*** cshen has joined #openstack-ansible | 00:07 | |
*** macza has quit IRC | 00:08 | |
*** Jeffrey4l has joined #openstack-ansible | 00:08 | |
*** cshen has quit IRC | 00:13 | |
*** dcdamien has quit IRC | 00:14 | |
openstackgerrit | Merged openstack/openstack-ansible-nspawn_hosts master: Use libeatmydata during nspawn cache prep https://review.openstack.org/627815 | 00:15 |
---|---|---|
*** jawad_axd has joined #openstack-ansible | 00:24 | |
*** jawad_axd has quit IRC | 00:29 | |
*** cshen has joined #openstack-ansible | 00:33 | |
*** cshen has quit IRC | 00:39 | |
openstackgerrit | Antony Messerli proposed openstack/openstack-ansible stable/rocky: Bump rabbitmq_server SHA to include upgrade fix https://review.openstack.org/628073 | 00:43 |
*** jawad_axd has joined #openstack-ansible | 00:45 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-ops master: Convert template setup to a role https://review.openstack.org/628074 | 00:45 |
*** jawad_axd has quit IRC | 00:49 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-ops master: Convert template setup to a role https://review.openstack.org/628074 | 01:02 |
*** jawad_axd has joined #openstack-ansible | 01:06 | |
*** tosky has quit IRC | 01:06 | |
*** jawad_axd has quit IRC | 01:10 | |
*** dave-mccowan has quit IRC | 01:23 | |
*** cshen has joined #openstack-ansible | 01:24 | |
*** markvoelker has quit IRC | 01:26 | |
*** markvoelker has joined #openstack-ansible | 01:26 | |
*** cshen has quit IRC | 01:29 | |
*** markvoelker has quit IRC | 01:31 | |
*** cshen has joined #openstack-ansible | 01:34 | |
*** macza has joined #openstack-ansible | 01:39 | |
*** cshen has quit IRC | 01:42 | |
openstackgerrit | zhouxinyong proposed openstack/ansible-config_template master: Add bugs url link to README.rst https://review.openstack.org/628077 | 01:50 |
openstackgerrit | zhouxinyong proposed openstack/openstack-ansible-ceph_client master: Fix README.rst https://review.openstack.org/628078 | 02:06 |
openstackgerrit | zhouxinyong proposed openstack/openstack-ansible-lxc_container_create master: Add bugs url link to README.rst https://review.openstack.org/628079 | 02:08 |
openstackgerrit | zhouxinyong proposed openstack/openstack-ansible-openstack_openrc master: Add bugs url link to README.rst https://review.openstack.org/628080 | 02:09 |
openstackgerrit | zhouxinyong proposed openstack/openstack-ansible-os_almanach master: Add bugs url link to README.rst https://review.openstack.org/628081 | 02:11 |
openstackgerrit | zhouxinyong proposed openstack/openstack-ansible-os_barbican master: Fix README.rst https://review.openstack.org/628082 | 02:12 |
openstackgerrit | zhouxinyong proposed openstack/openstack-ansible-os_manila master: Add bugs url link to README.rst https://review.openstack.org/628083 | 02:14 |
openstackgerrit | zhouxinyong proposed openstack/openstack-ansible-os_molteniron master: Fix README.rst https://review.openstack.org/628084 | 02:15 |
openstackgerrit | zhouxinyong proposed openstack/openstack-ansible-os_neutron master: Fix README.rst https://review.openstack.org/628085 | 02:17 |
openstackgerrit | zhouxinyong proposed openstack/openstack-ansible-os_placement master: Add bugs url link to README.rst https://review.openstack.org/628086 | 02:18 |
openstackgerrit | zhouxinyong proposed openstack/openstack-ansible-os_tempest master: Add bugs url link to README.rst https://review.openstack.org/628087 | 02:20 |
openstackgerrit | zhouxinyong proposed openstack/openstack-ansible-plugins master: Fix README.rst https://review.openstack.org/628088 | 02:21 |
openstackgerrit | zhouxinyong proposed openstack/openstack-ansible-rabbitmq_server master: Add bugs url link to README.rst https://review.openstack.org/628089 | 02:23 |
openstackgerrit | zhouxinyong proposed openstack/openstack-ansible-repo_build master: Add bugs url link to README.rst https://review.openstack.org/628090 | 02:24 |
openstackgerrit | zhouxinyong proposed openstack/openstack-ansible-tests master: Fix README.rst https://review.openstack.org/628091 | 02:26 |
