Monday, 2020-03-30

blinethat did work yankcrime, thanks00:33
*** negronjl has quit IRC00:46
*** JangwonLee_ has quit IRC00:47
*** JangwonLee has joined #openstack-kolla00:48
*** negronjl has joined #openstack-kolla00:48
*** yingjun has joined #openstack-kolla01:05
*** yingjun has quit IRC01:05
*** zhanglong has joined #openstack-kolla01:32
*** zhanglong has quit IRC01:36
*** zhanglong has joined #openstack-kolla01:38
*** ricolin_ has joined #openstack-kolla02:22
*** ricolin_ has quit IRC02:31
*** vishalmanchanda has joined #openstack-kolla03:24
*** zhanglong has quit IRC03:28
*** zhanglong has joined #openstack-kolla03:28
*** evrardjp has quit IRC04:03
*** dave-mccowan has quit IRC04:06
*** evrardjp has joined #openstack-kolla04:10
*** zhanglong has quit IRC04:27
*** zhanglong has joined #openstack-kolla04:28
*** evrardjp has quit IRC04:36
*** evrardjp has joined #openstack-kolla04:36
*** Tony31 has joined #openstack-kolla04:50
*** ykarel|away is now known as ykarel04:50
Tony31morning :)04:50
*** skramaja has joined #openstack-kolla05:02
*** JHTUI has joined #openstack-kolla05:18
JHTUIQuestion to anyone out there.  With Kolla Train, has anyone gotten Octavia to work in a multi-node cluster?  I can get it to the point it spins up the amp instances for the LB, but the heartbeat fails with the compute nodes unable to communicate to the amp instances and the openstack loadbalancer command fails. How does one get around this?05:20
*** ykarel is now known as ykarel|afk05:21
*** cah_link has joined #openstack-kolla05:25
JHTUIit keeps failing with no route to host, despite having the API interface specified that works with other modules.  security groups set up, opened up 5555 and the other ports, even did port 1-65535 both ways for giggles, attached a floating IP to the amp instances, the haproxy spins up fine on them, no errors in the containers.  The issue isentirely05:25
JHTUIthe controllers can't communicate. to the amp instances.  Boggles me.05:25
*** e0ne has joined #openstack-kolla05:38
*** ykarel|afk is now known as ykarel05:40
*** e0ne has quit IRC05:43
*** skramaja_ has joined #openstack-kolla06:01
*** skramaja_ has quit IRC06:02
*** skramaja_ has joined #openstack-kolla06:02
*** skramaja has quit IRC06:05
*** JHTUI has quit IRC06:18
*** e0ne has joined #openstack-kolla06:20
*** e0ne has quit IRC06:24
*** JHTUI has joined #openstack-kolla06:27
*** zhanglong has quit IRC06:30
*** zhanglong has joined #openstack-kolla06:34
Tony31hi JHTUI - no route to host means it may not be able to receive ARP response.. From the ansible host as well as all the nodes, can you ping all the nodes and the ansible host?06:35
Tony31@JHTUI06:35
*** Tony31 has quit IRC06:46
JHTUIyes can ping the nodes fine, in fact once I attach floating ip's I can ssh into the containers06:49
JHTUIthe octavia worker node just doesn't seem to be able to do the heartbeat/connectivity06:50
JHTUIset the amp network to the API network, verified the security works on the amps as adding port 22 allowed sshing into them, and when on the arp containers checking the logs on the containers showed the service was working and showed listening on the port.06:53
JHTUIessentially I'm running into the same issue the person who posted this is: https://ask.openstack.org/en/question/124991/octavia-worker-not-able-to-connect-to-amphora/06:55
JHTUItl;tr issue is:  WARNING octavia.amphorae.drivers.haproxy.rest_api_driver [-] Could not connect to instance. Retrying.: ConnectTimeout: HTTPSConnectionPool(host='XXX.XXX.XXX.XXX', port=9443): Max retries exceeded with url: //06:58
JHTUIwith the active/standby setup, it bounces between both AMP instances with the same message trying to establish connection until they both timeout and it bombs the Loadbalancer06:59
