Monday, 2017-10-02

*** dardelean_ has joined #openstack-kolla00:14
*** dave-mccowan has joined #openstack-kolla00:15
*** dardelean_ has quit IRC00:18
*** jamesbenson has joined #openstack-kolla00:34
*** jamesbenson has quit IRC00:39
*** hieulq has joined #openstack-kolla00:41
*** dardelean_ has joined #openstack-kolla00:50
*** hrw has quit IRC00:50
*** hrw has joined #openstack-kolla00:52
*** duonghq has joined #openstack-kolla00:52
*** dardelean_ has quit IRC00:54
*** tovin07_ has joined #openstack-kolla00:58
*** jascott1 has joined #openstack-kolla01:03
*** jtriley has quit IRC01:07
*** dave-mccowan has quit IRC01:30
*** dave-mccowan has joined #openstack-kolla01:33
*** genek has joined #openstack-kolla01:47
*** dave-mcc_ has joined #openstack-kolla01:49
*** dave-mccowan has quit IRC01:51
*** jtriley has joined #openstack-kolla01:55
*** dave-mccowan has joined #openstack-kolla01:56
*** dave-mcc_ has quit IRC01:59
*** genek has quit IRC02:04
*** genek has joined #openstack-kolla02:09
*** dave-mcc_ has joined #openstack-kolla02:18
*** dave-mccowan has quit IRC02:18
*** genek has quit IRC02:23
*** jtriley has quit IRC02:41
*** dave-mcc_ has quit IRC02:55
openstackgerritJeffrey Zhang proposed openstack/kolla master: [DNM]Testing in project jobs definition  https://review.openstack.org/50876803:06
openstackgerritJeffrey Zhang proposed openstack/kolla master: [DNM]Testing in project jobs definition 2  https://review.openstack.org/50879703:06
openstackgerritJeffrey Zhang proposed openstack/kolla master: [DNM]Testing in project jobs definition 2  https://review.openstack.org/50879703:08
openstackgerritJeffrey Zhang proposed openstack/kolla master: [DNM]Testing in project jobs definition  https://review.openstack.org/50876803:09
*** dardelean_ has joined #openstack-kolla03:14
openstackgerritJeffrey Zhang proposed openstack/kolla master: Testing in project jobs definition  https://review.openstack.org/50866103:19
*** dardelean_ has quit IRC03:19
*** jtriley has joined #openstack-kolla03:20
openstackgerritJeffrey Zhang proposed openstack/kolla-ansible master: Move to zuul v3 in project jobs  https://review.openstack.org/50875903:27
openstackgerritJeffrey Zhang proposed openstack/kolla-ansible master: Move to zuul v3 in project jobs  https://review.openstack.org/50875903:40
openstackgerritJeffrey Zhang proposed openstack/kolla-ansible master: Move to zuul v3 in project jobs  https://review.openstack.org/50875903:43
*** jtriley has quit IRC04:10
*** jaosorior has joined #openstack-kolla04:19
*** jtriley has joined #openstack-kolla04:46
*** unicell has joined #openstack-kolla04:58
*** unicell1 has joined #openstack-kolla05:02
*** numans has quit IRC05:03
*** unicell has quit IRC05:04
*** noVNC has joined #openstack-kolla05:04
*** numans has joined #openstack-kolla05:06
*** jascott1 has quit IRC05:07
*** jascott1 has joined #openstack-kolla05:08
*** logan- has quit IRC05:18
*** logan- has joined #openstack-kolla05:21
*** aagate has joined #openstack-kolla05:23
*** livelace has joined #openstack-kolla05:36
*** jtriley has quit IRC05:37
*** mdnadeem has joined #openstack-kolla05:40
noVNCanyone seen this error https://pastebin.com/raw/DBcx4VSh ???05:45
noVNCduring kolla-ansible upgrade05:45
*** logan- has quit IRC05:48
*** logan- has joined #openstack-kolla05:53
*** jtriley has joined #openstack-kolla06:11
*** serlex has joined #openstack-kolla06:14
*** aagate has quit IRC06:15
*** aagate has joined #openstack-kolla06:15
*** dciabrin has joined #openstack-kolla06:22
*** aagate has quit IRC06:30
*** noVNC has quit IRC06:37
*** shardy has joined #openstack-kolla06:37
*** chas has joined #openstack-kolla06:54
*** dardelean_ has joined #openstack-kolla07:00
*** dardelean_ has quit IRC07:03
*** jtriley has quit IRC07:06
*** pcaruana has joined #openstack-kolla07:08
*** livelace-link has joined #openstack-kolla07:10
openstackgerritJeffrey Zhang proposed openstack/kolla master: Testing in project jobs definition  https://review.openstack.org/50866107:14
openstackgerritJeffrey Zhang proposed openstack/kolla-ansible master: Move to zuul v3 in project jobs  https://review.openstack.org/50875907:18
*** nrado has joined #openstack-kolla07:22
*** dardelean_ has joined #openstack-kolla07:24
*** dardelean_ has quit IRC07:27
*** unicell1 has quit IRC07:29
*** rmart04 has joined #openstack-kolla07:33
*** jtriley has joined #openstack-kolla07:39
*** egonzalez has joined #openstack-kolla07:43
*** magicboiz has joined #openstack-kolla07:47
*** magicboiz has quit IRC07:53
openstackgerritMarcin Juszkiewicz proposed openstack/kolla master: cinder-api: handle Debian too  https://review.openstack.org/50881807:56
hrwmorning07:56
egonzalezmorning07:57
hrwegonzalez: can you review ^^?07:58
egonzalezJeffrey4l, is there any order to fix gates? this need to be merged first https://review.openstack.org/#/c/508376/ ?07:58
*** magicboiz has joined #openstack-kolla07:58
*** dardelean_ has joined #openstack-kolla07:59
*** dardelean_ has quit IRC08:00
*** dardelean_ has joined #openstack-kolla08:00
*** gfidente has joined #openstack-kolla08:07
*** gfidente has quit IRC08:07
*** gfidente has joined #openstack-kolla08:07
*** dougsz has joined #openstack-kolla08:16
nradoGood morning, is someone experienced with LBaaS v2 and the Octavia driver? I installed everything with source type (ubuntu + stable/ocata release).08:17