*** markvoelker has joined #openstack-ansible | 02:27 | |
*** jawad_axd has joined #openstack-ansible | 02:28 | |
*** jawad_axd has quit IRC | 02:33 | |
*** cshen has joined #openstack-ansible | 02:38 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-ops master: Convert template setup to a role https://review.openstack.org/628074 | 02:38 |
*** cshen has quit IRC | 02:44 | |
*** markvoelker has quit IRC | 02:50 | |
*** markvoelker has joined #openstack-ansible | 02:50 | |
*** cshen has joined #openstack-ansible | 03:16 | |
*** cshen has quit IRC | 03:26 | |
openstackgerrit | Merged openstack/openstack-ansible-ops master: Convert template setup to a role https://review.openstack.org/628074 | 04:16 |
*** chhagarw has joined #openstack-ansible | 04:30 | |
*** udesale has joined #openstack-ansible | 04:36 | |
*** markvoelker has quit IRC | 05:17 | |
*** DanyC has quit IRC | 05:20 | |
*** cshen has joined #openstack-ansible | 05:23 | |
*** macza has quit IRC | 05:27 | |
*** cshen has quit IRC | 05:28 | |
*** macza has joined #openstack-ansible | 05:31 | |
*** radeks__ has joined #openstack-ansible | 05:33 | |
*** macza has quit IRC | 05:38 | |
*** macza has joined #openstack-ansible | 05:47 | |
*** markvoelker has joined #openstack-ansible | 05:49 | |
*** shyamb has joined #openstack-ansible | 05:51 | |
*** macza has quit IRC | 05:56 | |
*** shyamb has quit IRC | 05:58 | |
*** cshen has joined #openstack-ansible | 06:08 | |
*** shyamb has joined #openstack-ansible | 06:16 | |
*** cshen has quit IRC | 06:22 | |
*** markvoelker has quit IRC | 06:22 | |
*** markvoelker has joined #openstack-ansible | 06:23 | |
*** macza has joined #openstack-ansible | 06:25 | |
*** markvoelker has quit IRC | 06:27 | |
*** macza has quit IRC | 06:30 | |
*** udesale has quit IRC | 06:33 | |
*** udesale has joined #openstack-ansible | 06:34 | |
*** macza has joined #openstack-ansible | 06:41 | |
*** fatdragon has quit IRC | 06:47 | |
*** fatdragon has joined #openstack-ansible | 06:48 | |
*** macza has quit IRC | 06:51 | |
*** fatdragon has quit IRC | 06:53 | |
*** shyamb has quit IRC | 07:06 | |
*** jawad_axd has joined #openstack-ansible | 07:13 | |
*** cshen has joined #openstack-ansible | 07:15 | |
*** shyamb has joined #openstack-ansible | 07:22 | |
fnpanic | hi | 07:37 |
openstackgerrit | Chandan Kumar proposed openstack/openstack-ansible-os_tempest master: Use tempest_tempestconf_profile for handling named args https://review.openstack.org/623187 | 07:42 |
*** hwoarang has quit IRC | 07:47 | |
*** hwoarang has joined #openstack-ansible | 07:50 | |
*** luksky has joined #openstack-ansible | 08:02 | |
*** radeks_ has joined #openstack-ansible | 08:03 | |
*** wattage has quit IRC | 08:04 | |
*** radeks__ has quit IRC | 08:06 | |
*** shyamb has quit IRC | 08:12 | |
*** kopecmartin|off is now known as kopecmartin | 08:16 | |
*** cshen has quit IRC | 08:19 | |
*** markvoelker has joined #openstack-ansible | 08:23 | |
*** tosky has joined #openstack-ansible | 08:27 | |
*** chhagarw has quit IRC | 08:34 | |
*** cshen has joined #openstack-ansible | 08:48 | |
*** shyamb has joined #openstack-ansible | 08:51 | |
*** cshen has quit IRC | 08:54 | |
*** hamzaachi has joined #openstack-ansible | 09:04 | |
*** shardy has joined #openstack-ansible | 09:06 | |
*** shardy has quit IRC | 09:06 | |
*** shardy has joined #openstack-ansible | 09:07 | |
*** fatdragon has joined #openstack-ansible | 09:08 | |
*** fatdragon has quit IRC | 09:12 | |
openstackgerrit | Merged openstack/openstack-ansible-galera_client master: cleanup: stop managing files inside /etc https://review.openstack.org/627785 | 09:20 |
openstackgerrit | Merged openstack/openstack-ansible-galera_client master: cleanup: remove tasks from pike https://review.openstack.org/627786 | 09:20 |
openstackgerrit | Merged openstack/openstack-ansible-galera_client master: cleanup: don't update_cache when adding a new repo https://review.openstack.org/627787 | 09:20 |
