Monday, 2019-11-18

*** ivve has quit IRC00:33
*** tosky has quit IRC00:46
*** goldyfruit_ has quit IRC01:53
*** macz has joined #openstack-ansible02:05
*** cshen has joined #openstack-ansible02:28
*** cshen has quit IRC02:32
*** macz has quit IRC02:51
*** schwicht has joined #openstack-ansible03:12
*** rohit02 has joined #openstack-ansible03:47
*** udesale has joined #openstack-ansible04:02
*** gokhani has joined #openstack-ansible05:37
*** raukadah is now known as chandankumar05:44
*** nurdie has joined #openstack-ansible05:49
*** nurdie_ has joined #openstack-ansible05:50
*** nurdie has quit IRC05:54
*** kopecmartin has joined #openstack-ansible05:57
*** nurdie_ has quit IRC06:08
*** nurdie has joined #openstack-ansible06:09
*** nurdie has quit IRC06:13
*** yolanda has quit IRC06:45
*** nurdie has joined #openstack-ansible06:50
*** nurdie has quit IRC06:54
*** cshen has joined #openstack-ansible07:08
*** rpittau|afk is now known as rpittau07:28
*** jbadiapa has joined #openstack-ansible07:38
cshenmorning07:48
*** luksky has joined #openstack-ansible08:08
jrossermorning08:08
*** librehash has joined #openstack-ansible08:20
*** tosky has joined #openstack-ansible08:20
librehashI need help deploying 'lobste.rs'. Its written on an 'Ansible playbook'. Obtaining the VPS is no problem for me. Offering $125, zero delays for someone to assist me with getting a lobste.rs instance up and running on a VPS that I am renting & can provide credentials to. | Here's the GitHub for reference (open source) = I need help deploying08:30
librehash'lobste.rs'. Its written on an 'Ansible playbook'. Obtaining the VPS is no problem for me. Offering $125, zero delays for someone to assist me with getting a lobste.rs instance up and running on a VPS that I am renting & can provide credentials to.08:30
librehash/ 'all you need to do is...' / 'the instructions are right there' ; don't care. Please either accept or counter-offer and let's get started. Only straightforward business.08:30
*** ivve has joined #openstack-ansible08:46
cshenlibrehash: SPAM?09:00
*** hamzaachi has joined #openstack-ansible09:11
*** DanyC has joined #openstack-ansible09:13
*** DanyC has quit IRC09:15
librehash?09:19
librehashNo, I am not spam. Apologies. I'm just an idiot and sent the message wrong. Thought I was copying the GitHub link, but I had the message itself copied.09:20
librehashSo it posted twice and now it looks stupid. If a mod could delete that message actually, that would be awesome.09:20
librehashBut now you know why I was looking for assistance. I'm a retard when it comes to computers.09:20
*** yolanda has joined #openstack-ansible09:22
*** cshen has quit IRC09:22
*** DanyC has joined #openstack-ansible09:25
*** cshen has joined #openstack-ansible09:28
*** hamzaachi has quit IRC09:53
*** rohit02 has quit IRC09:55
*** rohit02 has joined #openstack-ansible09:56
*** cshen has quit IRC10:02
*** cshen has joined #openstack-ansible10:04
*** cshen has quit IRC10:09
*** pcaruana has joined #openstack-ansible10:10
*** owalsh has quit IRC10:12
*** hamzaachi has joined #openstack-ansible10:18
*** sshnaidm|off is now known as sshnaidm|ruck10:20
openstackgerritMerged openstack/openstack-ansible-specs master: tox: Keeping going with docs  https://review.opendev.org/69066910:22
*** owalsh has joined #openstack-ansible10:22
openstackgerritMerged openstack/openstack-ansible-os_magnum master: tox: Keeping going with docs  https://review.opendev.org/69065610:25
openstackgerritMerged openstack/openstack-ansible-os_heat master: tox: Keeping going with docs  https://review.opendev.org/69066810:25
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-os_ceilometer master: Check conditional length before evaluation  https://review.opendev.org/69405510:28
openstackgerritMerged openstack/openstack-ansible-os_murano master: Update master for stable/train  https://review.opendev.org/69424210:29
openstackgerritMerged openstack/openstack-ansible-os_murano stable/train: Update .gitreview for stable/train  https://review.opendev.org/69424010:29
openstackgerritMerged openstack/openstack-ansible-os_murano stable/train: Update TOX/UPPER_CONSTRAINTS_FILE for stable/train  https://review.opendev.org/69424110:29