JHTUIbeen fighting this for several weeks.  Rebuilt the kolla instance several dozen times trying to get this to work.07:01
*** e0ne has joined #openstack-kolla07:01
JHTUII've even done silly things like trying to bind the amp interfaces to the public outfacing network, bind-linking new bridged networks onto the systems, still no dice07:04
*** e0ne has quit IRC07:05
*** dougsz has joined #openstack-kolla07:12
*** bengates has joined #openstack-kolla07:14
*** bengates has quit IRC07:18
*** bengates has joined #openstack-kolla07:19
*** zhanglong has quit IRC07:24
*** abdysn has joined #openstack-kolla07:30
*** zhanglong has joined #openstack-kolla07:32
*** rpittau|afk is now known as rpittau07:34
*** arxcruz|off is now known as arxcruz07:35
*** jbadiapa has joined #openstack-kolla07:47
*** jbadiapa has quit IRC07:50
*** jbadiapa has joined #openstack-kolla07:51
*** srini_ has joined #openstack-kolla07:55
*** e0ne has joined #openstack-kolla07:56
*** e0ne has quit IRC08:01
*** zhanglong has quit IRC08:13
*** shyamb has joined #openstack-kolla08:15
*** srini_ has quit IRC08:15
hrwmorning08:19
openstackgerritMarcin Juszkiewicz proposed openstack/kolla-ansible master: CI: move playbook files to tests/playbooks/ dir  https://review.opendev.org/71587208:19
*** zhanglong has joined #openstack-kolla08:19
openstackgerritMarcin Juszkiewicz proposed openstack/kolla-ansible stable/train: requirements: use oslo.config <= 8.0.0 for py2  https://review.opendev.org/71587308:24
*** tonythomas has joined #openstack-kolla08:24
openstackgerritMarcin Juszkiewicz proposed openstack/kolla-ansible master: CI: on aarch64 we only need to build images in upgrade jobs  https://review.opendev.org/71587508:28
*** shyam89 has joined #openstack-kolla08:38
*** JHTUI has quit IRC08:40
*** shyamb has quit IRC08:41
*** skramaja_ has quit IRC08:41
*** skramaja_ has joined #openstack-kolla08:41
hrwyoctozepto: ping https://review.opendev.org/#/c/71516408:45
patchbotpatch 715164 - kolla-ansible - CI: Always use upper-constraints - 1 patch set08:45
*** shyam89 has quit IRC08:53
openstackgerritPierre Riteau proposed openstack/kayobe master: Install python-openstackclient using upper constraints  https://review.opendev.org/71588008:53
*** shyam89 has joined #openstack-kolla08:54
openstackgerritMarcin Juszkiewicz proposed openstack/kolla-ansible master: CI: Always use upper-constraints  https://review.opendev.org/71516408:54
*** Tony31 has joined #openstack-kolla08:58
Tony31hi guys - hope you are keeping safe and well08:58
*** kevko_ has joined #openstack-kolla08:59
*** kevko has joined #openstack-kolla08:59
Tony31@mgoddard how are you doing?08:59
*** k_mouza has joined #openstack-kolla08:59
Tony31I'm running into this bug that it looks like you've pushed a fix to https://github.com/openstack/kolla-ansible/commit/93a4dcc1b97b1d7bbd3b91cc9c4bd4617ec6f9ba08:59
openstackgerritPierre Riteau proposed openstack/kolla-ansible master: Support setting Kafka storage volume  https://review.opendev.org/71530709:00
Tony31having some troubles pulling down the fix, though. Do I do that with `kayobe control host upgrade` ?09:01
hrwTony31: safe, well and bored09:02
Tony31good to see you hrw09:04
mnasiadkamorning09:04
Tony31morning mnasiadka09:04
*** cah_link1 has joined #openstack-kolla09:20
*** cah_link has quit IRC09:21
*** cah_link1 is now known as cah_link09:21
*** shyam89 has quit IRC09:30
*** ykarel is now known as ykarel|lunch09:32
openstackgerritMarcin Juszkiewicz proposed openstack/kolla-ansible master: CI: move playbook files to tests/playbooks/ dir  https://review.opendev.org/71587209:32
mgoddardhi Tony31, that fix should be in the stable branches. stable/<release>09:37
Tony31Hi @mgoddard - I am not sure how to pull it down. I am running `kayobe control host upgrade` but I get an error that I've modified some files. So I Then renamed `/etc/kolla` to `/etc/kolla.old` but I get the same error so I'm a bit confused now09:38
