Monday, 2020-07-13

*** this10nly has quit IRC00:55
*** markvoelker has joined #openstack-ansible01:15
*** schwicht has quit IRC01:18
*** markvoelker has quit IRC01:19
*** markvoelker has joined #openstack-ansible02:21
*** cshen has joined #openstack-ansible02:23
*** markvoelker has quit IRC02:25
*** cshen has quit IRC02:27
*** nurdie has joined #openstack-ansible02:33
*** markvoelker has joined #openstack-ansible02:34
*** markvoelker has quit IRC02:39
*** markvoelker has joined #openstack-ansible03:31
*** markvoelker has quit IRC03:36
*** dave-mccowan has quit IRC03:37
*** raukadah is now known as chandankumar04:20
*** cshen has joined #openstack-ansible04:23
*** cshen has quit IRC04:27
*** evrardjp has quit IRC04:33
*** evrardjp has joined #openstack-ansible04:33
*** nurdie has quit IRC04:56
*** nurdie has joined #openstack-ansible04:57
*** nurdie has quit IRC05:01
*** markvoelker has joined #openstack-ansible05:32
*** markvoelker has quit IRC05:36
*** udesale has joined #openstack-ansible05:38
chandankumarnoonedeadpunk: Hello, please have a look at this patch https://review.opendev.org/#/c/736507/ and https://review.opendev.org/727067 why ironic tests are not getting triggered, when free, thanks!05:56
jannodoes anyone deploy designate with openstack-ansible? how do you connect your nameservers with the designate containers as they don't have any public ip address05:56
*** nurdie has joined #openstack-ansible06:17
*** cshen has joined #openstack-ansible06:23
*** nurdie has quit IRC06:23
*** cshen has quit IRC06:28
*** this10nly has joined #openstack-ansible06:39
*** arkan has joined #openstack-ansible06:39
*** tosky has joined #openstack-ansible06:39
*** pcaruana has joined #openstack-ansible06:49
*** arkan has quit IRC06:52
*** yolanda has joined #openstack-ansible07:07
*** stingrayza has joined #openstack-ansible07:22
*** also_stingrayza has quit IRC07:23
jrosserjanno: it is possible to add extra interfaces to specific containers07:26
jrosserjanno: but this really all depends on how you want the architecture to end up and which actual dns server you're going to use07:30
jrosseri've done this with bind in the past07:30
*** arkan_ has joined #openstack-ansible07:53
*** arkan_ is now known as arkan07:53
*** halali_ has joined #openstack-ansible07:54
*** spatel has joined #openstack-ansible08:20
jannojrosser: thanks for the hint. we are looking at pdns at the moment, but bind would be an option as well08:22
jrosserjanno: i don't really know how it would work for pdns but with bind it does a zone transfer08:23
*** cshen has joined #openstack-ansible08:23
jrosserand i had it set up so that there was an interface on the designate container that could communicate both ways with where the bind was08:24
jrosserbut in my case that wasnt a public IP as the bind instance was pretty much in the same infrastructure08:25
*** spatel has quit IRC08:25
*** cshen has quit IRC08:28
jrosserjanno: actually i made some documentation for adding extra networks https://opendev.org/openstack/openstack-ansible/src/branch/master/doc/source/reference/configuration/extra-networks.rst08:28
jrosserfor something like designate it's good to arrange it so that there are fixed, known addresses on those extra container interfaces08:31
jrosserthen you can set up the config of the dns server to only allow transfers from those IP08:31
*** nurdie has joined #openstack-ansible08:35
*** jbadiapa has joined #openstack-ansible08:40
*** nurdie has quit IRC08:40
jannojrosser: thanks, I'll have a look at adding extra networks08:42
jrosserif you need any help give me a shout - you can also do it with fixed IP rather than the dynamic inventory which might be important for designate08:43
