Monday, 2017-10-09

mrhillsmanadil452100 you never want to shut down all the mariadb clusters at once00:10
mrhillsmanfind out which one is the master/lead node, and shut the other two down00:11
mrhillsmanthen you should be able to shutdown the lead node after a few moments00:12
mrhillsmanand start it back without any issues00:13
masbergood morning, has anyone deployed kolla5? I tried yesterday but was giving me errors, just wondering whether it is ready to use it or not00:20
adil452100<masber> maybe with the master branch you will have some chance to install it right00:21
adil452100<masber> The only thing I can say is it isn't yet production ready00:21
adil452100<masber> A lot of things don't work out of box00:22
adil452100<masber> You must troubleshoot a lot to get things working00:22
masberadil452100, I see, I got confused because I installed it using pip so I thought it was ready00:23
adil452100<masber> The PyPi package is full of bugs, don't use it if you want to save time00:23
adil452100<masber> use the master git version instead00:23
masberadil452100, I see, I will try again later, thank you00:24
adil452100<masber> for kolla and kolla-ansible00:24
adil452100<mrhillsman> thank you, you confirmed my thought00:25
SamYaplemrhillsman: just to clarify a bit, there is no master/lead in a galera cluster00:26
SamYaplehowever most clusters use haproxy loadbalancing with active/passive so ther eis one recieving all the reads and writes00:26
SamYaplemost openstack services these days no longer have deadlocks and can work with active/active writes00:26
mrhillsmanapologies, the one that is set as primary00:28
SamYaplemrhillsman: well again, not to be pedantic, but just to make sure people dont lose data, not the one thats set primary, the one with the most recent data00:29
SamYaplewhich is not neccessarily the one set primary in haproxy00:30
mrhillsmanhas the non -1 seqno00:30
SamYaplebecause that one could be down00:30
SamYaplemrhillsman: that only happens when its shutdown proerply00:30
SamYaplea running galera cluster has -100:30
SamYapleon all nodes00:30
mrhillsmanah ok00:32
*** dave-mccowan has joined #openstack-kolla00:36
*** hieulq has joined #openstack-kolla00:37
SamYaplemrhillsman: not trying to be pedantic, its just important for data integrity reasons :)00:38
mrhillsmanhaha, no worries00:41
mrhillsmanstupid interwebs went down for a moment00:42
mrhillsmancorrect comment adil452100 is that you never want to shut them all down at once if you want to avoid manual recovery00:45
mrhillsmanthere's quite a few articles re this online - http://galeracluster.com/documentation-webpages/restartingcluster.html - i have used this one before00:46
*** duonghq has joined #openstack-kolla00:47
mrhillsmanSamYaple better ^ ?00:49
SamYaplefor sure00:50
SamYaplejust trying to spread knowledge :)00:50
mrhillsmanno doubt ;)00:50
*** xinliang has joined #openstack-kolla01:05
*** zhenguo has joined #openstack-kolla01:06
*** tovin07_ has joined #openstack-kolla01:14
*** caowei has joined #openstack-kolla01:34
*** dave-mccowan has quit IRC01:49
adil452100Thank you guys01:54
adil452100<SamYaple> <mrhillsman> Is watcher horizon dashboard broken ?01:55
adil452100I have tried so many times today to add to the horizon container via globals.yml and kolla-ansible reconfigure without success01:56
adil452100The error displayed with : docker logs horizon is01:57
adil452100cp: cannot stat '/usr/lib/python2.7/site-packages/watcher_dashboard/local/enabled/_*[^__].py': No such file or directory01:57
*** caowei has quit IRC02:01
*** caowei has joined #openstack-kolla02:02
*** Pavo has joined #openstack-kolla02:03
openstackgerritJinxing Fang proposed openstack/kolla-ansible master: Remove discard configuration  https://review.openstack.org/50242202:05
