*** dave-mccowan has joined #openstack-kolla | 00:03 | |
*** chas has joined #openstack-kolla | 00:09 | |
*** fguillot has quit IRC | 00:11 | |
*** itlinux has quit IRC | 00:11 | |
*** chas has quit IRC | 00:14 | |
*** salv-orlando has joined #openstack-kolla | 00:15 | |
*** masber has joined #openstack-kolla | 00:17 | |
*** salv-orlando has quit IRC | 00:19 | |
*** manheim has joined #openstack-kolla | 00:26 | |
*** masber has quit IRC | 00:26 | |
openstackgerrit | Li Yingjun proposed openstack/kolla master: Add os-brick to glance container https://review.openstack.org/468604 | 00:26 |
---|---|---|
*** masber has joined #openstack-kolla | 00:26 | |
*** yingjun has joined #openstack-kolla | 00:27 | |
*** manheim has quit IRC | 00:30 | |
*** feisky has joined #openstack-kolla | 00:31 | |
*** feisky has left #openstack-kolla | 00:31 | |
*** powerd has quit IRC | 00:31 | |
*** fooliouno has joined #openstack-kolla | 00:36 | |
*** Pavo has joined #openstack-kolla | 00:51 | |
*** eaguilar has joined #openstack-kolla | 00:52 | |
*** Pavo has quit IRC | 00:53 | |
*** cuongnv has joined #openstack-kolla | 00:54 | |
*** eanylin has quit IRC | 01:12 | |
*** lucasxu has joined #openstack-kolla | 01:17 | |
*** lucasxu has quit IRC | 01:17 | |
*** lucasxu has joined #openstack-kolla | 01:20 | |
*** powerd has joined #openstack-kolla | 01:22 | |
*** lucasxu has quit IRC | 01:22 | |
*** lucasxu has joined #openstack-kolla | 01:23 | |
*** hrw has quit IRC | 01:32 | |
*** hrw has joined #openstack-kolla | 01:34 | |
*** caoyuan has joined #openstack-kolla | 01:39 | |
*** tovin07_ has joined #openstack-kolla | 01:39 | |
*** rwellum has quit IRC | 01:41 | |
*** eanylin has joined #openstack-kolla | 01:42 | |
Jeffrey4l | pomac, re btrfs: yes. | 01:48 |
*** yingjun has quit IRC | 01:50 | |
*** yingjun has joined #openstack-kolla | 01:51 | |
*** powerd has quit IRC | 01:51 | |
*** hongbin has quit IRC | 01:51 | |
*** lucasxu has quit IRC | 02:01 | |
*** eaguilar has quit IRC | 02:01 | |
*** unicell has quit IRC | 02:06 | |
*** chas has joined #openstack-kolla | 02:10 | |
*** lucasxu has joined #openstack-kolla | 02:11 | |
*** lucasxu has quit IRC | 02:13 | |
*** lucasxu has joined #openstack-kolla | 02:14 | |
*** chas has quit IRC | 02:15 | |
*** salv-orlando has joined #openstack-kolla | 02:15 | |
*** dave-mccowan has quit IRC | 02:15 | |
*** Pavo has joined #openstack-kolla | 02:16 | |
*** caowei has joined #openstack-kolla | 02:19 | |
*** jrist has quit IRC | 02:20 | |
*** salv-orlando has quit IRC | 02:20 | |
*** jrist has joined #openstack-kolla | 02:34 | |
*** Pavo has quit IRC | 02:34 | |
*** lucasxu has quit IRC | 02:40 | |
*** jamesbenson has joined #openstack-kolla | 02:41 | |
*** bjolo has quit IRC | 02:45 | |
*** lucasxu has joined #openstack-kolla | 02:45 | |
openstackgerrit | Merged openstack/kolla-kubernetes master: Remove pathfinder from call path of secret-generator https://review.openstack.org/464273 | 02:46 |
*** lucasxu has quit IRC | 02:47 | |
openstackgerrit | Serguei Bezverkhi proposed openstack/kolla-kubernetes master: Script to clean up kolla-kubernetes node labels https://review.openstack.org/466501 | 02:50 |
openstackgerrit | Merged openstack/kolla-ansible stable/ocata: Fix Telegraf role reconfigure action https://review.openstack.org/450846 | 02:51 |
*** lucasxu has joined #openstack-kolla | 02:56 | |
*** lucasxu has quit IRC | 03:04 | |
openstackgerrit | Van Hung Pham proposed openstack/kolla master: Trivial fix typos in documents https://review.openstack.org/469031 | 03:08 |
openstackgerrit | jimmygc proposed openstack/kolla master: Support VMware DVS https://review.openstack.org/459273 | 03:25 |
*** david-lyle has joined #openstack-kolla | 03:35 | |
*** janki has joined #openstack-kolla | 03:37 | |
*** lucasxu has joined #openstack-kolla | 03:45 | |
*** unicell has joined #openstack-kolla | 03:46 | |
*** salv-orlando has joined #openstack-kolla | 03:50 | |
*** salv-orlando has quit IRC | 03:54 | |
*** caowei has quit IRC | 04:01 | |
openstackgerrit | Jeffrey Zhang proposed openstack/kolla stable/ocata: Bump OpenStack Service version https://review.openstack.org/469322 | 04:04 |
*** jaosorior has quit IRC | 04:10 | |
*** lucasxu has quit IRC | 04:11 | |
*** chas has joined #openstack-kolla | 04:11 | |
*** jaosorior has joined #openstack-kolla | 04:13 | |
*** zhurong has joined #openstack-kolla | 04:14 | |
*** chas has quit IRC | 04:15 | |
*** zhurong has quit IRC | 04:19 | |
*** spsurya has joined #openstack-kolla | 04:27 | |
spsurya | morning all | 04:27 |
openstackgerrit | Anthony Lin proposed openstack/kolla-kubernetes master: Remove Kolla Ansible Dependencies on AIO script https://review.openstack.org/469326 | 04:33 |
*** caowei has joined #openstack-kolla | 04:36 | |
*** salv-orlando has joined #openstack-kolla | 04:39 | |
*** caowei has quit IRC | 04:56 | |
*** jamesbenson has quit IRC | 04:57 | |
openstackgerrit | Steve Baker proposed openstack/kolla master: kolla-build log to stderr https://review.openstack.org/469329 | 05:14 |
*** caowei has joined #openstack-kolla | 05:42 | |
*** unicell1 has joined #openstack-kolla | 05:44 | |
*** unicell has quit IRC | 05:45 | |
*** manheim has joined #openstack-kolla | 05:52 | |
*** manheim has quit IRC | 05:56 | |
*** jaosorior has quit IRC | 06:08 | |
*** sgrasley has quit IRC | 06:09 | |
*** caoyuan has quit IRC | 06:11 | |
*** caoyuan has joined #openstack-kolla | 06:13 | |
*** daidv has joined #openstack-kolla | 06:14 | |
*** ducttap__ has joined #openstack-kolla | 06:16 | |
*** jaosorior has joined #openstack-kolla | 06:17 | |
*** ducttape_ has quit IRC | 06:17 | |
*** jascott1 has joined #openstack-kolla | 06:22 | |
*** magicboiz has joined #openstack-kolla | 06:23 | |
*** jascott1 has quit IRC | 06:26 | |
*** caoyuan_ has joined #openstack-kolla | 06:34 | |
*** matrohon has quit IRC | 06:35 | |
*** caoyuan has quit IRC | 06:37 | |
*** skramaja has joined #openstack-kolla | 06:39 | |
*** jamesbenson has joined #openstack-kolla | 06:46 | |
*** jamesbenson has quit IRC | 06:50 | |
*** caoyuan has joined #openstack-kolla | 06:53 | |
*** matrohon has joined #openstack-kolla | 06:54 | |
*** shardy has joined #openstack-kolla | 06:54 | |
*** jascott1 has joined #openstack-kolla | 06:55 | |
*** caoyuan_ has quit IRC | 06:56 | |
masber | good afternoon all, an hour ago I tried to resize an instance which didn't work, then I rebooted the controller node and after that I realized that the fluentd container was having issues http://paste.openstack.org/raw/611050/ apparently it is a permission issue? | 07:02 |
masber | I did kolla-ansible reconfigure -i multinode but that did not fix the isue | 07:02 |
masber | should I do a deploy? | 07:03 |
*** kbyrne has quit IRC | 07:05 | |
*** kbyrne has joined #openstack-kolla | 07:06 | |
*** jascott1 has quit IRC | 07:07 | |
*** unicell has joined #openstack-kolla | 07:08 | |
*** unicell1 has quit IRC | 07:09 | |
*** Serlex has joined #openstack-kolla | 07:10 | |
hawi | hi there. not maybe related to Kolla, I have situation, where security group has all accesses needed but it just doesn't work. kolla/kolla-ansible 4.0.0, no other things have failed so far | 07:12 |
masber | hawi, is the service listening on the instance? | 07:13 |
masber | ssh to the instance and run ss -nolpt and see if the port is listening | 07:14 |
hawi | yes, ssh has been always up, when i have created new machines | 07:14 |
*** caowei_ has joined #openstack-kolla | 07:14 | |
masber | which port are we talking about? | 07:14 |
hawi | though, i cant ssh to instance actually in order to check it | 07:14 |
masber | is the instance up? | 07:14 |
hawi | yes | 07:14 |
hawi | all 12 | 07:14 |
masber | opentack server show <instance name> says that the machine is assigned to the right security port? | 07:15 |
*** caowei has quit IRC | 07:16 | |
*** caowei_ is now known as caowei | 07:16 | |
hawi | | f889d60f-dee6-4a64-ba87-8d36f145de4d | pm-avg-dhost-8 | ACTIVE | net-10.66.27.0=10.66.27.17 | | | 07:17 |
hawi | yes, security_groups | name='new' | 07:18 |
*** jmccarthy has joined #openstack-kolla | 07:18 | |
hawi | masber: https://pastebin.com/bB5ThVKZ | 07:20 |
hawi | and https://pastebin.com/Tep9kDrz | 07:22 |
*** unicell1 has joined #openstack-kolla | 07:24 | |
*** unicell has quit IRC | 07:25 | |
*** pcaruana has joined #openstack-kolla | 07:26 | |
*** korzen has joined #openstack-kolla | 07:27 | |
*** salv-orl_ has joined #openstack-kolla | 07:27 | |
*** salv-orlando has quit IRC | 07:30 | |
*** yangyapeng has joined #openstack-kolla | 07:31 | |
*** egonzalez has joined #openstack-kolla | 07:44 | |
egonzalez | bjolo__, around? | 07:44 |
openstackgerrit | zhubingbing proposed openstack/kolla master: Fix rally create verifier error https://review.openstack.org/467837 | 07:55 |
*** manheim has joined #openstack-kolla | 08:00 | |
*** zhubingbing has joined #openstack-kolla | 08:01 | |
*** reidrac has joined #openstack-kolla | 08:02 | |
*** lpetrut has joined #openstack-kolla | 08:02 | |
*** tvignaud has quit IRC | 08:03 | |
openstackgerrit | Eduardo Gonzalez proposed openstack/kolla-ansible master: DNM: enable port_security by default https://review.openstack.org/469373 | 08:08 |
*** reidrac has quit IRC | 08:12 | |
*** mgoddard has joined #openstack-kolla | 08:13 | |
*** kbyrne has quit IRC | 08:14 | |
*** tvignaud has joined #openstack-kolla | 08:14 | |
*** zhubingbing has quit IRC | 08:16 | |
*** kbyrne has joined #openstack-kolla | 08:17 | |
*** zhubingbing has joined #openstack-kolla | 08:17 | |
*** reidrac has joined #openstack-kolla | 08:21 | |
*** skramaja_ has joined #openstack-kolla | 08:21 | |
*** reidrac has quit IRC | 08:22 | |
*** reidrac has joined #openstack-kolla | 08:23 | |
*** skramaja has quit IRC | 08:23 | |
*** chas has joined #openstack-kolla | 08:24 | |
reidrac | morning, any thoughts on https://review.openstack.org/#/c/469068/ ? | 08:26 |
*** chas has quit IRC | 08:35 | |
*** chas has joined #openstack-kolla | 08:35 | |
*** pbourke has quit IRC | 08:35 | |
*** pbourke has joined #openstack-kolla | 08:36 | |
*** chas has quit IRC | 08:40 | |
*** aolwas has joined #openstack-kolla | 08:41 | |
*** rmart04 has joined #openstack-kolla | 08:43 | |
openstackgerrit | jimmygc proposed openstack/kolla-ansible master: Fix fwaas options https://review.openstack.org/463882 | 08:43 |
