Monday, 2020-09-07

*** cshen has joined #openstack-ansible01:15
*** cshen has quit IRC01:19
*** spatel has joined #openstack-ansible01:26
*** spatel has quit IRC01:30
*** jamesdenton has quit IRC02:30
*** jamesdenton has joined #openstack-ansible02:30
*** cshen has joined #openstack-ansible02:49
*** cshen has quit IRC02:53
*** spatel has joined #openstack-ansible04:18
*** evrardjp has quit IRC04:33
*** evrardjp has joined #openstack-ansible04:33
*** cshen has joined #openstack-ansible04:49
*** cshen has quit IRC04:54
*** miloa has joined #openstack-ansible05:45
*** spatel has quit IRC05:56
*** andrewbonney has joined #openstack-ansible06:59
*** cshen has joined #openstack-ansible07:14
*** shyamb has joined #openstack-ansible07:30
*** owalsh has quit IRC07:48
*** owalsh has joined #openstack-ansible07:52
*** pcaruana has quit IRC07:58
*** pcaruana has joined #openstack-ansible07:58
*** shyamb has quit IRC08:01
*** shyamb has joined #openstack-ansible08:12
*** maharg101 has quit IRC08:12
openstackgerritOpenStack Proposal Bot proposed openstack/openstack-ansible master: Imported Translations from Zanata  https://review.opendev.org/75013708:30
openstackgerritDmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible-os_senlin master: Initial commit to os_senlin  https://review.opendev.org/74936508:48
*** shyamb has quit IRC08:51
openstackgerritMerged openstack/openstack-ansible-os_glance master: Fix native service path  https://review.opendev.org/74990708:51
openstackgerritDmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible-os_glance stable/ussuri: Fix native service path  https://review.opendev.org/75013908:57
openstackgerritDmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible-os_glance stable/train: Fix native service path  https://review.opendev.org/75014008:57
openstackgerritMerged openstack/openstack-ansible master: Bump SHAs for master  https://review.opendev.org/75010509:36
*** shyamb has joined #openstack-ansible09:47
*** shyamb has quit IRC10:16
*** shyamb has joined #openstack-ansible10:23
*** shyamb has quit IRC10:27
*** shyamb has joined #openstack-ansible10:28
*** tosky has joined #openstack-ansible10:33
*** jawad_axd has joined #openstack-ansible10:50
openstackgerritMerged openstack/openstack-ansible-os_swift master: Delegate gnocchi retrievement task to setup host  https://review.opendev.org/74821711:13
*** shyamb has quit IRC11:34
*** shyamb has joined #openstack-ansible11:35
openstackgerritMerged openstack/openstack-ansible-ceph_client stable/train: Remove trailing '/' from ceph_apt_repo_url  https://review.opendev.org/75006311:51
*** shyam89 has joined #openstack-ansible12:25
*** shyam89 has quit IRC12:27
*** shyamb has quit IRC12:28
openstackgerritErik Berg proposed openstack/openstack-ansible-ceph_client stable/stein: Remove trailing '/' from ceph_apt_repo_url  https://review.opendev.org/75016712:56
openstackgerritDmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible master: Add integrated test for Ubuntu using ML2/OVN driver  https://review.opendev.org/73301713:03
openstackgerritDmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible-os_swift stable/ussuri: Delegate gnocchi retrievement task to setup host  https://review.opendev.org/75016913:07
openstackgerritMerged openstack/openstack-ansible-os_neutron master: Add Initial NSX Integration  https://review.opendev.org/74835713:10
*** jawad_axd has quit IRC13:29
*** cshen has quit IRC13:37
*** jbadiapa has joined #openstack-ansible14:06
*** cshen has joined #openstack-ansible14:13
openstackgerritMerged openstack/openstack-ansible stable/train: Bump SHAs for stable/train  https://review.opendev.org/75010614:16
openstackgerritMerged openstack/openstack-ansible stable/stein: Bump SHAs for stable/stein  https://review.opendev.org/75010714:16
openstackgerritMerged openstack/openstack-ansible master: Imported Translations from Zanata  https://review.opendev.org/75013714:16
openstackgerritMerged openstack/openstack-ansible-os_glance stable/train: Fix native service path  https://review.opendev.org/75014014:42
*** SecOpsNinja has joined #openstack-ansible15:08
*** pcaruana has quit IRC15:25
*** cshen has quit IRC15:35
*** miloa has quit IRC15:39
openstackgerritMerged openstack/openstack-ansible-ceph_client stable/stein: Remove trailing '/' from ceph_apt_repo_url  https://review.opendev.org/75016716:01
*** cshen has joined #openstack-ansible16:06
*** BlackFX has quit IRC16:08
*** openstackgerrit has quit IRC16:11
*** cshen has quit IRC16:46
*** SecOpsNinja has left #openstack-ansible16:52
*** SecOpsNinja has joined #openstack-ansible16:53
*** cshen has joined #openstack-ansible17:17
*** jpward has joined #openstack-ansible17:19
*** cshen has quit IRC17:22
*** jbadiapa has quit IRC17:22
*** andrewbonney has quit IRC17:42
*** SecOpsNinja has left #openstack-ansible18:04
*** cshen has joined #openstack-ansible18:35
*** MickyMan77 has joined #openstack-ansible18:56
MickyMan77When I run this command, openstack-ansible setup-openstack.yml, it fails on (TASK [os_keystone : Create database for service]).18:58
MickyMan77with msg,18:58
MickyMan77failed: [controller01_keystone_container-94d17e6e -> xx.xx.xx.xx] (item=None) => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": false}fatal: [controller01_keystone_container-94d17e6e]: FAILED! => {"censored": "the output has been hidden due to the fact that 'no_log: true' was18:59
