*** sdake_ has joined #openstack-kolla | 00:03 | |
*** sdake has quit IRC | 00:06 | |
*** tonanhngo has joined #openstack-kolla | 00:18 | |
*** tonanhngo has quit IRC | 00:20 | |
*** chas_ has joined #openstack-kolla | 00:22 | |
*** Pavo has joined #openstack-kolla | 00:25 | |
*** chas_ has quit IRC | 00:26 | |
*** Pavo has quit IRC | 00:29 | |
*** Pavo has joined #openstack-kolla | 00:33 | |
*** nihilifer has quit IRC | 00:36 | |
*** Pavo has quit IRC | 00:36 | |
*** tonanhngo has joined #openstack-kolla | 00:39 | |
*** tonanhngo has quit IRC | 00:42 | |
*** tonanhngo has joined #openstack-kolla | 01:04 | |
*** tonanhngo has quit IRC | 01:06 | |
*** zhubingbing has joined #openstack-kolla | 01:26 | |
*** tonanhngo has joined #openstack-kolla | 01:39 | |
*** tonanhngo has quit IRC | 01:41 | |
*** tonanhngo has joined #openstack-kolla | 01:56 | |
*** tonanhngo has quit IRC | 01:59 | |
*** zhubingbing has quit IRC | 02:01 | |
*** chas_ has joined #openstack-kolla | 02:23 | |
*** tonanhngo has joined #openstack-kolla | 02:23 | |
*** tonanhngo has quit IRC | 02:26 | |
*** chas_ has quit IRC | 02:28 | |
*** f13o has quit IRC | 02:28 | |
*** sdake has joined #openstack-kolla | 02:52 | |
*** tonanhngo has joined #openstack-kolla | 02:54 | |
*** sdake_ has quit IRC | 02:55 | |
*** tonanhngo has quit IRC | 02:56 | |
*** f13o has joined #openstack-kolla | 02:59 | |
*** sdake has quit IRC | 03:03 | |
*** f13o has quit IRC | 03:06 | |
*** schwicht has quit IRC | 03:11 | |
*** tonanhngo has joined #openstack-kolla | 03:14 | |
*** tonanhngo has quit IRC | 03:15 | |
*** Pavo has joined #openstack-kolla | 03:17 | |
*** chas_ has joined #openstack-kolla | 03:24 | |
*** chas_ has quit IRC | 03:28 | |
*** haplo37 has quit IRC | 03:42 | |
*** g3ek has quit IRC | 03:42 | |
*** tonanhngo has joined #openstack-kolla | 03:45 | |
*** tonanhngo has quit IRC | 03:47 | |
*** g3ek has joined #openstack-kolla | 03:48 | |
*** haplo37 has joined #openstack-kolla | 03:48 | |
*** tonanhngo has joined #openstack-kolla | 04:04 | |
*** tonanhngo has quit IRC | 04:07 | |
*** tonanhngo has joined #openstack-kolla | 04:25 | |
*** chas_ has joined #openstack-kolla | 04:25 | |
*** tonanhngo has quit IRC | 04:27 | |
*** chas_ has quit IRC | 04:30 | |
*** yingjun has joined #openstack-kolla | 05:04 | |
*** Pavo has quit IRC | 05:12 | |
*** Pavo has joined #openstack-kolla | 05:16 | |
*** karlamrhein has quit IRC | 05:24 | |
*** yingjun has quit IRC | 05:24 | |
*** zhenguo has quit IRC | 05:25 | |
*** alanmeadows has quit IRC | 05:25 | |
*** chas_ has joined #openstack-kolla | 05:26 | |
*** chas_ has quit IRC | 05:30 | |
*** alanmeadows has joined #openstack-kolla | 05:38 | |
*** zhenguo has joined #openstack-kolla | 05:39 | |
*** karlamrhein has joined #openstack-kolla | 05:39 | |
*** sdake has joined #openstack-kolla | 05:48 | |
*** CBR09 has joined #openstack-kolla | 06:09 | |
*** tonanhngo has joined #openstack-kolla | 06:14 | |
*** tonanhngo has quit IRC | 06:15 | |
*** sdake has quit IRC | 06:16 | |
*** Administrator_ has quit IRC | 06:17 | |
*** Administrator_ has joined #openstack-kolla | 06:18 | |
*** chas_ has joined #openstack-kolla | 06:26 | |
*** chas_ has quit IRC | 06:31 | |
*** Pavo has quit IRC | 07:12 | |
*** Pavo has joined #openstack-kolla | 07:16 | |
*** tonanhngo has joined #openstack-kolla | 07:24 | |
*** tonanhngo has quit IRC | 07:26 | |
*** chas_ has joined #openstack-kolla | 07:27 | |
*** chas_ has quit IRC | 07:31 | |
*** tonanhngo has joined #openstack-kolla | 07:44 | |
*** tonanhngo has quit IRC | 07:45 | |
*** tonanhngo has joined #openstack-kolla | 08:01 | |
*** tonanhngo has quit IRC | 08:03 | |
*** tonanhngo has joined #openstack-kolla | 08:14 | |