nradoBut the lbaas agents are not listed within the neutron agents and I'm getting this error in the lbaas-logs: https://gist.github.com/anonymous/553d786dc5284d70763157f9efd697e9.08:17
nradoIs this a known issue?08:17
*** Zophar has joined #openstack-kolla08:29
*** vincent_vdk has joined #openstack-kolla08:31
hrwegonzalez: that's why all gates fail?08:32
egonzalezhrw, yep, zuulv3 is not active and broke all our gates08:33
*** gkadam has joined #openstack-kolla08:33
egonzalezs/not/now08:33
hrwI just saw that inc0 and Jeffrey4l discussed it yesterday morning08:34
hrwtrying to catch up some stuff after linaro connect08:35
*** jtriley has quit IRC08:37
*** kbaegis has joined #openstack-kolla08:40
*** athomas has joined #openstack-kolla08:41
*** jascott1 has quit IRC08:44
*** jascott1 has joined #openstack-kolla08:44
*** jmccarthy has joined #openstack-kolla08:47
*** jascott1 has quit IRC08:49
*** jtriley has joined #openstack-kolla09:16
openstackgerritchao liu proposed openstack/kolla-ansible master: Add notes on docker version in quickstart and multinode guide  https://review.openstack.org/50879009:19
openstackgerritchao liu proposed openstack/kolla-ansible master: Add notes on docker version in quickstart and multinode guide  https://review.openstack.org/50879009:23
openstackgerritchao liu proposed openstack/kolla-ansible master: Add notes on docker version in quickstart and multinode guide  https://review.openstack.org/50879009:25
*** sambetts|afk is now known as sambetts09:28
*** yangyapeng has quit IRC09:29
*** yangyapeng has joined #openstack-kolla09:29
*** rmart04_ has joined #openstack-kolla09:30
*** rmart04 has quit IRC09:31
*** rmart04_ is now known as rmart0409:31
openstackgerritMerged openstack/kolla-ansible master: Add fluentd enable option  https://review.openstack.org/50071209:33
*** yangyapeng has quit IRC09:34
*** rmart04_ has joined #openstack-kolla09:38
*** rmart04 has quit IRC09:38
*** rmart04_ is now known as rmart0409:38
*** mdnadeem has quit IRC09:41
*** vbel has joined #openstack-kolla09:42
*** mdnadeem has joined #openstack-kolla09:44
vbelhello everyone, any designate experts? I wonder how to configure it safely. It need customer and instance facing interface which I think could be not that secure. I usually configure internal vip and let external router map ports instead of using internal/external haproxy/keepalived pairs. With designate it does not seem easy to use external router. All tutorials I have seen so far dealt with network_interface for designate09:46
*** kbaegis has quit IRC09:49
*** kbaegis has joined #openstack-kolla09:49
*** mdnadeem is now known as mdnadeem|afk09:49
vbelin another words, do I need to use neutron_external_interface with assigned public IP? The interface - does it have to be configured on controllers or/and network nodes. Network nodes already have such interface which does not have IP09:53
*** egonzalez has quit IRC09:55
*** mdnadeem|afk is now known as mdnadeem09:58
*** kbaegis has quit IRC10:01
*** kbaegis has joined #openstack-kolla10:14
*** duonghq has quit IRC10:15
*** jtriley has quit IRC10:20
*** tovin07_ has quit IRC10:21
*** kbaegis has quit IRC10:41
*** jtriley has joined #openstack-kolla10:45
*** kbaegis has joined #openstack-kolla10:45
*** jascott1 has joined #openstack-kolla10:46
*** pbourke has quit IRC10:50
*** pbourke has joined #openstack-kolla10:52
*** kbaegis has quit IRC11:01
*** dave-mccowan has joined #openstack-kolla11:07
Jeffrey4lwe can merge https://review.openstack.org/508661 this patch now ( need a fix), which moved to in-project-job.11:16
openstackgerritJeffrey Zhang proposed openstack/kolla master: Testing in project jobs definition  https://review.openstack.org/50866111:18
*** livelace has quit IRC11:18
*** dougsz has quit IRC11:23
*** egonzalez has joined #openstack-kolla11:24
*** mrunge has quit IRC11:24
*** mrunge has joined #openstack-kolla11:24
*** livelace has joined #openstack-kolla11:34
*** ansmith has joined #openstack-kolla11:36
*** rmart04_ has joined #openstack-kolla11:37
openstackgerritJeffrey Zhang proposed openstack/kolla-ansible master: Move to zuul v3 in project jobs  https://review.openstack.org/50875911:38
*** rmart04 has quit IRC11:39
*** rmart04_ is now known as rmart0411:39
*** rmart04_ has joined #openstack-kolla11:42
*** vincent_vdk has left #openstack-kolla11:42
*** rmart04 has quit IRC11:44
*** rmart04_ is now known as rmart0411:44
openstackgerritJeffrey Zhang proposed openstack/kolla master: Testing in project jobs definition  https://review.openstack.org/50866111:48
*** jtriley has quit IRC11:48
openstackgerritJeffrey Zhang proposed openstack/kolla-ansible master: Move to zuul v3 in project jobs  https://review.openstack.org/50875911:49
openstackgerritDan Ardelean proposed openstack/kolla-ansible master: Implement cinder-smb-hyperv ansible role  https://review.openstack.org/50853011:52