*** chas has joined #openstack-kolla | 08:44 | |
*** cristicalin has joined #openstack-kolla | 08:48 | |
*** chas has quit IRC | 08:48 | |
*** cristicalin has quit IRC | 08:50 | |
*** chas has joined #openstack-kolla | 08:50 | |
*** ducttape_ has joined #openstack-kolla | 08:52 | |
*** pbourke_ has joined #openstack-kolla | 08:53 | |
*** klowse1 has joined #openstack-kolla | 08:53 | |
*** rmart04_ has joined #openstack-kolla | 08:53 | |
*** peterjenkins___ has joined #openstack-kolla | 08:54 | |
*** ediardo_ has joined #openstack-kolla | 08:54 | |
*** SaMnCo_ has joined #openstack-kolla | 08:54 | |
*** chas has quit IRC | 08:55 | |
*** strigazi_ has joined #openstack-kolla | 08:56 | |
*** numans_ has joined #openstack-kolla | 09:00 | |
*** dmellado_ has joined #openstack-kolla | 09:00 | |
*** rmart04 has quit IRC | 09:01 | |
*** pbourke has quit IRC | 09:01 | |
*** ducttap__ has quit IRC | 09:01 | |
*** numans has quit IRC | 09:01 | |
*** athomas has quit IRC | 09:01 | |
*** ediardo has quit IRC | 09:01 | |
*** SaMnCo has quit IRC | 09:01 | |
*** peterjenkins__ has quit IRC | 09:01 | |
*** klowse has quit IRC | 09:01 | |
*** dmellado has quit IRC | 09:01 | |
*** strigazi has quit IRC | 09:01 | |
*** jistr has quit IRC | 09:01 | |
*** ediardo_ is now known as ediardo | 09:01 | |
*** SaMnCo_ is now known as SaMnCo | 09:01 | |
*** peterjenkins___ is now known as peterjenkins__ | 09:01 | |
*** rmart04_ is now known as rmart04 | 09:02 | |
*** jistr has joined #openstack-kolla | 09:02 | |
*** skramaja has joined #openstack-kolla | 09:05 | |
*** athomas has joined #openstack-kolla | 09:07 | |
*** skramaja_ has quit IRC | 09:07 | |
openstackgerrit | Eduardo Gonzalez proposed openstack/kolla master: Add e2fsprogs in nova-compute images https://review.openstack.org/469387 | 09:10 |
*** david-lyle has quit IRC | 09:11 | |
*** david-lyle has joined #openstack-kolla | 09:12 | |
*** reidrac has quit IRC | 09:16 | |
*** reidrac has joined #openstack-kolla | 09:17 | |
*** jaosorior is now known as jaosorior_lunch | 09:19 | |
openstackgerrit | Juan Badia Payno proposed openstack/kolla master: WIP - Modified fluentd Image https://review.openstack.org/467219 | 09:19 |
hawi | masber: deleted router networks and project and started it over, now works | 09:20 |
*** cristicalin has joined #openstack-kolla | 09:22 | |
*** masber has quit IRC | 09:23 | |
*** powerd has joined #openstack-kolla | 09:24 | |
*** sambetts|afk is now known as sambetts | 09:44 | |
*** duonghq has quit IRC | 09:45 | |
*** dmellado_ is now known as dmellado | 09:46 | |
*** cristicalin has quit IRC | 09:52 | |
*** tovin07_ has quit IRC | 09:55 | |
*** yingjun has quit IRC | 09:56 | |
zhubingbing | sup sdake | 09:58 |
*** caoyuan has quit IRC | 10:00 | |
spsurya | zhubingbing: sup | 10:00 |
spsurya | I moved to my location | 10:00 |
zhubingbing | hi spsurya | 10:00 |
zhubingbing | what's mean ? spsury | 10:01 |
*** fooliouno has quit IRC | 10:05 | |
*** mnasiadka has joined #openstack-kolla | 10:14 | |
openstackgerrit | Chen proposed openstack/kolla-ansible master: Update deprecated 'play_hosts' with 'ansible_play_batch' https://review.openstack.org/469415 | 10:18 |
spsurya | zhubingbing: i was somewhere else not in my country | 10:19 |
spsurya | since 3 months | 10:20 |
openstackgerrit | Chen proposed openstack/kolla-ansible master: Update deprecated 'play_hosts' with 'ansible_play_batch' https://review.openstack.org/469415 | 10:20 |
openstackgerrit | Eduardo Gonzalez proposed openstack/kolla-ansible master: Bump min Ansible version to 2.2.0 https://review.openstack.org/452067 | 10:21 |
*** cuongnv has quit IRC | 10:27 | |
*** bjolo has joined #openstack-kolla | 10:32 | |
bjolo | howdy | 10:32 |
bjolo | egonzalez, looking for me? | 10:33 |
egonzalez | bjolo, yep, how would you deploy kolla for provider networks? never done that with kolla | 10:33 |
bjolo | just deploy normally | 10:34 |
egonzalez | is regarding the br-ex change, we need a way to ensure neutron_external_network is not needed in compute nodes | 10:34 |
bjolo | when you create your network in neutron, you specify the --shared flag | 10:34 |
bjolo | that way you can deploy a vm directly on the external network. just like vmware, xenserver, proxmox, virtualbox | 10:35 |
bjolo | no router or tenant network needed | 10:35 |
egonzalez | provider networks need more containers in compute nodes | 10:35 |
bjolo | however, every compute node needs to have a nic and br-xxx on that network | 10:36 |
egonzalez | that case is not real provider network, is associating public IPs to instances directly, traffic still will go through network node | 10:36 |
bjolo | (well technically not every compute, since this could be a routed provider network. i.e. only a subset of compute have a br on one particular segment) | 10:36 |
bjolo | there is no floating IP, your fixed IP is in the public range | 10:37 |
bjolo | let me give you a screenshot | 10:37 |
egonzalez | yep, but to create real provider networks need dhcp and metadata agent on each compute https://docs.openstack.org/draft/networking-guide/deploy-ovs-provider.html#architecture | 10:38 |
*** jaosorior_lunch is now known as jaosorior | 10:41 | |
bjolo | na dont think so | 10:41 |
bjolo | if you read the docs it says dhcp/meta can be on any host | 10:41 |
*** chas has joined #openstack-kolla | 10:42 | |
*** shardy has quit IRC | 10:44 | |
egonzalez | right, then we have a problem, or br-ex is always created even when provider networks not exists (all computes need neutron_external_interface) or providers networks are not supported | 10:44 |
bjolo | thats my take on it | 10:44 |
bjolo | if we dont configure br-ex (and there can be more than one external right) we can not configure provider networks at all | 10:45 |
*** zhubingbing has quit IRC | 10:45 | |
bjolo | you wanna try? | 10:45 |
bjolo | i can give you access to our external cloud wich have provider network | 10:46 |
bjolo | when i tcpdump ping traffic on the br-ex interface, i can see the traffic going in/out directly to compute node | 10:47 |
*** chas has quit IRC | 10:47 | |
bjolo | is sean-k-mooney around? he is neutron developer right? | 10:47 |
*** chas has joined #openstack-kolla | 10:49 | |
bjolo | egonzalez, http://paste.openstack.org/show/611078/ | 10:51 |
*** daidv has quit IRC | 10:51 | |
*** chas has quit IRC | 10:53 | |
bjolo | i guess we can configure provider networks still w/o br-ex on compute, but whenever you try to deploy a vm nova will fail with something like "no valid host found" | 10:55 |
bjolo | im not an neutron expert but i think we need to revert both of these patches | 10:55 |
*** chas has joined #openstack-kolla | 10:55 | |
bjolo | if one really desires to not have br-ex on compute it should probably be a config option in that case | 10:56 |
egonzalez | bjolo, actually i'm testing deploying without external interface in compute reverting both changes | 10:58 |
*** caowei has quit IRC | 10:58 | |
bjolo | one thing that really makes this more complicated going forwar is routed provider networks | 10:58 |
bjolo | https://docs.openstack.org/newton/networking-guide/config-routed-networks.html | 10:58 |
*** salv-orl_ has quit IRC | 10:59 | |
bjolo | i.e. one network foo, with multiple subnets&segments sub1, sub2, etc | 10:59 |
bjolo | however sub1 only exist in rack A, and sub2 only exist in rack B for ex | 10:59 |
*** chas has quit IRC | 10:59 | |
bjolo | br-ex-sub1 should only be on nodes in rack A | 11:00 |
bjolo | br-ex-sub2 should only be on nodes in rack B | 11:00 |
bjolo | afk meeting | 11:00 |
bjolo | said this before, i wish to have inventory groups as targets | 11:01 |
bjolo | [compute] | 11:01 |
bjolo | rack! | 11:01 |
bjolo | rackA | 11:01 |
bjolo | rackB | 11:01 |
bjolo | and then i should be able to have /etc/kolla/config/rackA/neutron.conf | 11:02 |
bjolo | wrote a blueprint for that a while back | 11:03 |
bjolo | ok AFK! boss is calling :) | 11:03 |
openstackgerrit | Sam Betts proposed openstack/kolla-kubernetes master: Fix mistake in ironic-inspector config sed command https://review.openstack.org/469429 | 11:03 |
*** cristicalin has joined #openstack-kolla | 11:06 | |
openstackgerrit | Sam Betts proposed openstack/kolla-kubernetes master: Fix mistake in ironic-inspector config updater init https://review.openstack.org/469429 | 11:11 |
*** dave-mccowan has joined #openstack-kolla | 11:12 | |
egonzalez | bjolo, just tested the revert and works fine, the only thing is that ovs reports | 11:18 |
egonzalez | Bridge br-ex | 11:18 |
egonzalez | Controller "tcp:127.0.0.1:6633" | 11:18 |
egonzalez | is_connected: true | 11:18 |
egonzalez | fail_mode: secure | 11:18 |
egonzalez | Port fakeint | 11:18 |
egonzalez | Interface fakeint | 11:18 |
*** pradk has joined #openstack-kolla | 11:18 | |
egonzalez | error: "could not open network device fakeint (No such device)" | 11:18 |
egonzalez | but not make any issue in networking | 11:19 |
*** kbyrne has quit IRC | 11:23 | |
*** rwallner has joined #openstack-kolla | 11:23 | |
openstackgerrit | Eduardo Gonzalez proposed openstack/kolla-ansible master: Revert "Don't configure external bridge on computes if DVR is disabled" https://review.openstack.org/469439 | 11:25 |
*** mnasiadka has quit IRC | 11:29 | |
*** mnasiadka has joined #openstack-kolla | 11:29 | |
manheim | I can deploy kilo with kolla, right? | 11:37 |
*** mnasiadka has quit IRC | 11:38 | |
*** rwallner has quit IRC | 11:40 | |
*** rwallner has joined #openstack-kolla | 11:41 | |
reidrac | manheim: checkout the kilo-eol tag in kolla repo perhaps? | 11:44 |
bjolo | manheim, why? :) | 11:45 |
manheim | need to test something for a kilo deployment | 11:45 |
manheim | and I need a kilo test env | 11:46 |
