Friday, 2021-10-08

opendevreviewJames Denton proposed openstack/openstack-ansible-os_neutron master: Implements ironic_neutron_agent and baremetal ML2 driver  https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/81301103:38
opendevreviewJames Denton proposed openstack/openstack-ansible-os_neutron master: Implements ironic_neutron_agent and baremetal ML2 driver  https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/81301103:53
opendevreviewMerged openstack/openstack-ansible-os_ironic master: Refactor galera_use_ssl behaviour  https://review.opendev.org/c/openstack/openstack-ansible-os_ironic/+/81021005:50
*** odyssey4me is now known as Guest218407:34
opendevreviewAndrew Bonney proposed openstack/openstack-ansible-haproxy_server master: Fix typo for user supplied certificate variable  https://review.opendev.org/c/openstack/openstack-ansible-haproxy_server/+/81197909:56
opendevreviewMerged openstack/openstack-ansible stable/stein: fix double-double-quotes  https://review.opendev.org/c/openstack/openstack-ansible/+/81304410:15
opendevreviewMerged openstack/openstack-ansible-lxc_hosts stable/train: ensure 20listchanges is not in debian container  https://review.opendev.org/c/openstack/openstack-ansible-lxc_hosts/+/73162510:27
MrClayPoleI've recently completed an OSA upgrade from Rocky to Train. After the upgrade I was unable to deploy glance images as it was failing with the error "Incorrect configuration file: /etc/glance/rootwrap.conf". We currently used iSCSI LUNs to store glance images. This file was missing from /etc/glance. If I take this file from https://raw.githubusercontent.com/openstack/glance_store/stable/train/etc/glance/rootwrap.conf 11:08
MrClayPoleand add "/openstack/venvs/glance-20.2.6/etc/glance" to the "exec_dirs" it resolves the issue but I notice that rootwrap.conf isn't in the template dir from Stein onwards so I'm wondering if what I've done is the correct fix?11:08
cardiff_danjamesdenton: hey James, we talked back on Tuesday about instances in the 10.0.3.0/24 IP range. I was just wondering whether a bug had been logged about it so I can keep track?12:11
*** sshnaidm is now known as sshnaidm|afk12:17
jamesdentonhi cardiff_dan - no, no bug, yet. Sorry.12:42
cardiff_danno problem, we're putting this on our docs as a known issue for now so users don't get flummoxed :)12:44
jamesdentonunderstood. i don't think it's an OSA bug, necessarily, but a by-product of linux routing on-host12:46
spateljamesdenton here you go, HA with connection mirroring - https://satishdotpatel.github.io/ha-with-keepalived-and-conntrackd/12:47
jamesdentonnext stop, OSA!12:51
mgariepyspatel, systemd ? not systemctl ? also missing a `e` there `systemd enable keepalivd`12:54
opendevreviewMerged openstack/openstack-ansible master: Remove unnecessary pki step in haproxy install  https://review.opendev.org/c/openstack/openstack-ansible/+/81236112:56
mgariepynice post :D12:57
opendevreviewAndrew Bonney proposed openstack/openstack-ansible stable/wallaby: Remove unnecessary pki step in haproxy install  https://review.opendev.org/c/openstack/openstack-ansible/+/81309913:00
spatelThank you! damn it good catch let me fix it :)13:00
mgariepyalso the cp command ends with a . which works.. but isn't needed 13:01
spatelits my habit to do (.) but you are correct 13:02
spatelfixed... 13:03
jamesdentontough crowd! :D13:04
spatelvery tough..hehe13:05
mgariepysorry 13:05
mgariepylol13:05
jamesdentoni have a backlog of posts. lots of notes. 13:05
spatelglad that means you guys paying attention not just eyes rolling 13:05
jamesdentons/This post if/This post is/13:06
jamesdentonif i must contribute something13:06
jamesdentonbut yes, nice post!13:06
spateli should share my creds with you guys to we all can fix stuff :) 13:06
jamesdentonwe just need to submit PRs :D13:07
spatels/to/so/13:07
spateli think we should turn on conntrackd for OSA so during failover we don't lost any connection :) 13:08
mgariepyit works much better than it was now :)13:08
mgariepyservices expect to loose connection and reconnect now haha13:08
spatelHow does ESTABLISHED connection of mysql get handled ?13:09
spatelif someone running long terraform and failover trigger what will happened ? 13:10
mgariepyfor mysql anyway. if the failover happens when the host crash. the mysql on it will die also.. and connection will need to be re-done on the new master.13:10