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-tests master: Use the cached cirros image for tests run from this repo  https://review.opendev.org/69318510:30
openstackgerritMerged openstack/openstack-ansible master: tox: Keeping going with docs  https://review.opendev.org/69061110:33
*** CeeMac has joined #openstack-ansible10:37
CeeMacmorning10:37
openstackgerritMerged openstack/openstack-ansible-ceph_client master: tox: Keeping going with docs  https://review.opendev.org/69065310:39
*** cshen has joined #openstack-ansible10:43
*** cshen has quit IRC10:49
openstackgerritMerged openstack/openstack-ansible-os_cloudkitty master: Replace git.openstack.org with opendev.org  https://review.opendev.org/69429610:50
*** admin0 has quit IRC10:52
*** rohit02 has quit IRC11:06
*** luksky has quit IRC11:06
*** rohit02 has joined #openstack-ansible11:07
*** cshen has joined #openstack-ansible11:09
noonedeadpunkmornings11:09
jrossermorning11:10
*** librehash has quit IRC11:13
*** cshen has quit IRC11:14
*** udesale has quit IRC11:17
noonedeadpunkjrosser evrardjp: I think we can abandon https://review.opendev.org/#/c/689650/ as https://review.opendev.org/#/c/691318/ already merged11:19
noonedeadpunkor I misunderstood it?11:20
*** luksky has joined #openstack-ansible11:22
*** cshen has joined #openstack-ansible11:24
*** cshen has quit IRC11:33
*** cshen has joined #openstack-ansible11:38
*** bhyrted has joined #openstack-ansible11:41
bhyrtedansible train:11:41
bhyrtedTASK [os_ceilometer : Add keystone domain] ************************************************************************************************************************************************************************************************************************************11:41
bhyrtedfatal: [compute1]: FAILED! => {"msg": "The conditional check 'inventory_hostname == (groups[(ceilometer_services['ceilometer-agent-notification']['group'] | intersect(group_names))[0]] | intersect(ansible_play_hosts))[0]' failed. The error was: error while evaluating con11:41
bhyrtedditional (inventory_hostname == (groups[(ceilometer_services['ceilometer-agent-notification']['group'] | intersect(group_names))[0]] | intersect(ansible_play_hosts))[0]): list object has no element 0\n\nThe error appears to be in '/etc/ansible/roles/os_ceilometer/tasks/s11:41
bhyrtedervice_setup.yml': line 34, column 7, but may\nbe elsewhere in the file depending on the exact syntax problem.\n\nThe offending line appears to be:\n\n  block:\n    - name: Add keystone domain\n      ^ here\n"}11:41
bhyrtedany ideas?11:41
bhyrtedwhere to look ;-)11:41
openstackgerritMerged openstack/openstack-ansible-rabbitmq_server stable/train: Drop erlang bump for suse  https://review.opendev.org/69468311:56
jrosserbhyrted: looks like you might need this https://review.opendev.org/69405512:07
bhyrtedthanks, will look at it ;-)12:13
*** cshen has quit IRC12:18
*** cshen has joined #openstack-ansible12:20
*** DanyC has quit IRC12:20
*** DanyC has joined #openstack-ansible12:21
*** schwicht has quit IRC12:26
openstackgerritJonathan Rosser proposed openstack/openstack-ansible stable/train: Bump rabbitmq role SHA  https://review.opendev.org/69475912:36
jrossernoonedeadpunk: ^ this should hopefully unblock stable/train12:37
*** nicolasbock has joined #openstack-ansible12:37
*** cshen has quit IRC12:38
noonedeadpunkI think we  also will need to merge and backport https://review.opendev.org/#/c/694253/12:38
*** cshen has joined #openstack-ansible12:40
jrosserah yes12:40
openstackgerritMerged openstack/openstack-ansible-os_tempest master: Make smoke tests as a default whitelist tests  https://review.opendev.org/65206012:43
chandankumar\o/ finally merged12:44
*** luksky has quit IRC12:47
jrosserchandankumar: noonedeadpunk is that smoke test change something we want on stable/train?12:48
chandankumarjrosser: I think it will work12:49
jrosserwe are still RC in openstack-ansible but maybe not appropriate in tripleo world?12:49
noonedeadpunkBtw, I'm wondering about CI timing12:49
jrosserwe have had many timeouts in the last few days12:50
noonedeadpunkMainly they were for telemetry and centos upgrade jobs:(12:50