*** rwallner has quit IRC | 11:46 | |
*** rwallner has joined #openstack-kolla | 11:47 | |
*** mnasiadka has joined #openstack-kolla | 11:47 | |
*** manheim has quit IRC | 11:50 | |
*** manheim has joined #openstack-kolla | 11:50 | |
*** manheim has quit IRC | 11:55 | |
*** manheim has joined #openstack-kolla | 12:02 | |
*** kbaegis has joined #openstack-kolla | 12:05 | |
*** kbaegis has quit IRC | 12:05 | |
*** kbaegis has joined #openstack-kolla | 12:06 | |
*** kbaegis has quit IRC | 12:06 | |
*** kbaegis has joined #openstack-kolla | 12:06 | |
*** kbaegis has quit IRC | 12:06 | |
*** kbaegis has joined #openstack-kolla | 12:07 | |
*** kbaegis has quit IRC | 12:07 | |
*** kbaegis has joined #openstack-kolla | 12:07 | |
*** kbyrne has joined #openstack-kolla | 12:08 | |
*** manheim has quit IRC | 12:10 | |
*** zhubingbing has joined #openstack-kolla | 12:22 | |
kbaegis | eureka! | 12:23 |
kbaegis | works using global ansible (from portage), python2.7 venv source and target | 12:26 |
*** janki has quit IRC | 12:26 | |
*** manheim has joined #openstack-kolla | 12:29 | |
*** rwallner has quit IRC | 12:30 | |
*** rwallner has joined #openstack-kolla | 12:31 | |
openstackgerrit | Juan J. MartÃnez proposed openstack/kolla-ansible master: Fix vagrant development environment https://review.openstack.org/469068 | 12:38 |
*** zhubingbing_ has joined #openstack-kolla | 12:40 | |
*** zhubingbing has quit IRC | 12:41 | |
*** rwellum has joined #openstack-kolla | 12:42 | |
*** chas has joined #openstack-kolla | 12:42 | |
*** chas_ has joined #openstack-kolla | 12:47 | |
*** chas has quit IRC | 12:47 | |
*** mnasiadka has quit IRC | 12:47 | |
*** athomas has quit IRC | 12:48 | |
*** athomas has joined #openstack-kolla | 12:49 | |
Reepicheep | kbaegis: nice job | 12:50 |
openstackgerrit | Andy Smith proposed openstack/kolla-ansible master: Add qdrouterd role for messaging infrastructure component https://review.openstack.org/469462 | 12:51 |
*** chas_ has quit IRC | 12:52 | |
*** ansmith has joined #openstack-kolla | 12:54 | |
*** goldyfruit has joined #openstack-kolla | 12:58 | |
egonzalez | reidrac, added a few comments in the review | 13:04 |
*** chas has joined #openstack-kolla | 13:05 | |
*** goldyfruit has quit IRC | 13:07 | |
*** cristicalin has quit IRC | 13:07 | |
*** goldyfruit has joined #openstack-kolla | 13:08 | |
*** lucasxu has joined #openstack-kolla | 13:11 | |
*** chas has quit IRC | 13:14 | |
*** strigazi_ is now known as strigazi | 13:15 | |
openstackgerrit | Tim Rozet proposed openstack/kolla master: Adds opendaylight specific neutron-server container https://review.openstack.org/467712 | 13:15 |
openstackgerrit | Tim Rozet proposed openstack/kolla master: Adds opendaylight specific neutron-server container https://review.openstack.org/467712 | 13:16 |
*** chas has joined #openstack-kolla | 13:17 | |
*** eanylin has quit IRC | 13:19 | |
openstackgerrit | Juan J. MartÃnez proposed openstack/kolla-ansible master: Fix vagrant development environment https://review.openstack.org/469068 | 13:19 |
*** chas has quit IRC | 13:20 | |
*** zhubingbing_ has quit IRC | 13:20 | |
*** bjolo has quit IRC | 13:21 | |
reidrac | egonzalez: thanks a lot; replied and updated the PR | 13:24 |
reidrac | egonzalez: some of your comments are out of scope of the fix for bug 1693847; but I can make a new PR to correct those | 13:24 |
openstack | bug 1693847 in kolla "Vagrant development env broken after repo split" [Medium,In progress] https://launchpad.net/bugs/1693847 - Assigned to Juan J. MartÃnez (jjmartinez) | 13:24 |
reidrac | egonzalez: as the end what I want is a sane dev envrionment with vagrant | 13:24 |
*** rwallner has quit IRC | 13:28 | |
openstackgerrit | Tim Rozet proposed openstack/kolla master: Adds opendaylight specific neutron-server container https://review.openstack.org/467712 | 13:31 |
*** eanylin has joined #openstack-kolla | 13:34 | |
openstackgerrit | Sam Betts proposed openstack/kolla-kubernetes master: Allow overriding images for ironic pods with multiple containers https://review.openstack.org/469483 | 13:34 |
sdake | morning peeps | 13:40 |
*** blallau has joined #openstack-kolla | 13:40 | |
*** zhurong has joined #openstack-kolla | 13:41 | |
egonzalez | sdake, morning | 13:42 |
sdake | egonzalez any progress on the neutron bug | 13:42 |
sdake | egonzalez its blocking the entire kolla gate | 13:42 |
egonzalez | was thinking about the mariadb for stable/ocata, and think we cannot upgrade in ocata to 10.1 as is a major change, fix to ocata would be pin to 10.0.30 and remove pin once 10.0 mariadb-galera-server is fixed | 13:43 |
sdake | egonzalez i'm good with a backport of that change | 13:43 |
*** cristicalin has joined #openstack-kolla | 13:43 | |
egonzalez | sdake, this fixes gates https://review.openstack.org/#/c/469373/ | 13:43 |
sdake | egonzalez although for master, i want it fixed | 13:43 |
egonzalez | but, not sure about enabling port_security in already existing environments | 13:43 |
sdake | egonzalez agreement then? | 13:43 |
egonzalez | asked but nobody answer about that | 13:44 |
*** jtriley has joined #openstack-kolla | 13:44 | |
*** rmart04_ has joined #openstack-kolla | 13:44 | |
egonzalez | tried locally and broke all my existing networks | 13:44 |
*** rmart04 has quit IRC | 13:45 | |
*** rmart04_ is now known as rmart04 | 13:45 | |
sdake | i am asking internally | 13:46 |
*** krtaylor has quit IRC | 13:46 | |
sdake | cisco should know what that does :) | 13:46 |
*** sgrasley has joined #openstack-kolla | 13:46 | |
sdake | egonzalez do we have agreement then about a path forward for mariadb? | 13:48 |
sdake | @egonzalez "sambetts | 13:48 |
sdake | [6:48 AM] | 13:48 |
sdake | @stdake it enables the port security extension for neutron which provides use of security groups for controlling traffic in your neutron environment, e.g. ingress and egress rules etc" | 13:48 |
egonzalez | sdake, yep, although I would like that some mariadb expert adds an opinion | 13:49 |
sdake | egonzalez here is the general mariadb proposal: | 13:49 |
sdake | 1. pin stable/ocata to 10.0.30 | 13:49 |
sdake | 2. rework master to use rdo | 13:49 |
sdake | 3. this gives us 3+ mtnhs of testing with mariadb's versions | 13:50 |
sdake | rather rdo's versions | 13:50 |
sdake | 1 doesn't require any expert opinoin - it is what we were already shipping | 13:51 |
sdake | 2 requires probalby a proper rework of that extend_start script - my solution is sort of hacky and also requires multinode testing (which I didn't do) | 13:51 |
sdake | dmsimard ping re removal of epel from kolla | 13:52 |
egonzalez | will do a multinode test now | 13:52 |
sdake | with my patch? | 13:52 |
sdake | or wit hthe pin? | 13:52 |
*** rwallner has joined #openstack-kolla | 13:52 | |
sdake | we shoud probably do a multinode test with the pin as well | 13:52 |
sdake | i am on vacation and dont' have access to my lab | 13:53 |
sdake | or i'd do it myself | 13:53 |
egonzalez | with the pin is what we are already doing, at least I'm testing with multinodes for the last 2 months, will test with your patch | 13:54 |
*** krtaylor has joined #openstack-kolla | 13:54 | |
*** krtaylor has quit IRC | 13:55 | |
sambetts | sdake, egonzalez: do you have a link to a patch thats failing because of the neutron issue?? | 13:57 |
sambetts | I'd like to take a look at the traceback | 13:57 |
sdake | sambetts moment | 13:57 |
sdake | sambetts somewhere in this mess of logs: http://logs.openstack.org/83/469183/1/check/gate-kolla-dsvm-deploy-centos-source-centos-7-nv/aefdec3/console.html#_2017-05-31_00_09_43_335544 | 13:58 |
sdake | sambetts there may or may not be a backtrace, I am just not sure | 13:58 |
*** rmart04 has quit IRC | 13:58 | |
sdake | egonzalez cool - so the pin si good - i'll backpor tthat now | 13:59 |
sdake | looks like it was already cherrypicked | 14:01 |
sdake | and merged | 14:01 |
sdake | egonzalez can you apply a +2 to this cherrypick please: https://review.openstack.org/#/c/468655/1 | 14:02 |
*** rmart04 has joined #openstack-kolla | 14:02 | |
*** esmiurium has quit IRC | 14:02 | |
sdake | sambetts here is the review where master of kolla craters (it is just a gatecheck:) https://review.openstack.org/#/c/469183/ | 14:03 |
sdake | sambetts https://bugs.launchpad.net/kolla/+bug/1694420/ | 14:05 |
openstack | Launchpad bug 1694420 in neutron "AttributeError: 'NoneType' object has no attribute 'port_security_enabled" [High,In progress] - Assigned to Kevin Benton (kevinbenton) | 14:05 |
egonzalez | sambetts, http://logs.openstack.org/83/469183/1/check/gate-kolla-dsvm-deploy-centos-source-centos-7-nv/aefdec3/logs/kolla/neutron/neutron-openvswitch-agent.txt.gz | 14:05 |
sdake | egonzalez thanks | 14:05 |
sambetts | egonzalez: qq which version of OpenStack are you running? Newton or Ocata? | 14:06 |
egonzalez | master | 14:06 |
sambetts | egonzalez: I know there was a bug a release or so ago which was exactly that issue thats why I ask, I'm pretty certain it was fixed in more recent releases | 14:08 |
egonzalez | adding port_security to neutron extensions fixes the issue | 14:08 |
egonzalez | sambetts, started failing 1-2 days ago | 14:09 |
sambetts | correct, the bug before was that nova assumed that the port security extension was always available | 14:10 |
*** caoyuan has joined #openstack-kolla | 14:10 | |
*** salv-orlando has joined #openstack-kolla | 14:10 | |
sambetts | egonzalez: I'm surprised that enabling port_security by default causes problems with your existing networks, what failures do you see? | 14:11 |
egonzalez | sambetts, instances on existing networks didn't get dhcp and also floatingip didnt work, new networks worked fine. will try to run into that issue again and let you know | 14:13 |
*** manheim has quit IRC | 14:14 | |
egonzalez | sambetts, by default I mean, deploy without port_security, enable port_security and restart services(or upgrade). fresh deploys works fine | 14:15 |
sdake | egonzalez does the bug have that information? | 14:16 |
sdake | egonzalez perhaps the neutron peeps don't understand the full reach of the issue (its an upgrade problem) | 14:16 |
*** Pavo has joined #openstack-kolla | 14:17 | |
egonzalez | nope, the bug happen in fresh installs without port_security, this is another issue imo, will gather info and open a new bug if so, maybe was my side issue | 14:20 |
openstackgerrit | Vladislav Belogrudov proposed openstack/kolla-ansible master: Add possibility to configure tenant network types https://review.openstack.org/469511 | 14:24 |