*** cshen has joined #openstack-ansible08:48
*** nurdie has joined #openstack-ansible08:51
*** arkan has quit IRC08:52
*** arkan has joined #openstack-ansible08:52
*** nurdie has quit IRC08:56
*** nurdie has joined #openstack-ansible09:06
*** sshnaidm|afk is now known as sshnaidm09:09
*** nurdie has quit IRC09:11
openstackgerritMartin Kopec proposed openstack/openstack-ansible-os_tempest master: Remove deprecated scenario image option  https://review.opendev.org/72024209:11
openstackgerritMartin Kopec proposed openstack/openstack-ansible-os_tempest master: Remove deprecated scenario image option  https://review.opendev.org/72024209:17
openstackgerritMartin Kopec proposed openstack/openstack-ansible-os_tempest master: Remove deprecated scenario image option  https://review.opendev.org/72024209:17
*** aedc_ has joined #openstack-ansible09:27
*** cshen has quit IRC09:28
*** gshippey has joined #openstack-ansible09:41
*** halali_ has quit IRC09:43
*** shyamb has joined #openstack-ansible09:46
*** arkan has quit IRC09:52
*** shyamb has quit IRC09:53
*** arkan_ has joined #openstack-ansible09:54
*** arkan_ is now known as arkan09:54
*** cshen has joined #openstack-ansible10:01
*** cshen has quit IRC10:06
*** shyamb has joined #openstack-ansible10:27
*** cshen has joined #openstack-ansible10:33
*** cshen has quit IRC10:37
*** arkan has quit IRC10:52
*** halali_ has joined #openstack-ansible11:00
*** mgariepy has quit IRC11:03
*** markvoelker has joined #openstack-ansible11:06
*** arkan has joined #openstack-ansible11:09
*** schwicht has joined #openstack-ansible11:10
*** cshen has joined #openstack-ansible11:12
*** markvoelker has quit IRC11:16
*** cshen has quit IRC11:17
*** shyamb has quit IRC11:18
*** cshen has joined #openstack-ansible11:28
*** shyamb has joined #openstack-ansible11:30
*** markvoelker has joined #openstack-ansible12:01
*** markvoelker has quit IRC12:04
*** udesale_ has joined #openstack-ansible12:09
*** dave-mccowan has joined #openstack-ansible12:11
*** strattao has joined #openstack-ansible12:11
*** rh-jelabarre has joined #openstack-ansible12:12
*** udesale has quit IRC12:12
*** rh-jelabarre has quit IRC12:12
*** rh-jelabarre has joined #openstack-ansible12:12
*** mgariepy has joined #openstack-ansible12:13
*** dave-mccowan has quit IRC12:15
*** shyamb has quit IRC12:40
*** namrata has joined #openstack-ansible12:59
*** spatel has joined #openstack-ansible12:59
*** cshen has quit IRC13:06
*** mmethot has joined #openstack-ansible13:10
*** cshen has joined #openstack-ansible13:11
jannojrosser: I am following https://docs.openstack.org/openstack-ansible/latest/reference/configuration/extra-networks.html, but I wonder how/where to add the container_vars part as we have 'dnsaas_hosts: *infrastructure_hosts' in our config13:11
namrataHi Folks, I have a question about the release schedule, is there going to be a next stable/train release and if yes when it is planned.I have to present somethin which involves checkout to stable/train which I will do on 20.1.3(which fices inventory-manage.py TypeError issue) and do a minor upgrade (hence the next release question)13:24
*** aedc_ has quit IRC13:26
openstackgerritMerged openstack/openstack-ansible-plugins stable/ussuri: Do not use paramkio transport for delegated tasks  https://review.opendev.org/73952613:26
*** udesale_ has quit IRC13:27
*** jbadiapa has quit IRC13:27
*** irclogbot_2 has quit IRC13:27
*** alvinstarr has quit IRC13:27
*** maharg101 has quit IRC13:27
*** admin0 has quit IRC13:27
*** udesale_ has joined #openstack-ansible13:28
*** jbadiapa has joined #openstack-ansible13:28
*** irclogbot_2 has joined #openstack-ansible13:28
*** alvinstarr has joined #openstack-ansible13:28
*** maharg101 has joined #openstack-ansible13:28
*** admin0 has joined #openstack-ansible13:28
*** noonedeadpunk has quit IRC13:31
*** d34dh0r53 has joined #openstack-ansible13:45
*** nurdie has joined #openstack-ansible14:05
*** nurdie has quit IRC14:07
*** nurdie has joined #openstack-ansible14:08
*** cshen has quit IRC14:10
*** nurdie has quit IRC14:12
*** namrata has quit IRC14:13
*** spatel has quit IRC14:23
*** namrata has joined #openstack-ansible14:32
jrosserjanno: sorry was in meetings, you need something like this https://github.com/jrosser/openstack-ansible-ops/blob/designate-bind/designate-bind/groupvars/dnsaas-bind.yml14:35
