Monday, 2020-03-23

*** rphillips has quit IRC00:39
*** rphillips has joined #openstack-kolla00:39
*** zhanglong has joined #openstack-kolla01:12
*** cah_link1 has joined #openstack-kolla01:32
*** xinliang has joined #openstack-kolla01:32
*** cah_link has quit IRC01:33
*** cah_link1 is now known as cah_link01:33
*** dking_desktop has joined #openstack-kolla01:38
*** xinliang has quit IRC01:42
*** pbing19 has quit IRC02:14
*** ricolin_ has joined #openstack-kolla03:46
*** ricolin_ has quit IRC04:17
*** hongbin has quit IRC04:20
*** kao112111 has quit IRC04:21
*** ykarel|away is now known as ykarel04:32
*** vishalmanchanda has joined #openstack-kolla04:58
*** dking_desktop has quit IRC05:26
*** evrardjp has quit IRC05:36
*** evrardjp has joined #openstack-kolla05:36
*** cah_link1 has joined #openstack-kolla05:59
*** cah_link has quit IRC06:00
*** cah_link1 is now known as cah_link06:00
*** e0ne has joined #openstack-kolla06:29
*** e0ne has quit IRC06:34
*** cah_link has quit IRC06:34
*** abdysn has joined #openstack-kolla06:45
*** e0ne has joined #openstack-kolla07:03
*** e0ne has quit IRC07:07
*** k_mouza has joined #openstack-kolla07:12
*** k_mouza has quit IRC07:16
*** e0ne has joined #openstack-kolla07:18
*** e0ne has quit IRC07:23
*** pbing19 has joined #openstack-kolla07:32
openstackgerritRajat Dhasmana proposed openstack/kolla master: Add nfs dependencies to glance container  https://review.opendev.org/71439107:37
*** dougsz has joined #openstack-kolla07:56
*** e0ne has joined #openstack-kolla07:57
*** dougsz has quit IRC08:00
*** bengates has joined #openstack-kolla08:04
hrwmnorning08:06
hrw746M    /opt/stack08:06
hrwdeployed with dev_mode08:06
*** jbadiapa has joined #openstack-kolla08:08
*** pbing19 has quit IRC08:09
*** bengates has quit IRC08:13
*** bengates has joined #openstack-kolla08:14
openstackgerritMarcin Juszkiewicz proposed openstack/kolla-ansible master: nova: support dev_mode for API bootstrap  https://review.opendev.org/71439308:16
openstackgerritMarcin Juszkiewicz proposed openstack/kolla-ansible master: nova-cell: for dev_mode it is 'nova'  https://review.opendev.org/71439408:17
*** pbing19 has joined #openstack-kolla08:17
*** cah_link has joined #openstack-kolla08:19
*** dougsz has joined #openstack-kolla08:20
cosmicsoundTASK [kibana : Wait for kibana port] this one is a killer08:23
*** ykarel is now known as ykarel|lunch08:31
*** pbing19 has quit IRC08:37
*** arxcruz|off is now known as arxcruz|rover08:37
*** ktibi has joined #openstack-kolla08:48
*** reph has joined #openstack-kolla08:50
*** rpittau|afk is now known as rpittau08:52
mnasiadkamorning08:54
yoctozeptohrw: good catches there!08:55
*** reph has quit IRC08:56
yoctozeptomorning hrw and mnasiadka (and possibly others)08:56
yoctozeptomnasiadka: I fixed ovn change, now needs some thorough reviewing08:56
mnasiadkayoctozepto: saw something over the weekend, thanks08:57
yoctozeptomnasiadka: I also created a lottery-mode change in https://review.opendev.org/71412308:57
patchbotpatch 714123 - kolla-ansible - WIP/DNM: geneve testing - 8 patch sets08:57
*** jonaspaulo has joined #openstack-kolla08:57
yoctozeptoyou can spin the wheel and randomly succeed or fail08:57
yoctozeptogood for testing your lotto luck08:57
yoctozeptono relevant errors, no relevant warnings, no nothing08:58
yoctozeptosometimes getting connectivity, sometimes not :D08:58
mnasiadkayoctozepto: net_mlx5: cannot load glue library: libibverbs.so.1: cannot open shared object file: No such file or directory08:58
mnasiadkayoctozepto: this is interesting I would say08:58
yoctozeptomnasiadka: who cares about infiniband here08:59
yoctozeptomnasiadka: ubu/deb do not have it, it's c8 thingy08:59
yoctozeptomnasiadka: happens on any run08:59
mnasiadkayoctozepto: I would be worries if it wouldn't happen on any run :D08:59
mnasiadka*worried09:00
mnasiadkayoctozepto: the success factor of this job - is it influenced by the nodepool provider we use?09:02
