*** dimtruck is now known as zz_dimtruck | 01:09 | |
*** catintheroof has joined #openstack-barbican | 01:29 | |
*** catintheroof has quit IRC | 01:30 | |
*** dave-mccowan has quit IRC | 01:36 | |
*** jamielennox is now known as jamielennox|away | 01:54 | |
*** zz_dimtruck is now known as dimtruck | 01:56 | |
*** noslzzp has quit IRC | 02:37 | |
*** noslzzp has joined #openstack-barbican | 02:38 | |
*** noslzzp has quit IRC | 02:46 | |
*** noslzzp has joined #openstack-barbican | 02:48 | |
*** noslzzp has quit IRC | 03:21 | |
*** jamielennox|away is now known as jamielennox | 04:23 | |
*** jamielennox is now known as jamielennox|away | 05:11 | |
*** ssmith has joined #openstack-barbican | 05:17 | |
*** jaosorior_away is now known as jaosorior | 05:24 | |
*** jamielennox|away is now known as jamielennox | 05:51 | |
*** cpuga has quit IRC | 06:05 | |
*** jamielennox is now known as jamielennox|away | 06:23 | |
*** namnh has joined #openstack-barbican | 06:30 | |
*** pcaruana has joined #openstack-barbican | 06:39 | |
*** ssmith has quit IRC | 07:01 | |
*** andreas_s has joined #openstack-barbican | 07:26 | |
*** openstackgerrit has quit IRC | 08:18 | |
*** pbourke has joined #openstack-barbican | 08:29 | |
*** Kevin_Zheng has quit IRC | 08:56 | |
*** liujiong has joined #openstack-barbican | 09:02 | |
*** salmankhan has joined #openstack-barbican | 09:08 | |
*** mkoderer_ has joined #openstack-barbican | 09:21 | |
*** dgonzalez_ has joined #openstack-barbican | 09:21 | |
*** seife_ has joined #openstack-barbican | 09:21 | |
*** tpatzig_ has joined #openstack-barbican | 09:21 | |
*** mkoderer_ has quit IRC | 09:23 | |
*** dgonzalez_ has quit IRC | 09:23 | |
*** seife_ has quit IRC | 09:23 | |
*** tpatzig_ has quit IRC | 09:23 | |
rpi | Hi, I am trying to implement ocata (4.0.0) barbican with SoftHSM v2.2 on Ubuntu 16.04. I notice the release of openssl in 16.04 is 1.0.2g and this charm (https://github.com/openstack/charm-barbican-softhsm) references a missing function within <1.0.2h. I have recompiled softhsm2.2 against openssl 1.0.2k, and have initialised my slot, prepared my mkek and hmac labels but I receive CKR_MECHANISM_INVALID within the barbican api logs when trying to store | 09:53 |
---|---|---|
*** liujiong has quit IRC | 10:14 | |
*** salmankhan has quit IRC | 10:14 | |
*** salmankhan has joined #openstack-barbican | 10:20 | |
*** namnh has quit IRC | 10:56 | |
*** salmankhan has quit IRC | 11:17 | |
*** salmankhan has joined #openstack-barbican | 11:17 | |
*** salmankhan has quit IRC | 11:20 | |
*** salmankhan has joined #openstack-barbican | 11:26 | |
*** openstackgerrit has joined #openstack-barbican | 11:48 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican master: Updated from global requirements https://review.openstack.org/467138 | 11:48 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/castellan master: Updated from global requirements https://review.openstack.org/467140 | 11:48 |
*** salmankhan1 has joined #openstack-barbican | 12:00 | |
*** Kevin_Zheng has joined #openstack-barbican | 12:01 | |
*** salmankhan has quit IRC | 12:03 | |
*** salmankhan1 is now known as salmankhan | 12:03 | |
*** dgonzalez has quit IRC | 12:12 | |
*** dgonzalez has joined #openstack-barbican | 12:14 | |
*** dave-mccowan has joined #openstack-barbican | 12:14 | |
*** catintheroof has joined #openstack-barbican | 12:42 | |
*** jamielennox|away is now known as jamielennox | 12:49 | |
*** jaosorior has quit IRC | 12:57 | |
*** jaosorior has joined #openstack-barbican | 12:57 | |
*** cpuga has joined #openstack-barbican | 13:06 | |
*** cpuga has quit IRC | 13:08 | |
*** cpuga has joined #openstack-barbican | 13:08 | |
dave-mccowan | Hello Barbicaneers. I'd like to have a 10 minute IRC meeting today at 11am EDT(UTC-4) (about 2 hours from now) | 13:09 |