openstackgerrit | Merged openstack/openstack-ansible-galera_client master: cleanup: stop installing mysql headers https://review.openstack.org/627788 | 09:20 |
openstackgerrit | Merged openstack/openstack-ansible-galera_client master: cleanup: stop setting priority in a follow-up task https://review.openstack.org/627789 | 09:20 |
*** kopecmartin is now known as kopecmartin|afk | 09:25 | |
openstackgerrit | Jonathan Rosser proposed openstack/openstack-ansible-os_swift master: Remove unnecessary package install duplication https://review.openstack.org/614342 | 09:28 |
admin0 | https://docs.openstack.org/openstack-ansible-os_neutron/latest/app-openvswitch.html -- does rocky support everything on ovs ? | 09:32 |
openstackgerrit | Jonathan Rosser proposed openstack/openstack-ansible-lxc_hosts master: Minimise distro packages installed into the lxc image https://review.openstack.org/613078 | 09:32 |
openstackgerrit | Merged openstack/openstack-ansible-ceph_client stable/queens: Remove the dependency on SSH for monitors https://review.openstack.org/623235 | 09:34 |
openstackgerrit | Jonathan Rosser proposed openstack/openstack-ansible-os_nova master: If nova is installed on arm64 with active KVM, default to that. https://review.openstack.org/622981 | 09:37 |
*** shyamb has quit IRC | 09:41 | |
*** shyamb has joined #openstack-ansible | 09:41 | |
*** chhagarw has joined #openstack-ansible | 09:41 | |
*** hamzaachi_ has joined #openstack-ansible | 09:43 | |
*** hamzaachi has quit IRC | 09:46 | |
*** dcdamien has joined #openstack-ansible | 09:46 | |
*** fatdragon has joined #openstack-ansible | 09:48 | |
*** shyamb has quit IRC | 09:50 | |
*** fatdragon has quit IRC | 10:01 | |
*** shardy has quit IRC | 10:10 | |
*** shardy has joined #openstack-ansible | 10:10 | |
*** kopecmartin|afk is now known as kopecmartin | 10:22 | |
*** cshen has joined #openstack-ansible | 10:22 | |
*** cshen has quit IRC | 10:31 | |
*** cshen has joined #openstack-ansible | 10:32 | |
openstackgerrit | Chandan Kumar proposed openstack/openstack-ansible-os_tempest master: Added support for installing python-tempestconf from git https://review.openstack.org/625904 | 10:33 |
openstackgerrit | Merged openstack/openstack-ansible stable/queens: Add automated migration of neutron agents to bare metal https://review.openstack.org/625331 | 10:34 |
openstackgerrit | Merged openstack/openstack-ansible-os_nova master: Spice console doesn't work on aarch64+kvm. https://review.openstack.org/626936 | 10:42 |
*** cshen has quit IRC | 10:43 | |
*** jawad_axd has quit IRC | 10:44 | |
*** kopecmartin has quit IRC | 10:46 | |
*** jawad_axd has joined #openstack-ansible | 10:47 | |
*** kopecmartin has joined #openstack-ansible | 10:47 | |
*** luksky has quit IRC | 10:49 | |
*** shyamb has joined #openstack-ansible | 10:49 | |
openstackgerrit | Manuel Buil proposed openstack/openstack-ansible-os_neutron master: Use the new services names for sfc https://review.openstack.org/622216 | 10:50 |
*** stuartgr has joined #openstack-ansible | 11:03 | |
openstackgerrit | Manuel Buil proposed openstack/openstack-ansible-os_neutron master: Provide support for ovs-sfc https://review.openstack.org/621249 | 11:11 |
openstackgerrit | Manuel Buil proposed openstack/openstack-ansible-os_neutron master: Use the new services names for sfc https://review.openstack.org/622216 | 11:12 |
*** cshen has joined #openstack-ansible | 11:12 | |
openstackgerrit | Manuel Buil proposed openstack/openstack-ansible-os_neutron master: Use the new services names for sfc https://review.openstack.org/622216 | 11:14 |
*** shyamb has quit IRC | 11:16 | |
*** aedc has joined #openstack-ansible | 11:17 | |
*** cshen has quit IRC | 11:17 | |
*** udesale has quit IRC | 11:26 | |
*** shyamb has joined #openstack-ansible | 11:40 | |
*** ansmith has quit IRC | 11:48 | |
*** ansmith has joined #openstack-ansible | 11:49 | |
jamesdenton | admin0 what do you mean? | 11:53 |
admin0 | jamesdenton, so far i have made ovs work by using lb in controllers and then only br-vlan and br-vxlan in the network/compute nodes .. does rocky work without lb @ all ? | 12:02 |
