Wednesday, 2020-02-05

*** vesper has joined #openstack-ansible01:38
*** vesper11 has quit IRC01:39
*** gyee has quit IRC02:00
*** djhankb has joined #openstack-ansible02:05
*** rh-jelabarre has quit IRC03:13
*** raukadah is now known as chkumar|rover04:22
*** udesale has joined #openstack-ansible04:53
*** evrardjp has quit IRC05:33
*** evrardjp has joined #openstack-ansible05:34
*** errr has quit IRC05:55
*** errr has joined #openstack-ansible05:56
*** errr has quit IRC06:05
*** errr has joined #openstack-ansible06:07
*** jbadiapa has joined #openstack-ansible06:51
*** southquist has joined #openstack-ansible06:55
*** bhyrted has quit IRC06:59
openstackgerritMohammed Naser proposed openstack/openstack-ansible-os_nova master: pre-install: check if path is defined  https://review.opendev.org/70589207:21
openstackgerritMohammed Naser proposed openstack/openstack-ansible-os_nova master: pre-install: check if path is defined  https://review.opendev.org/70589207:41
*** elenalindq has joined #openstack-ansible08:16
*** rpittau|afk is now known as rpittau08:34
*** gshippey has joined #openstack-ansible08:45
*** gillesMo has joined #openstack-ansible08:49
*** DanyC has joined #openstack-ansible08:57
jrosseri think this is the next piece needed to unbreak stable/train https://review.opendev.org/#/c/703572/08:57
*** feichh has joined #openstack-ansible09:23
*** shyamb has joined #openstack-ansible10:06
*** mjwales has joined #openstack-ansible10:06
mjwalesEnabling page_size in an ldap keystone domain causes a critical error in Keystone: ERROR keystone IOError: write error. Has anyone come across this before?10:07
*** shyamb has quit IRC10:38
openstackgerritMerged openstack/openstack-ansible master: Bump SHAs for master  https://review.opendev.org/70425310:46
*** lkoranda has joined #openstack-ansible11:05
*** rpittau is now known as rpittau|bbl11:10
*** udesale_ has joined #openstack-ansible11:13
*** shyamb has joined #openstack-ansible11:15
*** udesale has quit IRC11:16
*** pcaruana has quit IRC11:37
*** ahosam has joined #openstack-ansible11:39
openstackgerritDmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible master: Do not append container_name for metal containers  https://review.opendev.org/70577811:40
openstackgerritMerged openstack/openstack-ansible stable/rocky: Remove log compression before upload  https://review.opendev.org/70337411:43
*** ahosam has quit IRC11:46
*** pcaruana has joined #openstack-ansible11:50
*** cshen has joined #openstack-ansible12:07
openstackgerritDmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible master: Do not append container_name for metal containers  https://review.opendev.org/70577812:09
*** tosky has joined #openstack-ansible12:12
*** cshen_ has joined #openstack-ansible12:12
*** shyamb has quit IRC12:13
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-openstack_hosts master: Use python3 to drop hosts file script where possible  https://review.opendev.org/70584912:15
*** cshen has quit IRC12:32
*** cshen has joined #openstack-ansible12:32
mathlinjrosser: thanks, worked like a charm12:42
*** rh-jelabarre has joined #openstack-ansible12:45
*** shyamb has joined #openstack-ansible12:54
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-openstack_hosts master: Use python3 to drop hosts file script where possible  https://review.opendev.org/70584913:01
openstackgerritDmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible-openstack_hosts master: Install gpg binary for Debian based systems  https://review.opendev.org/70595513:07
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-openstack_hosts master: Use python3 to drop hosts file script where possible  https://review.opendev.org/70584913:14
*** rpittau|bbl is now known as rpittau13:15
*** bhyrted has joined #openstack-ansible13:16
*** shyamb has quit IRC13:18
*** electrofelix has joined #openstack-ansible13:29
openstackgerritDmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible-ceph_client master: ansible_distribution_release insted of ansible_lsb  https://review.opendev.org/70596213:36
*** cshen_ has quit IRC13:38
openstackgerritSam Choraria proposed openstack/openstack-ansible-ops master: Allow beat processors to be defined through configuration data  https://review.opendev.org/70596513:45