*** zhangfei has joined #openstack-kolla02:41
mrhillsmanadil452100 have not tried using it02:42
mrhillsmani know that there was(are?) issues with horizon in pike02:42
* mrhillsman is running ocata02:42
adil452100Ok02:43
*** adil452100 has quit IRC02:57
*** daidv has joined #openstack-kolla03:14
*** Pavo has quit IRC03:19
*** Pavo has joined #openstack-kolla03:34
*** gkadam has joined #openstack-kolla03:35
*** mdnadeem has joined #openstack-kolla03:37
*** Pavo has quit IRC03:55
*** jaosorior has joined #openstack-kolla04:07
openstackgerritMerged openstack/kolla-ansible stable/pike: fix wrong keystone_authtoken settings  https://review.openstack.org/51032304:08
spsuryamorning all04:16
openstackgerritMerged openstack/kolla-ansible master: Remove discard configuration  https://review.openstack.org/50242204:29
*** coolsvap has joined #openstack-kolla04:42
*** ntpttr_laptop has joined #openstack-kolla04:48
*** ArminderSingh has quit IRC04:50
*** janki has joined #openstack-kolla04:53
*** ntpttr_laptop has quit IRC04:54
*** ArminderSingh has joined #openstack-kolla04:54
*** jascott1 has quit IRC05:15
*** jascott1 has joined #openstack-kolla05:16
*** jascott1 has quit IRC05:20
spsuryahonza: ping...05:21
spsuryaregarding this05:21
spsuryahttps://review.openstack.org/#/c/508869/05:21
*** jascott1 has joined #openstack-kolla05:31
spsuryacoolsvap: https://review.openstack.org/#/c/498332/05:53
spsuryacan you please review05:54
coolsvapspsurya: sure looking at it05:54
spsuryacoolsvap: saw your TC candidacy...that is nice :)05:56
coolsvapspsurya: can you add reference for your doc changes in https://etherpad.openstack.org/p/kolla-doc-restructure at bottom05:58
coolsvapso that its tracked and we do not have multiple changes for the same thing05:59
coolsvapthe current situation is I sometime get lost in doc changes06:01
coolsvapwhich is covering what and whether or not its duplicate06:01
spsuryacoolsvap: the PS i given is generic one not only specific to doc06:01
spsuryai changed in .sh file too06:02
openstackgerritjiangpch proposed openstack/kolla-ansible master: add zun-wsporxy into zun role  https://review.openstack.org/51041006:02
coolsvapagreed06:02
coolsvapit still has doc changes as well :) put it in others06:03
spsuryacoolsvap: thanks06:04
spsuryamay be later i will add another one with  https://etherpad.openstack.org/p/kolla-doc-restructure at bottom06:04
*** unicell has joined #openstack-kolla06:10
*** hachi__ has joined #openstack-kolla06:18
*** skramaja has joined #openstack-kolla06:21
*** unicell1 has joined #openstack-kolla06:22
*** unicell has quit IRC06:23
*** hachi__ has quit IRC06:30
*** hachi__ has joined #openstack-kolla06:30
*** unicell1 has quit IRC06:37
*** igordc has quit IRC06:48
*** igordc has joined #openstack-kolla06:50
*** genek has quit IRC06:53
*** serlex has joined #openstack-kolla07:03
*** pcaruana has joined #openstack-kolla07:08
openstackgerritChristian Berendt proposed openstack/kolla-ansible master: Restart services after a change in the external ceph configuration  https://review.openstack.org/50788807:16
openstackgerritChristian Berendt proposed openstack/kolla-ansible master: Add placement section to neutron.conf  https://review.openstack.org/50807507:17
*** yingjun has joined #openstack-kolla07:18
*** magicboiz has joined #openstack-kolla07:31
*** genek has joined #openstack-kolla07:34
openstackgerritJeffrey Zhang proposed openstack/kolla master: Use upgrade rather than create_schema for wather database  https://review.openstack.org/51042707:38