mnasiadkayoctozepto: in other words - is ovh worse than others, as usually? :D09:03
yoctozeptomnasiadka: you mean whether it's openly very hostile or not?09:03
hrwyoctozepto: would be nice to check is kolla_dev_mode directory usable in precheck but that overkill09:03
yoctozeptoack, lemme check09:03
yoctozeptohrw: we could run some job with dev mode, at least periodically09:03
yoctozeptoit went lame ;p09:03
hrwyoctozepto: it works09:07
hrwno need to create more and more weird ci checks09:07
hrwdo not be like nova where I send patch at 15:59 yesterday and still get some 3rdparty CI reports09:08
hrwyoctozepto: those dev_mode patches are more a signal than solution09:09
hrwboth need to be cleaned etc09:09
yoctozeptohrw: sure, no problem, and agreed it definitely should not be running on each change in 3 flavors...09:10
yoctozeptoI would add a periodic though on one of them09:11
yoctozeptoto have at least any insight into how well it behaves still ;p09:11
*** zhanglong has quit IRC09:11
yoctozeptomnasiadka: checked, no correlation present09:11
yoctozeptomnasiadka: rack/ovh both with successes and failures09:11
hrwmultitail++09:11
mnasiadkathen it's very interesting09:11
yoctozeptomnasiadka: agreed09:12
*** whoami-rajat has joined #openstack-kolla09:12
hrwyoctozepto: Deprecated: Option "api_servers" from group "glance" is deprecated for removal - nova change to do09:13
*** ykarel|lunch is now known as ykarel09:14
*** pbing19 has joined #openstack-kolla09:17
yoctozeptohrw: yeah, mnasiadka was on deprec hunt I believe09:17
hrwcpu_mode = none is fun09:19
hrwI have 4 instances running09:19
hrwall logless09:19
hrwand consoleless09:19
*** numans has joined #openstack-kolla09:22
*** reph has joined #openstack-kolla09:27
yoctozeptohrw: odd, this should be the 'easiest' for qemu09:28
hrwhttps://paste.centos.org/view/69e435fb09:28
hrwsimple qemu call ;D09:29
*** diga has joined #openstack-kolla09:32
hrwWARNING nova.virt.libvirt.driver [-] Running Nova with a QEMU version less than 4.0.0 is deprecated. The required minimum version of QEMU will be raised to 4.0.0 in the next release.09:37
hrwhm.09:37
*** e0ne has quit IRC09:39
*** e0ne_ has joined #openstack-kolla09:39
mnasiadkayoctozepto: yeah, I'll come back to that this week it seems09:46
mnasiadkaas long as my daughter will not want to play with me on ps4 whole day long09:46
yoctozeptomnasiadka: playing on switch is fine? :D09:47
mnasiadkayoctozepto: I have only ps4, fully occupied by a nearly-7-year-old...09:47
yoctozeptomnasiadka: you're just jealous!09:48
mnasiadkayoctozepto: of course I am, better to play than to deploy bloody ceph :)09:52
yoctozeptomnasiadka: nah, ceph always whispers: let's play a game :D09:53
*** ktibi_ has joined #openstack-kolla09:57
mgoddardmorning all09:58
*** ktibi has quit IRC10:00
*** k_mouza has joined #openstack-kolla10:00
openstackgerritMark Goddard proposed openstack/kolla stable/train: CentOS 8: Build bifrost image  https://review.opendev.org/71350910:10
openstackgerritMerged openstack/kolla master: Zun: add zun-cni-daemon image  https://review.opendev.org/70827310:16
*** dougsz has quit IRC10:19
*** reph has quit IRC10:20
*** dougsz has joined #openstack-kolla10:32
openstackgerritMark Goddard proposed openstack/kayobe master: CentOS 8: Enable overcloud upgrade job  https://review.opendev.org/71272310:33
*** reph has joined #openstack-kolla10:34
*** reph has quit IRC10:50
*** cah_link has quit IRC10:54
cosmicsoundgreets mgoddard10:56
mgoddardhey cosmicsound10:57
cosmicsoundhows going10:58
*** cah_link has joined #openstack-kolla11:02
mgoddardgood thanks. The sun is shining, always helps11:03
mgoddardYou?11:03
cosmicsoundsame here just had a walk in sun. now moving on with kolla testing11:05
hrwnova patch rewritten.11:20