openstackgerritJeffrey Zhang proposed openstack/kolla master: Testing in project jobs definition  https://review.openstack.org/50866112:05
openstackgerritJeffrey Zhang proposed openstack/kolla-ansible master: Move to zuul v3 in project jobs  https://review.openstack.org/50875912:07
openstackgerritDan Ardelean proposed openstack/kolla-ansible master: [HyperV] Add pull and precheck actions to nova-hyperv role  https://review.openstack.org/50885812:08
*** jtriley has joined #openstack-kolla12:15
*** nrado1 has joined #openstack-kolla12:17
*** lpetrut has joined #openstack-kolla12:17
*** nrado has quit IRC12:20
*** ipsecguy has quit IRC12:26
*** mnasiadka has joined #openstack-kolla12:27
*** ipsecguy has joined #openstack-kolla12:27
*** rmart04 has quit IRC12:30
*** Zophar has quit IRC12:38
hrwhm. "--push" argument is my new find ;D12:39
mnasiadkaHello12:46
mnasiadkaIs there a plan to make some progress on https://review.openstack.org/#/c/505786/ ?12:46
mnasiadkaWithout that - the ubuntu/binary pike build is a bit broken with ceph ;)12:46
openstackgerritHonza Pokorny proposed openstack/kolla master: Add tripleo-ui image  https://review.openstack.org/50886912:52
hrwmnasiadka: I was at conference last week12:53
hrwmnasiadka: once gates get into working state again we can go for it12:53
* hrw -> food12:53
*** ipsecguy_ has joined #openstack-kolla12:54
*** rhallisey has joined #openstack-kolla12:55
*** ipsecguy__ has joined #openstack-kolla12:56
*** ipsecguy has quit IRC12:58
*** ipsecguy_ has quit IRC13:00
mnasiadkaso let me apply that patch on my env and see if it works13:00
*** erlon has joined #openstack-kolla13:11
*** ipsecguy has joined #openstack-kolla13:13
*** rmart04 has joined #openstack-kolla13:15
*** ipsecguy__ has quit IRC13:17
*** Zophar has joined #openstack-kolla13:22
*** mnasiadka has quit IRC13:23
*** noVNC has joined #openstack-kolla13:28
openstackgerritBertrand Lallau proposed openstack/kolla master: Move a release note generated in bad place  https://review.openstack.org/50887913:33
*** lucasxu has joined #openstack-kolla13:34
noVNCJeffrey4l, sup13:35
openstackgerritDan Ardelean proposed openstack/kolla-ansible master: [HyperV] Add pull and precheck actions to nova-hyperv role  https://review.openstack.org/50885813:39
Jeffrey4lsup noVNC13:42
*** noVNC has quit IRC13:43
openstackgerritJeffrey Zhang proposed openstack/kolla master: Testing in project jobs definition  https://review.openstack.org/50866113:44
openstackgerritJeffrey Zhang proposed openstack/kolla master: Testing in project jobs definition  https://review.openstack.org/50866113:45
*** goldyfruit has joined #openstack-kolla13:58
*** hachi has joined #openstack-kolla14:02
*** hongbin has joined #openstack-kolla14:08
openstackgerritJeffrey Zhang proposed openstack/kolla-ansible master: Move to zuul v3 in project jobs  https://review.openstack.org/50875914:16
*** nrado1 has quit IRC14:20
*** jamesbenson has joined #openstack-kolla14:38
*** jamesbenson has quit IRC14:43
*** rmart04_ has joined #openstack-kolla14:46
*** aagate has joined #openstack-kolla14:48
*** rmart04 has quit IRC14:49
*** rmart04_ is now known as rmart0414:49
*** dardelean_ has quit IRC14:53
jmccarthyHmm any magnum/ansible pros here ? :) In relation to proxy settings (have a corporate proxy to deal with) - any idea how to improve this here ? https://review.openstack.org/#/c/379862/1/doc/advanced-configuration.rst14:54
jmccarthyWhat I mean is to optionally set http_proxy, https_proxy, no_proxy from env to pass in as needed some way ?14:55
jmccarthyI mean maybe for example, if they are or are not defined in globals.yml some way possibly ?14:56
*** jamesbenson has joined #openstack-kolla15:11
*** rmart04 has quit IRC15:13
openstackgerritJeffrey Zhang proposed openstack/kolla master: Testing in project jobs definition  https://review.openstack.org/50866115:17
*** noVNC has joined #openstack-kolla15:19
*** rhallisey has quit IRC15:23
*** rhallisey has joined #openstack-kolla15:24
*** nrado has joined #openstack-kolla15:24
*** noVNC has quit IRC15:24
openstackgerritJeffrey Zhang proposed openstack/kolla-ansible master: Move to zuul v3 in project jobs  https://review.openstack.org/50875915:27
*** pcaruana has quit IRC15:27
*** dardelean_ has joined #openstack-kolla15:29
openstackgerritJeffrey Zhang proposed openstack/kolla master: [DNM]Test zuulv3  https://review.openstack.org/50891515:30
*** dave-mccowan has quit IRC15:32
*** dave-mcc_ has joined #openstack-kolla15:32
*** dardelean_ has quit IRC15:33
*** hachi has quit IRC15:35
*** Zophar has quit IRC15:40
*** jistr is now known as jistr|off|mtg15:48
*** jistr|off|mtg is now known as jistr15:49
*** egonzalez has quit IRC15:54
*** jascott1 has quit IRC15:58
spsuryaSydney Community Contributor Awards !!!15:59
spsuryahttps://openstackfoundation.formstack.com/forms/cca_nominations_syd15:59
spsurya============================================================15:59
spsuryaHello guys15:59
spsuryaPlease spare your two minutes to nominate super active helping from Kolla16:00
*** jemcevoy has joined #openstack-kolla16:00
spsuryaI did for few members from Kolla16:01