openstackgerritMerged openstack/openstack-ansible master: Collect etcd logs  https://review.opendev.org/69371712:55
*** ansmith has quit IRC13:06
*** nurdie has joined #openstack-ansible13:16
*** nurdie_ has joined #openstack-ansible13:17
*** nurdie has quit IRC13:20
*** nurdie_ has quit IRC13:25
*** nurdie has joined #openstack-ansible13:26
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-tests master: tox: Keeping going with docs  https://review.opendev.org/69061313:26
*** nurdie has quit IRC13:27
*** luksky has joined #openstack-ansible13:39
*** weshay|ruck is now known as weshay13:40
jrosserchandankumar: do you know if something has changed in centos designate packaging that we've missed? https://zuul.opendev.org/t/openstack/build/a1a6da070da24907b964aae29318bf34/log/job-output.txt#1333113:40
*** KeithMnemonic has joined #openstack-ansible13:40
*** weshay has quit IRC13:46
*** hwoarang has quit IRC13:52
chandankumarjrosser: https://github.com/rdo-packages/designate-distgit as per this nothing got changed13:55
chandankumarjrosser: https://github.com/rdo-packages/designate-distgit/blob/rpm-master/openstack-designate.spec#L22813:55
jrosseroh https://github.com/rdo-packages/designate-distgit/commit/634042cf25bd0f12e33b0b403fc0b76b03b4d62013:55
jrosserthat'll be it13:56
chandankumarit is obsoleted by openstack-designate-producer13:56
*** hwoarang has joined #openstack-ansible13:58
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-os_designate master: Remove deprecated packages from centos installs  https://review.opendev.org/69477514:00
jrosserchandankumar: thanks for the pointer, should have a fix now14:00
*** ansmith has joined #openstack-ansible14:01
*** ansmith_ has joined #openstack-ansible14:02
*** ansmith has quit IRC14:05
*** rohit02 has quit IRC14:12
jrossernoonedeadpunk: looks like we have something wrong with swift ubuntu distro installs, unless you can see anything obvious i think i'll do an AIO?14:16
jrosserit looks like a package conflict14:16
* noonedeadpunk wondering how upgrade passes14:19
noonedeadpunkjrosser: I guess we need python3 packages14:21
openstackgerritDmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible-os_swift master: Install python3 packages for ubuntu  https://review.opendev.org/69478314:23
openstackgerritDmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible-os_swift master: Install python3 packages for ubuntu  https://review.opendev.org/69478314:25
*** schwicht has joined #openstack-ansible14:26
*** goldyfruit has joined #openstack-ansible14:40
*** goldyfruit_ has joined #openstack-ansible14:51
openstackgerritJonathan Rosser proposed openstack/openstack-ansible stable/train: Collect etcd logs  https://review.opendev.org/69380614:53
*** goldyfruit has quit IRC14:53
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-galera_server stable/train: Restart mysql when package is installed  https://review.opendev.org/69317214:53
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-os_keystone stable/train: Standardize on nginx-extras  https://review.opendev.org/69390314:54
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-os_keystone stable/train: Add possibility to overwrite public repo  https://review.opendev.org/69375714:55
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-os_glance stable/train: Drop common-db tag from db_sync task  https://review.opendev.org/69314614:55
*** udesale has joined #openstack-ansible15:22
*** nurdie has joined #openstack-ansible15:27
*** cshen has quit IRC15:33
jrossernoonedeadpunk: it passes https://review.opendev.org/#/c/694759/15:43
noonedeadpunkjrosser: yes, but I mean jenerally about your concern during upgrade15:44
jrosseryes so this next https://review.opendev.org/#/c/694253/ ?15:45
noonedeadpunkah, nice, it's already voted15:46
openstackgerritMikael Loaec proposed openstack/openstack-ansible-os_horizon stable/rocky: [WIP]Fix panels enable/disable for distro install.  https://review.opendev.org/69280415:54
jrosseryes, and i've depends on what looked like important patches to stable/train so hopefully that will save some time15:54
openstackgerritGeorgina Shippey proposed openstack/openstack-ansible-os_nova master: Remove deprecated filters  https://review.opendev.org/69479815:55