*** hongbin has joined #openstack-kolla | 14:25 | |
*** caoyuan has quit IRC | 14:30 | |
*** zhurong has quit IRC | 14:35 | |
openstackgerrit | Sam Betts proposed openstack/kolla-kubernetes master: Allow overriding images for ironic pods with multiple containers https://review.openstack.org/469483 | 14:40 |
*** kfir has joined #openstack-kolla | 14:43 | |
*** mnasiadka has joined #openstack-kolla | 14:44 | |
*** caoyuan has joined #openstack-kolla | 14:44 | |
kfir | I was following the kolla-ansible dev env guide (https://docs.openstack.org/developer/kolla-ansible/vagrant-dev-env.html). And got up to the point of running `kolla-build` in the operator VM. After that the guide instructs calling `kolla-ansible` which isn't available on the VM. What am I missing here? | 14:45 |
*** chas has joined #openstack-kolla | 14:46 | |
*** manheim has joined #openstack-kolla | 14:48 | |
openstackgerrit | Steven Dake proposed openstack/kolla-kubernetes master: Change ordering of PV retrieval https://review.openstack.org/469522 | 14:48 |
*** cristicalin has quit IRC | 14:49 | |
inc0 | good morning | 14:49 |
*** eaguilar has joined #openstack-kolla | 14:50 | |
sdake | sup inc0 | 14:50 |
sdake | kfir there is a patch in the queue to fix vagrant, although it is as yet unmerged - i'd suggest cherrypicking it or not using vagrant | 14:50 |
*** chas has quit IRC | 14:50 | |
*** manheim has quit IRC | 14:52 | |
kfir | anyone can help me finding the patch that @sdake was referring to? | 14:54 |
sdake | egonzalez i don't have kolla under my watched projects - any chance you can help kfir find the appropriate patch | 14:54 |
*** sgrasley has quit IRC | 14:54 | |
egonzalez | sure, kfir https://review.openstack.org/#/c/469068/ | 14:55 |
egonzalez | kfir, let me know if that fixes your issue | 14:55 |
sdake | inc0 re mariadb | 14:56 |
sdake | inc0 our plan of action is to backport sean's pin to ocata, and use mariadb from rdo going forward | 14:56 |
sdake | inc0 any objections? | 14:57 |
openstackgerrit | Vladislav Belogrudov proposed openstack/kolla-ansible master: Add flag to allow provider networks https://review.openstack.org/469529 | 14:57 |
inc0 | sdake: versions are relatively modern? | 14:57 |
sdake | inc0 i dont grok the quetion - could you be more specific please | 14:57 |
sdake | mariadb in rdo includes galera and percona | 14:58 |
inc0 | when we switched to canonical repos for ubuntu | 14:58 |
sdake | so we can eject those two repos for the centos case | 14:58 |
inc0 | xtrabackup was in some ancient version which broke multinode | 14:58 |
inc0 | I expect rdo to be more...cared for | 14:59 |
egonzalez | sambetts, here is a workflow where it fails http://paste.openstack.org/show/611109/ | 14:59 |
sdake | me too, although I can't verify an answer to the question as I am on vacation - egonzales is testing | 14:59 |
egonzalez | sambetts, deploy master without port_security, create networks, enable port security, create instance(not get dhcp), create new network and instance(get dhcp) | 15:00 |
kfir | egonzalez: If I understood correctly what I need to do was to cherry-pick the hash you suggested (8fe43171ce44631988844e2d63b2474a4938c437) onto master branch at kolla repo correct? | 15:00 |
kfir | because I'm getting fatal: bad object 8fe43171ce44631988844e2d63b2474a4938c437 | 15:01 |
egonzalez | sambetts, let me know what more info can i provide, i have this env running atm | 15:01 |
egonzalez | kfir, the change is not merged and not in the git tree, can checkout or pull from gerrit git fetch https://git.openstack.org/openstack/kolla-ansible refs/changes/68/469068/3 && git checkout FETCH_HEAD | 15:01 |
inc0 | egonzalez: neutron is still broken? | 15:02 |
openstackgerrit | Vladislav Belogrudov proposed openstack/kolla-ansible master: Add flag to allow provider networks https://review.openstack.org/469529 | 15:03 |
openstackgerrit | Vladislav Belogrudov proposed openstack/kolla-ansible master: Add flag to allow provider networks https://review.openstack.org/469529 | 15:03 |
egonzalez | inc0, neutron patch still under review, a fix is enabling port_security extension, but having issues enabling with existing networks | 15:04 |
*** jamesbenson has joined #openstack-kolla | 15:04 | |
*** ducttape_ has quit IRC | 15:04 | |
*** ducttape_ has joined #openstack-kolla | 15:05 | |
sdake | inc0 if you read doug's resolution carefully yo uwill see it requires a manifest in the containers | 15:05 |
inc0 | sdake: I know, I was working with him on this doc | 15:06 |
inc0 | manifest is required, I agree | 15:06 |
kfir | egonzalez: Now vagrant up failed. Something with mount.nfs (https://pastebin.com/6M8kHnSy) | 15:07 |
egonzalez | inc0, neutron patch is being merged atm, will let you know once is ready to recheck changes | 15:07 |
inc0 | egonzalez: thanks | 15:07 |
inc0 | at least we tested failure scenerio for multinode patchset;) | 15:07 |
*** manheim has joined #openstack-kolla | 15:08 | |
sdake | inc0 read my last comment on doug's review | 15:10 |
*** manheim has quit IRC | 15:12 | |
inc0 | good point sdake | 15:13 |
inc0 | although frankly? I'd be ok with removing and re-uploading ocata images | 15:14 |
sambetts | egonzalez: can you try toggling port security on and off your existing networks? I think you can do something like neutron net-update <uuid> --port-security-enabled=True / False | 15:14 |
inc0 | but right, we won't have manifest there too | 15:14 |
sdake | ya the backport restrctions are a problem | 15:14 |
sdake | if we could get the stable team to budge on that policy related to manifests, taht would be a suitable outcome as well | 15:15 |
*** sgrasley has joined #openstack-kolla | 15:15 | |
inc0 | technically we don't have this tag yet https://review.openstack.org/#/c/346455/ | 15:15 |
sdake | btw the stable maintainer was hired by red hat - might send a note to hte ml asking for a revisit of the stable policy | 15:15 |
sdake | inc0 right- but if we violate it, we wont get it for another 2 releases | 15:15 |
sdake | and we have been follwing it for 2 years.. | 15:15 |
inc0 | I know | 15:15 |
egonzalez | sambetts, conflicts because port have a security group associated with | 15:15 |
inc0 | one alternative would be to create external tool to inject it to container | 15:16 |
inc0 | that would actually make sense since we could use metadata of container instead of file in it | 15:17 |
sambetts | egonzalez: you can toggle it on the specific ports too, neutron port-update <uuid> then the same parameter | 15:17 |
kbaegis | Morning all | 15:17 |
kbaegis | egonzalez inc0 sdake thanks for all your help | 15:17 |
egonzalez | sambetts, conflict was against a port, in network worked, going try if works | 15:18 |
inc0 | that would allow us to retroactively add this stuff and refresh ocata images with it | 15:18 |
inc0 | kbaegis: you managed to get it up? | 15:18 |
kbaegis | So gentoo works with kolla-ansible in a venv 2.7 (target/host), ansible removed from the venv and 2.3.0.0 installed via portag | 15:18 |
*** klindgren_ has joined #openstack-kolla | 15:18 | |
kbaegis | ansible inside the venv, particularly 2.0 does not work | 15:18 |
sdake | klindgren_ you said you have manifest code - mind submitting it? klindgren ^^ | 15:19 |
inc0 | oh fun | 15:19 |
kbaegis | but yes, working on gentoo; now decoupled from ubuntu/centos upstream | 15:19 |
kbaegis | And, in my case, systemd too | 15:19 |
inc0 | we had sth like it written by kfox too | 15:19 |
inc0 | kbaegis: woot | 15:19 |
kbaegis | floatingips, designate, cinder and nova all rigorously tested | 15:19 |
inc0 | lol, that would make quite a blogpost;) | 15:20 |
egonzalez | sambetts, nope, didn't work, instance still without getting dhcp, port_security cannot be removed with a security group associated | 15:20 |
kbaegis | inc0: Now that I understand the actual problem. | 15:20 |
kbaegis | :) | 15:20 |
inc0 | we might be only deployment tool (besides devstack) that works on gentoo;) | 15:20 |
*** klindgren has quit IRC | 15:20 | |
sdake | insert obligatory gentoo joke here :) | 15:20 |
sambetts | egonzalez: interesting that the existing networks automatically get the (I assume) default security group associated with them | 15:21 |
kfir | egonzalez: Ended up trying to clone kolla-ansible repo as well and run vagrant up from there (saw this in the diff from the suggested patch). will update if that works once the setup is up | 15:21 |
*** iniazi_ has joined #openstack-kolla | 15:21 | |
inc0 | sdake: we had a lot of it already;) let's leave kbaegis alone and just marvel at his bravery | 15:21 |
sdake | inc0 ya - just joking around :) | 15:21 |
sdake | iirc kbaegis had gentoo working prior | 15:21 |
kbaegis | sdake: Yeah, but I had done it improperly | 15:22 |
kbaegis | sdake: pip and portage don't like eachother | 15:22 |
sdake | kbaegis fair enough - hope to see some docs :) | 15:22 |
kbaegis | sdake: Doing it right needs a venv, which I've set up | 15:22 |
egonzalez | sambetts, once port_security extension is enabled, existing ports are updated with port_security_enabled true, but network not work. not sure why because i cannot find any error message | 15:23 |
*** iniazi has quit IRC | 15:23 | |
kfir | egonzalez, in the operator vm now kolla-ansible is available but kolla-build is not and looks like some container images are missing... | 15:25 |
*** TxGirlGeek has joined #openstack-kolla | 15:26 | |
egonzalez | kfir, yep, that's what the change is doing, installing also kolla | 15:26 |
egonzalez | kfir, you can simply git clone kolla repo and install it | 15:26 |
*** korzen has quit IRC | 15:27 | |
kfir | egonzalez, inside the VM the I get from the kolla-ansible vagrant up? | 15:27 |
sambetts | egonzalez: port security rules are normally applied using iptables, there are special rules they put in place for neutron DHCP so that it isn't blocked by the security group rules, my guess is that those special rules only get applied at port create/binding time for the DHCP agent which isn't retriggered for existing networks | 15:27 |
*** mnasiadka has quit IRC | 15:27 | |
*** jascott1 has joined #openstack-kolla | 15:28 | |
sambetts | egonzalez: if thats the case then disabling DHCP on the subnet and then re-enabling it would remove and then readd the DHCP port | 15:28 |