spsurya==========================================================16:01
openstackgerritMarcin Juszkiewicz proposed openstack/kolla master: kolla: do not mention arch specific images in --help  https://review.openstack.org/50892216:02
*** vhosakot has joined #openstack-kolla16:08
inc0good morning16:11
kolla-slack<britthouser> morning!16:11
openstackgerritMerged openstack/kolla-ansible master: fix wrong keystone_authtoken settings  https://review.openstack.org/50822016:13
hrwmorning inc016:13
*** dardelean_ has joined #openstack-kolla16:24
*** dardelean_ has quit IRC16:25
*** cocakolla has joined #openstack-kolla16:31
*** aagate has quit IRC16:34
inc0Jeffrey4l: still around? mind if I take over gate changes when you're asleep?16:36
Jeffrey4linc0, sure. please.16:36
inc0thanks, get some rest man16:36
inc0awesome job, but don't overtax yourself16:37
inc0kfox1111: fyi, kolla-ansible and kolla are almost moved to local zuulv3 files16:39
inc0https://review.openstack.org/#/c/508759/1116:39
Jeffrey4linc0, thanks.16:40
kfox1111inc0: cool.16:40
kfox1111I've almost unbroken the kolla-kubernetes gate. :/16:40
kfox1111the transition broke a lot of things. :(16:41
inc0ahh the chaos16:41
inc0ahh the mayhem of new CI platform16:41
inc0;)(16:41
hrw;)16:41
kfox1111it did thinkgs like convert all the jobs to ubuntu single node. :/16:41
inc0so no more multinode jobs?16:41
kfox1111I had to tag them properly to get them back to multinode.16:42
inc0when we'll be done with kolla and kolla-ansible16:42
kfox1111still isn't quite working though.16:42
inc0I'll help you there16:42
kfox1111k. thx.16:42
*** dave-mcc_ has quit IRC16:46
*** jascott1 has joined #openstack-kolla16:52
*** jamesbenson has quit IRC16:53
inc0guys I'm going to propose patch removing gates from project-config16:53
inc0that means before we're done with moving jobs to local kolla, we're without CI16:53
inc0so I think we need code freeze16:53
inc0for time being16:53
kfox1111why?16:54
*** jamesbenson has joined #openstack-kolla16:54
inc0running double jobs is nightmare16:54
SamYapleno gate no merge!16:54
hrwinc0: infra gates are broken for now anyway so go for it16:54
inc0right, zuulv3 wansn't nice for us16:55
SamYaplei just rewrote my gates16:55
inc0kfox1111: want me to do the same for k8s or just kolla and ansible16:55
SamYapleremoved legacy jobs and then wrote new gates16:55
inc0SamYaple: we have most of rewrite done16:55
kfox1111no. I think I almost got it working.16:55
inc0https://review.openstack.org/#/c/508759/1116:55
inc0https://review.openstack.org/#/c/508661/16:56
inc0SamYaple: ^ if you can review these, would be awesome16:56
SamYapleill rewrite ur face16:56
inc0somebody's cranky on Monday16:57
SamYaplejeez... a two hour gate?16:57
inc0normally it's ~20min16:57
SamYaplethe patchset has the timeout at 2 hours (5400)16:58
SamYaplenot a big deal just found it interesting16:58
SamYapleyea get the initial gates merged and ill update it with some ansibilized code16:58
inc0yeah, sometimes installation of stuff have hickup16:58
SamYapleinc0: i told Jeffrey4l the same thing, but feel free to rip off this https://review.openstack.org/#/c/508718/17:00
SamYapleesspecially the setup-gate part17:00
*** dklyle has joined #openstack-kolla17:00
inc0thanks, I'll do it as soon as we have functional gates;)17:01
*** jamesbenson has quit IRC17:01
jascott1o/17:01
*** gkadam has quit IRC17:01
inc0I was thinking of just including our site.yaml into run.yaml playbook17:01
inc0so isntead of running kolla-ansible deploy, do it from ansible too17:02
SamYapleyou totally could, but i would take it slow at first17:02
*** david-lyle has quit IRC17:02
inc0oh totally17:02
*** jamesbenson has joined #openstack-kolla17:02
*** mdnadeem has quit IRC17:02
*** cocakolla has quit IRC17:03
*** dardelean has joined #openstack-kolla17:07
openstackgerritChristian Berendt proposed openstack/kolla-ansible master: Move vmware password parameters to passwords.yml  https://review.openstack.org/50842217:07
*** dardelean_ has joined #openstack-kolla17:08
*** harlowja has joined #openstack-kolla17:10
*** dardelean_ has quit IRC17:12
inc0aaaand patch is proposed and mail is sent17:13
inc0we're in code freeze now folks;)17:13
inc0feel free to work on ongoing patches, but don't merge anything until we resolve CI crysis17:14
*** Croata has joined #openstack-kolla17:21
openstackgerritMichal Jastrzebski (inc0) proposed openstack/kolla master: Moving jobs to kolla repo  https://review.openstack.org/50866117:23
SamYapleinc0: just fyi zuul is down right now17:25
SamYaplethey are restarting and patching17:25
*** dardelean_ has joined #openstack-kolla17:26
inc0thanks for heads up17:26
SamYapleor it might be back up, but anyway its goign up and down17:26
inc0ah the joy, ah the happiness17:28
SamYaplethis is why i did all my work over the weekend when it was all dead :)17:28
*** cocakolla has joined #openstack-kolla17:36
openstackgerritCharlie Kang proposed openstack/kolla-ansible master: ovs-dpdkctl.sh function list_dpdk_nics only grabs the first nic  https://review.openstack.org/50531917:38