*** egonzalez has joined #openstack-kolla07:41
*** shardy has joined #openstack-kolla07:55
*** hrw has joined #openstack-kolla08:04
*** jascott1 has quit IRC08:07
*** jascott1 has joined #openstack-kolla08:08
*** Radziu has joined #openstack-kolla08:08
openstackgerritjiangpch proposed openstack/kolla-ansible master: Make haproxy proxy to the right glance_api backend  https://review.openstack.org/51043608:10
*** jascott1 has quit IRC08:12
*** dougsz has joined #openstack-kolla08:17
*** gfidente has joined #openstack-kolla08:35
*** hachi__ has quit IRC08:36
*** kbaegis1 has joined #openstack-kolla08:41
*** kbaegis has quit IRC08:43
*** Radziu has quit IRC08:45
*** jmccarthy has joined #openstack-kolla08:46
*** manheim has joined #openstack-kolla08:56
*** dciabrin has quit IRC09:12
*** athomas has joined #openstack-kolla09:14
*** dciabrin has joined #openstack-kolla09:31
*** yingjun has quit IRC09:31
*** blallau has joined #openstack-kolla09:48
*** egonzalez has quit IRC09:50
openstackgerritMerged openstack/kolla-ansible stable/ocata: Add ovs section in neutron lbaas configuration  https://review.openstack.org/50557109:59
*** egonzalez has joined #openstack-kolla10:03
openstackgerritjiangpch proposed openstack/kolla master: Fix horizon doesn't handle static files error  https://review.openstack.org/51046110:06
*** pbourke has quit IRC10:08
*** jascott1 has joined #openstack-kolla10:09
*** pbourke has joined #openstack-kolla10:10
*** tovin07_ has quit IRC10:13
*** duonghq has quit IRC10:15
openstackgerritChason Chan proposed openstack/kolla master: Add EC2API to Kolla providing images list  https://review.openstack.org/51046610:18
openstackgerritChason Chan proposed openstack/kolla-ansible master: Add EC2API to kolla-ansible supporting service list  https://review.openstack.org/51046810:21
*** genek has quit IRC10:25
*** daidv has quit IRC10:29
*** caowei has quit IRC10:32
*** zhangfei has quit IRC10:41
*** leeuwenrjj has joined #openstack-kolla10:43
*** lpetrut has joined #openstack-kolla10:43
leeuwenrjjHi, very short newbie question for building containers: Can I somehow select which OpenStack version I will build from packages? It looks like I can give any location for building from source10:45
leeuwenrjjBut not from packages10:45
*** hachi_ has joined #openstack-kolla10:51
hrwmorning10:52
hrwleeuwenrjj: stable/pike builds pike. stable/ocata builds ocata10:52
hrwleeuwenrjj: and they use latest packages available10:52
spsuryaleeuwenrjj: for ocata : 4.0.0 and for Pike : 5.0.010:53
leeuwenrjjYes, so if I want to build something older then the original kolla version. Then I would need to build from source? (We want to first migrate to containers and after that upgrade)10:53
spsuryaleeuwenrjj: IIUC you have build the images and want to run container10:54
openstackgerritMerged openstack/kolla-ansible master: Fluentd: remove apache record_transformer filter  https://review.openstack.org/50197410:54
openstackgerritMerged openstack/kolla-ansible master: Fluentd: fix Mariadb mysqld_safe log not match  https://review.openstack.org/50216910:55
hrwhandy command for checking multiarch containers: "docker run --rm mplatform/mquery debian"10:55
leeuwenrjjSo we currently run Kilo. So we want to move that first to containers and upgrade to pike when the components are containerized.10:56
hrwI wonder how good Kolla was during Kilo cycle.10:57
leeuwenrjjSo we need to deploy Kilo containers first and then do all the upgrades. Which should be a lot easier when the services are running in containers.10:57
leeuwenrjjAre there many specifics in the build process for the openstack version? I would assume changing the repo should be good enough. e.g. the config files will come from outside of the container during runtime in our case.10:58