*** cshen has joined #openstack-ansible | 12:05 | |
jrosser | mnaser: does https://review.openstack.org/#/c/627785/ need an equivalent in galera_server role? | 12:10 |
*** cshen has quit IRC | 12:10 | |
jrosser | mnaser: because there is now brok here http://logs.openstack.org/23/625523/8/check/openstack-ansible-deploy-aio_metal-centos-7/ed814c7/job-output.txt.gz#_2019-01-03_10_22_05_041436 | 12:10 |
jamesdenton | admin0 The docs appear to call out br-mgmt being an OVS bridge, so i'm pretty sure you can eliminate linux bridges altogether | 12:12 |
*** luksky has joined #openstack-ansible | 12:24 | |
*** vollman has joined #openstack-ansible | 12:41 | |
*** shyamb has quit IRC | 13:04 | |
*** cshen has joined #openstack-ansible | 13:08 | |
*** cshen has quit IRC | 13:13 | |
*** ianychoi has joined #openstack-ansible | 13:17 | |
*** dave-mccowan has joined #openstack-ansible | 13:18 | |
*** markvoelker has quit IRC | 13:18 | |
*** markvoelker has joined #openstack-ansible | 13:20 | |
*** hamzaachi_ has quit IRC | 13:44 | |
*** vollman has quit IRC | 13:50 | |
*** hamzaachi has joined #openstack-ansible | 13:52 | |
openstackgerrit | Guilherme Steinmuller Pimentel proposed openstack/openstack-ansible-os_tempest master: Fix tempest workspace path https://review.openstack.org/628182 | 13:54 |
openstackgerrit | Guilherme Steinmuller Pimentel proposed openstack/openstack-ansible-os_tempest master: Fix tempest workspace path https://review.openstack.org/628182 | 13:55 |
*** lbragstad has joined #openstack-ansible | 13:58 | |
*** vollman has joined #openstack-ansible | 14:01 | |
*** jawad_axd has quit IRC | 14:01 | |
*** jawad_axd has joined #openstack-ansible | 14:02 | |
chandankumar | jrosser: mnaser I am doing some integration work for running os_tempest with devstack and tripleo-ci https://review.openstack.org/#/c/622865/ and https://review.openstack.org/627482 feel free to have a look | 14:05 |
chandankumar | *we | 14:05 |
*** jawad_axd has quit IRC | 14:06 | |
*** udesale has joined #openstack-ansible | 14:22 | |
noonedeadpunk | hi folks, am I right, that we're missing resource_filters distribution for cinder? As it seems, that cinder do not have any defaults for it https://github.com/openstack/cinder/blob/master/cinder/api/common.py#L375-L383 | 14:23 |
noonedeadpunk | If we don't have it, I'll place the patch for it then... | 14:24 |
openstackgerrit | Guilherme Steinmuller Pimentel proposed openstack/openstack-ansible-os_tempest master: Fix tempest workspace path https://review.openstack.org/628182 | 14:46 |
fnpanic | hi | 14:47 |
*** yetiszaf has quit IRC | 14:48 | |
fnpanic | what is the best way to get a root cert into the e.g. keystone containers? | 14:48 |
fnpanic | is using custom certs for keystone the best way? | 14:48 |
*** macza has joined #openstack-ansible | 14:49 | |
*** lbragstad has quit IRC | 14:50 | |
*** macza has quit IRC | 14:51 | |
openstackgerrit | Dmitriy Rabotjagov (noonedeadpunk) proposed openstack/openstack-ansible-os_cinder master: Adds resource_filters.json distribution https://review.openstack.org/628197 | 14:53 |
*** lbragstad has joined #openstack-ansible | 14:53 | |
noonedeadpunk | cloudnull: it seems, that I've placed conflicting patch to https://review.openstack.org/#/c/588953/6 - should I change it and place on top of yours? | 15:02 |
jrosser | fnpanic: are you using the ssl temrination on haproxy for keystone? | 15:03 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-ops master: Add pretasks to exit quick when needed https://review.openstack.org/628201 | 15:07 |
*** udesale has quit IRC | 15:08 | |
cloudnull | noonedeadpunk don't worry about it | 15:09 |
*** cshen has joined #openstack-ansible | 15:09 | |
cloudnull | all of those smart_sources patches need to be rebased. | 15:09 |
cloudnull | https://review.openstack.org/#/q/topic:smart-sources+(status:open+OR+status:open) | 15:09 |
cloudnull | the only place that pattern has been implemented is neutron | 15:10 |
cloudnull | it'd be great if we could get that in the roles | 15:10 |
