*** guozijn has joined #openstack-kolla | 00:15 | |
*** guozijn has quit IRC | 00:24 | |
*** factor has quit IRC | 01:02 | |
*** k_mouza has joined #openstack-kolla | 01:32 | |
*** whoami-rajat has joined #openstack-kolla | 01:35 | |
*** k_mouza has quit IRC | 01:36 | |
*** kplant has quit IRC | 01:56 | |
*** guozijn has joined #openstack-kolla | 01:57 | |
*** michaelbarkdoll has quit IRC | 02:16 | |
openstackgerrit | sunguangning proposed openstack/kolla-ansible master: Spelling mistake in manila.conf.j2 https://review.opendev.org/662123 | 02:24 |
---|---|---|
q[bline] | seems mariadb haproxy connection always fails on first run of deploy | 02:45 |
*** shyamb has joined #openstack-kolla | 02:51 | |
openstackgerrit | sunguangning proposed openstack/kolla-ansible master: Remove parameters from cinder.conf in the current version https://review.opendev.org/662127 | 03:00 |
*** guozijn has quit IRC | 03:14 | |
*** dave-mccowan has quit IRC | 03:15 | |
*** guozijn has joined #openstack-kolla | 03:24 | |
openstackgerrit | sunguangning proposed openstack/kolla-ansible master: Some parameters in glance.conf default section is useless 1. registry_host 2. cinder_catalog_info https://review.opendev.org/662129 | 03:25 |
shyamb | Hi | 03:27 |
*** guozijn has quit IRC | 03:27 | |
shyamb | Anyway good way to know docker run command for kolla based containers? | 03:27 |
*** JamesBenson has joined #openstack-kolla | 03:29 | |
openstackgerrit | sunguangning proposed openstack/kolla-ansible master: Some parameters in glance.conf default section is useless https://review.opendev.org/662129 | 03:29 |
*** guozijn has joined #openstack-kolla | 03:36 | |
*** shyamb has quit IRC | 04:09 | |
*** guozijn has quit IRC | 04:50 | |
q[bline] | anyone seen this from keystore? keystone.access_rules_config.backends.json [-] No config file found for access rules, application credential access rules will be unavailable.: IOError: [Errno 2] No such file or directory: '/etc/keystone/access_rules.json' | 04:58 |
q[bline] | keystone | 04:58 |
*** JamesBenson has quit IRC | 05:00 | |
*** pcaruana has joined #openstack-kolla | 05:00 | |
*** igordc has joined #openstack-kolla | 05:15 | |
*** absubram has joined #openstack-kolla | 05:35 | |
*** factor has joined #openstack-kolla | 05:37 | |
*** absubram has quit IRC | 05:50 | |
*** guozijn has joined #openstack-kolla | 05:50 | |
*** dteselkin has joined #openstack-kolla | 05:59 | |
*** radeks has joined #openstack-kolla | 05:59 | |
*** igordc has quit IRC | 06:01 | |
*** gdwornicki has joined #openstack-kolla | 06:01 | |
openstackgerrit | Krzysztof Klimonda proposed openstack/kolla-ansible master: Make fluentd-elasticsearch configuration more robust https://review.opendev.org/661747 | 06:03 |
*** radeks has quit IRC | 06:05 | |
*** radeks has joined #openstack-kolla | 06:10 | |
openstackgerrit | Chiawei Xie proposed openstack/kolla-ansible master: Add become for watcher config copying over https://review.opendev.org/662136 | 06:13 |
*** radeks_ has joined #openstack-kolla | 06:14 | |
*** radeks has quit IRC | 06:16 | |
*** radeks_ has quit IRC | 06:19 | |
*** radeks_ has joined #openstack-kolla | 06:20 | |
*** dteselkin has quit IRC | 06:21 | |
*** luksky has joined #openstack-kolla | 06:42 | |
openstackgerrit | Mark Goddard proposed openstack/kolla-ansible master: Spelling mistake in manila.conf.j2 https://review.opendev.org/662123 | 07:07 |
*** skramaja has joined #openstack-kolla | 07:21 | |
kklimonda | stackedsax: I'm working on rebasing https://review.opendev.org/#/c/548407 to stein and master and adding support for ubuntu/debian | 07:34 |
*** gdwornicki has quit IRC | 07:42 | |
kklimonda | btw, should I just rebase the review with my changes? | 07:43 |