dave-mccowan | Namnh would like to present/discuss his plans for rolling upgrades for Barbican. Please join if you can. | 13:09 |
dave-mccowan | alee kfarr redrobot jaosorior diazjf ^^^ | 13:10 |
*** ssmith has joined #openstack-barbican | 13:25 | |
openstackgerrit | Merged openstack/barbican master: Remove Certificate Orders and CAs from Documentation https://review.openstack.org/462368 | 13:34 |
*** dimtruck is now known as zz_dimtruck | 13:39 | |
jaosorior | dave-mccowan: I'm almost ending the day :/ | 13:44 |
*** dave-mcc_ has joined #openstack-barbican | 13:48 | |
*** dave-mccowan has quit IRC | 13:49 | |
*** dave-mccowan has joined #openstack-barbican | 13:50 | |
*** noslzzp has joined #openstack-barbican | 13:52 | |
*** dave-mcc_ has quit IRC | 13:53 | |
*** chlong has joined #openstack-barbican | 13:56 | |
openstackgerrit | Merged openstack/python-barbicanclient master: Updated from global requirements https://review.openstack.org/467189 | 13:59 |
*** rpi has quit IRC | 13:59 | |
*** rpi has joined #openstack-barbican | 14:00 | |
*** andreas_s has quit IRC | 14:01 | |
*** kfarr has joined #openstack-barbican | 14:11 | |
*** salmankhan has quit IRC | 14:14 | |
*** namnh has joined #openstack-barbican | 14:17 | |
*** zz_dimtruck is now known as dimtruck | 14:17 | |
namnh | kfarr: hello Kaitlin, here is my patch [1] to setup as your comment on the patch [2]. [1] https://review.openstack.org/#/c/466174/2 [2] https://review.openstack.org/#/c/452679/ | 14:24 |
namnh | kfarr: could you take a look at it. | 14:24 |
kfarr | namnh sure :) | 14:24 |
namnh | kfarr: thanks :) will we have the extra meeting after around 30'? | 14:26 |
kfarr | yeah I think so! I'll be here at least | 14:26 |
openstackgerrit | Merged openstack/barbican master: Updated from global requirements https://review.openstack.org/467138 | 14:29 |
namnh | kfarr: great, I will bring the rolling upgrade topic to discuss :) | 14:29 |
openstackgerrit | Merged openstack/castellan master: Updated from global requirements https://review.openstack.org/467140 | 14:29 |
*** salmankhan has joined #openstack-barbican | 14:56 | |
dave-mccowan | o/ | 14:58 |
dave-mccowan | Hi namnh | 15:01 |
alee | Hi namnh | 15:02 |
namnh | hello everyone, please wait a monent, let me restart my laptop, it have a problem :) | 15:04 |
*** namnh has quit IRC | 15:04 | |
*** namnh has joined #openstack-barbican | 15:05 | |
namnh | sorry for this | 15:05 |
namnh | I am ready | 15:06 |
dave-mccowan | namnh thanks for all your work on offline upgrades | 15:06 |
namnh | yes, you're welcome, i will talk about my topic for now or having to wait someone? | 15:07 |
dave-mccowan | namnh please start | 15:08 |
namnh | thanks, let me start a offline upgrade tag first, then rolling upgrade and finally zero downtime. | 15:09 |
namnh | for offline upgrade, I pushed up two patch sets. one is to fix grenade gate and one is docs for operators | 15:10 |
namnh | I think if we finish two patchs then we can request "supports-upgrade" tag to TC. is that right? | 15:11 |
dave-mccowan | namnh yes. the doc and gate are the final requirements. i'll show you how to submit the patch to request the tag later. | 15:12 |
namnh | here is the two patchs: https://review.openstack.org/#/c/466174/ and https://review.openstack.org/#/c/449022/ | 15:14 |
dave-mccowan | namnh ok, we'll review these soon. | 15:14 |
namnh | dave-mccowan: yes, I will follow the process | 15:14 |
namnh | thanks everyone for helping me to review my patch sets. | 15:16 |
namnh | although, I am not finish the offline upgrade tag but I am thinking about "rolling upgrade" tag. I will move to this tag | 15:17 |
namnh | in my option, to support "rolling upgrade" tag, we need to consider some things: | 15:17 |