*** ricolin_ has joined #openstack-kolla11:23
*** kplant has joined #openstack-kolla11:26
*** kplant has quit IRC11:26
*** sylar has joined #openstack-kolla11:28
*** sylar is now known as kplant11:28
*** cah_link has quit IRC11:28
*** e0ne_ has quit IRC11:32
*** e0ne has joined #openstack-kolla11:39
*** skramaja has joined #openstack-kolla11:40
openstackgerritMerged openstack/kolla-ansible master: cirros: upgrade to 0.5.1  https://review.opendev.org/71118211:41
hrwjuhu!11:42
*** evrardjp has quit IRC11:44
*** e0ne has quit IRC11:45
*** rpittau is now known as rpittau|bbl11:47
*** evrardjp has joined #openstack-kolla11:50
*** skramaja has quit IRC11:54
*** skramaja has joined #openstack-kolla11:54
hrwhm. I start to wonder how I did my work on 16GB of ram... 12/32 in constant use12:10
openstackgerritMerged openstack/kolla stable/train: CI: Install tox  https://review.opendev.org/71361612:10
openstackgerritMerged openstack/kolla-ansible stable/stein: CI: install tox  https://review.opendev.org/71361912:10
openstackgerritMerged openstack/kolla-ansible stable/rocky: CI: install tox  https://review.opendev.org/71362112:10
*** jimcrowleyibm has joined #openstack-kolla12:14
*** evrardjp has quit IRC12:27
*** e0ne has joined #openstack-kolla12:28
*** Fl1nt has joined #openstack-kolla12:34
Fl1ntGood afternoon everyone!12:34
*** cah_link has joined #openstack-kolla12:35
*** evrardjp has joined #openstack-kolla12:38
openstackgerritMark Goddard proposed openstack/kolla master: CentOS 8: Drop trickle install to build freezer  https://review.opendev.org/71163712:44
*** Abdallahyas has joined #openstack-kolla12:44
kplantany of you guys do ipv6 tenant networks in your clouds?12:47
*** abdysn has quit IRC12:47
osmanlicilegikplant: I used it for few weeks without any problem. the reason why I switched back to ipv4 is it's not possible to use dvr with ipv6.12:52
kplantdid you have to peer neutron with your upstream router?12:52
*** pbing19 has quit IRC12:55
*** Luzi has joined #openstack-kolla12:55
*** chrizl has joined #openstack-kolla12:55
*** Luzi_ has joined #openstack-kolla13:00
osmanlicilegikplant: In theory no, in practice yes :) If I understood correctly about your concern, I used ipv6-address-mode=slaac not to have conflicting issues with router.13:01
kplantwhat's what i was thinking of doing as a stop-gap13:01
*** Luzi has quit IRC13:01
kplantbut i think that'll require two NICs since the vlan for ipv6 will be different from the per-project vxlans for ipv413:02
osmanlicilegiI think so13:06
kplantokay, just making sure i wasn't over complicating this13:07
kplanti think the best solution is to do bgp between neutron and the upstream router13:07
kplantand then cut /64s for each project network13:07
kplanttoo bad we can't do dhcpv6-pd :-(13:07
*** rpittau|bbl is now known as rpittau13:08
osmanlicilegigood point. imho, bgp is a must for a problem free ipv6 network.13:08
kplanti think cloudnull and i were talking maybe a year ago about using bgp to eliminate the need for wasting IPs with neutron routers13:09
kplantand just routing through 1918 space13:09
kplantso it might be helpful there too13:10
kplantwasting IPv4 addresses*13:10
*** ykarel is now known as ykarel|away13:10
cloudnullthat was a long while back :D13:10
kplantyeah, at least a year i think13:12
*** sorin-mihai__ is now known as sorin-mihai13:12
*** zhanglong has joined #openstack-kolla13:17
*** gfidente has joined #openstack-kolla13:32
*** reph has joined #openstack-kolla13:36
*** TrevorV has joined #openstack-kolla13:38
*** gfidente is now known as gfidente|pto13:39
*** reph has quit IRC13:41
*** Luzi_ has quit IRC13:44
Fl1ntguys, let say I've got an interface named eno1.101 and that I set this interface as my neutron_external_interface, it will be linked to the br-ex, but are we OK that that interface shouldn't have an IP right?13:45
Fl1ntI want to use that NIC which is a vlan one, in order to create a flat network within my deployment.13:45
kplantthat interface should _not_ have an IP13:45
kplantif it does, it will become unreachable13:45
Fl1ntok, right, we're on sync so. thanks a lot!13:46
Fl1ntok, let me test something with the rocky k-a release so.13:46