*** lkoranda has quit IRC13:58
*** rpittau is now known as rpittau|mtg14:03
*** DanyC_ has joined #openstack-ansible14:06
*** DanyC has quit IRC14:10
*** lkoranda has joined #openstack-ansible14:12
*** pcaruana has quit IRC14:17
*** rpittau|mtg is now known as rpittau14:25
*** jamesdenton has joined #openstack-ansible14:34
*** cshen has quit IRC14:40
*** DanyC_ has quit IRC14:43
*** DanyC has joined #openstack-ansible14:44
*** DanyC has quit IRC14:45
*** DanyC has joined #openstack-ansible14:46
*** cshen has joined #openstack-ansible14:51
*** sshnaidm|afk is now known as sshnaidm14:51
*** cshen has quit IRC14:56
*** DanyC has quit IRC14:58
*** lkoranda has quit IRC15:01
*** DanyC has joined #openstack-ansible15:07
*** DanyC has quit IRC15:13
*** DanyC has joined #openstack-ansible15:13
*** DanyC has quit IRC15:18
*** CeeMac has joined #openstack-ansible15:25
*** chkumar|rover is now known as raukadah15:27
bjoerntAny ETA on 19.0.10 ?15:31
*** mjwales has quit IRC15:33
*** ianychoi_ is now known as ianychoi15:40
*** pcaruana has joined #openstack-ansible15:49
*** DanyC has joined #openstack-ansible15:57
*** openstackstatus has joined #openstack-ansible16:04
*** ChanServ sets mode: +v openstackstatus16:04
openstackgerritSam Choraria proposed openstack/openstack-ansible-ops master: Allow beat processors to be defined through configuration data  https://review.opendev.org/70596516:04
*** southquist has quit IRC16:06
*** udesale_ has quit IRC16:24
openstackgerritDmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible-os_nova master: Change nova_lock_path mode  https://review.opendev.org/70600616:31
noonedeadpunkbjoernt: patch is placed https://review.opendev.org/#/c/705447/116:33
noonedeadpunkwaiting for the release team approval16:33
bjoerntyes I was wondering why the patch didnt get merged16:34
*** DanyC_ has joined #openstack-ansible16:35
*** spatel has joined #openstack-ansible16:37
*** DanyC has quit IRC16:38
spatelnow my single openstack cluster has 350 compute nodes... do i need to be worry? or should i keep adding more?16:38
spatelEverything looks good on infra nodes.. rabbit, mysql etc...16:39
bjoerntWe have clusters running with well over 400 nodes but you need to watchout for api threads on neutron nova16:46
*** DanyC_ has quit IRC16:46
bjoerntrabbitmq ha policy I would watch out for16:46
openstackgerritDuncan Martin Walker proposed openstack/openstack-ansible-ops master: Expose Elasticsearch data path configuration  https://review.opendev.org/70477016:46
openstackgerritDuncan Martin Walker proposed openstack/openstack-ansible-ops master: Exposed config for logstash elasticsearch endpoints  https://review.opendev.org/70548316:46
openstackgerritDuncan Martin Walker proposed openstack/openstack-ansible-ops master: Explicitly use Elasticsearch data node for ILM index update  https://review.opendev.org/70601416:46
openstackgerritDuncan Martin Walker proposed openstack/openstack-ansible-ops master: Update ILM policy if non-existent  https://review.opendev.org/70601516:46
*** DanyC has joined #openstack-ansible16:46
spatelbjoernt: what to watch in ha policy?16:48
spateldo you know metrics ?16:48
bjoerntto limit to 2 copies16:48
bjoerntand that you run hipe which should be default16:49
spateldo you know any command or tool i should be checking that?16:49
spatelI am not very expert in rabbitMQ16:49
spateljust monitoring basic mesg rate at this point16:50
bjoerntlook inside the rabbitmq console to see message growth and latency16:50
bjoerntalso run the controller nodes on performance governor16:50
*** DanyC has quit IRC16:51
spatelbjoernt: you meant -> cpupower frequency-set -g governor16:51
bjoerntone way out of millions, lol16:51
bjoerntyes16:51
spatelDo you monitoring rabbitMQ with builtin monitoring GUI or you have other metrics?16:52
spatelI have telegraf script pumping data in influx16:52
openstackgerritDuncan Martin Walker proposed openstack/openstack-ansible-ops master: Explicitly use Elasticsearch data node for ILM index update  https://review.opendev.org/70601417:05
openstackgerritDuncan Martin Walker proposed openstack/openstack-ansible-ops master: Update ILM policy if non-existent  https://review.opendev.org/70601517:05
openstackgerritSam Choraria proposed openstack/openstack-ansible-ops master: Allow beat processors to be defined through configuration data  https://review.opendev.org/70596517:10
bjoerntwe have custom monitoring which use the management api17:15
*** DanyC has joined #openstack-ansible17:19
noonedeadpunkgshippey: regarding https://opendev.org/openstack/openstack-ansible-os_nova/commit/149d555d6b19ccfd903fff2797d901bfa3a0c69f are you sure that qemu-system and qemu-system-misc are required, since they just bring more archs to be supported?17:21
*** DanyC has quit IRC17:22
*** DanyC has joined #openstack-ansible17:22
jrossernoonedeadpunk: i think the issue was at upgrade time17:24