openstackgerritCharlie Kang proposed openstack/kolla-ansible master: ovs-dpdkctl.sh function list_dpdk_nics only grabs the first nic  https://review.openstack.org/50531917:38
*** dardelean_ has quit IRC17:42
*** shardy has quit IRC17:52
*** sambetts is now known as sambetts|afk17:54
*** lpetrut has quit IRC17:58
*** dklyle is now known as david-lyle18:06
*** rmart04 has joined #openstack-kolla18:09
*** hachi has joined #openstack-kolla18:10
*** rmart04 has quit IRC18:13
*** noVNC has joined #openstack-kolla18:20
*** chas has quit IRC18:23
*** jbadiapa_ has joined #openstack-kolla18:23
*** rhallisey has quit IRC18:23
*** jbadiapa has quit IRC18:25
*** itlinux has joined #openstack-kolla18:28
*** unicell has joined #openstack-kolla18:30
*** noVNC has quit IRC18:38
*** gfidente has quit IRC18:39
*** gfidente has joined #openstack-kolla18:51
*** gfidente has quit IRC18:51
*** gfidente has joined #openstack-kolla18:51
*** dave-mccowan has joined #openstack-kolla18:58
*** lpetrut has joined #openstack-kolla19:05
*** jmccarthy has left #openstack-kolla19:25
*** itlinux has quit IRC19:26
*** devananda has quit IRC19:28
*** hachi has quit IRC19:29
*** hachi has joined #openstack-kolla19:29
*** jascott1 has quit IRC19:33
*** jascott1 has joined #openstack-kolla19:34
*** dardelean_ has joined #openstack-kolla19:42
*** hachi has quit IRC19:46
*** dardelean_ has quit IRC19:47
*** hachi has joined #openstack-kolla19:47
*** noVNC has joined #openstack-kolla19:55
*** aolwas has joined #openstack-kolla20:03
*** MrNerdHair has joined #openstack-kolla20:12
*** dave-mcc_ has joined #openstack-kolla20:14
*** itlinux has joined #openstack-kolla20:14
MrNerdHairHey, I'd like to deploy OpenStack using Kolla on top of CentOS or Fedora Atomic Host. Can anyone point me in the right direction?20:15
inc0MrNerdHair: sure, I'd suggest starting with centos as we have playbooks to prep host for it20:16
*** dave-mccowan has quit IRC20:16
*** dave-mcc_ is now known as dave-mccowan20:17
inc0a bit unfortunate timing as we're in process of reworking our docs a lot, so now it's a bit chaotic, but let me walk you through20:17
inc01. You want to build your images20:17
MrNerdHairAtomic is already providing the Kubernetes cluster I want to deploy on, and I'm having a bit of trouble figuring out how to adapt the kolla-kubernetes bare metal deployment instructions20:17
inc0https://docs.openstack.org/kolla/latest/image-building.html20:17
inc0well kolla-k8s is different story;)20:17
MrNerdHair(can I just use the prebuilt ones from docker hub?)20:17
inc0well you still want images so ^ is available20:18
inc0I discourage that as they're very old20:18
inc0we're building publishing pipeline20:18
MrNerdHairah! was wondering about that b/c the version numbers didn't make a lot of sense20:18
inc0so soon dockerhub will have properly refreshed images, but that's in works20:18
inc0stick to building for now20:19
inc0so, you already have k8s, cool, you'll also need ceph or any other volume provider20:19
MrNerdHairlemme back up a bit20:20
inc0(also keep in mind that kolla-k8s is pre-1.0, so you might want to reconsider if you plan to use it for prod)20:20
MrNerdHair^^ that20:20
inc0for production, I'd suggest going for kolla-ansible..20:20
MrNerdHairI am (wanting to be) running OS on kolla on kubernetes on atomic on hyper-v.20:21
inc0add ".. managing hyper-v underneath" and you'll have perfect loop20:21
MrNerdHairI need to generate an artifact that deploys that whole stack automatically.20:22
MrNerdHairactually, that's exactly the idea20:22
inc0right, then you'll need more than that;) we don't have hyper-v in k8s just yet20:22
*** jascott1 has quit IRC20:22
inc0I know there was some work involved to make hyperv work with kolla-ansible20:23
MrNerdHairnot quite like that20:23
*** jascott1 has joined #openstack-kolla20:23
*** chas has joined #openstack-kolla20:23
MrNerdHairhyper-v runs atomic which runs nova which plugs into hyper-v and manages its VMs20:23
inc0https://github.com/openstack/kolla-ansible/blob/master/ansible/roles/nova-hyperv/tasks/install.yml20:23
*** athomas has quit IRC20:23
MrNerdHairthe atomic instance also runs magnum, which will spin up more atomic VMs as needed for linux containers20:24
inc0that's a cool stack20:24
MrNerdHairso the k8s never touches hyper-v20:24
MrNerdHaironly nova and neutron do (and maybe cinder? idk yet)20:25
inc0so one issue with kolla-k8s is that we don't have elegant orchestration to deploy20:25
inc0but we do have pretty good gating system, so you can disect what happens in gates20:25
*** jascott1 has quit IRC20:25
inc0that will involve a lot of bash-reading20:25
*** jascott1 has joined #openstack-kolla20:26
inc0but it's all bash that was proved over and over to deploy proper kolla-k8s20:26
MrNerdHairmy os cloud management plane runs on a kubernetes cluster backed by a etcd deployment, so the hope is that I can take another identically-configured machine, join the existing etcd cluster, and it will automagically integrate with the existing k9s and openstack deployments.20:27
inc0https://github.com/openstack/kolla-kubernetes/blob/master/tools/setup_gate.sh <- this is what is run in gates20:28