Tony31"fatal: [localhost]: FAILED! => {"before": "9770e596dd0a18d733f8682f32d7cf6b328739c5", "changed": false, "msg": "Local modifications exist in repository (force=no)."}09:39
Tony31"09:39
Tony31can I force=yes ?09:39
hrwmgoddard, mnasiadka: can you take a look at some patches? I would prefer to know should they be worked on or dropped.09:40
mnasiadkahrw: #define some :)09:40
hrwhttps://review.opendev.org/#/c/713135/ https://review.opendev.org/#/c/713134/ https://review.opendev.org/#/c/715164/ https://review.opendev.org/71520209:40
patchbotpatch 713135 - kolla - CI: Avoid tox - 33 patch sets09:40
patchbotpatch 713134 - kolla-ansible - CI: Avoid tox (and clean up gate setup) - 10 patch sets09:40
patchbotpatch 715164 - kolla-ansible - CI: Always use upper-constraints - 2 patch sets09:40
patchbotpatch 715202 - kolla - CI: Ansiblify setup of builders - 8 patch sets09:40
mgoddardhrw: I'm out until Thursday this week09:40
hrwhttps://review.opendev.org/715166 just waits for other patches09:40
patchbotpatch 715166 - kolla - Revert "openstack-base: pin setuptools < 46 to get... - 1 patch set09:40
hrwmgoddard: ok09:40
openstackgerritWill Szumski proposed openstack/kayobe master: Switch to stackhpc fork of resmo.ntp  https://review.opendev.org/71589309:42
Tony31anyone here know how to update kolla ansible from kayobe ?09:49
Tony31maybe it's not kolla-ansible I need to update?09:50
Tony31trying to pull the fix for this bug https://github.com/openstack/kolla-ansible/commit/93a4dcc1b97b1d7bbd3b91cc9c4bd4617ec6f9ba09:50
yankcrimebline: awesome09:52
Tony31@mgoddard - when using kayobe, how does the ansible files get installed to /etc/kolla ?09:52
dougszTony31: $kayobe control host bootstrap09:53
Tony31@dougsz I can try it - thanks09:53
dougszWill install the KA as set in you kolla.yml file09:53
Tony31@dougsz - thanks mate. that part is default - having a read now09:54
dougsznp - kolla_ansible_source_url and kolla_ansible_source_version are probably the vars of interest to you09:55
*** zhanglong has quit IRC09:56
*** cah_link1 has joined #openstack-kolla10:00
*** cah_link has quit IRC10:01
*** cah_link1 is now known as cah_link10:01
*** zhanglong has joined #openstack-kolla10:02
openstackgerritMarcin Juszkiewicz proposed openstack/kolla-ansible master: CI: on aarch64 we only need to build images in upgrade jobs  https://review.opendev.org/71587510:05
*** abdysn has quit IRC10:12
*** ykarel|lunch is now known as ykarel10:15
dougszAny thoughts on whether to support multiple instances of MariaDB on the same host?10:21
dougszhttps://review.opendev.org/#/c/61975610:21
patchbotpatch 619756 - kolla-ansible - Minimal support for deploying multiple instances o... - 19 patch sets10:21
dougsz^ part of that patch10:21
*** dciabrin has joined #openstack-kolla10:21
dougszI.e. for cells with shared cell controller group, should all cells use the same MariaDB cluster, or each have their own?10:22
dougszHaving their own makes the cells less coupled, and cgroups could be used to limit resources used for each MariaDB cluster10:23
dougszSharing a DB cluster on the other hand is simpler10:23
*** whoami-rajat is now known as whoami-rajat|lun10:25
*** whoami-rajat|lun is now known as whoami-rajat10:25
*** cah_link has quit IRC10:27
openstackgerritMarcin Juszkiewicz proposed openstack/kolla master: WIP: Remove support for CentOS 7  https://review.opendev.org/69245010:33
hrwgerrit complained about merge conflicts ;d10:33
*** Wellie has joined #openstack-kolla10:36
WellieHello10:36
*** skramaja_ has quit IRC10:39
*** skramaja_ has joined #openstack-kolla10:39
*** shyamb has joined #openstack-kolla10:39
kevkohi, is this fixed by other way or still a bug ? https://bugs.launchpad.net/kolla/+bug/184457410:44