*** magicboiz has quit IRC11:00
*** magicboiz has joined #openstack-kolla11:00
hrwleeuwenrjj: I do not know is Kolla able to build Kilo images11:02
*** jaosorior has quit IRC11:05
*** rhallisey_ has joined #openstack-kolla11:05
*** jaosorior has joined #openstack-kolla11:05
spsuryaleeuwenrjj: IIRC upgrade working Since newton11:11
*** kbaegis1 has quit IRC11:11
*** kbaegis has joined #openstack-kolla11:12
*** egonzalez has quit IRC11:19
*** jmccarthy has quit IRC11:19
manheimhrw I also tried to build. Kilo env but gave up...11:20
*** jmccarthy has joined #openstack-kolla11:20
openstackgerritMerged openstack/kolla-ansible master: Allow use of external ceph as cinder backup backend  https://review.openstack.org/51015311:22
*** egonzalez has joined #openstack-kolla11:26
openstackgerritMarcin Juszkiewicz proposed openstack/kolla stable/pike: base: use ceph/jewel on ubuntu  https://review.openstack.org/50578611:30
leeuwenrjjFYI: It looks like with a little edit in the docker file I can remove the Ocata reference and replace it by Kilo.11:34
*** coolsvap has quit IRC11:35
leeuwenrjjNot everything will build (e.g. keystone complains about barbican packages) but we happened to already upgrade keystone.11:35
*** shardy is now known as shardy_lunch11:40
nhlfrpbourke: hey. what's the status of https://blueprints.launchpad.net/kolla/+spec/mount-sources?11:40
nhlfrto get it implented, do we need to add the similar stuff like here https://review.openstack.org/#/c/454690/ to the other openstack components?11:41
*** sambetts|afk is now known as sambetts11:44
dasTorhi, just a short question, my deployment fails currently with: Restart fluentd container FAILED! => {"changed": false, "failed": true, "msg": "Unknown error message: Tag pike not found in repository docker.io/kolla/ubuntu-binary-fluentd"}11:44
dasTor docker images | grep fluent show that i already have the image: 192.168.0.21:5000/kolla/ubuntu-binary-fluentd                         5.0.0               b091562cc89011:45
dasTorwhy isn't kolla pulling it from my local registry?11:45
*** ansiwen[q] has joined #openstack-kolla11:46
nhlfrdasTor: what did you set in Docker options in /etc/kolla/globals.yml?11:49
nhlfrI mean, docker_registry and docker_namespace options11:49
dasTordocker_registry: "192.168.0.21:5000"11:50
dasTornothing else11:50
*** magicboiz has quit IRC11:52
nhlfrdasTor: ok. does your registry have valid ssl certificate? if not, did you specify it as an insecure registry in /etc/docker/daemon.json?11:52
dasTorwhen i tried before, it said The requested image does not exist: 192.168.0.21:5000/kolla/ubuntu-binary-fluentd:pike i did a kolla-build -b ubuntu and now i have this error11:52
dasTornhlfr, yes, i set it on the deploy host and all targets11:52
dasTorwhen i didn't it saiod something about https warning11:52
*** dave-mccowan has joined #openstack-kolla11:53
*** manheim has quit IRC11:53
*** manheim has joined #openstack-kolla11:53
*** dave-mcc_ has joined #openstack-kolla11:55
dasTorif i comment out: openstack_release: "pike"11:56
dasTor in globals.yml it still works, strange ....11:56
*** dave-mccowan has quit IRC11:58
pbourkenhlfr: it's been implemented piece by piece. not that many services are done yet tbh12:02
pbourkenhlfr: it's reasonably easy to add a service though if you need12:02
nhlfrpbourke: ok, fair enough. I will try to add neutron and kuryr soon12:04
pbourkenhlfr: cool, I had made a start on neutron if you want to use that as a starting point12:04
pbourkehttps://review.openstack.org/#/c/507547/12:04
