Thursday, 2019-03-14

*** mpjetta has quit IRC00:14
*** marst has joined #openstack-ansible00:19
*** cmart has quit IRC00:31
*** gyee has quit IRC00:39
*** marst has quit IRC00:42
*** cshen has joined #openstack-ansible00:57
*** cshen has quit IRC01:02
cloudnullevenings all01:14
*** cyberpear has quit IRC01:59
*** cmart has joined #openstack-ansible02:23
*** BjoernT has joined #openstack-ansible02:40
*** BjoernT_ has joined #openstack-ansible02:45
*** BjoernT has quit IRC02:48
*** dave-mccowan has joined #openstack-ansible02:50
*** dave-mccowan has quit IRC02:54
*** cshen has joined #openstack-ansible02:58
*** kmadac3 has joined #openstack-ansible03:01
*** cshen has quit IRC03:02
*** kmadac2 has quit IRC03:04
*** cmart has quit IRC04:21
*** udesale has joined #openstack-ansible04:22
*** raukadah is now known as chandankumar05:50
*** jbadiapa has quit IRC06:03
*** jbadiapa has joined #openstack-ansible06:04
*** ivve has joined #openstack-ansible06:37
*** DanyC has joined #openstack-ansible06:44
*** shardy has quit IRC06:44
*** shardy has joined #openstack-ansible06:52
*** DanyC has quit IRC06:54
*** rgogunskiy has joined #openstack-ansible06:57
*** BjoernT has joined #openstack-ansible07:00
*** kopecmartin|off is now known as kopecmartin07:00
*** BjoernT_ has quit IRC07:02
*** maxbab has joined #openstack-ansible07:12
*** markvoelker has quit IRC07:19
*** tosky has joined #openstack-ansible07:23
*** cshen has joined #openstack-ansible07:39
*** aedc has quit IRC07:43
*** gkadam_ has joined #openstack-ansible07:50
*** luksky has joined #openstack-ansible07:54
*** hamzaachi has joined #openstack-ansible07:55
openstackgerritChandan Kumar proposed openstack/openstack-ansible-tests master: Set tempest_image_dir to /opt/cache/files in openstack CI  https://review.openstack.org/64130407:55
openstackgerritChandan Kumar proposed openstack/openstack-ansible-os_tempest master: Fix tempest_image_dir default var to user's home tempest-image dir  https://review.openstack.org/64074207:55
*** hamzaachi has quit IRC07:56
*** hamzaachi has joined #openstack-ansible07:57
*** flaviosr has quit IRC08:01
*** hamzaachi has quit IRC08:02
*** fnpanic has joined #openstack-ansible08:06
fnpanicgood morning08:06
*** pcaruana has joined #openstack-ansible08:07
*** pcaruana has quit IRC08:11
*** BjoernT has quit IRC08:23
*** miloa has joined #openstack-ansible08:23
*** pcaruana has joined #openstack-ansible08:23
*** hamzaachi has joined #openstack-ansible08:24
openstackgerritMerged openstack/openstack-ansible-tests master: Fix bashate xargs run  https://review.openstack.org/64310408:25
*** hamzaachi has quit IRC08:25
*** hamzaachi has joined #openstack-ansible08:26
*** fnpanic has quit IRC08:26
*** fnpanic has joined #openstack-ansible08:41
*** CeeMac has joined #openstack-ansible08:58
CeeMacmorning09:00
*** simon-AS559 has joined #openstack-ansible09:02
*** Dantalion has joined #openstack-ansible09:09
openstackgerritChandan Kumar proposed openstack/openstack-ansible-tests master: Set tempest_image_dir to /opt/cache/files in openstack CI  https://review.openstack.org/64130409:11
miloamorning09:14
*** aedc has joined #openstack-ansible09:18
*** DanyC has joined #openstack-ansible09:22
fnpanic /UNIGNORE noonedeadpunk09:23
fnpanicUNIGNORE noonedeadpunk09:23
fnpanicargh09:23
*** pcaruana has quit IRC09:48
chandankumarjrosser: Hello10:00
chandankumarjrosser: I need some help here https://review.openstack.org/#/c/641304/ How Can I pass default value while using ternary?10:01
jrosserchandankumar: you can’t access role defaults from outside the role10:12
jrosserYou could conditionally include and extra tasks file that sets nodepool specific vars, that may be a better pattern10:14
chandankumarjrosser: I think we donot need http://git.openstack.org/cgit/openstack/openstack-ansible/tree/tests/roles/bootstrap-host/templates/user_variables.aio.yml.j2#n18910:17
chandankumarin openstack-ansible-tests10:17
chandankumaras it is already taken care by openstack-ansible10:18
jrosserAll of the osa role tests currently use Openstack-ansible-tests though10:20