*** tonanhngo has quit IRC | 08:16 | |
*** g3ek has quit IRC | 08:23 | |
*** haplo37 has quit IRC | 08:24 | |
*** chas_ has joined #openstack-kolla | 08:28 | |
*** haplo37 has joined #openstack-kolla | 08:29 | |
*** g3ek has joined #openstack-kolla | 08:29 | |
*** chas_ has quit IRC | 08:32 | |
*** Pavo has quit IRC | 09:12 | |
*** awiddersheim has quit IRC | 09:12 | |
*** Pavo has joined #openstack-kolla | 09:16 | |
*** fragatina has quit IRC | 09:26 | |
*** fragatina has joined #openstack-kolla | 09:27 | |
*** chas_ has joined #openstack-kolla | 09:29 | |
*** nihilifer has joined #openstack-kolla | 09:30 | |
*** yingjun has joined #openstack-kolla | 09:33 | |
*** chas_ has quit IRC | 09:34 | |
*** CBR09 has quit IRC | 09:34 | |
*** yingjun has quit IRC | 09:39 | |
*** yingjun has joined #openstack-kolla | 09:39 | |
*** yingjun has quit IRC | 09:44 | |
*** matrohon has joined #openstack-kolla | 10:00 | |
*** matrohon has quit IRC | 10:06 | |
*** neilus has quit IRC | 10:29 | |
*** neilus has joined #openstack-kolla | 10:30 | |
*** chas_ has joined #openstack-kolla | 10:30 | |
openstackgerrit | zhubingbing proposed openstack/kolla: Add trove role https://review.openstack.org/354901 | 10:32 |
---|---|---|
*** zhubingbing has joined #openstack-kolla | 10:33 | |
zhubingbing | hello guys | 10:34 |
zhubingbing | -) | 10:34 |
*** chas_ has quit IRC | 10:34 | |
*** stvnoyes has quit IRC | 10:42 | |
*** stvnoyes has joined #openstack-kolla | 10:43 | |
openstackgerrit | zhubingbing proposed openstack/kolla: Add trove role https://review.openstack.org/354901 | 10:55 |
*** chas_ has joined #openstack-kolla | 10:57 | |
*** Pavo has quit IRC | 11:12 | |
*** tonanhngo has joined #openstack-kolla | 11:14 | |
*** Pavo has joined #openstack-kolla | 11:16 | |
*** tonanhngo has quit IRC | 11:16 | |
*** f13o has joined #openstack-kolla | 11:28 | |
openstackgerrit | zhubingbing proposed openstack/kolla: Fix trove dockerfile https://review.openstack.org/396928 | 11:55 |
*** jmccarthy has quit IRC | 12:05 | |
*** chas_ has quit IRC | 12:06 | |
*** jmccarthy has joined #openstack-kolla | 12:06 | |
*** caowei has joined #openstack-kolla | 12:18 | |
*** neilus has quit IRC | 12:26 | |
*** g3ek has quit IRC | 12:46 | |
*** haplo37 has quit IRC | 12:47 | |
*** haplo37 has joined #openstack-kolla | 12:52 | |
*** g3ek has joined #openstack-kolla | 12:53 | |
*** neilus has joined #openstack-kolla | 12:57 | |
*** neilus has quit IRC | 13:01 | |
*** Pavo has quit IRC | 13:12 | |
*** tonanhngo has joined #openstack-kolla | 13:14 | |
*** tonanhngo has quit IRC | 13:15 | |
*** Pavo has joined #openstack-kolla | 13:16 | |
*** clayton has quit IRC | 13:25 | |
*** clayton has joined #openstack-kolla | 13:26 | |
*** tonanhngo has joined #openstack-kolla | 13:34 | |
*** sdake has joined #openstack-kolla | 13:35 | |
*** tonanhngo has quit IRC | 13:35 | |
openstackgerrit | zhubingbing proposed openstack/kolla: add extend_start.sh in trove dockerfile https://review.openstack.org/396932 | 13:36 |
*** caowei has quit IRC | 13:55 | |
*** caowei has joined #openstack-kolla | 14:00 | |
*** chas_ has joined #openstack-kolla | 14:07 | |
*** chas_ has quit IRC | 14:12 | |
*** tonanhngo has joined #openstack-kolla | 14:34 | |
*** sdake_ has joined #openstack-kolla | 14:45 | |
*** sdake has quit IRC | 14:49 | |
*** caowei has quit IRC | 14:55 | |
openstackgerrit | zhubingbing proposed openstack/kolla: add extend_start.sh in trove dockerfile https://review.openstack.org/396932 | 14:59 |