namnh | 1. implement rpc version: basically, we need to have a option in barbican.conf to show that it is last release. here is my idea: https://review.openstack.org/#/c/466247/ | 15:19 |
namnh | 2. online schema migrate: we need to implement to migrate database like cinder's command "cinder-manage db online_data_migrations" | 15:19 |
namnh | 3. gracefull shutdown | 15:20 |
namnh | for worker and keystone-listener they are using oslo.service to start service and oslo.service was implemented this feature, it means we have this one in barbican | 15:20 |
namnh | for barbican-api: I am not sure about this :) | 15:20 |
namnh | - ovo (oslo versionedobject: it depends on the architecture of each project. in my understanding, we don't need to this feature because we don't have any service which get information from database via a service like barbican-api or worker. for example: nova-compute want to get information from database via nova-condutor. in this case, ovo will be useful to modify this infor before sending to nova-compute. | 15:22 |
namnh | trigger: I can learn how to use trigger from keystone or glance that are using trigger to migrade db | 15:22 |
namnh | =)) I prepared some sentences before this meeting. | 15:23 |
namnh | that is my idea about how to support "rolling upgrade" tag for barbican | 15:24 |
namnh | what do you think about this? | 15:24 |
dave-mccowan | thanks for your proposal ,namnh. i'm excited to get this feature for barbican. | 15:25 |
kfarr | +1 | 15:25 |
dave-mccowan | to be honest, i don't know much about this area of code, so i can't be much help reviewing. | 15:25 |
dave-mccowan | kfarr, alee: do you know this area of code? if not, maybe we can recruit some barbican alumni to help out. | 15:26 |
alee | dave-mccowan, I;m not very familiar with it either. I think either redrobot or even better woodster would be better positioned to lookk at these | 15:27 |
kfarr | About oslo objects? I think jaosorior knew the most | 15:27 |
dave-mccowan | namnh please keep working on this proposal. it seems very reasonable. i will recruit some help to review. | 15:28 |
alee | and yeah, we can ping jaosorior | 15:28 |
namnh | i would like to confirm with you one thing: currenlty, there are no any services which get information from database via a service like barbican-api or worker | 15:28 |
namnh | is that right? | 15:28 |
namnh | dave-mccowan: yes, I will. | 15:29 |
jaosorior | what did I do? | 15:30 |
*** chlong has quit IRC | 15:31 | |
dave-mccowan | jaosorior scroll back for context. in short: namnh is proposing to changes to support rolling upgrades and we need some expertise to review his ideas and answer his questions. (you're the expert. :-) ) | 15:31 |
*** diazjf has joined #openstack-barbican | 15:31 | |
jaosorior | ok, so, this caught me a little off guard | 15:32 |
jaosorior | I think this merits a blueprint (could even be in a light format) | 15:32 |
namnh | dave-mccowan: =))) | 15:32 |
jaosorior | and I'll do some research based on the blueprint to review it properly | 15:32 |
dave-mccowan | ok namnh: i can help putting your ideas into a blueprint document to help with review. | 15:33 |
namnh | jaosorior: so I will make a blueprint for this idea? | 15:33 |
jaosorior | namnh: doesn't have to be the full format of a blueprint | 15:33 |
dave-mccowan | jaosorior namnh had a particular question about how barbican does database access. | 15:33 |
jaosorior | there was a "light" format but I can't find it now | 15:34 |
jaosorior | So, for a long time we had brewed our own database code | 15:34 |
jaosorior | which made sense at the tiem, since no oslo.db existed (and if it did... it was on very early stages) | 15:34 |
jaosorior | idealy we should be switching fully to it | 15:34 |