jrosserIt depends what you are tying to fix10:20
jrosserRight, I’m away for the rest of today.....10:20
chandankumarabandoning the ansible-tests patch10:20
openstackgerritChandan Kumar proposed openstack/openstack-ansible-os_tempest master: Fix tempest_image_dir default var to user's home tempest-image dir  https://review.openstack.org/64074210:21
jamesdentonadmin0 It is not abandoned, but does need to be rebased and revisited.10:41
*** udesale has quit IRC10:56
*** udesale has joined #openstack-ansible10:56
*** nicolasbock has joined #openstack-ansible10:57
*** yolanda has quit IRC11:02
*** yolanda has joined #openstack-ansible11:03
*** shardy has quit IRC11:11
*** udesale has quit IRC11:15
*** udesale has joined #openstack-ansible11:15
*** udesale has quit IRC11:27
*** aedc has quit IRC11:27
*** udesale has joined #openstack-ansible11:28
*** nicolasbock has quit IRC11:29
*** nicolasbock has joined #openstack-ansible11:30
*** rgogunskiy has quit IRC11:31
openstackgerritJean-Philippe Evrard proposed openstack/openstack-ansible master: Fix bashate  https://review.openstack.org/64330011:32
*** pcaruana has joined #openstack-ansible11:32
*** rgogunskiy has joined #openstack-ansible11:33
odyssey4meguilhermesp mnaser I think it may be best to just branch stable/rocky from the current head of master for os_mistral, then use that branch for the integrated build. Any fixes that go in can then be specific to the branch. At the very least, the way the python builds happen will be different between Stein (new method) and Rocky (old method).11:39
*** dave-mccowan has joined #openstack-ansible11:46
*** luksky has quit IRC11:50
*** rgogunskiy has quit IRC11:55
*** rgogunskiy has joined #openstack-ansible11:56
*** ansmith has quit IRC11:58
chandankumarodyssey4me: Hello12:14
chandankumarodyssey4me: please have a look at this one https://review.openstack.org/#/c/640742/ when free!12:14
*** luksky has joined #openstack-ansible12:18
ostackzevrardjp jrosser Hi, how exactly should "real" SSL certificates work? I mean I have specified cert related variables like haproxy_user_ssl_cert in user_variables.yml, run playbooks and horizon URL is "green" now, but "list stacks" still fails. Seems this is due to IP used in URL, not hostname https://pastebin.com/raw/7yfE4H1B12:23
evrardjphttps://docs.openstack.org/openstack-ansible/latest/user/security/index.html ?12:33
chandankumarodyssey4me: thanks!12:34
ostackzevrardjp, thanks, must be I missed that I need to define ssl cert file for all services not only haproxy12:36
ostackzodyssey4me jrosser still just using "real" certs for all services does not seem enough, because SSL lib complains that it does not like IP to be used in URL: ERROR urllib3.connection <...> CertificateError: hostname '10.x.x.x' doesn't match either of '*.zzzzzzzzz.zz', 'zzzzzzzzz.zz'12:43
ostackznot clear how to make heat to work. Is there any variable I can force heat to use URLs instead of IP?  Because I cannot "real" cert for internal IP12:47
*** ansmith has joined #openstack-ansible12:48
*** ansmith_ has joined #openstack-ansible12:50
*** ansmith has quit IRC12:53
*** hwoarang has quit IRC12:56
*** hwoarang has joined #openstack-ansible12:57
*** maxbab has quit IRC13:00
evrardjpsorry I am in meetings for the whole day, I can't really help you now13:03
ioniostackz, i for one have the endpoints configured with domain13:08
ioniadding the ssl to haproxy makes all services that use public url(endpoint) to have a valid ssl13:09
ioniexternal_lb_vip_address: yourdomain13:09
ioniin /etc/openstack_deploy/openstack_user_config.yml13:09
ostackzioni I did put external_lb_vip_address ad domain name, but then Keepalived fails saying domain is not IP address13:10
ostackzioni do you have Rocky with working heat stacks?13:15
*** fnpanic has quit IRC13:15
ionii don't really use heat13:15
ostackzioni in horizon, if you click on Orchestration->Stacks - do you see empty list(this is ok) or "Error: Unable to retrieve stack list."?13:17
ionii don't have horizon13:20
ionilet me try something13:20
ostackzioni from cli that would be "openstack stack list"13:20