*** kbaegis1 has joined #openstack-kolla12:04
*** kbaegis1 has quit IRC12:05
nhlfrpbourke: thanks!12:06
hrwhttps://review.openstack.org/#/c/508818/ - can someone +2/+W it? Makes cinder-api work on Debian. It is just s/['ubuntu']/['debian', 'ubuntu']/ change12:07
*** kbaegis has quit IRC12:08
hrwrecheck is in a queue12:08
spsuryahrw: done12:15
hrwthanks12:15
*** magicboiz has joined #openstack-kolla12:23
*** hachi_ has quit IRC12:27
*** genek has joined #openstack-kolla12:30
*** gkadam has quit IRC12:35
*** shardy_lunch is now known as shardy12:40
*** magicboiz has quit IRC12:49
*** manheim has quit IRC13:01
*** ansmith has joined #openstack-kolla13:02
*** magicboiz has joined #openstack-kolla13:05
hrwcan I also get some eyes on https://review.openstack.org/#/c/508340/ one? It moves from one Linaro repo to another as we restructured repositories to make two especially for Kolla use (one for master, one for Pike).13:10
hrwchanges only Debian13:10
hrwwe provide packages for both aarch64 and x86-6413:10
*** manheim has joined #openstack-kolla13:10
openstackgerritMerged openstack/kolla master: Add tripleo-ui image  https://review.openstack.org/50886913:15
*** mdnadeem has quit IRC13:16
*** skramaja has quit IRC13:18
*** janki has quit IRC13:18
*** janki has joined #openstack-kolla13:18
openstackgerritMick Thompson proposed openstack/kolla-ansible master: Add cinder-volume host configuration to support HA  https://review.openstack.org/51056613:21
lvdombrkrfolks, who use letsencrypt certeficates in kolla?13:23
lvdombrkri have question about certeficate renew13:23
openstackgerritPaul Bourke (pbourke) proposed openstack/kolla-ansible master: Add cinder-volume host configuration to support HA  https://review.openstack.org/51056613:30
openstackgerritMerged openstack/kolla-ansible master: [HyperV] Add pull and precheck actions to nova-hyperv role  https://review.openstack.org/50885813:34
*** dgonzalez has left #openstack-kolla13:39
*** janki has quit IRC13:42
openstackgerritPaul Bourke (pbourke) proposed openstack/kolla-ansible master: Add cinder-volume host configuration to support HA  https://review.openstack.org/51056613:43
*** Pavo has joined #openstack-kolla13:50
*** zhangfei has joined #openstack-kolla13:54
*** leeuwenrjj has quit IRC13:55
*** hrw has quit IRC13:58
*** david-lyle has joined #openstack-kolla14:08
openstackgerritMerged openstack/kolla master: cinder-api: handle Debian too  https://review.openstack.org/50881814:12
lvdombrkrfolks, who use letsencrypt certeficates in kolla?14:19
Pavomorning gents14:23
Pavolvdombrkr that is am amazing idea, if you figure it out please post a solution14:23
egonzalezlvdombrkr, looks like nobody uses them14:23
egonzalezor nobody in this chat at least14:24
*** aagate has joined #openstack-kolla14:27
*** serlex has quit IRC14:28
*** zhangfei has quit IRC14:28
*** ntpttr_laptop has joined #openstack-kolla14:39
*** ntpttr_laptop has quit IRC14:45
*** jmccarthy has left #openstack-kolla14:49
*** klindgren has joined #openstack-kolla15:35
*** rhallisey_ has quit IRC15:36
*** jgriffith_ is now known as jgriffith15:41
*** vhosakot has joined #openstack-kolla15:42
SamYaplelvdombrkr: i did when lets encrypt firstlanded, but i dont use kolla-ansible at the moment15:43
*** ntpttr_laptop has joined #openstack-kolla15:53
*** ntpttr_laptop has quit IRC15:53
*** zhubingbing__ has joined #openstack-kolla15:57
*** egonzalez has quit IRC15:58
*** jascott1 has quit IRC16:09
*** blallau has quit IRC16:12
*** dave-mcc_ is now known as dave-mccowan16:13
*** manheim has quit IRC16:22
*** lpetrut has quit IRC16:23
*** zhubingbing__ has quit IRC16:28
*** pcaruana has quit IRC16:32
*** jaosorior has quit IRC16:33
kfox1111second for https://review.openstack.org/#/c/507252/ please.16:33