*** tonanhngo has joined #openstack-kolla | 15:00 | |
*** chas_ has joined #openstack-kolla | 15:08 | |
*** Pavo has quit IRC | 15:12 | |
*** jrist has quit IRC | 15:12 | |
*** chas_ has quit IRC | 15:13 | |
*** tonanhngo has joined #openstack-kolla | 15:14 | |
*** tonanhngo has quit IRC | 15:16 | |
*** sdake_ has quit IRC | 15:16 | |
*** Pavo has joined #openstack-kolla | 15:17 | |
*** sdake has joined #openstack-kolla | 15:20 | |
*** zhubingbing has quit IRC | 15:28 | |
*** tonanhngo has joined #openstack-kolla | 15:34 | |
*** tonanhngo has quit IRC | 15:37 | |
*** neilus has joined #openstack-kolla | 15:40 | |
*** awiddersheim has joined #openstack-kolla | 15:43 | |
openstackgerrit | Andrew Widdersheim proposed openstack/kolla: Fix precheck conditional in site.yml https://review.openstack.org/396760 | 15:45 |
*** sdake_ has joined #openstack-kolla | 15:45 | |
*** sdake has quit IRC | 15:48 | |
*** tonanhngo has joined #openstack-kolla | 15:54 | |
*** tonanhngo has quit IRC | 15:56 | |
*** jrist has joined #openstack-kolla | 16:06 | |
*** chas_ has joined #openstack-kolla | 16:09 | |
*** chas_ has quit IRC | 16:13 | |
*** tonanhngo has joined #openstack-kolla | 16:15 | |
*** tonanhngo has quit IRC | 16:17 | |
openstackgerrit | Eduardo Gonzalez proposed openstack/kolla: Fix ovs-cleanup issue at cleanup scripts https://review.openstack.org/396948 | 16:24 |
openstackgerrit | Eduardo Gonzalez proposed openstack/kolla: Fix ovs-cleanup issue at cleanup scripts https://review.openstack.org/396948 | 16:32 |
openstackgerrit | Merged openstack/kolla: Add Karbor doc link in README.rst https://review.openstack.org/396613 | 16:38 |
*** tonanhngo has joined #openstack-kolla | 16:39 | |
*** tonanhngo has quit IRC | 16:41 | |
openstackgerrit | Merged openstack/kolla: Add enable_cinder_backend_nfs option example https://review.openstack.org/396720 | 16:42 |
*** bmace has quit IRC | 16:51 | |
*** bmace has joined #openstack-kolla | 16:51 | |
*** tonanhngo has joined #openstack-kolla | 16:57 | |
*** tonanhngo has quit IRC | 17:00 | |
*** Pavo has quit IRC | 17:12 | |
*** Pavo has joined #openstack-kolla | 17:12 | |
*** tonanhngo has joined #openstack-kolla | 17:15 | |
*** tonanhngo has quit IRC | 17:16 | |
v1k0d3n | kfox1111: you there this morning? | 17:28 |
*** g3ek has quit IRC | 17:32 | |
*** haplo37 has quit IRC | 17:32 | |
*** tonanhngo has joined #openstack-kolla | 17:34 | |
*** g3ek has joined #openstack-kolla | 17:34 | |
*** haplo37 has joined #openstack-kolla | 17:34 | |
*** tonanhngo has quit IRC | 17:35 | |
kfox1111 | v1k0d3n: hi | 17:44 |
kfox1111 | whats up? | 17:44 |
*** ipsecguy_ has joined #openstack-kolla | 17:44 | |
v1k0d3n | saw some of the discussion around the 14 character limitation. i think that is being improved in v2.0.0 which is in rc2 currently. | 17:45 |
kfox1111 | ah. that would be really nice. | 17:45 |
v1k0d3n | did you run into some of the same issues reported in helm too? | 17:45 |
v1k0d3n | https://github.com/kubernetes/helm/issues/1219 | 17:45 |
v1k0d3n | i probably missed it, but is helm for sure a go? been waiting to see if kolla-kube made a decision on this yet. | 17:45 |
kfox1111 | ah. didn't see that one yet. | 17:46 |
v1k0d3n | well, it's actually because of the kube dns max limitation. | 17:46 |
kfox1111 | v1k0d3n: its a go unless we find some major showstopper. | 17:46 |
kfox1111 | its a package name though, why woudl that matter? | 17:47 |
kfox1111 | is not in dns. | 17:47 |
v1k0d3n | ah! ok...i missed that. glad this is a go. | 17:47 |
v1k0d3n | we definitely want to help address some of this then. | 17:47 |
v1k0d3n | have you see the SAP repo, and how they are addressing some of these same things? | 17:47 |
kfox1111 | they arn't. | 17:47 |
kfox1111 | they are currently doing a bunch of orchestration with it too. | 17:48 |
v1k0d3n | it's not a direct drop and replace at all, but some of the work can definitely be reused. | 17:48 |