ioniyeah, let me switch to public url13:20
ionino error13:21
ioniworks fine13:21
ostackzand do you have Rocky release?13:21
ioniyes13:21
ionihaproxy_keepalived_external_vip_cidr: "{{external_lb_vip_address}}/32"13:21
ionihaproxy_keepalived_internal_vip_cidr: "{{internal_lb_vip_address}}/32"13:21
ioniin user_variables.yml13:21
ionithat's all i did13:22
ostackzok, sounds promissing! Need to understand why specifying external_lb_vip_address: my.hostname.here does not work for me13:23
ionican you ping it?13:23
ionii had an issue when the hostname of the controller was the same as external_lb_vip_address and /etc/hosts was messed up13:24
ionihad the wrong ip mapped13:24
ostackznetwork wise it is ok - can ping and open ports. The issue is that ssl libs do not like IP in URL of site, but I cannot get "real" cert for internal IP. https://pastebin.com/raw/7yfE4H1B13:28
ioniopenstack endoint list13:29
*** marst has joined #openstack-ansible13:31
*** rgogunskiy has quit IRC13:32
ostackzioni all endpoints are listed as IP https://x.x.x.x:port13:42
ionieven for private?13:43
ioni*internal13:43
ostackzyes, internal, public, admin13:44
ostackzIP of coures differs, but there are no URLs13:44
ostackzin your case you have name based URLs, right? For public endpoints13:45
*** marst has quit IRC13:45
guilhermespmornings13:48
guilhermespodyssey4me: yeah that'll be the idea. mnaser is going to branch it today and then I'm gonna make the fixes here https://review.openstack.org/#/c/642614/113:48
guilhermespwe are about to deploy it in a rocky env today hopefully13:49
*** hwoarang has quit IRC13:53
*** hwoarang has joined #openstack-ansible13:55
odyssey4meguilhermesp I don't think the python_venv_build role for stable/rocky is at the same level as that for master, so using os_mistral as-is may present some challenges14:05
jrosserostackz: if you change the external vip from an ip to an fqdn you will need to run all the playbooks again, to update the service catalog. Have you done that?14:06
ostackzjrosser yes, but afterwards keepalived complained that url is not valid IP address14:07
ostackzstill wondering if it is ok to set external_lb_vip_address as fqdn not IP14:08
*** aludwar has joined #openstack-ansible14:08
*** cmart has joined #openstack-ansible14:08
jrosserYes it is ok14:09
ostackzioni jrosser and I have "haproxy_keepalived_external_vip_cidr: "{{external_lb_vip_address}}/24"", may be netmask is not ok? Should it be /32 in all cases?14:09
jrosserBut it must resolve properly with a dns entry sonewhere14:09
*** marst has joined #openstack-ansible14:10
ostackzioni, jrosser, thanks! allright I need to get endpoints to URL then. Also will have to check if putting /32 in mask resolves keepalived issue.14:12
cloudnullmornings14:13
jrosserostackz: yes one step at a time, get the service catalog straight or things won’t be right later14:14
*** cmart has quit IRC14:14
jrosserostackz: I have haproxy_keepalived_external_vip_cidr set to “<external-ip>/32”14:16
*** cmart has joined #openstack-ansible14:17
jrosserAnd external_lb_vip_address to <fqdn>14:17
jrosserAnd your dns setup must agree about those two things14:18
*** fnpanic has joined #openstack-ansible14:22
jrosserceph repos look brok somehow http://logs.openstack.org/00/643300/1/check/openstack-ansible-deploy-aio_ceph-ubuntu-bionic/6798a07/job-output.txt.gz#_2019-03-14_12_36_42_17038014:25
mnaseri think we have to readapt things to not use python_venv_build in a stable/rocky change14:32
mnasercc guilhermesp ^14:32
*** hwoarang has quit IRC14:35
odyssey4memnaser yep, it'll need to align to doing what the stable/rocky roles do14:35
*** hwoarang has joined #openstack-ansible14:36
guilhermesponce we have a branch for rocky we can adapt I think. I'd assume I can get another rocky roles as reference?14:36
guilhermespmnaser odyssey4me14:36
cloudnulljrosser that could be the repos are sync'ing which would cause the md5sum mismatch14:36
jrosserit's been like that for ~24 hours now14:37
mnaserguilhermesp: yeah you can look at any role inside stable/rocky and itll have the 'older' format which doesnt use venv14:37