jaosorior | and IIRC, at least we use the oslo.db-provided engine (which fixes a bunch of issues we used to have) | 15:35 |
dave-mccowan | namnh what is your question about database via a service? | 15:35 |
jaosorior | we still define our own models using sqlalchemy directly though | 15:35 |
jaosorior | so we don't have full support of all the features in oslo.db | 15:36 |
namnh | dave-mccowan: my question is that: are there any services in barbican which get information from database via a service (barbican-api or worker) | 15:37 |
namnh | dave-mccowan: for example: nova-compute want to get information from database via nova-condutor. in this case, ovo will be useful to modify this infor before sending to nova-compute. | 15:37 |
jaosorior | namnh: it's sort of mixed unfortunately | 15:37 |
jaosorior | namnh: so we also would need to have that separation done as well | 15:38 |
namnh | jaosorior: I am trying to confirm this to decide whether using ovo or not. actually, there are some project which don't use ovo to rolling upgrade like keystone and glance | 15:40 |
*** chlong has joined #openstack-barbican | 15:43 | |
namnh | jaosorior: summary, I will make a blueprint for this idea and list some items that need to solve? | 15:44 |
jaosorior | namnh: that would be great | 15:44 |
dave-mccowan | namnh if you would like, i can start a patch for the blueprint. i will take your ideas from this meeting and put them in the spec format, listing you as author. | 15:45 |
namnh | dave-mccowan: that is great after that i will contribute to list some items, right? | 15:47 |
*** pcaruana has quit IRC | 15:47 | |
dave-mccowan | namnh yes, you can write the second patch. i'll just help you get started. | 15:47 |
namnh | dave-mccowan: I am sorry for misunderstanding your meant, you mean that you push the patch set and I will comment on the patch. after that you will update a final patch. | 15:50 |
namnh | dave-mccowan: is that right, it's ok for me | 15:50 |
dave-mccowan | namnh i will push the first patch. then, you can comment or push the second patch. either way is fine with me. | 15:51 |
namnh | dave-mccowan: thanks in advance :) for this idead, i will work this with jaosorior :) | 15:53 |
namnh | s/idead/idea :)))) | 15:54 |
namnh | jaosorior: is it ok for you? :) | 15:55 |
dave-mccowan | namnh is there anything else you want to discuss now? | 15:55 |
namnh | dave-mccowan: one topic about zero downtime upgrade :) | 15:56 |
namnh | dave-mccowan: do we have time? | 15:56 |
dave-mccowan | namnh sure, keep going. | 15:57 |
namnh | maybe this idea for the future. however image that we finish "rolling upgrade" :) like keystone or glance. However I tested downtime during rolling upgrade keystone | 15:58 |
namnh | there are still one or two failure requests, and it occurs in migration phase | 15:59 |
namnh | so I think about holding request during migration database and here my POC: https://review.openstack.org/#/c/466251/ | 16:00 |
*** diazjf has quit IRC | 16:00 | |
namnh | we can use a feature in Pecan to hold incoming request from users and other projects during upgrade database | 16:01 |
namnh | for testing keystone: https://www.youtube.com/watch?v=YgGkFvXtRZs&feature=youtu.be and http://prntscr.com/fb6q64 | 16:01 |
jaosorior | namnh: it's good | 16:01 |
namnh | but I think this solution is not good in case taking a long time to upgrade db. | 16:01 |
namnh | what do you think about this idea? | 16:02 |
*** diazjf has joined #openstack-barbican | 16:02 | |
namnh | bty, here is a presentation about testing rolling upgrade for 5 projects. I and my co-worker do this but I could not go to the boston summit to present :) | 16:03 |
namnh | https://www.youtube.com/watch?v=VxfPe6EbT0s | 16:04 |
kfarr | namnh thanks for the link! we missed you in Boston! | 16:05 |