*** chas has quit IRC20:28
inc0yeah we had similar idea with k8s on top of ironic stack20:28
inc0I mean ironic deploys bare metal, stuff installs k8s on it and joins into cluster, openstack scales up20:28
inc0but that's...well... future20:29
MrNerdHairwith the end goal of having the whole deployment packed into a binary image, so that you just PXE boot a new node and it brings the whole thing up20:29
inc0^and that pxe can be run with ironic;)20:29
inc0so we were thinking of hacking around this stack during PTG 2 weeks ago20:30
MrNerdHaircrucially, though, the deployment procedure for an additional node is identical to the deployment procedure for the first... the only difference is that the new node gets given the X.509 certs to integrate with the existing cluster.20:30
inc0but you know..20:30
inc0anyway, what you want is 1. registry of kolla images20:30
MrNerdHairright, I can make that happen20:31
inc0(you can run it on k8s + nodeport for insecure registry)20:31
inc02. helm registry (simple http server)20:31
inc0then you just do helm install in correct order with waiting for stuff to finish20:31
MrNerdHairok, seems doable, will bing up tiller at the same time as the k8s cluster20:31
MrNerdHair3) ??? 4) profit20:31
inc0yeah, you'll need a lot of underpants20:32
*** gema has quit IRC20:32
MrNerdHairit looks like kolla-k8s has a bunch of python and stuff on top of the helm charts?20:32
inc0well not really, what it has is *a bunch* of helm charts20:33
inc0python/shell stuff on top of it is just to make building easeir20:33
inc0https://github.com/openstack/kolla-kubernetes/blob/master/tools/helm_build_all.sh <- like this20:34
MrNerdHairAll I need is keystone, glance, neutron, cinder, nova, horizon, barbican, magnum, and manila. I'm hoping I can figure out how to extract the charts for just those. I have no idea if that's practical though.20:36
inc0thats most of it really there20:37
inc0well, you'll need a driver for cinder too20:37
inc0so iscsi if you hate your data or ceph20:37
MrNerdHairstorage will be provided by hyper-v storage spaces (direct?)20:37
inc0ok that works20:37
inc0can k8s use this as volume provider too?20:38
MrNerdHairthe atomic VM will have a block device attached that is backed by storage spaces20:38
inc0what I'm sayin is kubectl pv create20:39
inc0lots of things (mariadb for example) in k8s is backed with pv20:39
inc0in kolla-k8s20:39
MrNerdHairhmm... gotta think about that. was planning on most stuff going into manila, but obv. that doesn't work there.20:40
inc0well you'll need some storage for database files, all I'm saying20:41
inc0and it won't hurt your k8s effort to have trusty volume provider either20:41
inc0on bright note, microsoft goes heavy on k8s now20:41
inc0so I wouldn't be surprised if k8s could use hyperv storage natively20:42
MrNerdHairjust for the management plane, though... they shouldn't grow much as the tenant stuff scales?20:42
inc0well depends, are you going to give same k8s for tenants as well?20:42
MrNerdHairyes, but magnum will handle that20:43
MrNerdHairso this cluster will be dedicated to management stuff20:44
MrNerdHairI can make iSCSI work... is it really that bad?20:44
MrNerdHair(I'm lookign through the k8s PV drivers)20:45
inc0well, if iscsi is just iface for netapp or sth, it's fine, but if it's for lvm, you have no replication for your data20:45
inc0so if server blows, it takes data with it20:46
inc0blows up that is;)20:46
inc0also there are some funky stuff with iscsi (or rather tgtd) + containers20:46
inc0solved in kolla, but you'd need to keep an eye on it20:47
inc0I personally don't know much about that tho, I like ceph too much to bother with iscsi20:47
MrNerdHairI can run the MS iSCSI target thing to expose the storage spaces magical cluster shared volume stuff, that would probably fix it20:47
inc0probably, yeah20:47
inc0dunno what happens when tgtd dies, but well20:48
MrNerdHairhmm... just had a thought. ceph is great if you don't run windows, but all my managment plane stuff isn't going to be running windows, it's going to be in atomic.20:48
MrNerdHairgonna have to mull on that for a while.20:49
inc0there are ways to deploy ceph on top of k8s, but I don't know them too well20:50
inc0https://rook.io/ stuff like this (although this one is kinda scary as it wraps ceph native code into golang)20:50
inc0I personally deploy my cephs with kolla-ansible20:50
inc0or ceph-deploy20:51
inc0anyway, ceph likes k8s and vice versa, so you can back your k8s and cinder (if you want) with it20:51
inc0anywya, so assuming you have k8s with pv driver20:52
inc0go through kolla-k8s docs20:52
*** gfidente has quit IRC20:52
inc0https://docs.openstack.org/kolla-kubernetes/latest/deployment-guide.html#step-3-deploying-kolla-kubernetes20:53
inc0and if you run into problems, try digging through gate code20:53
MrNerdHairI follow all that stuff until you have to start pip installing things20:53
inc0on your deploy node tho20:54
inc0you don't need to pip install stuff on nodes with k8s20:54
MrNerdHairon atomic I don't have access to python natively, so I'd have to put all this in a container that acts as the deploy node.20:54