*** macz has joined #openstack-ansible15:58
*** luksky has quit IRC15:59
*** hamzy has quit IRC16:01
*** gyee has joined #openstack-ansible16:02
*** udesale has quit IRC16:06
*** hamzaachi has quit IRC16:12
*** hamzaachi has joined #openstack-ansible16:14
openstackgerritDmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible-os_swift master: Install python3 packages for ubuntu  https://review.opendev.org/69478316:20
*** hamzaachi_ has joined #openstack-ansible16:30
*** hamzaachi has quit IRC16:33
openstackgerritGeorgina Shippey proposed openstack/openstack-ansible-os_nova master: Readd some QEMU distro packages  https://review.opendev.org/69480716:41
*** hamzy has joined #openstack-ansible16:51
openstackgerritMerged openstack/openstack-ansible-rabbitmq_server master: Replace git.openstack.org with opendev.org  https://review.opendev.org/69436616:59
*** hamzaachi_ has quit IRC16:59
*** aedc has joined #openstack-ansible16:59
openstackgerritMerged openstack/openstack-ansible-openstack_openrc master: Replace git.openstack.org with opendev.org  https://review.opendev.org/69436516:59
openstackgerritMerged openstack/openstack-ansible-os_manila master: Replace git.openstack.org with opendev.org  https://review.opendev.org/69432317:00
*** luksky has joined #openstack-ansible17:02
openstackgerritMerged openstack/openstack-ansible-lxc_hosts master: Replace git.openstack.org with opendev.org  https://review.opendev.org/69438017:03
openstackgerritMerged openstack/openstack-ansible-ceph_client master: Replace git.openstack.org with opendev.org  https://review.opendev.org/69438317:07
openstackgerritMerged openstack/openstack-ansible-lxc_container_create master: Replace git.openstack.org with opendev.org  https://review.opendev.org/69438117:12
openstackgerritMerged openstack/openstack-ansible-haproxy_server master: Replace git.openstack.org with opendev.org  https://review.opendev.org/69437817:16
*** rpittau is now known as rpittau|afk17:18
*** hamzy has quit IRC17:21
*** hamzy has joined #openstack-ansible17:22
jrosserfallout from using the tempest smoke tests https://zuul.opendev.org/t/openstack/build/71147cad1e594f5e83d1e548685f0e71/log/logs/openstack/aio1-utility/tempest_run.log.txt.gz17:25
jrosserit's now actually trying to test designate, but as we don't provision bind or anything as a backend in the integrated repo that is never going to pass17:25
openstackgerritMerged openstack/ansible-role-python_venv_build master: Replace git.openstack.org with opendev.org  https://review.opendev.org/69437517:38
*** ThomasThaulow has joined #openstack-ansible17:49
ThomasThaulowHello! :)17:50
*** ThomasThaulow has quit IRC17:56
*** nicolasbock has quit IRC17:58
*** spatel has joined #openstack-ansible17:59
spatelFolks, i want to add "domain_specific_drivers_enabled = True" in /etc/keystone/keystone.conf file under [identitiy] section17:59
spatelwhat entry i should be adding in user_variables.yml?18:00
*** DanyC has quit IRC18:00
spatelkeyston_domain_specific_drivers_enabled = True   ?18:00
*** ThomasThaulow has joined #openstack-ansible18:00
spatelor i should be doing this way - https://docs.openstack.org/project-deploy-guide/openstack-ansible/draft/app-advanced-config-override.html18:01
*** hamzaachi_ has joined #openstack-ansible18:02
ThomasThaulowI have OpenStack Ansible deployed for HA on 2 controllers. However I struggle if servers are restarted, it does not go up again. I need to stop MariaDB, then do a recovery and start to get things working! Any idea why? I read somewhere that HA with kolla-ansible / openstack needs 3 nodes. Might this be relevant?18:02
*** sshnaidm|ruck is now known as sshnaidm|afk18:05
*** ThomasThaulow has quit IRC18:07
spatelThomasThaulow: you need 3 node min for Galera cluster.18:07
spatelOr you this hack - http://heiterbiswolkig.blogs.nde.ag/2018/03/19/ha-galera-two-node-cluster/18:08
*** hamzaachi_ has quit IRC18:09
*** hamzaachi_ has joined #openstack-ansible18:10
jrosserspatel: if there is a var already for you to override in the keystone role defaults, just use that directly18:10
jrosserif there isn’t one, config override is your answer18:10