cloudnull | its a lot less things to carry in the roles | 15:10 |
fnpanic | jrosser: i added custom certs to haproxy | 15:10 |
fnpanic | yes | 15:10 |
noonedeadpunk | ah, ok. I just don't want to add cinder to the list of the problematic roles. Yeah, they are nice and would be great to see them implemented. | 15:11 |
cloudnull | ++ | 15:11 |
jrosser | fnpanic: so iirc there shouldnt be any ssl in the keystone containers? so the CA shoudlnt be needed there? | 15:11 |
fnpanic | haproxy_user_ssl_cert: | 15:11 |
*** jawad_axd has joined #openstack-ansible | 15:11 | |
fnpanic | the ca is required for the ldaps connection to our ad | 15:12 |
fnpanic | which uses a privat ca | 15:12 |
jrosser | ah different question then :) | 15:12 |
fnpanic | i tought using the keystone ssl cert would also then include the root cert and i am done :-) | 15:13 |
fnpanic | i need a way to get the root cert into the keystone containers reliable | 15:13 |
fnpanic | :-) | 15:13 |
jrosser | you've got several options there | 15:13 |
*** cshen has quit IRC | 15:14 | |
noonedeadpunk | cloudnull: I've got lost in thoughts, how config files appears in {{ cinder_bin | dirname }}/etc/cinder"? As in rocky I do not see mine resource_filters.json, however it's present in github https://github.com/openstack/cinder/blob/stable/rocky/etc/cinder/resource_filters.json | 15:14 |
*** ivve has joined #openstack-ansible | 15:15 | |
jrosser | fnpanic: if you have your CA cert all nicely packaged up in an installable .deb or .rpm from a custom repo then you can fire it in here https://github.com/openstack/openstack-ansible-lxc_hosts/blob/master/defaults/main.yml#L183 | 15:15 |
*** Bhujay has joined #openstack-ansible | 15:15 | |
*** jawad_axd has quit IRC | 15:16 | |
*** Bhujay has quit IRC | 15:16 | |
noonedeadpunk | I understand, that it's been packed on repo_container, downloaded on destination container, but shouldn't all config files from github be present in venv? | 15:16 |
jrosser | but i do think that you are most probably going to have interesting times making all the various libraries pick up custom certificates correctly | 15:16 |
cloudnull | noonedeadpunk those files are not present in /etc/$SERVICE unless we have a template for them. | 15:18 |
cloudnull | with the smart_sources pr we begin using whats provided by the service via the venv | 15:19 |
noonedeadpunk | cloudnull Yeah, I've got the point. I mean, that shouldn't all these files be already present inside venv? As now I have only small part of them http://paste.openstack.org/show/739872/ | 15:20 |
noonedeadpunk | And I thought, that everything from https://github.com/openstack/cinder/tree/stable/rocky/etc/cinder should be present there | 15:21 |
cloudnull | noonedeadpunk it would be with https://review.openstack.org/#/c/588953/ :) | 15:23 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_cinder master: Cleanup files and templates using smart sources https://review.openstack.org/588953 | 15:24 |
cloudnull | noonedeadpunk if you have the time to test that pr in one of your environments it'd be great to get some feedback on that. | 15:25 |
fnpanic | jrosser: so this would work? just packaging will not be enough i guess | 15:28 |
noonedeadpunk | cloudnull: I'll try to - having a huge backlog what I've promised to do | 15:30 |
fnpanic | update-ca-certificates i think | 15:30 |
cloudnull | noonedeadpunk I totally understand :) | 15:30 |
jrosser | fnpanic: well it all depends i think | 15:33 |
jrosser | i build .deb for custom certificates for hosts (not OSA containers) and they have stuff in the post-install scripts to do update-ca-certificates | 15:34 |
jrosser | but it gets a bit ugly, becasue some python libs look in the certifi CA set (like requests lib) and not the system CA store | 15:35 |
fnpanic | i was also thinking like this | 15:35 |
fnpanic | what against a playbook with copies the cert and does the update? | 15:35 |
jrosser | imho extending one of the OSA roles to properly install custom CA would be great, becasue it could handle this certifi business properly at the same time | 15:36 |