openstackLaunchpad bug 1844574 in kolla "td-agent user does not have permission to create /var/run/fluentd" [Medium,Expired]10:44
*** zhanglong has quit IRC10:45
*** dmellado has quit IRC10:50
*** rpittau is now known as rpittau|bbl10:56
*** e0ne has joined #openstack-kolla11:00
*** cah_link has joined #openstack-kolla11:02
*** e0ne has quit IRC11:05
*** e0ne has joined #openstack-kolla11:05
*** JangwonLee_ has joined #openstack-kolla11:08
*** JangwonLee has quit IRC11:11
*** JangwonLee__ has joined #openstack-kolla11:16
*** JangwonLee_ has quit IRC11:19
*** gfidente has quit IRC11:21
hrwmeh.11:25
hrwdocker_image_tag is set and not used11:25
hrwat least looks that way11:26
hrwhttps://416277a5687e0626ea6a-8dbb68c995c97f9fb5b4258bb26a4c49.ssl.cf5.rackcdn.com/715875/2/check-arm64/kolla-ansible-debian-source-aarch64/7b56736/job-output.json lists docker_image_tag == master-aarch64 like it is set in run.yml11:27
*** JangwonLee_ has joined #openstack-kolla11:27
hrwhttps://416277a5687e0626ea6a-8dbb68c995c97f9fb5b4258bb26a4c49.ssl.cf5.rackcdn.com/715875/2/check-arm64/kolla-ansible-debian-source-aarch64/7b56736/primary/logs/ansible/deploy uses "kolla/debian-source-fluentd:master" image11:27
openstackgerritMarcin Juszkiewicz proposed openstack/kolla-ansible master: CI: on aarch64 we only need to build images in upgrade jobs  https://review.opendev.org/71587511:29
hrwhope it fixes11:30
*** JangwonLee__ has quit IRC11:30
openstackgerritPiotr Rabiega proposed openstack/kolla master: add dpdk_telemetry and logparser  https://review.opendev.org/71592311:40
*** JangwonLee__ has joined #openstack-kolla11:55
*** JangwonLee_ has quit IRC11:59
*** skramaja_ has quit IRC12:03
*** Fl1nt has joined #openstack-kolla12:03
Fl1ntGood afternoon gentlemen !12:03
*** e0ne has quit IRC12:04
*** e0ne has joined #openstack-kolla12:04
*** dmellado has joined #openstack-kolla12:06
*** shyamb has quit IRC12:16
mgoddardFl1nt: and people of any gender!12:17
Fl1ntthat's an implied expression so yes.12:20
*** rpittau|bbl is now known as rpittau12:46
openstackgerritDoug Szumski proposed openstack/kayobe stable/train: Fix loading of Monasca Grafana dashboards  https://review.opendev.org/71593412:55
*** oyrogerg has quit IRC12:56
openstackgerritDoug Szumski proposed openstack/kayobe master: Fix loading of Monasca Grafana dashboards  https://review.opendev.org/71563812:57
*** oyrogerg has joined #openstack-kolla12:58
*** dave-mccowan has joined #openstack-kolla12:59
*** Luzi has joined #openstack-kolla13:02
openstackgerritMarcin Juszkiewicz proposed openstack/kolla-ansible master: CI: on aarch64 we only need to build images in upgrade jobs  https://review.opendev.org/71587513:04
*** gfidente has joined #openstack-kolla13:07
yoctozeptodougsz: would it be hard to deliver the more flexbile approach? would delivering simplified one make it hard to introduce the flexible one?13:10
*** irclogbot_3 has quit IRC13:13
openstackgerritPierre Riteau proposed openstack/kayobe master: Fix loading of Monasca Grafana dashboards  https://review.opendev.org/71563813:14
hrwuf. this version looks like working one13:14
*** irclogbot_3 has joined #openstack-kolla13:18
dougszyoctozepto: I will rebase the patch and report back, thanks13:19
*** TrevorV has joined #openstack-kolla13:24
*** Luzi has quit IRC13:26
*** cah_link1 has joined #openstack-kolla13:29
*** jimcrowleyibm has joined #openstack-kolla13:30
*** dking_desktop has joined #openstack-kolla13:30
*** cah_link has quit IRC13:31
*** cah_link1 is now known as cah_link13:31
*** jimcrowleyibm has quit IRC13:32
*** jimcrowleyibm has joined #openstack-kolla13:33
*** noxoid has joined #openstack-kolla13:40
*** dmellado has quit IRC14:04
*** dmellado has joined #openstack-kolla14:05
*** e0ne has quit IRC14:15
*** noxoid has quit IRC14:23
*** ykarel is now known as ykarel|away14:25
hrwopenstack is full of crap and lack of useful stuff14:44