*** sorin-mihai has quit IRC13:53
*** reph has joined #openstack-kolla13:54
mgoddardyoctozepto, hrw, mnasiadka: I'm going to propose some final rocky releases14:07
hrwgo for it14:08
*** noxoid has joined #openstack-kolla14:08
kplanthmmm does enable_neutron_provider_networks allow non-admins to attach instances to provider nets?14:13
Fl1nt@mgoddard, can you add swift multi-policies/multi-region from Alexis request? https://bugs.launchpad.net/kolla-ansible/train/+bug/184475214:13
openstackLaunchpad bug 1844752 in kolla-ansible train "Swift role does not deploy multi-policies ring files" [Medium,Fix released] - Assigned to Alexis Deberg (adeberg)14:13
mgoddardkplant: that's right14:14
kplantcrap14:14
kplantthanks14:14
mgoddard:)14:14
mgoddardFl1nt: I'm not a swift expert. Commit message suggests at least multi-policy14:16
mgoddardFl1nt: in general, kolla supports multiple regions: https://docs.openstack.org/kolla-ansible/latest/user/multi-regions.html14:17
mgoddardI don't know if we're missing something for Swift14:17
Fl1ntyep, but I worked with Alexis, (actually created the cloud platform from which this request come from) and it's implicit to the ring thing.14:17
Fl1ntnope, that little fix is doing everything14:17
Fl1ntas zone/region are embedded within ring files.14:18
Fl1ntat creation.14:18
Fl1ntso just that fix would be enough ^^14:18
*** hongbin has joined #openstack-kolla14:19
mgoddardthat's good14:20
Fl1ntthanks a lot!!14:20
mgoddardso for my understanding, would you include the ring files for all regions?14:20
Fl1ntyes, you need to include all ring files to14:20
Fl1ntso let say you have region 1 2 3 you'll have obj_[1:3] / container_[1:3] etc14:21
Fl1ntactually not, nevermind, I mixed things a bit. Swift rings aren't that easy to keep in mind ^^14:23
Fl1ntso14:23
Fl1ntif you have multiple policies14:23
Fl1ntP1 P2 P314:23
Fl1ntyou'll have obj_P1 obj_P2 etc ring files14:23
*** Trevor_V has joined #openstack-kolla14:23
mgoddardhmm. Maybe a cleaner solution would have been to configure the entire list rather than always having container.ring.gz etc14:24
Fl1ntwithin these policies ring file, you'll declare at build time with region and zone they handle ^^14:24
Fl1ntactually you need the default container.ring.gz as they're used and define your default policu14:24
openstackgerritMerged openstack/kayobe master: CentOS 8: Enable overcloud upgrade job  https://review.opendev.org/71272314:24
Fl1ntpolicy sorru14:25
Fl1ntsorry14:25
Fl1nt-_-14:25
Fl1nta completely clean solution would be to generate all rings and config from the disk creation (as you do it with kayobe If I'm not wrong).14:26
mgoddardthanks for the explanation :)14:27
*** TrevorV has quit IRC14:27
Fl1ntyou're welcome, honestly, swift ring management and building is a mess, I tend to use CEPH as backend as much as possible but some customers being... back in 90's and a little bit resistant... I sometimes need to deal with that ^^14:28
openstackgerritMerged openstack/kolla stable/train: CentOS 8: Enable hacluster and masakari images  https://review.opendev.org/71405514:31
openstackgerritMerged openstack/kolla-ansible stable/train: CI: CentOS 8: Enable Masakari job and periodics  https://review.opendev.org/71405914:31
openstackgerritMark Goddard proposed openstack/kayobe master: CI: Add overcloud host configure job  https://review.opendev.org/71027714:33
*** TrevorV has joined #openstack-kolla14:34
yoctozeptomgoddard: care to wait for mariadb fix?14:35
yoctozeptomgoddard: I *think* I could deliver today14:36
mgoddardyoctozepto: I think we should merge it after final release14:36
yoctozeptomgoddard: ok14:37
*** Trevor_V has quit IRC14:37
mgoddardwe can always direct people to stable/rocky14:37
yoctozeptomgoddard: yeah, right, I could break it14:37
yoctozeptoin some weird way14:37
mgoddardit happens14:37
mgoddardand it's quite a critical part14:37
yoctozeptothe codebase has drifted a considerable "bit"14:37