jrosserwhen you had older versions of those things installed, but becasue the extra packages had been dropped and are not coming in through a depends-on you end up with broken installation17:25
noonedeadpunkjrosser: yeah, I can recall it, and I agree that qemu-utils _must_ be in the list17:25
noonedeadpunkso we kinda need to drop them in an appropriate way?17:26
noonedeadpunkso that be no conflict during packages update?17:26
jrosserif they're no longer needed then they should be uninstalled, rather than just dropped from the install list17:27
jrosserthen i think it would be ok17:27
*** gyee has joined #openstack-ansible17:29
*** shananigans has joined #openstack-ansible17:29
noonedeadpunkI just do one pretty hacky thing, and like in older nova if archs not in the list are installed https://opendev.org/openstack/nova/src/branch/master/nova/objects/fields.py#L208-L216 nova-compute just fails with "InvalidArchitectureName: Architecture name 'armv6l' is not recognised"17:30
noonedeadpunkwhile I have x86_64 host17:30
noonedeadpunkI think it's fixed now though in nova, so not a big deal17:32
*** evrardjp has quit IRC17:33
*** evrardjp has joined #openstack-ansible17:34
jrosserdo you think we shave something broken that needs fixing?17:35
*** DanyC has quit IRC17:35
*** DanyC has joined #openstack-ansible17:36
jrosseri did some more centos-8 today, seems unclear if repo priorities are a thing any more though17:38
jrossermnaser: ^ have you done any centos-8?17:39
*** DanyC_ has joined #openstack-ansible17:39
*** DanyC has quit IRC17:40
*** NobodyCam has quit IRC17:50
*** NobodyCam has joined #openstack-ansible17:51
*** errr has quit IRC17:56
*** errr has joined #openstack-ansible17:56
openstackgerritDuncan Martin Walker proposed openstack/openstack-ansible-ops master: Propagated ILM changes to auditbeat install  https://review.opendev.org/70606918:00
*** DanyC has joined #openstack-ansible18:01
*** DanyC has quit IRC18:01
*** rpittau is now known as rpittau|afk18:01
*** johnsom has quit IRC18:03
*** johnsom has joined #openstack-ansible18:03
*** DanyC_ has quit IRC18:05
spateljrosser: if you want i can give it a try with centos-8 (i was thinking of deploying osa on centos-8 in my lab)18:28
jrosserwell this is extremely early attempt to build an AIO without containers18:29
jrosserand I seem to fail at simple things like making the rpm repo priorities work currently18:30
jrosserand also having to compile non existent packages from C code :(18:30
jrosserif you want to hack on getting centos 8 working that would be great18:31
spateljrosser: i will give it a shot18:42
*** theintern_ has joined #openstack-ansible18:51
*** theintern_ is now known as the_intern18:52
*** electrofelix has quit IRC18:59
*** gshippey has quit IRC19:01
openstackgerritShannon Mitchell proposed openstack/openstack-ansible-os_designate master: Fix paging link protocol when behind haproxy  https://review.opendev.org/70609019:14
*** spatel has quit IRC19:22
*** NobodyCam has quit IRC19:39
*** johnsom has quit IRC19:40
*** bhyrted has quit IRC20:24
guilhermespjamesdenton: hey man, I've faced some strange behavious with iptables_hybrid driver for ovs... like after creating batches of vms at once, there is a point that neutron agent breaks like http://paste.openstack.org/show/789175/ and then vms fails to allocate a ports. I talked with some guys on neutron and they said like ovs firewall is mostly used in train now20:47
guilhermespafter changing my driver from iptables_hybrid to openvswitch, it seems the iptable errors on agents are not happenening aymore20:48
guilhermespare you aware of something regarding support or testing of iptables_hybrid driver so far?20:49
jamesdentonone sec20:49
jamesdentonon a call20:49
guilhermespsure! no worries :)20:49
*** mgariepy has quit IRC20:54
*** the_intern has quit IRC20:58
jamesdentoncan't say i have seen that, as we are dealing primarily with Stein right now (w/ iptables_hybrid IIRC)21:07
jamesdentonbut it does look like some invalid lines may be at fault21:07
jamesdentonhow many are you spinning up simultaneously21:08
guilhermespi did 4 batches of 15 instances, the 4th batch usually breaks agent21:09
guilhermespso when I changed to openvswitch driver, like much more batches ( >100vm) in an interval of 5 to 10 minutes didn't break for now21:09
guilhermespwe are with a deployment which is under a stress test since yesterday21:09
jamesdentonit would not surprise me if there was some regression in that driver21:10
guilhermespso at some point, with lots of vms being created in a small interval breaks ovs agents21:10
jamesdentonhow are you recovering from the issue?21:11