jrosser | cloudnull: have you had to deal with custom root CA? not sure we have a nice mechanism to deploy them right now? | 15:37 |
*** hamzaachi_ has joined #openstack-ansible | 15:38 | |
cloudnull | no, not really. | 15:38 |
*** hamzaachi has quit IRC | 15:41 | |
cloudnull | we've had talks of supporting hashicorp vault for such purposes, but nothings come of that yet. | 15:41 |
jrosser | in this case it's if you have your corporate CA cert, the public bit | 15:41 |
jrosser | that may need to go into the CA store of the hosts/and/or/containers for stuff like keystone<>ldaps that fnpanic is looking at | 15:42 |
jrosser | so i don't think theres a new secret as such | 15:42 |
fnpanic | yeah, i will try the deb and playbook variant. see what works best :-) | 15:43 |
fnpanic | thanks! | 15:44 |
jrosser | on it's own the deb may not be enough | 15:44 |
fnpanic | ? | 15:44 |
cloudnull | on the topic of certificates, I'd love for us to support tokenless auth: (https://specs.openstack.org/openstack/keystone-specs/specs/keystone/liberty/keystone-tokenless-authz-with-x509-ssl-client-cert.html) assuming it still works -cc lbragstad | 15:44 |
fnpanic | deb + post install script | 15:44 |
jrosser | perhaps try just by hand first and then automate it | 15:44 |
jrosser | becasue of python-requests specifically | 15:44 |
fnpanic | yeah i have it running manual :-) | 15:44 |
fnpanic | copied to the container and then ran update-ca-certs | 15:45 |
fnpanic | that works | 15:45 |
jrosser | ok, nice | 15:45 |
jrosser | well openstack-hosts is the role that runs against all hosts and containers | 15:45 |
fnpanic | i was just in fear that something in the OSA playbooks would kill it :-) | 15:45 |
jrosser | you could look at adding a new var and tasks to that for dropping custom CA | 15:45 |
fnpanic | isn't there a place somewhere for addin this kind of tasks without patching the OSA playbooks? | 15:46 |
cloudnull | fnpanic you could add things to the ops repo? | 15:47 |
lbragstad | cloudnull https://docs.openstack.org/keystone/latest/admin/configure_tokenless_x509.html | 15:47 |
cloudnull | https://github.com/openstack/openstack-ansible-ops/ | 15:47 |
lbragstad | that *should* still work... if it doesn't, we've got bugs to fix | 15:47 |
cloudnull | lbragstad so its still supported, and not to be removed anytime soon ? | 15:47 |
lbragstad | if it is, it's news to me | 15:48 |
cloudnull | cool! | 15:48 |
lbragstad | we have a backlogged action item to dig into that implementation | 15:48 |
* cloudnull adds to my list of things I want to do one day :) | 15:48 | |
jrosser | fnpanic: i'd be interested in having it in the proper ansible roles - we can help you with the patch | 15:48 |
openstackgerrit | Merged openstack/openstack-ansible-ops master: Add pretasks to exit quick when needed https://review.openstack.org/628201 | 15:50 |
lbragstad | cloudnull the idea was to make it so instead of using SAML for federated authentication and auto-provisioning, we could abstract the auto-provisioning flow from federated authentication, then users could federated using certificates issued by their CA | 15:50 |
cloudnull | ^ thats the dream | 15:50 |
lbragstad | nice - yeah.. that's the approach the Oath wants to take with their federated identity stuff | 15:51 |
lbragstad | (since they use an external idp for identities) | 15:51 |
fnpanic | jrosser: i will then try to come up with proper ansible roles | 15:51 |
fnpanic | cloudnull: adding then to ops repo makes sense :-) | 15:52 |
cloudnull | also, happy new year lbragstad ! | 15:52 |
lbragstad | happy new year :) | 15:52 |
cloudnull | fnpanic if you add some bits to the ops repo and its something that can be made into a general purpose tool we might be able to take that and add it to our osa roles as needed | 15:54 |
cloudnull | but the ops repo is a great place to prototype things and / or add tooling that may not quite fit in the core roles. | 15:54 |