kfox1111 | yeah. will churn through it in detail at some point. | 17:48 |
kfox1111 | right now, just tryign to understand helm and figure out how we map what we have into that model. | 17:48 |
*** ipsecguy has quit IRC | 17:48 | |
kfox1111 | you see the poc I've been working on? | 17:49 |
v1k0d3n | i haven't | 17:49 |
v1k0d3n | where is that? | 17:49 |
kfox1111 | https://review.openstack.org/#/c/396296/ | 17:49 |
v1k0d3n | SAP is a PoC too...just throwing that out there. | 17:49 |
kfox1111 | it has a working gate with neutron-l3-agent deployed with helm. | 17:49 |
*** eaguilar has joined #openstack-kolla | 17:50 | |
v1k0d3n | can we see if we can include the SAP folks? | 17:50 |
kfox1111 | sure. you can share the link with whomever is interested. | 17:50 |
v1k0d3n | reason why...everyone goes through some of the same learning curves...one of the hardest is how to make some of the configmap items agnostic so operators can plug in their own items. | 17:50 |
v1k0d3n | they have been doing a lot of work around this lately...some good updates. | 17:50 |
kfox1111 | thats the problem I've seen with sap's implementation so far | 17:50 |
kfox1111 | it seems very opinionated. | 17:50 |
v1k0d3n | (look through the PR's) | 17:50 |
v1k0d3n | so... | 17:51 |
v1k0d3n | they wen't with very opinionated first...because they just wanted it to work | 17:51 |
kfox1111 | yeah. everyone wants to start that way. | 17:51 |
v1k0d3n | now they are scaling back to a less opinionated model/approach...as they learn and communcate with the helm/deis folks. | 17:51 |
kfox1111 | the problem is, you end up building a architecture around it that has way too many asumptions. | 17:51 |
v1k0d3n | well, yeah...makes sense though. start with what you know to limit the learning curve and then work back. | 17:52 |
kfox1111 | so, like, they do all the service stuff per service in a single helm package. | 17:52 |
kfox1111 | makes it really easy to orchestrate it. | 17:52 |
kfox1111 | but really difficult to make the config generic. | 17:52 |
v1k0d3n | actually they're working through this now... | 17:52 |
v1k0d3n | one sec... | 17:53 |
kfox1111 | I usually take a different aproach. | 17:53 |
kfox1111 | slower to get somethign working, but less reworking. | 17:53 |
kfox1111 | break up the design ahead of time into something that shoudl work for the long run, | 17:53 |
kfox1111 | and make a prototype of each of the pieces with bare minimum functionality. | 17:53 |
kfox1111 | then it can be fleshed out in parallel. | 17:53 |
v1k0d3n | yeah, either works. i can fully understand both methods. | 17:54 |
*** neilus has quit IRC | 17:54 | |
v1k0d3n | i try to work similarly. | 17:54 |
v1k0d3n | (as your approach) | 17:54 |
v1k0d3n | just wondering if we can merge some of this effort | 17:55 |
*** tonanhngo has joined #openstack-kolla | 17:55 | |
kfox1111 | yeah. we can certainly try | 17:55 |
*** tonanhngo has quit IRC | 17:58 | |
*** neilus has joined #openstack-kolla | 18:01 | |
*** pbourke has quit IRC | 18:06 | |
*** pbourke has joined #openstack-kolla | 18:08 | |
*** chas_ has joined #openstack-kolla | 18:10 | |
*** chas_ has quit IRC | 18:15 | |
*** eaguilar has quit IRC | 18:23 | |
*** tonanhngo has joined #openstack-kolla | 18:24 | |
*** eaguilar has joined #openstack-kolla | 18:25 | |
*** tonanhngo has quit IRC | 18:25 | |
*** neilus has quit IRC | 18:29 | |
*** Pavo has quit IRC | 18:34 | |
*** awiddersheim has quit IRC | 18:38 | |
*** Pavo has joined #openstack-kolla | 18:43 | |
*** neilus has joined #openstack-kolla | 18:50 | |
*** eaguilar has quit IRC | 18:51 | |
*** neilus has quit IRC | 18:54 | |
*** f13o has quit IRC | 18:58 | |
*** chas_ has joined #openstack-kolla | 19:11 | |
*** f13o has joined #openstack-kolla | 19:12 | |
*** chas_ has quit IRC | 19:15 | |
*** harbor has joined #openstack-kolla | 19:27 | |
*** harbor is now known as portdirect_ | 19:28 | |
*** portdirect_ is now known as portdirect | 19:40 | |
Pavo | ok so I think I ready to try this kolla-kubernetes where do I start and will need full install instructions | 19:43 |
