 22:59 |
*** guhcampos has joined #openstack-ansible | 22:59 | |
prometheanfire | selinux is fun, I'd recommend swift's books (sven's) | 23:01 |
prometheanfire | https://www.amazon.com/SELinux-System-Administration-Sven-Vermeulen-ebook/dp/B01LWM02WI and https://www.amazon.com/SELinux-Cookbook-Sven-Vermeulen-ebook/dp/B00NVDAWII | 23:02 |
*** esberglu has quit IRC | 23:07 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-lxc_hosts master: Install SELinux packages asynchronously https://review.openstack.org/539724 | 23:08 |
evrardjp | interesting books. So many books, so little time | 23:11 |
prometheanfire | he's a fellow belgian too | 23:13 |
evrardjp | mhayden: could you vote on this please? https://review.openstack.org/#/c/536372/ | 23:13 |
evrardjp | his name rings me a bell | 23:14 |
evrardjp | maybe I have met him in a meetup | 23:14 |
*** phalmos has quit IRC | 23:14 | |
prometheanfire | used to work for a bank or something, not sure now | 23:16 |
idlemind | oh nice thx for the links | 23:17 |
idlemind | ya i get the purpose for and totally would prefer apps work w/selinux than the cop out of just disabling | 23:17 |
evrardjp | prometheanfire: yeah | 23:20 |
evrardjp | KBC | 23:20 |
evrardjp | idlemind: every time you disable selinux, a mhayden cries. | 23:20 |
evrardjp | :D | 23:22 |
idlemind | lol that should be a t-shirt | 23:22 |
*** rstarmer has quit IRC | 23:24 | |
evrardjp | He has tshirts about selinux, it's not a joke! :D | 23:25 |
evrardjp | ahah | 23:25 |
*** john51 has quit IRC | 23:26 | |
prometheanfire | I bought some :P | 23:26 |
prometheanfire | ok, really leaving now :P | 23:27 |
idlemind | ubuntu's cloud image ... 257 mb ... centos cloud image 837 mb | 23:28 |
idlemind | #winning | 23:28 |
evrardjp | OH | 23:28 |
evrardjp | that's interesting. | 23:28 |
evrardjp | that could also be the cause of slow gates. | 23:29 |
evrardjp | idlemind: thanks I completely forgot that! | 23:29 |
idlemind | slowing down storage | 23:29 |
idlemind | np i just noticed cuz i'm loadin' my cloud up w/some images to play with | 23:29 |
evrardjp | well, what I mean is that you give us an idea of optimization... | 23:30 |
evrardjp | :D | 23:30 |
idlemind | format c: | 23:30 |
idlemind | ? | 23:30 |
evrardjp | omg, that command ! | 23:31 |
evrardjp | from my far past. | 23:31 |
evrardjp | :D | 23:31 |
*** john51 has joined #openstack-ansible | 23:33 | |
openstackgerrit | Shannon Mitchell proposed openstack/openstack-ansible-ops master: Fix openstack-service-setup.yml GATEWAY_NETWORK to match the flat network. https://review.openstack.org/539730 | 23:36 |
*** rstarmer has joined #openstack-ansible | 23:37 | |
*** zenirc369 has joined #openstack-ansible | 23:40 | |
*** john51 has quit IRC | 23:43 | |
*** john51 has joined #openstack-ansible | 23:45 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!