inc0yeah that works20:54
MrNerdHairso I'm guessing it all uses kubectl and if that's hooked up right it will configure on the right cluster?20:55
inc0kubectl and helm, yeah20:56
MrNerdHairso what about the stuff about editing /etc/kolla/whatever? are those files on the deploy container or the cluster node or what?20:57
inc0deploy container20:57
inc0all that is in deploy container20:57
MrNerdHairso what do the network and neutron interface settigns even mean in that context?20:57
inc0well, based on that kolla-k8s will create configmaps20:58
*** chas has joined #openstack-kolla20:58
inc0which will be what matters20:58
inc0although docs with /etc/kolla stuff might be out of date20:59
inc0yup, it is20:59
MrNerdHairwhat machine are those the interface names for? the atomic host itself? and if so, what if the names are different when I bring up another atomic node and make it multimaster?20:59
inc0it's host machines, yes, neutron needs that for net-host stuff20:59
inc0kfox1111: ^ good question, how to tell init-container name of iface for different node?21:00
MrNerdHaira wrinkle here is that centos atomic uses "predicatable network interface names", which are not predictable for cloud VMs.21:00
*** dave-mccowan has quit IRC21:01
inc0https://github.com/openstack/kolla-kubernetes/blob/3765d05f6d5edcf950469a776b157d7f4d161899/tests/bin/setup_config_iscsi.sh#L27 <- you want this line instead of kolla-ansible gencontif21:01
inc0genconfig21:01
MrNerdHairI already had to fight cloud-init about that, because you can't fix that without changing the kernel arguments -_-21:01
kolla-slack<kfox1111> The iface name is in the config file.  The in it container find the ip associated with it.21:01
*** cocakolla has quit IRC21:02
inc0yeah, but can we specify iface name per node?21:02
inc0node1 - eth0, node2-ens321:02
*** cocakolla has joined #openstack-kolla21:02
*** cocakolla has quit IRC21:03
kolla-slack<kfox1111> Per node? Should be that different. But, I think there is an override file on the host that y oh can put the interface in.21:03
*** cocakolla has joined #openstack-kolla21:03
*** cocakolla has quit IRC21:03
*** hachi has quit IRC21:04
*** cocakolla has joined #openstack-kolla21:04
*** cocakolla has quit IRC21:04
*** cocakolla has joined #openstack-kolla21:05
*** cocakolla has quit IRC21:05
MrNerdHairgoing through these instructions, it seems like most of this procedure is just building a set of helm charts and then running a bunch of helm installs. That's exactly what i'd like it to be, but I'm not certain that nothing else in the procedure touches the actual k8s cluster.21:05
*** cocakolla has joined #openstack-kolla21:06
*** cocakolla has quit IRC21:06
MrNerdHairexcept maybe the kolla-ansible/tools/init-runonce bit? not entirely sure where the optional bits about cinder and lvm stop.21:06
*** cocakolla has joined #openstack-kolla21:06
*** cocakolla has quit IRC21:07
*** dciabrin has quit IRC21:07
*** cocakolla has joined #openstack-kolla21:07
*** cocakolla has quit IRC21:07
*** serlex has quit IRC21:08
inc0init-runonce shouldn't matter21:08
MrNerdHairphew21:08
inc0it';s just to create things like network or router21:08
*** cocakolla has joined #openstack-kolla21:08
*** cocakolla has quit IRC21:08
inc0it'll run neutron net-create for ya;)21:08
inc0to bootstrap somethign21:08
MrNerdHairyou can do that in horizon yourself though, right?21:09
*** cocakolla has joined #openstack-kolla21:09
*** cocakolla has joined #openstack-kolla21:10
*** cocakolla has quit IRC21:10
inc0sure21:10
*** cocakolla has joined #openstack-kolla21:10
MrNerdHairI'm hoping I can create a container that produces a set of helm charts as an artifact, and then another "deployment" container that just runs those helm charts. I can put the first container in my CI system and the second can be wrapped up into an OCI image and become part of my deployment package.21:11
*** cocakolla has quit IRC21:11
inc0that'd work21:11
*** cocakolla has joined #openstack-kolla21:11
MrNerdHairit wouldn't actually have any kolla-k8s stuff in it, just the kolla images, helm charts, and a script with a set of helm-install commands.21:11
*** cocakolla has quit IRC21:11
inc0well...that is kolla-k8s really;)21:12
*** cocakolla has joined #openstack-kolla21:12
inc0you'll also need something to create config files for nova and whatnot21:12
*** cocakolla has quit IRC21:12
inc0https://github.com/openstack/kolla-kubernetes/blob/3765d05f6d5edcf950469a776b157d7f4d161899/tests/bin/setup_config_iscsi.sh#L27 run this command and then run kolla-kubernetes res create configmap on them21:12
*** cocakolla has joined #openstack-kolla21:13
inc0https://github.com/openstack/kolla-kubernetes/blob/b195d41cf9b503e804041e3579144437e4c34654/tools/setup_dev_env.sh#L15621:13
*** cocakolla has quit IRC21:13
*** aagate has joined #openstack-kolla21:13
inc0which really is glorified kubectl create configmap --from-file blah21:13
MrNerdHairok, so to recap: hyper-v installs with an unattend.xml that launches a powershell script. PS script copies down the centos atomic image and a cloud-init ISO, and starts it as a VM. cloud-init sets up networking, and the run_cmd section brings up etcd using dns-sd (via a container that runs an avahi-to-dnsmasq proxy).21:15