*** portdirect has quit IRC | 19:46 | |
*** Pavo has quit IRC | 19:47 | |
*** f13o has quit IRC | 19:49 | |
*** harbor has joined #openstack-kolla | 19:50 | |
*** harbor is now known as portdirect | 19:50 | |
*** v1k0d3n has quit IRC | 20:06 | |
kfox1111 | anyone have a link to kuberntees-endpoint | 20:06 |
*** chas_ has joined #openstack-kolla | 20:12 | |
*** chas_ has quit IRC | 20:16 | |
portdirect | kfox1111: https://github.com/stackanetes/kubernetes-entrypoint | 20:17 |
portdirect | kfox1111: I have reservations... | 20:18 |
portdirect | I'f be much keener on this as an init container rather than an entrypoint | 20:19 |
*** eaguilar has joined #openstack-kolla | 20:25 | |
*** tonanhngo has joined #openstack-kolla | 20:29 | |
*** tonanhngo has quit IRC | 20:31 | |
*** f13o has joined #openstack-kolla | 20:32 | |
kfox1111 | portdirect: I just want to look at it a bit so I understand the use cases for it better. | 20:34 |
kfox1111 | portdirect: thanks for the link. | 20:35 |
sdake_ | kfox1111 there is a more important link you are missing i htink | 20:35 |
sdake_ | https://github.com/stackanetes/stackanetes/blob/master/nova/manifest.jsonnet | 20:36 |
sdake_ | see: https://github.com/stackanetes/stackanetes/blob/master/nova/templates/api/deployment.yaml.j2#L36 | 20:38 |
sdake_ | kfox1111 the use case for it is dep management | 20:39 |
sdake_ | pavo kolla-kubernetes is under heavy development | 20:41 |
sdake_ | pavo few people know even how to get it to run multinode ;( | 20:42 |
sdake_ | oops pavo not here | 20:42 |
*** portdirect has quit IRC | 21:00 | |
*** harbor has joined #openstack-kolla | 21:01 | |
*** harbor is now known as portdirect | 21:01 | |
*** tonanhngo has joined #openstack-kolla | 21:06 | |
kfox1111 | sdake_: thx. | 21:07 |
*** tonanhngo has quit IRC | 21:07 | |
kfox1111 | I do see a use case for entrypoint, but not quite in the way I think they tought it would be used. | 21:07 |
kfox1111 | their stated goal is to put it in all the containers. but I think that is unnessisary now. | 21:08 |
kfox1111 | you could make it as a side car container and put it as an init-container. | 21:08 |
sdake_ | agree | 21:08 |
kfox1111 | you get the same benifits, without having to tweak every container. | 21:08 |
sdake_ | that is what the purpose of the operator container is imo ;) | 21:08 |
sdake_ | why have two do the same task? | 21:08 |
kfox1111 | it even has an enhanced benifit. | 21:08 |
kfox1111 | entrypoint needs k8s creds to work. | 21:08 |
sdake_ | so do operator containers | 21:09 |
kfox1111 | while in an init container, it can be restricted just to that container, enhancing security. | 21:09 |
kfox1111 | so the rest of the containers don't need the token. | 21:09 |
sdake_ | the operator containers need to be able to do stuff with kubernetes directly | 21:09 |
kfox1111 | it looks like operator containers and entrypoint are complimentery too. | 21:09 |
sdake_ | even if you take out dep management | 21:09 |
kfox1111 | yeah. | 21:10 |
kfox1111 | not sure all dep management is appropriate for entrypoint. but some for sure. | 21:10 |
kfox1111 | operators can do the rest. | 21:10 |
*** eaguilar has quit IRC | 21:10 | |
sdake_ | why add the complexity of entrypoint as a seprate whole container if operator can do the whole schebang? | 21:11 |