*** jaosorior has joined #openstack-kolla16:33
*** jascott1 has joined #openstack-kolla16:34
*** jaosorior has quit IRC16:38
*** jaosorior has joined #openstack-kolla16:40
*** jaosorior has quit IRC16:53
*** dougsz has quit IRC16:59
*** harlowja has joined #openstack-kolla17:01
openstackgerritMathias Ewald proposed openstack/kolla-ansible master: Add sensu role  https://review.openstack.org/48836717:06
*** mewald has joined #openstack-kolla17:07
*** manheim has joined #openstack-kolla17:11
*** krtaylor_ has joined #openstack-kolla17:13
*** krtaylor has quit IRC17:14
*** manheim has quit IRC17:15
*** athomas has quit IRC17:16
*** krtaylor_ has quit IRC17:17
*** krtaylor has joined #openstack-kolla17:17
*** shardy has quit IRC17:18
*** Pavo has quit IRC17:24
inc0lvdombrkr: hey, I think someone floated idea of having letsencrypt generation built into kolla-ansible17:30
inc0I remember talking about it in PTH17:31
inc0PTG17:31
*** mgoddard has joined #openstack-kolla17:34
vhosakotyeah, I remember somebody mentioned letsencrypt at the PTG too.17:41
*** sambetts is now known as sambetts|afk17:45
*** mewald has quit IRC17:46
*** aagate has quit IRC17:54
*** jamesbenson has joined #openstack-kolla17:59
openstackgerritMerged openstack/kolla-kubernetes master: Remove the resolv.conf workaround  https://review.openstack.org/50725218:03
kfox1111rwellum: thx.18:07
kfox1111inc0: might have been tangential to one of our conversations.18:07
kfox1111k8s supports automatic letsencrypt.18:07
rwellumyw kfox111118:10
*** pcaruana has joined #openstack-kolla18:11
*** jamesbenson has quit IRC18:14
*** sambetts|afk has quit IRC18:17
*** mgoddard has quit IRC18:18
*** dciabrin has quit IRC18:19
*** sambetts_ has joined #openstack-kolla18:20
*** dciabrin has joined #openstack-kolla18:20
*** jamesbenson has joined #openstack-kolla18:24
*** serlex has joined #openstack-kolla18:29
*** aagate has joined #openstack-kolla18:50
inc0kfox1111: I think we can't really use it because we run haproxy instead of kube load balancers right?18:51
kfox1111if you fronted your haproxies with ingress, it would work.18:51
inc0well...we could modify haproxy tls to use certs18:51
inc0or that18:51
inc0right18:51
kfox1111I want to do that too.18:51
kfox1111Ideally, you would have 2 layers of tls.18:52
*** unicell has joined #openstack-kolla18:52
SamYapleinc0:  you can do letencrypt in kolla-ansible easily https://yaple.net/2016/07/10/letsencrypt-haproxy-and-auto-renewal/18:52
kfox1111the user facing termination would be the only thing with the main certs.18:52
SamYapleits a little outdated, but its pretty straightforward18:52
kfox1111then it would use local certs from that pod to the services.18:52
SamYapleyoull jsut want to have a letencrypt container running to serve requests18:52
kfox1111cool. :)18:52
kfox1111I'm really excited for the proposed wild card lets encrypt certs.18:53
harlowjahas anyone seen this one (and knows the issue) @ https://gist.github.com/harlowja/ce809a62d26dcc63b2b6e932c987de1e ?18:53
SamYaplekfox1111: yea i dont know how i feel about that. i like the idea, but wild-card certs are poor security18:54
SamYaplei suppose if you are just using it for encryption then its a good thing18:54
kfox1111yeah. its better not to use them, but...18:54
kfox1111its way better then using nothing...18:55
SamYapleharlowja: looks like very old libvirt version. what are you trying ot build?18:55
SamYaplekfox1111: agreed. ive been slowly cultivating certs for years18:55
kfox1111but when you have a nice seperation of ingress has the widcard, and backends don't, its a bit safer too.18:55