hrwfg;e3hgy7te398ty2#14:44
hrwwhy cinder lacks 'image create --from-url https://somewhere' is unknown to me14:45
*** klippo has left #openstack-kolla14:46
*** noxoid has joined #openstack-kolla14:59
*** yoctozepto has quit IRC15:07
*** yoctozepto has joined #openstack-kolla15:08
*** osmanlicilegi has quit IRC15:08
*** ab-a has quit IRC15:08
*** arxcruz has quit IRC15:09
*** obre has quit IRC15:09
*** osmanlicilegi has joined #openstack-kolla15:10
*** pescobar has quit IRC15:10
*** EmilienM has quit IRC15:10
*** arxcruz has joined #openstack-kolla15:10
*** ab-a has joined #openstack-kolla15:11
*** EmilienM has joined #openstack-kolla15:11
*** JHTUI has joined #openstack-kolla15:13
*** pescobar has joined #openstack-kolla15:20
*** ab-a has quit IRC15:26
mnasiadkahrw: cinder and image?15:27
*** ab-a has joined #openstack-kolla15:30
*** dmellado has quit IRC15:32
hrwwhatever15:38
hrwopenstack cli sucks terribly15:38
hrwpython-SERVICEclient -> python-openstackclient migration started in ocata (or earlier) and is still in progress15:39
*** andreykurilin has quit IRC15:39
hrwyou use one command to list, other to use etc15:39
*** obre has joined #openstack-kolla15:39
*** dmellado has joined #openstack-kolla15:39
openstackgerritMarcin Juszkiewicz proposed openstack/kolla master: Revert "openstack-base: pin setuptools < 46 to get horizon working"  https://review.opendev.org/71516615:44
*** ab-a has quit IRC15:45
*** r3ap3r has quit IRC15:45
*** cz3 has quit IRC15:45
*** andrein has quit IRC15:45
*** niedbalski has quit IRC15:45
*** rpittau has quit IRC15:45
openstackgerritMarcin Juszkiewicz proposed openstack/kolla master: Revert "openstack-base: pin setuptools < 46 to get horizon working"  https://review.opendev.org/71368115:45
mnasiadkahrw: yeah well, the usability part of OpenStack always sucked big time, there are some really useful API calls that are not covered in any client :)15:45
*** ab-a has joined #openstack-kolla15:45
*** r3ap3r has joined #openstack-kolla15:45
*** cz3 has joined #openstack-kolla15:45
*** andrein has joined #openstack-kolla15:45
*** niedbalski has joined #openstack-kolla15:45
*** rpittau has joined #openstack-kolla15:45
mnasiadkahrw: so you end up running curl :)15:45
hrwmnasiadka: Debian -300Mbps-> PL -20Mbps-> US15:46
*** andreykurilin has joined #openstack-kolla15:46
hrwlooks like perfect waste of time and bandwidth15:46
kplant<hrw> why cinder lacks 'image create --from-url https://somewhere' is unknown to me15:48
*** jovial[m] has quit IRC15:48
kplantglance _not_  having that slows down my builds SO much15:48
hrwcinder/glance/whateverstoresimageinallinoneormultinode15:49
kplanti empathize15:49
mnasiadkakplant: propose a patch? :)15:50
hrwlike I wrote on twitter...15:50
hrwIt was hard to write so should be hard to use and hard to understand.15:50
hrwFeels like motto of #OpenStack projects...15:50
mnasiadkahrw: well, OpenStack has a history of not caring for how to use it - and now with a lot of companies focus elsewhere - it's not easy to find people to work on the CLI15:53
kplantperhaps an entire release could be tanked and converted into a technical debt release?15:55
Fl1ntWell, that's the issue with every single community would them be open sources or gaming, you've a hype that bring many, then elits decide that you don't need what you're looking for, then they finish to be alone in there own kingdom but it's an empty castle15:55
JHTUIAnyone here get octavia working on kolla in a multi-node setup?15:56
Fl1ntyep15:56
Fl1ntstein release15:57
Fl1ntbut yep15:57
noxoidsame, octavia on stein works for me15:57