spateljrosser: variable isn't specified in role file default/main.yml file.18:11
spatelI belive i have to go with override18:11
openstackgerritMerged openstack/openstack-ansible-os_zun master: Replace git.openstack.org with opendev.org  https://review.opendev.org/69436118:12
*** hamzaachi_ has quit IRC18:16
*** hamzaachi_ has joined #openstack-ansible18:16
spateljrosser: question related this block18:18
-spatel- # keystone_ldap:18:18
-spatel- # Users:18:18
-spatel- # url: "ldap://127.0.0.1"18:18
-spatel- # user: "root"18:18
-spatel- # password: "secrete"18:18
spatelIn - https://docs.openstack.org/openstack-ansible-os_keystone/latest/18:18
spatelhow do i define domain name ?18:19
spatellike /etc/keystone/domains/keystone.FOO.conf   (FOO is my domain)18:19
mnaserdid you check the role code? :)18:20
mnaserhttp://github.com/openstack/openstack-ansible-os_keystone has all your answers on how FOO is created18:20
spatel:) now doing it...18:20
jrosseryes it is all there in the doc I think18:21
jrosserright here https://docs.openstack.org/openstack-ansible-os_keystone/latest/configure-keystone.html#implementing-ldap-or-active-directory-backends18:22
spatelin doc its not saying where to specify domain ?18:22
spatelMyCorporation:18:22
mnasermaybe look at the actual roles18:22
spateldamn it :)18:22
-spatel- keystone_ldap:18:23
-spatel- MyCorporation:18:23
spatelMyCorporation going to be my FOO domain18:23
jrosseryes :)18:23
spatelThanks both of you :)18:24
spateljrosser: in that doc its not saying anywhere that "domain_specific_drivers_enabled" is default False, it would be good to have one liner saying enable domain_specific_drivers_enabled before move forward.18:27
jrosserpatch it :)18:28
spateli never done patch before so it would be learning curve for me, but happy to do that18:28
jrosserI’ve not looked at keystone/ldap before18:28
chandankumarjrosser: does designate issue got fixed?18:29
jrosserso if we already have a switch to turn that on and it’s missing a setting, it should be fixed18:29
jrosserchandankumar: yes and no :/18:29
chandankumarjrosser: sorry did not get that, any other issue pops up?18:30
jrosseryes the packages are now installed properly I think, but the tempest change looks like it actually now really tries to test designate18:30
jrosserI think the smoke test change may now be increasing the test coverage, which is good18:30
spateljrosser: we should add "domain_specific_drivers_enabled" key in role/os_keystone/default/main.yml which is missing (so folks can turn on/off) - https://docs.openstack.org/keystone/latest/admin/configuration.html#integrate-identity-with-ldap18:31
jrosserspatel: or we can wire it automatically if keystone_ldap is defined18:32
jrosserbut like I say I never really did this so would have to look at what the right answer is18:32
spateljrosser: there are two way we can enable LDAP with multi-domain and without multi-domain ( best approach is multi-domain )18:34
chandankumarjrosser: good to know that if designate tests failing we can ask team to look into that18:34
jrosserchandankumar: I think really it’s an OSA issue, we leave it to the deployer to make the designate backend DNS with bind or powerdns or whatever they want18:36
spateljrosser: anyway we can at least improve documentation of OSA and rest folks can decide.. :)18:36
chandankumarjrosser: :-)18:36
jrosserchandankumar: so now the designate tempest test actually tries to test it, there’s no backend there so *fail*18:36
*** gouthamr_ is now known as gouthamr18:51
openstackgerritMerged openstack/openstack-ansible-os_cinder master: Replace git.openstack.org with opendev.org  https://review.opendev.org/69429519:26
mgariepyspatel, https://github.com/openstack/openstack-ansible-os_keystone/blob/master/templates/keystone.conf.j2#L78-L8119:28
*** aedc has quit IRC19:29
openstackgerritMerged openstack/openstack-ansible-os_nova master: Replace git.openstack.org with opendev.org  https://review.opendev.org/69432819:31
*** tosky has quit IRC19:34
*** nicolasbock has joined #openstack-ansible19:38
spatelmgariepy: sweet!!!19:39
openstackgerritMerged openstack/openstack-ansible-os_magnum master: Replace git.openstack.org with opendev.org  https://review.opendev.org/69431819:42