sambetts | and apply the rules | 15:28 |
egonzalez | let me try | 15:29 |
sambetts | egonzalez: BTW which services did you restart when you changed the neutron config#? | 15:30 |
*** krtaylor has joined #openstack-kolla | 15:30 | |
egonzalez | sambetts, all | 15:30 |
egonzalez | sambetts, disabling dhcp and enabling again worked , yay! | 15:30 |
sambetts | \o/ | 15:30 |
sambetts | the port binding event must be the trigger to apply those rules | 15:31 |
egonzalez | sambetts, should I open a bug in neutron? | 15:31 |
*** mnasiadka has joined #openstack-kolla | 15:32 | |
*** dciabrin has quit IRC | 15:32 | |
sambetts | hmm I'm not sure how to word the bug, something like "port security rules only applied at port binding/creation time, so when port security is enabled in the config existing ports don't have their rules applied" ? | 15:33 |
*** skramaja has quit IRC | 15:33 | |
klindgren_ | sdake, sorry need more context. | 15:34 |
openstackgerrit | Sam Betts proposed openstack/kolla-kubernetes master: Allow overriding images for ironic pods with multiple containers https://review.openstack.org/469483 | 15:34 |
sdake | klindgren_ please review: https://review.openstack.org/#/c/469265/2 | 15:34 |
egonzalez | sambetts, will do tomorrow and retrieve iptables rules to provide more information. need to deploy fresh again. Thanks for the help! | 15:34 |
sdake | klindgren_ we want to meet the manifest requirements in kolla images | 15:34 |
sambetts | egonzalez: No problem :) | 15:35 |
sdake | i saw harlowja had written some code (or you did) to make it work in your internal work in godaddy | 15:35 |
sdake | klindgren_ there was a ml post on the topic with output included | 15:35 |
sdake | klindgren_ several months ago | 15:35 |
openstackgerrit | Vladislav Belogrudov proposed openstack/kolla-ansible master: Allow external MongoDB cluster for Ceilometer https://review.openstack.org/456908 | 15:35 |
*** mnasiadka has quit IRC | 15:36 | |
*** jascott1 has quit IRC | 15:37 | |
*** jamesPR has joined #openstack-kolla | 15:37 | |
klindgren_ | ah let me see what I can find - Josh did most of that work. I think most of it was done via jenkins though. | 15:37 |
jamesPR | sup everyone ;) | 15:38 |
*** jascott1 has joined #openstack-kolla | 15:38 | |
*** caoyuan has quit IRC | 15:38 | |
egonzalez | rwellum, sup, saw added cells as meeting agenda | 15:39 |
*** jascott1 has quit IRC | 15:42 | |
*** jascott1 has joined #openstack-kolla | 15:42 | |
*** mnasiadka has joined #openstack-kolla | 15:42 | |
*** rwallner has quit IRC | 15:42 | |
*** rwallner has joined #openstack-kolla | 15:43 | |
*** duonghq has joined #openstack-kolla | 15:44 | |
duonghq | evening guys | 15:44 |
*** matrohon has quit IRC | 15:44 | |
*** dciabrin has joined #openstack-kolla | 15:44 | |
dciabrin | hey rasca: | 15:45 |
dciabrin | rasca: we have a super-duper-plan-C | 15:45 |
dciabrin | rasca: we're just gonna use bandini's script to deploy amupstream/master on had-05. okay for you? I think we have all we need | 15:45 |
*** jascott1 has quit IRC | 15:46 | |
inc0 | sounds like a code dciabrin | 15:46 |
inc0 | ;) | 15:46 |
dciabrin | inc0, oops | 15:47 |
* dciabrin is embarrassed now :) | 15:47 | |
*** mnasiadka has quit IRC | 15:47 | |
inc0 | no worries, happened to me more than once | 15:47 |
sdake | sup duonghq | 15:47 |
*** lpetrut has quit IRC | 15:47 | |
duonghq | hi sdake | 15:48 |
*** jascott1 has joined #openstack-kolla | 15:48 | |
sdake | sup jascott1 | 15:49 |
*** jascott1 has quit IRC | 15:51 | |
*** jascott1 has joined #openstack-kolla | 15:51 | |
jascott1 | sdake yo mang! | 15:52 |
sdake | jascott1 living the dream dude? | 15:52 |
sdake | jascott1 didy ou see my destroy patch merged :) | 15:53 |
jascott1 | i saw the +2's were a flyin | 15:53 |
sdake | (after 51 iterations) | 15:53 |
jascott1 | haha | 15:53 |
sdake | now for a "deploy.yml" :) | 15:54 |
inc0 | 51 iterations...thats cute | 15:54 |
inc0 | https://review.openstack.org/#/c/466007/ | 15:55 |
jascott1 | sdake I have broken the playbook into deploy-k8s and deploy-kolla | 15:55 |
inc0 | meeting in 5 | 15:56 |
sdake | egonzalez any idea why https://review.openstack.org/#/c/468655/1 gate fails? | 15:56 |
rwellum | egonzalez: yes I did - is that ok? | 15:58 |
egonzalez | rwellum, yep | 15:58 |
*** rmart04 has quit IRC | 15:58 | |
*** rmart04 has joined #openstack-kolla | 15:58 | |
*** rmart04 has quit IRC | 16:04 | |
egonzalez | sdake, mysql_install_db command is provided by MariaDB-Galera-server package which is not being installed atm in ocata due missing package | 16:05 |
sdake | egonzalez that is stable/ocata - and the ocata branch hasa cherrypick of sean mooney's pin | 16:06 |
*** david-lyle has quit IRC | 16:06 | |
egonzalez | sdake, cherry-pick but not merged yet https://review.openstack.org/#/c/468454/ | 16:06 |
sdake | egonzalez can you ack it then :) | 16:08 |
egonzalez | sdake, can i do it if i'm the commiter of a cherry-pick ? | 16:09 |
sdake | inc0 Jeffrey4l can you ack the above review plz | 16:09 |
sdake | egonzalez didn't see that sorry :) | 16:09 |
Jeffrey4l | done. | 16:10 |
*** mnasiadka has joined #openstack-kolla | 16:10 | |
sdake | thanks Jeffrey4l | 16:11 |
Jeffrey4l | np. | 16:12 |
*** david-lyle has joined #openstack-kolla | 16:14 | |
*** mnasiadka has quit IRC | 16:14 | |
*** eaguilar has quit IRC | 16:18 | |
*** kbaegis1 has joined #openstack-kolla | 16:18 | |
*** kbaegis has quit IRC | 16:18 | |
openstackgerrit | Merged openstack/kolla-kubernetes master: Fix mistake in ironic-inspector config updater init https://review.openstack.org/469429 | 16:24 |
*** chas has joined #openstack-kolla | 16:27 | |
*** chas has quit IRC | 16:31 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/kolla master: Updated from global requirements https://review.openstack.org/469567 | 16:37 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/kolla-ansible master: Updated from global requirements https://review.openstack.org/469568 | 16:37 |
*** rwallner has quit IRC | 16:38 | |
openstackgerrit | Eduardo Gonzalez proposed openstack/kolla master: Revert "pin mariadb version for rpm distros" https://review.openstack.org/467729 | 16:42 |
*** sambetts is now known as sambetts|afk | 16:42 | |
*** sayantan_ has joined #openstack-kolla | 16:45 | |
*** daidv has joined #openstack-kolla | 16:45 | |
openstackgerrit | Steven Dake proposed openstack/kolla master: Revert "pin mariadb version for rpm distros" https://review.openstack.org/469583 | 16:46 |
openstackgerrit | Tim Rozet proposed openstack/kolla master: Adds opendaylight specific neutron-server container https://review.openstack.org/467712 | 16:48 |
*** eaguilar has joined #openstack-kolla | 16:49 | |
harlowja | sdake klindgren_ what i do | 16:50 |
harlowja | lol | 16:50 |
*** pcaruana has quit IRC | 16:50 | |
klindgren_ | The json file that we dump into files that link it to the build system | 16:51 |
*** eaguilar has quit IRC | 16:53 | |
*** rwallner has joined #openstack-kolla | 16:55 | |
*** salv-orlando has quit IRC | 16:55 | |
*** mgoddard has quit IRC | 16:57 | |
egonzalez | duonghq, thanks for that helpful information :) | 16:57 |
duonghq | inc0, can you make decission for osprofiler bp? | 16:57 |
*** rwallner has quit IRC | 16:58 | |
duonghq | egonzalez, thanks for write down the bp and implementation | 16:58 |
*** daidv has quit IRC | 16:59 | |
inc0 | duonghq: frankly I don't know problem well enough | 16:59 |
inc0 | just do what you feel is best | 16:59 |
*** daidv has joined #openstack-kolla | 16:59 | |
duonghq | inc0, :P | 16:59 |
inc0 | :D | 16:59 |
*** hieulq_ has joined #openstack-kolla | 16:59 | |
inc0 | bbiaf, food and moving to office;) | 16:59 |
*** unicell1 has quit IRC | 16:59 | |
duonghq | inc0, cya | 17:00 |
duonghq | egonzalez, can you mark the bp as started? | 17:00 |
egonzalez | duonghq, done | 17:01 |
rwellum | Can someone help me find the commit that moved the nova micro-services into a service chart? Or show me how to search correctly? | 17:01 |
duonghq | egonzalez, nice, very interesting bp | 17:01 |
duonghq | egonzalez, should we target it to pike? | 17:02 |
*** rwallner has joined #openstack-kolla | 17:02 | |
egonzalez | duonghq, yeah, probably lands for pike, is an easy change to review | 17:03 |
duonghq | :D | 17:03 |
duonghq | I need sleep, see you later egonzalez | 17:04 |
egonzalez | see ya duonghq ! | 17:04 |
*** duonghq has quit IRC | 17:04 | |
*** hieulq__ has joined #openstack-kolla | 17:04 | |
*** hieulq_ has quit IRC | 17:08 | |
*** egonzalez has quit IRC | 17:09 | |
*** Pavo has quit IRC | 17:11 | |
*** eaguilar has joined #openstack-kolla | 17:14 | |
*** kolla-slack1 has quit IRC | 17:14 | |
*** kolla-slack has joined #openstack-kolla | 17:14 | |
sdake | rwellum here is what i do | 17:14 |
sdake | rwellum use grep to find the cell0 in the service chart | 17:15 |
sdake | rwellum then use git blame on the file in question | 17:15 |
sdake | it will list the git commit with each line containing a change | 17:15 |
sdake | then git revert ID | 17:15 |
harlowja | sdake inc0 klindgren_ yes, i can throw out there a kolla-jenkins thing if the kolla people want to get that started | 17:17 |
harlowja | i don't mind | 17:17 |
harlowja | it'd probably be useful for others | 17:18 |
* harlowja already has https://github.com/harlowja/kolla-jenkins but its not up to date | 17:18 | |
harlowja | can move that under openstack/kolla-jenkins | 17:18 |
harlowja | (post-update) | 17:18 |
harlowja | if people here would like that, i don't mind | 17:18 |
*** eaguilar has quit IRC | 17:18 | |
*** Serlex has quit IRC | 17:19 | |
rwellum | sdake ack | 17:23 |
* harlowja just requires some work | 17:23 | |
harlowja | https://gist.github.com/harlowja/8f9ea412ec892f72808c48114e6fb70f is some of this... | 17:24 |
*** eaguilar has joined #openstack-kolla | 17:24 | |
*** eaguilar has quit IRC | 17:24 | |
harlowja | https://gist.github.com/harlowja/8f9ea412ec892f72808c48114e6fb70f#file-gistfile1-txt-L134 | 17:24 |