*** hjensas has quit IRC15:57
JHTUII'm running into an issue where the octavia-workers can't talk to the amphora instances for the heartbeat/connectivity check.  Any idea how to get past that?15:57
hrwmnasiadka: yeah15:57
Fl1nt@JHTUI, look at your CA Cert, then at your management network.15:58
hrwhttps://review.opendev.org/715875 looks like success. fails on aarch64 still but that's unrelated faulure after deploying/run15:58
patchbotpatch 715875 - kolla-ansible - CI: on aarch64 we only need to build images in upg... - 4 patch sets15:58
JHTUIit gets past the CA cert validation.  Error isoctavia.amphorae.drivers.haproxy.rest_api.driver Could not connect to instance Retrying (over and over) with connect timeout16:00
JHTUIto port 944316:00
Fl1ntok, you can have a look at your amphorae instance, within the logs and then throw a tcpdump to see if you can get the packets actually reach your management interface.16:01
* hrw out16:01
JHTUII've verified that the octavia worker node can't send/receive packets to the amp instances, and the question is I don't know why.  Per the kolla documentation, I have the bonded network as the API interface, and set up networking and security as they expected.  For giggles I even oopened up ports 1:65535 to remove all possibilities16:03
Fl1nt@JHTUI, did you created the mgmt-net ?16:04
JHTUIyes.16:04
Fl1ntand you instance get an IP from it within the namespace?16:05
JHTUIwith the uuid assigned as the octavia network in the globals.yml16:05
JHTUIyes both amph instances get IP's16:05
JHTUII've tried silly things like attempting to bind the LB's to a public facing networks as well16:06
*** bengates has quit IRC16:07
Fl1ntput yourself on this network gateway and do a tcpdump, you should be able to see packets.16:07
Fl1ntCan't remember exactly but each time that I get my amphorae that couldn't be reached by the worker it was either a routing issue, a namespace issue or a certificate issue.16:08
JHTUIthis one looks like a routing issue.  So the question is if I set all the globals correctly yet it still can't route, what's  missing?16:09
Fl1ntwho manage your networks within your company/platform?16:10
Fl1ntit may be a missing vlan distribution16:10
Fl1ntor a missing route declaration16:10
JHTUIwe do, and I already verified the API bond interface (bond2) can reach all the hardware in the cluster16:10
Fl1ntat TOR or Core swithc16:10
Fl1ntwhich kind of equipment is the gateway of your mgmt-net ? physical switch? OpenVswitch?16:11
Fl1ntwhich type of network did you used as mgmt-net ?16:12
*** e0ne has joined #openstack-kolla16:12
Fl1ntvxlan?16:12
JHTUIvxlan16:12
Fl1ntdid you tried to create a VM on this mgmt-net and to send it packets from your control plan ?16:12
*** rpittau is now known as rpittau|afk16:12
JHTUIyea, that part works.16:12
JHTUIthis is probably user error on my end, but I can't see where I messed this up16:13
Fl1ntwait a second,when placed within the amphorae you see packets incoming?16:13
JHTUII've rebuilt it so many times I'm seeing octavia in my dreams16:13
JHTUII'm seeing packets going over the bridge, but not being received by amphorae, that's why I'm head scratching16:14
JHTUIit's *got* to be a routing issue, but I don't know where16:14
JHTUIbeen trying to find examples of working octavia setups so I could compare to what I have to see what I screwed up on, but the documentation on howtos are woefully lacking16:15
Fl1ntThere is something that I can't figure out, you told me "that part works" when asked to put a VM within the MGMT-NET and send traffic to it from the control plan, then your amphorae instances don't?16:15
Fl1ntDid you created the appropriate secgroup?16:15
JHTUIyes, secgroup has 5555, 22, and 9443 opened.  Getting frustrated I also opened all of udp and tcp fro 1:65535 to see if it was blocking on a non-registered port as well16:16