namnh | kfarr: thanks for helping to review the patch sets for "offline upgrade". could you please help me to push up the process of this tag | 16:06 |
*** diazjf has quit IRC | 16:06 | |
dave-mccowan | thanks namnh we'll check out the links. hopefully we all can make the next summit in Sydney. :-) | 16:07 |
namnh | =))) thanks. what do you think about zero downtime upgrade | 16:07 |
namnh | hold requests. there will be a problem if upgrading barbican database takes a long time | 16:08 |
namnh | dave-mccowan, kfarr, jaosorior | 16:09 |
dave-mccowan | namnh it's a very interesting idea. we'd need to make sure there is some limit to hold requests, so not to create an issue. | 16:10 |
dave-mccowan | an issue when the migrate takes a long time, or there is some other database failure. | 16:11 |
dave-mccowan | namnh for the upgrade tag: in the governance repo, add the tag to the file governance/reference/projects/barbican.rst | 16:12 |
*** diazjf has joined #openstack-barbican | 16:14 | |
dave-mccowan | namnh correction, in the file governance/reference/project.yaml. add the tag "assert:supports-upgrade" under barbican. | 16:17 |
namnh | dave-mccowan: yes, i will try to finish upgrade tag soom to do this job :) | 16:19 |
namnh | dave-mccowan: one last question, do you have any plan to change database in near future? | 16:19 |
namnh | dave-mccowan: I mean, deleting or alter in barbican database | 16:20 |
dave-mccowan | namnh i can't think of any proposed features that would require a change to the barbican database. | 16:23 |
namnh | dave-mccowan: yes, that is last question. thank all for listening my idea :) | 16:24 |
namnh | kfarr jaosorior. thank you. | 16:25 |
dave-mccowan | thanks namnh, we appreciate the contributions. | 16:27 |
namnh | dave-mccowan kfarr jaosorior: see you later. | 16:29 |
*** chlong has quit IRC | 16:30 | |
*** namnh has quit IRC | 16:34 | |
*** diazjf has quit IRC | 17:04 | |
*** diazjf has joined #openstack-barbican | 17:06 | |
openstackgerrit | Kaitlin Farr proposed openstack/barbican master: DevStack plugin set tempest options in test-config section https://review.openstack.org/467330 | 17:15 |
*** jaosorior is now known as jaosorior_away | 17:17 | |
*** diazjf has quit IRC | 17:18 | |
*** kfarr has quit IRC | 17:19 | |
*** salmankhan has quit IRC | 17:23 | |
*** dimtruck has quit IRC | 17:36 | |
*** dimtruck has joined #openstack-barbican | 17:38 | |
*** arunkant has joined #openstack-barbican | 18:32 | |
*** alee has quit IRC | 19:36 | |
*** dave-mccowan has quit IRC | 20:10 | |
*** salmankhan has joined #openstack-barbican | 20:43 | |
*** ssmith has quit IRC | 21:04 | |
-openstackstatus- NOTICE: The logserver has filled up, so jobs are currently aborting with POST_FAILURE results; remediation is underway. | 21:19 | |
*** ChanServ changes topic to "The logserver has filled up, so jobs are currently aborting with POST_FAILURE results; remediation is underway." | 21:19 | |
*** dimtruck is now known as zz_dimtruck | 21:33 | |
*** catintheroof has quit IRC | 21:33 | |
*** jroll has quit IRC | 21:47 | |
*** jroll has joined #openstack-barbican | 21:47 | |
*** jroll has quit IRC | 21:49 | |
*** salmankhan has quit IRC | 21:52 | |
*** alee has joined #openstack-barbican | 21:53 | |
*** zz_dimtruck is now known as dimtruck | 21:53 | |
*** jroll has joined #openstack-barbican | 21:53 | |
*** cpuga has quit IRC | 22:02 | |
*** dave-mccowan has joined #openstack-barbican | 22:43 | |
*** cpuga has joined #openstack-barbican | 23:36 | |
*** cpuga has quit IRC | 23:37 | |
*** cpuga has joined #openstack-barbican | 23:40 | |
*** dimtruck is now known as zz_dimtruck | 23:48 | |
*** zz_dimtruck is now known as dimtruck | 23:51 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!