jrosser | fnpanic: it's probably not really much more than http://paste.openstack.org/show/739875 with some added niceness to make to accept a list of certs and do a whole bunch at once | 15:57 |
jrosser | i think rocky branch is a bit wedged up currently - needs this https://review.openstack.org/#/c/627851/ or something similar | 16:00 |
fnpanic | Thanks a lot! | 16:02 |
openstackgerrit | Mohammed Naser proposed openstack/openstack-ansible master: wip: upgrade jobs https://review.openstack.org/627782 | 16:17 |
*** dcdamien has quit IRC | 16:26 | |
*** macza has joined #openstack-ansible | 16:26 | |
*** fatdragon has joined #openstack-ansible | 16:27 | |
spotz | Happy New Years everyon! | 16:27 |
cloudnull | HNY 2u2 spotz | 16:28 |
*** fatdragon has quit IRC | 16:31 | |
*** sawblade6 has quit IRC | 16:33 | |
vollman | To issue a recheck of the centos zuul gate that failed here https://review.openstack.org/#/c/626181/ is it still just recheck? | 16:34 |
jrosser | vollman: yes, just recheck | 16:36 |
vollman | jrosser: ty | 16:36 |
*** cshen has joined #openstack-ansible | 16:38 | |
openstackgerrit | Guilherme Steinmuller Pimentel proposed openstack/openstack-ansible-os_tempest master: Fix tempest workspace path https://review.openstack.org/628182 | 16:43 |
*** cshen has quit IRC | 16:43 | |
guilhermesp | hello all!! friendly ping to cores to take a look at this backport https://review.openstack.org/#/c/628032/ :D | 16:48 |
*** jawad_axd has joined #openstack-ansible | 17:03 | |
*** jawad_axd has quit IRC | 17:07 | |
*** kopecmartin is now known as kopecmartin|off | 17:09 | |
spotz | guilhermesp: looking | 17:12 |
*** dcdamien has joined #openstack-ansible | 17:14 | |
*** vollman has quit IRC | 17:19 | |
*** gyee has joined #openstack-ansible | 17:25 | |
admin0 | my queens minor upgrade fails on this: https://pastebin.com/ZrEcufah -- this is on the setup-infra playbook .. any ideas how do I overcome this and when I re-run it, do i have to do -e rabbitmq_upgrade=true everytime ? | 17:26 |
guilhermesp | thanks spotz | 17:33 |
*** luksky has quit IRC | 17:38 | |
*** masterpe has quit IRC | 17:39 | |
spotz | guilhermesp: no prob | 17:46 |
admin0 | i am going to do a repo-build and hope for the best | 17:58 |
*** DanyC has joined #openstack-ansible | 17:59 | |
*** dcdamien has quit IRC | 18:00 | |
*** DanyC has quit IRC | 18:04 | |
admin0 | had to delete all and re-run the repo build .. but its working now :) | 18:27 |
admin0 | short lived .. the os-keystone checks for curl http://URL:8181/os-releases/17.1.5/ubuntu-16.04-x86_64/ | 18:33 |
admin0 | requirements_absolute_requirements.txt .. while the repo only has reqirements.txt and requirements_constraints.txt | 18:33 |
admin0 | so its checking for a file that does not exist | 18:34 |
admin0 | how do I fix this ? | 18:34 |
*** DanyC has joined #openstack-ansible | 18:37 | |
*** cshen has joined #openstack-ansible | 18:39 | |
openstackgerrit | Merged openstack/openstack-ansible-os_neutron stable/rocky: Plug port on OVS agents instead of L3 agents only https://review.openstack.org/628032 | 18:41 |
*** DanyC has quit IRC | 18:43 | |
*** DanyC has joined #openstack-ansible | 18:43 | |
*** cshen has quit IRC | 18:45 | |
*** DanyC has quit IRC | 18:46 | |
*** DanyC has joined #openstack-ansible | 18:47 | |
*** DanyC_ has joined #openstack-ansible | 18:55 | |
*** DanyC has quit IRC | 18:59 | |
*** cshen has joined #openstack-ansible | 19:00 | |
*** jawad_axd has joined #openstack-ansible | 19:11 | |
*** jawad_axd has quit IRC | 19:15 | |
redkrieg | I changed the node I use as one of my swift-proxy_hosts and destroyed the container with the lxc-container-destroy.yml playbook, but when I run my setup again it complains that it can't reach the swift proxy container on the old host. how can I clear this from ansible? | 19:22 |
*** cshen has quit IRC | 19:28 | |
*** KeithMnemonic has quit IRC | 19:28 | |
*** vollman has joined #openstack-ansible | 19:28 | |
*** dcdamien has joined #openstack-ansible | 19:36 | |
*** DanyC_ has quit IRC | 19:37 | |
*** vollman has quit IRC | 19:40 | |
openstackgerrit | Merged openstack/openstack-ansible-os_tempest master: Add the manila-tempest-plugin https://review.openstack.org/626181 | 19:41 |