jrosserbut i did that before the extra networks variable existed so the bottom part is no longer required14:35
*** spatel has joined #openstack-ansible14:41
*** cshen has joined #openstack-ansible14:42
*** cshen has quit IRC14:46
*** spatel has quit IRC14:47
admin0jrosser, i have this as my config https://gist.github.com/a1git/8d8f3369b861f10102c7fc7c08cbec21 .. i do not know how to map the hosts to the correct group14:51
admin0do i create c1_hosts: put c1: ip .. .. but how do I specify those for image_hosts or haproxy_hosts ?14:52
admin0oh .. i get it .i think14:53
jrosseradmin0: not quite sure what the trouble is? also i'm in a meeting right now14:58
admin0oh ..14:59
*** this10nly has quit IRC15:06
*** udesale_ has quit IRC15:07
*** nurdie has joined #openstack-ansible15:07
nsmedsWith the galera role, if we initially launched it with `galera_use_ssl: false` and want to switch to `true`, happen to know if the role supports this?15:09
nsmedsi.e. will the cluster remain online and healthy, or will there be issues when some galera servers are SSL and others aren't (since the role is applied in serial)15:10
*** cshen has joined #openstack-ansible15:16
*** cshen has quit IRC15:20
admin0jrosser, when you are free to look,  complete error message I am getting and all the configs: https://gist.github.com/a1git/af375603b3b41e0fd773d1921a333db315:25
admin0error is on line 815:26
admin0my bad :D15:27
*** gyee has joined #openstack-ansible15:41
*** d34dh0r53 has quit IRC15:47
openstackgerritMerged openstack/ansible-role-systemd_service stable/ussuri: Revert "Build out the PrivateNetwork function for services"  https://review.opendev.org/73956415:48
*** grantza has joined #openstack-ansible15:57
*** d34dh0r53 has joined #openstack-ansible15:58
openstackgerritMerged openstack/openstack-ansible-os_keystone stable/ussuri: Identity Providers support improvments  https://review.opendev.org/73957016:01
*** nurdie_ has joined #openstack-ansible16:05
*** nurdie has quit IRC16:09
*** nurdie_ has quit IRC16:13
*** mgariepy has quit IRC16:14
*** namrata has quit IRC16:25
*** d34dh0r53 has quit IRC16:29
*** spatel has joined #openstack-ansible16:31
*** d34dh0r53 has joined #openstack-ansible16:32
openstackgerritMerged openstack/openstack-ansible stable/ussuri: Fix KeyError raised when max hostname length exceeded  https://review.opendev.org/74044116:56
*** mgariepy has joined #openstack-ansible17:13
*** cshen has joined #openstack-ansible17:17
*** cshen has quit IRC17:21
*** spatel has quit IRC17:50
admin0has anyone came across this type of neutron error: https://gist.githubusercontent.com/a1git/2693eb0661b4539e282cc043ae0dffd6/raw/5d88e284628a85a167828ddb56c634c5ce54a867/gistfile1.txt17:50
admin0the playbooks ran fine .. no errors ..17:50
admin0also I do not have the /var/log/neutron folders .. everything is on /var/log/syslog file17:51
admin0on 21.0.0.0rc217:52
*** spatel has joined #openstack-ansible17:56
jrosseradmin0: "Permission denied: '/var/lock/neutron'" can you see if you have that directory and what the permissions problem might be?18:06
ioni i've updated an aio from train to ussuri and most of the upgrade went fine18:07
ionii've noticed that ceph mon wasn't updated but ceph osd was updated18:07
ioniso on ceph-mon packages are still on 14.2.8 and ceph osd are on 15.2..418:08