Fl1ntwhen you're trying to capture the packets, do you put yourself within the amphorae namespace?16:17
JHTUII actually dropped a floating ip to theamp instances, logged in and ran tcpdump on them16:18
Fl1ntthat won't work, you need to capture the traffic from within the namespace.16:18
JHTUIhum ok.16:18
JHTUII'll check that out.  Do you have an example octavia setup I can compare against on a known working install?  Not having one I'm finding it hard to compare16:19
JHTUIbeen at this for a few weeks so I'm frustrated16:19
JHTUIdoesn't help that it takes about 45 minutes for the LB to timeout and fail16:20
*** Tony31 has quit IRC16:21
*** kevinz has quit IRC16:22
noxoidJHTUI, sec, i can provide you an example16:27
noxoidJHTUI, http://paste.openstack.org/show/3E65oM8YPx8dFHhimW4i/16:30
noxoidonly thing i intentionally omitted was the config dir with the octavia certs16:31
noxoidlet me know if theres anything else that may be useful16:31
JHTUIdid you have to add specific interfaces on the compute/controllers to bridge the connections outside the kolla install for this?16:34
noxoidon the compute side neutron handles the configuration (via openvswitch). i manually set up the bond1.1002 interface on the controller via kickstart. vlan1002 is trunked to both the compute nodes and controller nodes at the top-of-rack16:35
*** evrardjp has quit IRC16:36
*** evrardjp has joined #openstack-kolla16:36
*** kevko_ has quit IRC16:37
*** kevko has quit IRC16:37
*** hjensas has joined #openstack-kolla16:39
JHTUInoxoid, understood on the ca certs, could you let me know what the subnet is for your management network?16:39
noxoidmy octavia management network?16:41
JHTUIyea, is it in the same subnet as the bond1 trunk?16:42
noxoidits in the paste, 10.102.0.0/2116:42
JHTUIahah, ok, I think that's what I screwed up on.  I had my lb management subnet larger than the API bond interface16:42
noxoidif you're talking about api_interface, i have mine completely separate16:43
noxoidapi_interface: "bond1.1001"16:43
noxoidoctavia_network_interface: "bond1.1002"16:43
*** bengates has joined #openstack-kolla16:43
JHTUIhum. ok.   so your management interface  is sitting on the new trunk you then set up on the controllers16:44
noxoidyou dont have to use separate networks if you're ok with amphora vms accessing your api_interface network16:44
noxoidwhich id recommend against16:44
noxoidfor a production install anyways16:44
JHTUIagreed.  Right now we're just trying a POC so at this point I just want it up, I'm  a week behind and my manager is getting twitchy :)16:45
generalfuzzWelcoming any additional reviews for our initial backend tls implementation for Keystone service: https://review.opendev.org/#/c/713986/16:47
patchbotpatch 713986 - kolla-ansible - Add support for encrypting backend HAProxy traffic... - 5 patch sets16:47
JHTUIsurprised that kolla's module for octavia doesn't do this for you noxoid.  It's all ansible driven so theoretically it wouldn't be hard.16:47
noxoidits possible but i like to think kolla doesnt do it as octavia deployments can be fairly site-specific16:48
johnsomI agree, it would be great to have kolla handle this16:48
JHTUIyea, but even still it should be easy enough to make a fact sheet for deploy.  it's the entire purpose of ansible.16:48
johnsomThere seem to be a lot of questions about this and OSA and tripleo both set this up for the user.16:49
noxoidyea this isnt the first person ive tried to help with octavia16:50
JHTUIyea, the big issue with octavia is no where in documentation does it state having to manually set up bridges in controllers to match the lb-management network and unless you have a good understanding of both openstack, networking, and packet sniffing to detect why you need this, people would get frustrated.  I mean I'm no slouch in this and even I16:50