openstackgerritMerged openstack/openstack-ansible-repo_server master: Replace git.openstack.org with opendev.org  https://review.opendev.org/69436719:47
spatelmgariepy: how do i push LDAP SSL cert file for TLS connection?  or it has to be manually ?19:48
spateltls_cacertfile: "/etc/keystone/ssl/ipa.crt" this file.19:49
openstackgerritMerged openstack/openstack-ansible-os_blazar master: Replace git.openstack.org with opendev.org  https://review.opendev.org/69428219:49
mgariepyspatel, yep you need to push it manually last time i checked.19:52
mgariepyspatel, also i you are using ldap with domains you will have to disable openrc v2 from horizon : https://github.com/openstack/openstack-ansible-os_horizon/blob/master/defaults/main.yml#L25719:53
openstackgerritMerged openstack/openstack-ansible-os_neutron master: Replace git.openstack.org with opendev.org  https://review.opendev.org/69432519:54
spatelmgariepy: hmm! so i have to do horizon_show_keystone_v2_rc: False19:56
openstackgerritMerged openstack/openstack-ansible-os_heat master: Replace git.openstack.org with opendev.org  https://review.opendev.org/69430919:59
mgariepywhich releaes are you deploying ?19:59
openstackgerritMerged openstack/openstack-ansible-os_keystone master: Replace git.openstack.org with opendev.org  https://review.opendev.org/69431519:59
spateli have queen and stein19:59
mgariepymake sure horizon playbooks supports it for your release.19:59
spatelif not then can i edit by hand?20:00
mgariepybut you cloud always do overrides but i haven't done that for horizon config.20:00
spatellet me see what i can do..20:00
openstackgerritMerged openstack/openstack-ansible-os_masakari master: Replace git.openstack.org with opendev.org  https://review.opendev.org/69431920:01
spateli believe i have to add TLS config in /etc/ldap/ldap.conf file also, not sure if ansible playbook take care of it or not20:02
spatelmgariepy: also how do i add [assignment] section in /etc/keystone/domains/keystone.FOO.conf file.20:04
spatelhttps://github.com/openstack/openstack-ansible-os_keystone/blob/master/templates/keystone.domain.conf.j220:05
spatelshould i be adding here or overwrite should support?20:05
mgariepyhttps://github.com/openstack/openstack-ansible-os_keystone/blob/master/tasks/keystone_ldap_setup.yml#L35-L4620:06
spatelI want to add following two line in domain specific file..20:08
-spatel- [assignment]20:08
-spatel- driver = sql20:08
spatelas per this it doesn't support - https://github.com/openstack/openstack-ansible-os_keystone/blob/master/templates/keystone.domain.conf.j220:08
spatelif you don't specify assignment then default is driver = ldap20:09
spatelbut in my case i want to use sql20:09
spatelif it required patch then i can open ticket for improvement.20:10
mgariepymy assignement is sql backed.20:11
spateldo you have assignment specified in domain specific file?20:12
spatelmay be that value coming from keystone.conf file20:12
spatellet me try without that and see if it work20:12
mgariepyin keystone.conf i have [assignement] driver=sql20:13
mgariepyand both local sql accounts(default domain) and ldap domain do use local sql assignment20:13
spateli thought domain specific file also need that but look like not.20:13
mgariepynop it doesn't need it.20:14
*** hamzaachi_ has quit IRC20:26
cjloaderhi can we get +2+W on https://review.opendev.org/#/c/693903/?20:28
spatelmgariepy: domain = project right in multi-domain ?20:29
spatelif i create keystone.foo.conf then i have to create foo project to match config20:30
mgariepyno20:31
spatelhmm!20:31
mgariepythe domain will hold your users, you will have to do something like: openstack user list --domain <my_super_domain>20:32
mgariepyto list the users from that domain20:32
spatelI am getting this error "You are not authorized for any projects or domains."  (you are saying i have to create domain foo in sql and inside that domain i can create whatever project name i like.. bar / abc etc..)20:32
mgariepyyou are not part of any project.20:32
mgariepyyou can add a domain user to a project under the default domain.20:33
mgariepyyou can do like: openstack role add --user test --user-domain my_domain --project my-project member20:33