yoctozeptoyeah, agreed14:37
mgoddardas have mariadb versions14:37
*** Abdallahyas has quit IRC14:45
*** ricolin_ has quit IRC15:01
*** ricolin_ has joined #openstack-kolla15:01
openstackgerritRajat Dhasmana proposed openstack/kolla master: Add nfs dependencies to glance container  https://review.opendev.org/71439115:06
*** riuzen has joined #openstack-kolla15:06
*** evrardjp has quit IRC15:07
riuzenGot this error when execute command kolla-genpasswd. https://paste.ubuntu.com/p/KCNY5nRzR7/ whats wrong?15:08
*** evrardjp has joined #openstack-kolla15:11
hrwok, time to redeploy15:23
*** zhanglong has quit IRC15:30
yoctozeptohrw, mgoddard: https://review.opendev.org/71447515:30
patchbotpatch 714475 - project-config - Cache CirrOS 0.5.1 - 1 patch set15:30
mgoddardyoctozepto: nice job15:32
mgoddardone patch closer to infra-core15:32
yoctozeptomgoddard: haha, thanks ;p15:32
hrwcommented15:33
yoctozeptohrw: will we be doing aarch64 solely on 0.5.1?15:37
hrwyoctozepto: there is only one ver of cirros in k-a15:39
hrwon all 3 archs15:39
hrwI just not mentioned ppc64le one as we lack CI for it15:39
yoctozeptohrw: asked if we want to cache 0.4.0 for it, but I guess not, we can move kolla CI to any version and devstack probably does not care below Ussuri15:41
yoctozeptohrw: so 0.5.1 only it is15:41
hrwyep15:41
hrwif someone uses 0.4.0 on aarch64 then should stop15:41
*** KeithMnemonic has joined #openstack-kolla15:42
yoctozepto++15:42
*** dking_desktop has joined #openstack-kolla15:46
Fl1ntok, so, I've redeployed my neutron_external_interface without IP, from within the router I can ping the switch ip (GW) but I can't ping or ssh the instance, and yes, that instance got ICMP and SSH opened up to everyone just in case ^^15:48
Fl1ntweird thing is, my router qg interface got a 10.1.1.18/24 IP then the FIP is attached as a 10.1.1.123/32 is that normal?15:49
yoctozeptohrw: https://review.opendev.org/#/c/714481/115:50
patchbotpatch 714481 - project-config - Cache CirrOS 0.5.1 for AArch64 too - 1 patch set15:50
hrw+115:50
Fl1ntwhen I created my "FIP" network, I created it from the admin use admin panel>network15:51
Fl1ntthen15:51
Fl1ntnew network15:51
Fl1ntnetwork name <dummy>15:51
Fl1ntexternal network15:51
yoctozeptoFl1nt: yeah, they are /3215:51
Fl1ntflat from physnet115:51
Fl1ntattributed to admin tenant15:52
yoctozeptois 10.1.1.18 pingable?15:52
*** skramaja has quit IRC15:52
Fl1ntyes15:52
Fl1ntfrom within the router15:52
Fl1ntisn't the router suppose to handle some iptables rules?15:57
*** klindgren_ has joined #openstack-kolla16:03
*** klindgren has quit IRC16:03
hrwdeployment ends16:04
Fl1ntIs the br-int supposed to carry all my router interfaces? my qr and qg ports/interfaces are handled by the br-int which in turn is connected to the br-ex using the patch int-br-ex.16:05
Fl1ntIs that correct?16:05
Fl1ntI always thought my router should be connected to both br-ex (through qg interface) and to the br-int (through qr interface) the then itself connect to br-tun through peer between patch-tun <-> patch-int16:07
*** e0ne has quit IRC16:08
*** e0ne has joined #openstack-kolla16:08
*** pbing19 has joined #openstack-kolla16:12
hrwmeh, spawning instance takes ages...16:22
*** klindgren has joined #openstack-kolla16:24
*** klindgren_ has quit IRC16:25
yoctozeptoFl1nt: br-int is where most magic happens16:37
hrwGIWO$TGHWOT16:39
hrwone day I will store working globals.yml in safe16:39
hrw40 minutes for deploy, 3.5 minutes for 'sorry, failed to spawn'16:41
*** reph has quit IRC16:42
kplant(-:16:42
*** pbing19 has quit IRC16:43
*** iniazi has quit IRC16:46
yoctozepto;D16:46
*** iniazi has joined #openstack-kolla16:46
Fl1ntok, let's try something easier, I'll create a private network, that network is using vxlan underneath. then let's try to ping that machine from another node in that vxlan.16:47