admin0 i have the following directory neutron neutron-dhcp-agent/ neutron-l3-agent/ neutron-linuxbridge-agent/ neutron-metadata-agent/ neutron-metering-agent/  .. all ownership of neutron neutron18:08
ioniis this issue known?18:08
arkanHi guys, I just want to thank this community for the great efforts and for helping people (newbies like me) and a special thank for the warrior @CeeMac who came with a brilliant idea of helping me to make progress with octavia18:11
arkanalso thanks for @jrosser @ioni @jamesdenton and all18:12
ioniarkan: nice to hear that is working. any chance to tell me what was wrong?18:13
arkanCeeMac made me first escape of Netplan :))18:14
arkanso I destroyed it18:14
arkanand returned to ifupdown18:15
ionireally, i think i made a comment about netplan , i joked around that i never saw anyone using that stuff18:15
arkanthen I he told me to move neutron to compute node18:15
arkanioni: guys you are mentally connected18:15
arkanyour network is the stars18:16
arkaneven when you joke you give solutions18:16
arkan:))18:16
arkanthen he told me to make some changes in the openstack_user_config and user_variables18:17
arkanand creat veth pairs also18:17
admin0jrosser, any ideas on how i can solve this18:18
CeeMacTo be fair we made some other changes as well, so I can't say for certainty it was netplan. But I've never been a big fan and it does cause some known issues18:18
ioninice to hear that is everything is working fine for you18:18
arkanioni: we made progress, now the LB is online18:18
arkanbut the current problem is the certificate issue18:19
arkanbut at least I can see the "503 Service Unavailable"18:19
admin0arkan, when can we see the configs to replicate this in our env :D18:19
ionii don't have any issues with certs18:19
ioniworking fine in "production" and inn testing lab18:20
arkanI can not add vms into the pool because of http://paste.openstack.org/show/795892/18:20
*** spatel has quit IRC18:20
ioniok, you have public endpoint on ssl that is invalid?18:20
arkanit's pointing on the controller node18:21
arkanopenstack.arkan.cloud ---> 192.168.50.21018:21
ionii think that's the issue18:21
arkanshould I install a certificate with letencrypt ?18:22
ioniit won't generate because it's a private ip18:22
ionican you paste /etc/octavia/octavia.conf ?18:22
arkanok18:23
ioniall sections should have endpoint_type = internalURL18:23
arkanhttp://paste.openstack.org/show/795893/18:24
ioniit's all internal18:25
ioniwhat about openstack endpoint list18:25
arkanhttp://paste.openstack.org/show/795894/18:26
arkanadmin0: I will give the config18:27
ioniok, so why is using the public endpoint for neutron?18:28
arkanmaybe if the cert stuff to be resolved, so you will get the full functional package18:28
ioniadd in [neutron]18:28
ioni insecure=true18:28
arkanI use this in my openstack_user_config.yml external_lb_vip_address: openstack.arkan.cloud18:29
arkanand keystone_public_endpoint: https://openstack.arkan.cloud:5000 in user_variables18:30
arkanioni: I will add insecure=true under [neutron] section18:30
ionimaybe add them in all sections18:31
jrosseradmin0: did you look at /var/lock/neutron like i asked?18:31
admin0yes18:31
admin0all folders have ownership of neutron:neutron18:31
johnsomarkan There was a recent bug that might be causing that for you. In your octavia.conf file, can you try (we don't recommend leaving this set) adding "allow_invisible_resource_usage = True" to the "[networking]" section, then restart the API and worker processes? This will test if it is the bug or not.18:31
admin0jrosser, this is how the /var/lock looks like http://paste.openstack.org/show/795895/18:32
arkanjohnsom: ok, I will do that18:32
openstackgerritMerged openstack/openstack-ansible stable/stein: Fix KeyError raised when max hostname length exceeded  https://review.opendev.org/74044318:32