sdake_ | we are already adding operator to handle the orchestration tasks | 21:11 |
sdake_ | entrypoint = dep management = one peice of orchestration puzzle | 21:11 |
kfox1111 | one use case I can see is, say rebooting a node, where there are libvirt/openvswitch containers. | 21:11 |
kfox1111 | the daemonsets are already deployed, so an operator has no influence in it. | 21:11 |
kfox1111 | but it would be handy for the libvirt container to wait until the opevswitch one is started on the same host. | 21:12 |
portdirect | kfox1111: the security implications are one of the primary resons for moving it out into an init container, also the issues that you have experienced with ingress controllers can become apparent - wehre the rate-linkits on the k8s api server would potential prevent services from starting following an outage, or other event that causes abnomal load on the th api server | 21:12 |
*** chas_ has joined #openstack-kolla | 21:13 | |
sdake_ | kfox1111 yes, this is the model of operator containers | 21:13 |
kfox1111 | yeah. I think entrypoint should be used sparingly, so not too much load on the api server. but used strategically along with operators would make sense. | 21:13 |
sdake_ | operators are intelligent agents | 21:15 |
sdake_ | they need to be smart enough to back off the api servers if there is no forward progress in the system | 21:15 |
kfox1111 | yeah. being centralized, they can. | 21:15 |
kfox1111 | entrypoint containers can't, as tehy are decenteralized | 21:15 |
portdirect | yup | 21:16 |
*** chas_ has quit IRC | 21:17 | |
kfox1111 | hmm... | 21:19 |
portdirect | just to clarify the problem I've seen is this: api-server rate limits - so kubelet cannot report status of pods etc - health checks times out (node/service/endpoint) - api server marks health service unhealthy - scheduler tries to rebuild healthy service - more api-server requests - downward spiral of death... | 21:19 |
kfox1111 | you know though, I solved one of the entrypoint issues in a very different way. | 21:19 |
kfox1111 | I had one daemonset just write out a file on /dev/shm/ when inited, and have the other daemonset 1 second sleep loop until it shows up. | 21:20 |
kfox1111 | scales linearly, doesn't require k8s creds, and doesn't touch the api server. | 21:21 |
portdirect | it's ugly but works | 21:21 |
kfox1111 | did that for a physics system. | 21:21 |
kfox1111 | a little hackish, but worked well. | 21:21 |
portdirect | I've used that in the past, though I now tend to use a deadicated etcd-server | 21:22 |
kfox1111 | that would work too. | 21:22 |
kfox1111 | more etcd systems to manage though. | 21:22 |
portdirect | I'm gonna have a play around - but I think we many be able to use annotations of the k8s service assosiated with each openstack service to track deps and state | 21:23 |
kfox1111 | yeah. I think that would work. | 21:24 |
portdirect | It's what we used for traking security groups attached to pods on the initial k8s netron cni driver - obviously annotating pods not services | 21:25 |
sdake_ | portdirect another option as well is to use the thirdparty passthrough to etcd to do the job | 21:25 |
portdirect | as operators are goint to be interacting with the api, they would be able to do that. | 21:26 |
portdirect | sdake: need to look into that - sounds v interesting. | 21:26 |
portdirect | you have a link to docs? - my google fu is not at full strength | 21:27 |
portdirect | I think we also need to have real think about security, I'm not sure that having openstack inside a single namespace is a good idea - k8s ABAC sucks | 21:31 |
sdake_ | portdirect which docs? | 21:31 |
kfox1111 | abac sucks, but rbac is starting to mature quite nicely. | 21:31 |