spatelif we don't need then sure we don't need to make it over complicated :) 13:10
mgariepyhow the mysql connection through haproxy would be migrated to the new server ? when it's controlled it's not much of an issue.13:12
mgariepybut if the host1 becomes unavailable the backup keepalived/haproxy node won't be able to connect to it.13:13
spatelhmm13:14
opendevreviewJames Denton proposed openstack/openstack-ansible-os_neutron master: Implement ironic_neutron_agent and baremetal driver  https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/81301113:24
spateljamesdenton look like Ironic goodness going on :) 13:30
jamesdentonthere's a little bit of movement there. probably need to do some cleanup in that role13:31
jamesdentonand a blog post could help,m too13:31
spatelI would wait for that 13:32
spatelI haven't seen anyone using Ironic with OSA (i may be wrong)13:32
jamesdentoni've been using it locally for at least the last... 9 months or so. Pretty sure we have some customers using it, too13:33
spatelwhy i haven't seen any doc on openstack-ansible page? 13:33
spateli think it need some special stuff to make it work like PXE lan etc13:34
jamesdentonwell, someone needs to write the doc, i guess :D13:37
jamesdentonit's somewhere in my stack of notes13:37
spateli will see if i get some free time for ironic, i want to learn that because we have so many pizza box in datacenter and one dedicated guy managing it so i would like to put them in openstack to manage hardware 13:43
jamesdentonmgariepy i did confirm ipmitool was fully functional on this deployed baremetal instance14:44
mgariepyhopefully not on a shared ethenet network ;)14:45
jamesdentonwell14:48
jamesdenton:D14:48
opendevreviewAndrew Bonney proposed openstack/openstack-ansible-os_tempest stable/wallaby: Pin neutron-tempest-plugin to v1.6.0  https://review.opendev.org/c/openstack/openstack-ansible-os_tempest/+/81319814:48
mgariepyany idea how it's kept secured ?14:48
jamesdentonwell, this was in my lab, not public cloud14:48
jamesdentonso no, i'm not sure14:48
jamesdentonlocal ipmi allowed, but access to another host requires auth.14:49
mgariepyyes indeed.14:49
jamesdentonso maybe there's username and password rotation in place, not sure14:49
opendevreviewAndrew Bonney proposed openstack/openstack-ansible stable/wallaby: Remove unnecessary pki step in haproxy install  https://review.opendev.org/c/openstack/openstack-ansible/+/81309914:49
mgariepy¯\_(ツ)_/¯ well 14:51
mgariepyipmitool over lan needs auth unless cypher 0 can be used.14:55
mgariepyhttps://book.hacktricks.xyz/pentesting/623-udp-ipmi14:55
opendevreviewJames Denton proposed openstack/openstack-ansible-os_neutron master: Add support for openvswitch interface driver with OVN  https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/81320015:03
opendevreviewMerged openstack/openstack-ansible-os_cinder master: setup.cfg: Replace dashes with underscores  https://review.opendev.org/c/openstack/openstack-ansible-os_cinder/+/78971217:20
spatelvery ugly question, we have many kind of servers in openstack like gen8, gen9, Dell etc... is there a way from VM i can pull that information out related which hardware its running? 17:56
jamesdentoni think that's all abstracted away18:36
jamesdentonanyone here using Trove?18:40
spatelI have never heard anyway talking about Trove here :)19:03
jamesdenton:)19:10
opendevreviewMerged openstack/openstack-ansible master: Implements framework for ironic_neutron_agent and Neutron 'baremetal' plugin  https://review.opendev.org/c/openstack/openstack-ansible/+/81300619:16
opendevreviewMerged openstack/openstack-ansible master: Add serial execution to all playbooks  https://review.opendev.org/c/openstack/openstack-ansible/+/80518819:20
jamesdentonanyone seen an issue where a constraints file isn't built on the repo server? I can see global-constraints.txt, requirements.txt, source-constraints.txt, but not regular 'ol constraints.txt -20:29
spateljamesdenton what is error related on compute nodes - Timed out waiting for nova-conductor.  Is it running?21:18
spatelmy nova-conductor service is running21:18
spateldoes compute use rabbitMQ to talk to nova-conductor? 21:19

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!