Friday, 2023-10-27

opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible master: Deprecate OpenDaylight support  https://review.opendev.org/c/openstack/openstack-ansible/+/89743706:27
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible master: Tune SSH in pre-step setup  https://review.opendev.org/c/openstack/openstack-ansible/+/89931807:45
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible master: DNM test metal CI speed without connection plugin  https://review.opendev.org/c/openstack/openstack-ansible/+/89931207:47
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible master: DNM test metal CI speed without connection plugin  https://review.opendev.org/c/openstack/openstack-ansible/+/89931207:47
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible master: DNM test metal CI speed without connection plugin  https://review.opendev.org/c/openstack/openstack-ansible/+/89931207:47
opendevreviewMerged openstack/openstack-ansible master: Map default value of rabbitmq_management_ssl to haproxy_ssl  https://review.opendev.org/c/openstack/openstack-ansible/+/89941611:14
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible stable/2023.1: Map default value of rabbitmq_management_ssl to haproxy_ssl  https://review.opendev.org/c/openstack/openstack-ansible/+/89933111:46
opendevreviewMerged openstack/ansible-role-zookeeper master: Use jdk 17 for Zookeeper  https://review.opendev.org/c/openstack/ansible-role-zookeeper/+/89938612:25
opendevreviewMerged openstack/openstack-ansible-os_gnocchi stable/2023.1: Use proper galera port in configuration  https://review.opendev.org/c/openstack/openstack-ansible-os_gnocchi/+/89235612:57
spatelmorning folks!! 13:20
NeilHanlonmornin'!13:20
spatelFinally I got little time today to breath so saying Helll13:21
spatelhello*13:21
NeilHanlonthat is good to hear! It's been quite a week13:21
spatelYep!! 13:38
spatelI am busy in building out new datacenter and its giving me tough time :(13:38
spatelIts not easy to start thing from scratch!! 13:39
NeilHanlon:( hopefully you won't have to work this weekend?13:39
spatelNot weekend but in to late nights :)13:39
spatelI am almost done!! hope next week start rolling out openstack 13:40
NeilHanlonNo no it's not.. I had to do something similar a few years ago under a time crunch. Was only in town for a week and I had to install and bootstrap a whole new network and get traffic flowing to our old cage13:40
NeilHanlonnice! :) 13:40
spatelMy developer asking for k8s cluster so spending lots of time there to make it right :)13:42
spatelDo you guys still using openvswitch plugin for production or OVN?13:42
NeilHanlonhttps://drop1.neilhanlon.me/irc/uploads/db0b9822a4757f71/image.png relevant re: kubernetes ;) 13:44
NeilHanlonI'm still using ovs in my `production` -- though it's really not anything close to production, just my home lab. Slowly I am trying to move to OVN (though, reluctantly)13:45
mgariepylol kubernetes13:52
mgariepyI have both in prod but not much beside base and manila services for now.13:54
jamesdentonspatel we are all OVS here, but next big production cloud is slated to use OVN. Need to really determine parity, though13:54
spatelNeilHanlon lol for that funny link :)13:54
spateljamesdenton I am still worried to deploy OVN.. just human nervousness 13:55
spatelI don't want to end up midnight to debug something I am not very good at..13:56
spatelI am planning to deploy small 60 node cluster using OVN in next few month just to use for k8s. 13:56
spatelcurrently deploying 600 node cloud but thinking to use OVS only. 13:57
spatel600 for OVN will be big milestone.. I would start with 60 first to get hands on13:57
NeilHanlonI think it is smart to stick with what you know while learning the new thing13:57
spatel+113:57
jamesdentonspatel i am nervous too :)13:57
NeilHanlonOVN makes sense to me conceptually, but I grok the concepts themselves. For me, though, I just don't have the scale at which I require something like OVN13:58
spatelI am reading all mailing list everyday and people brining strange issues with OVN and I have no idea what are those :) 13:58
NeilHanlonRemember RFC 192513:58
NeilHanlon(6)  It is easier to move a problem around (for example, by moving13:58