guilhermespcool then mnaser14:38
fnpanicjrosser: we noticed this also. Looks like the error happend on the 12. in the ceph repo14:39
fnpanicit is bricked for now14:39
* jrosser asks in #ceph-devel14:42
jrosseralso, is there a good reason why all the playbooks in the tests repo are connection: local? Does something bad happen if it is not like that?14:44
*** hwoarang has quit IRC14:46
odyssey4mejrosser it's complicated... they're not all like that, but they're supposed to be - the role tests do not run as root, so accessing localhost things gets more complicated14:48
odyssey4mewe've hit plenty of inventory and fact gathering issues along the way, which is one of the many nails in the role test coffin14:49
jrosserodyssey4me: i am stuck with this http://logs.openstack.org/45/641445/16/check/openstack-ansible-functional-ubuntu-bionic/093e1ed/job-output.txt.gz#_2019-03-12_18_43_16_69102014:49
jrosseri have installed pyopenssl on the host but i think that it isnt in the tox env14:49
jrosserso the ansible openssl_* modules can't see it14:49
jrosserso i was wondering if to move that part to be *not* connection: local to be in the regular host environment14:50
odyssey4mejrosser yep, that's exactly it - so either put the modules in the tox env, or change the python_venv_interpreter for that task14:51
jrosserwhich would be best - i spend 10x more time on the test than the functionality by now :(14:51
*** hwoarang has joined #openstack-ansible14:52
odyssey4meI think the latter is likely easier14:52
odyssey4mesomething like ansible_python_interpreter: "/usr/bin/python2"14:53
*** fnpanic has quit IRC14:54
*** yolanda has quit IRC14:57
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-openstack_hosts master: Install user supplied CA certificates into system trust store  https://review.openstack.org/64144514:59
jrosserodyssey4me: thanks for the tip!14:59
*** BjoernT has joined #openstack-ansible15:02
*** cmart has quit IRC15:34
*** hamzy has quit IRC15:43
*** yolanda has joined #openstack-ansible15:45
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-openstack_hosts master: Install user supplied CA certificates into system trust store  https://review.openstack.org/64144515:46
spotzmnaser do we have a plan for PTG yet?16:05
*** ostackz has quit IRC16:11
*** ivve has quit IRC16:25
*** hamzaachi has quit IRC16:25
*** kopecmartin is now known as kopecmartin|off16:26
*** cshen has quit IRC16:27
*** hamzaachi has joined #openstack-ansible16:27
*** hamzaachi_ has joined #openstack-ansible16:30
*** hamzaachi has quit IRC16:32
*** luksky has quit IRC16:41
chandankumarmnaser: cloudnull https://review.openstack.org/#/c/640742/ please have a look, when free!16:42
spotzchandankumar: done16:45
chandankumarspotz: thanks!16:45
guilhermespchandankumar: have you seen jobs failing like this ? http://logs.openstack.org/42/642842/2/check/openstack-ansible-deploy-aio_distro_lxc-opensuse-423/a10a1b5/logs/ara-report/result/92126a64-3f78-4462-a62c-f5117329e569/16:45
*** emine__ has quit IRC16:46
chandankumarguilhermesp: checking!16:46
spotzchandankumar: NP16:46
guilhermespchandankumar: thx!16:48
*** cmart has joined #openstack-ansible16:49
chandankumarguilhermesp: it appears to be something new , need to take a look!16:50
*** gkadam_ has quit IRC16:50
guilhermespall right! I've been seeing this since last Tuesday I think... rechecked yesterday thinking that was something intermittent16:52
chandankumardo you know where we dump /var/log/tempest.log in logs folder?16:53
guilhermesphum not sure, digging into the reports to see if I find16:55
*** udesale has quit IRC17:06
*** gyee has joined #openstack-ansible17:07
*** hamzy has joined #openstack-ansible17:09
chandankumarI think I reproduced the issue17:14
guilhermespnice chandankumar ? something that needs a PR? you don't have time I can submit one17:22
guilhermesp(exclude ? mark :P )17:22
chandankumarhttp://paste.openstack.org/show/747805/17:23
chandankumari have done pip install tempest, tempest init foobar then temepst run17:23
chandankumarI have asked gmann to look into it17:23