jrosser | redkrieg: there is a script here you can use to remove unwanted inventory items https://github.com/openstack/openstack-ansible/blob/master/scripts/inventory-manage.py | 19:51 |
redkrieg | jrosser: thanks! | 19:55 |
*** DanyC has joined #openstack-ansible | 19:59 | |
*** cshen has joined #openstack-ansible | 20:00 | |
*** cshen has quit IRC | 20:05 | |
openstackgerrit | Manuel Buil proposed openstack/openstack-ansible-os_neutron master: Provide support for ovs-sfc https://review.openstack.org/621249 | 20:07 |
openstackgerrit | Manuel Buil proposed openstack/openstack-ansible-os_neutron master: Provide support for ovs-sfc https://review.openstack.org/621249 | 20:09 |
openstackgerrit | Manuel Buil proposed openstack/openstack-ansible-os_neutron master: Use the new services names for sfc https://review.openstack.org/622216 | 20:14 |
*** DanyC has quit IRC | 20:25 | |
*** cshen has joined #openstack-ansible | 20:32 | |
*** hamzaachi_ has quit IRC | 20:36 | |
*** cshen has quit IRC | 20:37 | |
admin0 | can anyone help? upgrade fails because its searching for :8181/os-releases/17.1.5/ubuntu-16.04-x86_64/requirements_absolute_requirements.txt , while only reqirements.txt and requirements_constraints.txt exists | 21:17 |
admin0 | need someone on latest queens to confirm if they see that file in their local repo or not | 21:34 |
*** mhayden has quit IRC | 21:47 | |
*** mhayden has joined #openstack-ansible | 21:47 | |
jrosser | admin0: the repo build should create it - here is a queens CI job http://logs.openstack.org/31/625331/9/check/openstack-ansible-deploy-aio_lxc-ubuntu-xenial/f559c97/logs/ara-report/result/a11ec9de-7e61-4238-bd9f-aab06145081c/ | 21:48 |
*** cshen has joined #openstack-ansible | 21:48 | |
jrosser | you should then be able to find the file by hand in the repo container | 21:48 |
jrosser | and if you have more than one infra node check that all the repo container contents are synced | 21:49 |
admin0 | is it safe to delete all infra containers and re-create ? | 21:49 |
jrosser | infra node vs. repo container? not quite following | 21:50 |
*** fatdragon has joined #openstack-ansible | 21:50 | |
admin0 | my mistake :D | 21:51 |
admin0 | repo containers | 21:51 |
jrosser | if the repo build says it has created the abolute requirements file then you should be able to find it by entering the container and looking | 21:51 |
*** cshen has quit IRC | 21:52 | |
*** fatdragon has quit IRC | 22:01 | |
*** radeks_ has quit IRC | 22:04 | |
admin0 | jrosser, there is no file in my root@c2-repo-container-b6e094cc:/var/www/repo/os-releases/17.1.5/ubuntu-16.04-x86_64# ls -al | 22:10 |
admin0 | i mean the repo containers | 22:10 |
jrosser | but the task to create it succeeds? | 22:11 |
admin0 | if i need to nuke and recreate my repo containers, what is the command for that ? | 22:11 |
admin0 | i know how to nuke and recreate | 22:12 |
admin0 | then i run the repo_build | 22:12 |
*** fatdragon has joined #openstack-ansible | 22:13 | |
admin0 | nuked all 4 repo containers .. now running the repo_build | 22:16 |
admin0 | all 3* | 22:17 |
*** fatdragon has quit IRC | 22:17 | |
admin0 | finally it created :) | 22:47 |
admin0 | not sure what different thing i did | 22:47 |
*** cshen has joined #openstack-ansible | 22:55 | |
*** cshen has quit IRC | 23:00 | |
openstackgerrit | Mohammed Naser proposed openstack/openstack-ansible-memcached_server master: speedup: drop apt pinning dependency https://review.openstack.org/628320 | 23:20 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-ops master: Update the embedded-ansible-setup process to be configurable https://review.openstack.org/628321 | 23:21 |
*** hamerins has joined #openstack-ansible | 23:31 | |
*** hamerins has quit IRC | 23:40 | |
*** macza has quit IRC | 23:54 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!