kfox1111 | we may need to study rbac and come up with some rules to ship. | 21:31 |
sdake_ | you mean this: https://github.com/kubernetes/kubernetes/blob/master/docs/design/extending-api.md | 21:31 |
portdirect | sdake, cheers | 21:32 |
sdake_ | there isn't enough life on this planet to fill a space cruiser | 21:33 |
sdake_ | and on that note, I depart ;) | 21:33 |
kfox1111 | hehe | 21:34 |
kfox1111 | sdake_: l8r | 21:34 |
*** Jeffrey4l has quit IRC | 21:34 | |
portdirect | laters | 21:34 |
openstackgerrit | Eduardo Gonzalez proposed openstack/kolla: Create Senlin home directory https://review.openstack.org/396956 | 21:34 |
kfox1111 | you know... | 21:34 |
kfox1111 | with our template libraries, | 21:35 |
kfox1111 | I think we can easily slide in kubernetes-entrypoint in each container with a flag. | 21:35 |
kfox1111 | so those wanting entrypoint can use it. | 21:35 |
kfox1111 | s/continer/pod/ | 21:36 |
portdirect | 'tis the nice thing about go | 21:37 |
kfox1111 | then those wanting to use it that way could. | 21:37 |
kfox1111 | its the nice thing about using a template language in front of pods. | 21:37 |
kfox1111 | so helm's templates or jinja2. | 21:37 |
portdirect | I personally prefer j2, but we would be swimming against the tide. | 21:39 |
portdirect | and the sea is cold. | 21:39 |
kfox1111 | portdirect: there is a flag in helm for which template language to use. someone could implement a jinja plugin.... :) | 21:40 |
*** neilus has joined #openstack-kolla | 21:40 | |
portdirect | the sea just got warmer | 21:40 |
openstackgerrit | Eduardo Gonzalez proposed openstack/kolla: Tacker Docker configuration https://review.openstack.org/396391 | 21:40 |
kfox1111 | golang templates are pretty weird. I prefer jinja2 myself. | 21:40 |
kfox1111 | though the weirdness isn't much functionally different. you can do pretty much everything either way. | 21:41 |
kfox1111 | I got l3-agent to deploy with it successfully. | 21:41 |
portdirect | n another (but slightly releated) note, havw you used romana? | 21:42 |
portdirect | *on | 21:43 |
kfox1111 | nice... entrypoint has this: DEPENDENCY_SOCKET=/var/run/openvswitch/ovs.socket | 21:43 |
kfox1111 | that would work decentralized. | 21:43 |
kfox1111 | hmm.. and they have a template engine too. | 21:43 |
*** fragatina has quit IRC | 21:44 | |
kfox1111 | even if we don't use anything but those features, its still useful. | 21:44 |
kfox1111 | we should make a kubernetes-entrypoint only container to play with. | 21:45 |
*** neilus has quit IRC | 21:46 | |
portdirect | I think that's the best way to play with it - I've done a few experiments where it just runs /bin/true as it's launch command | 21:46 |
portdirect | have stackanets published the source for their containers anywhere? | 21:47 |
kfox1111 | https://github.com/stackanetes/ | 21:48 |
portdirect | I cant see them? | 21:48 |
kfox1111 | portdirect: you were talking about working on contributing alpine based images. is that still a thing? | 21:48 |
portdirect | yup | 21:49 |
kfox1111 | cool. | 21:49 |
portdirect | I've made some progess on moving my stuff over | 21:49 |
portdirect | but been held up with other stuff | 21:49 |
portdirect | it's been a bit triky to ake the most of using alpine with the current kolla-build | 21:50 |
kfox1111 | ah. yeah. I don't think it was desigened with alpine in mind. | 21:50 |
portdirect | need to finish this: https://review.openstack.org/#/c/392115/ | 21:50 |
portdirect | without it the images end up very similar in size to centos etc | 21:51 |
kfox1111 | ah. cool. I"ll keep an eye in it. :) | 21:51 |
kfox1111 | oh really? weird. | 21:51 |
portdirect | about 200mb off the base - but the delta's remain similar | 21:52 |