SamYapleive got ~600 unique certs18:55
kfox1111wow.18:55
kfox1111how often do you need to update one?18:55
SamYaple3 months18:56
kfox1111not too bad.18:56
SamYaplewell they have rate limits you know? so its better to get them in. because you can update as many as you want, but you cant create them all from scratch18:56
SamYapleyou get like 10 a week or something18:56
kfox1111the problem I have is no path from external to internal.18:56
kfox1111so I'd havve to place some web service externally to gather them,18:56
SamYapleso i have one for each service, nova-novncproxy.yaple.net neutron-server.yaple.net cinder-api.yaple.net etc18:57
kfox1111but do something more manual to get them inside. :/18:57
SamYaplehmm yea18:57
kfox1111a few wildcards would be much easier to transfer in,18:57
SamYaplei would just run an internal CA in that case18:57
kfox1111we do that. but I kind of hate it.18:57
SamYaplethen you could actually do client certs18:57
kfox1111it breaks the internet trust model.18:57
kfox1111cause the holder of that ca can spoof anybody.18:57
SamYapleoh please the current CAs break the trust model18:57
SamYaplehow many breaches exist?18:58
kfox1111some have. but they have also been kicked out.18:58
SamYaplethis is for internal environment anyway18:58
SamYapleif someone is already internal and has your CA, you would be screwed anyway18:58
kfox1111the line between internal/external is often fuzzy. :/18:58
*** lpetrut has joined #openstack-kolla18:58
SamYaplethey would have your wildcard cert and key anyway18:58
kfox1111no, its more nuanced then that.18:58
kfox1111say you work for a compay A, and you also work with collaboration B.18:59
kfox1111both self sign their certs and expect you to load in their CA's into your browser.18:59
kfox1111both could spoof your bank and other sites.18:59
kfox1111yeah, you could keep a whole seperate browser chain of trust for each org.18:59
kfox1111but what a pain.... :/19:00
kfox1111better if they just had a proper chain of trust.19:00
*** lpetrut has quit IRC19:00
SamYapleso they have hijacked your dns and have generated false certs19:00
SamYaplethere are bigger issues there19:01
*** lpetrut has joined #openstack-kolla19:01
kfox1111possible. but security is having many walls.19:02
kfox1111one of the collaborations I work with: https://www.opensciencegrid.org/ has a huge number of CA's in its own chain of trust.19:02
kfox1111if any of them has a breach, its a problem.19:02
kfox1111just seems like a bad idea to me. I think in general the main chain of trust is more secure then orgs.19:03
SamYaplei hear you. i fall on the otherside of that argument personally19:04
SamYaplebut i was more refering to a CA per environment for openstack19:04
kfox1111yeah...19:06
kfox1111I really wish there was a way to do a CA per subdomain.19:06
kfox1111not, here's a ca. lets trust it for the world.19:07
kfox1111that part of the internet's very broken.19:07
*** jrist has quit IRC19:07
SamYaplei like the idea of a blockchain "ca" where each domain is its own blockchain19:08
SamYapleyou could sync that fairly quickly19:08
kfox1111+119:09
kfox1111or, I think you could probably extend the dns security stuff to have a signed https ca record.19:09
SamYapleyou could have the lax and paranoid setting there too. sync blockchain everytime you query dns (for revocation) or more relaxed for speed19:10
kfox1111probably woudn't need any software at all, other then have the browsers do an extra dns lookup.19:10
SamYapleoh jeez. want to talk about internet being broken its dns19:10
kfox1111hehe.19:10
kfox1111yeah, well, thats a whole nother conversation. :)19:11