*** cah_link1 has joined #openstack-kolla16:50
*** cah_link has quit IRC16:51
*** cah_link1 is now known as cah_link16:51
*** pbing19 has joined #openstack-kolla16:55
*** rpittau is now known as rpittau|afk17:08
*** diga has quit IRC17:10
*** bengates has quit IRC17:11
Fl1nthum... how do you test your private vxlan are working ?17:15
kplantdefine are working :-)17:18
kplantif you mean can pass traffic to L2 adjacent things, just add another instance to vxland17:18
kplantvxlan*17:18
*** cah_link1 has joined #openstack-kolla17:19
openstackgerritMark Goddard proposed openstack/kolla-ansible master: Fix kolla-ansible stop with heterogeneous hosts  https://review.opendev.org/71449617:21
*** cah_link has quit IRC17:22
*** cah_link1 is now known as cah_link17:22
openstackgerritMark Goddard proposed openstack/kolla-ansible master: Fix kolla-ansible stop with heterogeneous hosts  https://review.opendev.org/71449617:22
hrwmultinode without ceph should still work, right?17:23
kplanti think it just uses lvm17:23
kplantbut it's been a while since i've tested that17:24
mgoddardhrw: some caveats - glance filestore needs NFS or to only run on one host17:24
mgoddardalthough we set up single host by default17:24
Fl1ntFor now, I've a bunch of VM using 192.168.0.0/24 addresses, but my underlying neutron_tunnel_interface is eno1.32 with network 10.32.0.0/24.17:25
Fl1ntSo I'm looking for a way to jump onto my VMs from the hypervisor17:25
Fl1ntin order to test that my tunnels are working fine17:26
hrwmanaged to run tempest against k-a deployment and now wonder about adding second compute17:26
hrweven without shared storage17:26
hrwRan: 875 tests in 629.7935 sec.17:26
hrw - Passed: 56117:26
hrw - Skipped: 15817:26
hrw - Expected Fail: 017:26
hrw - Unexpected Success: 017:26
hrw - Failed: 15617:26
*** reph has joined #openstack-kolla17:26
hrwSum of execute time for each test: 6905.4520 sec.17:26
hrw156 ;(17:26
hrwtempest log is usual openstack one. close to useless17:27
Fl1ntcan I add a vnic from my hypervisor onto the linux bridge which the VMs tap are linked to ?17:29
*** reph has quit IRC17:31
*** reph has joined #openstack-kolla17:32
*** evrardjp has quit IRC17:36
*** evrardjp has joined #openstack-kolla17:36
*** pbing19 has quit IRC17:37
*** pbing19 has joined #openstack-kolla17:37
*** e0ne has quit IRC17:38
*** ktibi_ has quit IRC17:40
*** pbing19 has quit IRC17:43
*** pbing19 has joined #openstack-kolla17:43
*** TrevorV has quit IRC17:45
kplanthttps://docs.openstack.org/kolla-ansible/latest/reference/networking/provider-networks.html states "For provider networks compute hosts must have external bridge created and configured by Ansible tasks like it is already done for tenant DVR mode networking."17:47
kplantis that something k-a has? or do i need to do that on my own17:47
mgoddardkplant: it's the same requirement as on your network hosts - neutron_external_interface must exist17:48
kplanti figured as much, but for some reason i can't pass any traffic17:49
kplanti see the traffic egressing my interface with the vlan tag, and that's about it17:49
Fl1ntoh, so we end up within almost the same issue ^^17:50
Fl1ntI'm fighting since this morning with my external_network part of the install too.17:51
Fl1ntexcept that I'm stuck with FIP not working.17:51
* hrw off17:52
Fl1ntI even reinstall without DVR and Provider network just to be sure it's not something conflicting xD17:52
kplantFIP is fine for me17:52
kplantbut bridging a provider network directly to an instance, not so much17:53
Fl1ntso we have to opposite issue actually ^^17:53
Fl1ntmy provider network using this neutron_external_interface actually works fine ^^17:53
kplantintardesting17:55
*** riuzen has quit IRC17:56
Fl1ntso, my network node get a nic.vlanID interface as neutron_external_interface my compute nodes get something similar, all those nodes are attached to a switch that have vlanID access port for each nic of them all.17:58
Fl1ntthat switch is the gateway (10.1.1.254) for that external/provider network.17:59
Fl1ntwhen using it as a provider network (flat) it works18:00