kfox1111 | if I remember right, most of the stuff is in the base by default and the leave images are pretty thin, | 21:53 |
kfox1111 | so that would make sense to me. | 21:53 |
*** v1k0d3n has joined #openstack-kolla | 21:53 | |
portdirect | yup - so you end up dragging gcc and all the development libs about | 21:53 |
kfox1111 | oh. gcc's still in the image? wow... yeah. thats an issue. | 21:54 |
portdirect | .... I know... | 21:54 |
kfox1111 | v1k0d3n: ping | 21:54 |
portdirect | all of the images kola build at the moment have full development libs and compilers in them afak | 21:55 |
kfox1111 | yeah, thats kind of lame. | 21:55 |
portdirect | once I've got alpine finished the kolla images should be a similar size to the ones I'm using at the moment: https://microbadger.com/images/port/openstack-neutron-api | 21:56 |
*** awiddersheim has joined #openstack-kolla | 21:57 | |
kfox1111 | nice. | 21:57 |
*** neilus has joined #openstack-kolla | 21:58 | |
*** v1k0d3n has quit IRC | 21:58 | |
*** v1k0d3n has joined #openstack-kolla | 22:00 | |
kfox1111 | v1k0d3n: alive? | 22:01 |
*** nihilifer has quit IRC | 22:05 | |
*** v1k0d3n has quit IRC | 22:13 | |
*** chas_ has joined #openstack-kolla | 22:14 | |
*** neilus_ has joined #openstack-kolla | 22:15 | |
*** fragatina has joined #openstack-kolla | 22:16 | |
*** chas_ has quit IRC | 22:18 | |
*** neilus has quit IRC | 22:19 | |
*** Guest93429 has joined #openstack-kolla | 22:20 | |
*** portdirect is now known as portd | 22:24 | |
*** portd is now known as port | 22:24 | |
*** port is now known as portdirect_away | 22:24 | |
sdake_ | portdirect_away no they have not | 22:29 |
*** portdirect_away is now known as portdirect | 22:32 | |
*** Guest93429 has quit IRC | 22:32 | |
portdirect | sdake: sweet, sry i missed that! where do they get removed? | 22:32 |
*** newmember has joined #openstack-kolla | 22:40 | |
portdirect | sdake: https://gist.github.com/intlabs/e0ad9512ef35f21f96984991c4739e4b | 22:59 |
kfox1111 | portdirect: I'd guess the source based ones would still do gcc as its gota build from source. | 23:02 |
kfox1111 | do the binary distro's have the same issue? | 23:02 |
*** Pavo has joined #openstack-kolla | 23:04 | |
portdirect | yeah, I get round it buy explicity installing and then uninstalling as required, saves some space, but makes for horribly slow builds: https://github.com/portdirect/harbor/blob/latest/docker/openstack/openstack-cinder/openstack-cinder-centos/Dockerfile#L33 | 23:08 |
portdirect | kfox1111: not that I've seen, though I've not done much with them | 23:09 |
*** tonanhngo has joined #openstack-kolla | 23:09 | |
*** tonanhngo has quit IRC | 23:12 | |
kfox1111 | portdirect: yeah. I only use binary builds. | 23:15 |
portdirect | kfox1111: they dont, sorry for the sweeping statement | 23:21 |
*** portdirect is now known as portdirect_away | 23:21 | |
*** neilus_ has quit IRC | 23:24 | |
*** neilus has joined #openstack-kolla | 23:24 | |
*** Jeffrey4l has joined #openstack-kolla | 23:30 | |
Pavo | kfox1111 is kolla-kubernetes working? | 23:43 |
*** f13o has quit IRC | 23:44 | |
kfox1111 | portdirect_away: no worries. | 23:55 |
kfox1111 | Pavo: yeah, I'd say so. very little docs yet though. | 23:55 |
kfox1111 | I have a gate job for multinode with ceph backend for kolla-kubernetes. so its fairly well tested. | 23:56 |
kfox1111 | but the only real complete multinode docs are that setup_gate.sh script. | 23:56 |
Pavo | would that script guide me on how to setup my 2 nodes and networking? | 23:57 |
Pavo | how much change would I need to do from this? https://www.gliffy.com/go/publish/11309187 | 23:58 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!