SamYapleup until recently 6 people could *independantly* destroy the internet19:11
SamYaplecrazy19:11
kfox1111indeed.19:11
*** dciabrin has quit IRC19:18
*** jrist has joined #openstack-kolla19:20
harlowjaSamYaple mitaka but perhaps that version is busted19:23
harlowjaanyway, if nobody else seen, that's ok, i'll figure it out :-P19:24
SamYapleharlowja: ah thats probably right for mitaka19:25
SamYaplebut thats so old you probably wont get much help for it19:25
SamYaplenewton is about to EOL, mitaka EOL'd 6 months ago19:25
harlowjaya, expected so19:25
harlowjasad fact is nobody can upgrade that i know of at the pace openstack releases things, ha19:26
*** manheim has joined #openstack-kolla19:40
*** manheim has quit IRC19:41
*** manheim has joined #openstack-kolla19:54
*** manheim has quit IRC19:55
SamYapleharlowja: no, i agree, but you are over 2 years behind now19:57
SamYaplemost larger companies skip releases so they have once a year upgrades19:58
*** manheim has joined #openstack-kolla20:05
*** manheim has quit IRC20:05
*** dciabrin has joined #openstack-kolla20:06
kfox1111yeah.... :/20:06
kfox1111I'm hoping once we get the kolla-kubernetes upgrade gates going,20:07
kfox1111to keep a copy of the mitaka deployment ones around, and the intermediary jobs,20:07
kfox1111so we can test a multi version upgrade.20:07
kfox1111start at mitaka, perform the upgrade jobs for each version up to trunk.20:08
*** pcaruana has quit IRC20:18
*** jamesbenson has quit IRC20:22
*** jamesbenson has joined #openstack-kolla20:22
*** jamesbenson has quit IRC20:23
*** jamesbenson has joined #openstack-kolla20:25
*** jamesbenson has quit IRC20:26
*** jamesbenson has joined #openstack-kolla20:27
*** rhallisey has quit IRC20:34
*** manheim has joined #openstack-kolla20:50
*** manheim has quit IRC20:50
*** hrw has joined #openstack-kolla20:56
*** erlon has joined #openstack-kolla20:57
*** ansmith has quit IRC20:58
*** jamesbenson has quit IRC21:00
*** jascott1 has quit IRC21:02
*** lpetrut has quit IRC21:11
*** jascott1 has joined #openstack-kolla21:15
*** jascott1 has quit IRC21:18
*** jascott1 has joined #openstack-kolla21:20
*** Pavo has joined #openstack-kolla21:29
openstackgerritEduardo Gonzalez proposed openstack/kolla master: Re-enable bifrost test_build  https://review.openstack.org/46501221:29
openstackgerritEduardo Gonzalez proposed openstack/kolla master: Re-enable bifrost test_build  https://review.openstack.org/46501221:32
*** serlex has quit IRC21:33
*** jamesbenson has joined #openstack-kolla21:35
*** jamesbenson has quit IRC21:38
*** manheim has joined #openstack-kolla21:42
*** manheim has quit IRC21:42
*** bmace has quit IRC21:44
*** bmace has joined #openstack-kolla21:45
*** ansmith has joined #openstack-kolla21:49
*** Pavo has quit IRC21:54
*** jamesbenson has joined #openstack-kolla22:00
*** jamesbenson has quit IRC22:02
*** jrist has quit IRC22:14
openstackgerritOpenStack Proposal Bot proposed openstack/kolla-kubernetes master: Updated from global requirements  https://review.openstack.org/50944322:24
*** jrist has joined #openstack-kolla22:35
*** gfidente has quit IRC22:35
*** manheim has joined #openstack-kolla22:52
*** dciabrin has quit IRC23:04
*** vhosakot has quit IRC23:05
*** vhosakot has joined #openstack-kolla23:05
*** MasterOfBugs has joined #openstack-kolla23:06
*** dciabrin has joined #openstack-kolla23:16
*** manheim has quit IRC23:41
*** MasterOfBugs has quit IRC23:45
*** manheim has joined #openstack-kolla23:48
*** jamesbenson has joined #openstack-kolla23:49
*** jtriley has joined #openstack-kolla23:52
*** jamesbenson has quit IRC23:53

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!