arkanwooooooooowwwww. it worked18:36
arkanmagic stuff18:36
johnsomarkan Are you on Train or ???18:36
arkanyes18:36
arkantrain18:36
johnsomYou are missing this patch: https://review.opendev.org/738265 It's included in 5.0.2 release of Train18:36
arkanoohhh my goodness my mind now got crazy of happiness18:37
arkanthe LB is working, with round robin18:37
arkanfor my 2 vms with simple web server18:37
johnsomSorry about that, a recent patch forgot to include the interface/endpoint in the keystone setup.18:37
jrosserarkan: i'm fairly sure that octaiva bug is the one i asked you to update the SHA of the octavia service for18:37
johnsomjrosser +118:37
arkanjrosser: about the sha256, I've changed only os_horizon18:38
arkanfor octavia, no, I did not change it18:38
jrosserright ok - so for now you can stick with the workaround from johnsom i guess as you've got it all working18:38
arkanthis is amazing guys18:39
johnsomarkan Don't forget to unset that after you apply the new release18:39
jrosserbut if you do an upgrade to the next tag of openstack-ansible train then i think you will get the fix automatically18:39
admin0arkan, send in a howto so that we can replicate it :)18:39
arkanadmin0: sure I will arrange the config stuff and files18:39
admin0jrosser, i am on 21.0.0.0rc2 and hosts are ubuntu-20.04 if that helps18:40
jrosseradmin0: i don't really know whats happening there, i have a train/bionic deployment here and i see that directory and files inside it18:42
admin0i see 2 issues ..  1 .. that error itself    2.  the absence of /var/log/neutron folder ( everything is coming on syslog )18:43
*** cshen has joined #openstack-ansible18:44
jrosserthe logs should be in the journal these days?18:44
jrosserhmm thats not entirely whats happening here though18:45
*** spatel has joined #openstack-ansible18:48
*** spatel has quit IRC18:48
*** spatel has joined #openstack-ansible18:48
admin0i did a chmod -R 777 /var/lock/neutron*18:55
admin0result is the same18:55
arkanadmin0: https://gist.github.com/arkanmgerges/9e2d5174683649f007993a4f6523604c19:21
*** cshen has quit IRC19:52
*** cshen has joined #openstack-ansible19:54
*** cshen has quit IRC19:58
*** cshen has joined #openstack-ansible20:01
*** cshen has quit IRC20:05
admin0jrosser, a reboot fixed that issue .. but i have 3 more issues :D20:07
admin0i created a flat networking .. but the brq is not the interface or under br-vlan .. its kind of isolated20:07
admin0jrosser, latest issue and the config: https://gist.github.com/a1git/af375603b3b41e0fd773d1921a333db320:13
*** cshen has joined #openstack-ansible20:33
jrosseradmin0: uuuurrrrrggghhh https://bugs.launchpad.net/nova/+bug/186302120:38
openstackLaunchpad bug 1863021 in OpenStack DBaaS (Trove) "[SRU] eventlet monkey patch results in assert len(_active) == 1 AssertionError" [Undecided,In progress] - Assigned to Lingxian Kong (kong)20:38
*** arkan has quit IRC20:52
*** cshen has quit IRC21:06
*** cshen has joined #openstack-ansible21:39
*** tow has joined #openstack-ansible22:09
*** cshen has quit IRC22:13
admin0jrosser, i have decided to forget 20.04 and ussuri rc2 and go with bionic/train for the time being22:30
*** gshippey has quit IRC22:31
*** tosky has quit IRC22:42
*** spatel has quit IRC22:43
*** cshen has joined #openstack-ansible22:43
*** schwicht has quit IRC22:55
*** schwicht has joined #openstack-ansible23:00
*** spatel has joined #openstack-ansible23:15
*** cshen has quit IRC23:18
*** spatel has quit IRC23:19
*** tow has quit IRC23:45
*** tow has joined #openstack-ansible23:45
*** cshen has joined #openstack-ansible23:49
openstackgerritMerged openstack/openstack-ansible stable/train: Fix KeyError raised when max hostname length exceeded  https://review.opendev.org/74044223:56

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!