*** unicell has joined #openstack-kolla | 17:26 | |
*** chas has joined #openstack-kolla | 17:28 | |
*** ipsecguy_ has quit IRC | 17:30 | |
*** ipsecguy has joined #openstack-kolla | 17:30 | |
*** tonanhngo has joined #openstack-kolla | 17:31 | |
*** jmccarthy has quit IRC | 17:34 | |
*** eaguilar has joined #openstack-kolla | 17:34 | |
*** eaguilar has quit IRC | 17:34 | |
*** MasterOfBugs has joined #openstack-kolla | 17:38 | |
*** hieulq__ has quit IRC | 17:39 | |
harlowja | ` Map jenkins_job` in that contains the thing we write | 17:40 |
harlowja | into `job.json` | 17:40 |
harlowja | (inside the container) | 17:40 |
harlowja | https://gist.github.com/harlowja/d8dfaa6938694454432037d1e651bad6 is somewhat of whats in that map | 17:41 |
rwellum | sdake: https://review.openstack.org/#/c/466536/ | 17:41 |
sdake | rwellum right you want to revert that commit | 17:42 |
*** jaosorior is now known as jaosorior_away | 17:44 | |
rwellum | sdake: it's a multi function commit so a simple revert won't work. | 17:44 |
*** athomas has quit IRC | 17:44 | |
sdake | rwellum git revert returns errors? | 17:44 |
rwellum | No I mean there are three pieces to the commit and I'm assuming 2 of them are still valid. | 17:47 |
*** manheim has joined #openstack-kolla | 17:48 | |
*** chas has quit IRC | 17:48 | |
*** chas has joined #openstack-kolla | 17:49 | |
*** chas has quit IRC | 17:53 | |
sbezverk | rwellum: why you want to revert? | 17:55 |
*** sean-k-m1 has joined #openstack-kolla | 17:59 | |
*** sean-k-mooney has quit IRC | 18:00 | |
*** sgrasley has quit IRC | 18:06 | |
*** ducttape_ has quit IRC | 18:06 | |
*** mnasiadka has joined #openstack-kolla | 18:10 | |
*** ducttape_ has joined #openstack-kolla | 18:12 | |
*** mnasiadka has quit IRC | 18:15 | |
*** daidv has quit IRC | 18:28 | |
*** chas has joined #openstack-kolla | 18:29 | |
inc0 | hmm I think I forgot to turn my home pc... and now I have smaller tmux | 18:29 |
trozet | sean-k-m1: you got a second for some really noob questions? | 18:34 |
*** mgoddard has joined #openstack-kolla | 18:34 | |
trozet | or maybe inc0:^ | 18:39 |
inc0 | trozet: just ask;) | 18:39 |
jamesbenson | *trozet I can try (if they are easy ones), but having issues myself too | 18:39 |
trozet | inc0, jamesbenson: so i tried to deploy the ODL kolla container in tripleo and i see this: https://paste.fedoraproject.org/paste/jS~oVDD3u7l2bEn5ljoBTV5M1UNdIGYhyRLivL9gydE=/raw | 18:40 |
trozet | inc0, jamesbenson: which looks like something tried to sudo, so i figured I would just pull the ODL container in docker outside of OOO and try to just docker run it | 18:40 |
inc0 | trozet: I assume you're running something equivalent to docker run ? | 18:41 |
trozet | inc0, jamesbenson: so when i just try a docker run on my server of that container, No such file or directory: '/var/lib/kolla/config_files/config.json' | 18:41 |
trozet | inc0, jamesbenson: and i wehn i look in /var/lib/kolla/config_files/ on the tripleo server, there are tons of them, per service | 18:41 |
inc0 | trozet: our default command is kolla-start | 18:41 |
inc0 | so it will look for config files | 18:42 |
*** eaguilar has joined #openstack-kolla | 18:42 | |
inc0 | if you try to manually run neutron server | 18:42 |
trozet | inc0, jamesbenson: i'm wondering how does config.json normally get installed/created? | 18:42 |
*** jamesPR has quit IRC | 18:42 | |
inc0 | as in docker run -v my_neutron.conf:/etc/neutron/server.conf -it neutron-odl-server neutron-server | 18:42 |
inc0 | trozet: it's this thing https://github.com/openstack/kolla-ansible/blob/master/ansible/roles/neutron/templates/neutron-server.json.j2 | 18:43 |
*** krtaylor has quit IRC | 18:44 | |
trozet | inc0: ah, i'm currently just using the opendaylight containre that mgkwill added to kolla | 18:44 |
inc0 | if you manually specify command to run, it's gonna be ok | 18:45 |
trozet | inc0: ok let me try that | 18:45 |
trozet | inc0: yeah that works, so then normally it will run kolla_start and then load any json config file in that directory as well? | 18:47 |
inc0 | normally you create config.json in dir, which specifies what config files should be coppied and what permissions to give them | 18:47 |
inc0 | and which command to run | 18:47 |
*** kbaegis1 has quit IRC | 18:48 | |
trozet | inc0: right, so in my file in my tripleo setup I have: | 18:50 |
trozet | [root@overcloud-controller-0 config_files]# cat /var/lib/kolla/config_files/opendaylight_api.json | 18:50 |
trozet | {"command": "/opt/opendaylight/start", "permissions": [{"owner": "odl:odl", "path": "/opt/opendaylight", "recurse": true}]}[root@overcloud-controller-0 config_files] | 18:50 |
inc0 | yeah, looks good | 18:51 |
trozet | 0fadbe820192 192.168.24.1:8787/tripleoupstream/centos-binary-opendaylight:latest "kolla_start" About an hour ago Restarting (1) 51 minutes ago opendaylight_api | 18:51 |
trozet | inc0: and it looks like it was trying to run kolla_start^ when it hit the issue | 18:51 |
inc0 | that's what will be run if you won't specify anythig else | 18:52 |
trozet | inc0: oh crap, it should be /opt/opendaylight/bin/start, thats one problem | 18:53 |
jamesbenson | okay, running into a roadblock as well.. I'm doing a simple deploy, but mariaDB doesn't start up... here are the mariadb logs: http://paste.openstack.org/show/611135/ | 19:02 |
inc0 | jamesbenson: it seems you put down whole cluster and now you try to restart it? | 19:02 |
jamesbenson | yeah | 19:02 |
inc0 | jamesbenson: if you want to keep data, there is some work to be done | 19:04 |
trozet | inc0: inside the ODL container bash shell, if i create that config.json and try to run kolla_start, I get ERROR:__main__:InvalidConfig: KOLLA_CONFIG_STRATEGY is not set properly | 19:04 |
inc0 | if you don't care, I'd say delete whole thing and redeploy | 19:04 |
*** chas has quit IRC | 19:04 | |
trozet | inc0: i just did this, export KOLLA_CONFIG_STRATEGY=COPY_ALWAYS | 19:05 |
inc0 | trozet: kolla-ansible sets few envs too | 19:05 |
trozet | seems to have gotten farther | 19:05 |
inc0 | that's good | 19:05 |
*** chas has joined #openstack-kolla | 19:05 | |
inc0 | I'd suggest deploying kolla-ansible somewhere on the side | 19:05 |
inc0 | and have docker inspect to see what's happening | 19:05 |
jamesbenson | inc0: can I show you my config and tell me if I'm crazy? This is what I tried originally: multinode: http://paste.openstack.org/show/611136/ globals: http://paste.openstack.org/show/611137/ | 19:06 |
trozet | inc0: Running command: '/opt/opendaylight/bin/start' | 19:06 |
trozet | inc0: so looks good, not sure what is causing the original error message of not having passwordless sudo or something, i would have thought the container would execute as root | 19:06 |
jamesbenson | also had fernet enabled, but disabled it recently.... | 19:06 |
inc0 | I don't see anything particulary crazy | 19:07 |
trozet | inc0: oh it executes as 'odl' user I guess | 19:07 |
inc0 | trozet: we normally don't run root in container | 19:07 |
jamesbenson | inc0, it seemed to work before, but now it crashed on ceph, mariadb, fernet... no idea why... | 19:08 |
trozet | inc0: ah now i get it if i try to run kolla_start as odl user | 19:08 |
inc0 | mariadb issue is restarting whole cluster | 19:08 |
*** eaguilar_ has joined #openstack-kolla | 19:08 | |
inc0 | http://galeracluster.com/documentation-webpages/restartingcluster.html | 19:08 |
*** eaguilar has quit IRC | 19:08 | |
trozet | inc0: it looks like in the opendaylight kolla Dockerfile there is no sudo permissions being set? | 19:09 |
*** chas has quit IRC | 19:09 | |
inc0 | possibly | 19:10 |
inc0 | we normally handcraft sudoers | 19:10 |
trozet | inc0: ok let me try to fix it | 19:10 |
inc0 | for security | 19:10 |
inc0 | jamesbenson: what are issues with ceph and rest? | 19:10 |
jamesbenson | fernet initially yelled at me for selecting 604800 (one week), so I changed it back to 1 day...then other errors I don't recall... ceph couldn't partition the images even though they have the correct tags in parted | 19:12 |
*** rwallner has quit IRC | 19:12 | |
jamesbenson | I'm reinstalling the OS in all of the systems, besides my deployment node so I have a clean start.... | 19:12 |
jamesbenson | should just be a few minutes... | 19:12 |
inc0 | let me know | 19:13 |
inc0 | how it goes | 19:13 |
*** lucasxu has quit IRC | 19:13 | |
*** rwallner has joined #openstack-kolla | 19:16 | |
*** rwallner_ has joined #openstack-kolla | 19:17 | |
*** sayantan_ has quit IRC | 19:17 | |
jamesbenson | with a clean system, all I do is this: https://github.com/JamesOBenson/Kolla-misc/blob/master/kolla_bridge.yml to help set up the environment a little, then bootstrap, etc.. | 19:17 |
*** sayantan_ has joined #openstack-kolla | 19:17 | |
*** sayantan_ has quit IRC | 19:21 | |
*** rwallner has quit IRC | 19:21 | |
*** lpetrut has joined #openstack-kolla | 19:23 | |
sdake | kfox1111 around? | 19:23 |
kfox1111 | hi | 19:24 |
*** sayantan_ has joined #openstack-kolla | 19:24 | |
*** sayantan_ has quit IRC | 19:27 | |
*** sayantan_ has joined #openstack-kolla | 19:30 | |
*** sayantan_ has quit IRC | 19:33 | |
kfox1111 | sdake: whats up? | 19:33 |
jamesbenson | inc0, going to deploy 3 controllers, 3 network, 1 monitoring, 1 compute, 7 storage..... if it works, I'll add the rest of the compute. | 19:36 |
*** sayantan_ has joined #openstack-kolla | 19:36 | |
trozet | inc0: it's not OK to allow 'odl' user to run root on everything right? | 19:36 |
*** krtaylor has joined #openstack-kolla | 19:37 | |
rwellum | sbezverk: sorry was away. The part I think may need to be reverted is moving the cell micro-service into the service chart. I see the pops flap and restart continuously for a few minutes until it settles down. According to sdake there's a circular dependency. Look at 16:13:52 onwards from here: | 19:40 |
rwellum | http://eavesdrop.openstack.org/meetings/kolla/2017/kolla.2017-05-31-15.59.log.html | 19:40 |
*** sayantan_ has quit IRC | 19:41 | |
*** Pavo has joined #openstack-kolla | 19:41 | |
*** sayantan_ has joined #openstack-kolla | 19:43 | |
rwellum | s/pods/pops | 19:43 |
openstackgerrit | Rob Crittenden proposed openstack/kolla master: Add images for novajoin services https://review.openstack.org/466268 | 19:43 |