NeilHanlon        the problem to a different part of the overall network13:58
NeilHanlon        architecture) than it is to solve it.13:58
jamesdenton#truth13:59
spatel:)13:59
opendevreviewMerged openstack/openstack-ansible stable/zed: Define install_method default when hosts resolution depend on it  https://review.opendev.org/c/openstack/openstack-ansible/+/89807313:59
mgariepyi aggree it's a whole set of new tool to learn.13:59
NeilHanlon(yes, I _do_ have that RFC bookmarked 😂)13:59
spatelI think OVN is better fit for k8s the way it works 13:59
spatelThe Twelve Networking Truths RFC 192513:59
spateljamesdenton my engineering asking can we ssh to k8s pod/container... :O14:00
spatelI think k8s doesn't support to take your native vlans to pod level correct?14:01
spatelIn GCP you can do that but I am sure they are using BGP to make it possible14:01
spatelThey want to bring physical server and pods on same vlan so they can talk to each other without LB etc.. shit to expose things14:02
spatelDid you guys try nomad ? - https://bluexp.netapp.com/blog/cvo-blg-kubernetes-vs-nomad-understanding-the-tradeoffs14:03
jamesdentoni think using native k8s constructs is prob best for everyone. lots of terrible ideas out there :D14:07
spatellol14:08
spatelHow do you maintaining so many virtual routers for k8s? 14:09
spatelThat is different challenge with openvswitch14:10
mgariepyspatel, are you using ovs flow with ovs ? or still on iptables shim ?14:21
spatelPlanning to use ovs flow instead of iptables14:23
spatelwhy? any thing i should be worry?14:23
mgariepyno14:23
mgariepyit works flawlessly14:23
spatel++++1 14:23
mgariepyit's just not iptables. and need a new parser in your brain to read/understand it ;)14:24
spatelI see 14:24
spatelmostly every few time you have to deal with that level of debugging..14:24
mgariepygood news is that it's the same for ovn after that.. 14:24
spatelYes! 14:25
noonedeadpunkFolks, does anybody see `LIBVIRT_PRT` iptables table for nat on ubuntu 22.04 compute node?16:07
spatelnoonedeadpunk what is the use of it? first time heard16:20
noonedeadpunkin openstack world - no use.16:21
noonedeadpunkBut kinda wonder how to get rid of that16:22
jrosseris it libvirts "default" network?16:22
noonedeadpunkyeah, kinda. But you better not to create a neutron network that will intersect with that16:22
jrosser`virsh net-list` or smth16:22
noonedeadpunkyeah ` default   active   yes         yes`16:25
noonedeadpunkHow to prevent libvirt creating it...16:26
noonedeadpunkbut deleting network breaks connectivity to VMs16:30
noonedeadpunkwtf16:30
jrosserdo you use ovs + iptables? maybe that got broken16:33
noonedeadpunkyup16:33
noonedeadpunkis it safe to use mix of computes for iptables and native ovs?16:33
noonedeadpunkcrap16:35
noonedeadpunkSeems I should really switch to native ovs, huh16:39
noonedeadpunkhm... and we have this obviously: https://opendev.org/openstack/openstack-ansible-os_nova/src/branch/master/tasks/drivers/kvm/nova_compute_kvm_virsh_net_remove.yml16:44
noonedeadpunkwhich obviously didn't work for me somehow...16:44
jrosserNeilHanlon: do we have an ovs package oddness here? https://review.opendev.org/c/openstack/openstack-ansible/+/899331?tab=change-view-tab-header-zuul-results-summary16:45
noonedeadpunkwtf16:46
NeilHanlonbleh. apparently..17:06
NeilHanlonsorry.. i need to track their updates better17:06
NeilHanlonI've got the updates building now17:11
NeilHanlontagged them to -release just now. I think the packages should be available within a day. sorry again19:58
opendevreviewDmitriy Rabotyagov proposed openstack/ansible-role-systemd_service master: Filter loop lists instead of conditionally run them  https://review.opendev.org/c/openstack/ansible-role-systemd_service/+/89950920:25
noonedeadpunkso... I've checked ansible logs of compute deployments and on all computes these 2 tasks were skipeed https://opendev.org/openstack/openstack-ansible-os_nova/src/branch/master/tasks/drivers/kvm/nova_compute_kvm_virsh_net_remove.yml#L21-L2822:18
noonedeadpunkwhat is more /o\ is that after default net removal and compute reboot it re-appears22:18

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!