guilhermespthat's nice, thanks chandankumar !17:24
guilhermespodyssey4me mnaser so I can branch it the os_mistral role now for stable/rocky. Just wanted to know the best way to do it and then I can change the python_venv in rocky to fit the pattern in rocky17:27
*** miloa has quit IRC17:27
openstackgerritChandan Kumar proposed openstack/openstack-ansible-os_tempest master: Install tempest from git  https://review.openstack.org/64340417:31
*** chandankumar is now known as chkumar24617:34
*** DanyC has quit IRC17:39
*** DanyC has joined #openstack-ansible17:40
*** DanyC has quit IRC17:41
*** priteau has joined #openstack-ansible17:45
*** goldenfri has quit IRC17:48
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-openstack_hosts master: Install user supplied CA certificates into system trust store  https://review.openstack.org/64144518:04
*** cshen has joined #openstack-ansible18:05
*** simon-AS559 has quit IRC18:07
openstackgerritMerged openstack/openstack-ansible-os_tempest master: Fix tempest_image_dir default var to user's home tempest-image dir  https://review.openstack.org/64074218:07
*** DanyC has joined #openstack-ansible18:15
*** hamzaachi_ has quit IRC18:16
*** ivve has joined #openstack-ansible18:17
*** DanyC has quit IRC18:19
*** cshen has quit IRC18:21
*** cmart has quit IRC18:33
openstackgerritChandan Kumar proposed openstack/openstack-ansible-os_tempest master: Set tempest concurrency to int only  https://review.openstack.org/64342318:35
chkumar246guilhermesp: ^^ with above review that warning/error will go away if we backport above patch for rocky also!18:36
* chkumar246 will do some more tests tomorrow, see ya!18:42
*** cmart has joined #openstack-ansible18:43
guilhermespthank you for that chkumar246 !!!18:46
*** priteau has quit IRC18:56
*** aedc has joined #openstack-ansible18:58
openstackgerritOpenStack Release Bot proposed openstack/openstack-ansible-os_mistral stable/rocky: Update .gitreview for stable/rocky  https://review.openstack.org/64343219:06
openstackgerritOpenStack Release Bot proposed openstack/openstack-ansible-os_mistral stable/rocky: Update UPPER_CONSTRAINTS_FILE for stable/rocky  https://review.openstack.org/64343319:07
openstackgerritOpenStack Release Bot proposed openstack/openstack-ansible-os_mistral master: Update master for stable/rocky  https://review.openstack.org/64343419:07
*** priteau has joined #openstack-ansible19:16
*** priteau has quit IRC19:21
*** priteau has joined #openstack-ansible19:23
openstackgerritGuilherme  Steinmuller Pimentel proposed openstack/openstack-ansible-os_mistral master: Port venv build of os_mistral to stable/rocky  https://review.openstack.org/64344219:28
*** priteau has quit IRC19:28
guilhermespmnaser odyssey4me and any other core, reviews would be really appreciated ^19:28
*** luksky has joined #openstack-ansible19:43
jrosserguilhermesp: thats a patch to master - i'm not sure i understand19:44
guilhermespyeah19:44
guilhermespjust noticed that19:44
guilhermespfunny coz I checked out stable/rocky locally19:44
openstackgerritMerged openstack/openstack-ansible-os_mistral stable/rocky: Update .gitreview for stable/rocky  https://review.openstack.org/64343219:46
openstackgerritMerged openstack/openstack-ansible-os_mistral master: Update master for stable/rocky  https://review.openstack.org/64343419:46
*** cshen has joined #openstack-ansible19:46
*** yolanda has quit IRC19:46
*** cshen has quit IRC19:50
guilhermespis there a way to edit the PR to stable/rocky or would I need to abandon and create a new one?20:03
admin0 is this normal: message": "Exceeded maximum number of retries. Exceeded max scheduling attempts 5 for instance xxx-xxx- . Last exception: internal error: cannot load AppArmor profile20:04
admin0i didn't missed any playbook runs20:04
openstackgerritGuilherme  Steinmuller Pimentel proposed openstack/openstack-ansible-os_mistral master: Port venv build of os_mistral to stable/rocky  https://review.openstack.org/64344220:07