JHTUIgot lost16:50
noxoidyea, https://shreddedbacon.com/post/openstack-kolla/ helped me piece that together16:50
noxoid"turned the lightbulb on" so to speak16:51
JHTUIyea, his last section about the provider network was the bulb that got me as far as I did.  I was close, but missing some subnets16:51
*** bengates has quit IRC16:57
JHTUIwhat I would suggest for the ansible part of the kolla octavia buildout is a fact sheet that handles base network buildouts.  For those customers/clients/other that have obtuse networks that just go beyond what you can account for, have part of the fact data sheet a bypass variable, then provide documentation on how to manually set up networking17:05
JHTUIfor kolla octavia.  Then in the kolla ansible code, you just have a block/rescue section with a when variable comparison that if 'octavia-network-manual is true' you don't execute that network block section that would set up the controllers with the bonded interfaces17:05
*** k_mouza has quit IRC17:21
*** bengates has joined #openstack-kolla17:25
*** bengates has quit IRC17:40
*** rlandy has joined #openstack-kolla17:41
rlandymgoddard: hi - in kolla/docker, does the directory structure have any impact on the order in which containers are built?17:44
*** e0ne has quit IRC17:58
*** dciabrin_ has joined #openstack-kolla18:02
*** dciabrin has quit IRC18:05
*** bengates has joined #openstack-kolla18:13
*** vishalmanchanda has quit IRC18:18
*** k_mouza has joined #openstack-kolla18:19
*** k_mouza has quit IRC18:20
mgoddardrlandy: hi. No, it's determined based on the dependencies between images18:23
mgoddardso base first, then openstack-base, etc.18:24
rlandymgoddard: ok - so a flat list of directories with the correct dependencies would work18:25
mgoddardrlandy: yes18:25
rlandythank you18:25
mgoddardnp18:25
*** rlandy is now known as rlandy|brb18:29
*** bengates has quit IRC18:29
yoctozeptohrw, mnasiadka: re: glance  - I don't think glance allows to download by glance-api; I guess that is what hrw tried18:30
yoctozeptothat said, the standalone glance client has more features; it's a bit of a concern in the community...18:30
mnasiadkayoctozepto: I know, it should be easy to implement in the client though18:37
mnasiadkaBut with the OSC vs glance fuss, I don’t want to even talk about it18:37
openstackgerritMarcin Juszkiewicz proposed openstack/kolla-ansible master: CI: Always use upper-constraints  https://review.opendev.org/71516418:38
openstackgerritMarcin Juszkiewicz proposed openstack/kolla-ansible master: CI: Always use upper-constraints  https://review.opendev.org/71516418:42
hrwnow it will work properly18:42
hrwdowngrade k-a and requirements, install, deploy, test, switch BOTH to master, upgrade18:42
hrwthe side effect? we know that k-a/master installs fine with u-c/train ;D18:43
*** pbing19 has joined #openstack-kolla18:46
yoctozeptohrw: better than previously: we knew stable/train can install master... ;-)18:47
*** rlandy|brb is now known as rlandy18:54
*** jbadiapa has quit IRC19:14
*** bengates has joined #openstack-kolla19:24
*** JHTUI has quit IRC19:27
*** cah_link has quit IRC19:32
*** bengates has quit IRC19:38
*** dougsz has quit IRC19:44
*** gfidente is now known as gfidente|afk19:49
*** jimcrowleyibm has quit IRC20:16
*** k_mouza has joined #openstack-kolla20:20
*** k_mouza has quit IRC20:25
*** pbing19 has quit IRC21:17
*** tonythomas has quit IRC21:41
*** todd-inmotion has joined #openstack-kolla22:23
*** k_mouza has joined #openstack-kolla22:27
*** k_mouza has quit IRC22:27
*** k_mouza has joined #openstack-kolla22:28
*** k_mouza has quit IRC22:33
*** TrevorV has quit IRC22:57
*** todd-inmotion has quit IRC22:57
*** gfidente|afk has quit IRC23:14
*** sorin-mihai has joined #openstack-kolla23:39

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!