hrw | kklimonda: do not rebase just for rebase, but if you change patch then rebase before sending for review | 07:46 |
kklimonda | hrw: yes, the plan is to actually add changes to make it work on ubuntu with stein and master - I just wasn't sure what are the rules for "hijacking" reviews | 07:50 |
*** priteau has joined #openstack-kolla | 07:53 | |
hrw | kklimonda: do master first. | 08:05 |
hrw | kklimonda: about hijacking... if last revision is old then it feels forgotten so just go for it | 08:07 |
kklimonda | hrw: I'll be pushing master only (not sure if it's even a candidate for backporting to stein anyway) but I have to get it to work primarily with stein for our deployment - working on master is to have this upstreamed, and avoid diverging too much | 08:08 |
hrw | ok | 08:08 |
*** dougsz has joined #openstack-kolla | 08:09 | |
*** k_mouza has joined #openstack-kolla | 08:17 | |
openstackgerrit | Chiawei Xie proposed openstack/kolla-ansible master: Add become for watcher config copying over https://review.opendev.org/662136 | 08:23 |
* hrw off | 08:25 | |
*** k_mouza has quit IRC | 08:27 | |
*** k_mouza has joined #openstack-kolla | 08:28 | |
*** k_mouza has quit IRC | 08:32 | |
*** k_mouza has joined #openstack-kolla | 08:33 | |
*** gfidente has joined #openstack-kolla | 08:44 | |
openstackgerrit | Chason Chan proposed openstack/kolla-ansible master: Fix the deploy guide build failed https://review.opendev.org/661879 | 09:00 |
openstackgerrit | Chason Chan proposed openstack/kolla-ansible master: Add a explanatory note for "placement_api_port" https://review.opendev.org/662164 | 09:06 |
kklimonda | stackedsax: was the plan for that patchset to "chain" haproxies? so that if local backend (non-encrypted) is not responding, we're sending it to another haproxy? | 09:18 |
kklimonda | mgoddard: perhaps you know more about how internal TLS was to be implemented? | 09:20 |
*** cah_link has joined #openstack-kolla | 09:22 | |
kklimonda | or is it just very incomplete at this stage, and the idea is to add per-backend certificates plus update configs to use them? | 09:22 |
*** cah_link has quit IRC | 09:28 | |
*** cah_link has joined #openstack-kolla | 09:34 | |
*** cah_link has quit IRC | 09:41 | |
kklimonda | hmm, going through the comments it seems that the idea is to have all traffic go haproxy, but I can't see how was that supposed to work even with the initial patch - haproxy is listening only on the VIP address | 09:47 |
kklimonda | how will this affect client address, if the request goes client -> haproxy -> haproxy -> backend? | 09:50 |
kklimonda | will X-Forwarded-For be correct? | 09:50 |
*** factor has quit IRC | 09:53 | |
*** cah_link has joined #openstack-kolla | 09:59 | |
*** cah_link has quit IRC | 10:20 | |
*** factor has joined #openstack-kolla | 10:37 | |
openstackgerrit | Krzysztof Klimonda proposed openstack/kolla-ansible master: Allow disabling insecure API endpoints https://review.opendev.org/548407 | 10:54 |
*** k_mouza_ has joined #openstack-kolla | 10:56 | |
*** k_mouza has quit IRC | 10:56 | |
*** guozijn has quit IRC | 11:00 | |
*** tonythomas has joined #openstack-kolla | 11:03 | |
*** dave-mccowan has joined #openstack-kolla | 11:10 | |
openstackgerrit | Chason Chan proposed openstack/kolla-ansible master: Fix the deploy guide build failed https://review.opendev.org/661879 | 11:21 |