inc0 | trozet: no, it's not;) good for debugging but at the end we want it to be limited | 19:44 |
trozet | inc0: :) ok thanks | 19:44 |
inc0 | jamesbenson: sounds good | 19:44 |
*** egonzalez has joined #openstack-kolla | 19:45 | |
*** pcaruana has joined #openstack-kolla | 19:45 | |
*** sayantan_ has quit IRC | 19:45 | |
*** sayantan_ has joined #openstack-kolla | 19:49 | |
jamesbenson | [WARNING]: when statements should not include jinja2 templating delimiters such as {{ }} or {% %}. Found: {{ 'trove_api' not in haproxy_stat }} | 19:50 |
jamesbenson | inc0: are these types of warnings ok? I dont remember them before: | 19:50 |
*** mgoddard has quit IRC | 19:51 | |
inc0 | ansible adds a lot of warnings | 19:51 |
inc0 | probably we should fix it at some point | 19:51 |
*** sayantan_ has quit IRC | 19:52 | |
*** rwallner_ has quit IRC | 19:53 | |
jamesbenson | just checking, I didnt think it was a problem ... I'm familiar with ansible warnings | 19:53 |
*** mnasiadka has joined #openstack-kolla | 19:55 | |
*** sayantan_ has joined #openstack-kolla | 19:55 | |
trozet | inc0: where do you add users to the kolla group? | 19:58 |
trozet | inc0: i see a macro configure_user, does that do it automatically? | 19:58 |
inc0 | trozet: right, we also add users at beggining of base | 19:58 |
trozet | inc0: i see the problem, the current code has the user as 'opendaylight' | 19:59 |
*** sayantan_ has quit IRC | 19:59 | |
trozet | inc0: but that user doesnt exist in the container, i think it should be odl | 20:00 |
*** mnasiadka has quit IRC | 20:00 | |
jamesbenson | inc0 I need to run, I'll update you in an hour or tomorrow.... | 20:00 |
*** salv-orlando has joined #openstack-kolla | 20:00 | |
*** jamesbenson has quit IRC | 20:00 | |
*** jascott1 has quit IRC | 20:01 | |
*** TxGirlGeek has quit IRC | 20:01 | |
*** jascott1 has joined #openstack-kolla | 20:02 | |
*** eaguilar_ has quit IRC | 20:02 | |
*** sayantan_ has joined #openstack-kolla | 20:02 | |
*** pcaruana has quit IRC | 20:02 | |
*** sayantan_ has quit IRC | 20:02 | |
*** sayantan_ has joined #openstack-kolla | 20:02 | |
*** eaguilar has joined #openstack-kolla | 20:03 | |
*** sayantan_ has quit IRC | 20:04 | |
*** sayantan_ has joined #openstack-kolla | 20:05 | |
*** jascott1 has quit IRC | 20:06 | |
*** jascott1 has joined #openstack-kolla | 20:08 | |
trozet | inc0: what is this directory used for? /var/log/kolla/opendaylight | 20:08 |
*** TxGirlGeek has joined #openstack-kolla | 20:09 | |
*** salv-orlando has quit IRC | 20:09 | |
openstackgerrit | Michal Jastrzebski (inc0) proposed openstack/kolla-ansible master: Enable multinode gate https://review.openstack.org/466007 | 20:11 |
mgkwill | trozet: that's location of ODL log in container | 20:11 |
*** salv-orlando has joined #openstack-kolla | 20:11 | |
trozet | mgkwill: but logs for ODL are placed in /opt/opendaylight/data/log/karaf.log | 20:11 |
inc0 | trozet: take a wild guess;) | 20:11 |
trozet | inc0: well i didnt know if it was for something kolla-ansible specific | 20:12 |
inc0 | trozet: can you configure it to use /var/log/kolla? | 20:12 |
trozet | inc0: because odl logs dont go in there | 20:12 |
trozet | inc0: no | 20:12 |
mgkwill | trozet: by default yes but I changed to conform to kola logging | 20:12 |
inc0 | damn, we mount /var/log/kolla as volume | 20:12 |
inc0 | that's why it's important for all logs to land there | 20:12 |
mgkwill | trozet: it's all configurable in ODL | 20:13 |
trozet | mgkwill: how did you change it? | 20:13 |
*** TxGirlGeek has quit IRC | 20:13 | |
*** jascott1 has quit IRC | 20:13 | |
mgkwill | There's a logging config file for karaf, I'm at lunch or I'd send you link | 20:14 |
trozet | mgkwill: i'm trying to add/fix the sudoers stuff | 20:14 |
*** powerd has quit IRC | 20:14 | |
*** jascott1 has joined #openstack-kolla | 20:14 | |
mgkwill | trozet: what is issue with sudoers? | 20:15 |
openstackgerrit | Tim Rozet proposed openstack/kolla master: Fixes odl username and sudoers permissions https://review.openstack.org/469640 | 20:15 |
trozet | mgkwill:^ | 20:15 |
*** TxGirlGeek has joined #openstack-kolla | 20:15 | |
mgkwill | inc0: FYI logs are configured to kolla mount location - conforming to kolla practice | 20:17 |
inc0 | that's cool | 20:17 |
inc0 | there are reasons for that - for example central logging | 20:17 |
mgkwill | trozet: I'll take a look in a few, but don't understand issue you are seeing. IE need. | 20:18 |
*** TxGirlGeek has quit IRC | 20:18 | |
mgkwill | inc0: agreed | 20:18 |
*** kbaegis has joined #openstack-kolla | 20:18 | |
egonzalez | trozet opendatlight user is defined https://github.com/openstack/kolla/blob/master/kolla/common/config.py#L846 will need to be changed too or build will fail | 20:18 |
*** eaguilar has quit IRC | 20:18 | |
trozet | mgkwill: it is the wrong user i think | 20:19 |
trozet | im not even sure i need the sudo permissions, once the user is fixed | 20:19 |
*** jascott1 has quit IRC | 20:19 | |
trozet | egonzalez: thanks for the pointer | 20:20 |
*** lucasxu has joined #openstack-kolla | 20:20 | |
*** jascott1 has joined #openstack-kolla | 20:21 | |
openstackgerrit | Michal Jastrzebski (inc0) proposed openstack/kolla-ansible master: Enable multinode gate https://review.openstack.org/466007 | 20:21 |
egonzalez | inc0 neutron fix failed to merge, they also have gates problems ;) | 20:21 |
*** lucasxu has quit IRC | 20:21 | |
inc0 | oh joy;) | 20:22 |
inc0 | egonzalez: might giving this a look? https://review.openstack.org/#/c/466007/75 | 20:22 |
trozet | mgkwill, inc0: yeah we dont even need sudoers, just need to fix the user | 20:23 |
inc0 | tomorrow maybe, when you'll be awaken and gates will be up | 20:23 |
*** jascott1 has quit IRC | 20:26 | |
openstackgerrit | Tim Rozet proposed openstack/kolla master: Fixes odl username and sudoers permissions https://review.openstack.org/469640 | 20:27 |
*** jascott1 has joined #openstack-kolla | 20:28 | |
*** eaguilar has joined #openstack-kolla | 20:29 | |
openstackgerrit | Michal Jastrzebski (inc0) proposed openstack/kolla-ansible master: Enable multinode gate https://review.openstack.org/466007 | 20:30 |
mgkwill | trozet: it'd be helpful to know why tripleooo needs to sudo inside container - but I can't remember how user is done but assumption is that all config is done via config files loaded at start or rest api | 20:33 |
*** jascott1 has quit IRC | 20:33 | |
trozet | mgkwill: it doesnt need sudo, the problem was the kolla_start exec uses sudo to set config | 20:33 |
trozet | mgkwill: and the odl user was not in the kolla group | 20:33 |
*** jascott1 has joined #openstack-kolla | 20:34 | |
*** TxGirlGeek has joined #openstack-kolla | 20:34 | |
*** jascott1 has quit IRC | 20:34 | |
trozet | mgkwill: i just updated the patch and removed the sudo stuff | 20:34 |
*** jascott1 has joined #openstack-kolla | 20:35 | |
mgkwill | trozet: Weird, we've been using this image for a while without issue | 20:36 |
*** eaguilar has quit IRC | 20:36 | |
trozet | mgkwill: were you using packages? | 20:36 |
trozet | mgkwill: odl package i mean | 20:36 |
mgkwill | trozet no source, that sounds like difference | 20:36 |
trozet | mgkwill: yeah the ODL RPM creates an 'odl' user and makes all the files belong to odl, along with and odl group | 20:37 |
mgkwill | trozet you mean like rpm right? No | 20:37 |
*** jascott1 has quit IRC | 20:37 | |
sdake | kfox1111 nm i sorted it out on my own | 20:38 |
trozet | mgkwill: can you tell me how you move the logging file? we should also do that in the RPM | 20:38 |
sdake | kfox1111 thanks for being attentive tho :) | 20:38 |
mgkwill | trozet, i can see issue in that case | 20:38 |
*** ansmith has quit IRC | 20:39 | |
mgkwill | trozet still at lunch, point you to it when back. | 20:40 |
trozet | mgkwill: oh ok, thanks | 20:41 |
*** jascott1 has joined #openstack-kolla | 20:41 | |
sdake | inc0 here is the revert pin: https://review.openstack.org/#/c/469583/ | 20:44 |
sdake | no bueno | 20:44 |
*** jascott1 has quit IRC | 20:46 | |
*** jamesbenson has joined #openstack-kolla | 20:46 | |
*** jascott1 has joined #openstack-kolla | 20:48 | |
*** jamesbenson has quit IRC | 20:51 | |
*** jamesbenson has joined #openstack-kolla | 20:51 | |
*** jascott1 has quit IRC | 20:52 | |
sbezverk | rwellum: hmm why the gate then working fine? | 20:54 |
*** jascott1 has joined #openstack-kolla | 20:54 | |
*** jascott1 has quit IRC | 20:59 | |
sdake | sbezverk the gate works fine because the commands run bck to back | 20:59 |
sdake | e.g. the cell0 fials, but enters running state | 20:59 |
sdake | the waitforpods.py says "a-ok" | 20:59 |
sdake | and continues on | 20:59 |
sdake | then it fails | 20:59 |
sdake | and then it eventually does its thing | 21:00 |
sdake | i have withnessed it only when running a manual workflow - and sometimes error count > 0 when running automated | 21:00 |
*** jtriley_ has joined #openstack-kolla | 21:00 | |
jamesbenson | inc0: still there? | 21:00 |
sdake | in our team meeting today we talked about rewriting the (dead upstream) of entrypoint to permit this model to work properly | 21:01 |
sdake | with dependencies for deploy and upgrade | 21:01 |
sdake | we also talked about a helm tiller thing | 21:01 |
sdake | some kind of integration (native) | 21:02 |
*** jascott1 has joined #openstack-kolla | 21:02 | |
sdake | in the short term, we are going to use microcharts for deploying in a container | 21:02 |
*** sgrasley has joined #openstack-kolla | 21:02 | |
sdake | and that entrypoint mulligan will come next | 21:02 |
*** jtriley has quit IRC | 21:03 | |
sdake | cell0 must run after compute kit is deployed | 21:04 |
sdake | if computekit isn't deployed cell0 goes fail | 21:04 |
sdake | rather after nova-compute is deployed | 21:04 |
harlowja | inc0 would u be receptive to a kolla-jenkins | 21:05 |
harlowja | i can just get this going, if so | 21:05 |
harlowja | or shall i ask elsewhere on ml | 21:05 |
*** jtriley_ has quit IRC | 21:05 | |
inc0 | harlowja: I would | 21:05 |
inc0 | ;0 | 21:05 |
harlowja | ok | 21:05 |
*** TxGirlGeek has quit IRC | 21:06 | |
*** jascott1 has quit IRC | 21:07 | |
*** TxGirlGeek has joined #openstack-kolla | 21:07 | |
inc0 | harlowja: that would fit nicely with our "publish the images" thing | 21:07 |