Fl1ntwhen trying to use it as a FIP pool, it doesn't.18:00
mgoddardFl1nt: if the switch port is access mode, you want untagged on the host right?18:00
kplantmgoddard: ugh, my port descriptions were wrong on my switch18:01
kplantyou were absolutely right18:01
Fl1nt@mgoddard, sorry, they're trunked ports... my mistake, I'm looking at too many things today.18:03
Fl1ntso my nic is tagged on the host18:03
Fl1ntnot on OS18:03
mgoddardk18:03
openstackgerritJames Kirsch proposed openstack/kolla-ansible master: Add support for encrypting backend HAProxy traffic to Keystone service  https://review.opendev.org/71398618:05
Fl1ntso mistery amplify, I can't ping my vm private IP from the router... definitely something bad in between.18:18
*** e0ne has joined #openstack-kolla18:19
*** e0ne has quit IRC18:20
*** hongbin has quit IRC18:22
Fl1ntguys, where do you install your DHCP agent on host or controller/network node when _NOT_ doing DVR or provider network but only private vxlan and FIP?18:23
Fl1ntI did used my controllers.18:27
*** reph has quit IRC18:27
kplantyeah, same18:29
kplantif you don't have dedicated neutron nodes18:29
kplantcontroller18:29
Fl1ntI'm asking dumb question since an hours but this issue is just making me feel like if all I learned about OS networking wasn't right ^^18:31
Fl1nt@kplant, how are your IPTables within your router?18:32
*** k_mouza has quit IRC18:32
kplantwhat's your root problem? maybe i can help18:32
*** e0ne has joined #openstack-kolla18:32
Fl1ntI can't get my VMs to get a proper FIP, and those instances that get a private IP 192.168.0.0/24 can't be pingged from the router itself, but they correctly get IPs from DHCP namespace and DHCP namespace correctly send FIP address to the router that correctly put it on the vnic qrbalbal18:34
Fl1ntit's like my router is missing IPTables rules18:34
kplantcan your vms talk to each other on the vxlan?18:34
Fl1ntthat's the tricky part, I don't know how to try that18:37
Fl1ntcan I just add a new vnic to the linux bridge where the instances TAP are linked and then snif it ?18:38
kplantjust make two VMs on the same vxlan18:39
kplantand ping one from the other18:39
kplantand yes you can sniff with "ip netns <name> tcpdump -i blah blah"18:40
Fl1ntI can't access those VMs, they're on a private lan.18:40
kplantuse the console18:40
Fl1ntthe virsh one? or the vnc/spice one?18:40
kplantwhichever works for you18:40
Fl1ntcan't access spice/vnc, virsh console domID from within nova_libvirt just show the message about escape char ^^18:41
kplantoof18:41
*** k_mouza has joined #openstack-kolla18:41
Fl1ntyeah ^^18:41
kplantlet's talk about your neutron interface18:41
Fl1ntyep18:42
kplantis it a real interface or sub interface18:42
Fl1ntit's a real interface on the host18:42
Fl1ntvlan interface18:42
kplantwell18:42
kplantthat's a sub-interface :-)18:42
Fl1ntthat's a vnic yes18:42
kplantso you feed neutron a vlan interface which means you're already tagging18:42
Fl1ntyep18:43
kplantand mapping that to something like 'physnet1' ?18:43
Fl1ntexactly sir18:43
kplantand you're creating a flat provider network in openstack?18:43
kplantwith physnet118:43
Fl1ntyes18:43
kplantdid you test that vlan interface before your deploy?18:43
Fl1ntyes18:44
Fl1ntit work18:44
kplantwhen you created your router, can you see it in the arp table?18:44
kplantit should take some ip in the subnet you gave it18:44
Fl1ntyes18:44
Fl1ntand it's pingable and the GW switch too18:44
kplantsweet18:44
kplantand your security groups allow the types of traffic you want?18:45
kplantie: ssh18:45
Fl1ntyep ICMP and SSH from anywhere18:45
kplanthmm18:46
Fl1ntwhen I tcpdump the qr/qg nic, I see the 10.1.1.x -> 192.168.0.x request, but that doesn't go anywhere18:46
*** k_mouza has quit IRC18:46
Fl1nthence why I'm thinking about a missing flow or iptable rule18:47
kplantthat's weird18:47
kplantso how do you _know_ your instance is getting an address via dhcp18:47