*** guozijn has joined #openstack-kolla | 11:23 | |
*** kplant has joined #openstack-kolla | 11:24 | |
*** JangwonLee_ has joined #openstack-kolla | 11:33 | |
*** JangwonLee has quit IRC | 11:37 | |
*** k_mouza_ has quit IRC | 11:46 | |
*** k_mouza has joined #openstack-kolla | 11:47 | |
*** luksky has quit IRC | 11:48 | |
*** priteau has quit IRC | 12:01 | |
*** priteau has joined #openstack-kolla | 12:04 | |
*** tolisbar has joined #openstack-kolla | 12:20 | |
*** tolisbar has quit IRC | 12:22 | |
*** niceplace has quit IRC | 12:26 | |
*** goldyfruit has quit IRC | 12:28 | |
*** niceplace has joined #openstack-kolla | 12:29 | |
*** sshnaidm|off has quit IRC | 12:32 | |
*** skramaja has quit IRC | 12:33 | |
*** guozijn has quit IRC | 12:34 | |
*** guozijn has joined #openstack-kolla | 12:35 | |
*** priteau has quit IRC | 12:36 | |
*** sshnaidm has joined #openstack-kolla | 12:49 | |
*** priteau has joined #openstack-kolla | 13:00 | |
openstackgerrit | Chason Chan proposed openstack/kolla-ansible master: Add deploy guide stuff to irrelevant file list of zuul https://review.opendev.org/662209 | 13:11 |
*** happyhemant has joined #openstack-kolla | 13:16 | |
openstackgerrit | Chason Chan proposed openstack/kolla-ansible master: Fix the deploy guide build failed https://review.opendev.org/661879 | 13:16 |
openstackgerrit | Taeha Kim proposed openstack/kolla master: Add RHEL subscription registration https://review.opendev.org/495148 | 13:18 |
openstackgerrit | Krzysztof Klimonda proposed openstack/kolla-ansible master: Make fluentd-elasticsearch configuration more robust https://review.opendev.org/661747 | 13:19 |
*** priteau has quit IRC | 13:23 | |
*** pcaruana has quit IRC | 13:23 | |
openstackgerrit | Krzysztof Klimonda proposed openstack/kolla-ansible master: Add support for elasticsearch TLS and authentication in fluentd https://review.opendev.org/662215 | 13:28 |
*** goldyfruit has joined #openstack-kolla | 13:29 | |
openstackgerrit | Zijian Guo proposed openstack/kolla-ansible master: Fix the document of external ceph for gnocchi https://review.opendev.org/662220 | 13:43 |
*** pcaruana has joined #openstack-kolla | 13:47 | |
*** dciabrin has joined #openstack-kolla | 13:47 | |
*** dciabrin_ has quit IRC | 13:50 | |
*** luksky has joined #openstack-kolla | 14:09 | |
openstackgerrit | Pierre Riteau proposed openstack/kolla-ansible stable/queens: Upgrade identity v2 to identity v3 API https://review.opendev.org/662230 | 14:10 |
*** k_mouza has quit IRC | 14:13 | |
*** k_mouza has joined #openstack-kolla | 14:17 | |
*** JamesBenson has joined #openstack-kolla | 14:26 | |
*** k_mouza has quit IRC | 14:26 | |
*** dpawlik has quit IRC | 14:29 | |
*** k_mouza has joined #openstack-kolla | 14:35 | |
*** k_mouza has quit IRC | 14:35 | |
*** k_mouza has joined #openstack-kolla | 14:35 | |
*** itlinux has quit IRC | 14:48 | |
*** iclon_ has joined #openstack-kolla | 15:00 | |
*** guozijn has quit IRC | 15:02 | |
*** iclon__ has quit IRC | 15:02 | |
*** zbr_ has joined #openstack-kolla | 15:07 | |
*** zbr has quit IRC | 15:09 | |
*** absubram has joined #openstack-kolla | 15:14 | |
*** guozijn has joined #openstack-kolla | 15:24 | |
*** pcaruana has quit IRC | 15:33 | |
*** luksky has quit IRC | 15:41 | |
*** itlinux has joined #openstack-kolla | 15:46 | |
stackedsax | kklimonda: I've only started reading through the patchset myself, so I'm hardly an authority | 16:09 |
kklimonda | welp :) | 16:10 |
stackedsax | but I thought the non-encrypted network was to be disabled entirely, no? | 16:10 |
stackedsax | what you're describing seems like what I'd expect based on what was describrd to me about the approach | 16:11 |
kklimonda | stackedsax: with TLS enabled, openstack services are all running over https but the TLS termination is always done by haproxy, and not backends | 16:11 |
*** JamesBenson has quit IRC | 16:11 | |
stackedsax | ah, right. Yeah this was what I was wondering about, too | 16:11 |
stackedsax | on a call at the moment... | 16:11 |
kklimonda | so haproxy connects to the local backend over http (and 127.0.0.1) and if that backend is down, the request is forwarded to another haproxy | 16:12 |