spatelBut i have to create "foo" domain first right otherwise how ldap will pull users?20:34
spatelcurrently i have only "Default" domain20:35
mgariepyyou add your config for ldap in user_variable.yml20:35
spatelthat i did20:35
mgariepythen run keystone playbook20:35
spatelthat i did too20:35
mgariepyfrom there, if you go into the utility container you can list the user from your domain ?20:35
mgariepyopenstack user list --domain <domain you configured>20:36
mgariepyyou see your ldap user?20:36
spateloh!!! i can see LDAP users now20:36
spateli was missing --domain foo  option20:37
mgariepyyou can configured horizon to either user multiple domains or not.20:37
spatelI did configure horizon also20:37
spateland i can see domain option20:37
spatelhow do i assign ldap user to default domain _member_ role?20:38
mgariepyyep20:38
mgariepyopenstack role assignment list --project <project> --names20:39
mgariepy( --names ) is your friend.20:39
mgariepywhat i do is : openstack role add --project myproject --user myuser --user-domain foo Member20:40
spatellet me try20:41
spatelsweet!!! that did the magic :)20:42
spateli am in20:42
spateli was confused in domain vs project... :)20:43
spateli thought i have to create domain in sql which will get map with ldap domain, but now its clear :)20:43
mgariepyit's...20:44
mgariepyflexible.20:44
mgariepyhaha20:44
spatelthanks for your help!!20:45
spatelmgariepy: do you guys use teraform ?20:45
spatelhow do i manager password in file ? (i am worried about security)20:45
spatelhow do you manage password in file ? (i am worried about security)20:45
mgariepyi don't use terraform much but some users do.20:47
spatelwe are also not using but look like in soon we will start using it, looking for good way to handle password in file..20:48
*** schwicht has quit IRC20:50
mgariepyin keystone you can have application credential. but i havent used it yet.20:51
mgariepysoon maybe.20:51
spatelhmm i heard that and will look into it20:55
mgariepycya20:57
*** mgariepy has quit IRC20:57
*** goldyfruit_ has quit IRC21:02
*** goldyfruit has joined #openstack-ansible21:17
openstackgerritMerged openstack/openstack-ansible stable/train: Bump rabbitmq role SHA  https://review.opendev.org/69475921:26
*** DanyC has joined #openstack-ansible21:28
*** schwicht has joined #openstack-ansible21:31
*** ansmith_ has quit IRC21:34
*** schwicht has quit IRC21:48
*** hamzaachi has joined #openstack-ansible21:52
openstackgerritBjoern Teipel proposed openstack/openstack-ansible master: Adding missing tag for dynamic-address-fact task  https://review.opendev.org/69484921:53
jrosserwe need to fix this cert check https://zuul.opendev.org/t/openstack/build/121aacc2bf2e48d59e8826b5891c2c03/log/logs/openstack/aio1-utility/tempest.log.txt.gz#23621:53
*** hamzaachi has quit IRC21:53
*** hamzaachi has joined #openstack-ansible21:54
*** hamzaachi has quit IRC21:55
*** hamzaachi has joined #openstack-ansible21:55
*** hamzaachi_ has joined #openstack-ansible22:06
jrossermaster is now blocked with the tempest smoke test change, ceph fails https://review.opendev.org/#/c/694253/22:06
*** hamzaachi has quit IRC22:07
openstackgerritMerged openstack/openstack-ansible-os_neutron master: pep8 fix  https://review.opendev.org/69141222:14
*** schwicht has joined #openstack-ansible22:24
*** hwoarang has quit IRC22:24
*** tosky has joined #openstack-ansible22:26
*** pcaruana has quit IRC22:26
*** schwicht has quit IRC22:26
openstackgerritMerged openstack/openstack-ansible-os_placement master: Replace git.openstack.org with opendev.org  https://review.opendev.org/69434822:26
*** hwoarang has joined #openstack-ansible22:28
*** ansmith_ has joined #openstack-ansible22:29
*** DanyC has quit IRC22:32
*** DanyC has joined #openstack-ansible22:33
*** hamzaachi_ has quit IRC22:38
*** nurdie has quit IRC22:41
*** luksky has quit IRC23:02
*** spatel has quit IRC23:02
*** admin0 has joined #openstack-ansible23:09
*** DanyC has quit IRC23:19
*** nurdie has joined #openstack-ansible23:21
*** nurdie has quit IRC23:25
*** ivve has quit IRC23:26
*** goldyfruit has quit IRC23:36
*** nicolasbock has quit IRC23:50

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!