guilhermesphaleyb on #openstack-neutron commented that ovs firewall is mostly used in train and is more tested in gates nowadays i guess21:11
guilhermesprestarting the agent jamesdenton21:11
jamesdentonyeah, i know that ovs firewall has become used more and more. there was a bug i didn't like and had refrained from using it. it just got patched but i have not tested it21:12
jamesdentonhttps://bugs.launchpad.net/neutron/+bug/173206721:12
openstackLaunchpad bug 1732067 in OpenStack Security Notes "openvswitch firewall flows cause flooding on integration bridge" [Undecided,New]21:12
guilhermesphum i see, yeah im not sure about ovs firewall tbh... but we might have an issue with iptables_hybrid as we use as the default driver for ovs21:13
jamesdentonyeah, you're kinda screwed either way!21:13
jamesdentonport_security=false. fixed.21:13
guilhermespjamesdenton: lol yeah, i think stress tests screws us all at some point21:14
guilhermesphum so you leave the port unsecure to fix the bug above o.O ?21:16
jamesdentonnaw, just saying don't run port security and you won't have any ovs firewall or iptables issues :D21:17
guilhermespah yeah21:18
*** tosky has quit IRC21:18
guilhermespwell, in that case I will try out openvswitch and see how it behaves in subsequent stress testings21:20
jamesdentonworth a shot. we had seen performance degradation (actual lower throughput) with that bug i referenced21:21
jamesdentonbut it was a whiel ago21:21
jamesdentonif i have some time tomorrow, i will try to replicate your test in my env21:21
jamesdentonwill have to see where i am at neutron-wise21:21
guilhermespnice jamesdenton thanks! I will keep watching metrics of our rally tests to see if the error occours again. Currently I have some computes that are going to be tested running openvswitch driver21:23
guilhermespi will keep you informed as well21:23
jamesdentonplease do!21:23
jamesdentonwere those the only relevant logs you had? at that url?21:24
guilhermespyeah... i've spent the whoole day looking for other relevant logs21:24
guilhermespbut all rally tests were failing with timeouts to build ( allocate the port). Then I started to do some manual testss and creating lots of vms on only one compue, at some point, broke the agent and I was not able to create more instnace in this compute21:25
guilhermesponly after a agent restart ( restart and wait for some time to flush error logs )21:25
jamesdentoncan you share your server create command?21:27
guilhermespand tbh, never seen such errors.... we monitor the agents, and even with those iptables rules breaking the agent, we could see the agent up through the openstack perspective.21:27
guilhermespusually openstack server create --flavor test --image ubuntu-bionic --key-name deploy --availability-zone nova:kvm3.specterops.iad1.vexxhost.net --network public --max 15 test-kvm321:27
jamesdentonyeah, it's "healthy"21:28
jamesdentonok pretty standard. cool, thanks21:28
jamesdentonwhat um, neutron version are you at? /openstack/venvs/neutron-*21:28
guilhermesp20.0.121:29
jamesdentonok, i have some upgrading to do21:29
jamesdentoni will keep ya posted21:30
guilhermespthe only difference for now is that we were using centos compute nodes, but now we are running debian ones21:30
jrosserlooks like theres a fix to the ovs flooding in stable/train now21:30
guilhermespi did a conversion recentrly, but not sure if I can say that is related to distro as the cloud started to be heavily used 1 day ago21:30
*** elenalindq has quit IRC21:30
jamesdentonhmmm, maybe it's a debian thing :D21:31
guilhermespi guess that may the reason it is more tested on gates now ;P21:31
guilhermespit's a debian buster compute running 20.0.121:31
guilhermespok so will have a quick rehearsal in a while but I will try to keep an eye here in case you need some more details21:32
jamesdentoni won't have time to look today but it's on my list21:32
guilhermespcool cool thanks anyways \m/21:33
*** hwoarang has quit IRC21:35
*** hwoarang has joined #openstack-ansible21:37
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-os_tempest stable/train: Always use virtualenv and pip to install tempest on Ubuntu  https://review.opendev.org/70533621:55
*** nicolasbock has joined #openstack-ansible21:57
*** nicolasbock has quit IRC22:23
*** yolanda has joined #openstack-ansible22:35
*** shananigans has quit IRC22:40
*** rh-jelabarre has quit IRC22:46
*** NobodyCam has joined #openstack-ansible23:00
*** johnsom has joined #openstack-ansible23:02
*** hwoarang has quit IRC23:51
*** hwoarang has joined #openstack-ansible23:53

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!