kklimonda | if we want to disable internal (non–encrypted) network, then all services must be either configured to listen on localhost, or their port changed. | 16:15 |
kklimonda | for now I've changed haproxy configuration so that it's listening on "public" network, otherwise it would steal the port from the backend. | 16:16 |
kklimonda | there is also a question of how to support non-http services like mariadb, memcached and rabbitmq - until they are configured with TLS, we can't remove the internal network I think | 16:16 |
*** luksky has joined #openstack-kolla | 16:33 | |
*** k_mouza_ has joined #openstack-kolla | 16:37 | |
*** k_mouza has quit IRC | 16:41 | |
*** k_mouza_ has quit IRC | 16:42 | |
*** dougsz has quit IRC | 16:42 | |
*** ivve has quit IRC | 16:43 | |
*** mgoddard has quit IRC | 16:44 | |
*** mgoddard has joined #openstack-kolla | 16:46 | |
*** ivve has joined #openstack-kolla | 16:58 | |
*** goldyfruit has quit IRC | 16:58 | |
*** goldyfruit has joined #openstack-kolla | 16:59 | |
*** mgoddard has quit IRC | 17:00 | |
*** mgoddard has joined #openstack-kolla | 17:02 | |
*** happyhemant has quit IRC | 17:05 | |
*** guozijn has quit IRC | 17:09 | |
*** goldyfruit has quit IRC | 17:14 | |
*** goldyfruit has joined #openstack-kolla | 17:14 | |
*** gfidente is now known as gfidente|afk | 17:32 | |
*** absubram has quit IRC | 17:52 | |
*** jonaspaulo has joined #openstack-kolla | 17:56 | |
*** jschluet has quit IRC | 18:19 | |
*** pcaruana has joined #openstack-kolla | 18:24 | |
*** jschlueter has joined #openstack-kolla | 18:40 | |
*** JamesBenson has joined #openstack-kolla | 18:43 | |
*** JamesBenson has quit IRC | 18:48 | |
*** jschlueter has quit IRC | 19:15 | |
*** kplant has quit IRC | 19:27 | |
*** k_mouza has joined #openstack-kolla | 19:32 | |
*** k_mouza has quit IRC | 19:36 | |
*** tonythomas has quit IRC | 19:38 | |
*** jschluet has joined #openstack-kolla | 19:40 | |
*** jschluet has quit IRC | 19:49 | |
*** igordc has joined #openstack-kolla | 19:49 | |
*** igordc has quit IRC | 19:50 | |
*** JamesBenson has joined #openstack-kolla | 19:55 | |
*** JamesBenson has quit IRC | 19:55 | |
*** JamesBenson has joined #openstack-kolla | 19:56 | |
*** igordc has joined #openstack-kolla | 20:00 | |
*** jschluet has joined #openstack-kolla | 20:03 | |
*** radeks has joined #openstack-kolla | 20:05 | |
*** radeks_ has quit IRC | 20:06 | |
*** dteselkin has joined #openstack-kolla | 20:10 | |
*** factor has quit IRC | 20:14 | |
*** radeks has quit IRC | 20:27 | |
q[bline] | I tried kolla-ansible with stein and rocky; in rocky, mariadb can't form a cluster and in stein keystore fails connections; any recommendations? My next stop is openstack-ansible | 20:46 |
openstackgerrit | Michal Nasiadka proposed openstack/kolla master: Ceph: Update to Nautilus on CentOS and OracleLinux https://review.opendev.org/657989 | 20:52 |
q[bline] | is there an alternative to keystore? | 20:57 |
*** pcaruana has quit IRC | 21:18 | |
*** itlinux has quit IRC | 21:23 | |
*** whoami-rajat has quit IRC | 21:24 | |
q[bline] | OK, keystone freakin worked this last run; so happy. | 21:30 |
*** unicell has joined #openstack-kolla | 21:43 | |
*** JamesBenson has quit IRC | 22:02 | |
*** luksky has quit IRC | 22:16 | |
*** goldyfruit has quit IRC | 22:17 | |
*** jonaspaulo has quit IRC | 22:22 | |
*** itlinux has joined #openstack-kolla | 22:42 | |
*** goldyfruit has joined #openstack-kolla | 22:52 | |
*** iclon__ has joined #openstack-kolla | 23:00 | |
*** iclon_ has quit IRC | 23:03 | |
*** JamesBenson has joined #openstack-kolla | 23:03 | |
*** JamesBenson has quit IRC | 23:07 | |
*** unicell has left #openstack-kolla | 23:31 | |
q[bline] | anyone know if I need to run reconfigure to add a ceph.conf override or can I just rerun the deploy? | 23:38 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!