MickyMan77specified for this result", "changed": false}18:59
MickyMan77how can I unhide so19:02
MickyMan77*so I can find the error ?19:02
*** ChiTo has joined #openstack-ansible19:23
ChiToHi everybody, I have some questions about my external HAProxy and Internal HAProxy, my question is if I can create two set of HAProxy clusters to load balance one for external VIP APIs connectivity and the other for Internal VIP services, should I create two set of host groups for this use case?19:25
*** gregwork has joined #openstack-ansible19:27
*** cshen has quit IRC19:32
*** openstackgerrit has joined #openstack-ansible20:25
openstackgerritMerged openstack/openstack-ansible-os_nova master: Set Bridge Information for NSX Integration  https://review.opendev.org/74875120:25
admin0ChiTo, is that required ?20:30
admin0i mean you can easily have the same server do the internal and external IP (whcih can be internal) and then NAT/Forward/manage that from an external cluster20:30
admin0for example, i use 10.x for my external LB IP and the 172.29 for internal .. then from an external LB cluster, nat a public IP to the 10.x20:31
ChiToadmin0: Unfortunately in the past I have a lot of problems in terms of load from external clients vs the internal clients, and that is why I would like to separate two domains, but not sure if I have to create a separated hosst group for the HAproxy-external20:32
ChiToadmin0: at the end of the day is just duplicating HAproxies, and I get it but I just wonder if from the openstack-ansible I can just add a new haproxy besides the internal one20:33
admin0how about ( haproxy cluster , managed by you that holds the public IP) -> NAT 1:1 to the 3 controllers20:35
admin0that is something near to what you want20:38
admin02 groups of haproxies .. but without a change in the ansible20:38
admin0and good thing is if those 3 externals are also not good enough, can upgrade to hardware20:38
ChiToadmin0: Understood, that sounds good, so then I would have to deploy my own haproxy right without depending on openstack-ansible?20:39
ChiToadmin0: And what about if I deploy two groups of HAProxy from the user yaml perspective and assign two different VIPs?20:39
ChiTofrom the same internal domain20:39
admin0this gives you multiple options .. your own haproxy .. or vyos, or a physical router, or anything .. where you host the publc IP .. and then just NAT 1:1 to the external IP20:40
ChiTobut just separate that through my NAT from my router to one of the VIP20:40
ChiToand the other one to endpoints that are admin/internal20:40
admin0my thought on this is .. if haprpoxy is not enough for you now .. chances are you need to go hardware20:40
ChiTototally agreed20:42
admin0is your public IP directly in the haproxy in openstack now ?20:42
ChiTonot so far, because actually I route through a NAT entry in my router20:42
ChiTothat is why I was thinking of a two internal VIPs20:42
admin0what is the actual issue ? is it the number of connections ?20:43
ChiTothat is correct, it is a lot of number of connections to the HAproxy externally and it gets a high load20:43
ChiToand that impacts the internal users, that not necessarily saturate the service but those users are more important than the external ones20:44
admin0how many connections are we talking about here ? 100k plus ?20:46
ChiTois a mix between number of connections plus CPU capacity on those HAproxies (which are VMs actually)20:46
ChiTothey are in the order of thousands not even tens of thousands20:47
admin0in osa, the haproxy runs on metal on the contollers ... so if its virtual in your case, maybe increase resources there and tune the host kernel or something20:48
admin0order of thousands sounds not that much high tbh20:48
ChiToadmin0: I totally agreed, has to do with my host capabilities, unfortunately are not great20:48
ChiToadmin0: Perhaps moving those to run on metal should work better to avoid the hypervisor overhead as well20:49
admin0because what i think is .. even if you add 3 more haproxies ..  if the controllers itself are under load, then it will not solve anything20:49
ChiToadmin0: Yes, I agree, I need to reprovision some servers to make sure HAProxy is on a metal as you propose with less burden20:51
admin0maybe possible to add some cpu or ram to the current ones ?20:52
ChiToadmin0: Unfortunately they are very loaded so far with some other internal infrastructure VMs20:52
ChiToadmin0: But I will see if I can get a couple of new servers20:53
ChiTowell three ideally20:53
admin0yeah20:53
ChiToadmin0: Do you know by chance if I can modify manually the inventory json?20:53
admin0i recommend not :D20:53
ChiToto assign specific IP Addresses to my lxc containers20:53
ChiToinstead of letting to assign them automatically20:54
ChiTobased on my container ip pool segment20:54
admin0its a cloud .. treat it like cattle like it should be :)20:54
admin0you are now making it a pet :)20:54
ChiTo:) agreed20:54
ChiTothanks a lot for your comments and feedback admin0, they were very useful!20:55
admin0you are welcome20:56
*** cshen has joined #openstack-ansible21:28
*** cshen has quit IRC21:32
*** tosky has quit IRC23:16

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!