*** DanyC has joined #openstack-ansible20:08
openstackgerritGuilherme  Steinmuller Pimentel proposed openstack/openstack-ansible-os_mistral stable/rocky: Port venv build of os_mistral to stable/rocky  https://review.openstack.org/64344920:14
guilhermespthat's the correct one jrosser mnaser cloudnull odyssey4me  ^20:15
guilhermespI will abandon the wrong one20:15
*** priteau has joined #openstack-ansible20:24
*** marst has quit IRC20:34
*** ansmith_ has quit IRC20:35
*** priteau has quit IRC20:43
openstackgerritGuilherme  Steinmuller Pimentel proposed openstack/openstack-ansible-os_mistral stable/rocky: Port venv build of os_mistral to stable/rocky  https://review.openstack.org/64344920:44
*** hamzy has quit IRC20:45
*** marst has joined #openstack-ansible21:01
*** BjoernT has quit IRC21:34
admin0if all rabbitmq containers were nuked/recreated, does the cluster fix itself or is there a need to run the setup-openstack playbook again ?21:41
*** cshen has joined #openstack-ansible21:46
admin0i guess i will find out and will update here :D21:47
*** cshen has quit IRC21:50
admin0have to run setup openstack :)21:54
cloudnullhey admin022:04
cloudnullyes you have to rerun the setup-openstakc22:04
cloudnullthat will recreate all the messaging users and vhosts22:04
admin0\o22:04
admin0yep .. running it now22:05
admin0btw, now i am a proud (runner) of 11 different openstack platforms .. all based on OSA :)22:05
admin05 are in 5 different countries - internal cloud to the company ..  4 = specific use case based to test things like NUMA etc22:06
*** DanyC has quit IRC22:08
cloudnullvery nice!22:10
cloudnullall running the same release?22:10
admin0all 5 are on 18.1.222:10
cloudnullhow have your NUMA testing been going?22:10
admin0the 4 are on diff versions22:10
admin02 is used to test with sr-iov ..22:10
cloudnullsweet!22:10
admin01 i am trying to get jamesdenton patch and see if i can get dpdk running/working22:11
admin01 is kind of used for DTAP22:11
admin0before i affect 1000+ users, i test update in one before i schedule in the rest of the 522:11
admin02 are in ovs, 3 are in lb ,   1 has ceph,     rest 4 are local storage22:11
admin0all kinds of22:11
admin01 has linux for cinder, 1 has ceph, one has qnap, one has equalogic :D22:12
admin0what would help me now is a global monitoring dashboard, and a global ELK dashboard22:12
admin0i want to provide ELK to the company, so that people can  grep their UUID/requestID themselves and figure out what went wrong before opening ticket22:13
admin04 have AD backend ..22:13
cloudnullthats how we use elk22:14
*** simon-AS559 has joined #openstack-ansible22:14
cloudnullyou can also now rollup multiple elk clusters into a crentralized thing22:14
admin0us, canada, uk, sweden, india .. 5 different latency zones -- so i keep it separate22:15
admin0i also found servers geting their / full because somehow /var/log/libvirt/libvirt.log is not properly rotated22:15
admin0so it reached 40-50+ gb in size22:16
cloudnulluh, thats massive22:16
* cloudnull have not had that issue before 22:16
admin0maybe because the cloud is used a lot22:17
admin0some day it crosses 1000+ instance launches ..22:18
admin0but its also deleted as the products is being tested, demoed , all versions etc22:18
cloudnullcould be the high vm churn rate22:21
*** pcaruana has quit IRC22:21
admin0since the number of serves are growing, i am thinking maybe a centralized saltstack to manage all22:21
cloudnullive not given salt a try in years.22:22
cloudnullid be curious what you think of it22:22
admin0i used it in my last job which had  mirantis openstack22:22
admin0i found it better than ceph/puppet22:23
admin0chef/puppet22:23
admin0the job before that was openstack via puppet and the job before that was via ceph22:23
admin0chef :D22:23
admin0chef => puppet => saltstack => OSA22:23
admin0that is my journey..22:23
admin0i gave osa-ops a try once .. but elasticsearch gave me 100% cpu usage on all 56 cores .. very afraid to try now22:24
admin0if it can have something like nagios/icinga/check_mk as well,it would be awesome :)22:25
*** marst has quit IRC22:25
cloudnullprometheanfire might have some icinga2 recommendations22:30