Fl1ntvirsh on the compute node know about it on the dominfo and iface info18:48
kplantcan you ping it from your ip net namespace?18:49
kplant'ip netns <name> exec ping 192.168.0.x'18:49
Fl1ntnope18:49
kplantand this is just a vxlan?18:49
Fl1ntyes18:49
kplantlinuxbr, ovs?18:49
Fl1ntovs18:49
kplantdid you build tunnel interfaces on your nodes and specify them in globals.yml?18:50
Fl1ntyes18:50
kplanthah18:50
kplantit's hard for me to really go on much else without direct access to it18:50
Fl1ntyeah, don't worry, I'll finish to figure that out at some point ^^18:50
kplantvirsh console doesn't work?18:51
Fl1ntnope18:51
Fl1ntwell, it work as I get it18:51
Fl1ntbut I can't input anything except for escape chars18:51
Fl1ntok, you know what, I'll see that later on tomorrow morning :D that's enough headhashes for today ^^18:52
Fl1ntthanks a loooooot for your help @kplant18:52
kplanthey, one more thing18:52
Fl1ntyes sure18:52
kplantmake sure your instance is built with the correct options so serial console is working18:52
kplantor try something like centos7 generic cloud18:53
kplantjust to be sure18:53
Fl1ntthat's actually the image that I use ^^18:53
kplantO_O18:53
Fl1ntdon't get any journal neither on the instances once up and running... weird.18:54
kplantcan you paste your globals.yml when you get a chance?18:55
kplantsomething soudns very unhappy18:55
Fl1ntyep, I'll have it on tomorrow, I've closed the VPN for now ^^18:56
Fl1ntI'm more and more thinking about a nova issue actually18:56
kplantyeah honestly everything with neutron sounds pretty good18:56
Fl1ntwhat's weird is virsh thinking its VMs are up and running and I almost trust it as everything related to the VMs (nic/storage/etc) are their as expected.18:57
Fl1ntI'll try to make them launch a simple ISO to see if they boot up at least.18:57
kplanti would try to access the console immediately after the vm is started18:58
kplantsee if you catch any output18:58
Fl1ntI'll do that too18:58
Fl1ntmaybe at some point I'll try to redirect the TTYConsole to my own terminal.18:59
*** hongbin has joined #openstack-kolla19:18
*** ricolin_ has quit IRC19:24
cosmicsoundwhat most users here have OVS or ODL ?19:34
Fl1nt@kplant, solved... I'm just stupid...19:44
Fl1ntit ended up that I used a stale centos-7-generic image...19:44
Fl1nttested a cirros and it work like a charm.19:44
kplant:-)19:44
Fl1nt@cosmicsound, ovs19:44
Fl1ntso, all in all, I banged my head around my office all day long for a stupid non working image, I should have know that it didn't want from neutron at the begining of the day when I checked the router and that nothing strange happened and that my compute nodes where correctly receiving IPs from the DHCP namespace...19:46
Fl1ntwhat a wonderful day \o/19:46
*** vishalmanchanda has quit IRC19:46
*** reph has joined #openstack-kolla19:53
*** Fl1nt has quit IRC19:55
*** reph has quit IRC19:57
*** dougsz has quit IRC20:14
*** thatcher_ has joined #openstack-kolla20:30
*** e0ne has quit IRC20:31
*** thatcher_ has quit IRC20:34
*** thatcher_ has joined #openstack-kolla20:37
openstackgerritJames Kirsch proposed openstack/kolla-ansible master: Add support for encrypting backend HAProxy traffic to Keystone service  https://review.opendev.org/71398621:32
openstackgerritJames Kirsch proposed openstack/kolla-ansible master: Add support for encrypting backend Keystone HAProxy traffic  https://review.opendev.org/71398621:33
*** cah_link1 has joined #openstack-kolla22:20
*** noxoid has quit IRC22:20
*** cah_link has quit IRC22:21
*** cah_link1 is now known as cah_link22:21
*** ktibi_ has joined #openstack-kolla22:39
*** ktibi_ has quit IRC22:44
*** cah_link1 has joined #openstack-kolla23:18
*** cah_link has quit IRC23:20
*** cah_link1 is now known as cah_link23:20
*** mrunge has quit IRC23:30
*** mrunge has joined #openstack-kolla23:31
*** pbing19 has quit IRC23:43
*** jonaspaulo has quit IRC23:54

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!