MrNerdHairthen it starts flanneld, kubelet, kube-apiserver, kube-controller-master, kube-scheduler, and kube-proxy.21:15
MrNerdHairthen it checks to see if it's a new cluster, and if it is, it launches the prepackaged OCI container with the kolla-k8s artifacts in it.21:16
MrNerdHairthat brings up the openstack cluster, and the hyper-v nova, neutron, and cinder drivers find it via DNS or something maybe.21:18
MrNerdHairand then I can run TripleO on all that just to piss people off.21:19
inc0:D21:19
inc0so one thing there is different configuration per node (iface names?)21:19
inc0so you need to figure that one out21:20
inc0other than that, looks good21:20
MrNerdHair(of course, tripleO will be brought up using kolla-k8s on top of magnum, for good measure.)21:20
inc0I'd also love to see this container sometime21:20
MrNerdHairThe whole reason I'm doing this is that I trust Hyper-V's software TPMs.21:20
MrNerdHair(at least when you seal the HGS keys to the right PCRs.)21:21
inc0https://wiki.qemu.org/Features/TPM21:22
inc0just sayin'21:22
inc0anyway, I don't know much about it21:23
inc0or anything really21:23
MrNerdHairyeah, but hyper-v is actually super tiny, like under a meg. it's really the only bare metal hypervisor there is. the "management OS" is just another VM, and it can be restricted easily.21:23
MrNerdHairthe attack surface for a kvm or esxi solution is much bigger, and once you break out of the VM you own the platform.21:24
MrNerdHairin hyper-v, say you exploit a virtual driver vulnerability. well, the virtual drivers are all run on the managment OS... the *actual* hypervisor just shuttles data around.21:25
MrNerdHairso a compromise gets you code execution in an environment that can't read anything important.21:26
MrNerdHairthe vTPMs are tiny VMs too, with all the protections that affords, which is why I trust them more than any other platform's VM TPM solution.21:27
MrNerdHair(also Hyper-V server is free)21:27
inc0again, I'm ignorant, but thanks, good learning21:27
MrNerdHairnp. I like to contribute back too!21:28
MrNerdHairthanks for your help21:28
inc0no problem, feel free to ask if you run into hurdles21:28
MrNerdHairI'll probably whack at this more tomorrow. I'll maybe pop back on then21:29
kolla-slack<britthouser> Does Hyper-V has SELinux?21:30
MrNerdHairit's windows, so no :P21:31
MrNerdHairyou can run an SELinux shielded VM, though21:32
MrNerdHairthat prevents the managment OS from accessing the VM's memory or TPM data21:33
*** rhallisey has joined #openstack-kolla21:33
*** jascott1 has quit IRC21:33
*** jascott1 has joined #openstack-kolla21:33
MrNerdHairso at that point, you're a peer of the windows part of the system, and you get all the same security guarantees you might expect on a normal setup21:34
*** jascott1 has quit IRC21:35
*** itlinux has quit IRC21:36
MrNerdHairOh, yeah, the hyper-v hypervisor can enforce code integrity policies on the management OS kernel too :)21:36
MrNerdHairthat means you can create a signed list of all the hashes of any page of code that gets to be marked executable on the whole system, and not even a kernel compromise can change that21:37
*** itlinux has joined #openstack-kolla21:37
*** jascott1 has joined #openstack-kolla21:40
*** rhallisey has quit IRC21:42
*** lucasxu has quit IRC21:47
*** Croata has quit IRC21:49
*** lpetrut has quit IRC21:50
*** jascott1 has quit IRC21:50
*** jascott1 has joined #openstack-kolla21:51
*** jascott1 has quit IRC21:53
*** jamesbenson has quit IRC21:55
*** itlinux has quit IRC21:56
*** jascott1 has joined #openstack-kolla21:57
*** jascott1 has quit IRC22:02
*** jascott1 has joined #openstack-kolla22:02
*** jascott1 has quit IRC22:06
openstackgerritchao liu proposed openstack/kolla-ansible master: Add notes on docker version in quickstart and multinode guide  https://review.openstack.org/50879022:10
*** chas has quit IRC22:16
*** chas has joined #openstack-kolla22:18
*** jascott1 has joined #openstack-kolla22:20
*** jascott1 has quit IRC22:22
*** chas has quit IRC22:24
honzaI'm getting errors when building centos+source, it's complaining about missing "scsi-target-utils".  Ideas?22:35
honzaIt works fine in binary though which is weird.22:37
*** jascott1 has joined #openstack-kolla22:38
jascott1sbezverk ping22:39
honzaLooks like "scsi-target-utils" was removed in epel 7?22:40
*** fuegoel has joined #openstack-kolla22:42
*** nrado has quit IRC22:45
*** noVNC has quit IRC22:48
*** MrNerdHair has quit IRC22:54
*** dardelean_ has joined #openstack-kolla23:00
*** dardelean has quit IRC23:01
*** mrunge_ has joined #openstack-kolla23:05
*** mrunge has quit IRC23:07
openstackgerritKevin Fox proposed openstack/kolla-kubernetes master: Fixes for Kubernetes 1.8  https://review.openstack.org/50868223:22
*** hongbin has quit IRC23:30
*** jamesbenson has joined #openstack-kolla23:33
*** jamesbenson has quit IRC23:37
*** dardelean_ has quit IRC23:46
*** goldyfruit has quit IRC23:49

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!