cloudnullthe osp elk tools have evolved quite a bit recently, specifically the collectors have been tuned quite a bit22:31
cloudnullI run elk on dedicated logging nodes within a cluster.22:31
admin0how to do that ?22:31
cloudnullI'd probably not recommend putting it on the infra hosts22:31
admin0can't forget this: https://ibb.co/sFhjzp622:32
admin0elk on infra node :)22:33
cloudnullThis is our deployment tool chain, https://github.com/rcbops/magnanimous-turbo-chainsaw22:33
cloudnullwe piggyback on the log_hosts defined within the openstack_user_config.yml22:33
cloudnullwe also use an overlay inventory file which allows is to deploy our ops tools without having to extend the osa inventory22:34
cloudnullhttps://github.com/openstack/openstack-ansible-ops/tree/master/overlay-inventories22:34
cloudnullin that way we can deploy elk, skydive, grafana, and osquery without having to mess with files in env.d or regenerating osa inventory22:36
cloudnullwhich is important to us, maybe not everyone, mainly because we're supporting clouds as old as kilo22:36
*** ivve has quit IRC22:36
* cloudnull hides his face in shame 22:36
*** aedc has quit IRC22:36
admin0no .. should be proud that you are still supporting it :)22:37
admin0others would run away22:37
admin0i know of an icehouse cluster still running22:37
* cloudnull knows of a grizzly cluster still running 22:38
admin0:)22:38
cloudnullbut yes, thats a good way to look at it22:38
cloudnullso our tools have all been made to support legacy things but also to let us do what we need without having to modify the running config within an osa deployment22:39
admin0i will try magnanimous22:39
cloudnullmaybe not super important for a lot of folks m but it was for us22:39
cloudnullyea , give it a spin. works pretty well22:40
admin0it has to be run from the deploy node ?22:40
cloudnullits just a couple helper things surounding the osa-ops repo22:40
cloudnullyes22:40
cloudnullfrom the deployment host22:40
cloudnullit needs to be able to read the osa inventory json file22:40
prometheanfireohai?22:42
prometheanfireI like the stuff in https://github.com/rcbops/magnanimous-turbo-chainsaw / osa-ops :P22:42
admin0the elk/ server is not a part of openstack inventroy .. in which file do we specify it22:43
admin0and what kind of connectivity does it need .. br-mgmt range ?22:43
cloudnullbr-mgmt is all it needs22:45
cloudnulland to deploy it with the magnanimous-turbo-chainsaw all you need to have is "log_hosts" defined in your openstack_user_config.yml22:46
admin0so log_hosts is where it will do all of this stuff ?22:46
cloudnullyes.22:46
cloudnullitll install the collectors within the hosts in your cluster, but elasticsearch, logstash, and kibana are all deployed on the log hosts.22:47
admin0steps #1.   prepare a new server for elk/<other cool stuff>  #2 give it a br-mgmt range  #3. git checkout mtc on deploy  #4. add this server as log_host in the inventory  #5. follow the rest of the stuff in the ReadMe22:47
cloudnullprometheanfire do you still icinga2 ?22:47
cloudnulladmin0 yes22:47
prometheanfiresomewhat, both that and netdata (easy to set up)22:48
admin0do you have a script or something for the icinga part reading from the inventory ?22:49
prometheanfireI don't use icinga or netdata to monitor openstack, just other services22:52
prometheanfiresorry :|22:52
admin0ok22:54
admin0how do you guys monitor openstack ?23:03
*** simon-AS559 has quit IRC23:04
guilhermespAny core to help me to merge it? :P https://review.openstack.org/64344923:04
*** luksky has quit IRC23:11
prometheanfireadmin0: grafana, elk, prometheus (depending on what you are monitoring)23:22
prometheanfirelogs or metrics23:22
prometheanfirecheck out https://github.com/openstack/openstack-ansible-ops23:22
admin0yep .. i will be setting that up tomororw23:23
prometheanfirethat's more of a gathering place for tools, but take a look around :D23:24
*** tosky has quit IRC23:26
*** gyee has quit IRC23:34
*** cshen has joined #openstack-ansible23:46
*** cshen has quit IRC23:50

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!