inc0 | if we could replicate gates we run in openstack locally, make it easy | 21:07 |
inc0 | that would be frickin' awesome | 21:07 |
harlowja | hmmm | 21:08 |
harlowja | jenkins and what the gates do is slightly different | 21:08 |
sbezverk | sdake: instead of rolling back, it is better then get entrypoint guy fix condition based on daemonset | 21:08 |
harlowja | but sure, close would be fine | 21:08 |
inc0 | yeah, let's talk | 21:08 |
*** jascott1 has joined #openstack-kolla | 21:08 | |
sdake | sbezverk i believe the entrypoint maintainer is no longer maintaing it | 21:08 |
*** manheim has quit IRC | 21:10 | |
*** pcaruana has joined #openstack-kolla | 21:12 | |
*** jascott1 has quit IRC | 21:13 | |
*** rwallner has joined #openstack-kolla | 21:14 | |
*** manheim has joined #openstack-kolla | 21:14 | |
*** TxGirlGeek has quit IRC | 21:14 | |
*** bjolo has joined #openstack-kolla | 21:14 | |
*** jascott1 has joined #openstack-kolla | 21:15 | |
*** TxGirlGeek has joined #openstack-kolla | 21:15 | |
*** salv-orlando has quit IRC | 21:16 | |
*** TxGirlGeek has quit IRC | 21:18 | |
*** rwallner has quit IRC | 21:18 | |
*** TxGirlGeek has joined #openstack-kolla | 21:19 | |
*** jascott1 has quit IRC | 21:20 | |
*** jascott1 has joined #openstack-kolla | 21:21 | |
*** harlowja has quit IRC | 21:21 | |
*** jascott1 has quit IRC | 21:26 | |
*** jascott1 has joined #openstack-kolla | 21:26 | |
*** TxGirlGeek has quit IRC | 21:28 | |
*** pcaruana has quit IRC | 21:29 | |
*** lpetrut has quit IRC | 21:30 | |
*** sayantan_ has quit IRC | 21:31 | |
*** sgrasley has quit IRC | 21:32 | |
*** TxGirlGeek has joined #openstack-kolla | 21:33 | |
*** TxGirlGeek has quit IRC | 21:35 | |
*** TxGirlGeek has joined #openstack-kolla | 21:39 | |
*** chas has joined #openstack-kolla | 21:41 | |
*** TxGirlGeek has quit IRC | 21:42 | |
*** powerd has joined #openstack-kolla | 21:43 | |
*** chas has quit IRC | 21:46 | |
*** manheim has quit IRC | 21:54 | |
*** manheim has joined #openstack-kolla | 21:55 | |
*** mnasiadka has joined #openstack-kolla | 21:55 | |
Reepicheep | is there a more elegent way of replacing the haproxy.pem cert on the network nodes? short of redeploying? | 21:56 |
Reepicheep | I could replace the /etc/kolla/haproxy/haproxy.pem on each network node and restart haproxy containers | 21:57 |
Reepicheep | or beter yet maybe send a HUP to the haproxy process inside the containers to prevent the keepalive from kicking in | 21:57 |
Reepicheep | I'm automating this because I'm using Let's Encrypt | 21:58 |
*** powerd has quit IRC | 22:00 | |
*** mnasiadka has quit IRC | 22:00 | |
*** jascott1 has quit IRC | 22:01 | |
*** jascott1 has joined #openstack-kolla | 22:01 | |
*** harlowja has joined #openstack-kolla | 22:06 | |
*** rwsu has quit IRC | 22:06 | |
*** jascott1 has quit IRC | 22:07 | |
*** jascott1 has joined #openstack-kolla | 22:09 | |
*** mnasiadka has joined #openstack-kolla | 22:14 | |
*** mnasiadka has quit IRC | 22:19 | |
openstackgerrit | Michal Jastrzebski (inc0) proposed openstack/kolla-ansible master: Enable multinode gate https://review.openstack.org/466007 | 22:20 |
inc0 | Reepicheep: not sure tbh | 22:21 |
inc0 | good question | 22:21 |
*** egonzalez has quit IRC | 22:21 | |
*** TxGirlGeek has joined #openstack-kolla | 22:22 | |
*** rwellum has quit IRC | 22:31 | |
Reepicheep | inc0: thanks.. I will work on it. I was just wondering if there was already some way of doing it from ansible before I spent time developing my own | 22:36 |
inc0 | well if you'll manage to get new key into container you can just run reconfigure | 22:38 |
inc0 | but that won't do hup | 22:38 |
inc0 | so probably you'll end up doing something on your own, which I'd love to see in our codebase;) | 22:38 |
Reepicheep | well here one thing that could be added if others find it usfull and it passes the guidlines to make it into the code base | 22:40 |
Reepicheep | I add a few lines to the haproxy to redirect .well-known/acme-challenge/ to a differnt web server.. currently an nginx docker container on my kolla machine | 22:41 |
Reepicheep | http://paste.openstack.org/show/611143/ | 22:42 |
Reepicheep | that is specific to my install but by using some ansible parameters it could be made more generic and enabled only when needed | 22:43 |
*** krtaylor has quit IRC | 22:46 | |
*** kbaegis has quit IRC | 22:54 | |
*** kbaegis has joined #openstack-kolla | 22:54 | |
*** powerd has joined #openstack-kolla | 23:02 | |
Reepicheep | This is working for now.. I have a bash script copy it to /etc/kolla/haproxy/ on each network node | 23:03 |
Reepicheep | then use docker cp to get it into the container and then restart the containers | 23:03 |
*** jamesbenson has quit IRC | 23:03 | |
Reepicheep | now I just need to convert that to an ansible playbook to make it more shareable ;) | 23:04 |
*** jamesbenson has joined #openstack-kolla | 23:05 | |
*** emccormick has quit IRC | 23:05 | |
bmaltais | Reepicheep: wouldn't kolla-ansible deploy -i multinode --tags haproxy do about the same? | 23:06 |
bmaltais | Reepicheep: This would limit actions only to haproxy and should update updated pem files quickly | 23:07 |
*** MasterOfBugs has quit IRC | 23:07 | |
*** rwsu has joined #openstack-kolla | 23:08 | |
Reepicheep | or at least some ansible commands something like this maybe: | 23:08 |
Reepicheep | ansible -i ./multinode -m shell -a "docker cp cp /etc/kolla/haproxy/haproxy.pem haproxy:/etc/haproxy/" network | 23:08 |
Reepicheep | bmaltais: I'm just trying to make it simple and quick | 23:08 |
bmaltais | Reepicheep: Did you try updating the /etc/kolla/haproxy/haproxy.pem file and then run "kolla-ansible deploy -i multinode --tags haproxy" to compare results? | 23:09 |
*** jamesbenson has quit IRC | 23:09 | |
bmaltais | Reepicheep: I think the built-in "--tags haproxy" scope does essentially the same as your script. | 23:10 |
Reepicheep | yeah.. that actually works .. it just takes a while and if something else where to go horibly wrong when it's running at 2 in the morning it would not be as good | 23:10 |
bmaltais | Reepicheep: Even with the --tags haproxy? That cut down the execution time a lot since it only focus on haproxy specific changes and does not touch anything else. | 23:11 |
bmaltais | Reepicheep: About 10 times faster that without the --tags for me. | 23:11 |
bmaltais | Reepicheep: But probably not as fast as your specific script ;-) | 23:12 |
Reepicheep | so the 'ansible -i ./multinode -m shell -a "commads" network' works for the docker cp and docker restart part.. is there a simple ansible command to copy /etc/kolla/certificates/haproxy.pem to the network nodes? | 23:12 |
Reepicheep | currently I use scp in a script but I don't get to use the "network" host group from the inventory | 23:13 |
*** pradk has quit IRC | 23:13 | |
dims | inc0 : kfox1111 : one question, does the resolution as it stands give you enough freedom to experiment? | 23:14 |
inc0 | dims: yeah, I think current format is exactl what we were planning to do in the first place | 23:14 |
*** kbaegis has quit IRC | 23:14 | |
dims | inc0 : ok, let's ship it then! | 23:14 |
inc0 | we still have lots of unanswered questions, like how to handle tags and whatnot, but we'll have to figure it out as we go | 23:15 |
dims | ack inc0 | 23:15 |
inc0 | as I said in review, release team feedback would be greatly appreciated | 23:15 |
*** ducttape_ has quit IRC | 23:15 | |
*** goldyfruit has quit IRC | 23:16 | |
Reepicheep | bmaltais: one reason I'm would not mind it being as quick as possible is that my acme client I use will verify the new cert for me after it is installed | 23:16 |
dims | wearing my release hat, there's no difference in release process for kolla, we do the same thing as before, you request a version with a SHA and we use existing jobs to push tarballs out | 23:16 |
Reepicheep | if it takes 10 minutes for it to "restart the service" that is a long time for the acme client to wait | 23:16 |
dims | inc0 : we can review once again when you have sorted out how you want to do stuff | 23:17 |
inc0 | well, yes and no, that's what I'm saying. We have to deal with version of kolla + version of service in container + versions of all deps of this service | 23:17 |
inc0 | makes things funny, probably good PTG discussion | 23:17 |
inc0 | and arguably version of Kolla is least important of 3;) | 23:18 |
*** jascott1 has quit IRC | 23:18 | |
*** jascott1 has joined #openstack-kolla | 23:18 | |
dims | inc0 : i'd recommend talking to requirements team (dirk, prometheanfire) as we cannot ever run a "full" set of tests that will cover all scenarios and there's need to pin/block/avoid versions and work with teams to get things working right. which is what you will end up doing too | 23:19 |
inc0 | yeah, that too | 23:19 |
inc0 | as I said, fun:) | 23:19 |
inc0 | for now, let's start somewhere and we'll figure it out as we go | 23:19 |
dims | inc0 : you can always have another git repo for maintaining version/manifest and what not depending on what you want to do | 23:19 |
dims | ++ | 23:19 |
*** jascott1 has quit IRC | 23:24 | |
*** jascott1 has joined #openstack-kolla | 23:26 | |
*** jascott1 has quit IRC | 23:30 | |
*** jascott1 has joined #openstack-kolla | 23:32 | |
*** jtriley has joined #openstack-kolla | 23:36 | |
*** jascott1 has quit IRC | 23:37 | |
*** jascott1 has joined #openstack-kolla | 23:39 | |
*** TxGirlGeek has quit IRC | 23:39 | |
*** chas has joined #openstack-kolla | 23:40 | |
*** jascott1 has quit IRC | 23:41 | |
*** jascott1_ has joined #openstack-kolla | 23:41 | |
sbezverk | kfox1111: ping | 23:44 |
*** chas has quit IRC | 23:44 | |
*** jascott1_ has quit IRC | 23:46 | |
*** masber has joined #openstack-kolla | 23:46 | |
*** manheim has quit IRC | 23:48 | |
*** manheim has joined #openstack-kolla | 23:49 | |
sdake | dims i woudl like a resolution to hte stable follows policy and the manfiest code | 23:53 |
dims | sdake : follow up resolution? | 23:53 |
*** manheim has quit IRC | 23:53 | |
sdake | dims i think a simple exception can handle it | 23:54 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!