dcapone2004 | nvm....found the correct path in the playbook files and once I put the override file there everything works as expected | 00:51 |
---|---|---|
*** wuchunyang has joined #openstack-kolla | 00:58 | |
*** wuchunyang has quit IRC | 01:02 | |
*** cah_link1 has joined #openstack-kolla | 01:32 | |
*** cah_link has quit IRC | 01:33 | |
*** cah_link1 is now known as cah_link | 01:33 | |
dmsimard | I'm still hacking on it but here's some info about the 25 longest playbooks and tasks from kolla-ansible: http://paste.openstack.org/show/794185/ | 01:51 |
dmsimard | data is from https://api.trunk.demo.recordsansible.org/?path=kolla-ansible&order=-duration | 01:52 |
*** alanmeadows_ has joined #openstack-kolla | 02:20 | |
*** crindi_ has joined #openstack-kolla | 02:21 | |
*** alanmeadows has quit IRC | 02:28 | |
*** crindi has quit IRC | 02:28 | |
*** rm_work has quit IRC | 02:28 | |
*** alanmeadows_ is now known as alanmeadows | 02:28 | |
*** crindi_ is now known as crindi | 02:28 | |
*** yankcrime has quit IRC | 02:56 | |
*** wuchunyang has joined #openstack-kolla | 03:01 | |
*** hongbin has joined #openstack-kolla | 03:19 | |
*** e0ne has joined #openstack-kolla | 03:23 | |
*** e0ne has quit IRC | 03:28 | |
*** wuchunyang has quit IRC | 03:30 | |
*** e0ne has joined #openstack-kolla | 03:43 | |
*** e0ne has quit IRC | 03:47 | |
*** Torel has quit IRC | 03:55 | |
*** e0ne has joined #openstack-kolla | 04:03 | |
*** ykarel|away is now known as ykarel | 04:07 | |
*** e0ne has quit IRC | 04:07 | |
*** wuchunyang has joined #openstack-kolla | 04:12 | |
*** wuchunyang has quit IRC | 04:17 | |
*** skramaja has joined #openstack-kolla | 04:18 | |
*** e0ne has joined #openstack-kolla | 04:23 | |
*** e0ne has quit IRC | 04:27 | |
*** evrardjp has quit IRC | 04:33 | |
*** evrardjp has joined #openstack-kolla | 04:33 | |
*** wuchunyang has joined #openstack-kolla | 04:58 | |
*** vishalmanchanda has joined #openstack-kolla | 05:04 | |
*** wuchunyang has quit IRC | 05:04 | |
*** abdysn has joined #openstack-kolla | 05:04 | |
*** wuchunyang has joined #openstack-kolla | 05:16 | |
*** ricolin has joined #openstack-kolla | 05:19 | |
*** wuchunyang has quit IRC | 05:20 | |
*** k_mouza has joined #openstack-kolla | 05:24 | |
*** k_mouza has quit IRC | 05:28 | |
*** seco has joined #openstack-kolla | 05:51 | |
*** hongbin has quit IRC | 05:57 | |
*** xinliang has joined #openstack-kolla | 06:02 | |
*** xinliang has quit IRC | 06:06 | |
osmanlicilegi | morning | 06:14 |
yoctozepto | morning | 06:39 |
openstackgerrit | Radosław Piliszek proposed openstack/kolla master: [DNM] test neutron patch https://review.opendev.org/731985 | 06:44 |
*** sorin-mihai has joined #openstack-kolla | 06:46 | |
seco | morning | 06:48 |
sorin-mihai | maybe i'm repeating myself, have been asking this in different forms in different channels. i'm trying to understand what is the best way to use multiple public provider subnets along with private subnets. if this is not the best place to ask, please let me know where to move this discussion | 06:56 |
sorin-mihai | at the moment i have a /30 in the router/firewall and another /28 provided by the ISP. if i add the /28 in the router, i can DNAT/SNAT to IPs in a private /16 that is used as DMZ. this seems to be working fine as i can keep an eye on the traffic on thse IPs using the IDS functionality of the router | 06:57 |
sorin-mihai | the private /16 is also the subnet used for 'management' in the server, i use it to ssh in the openstack server but also in other servers behind that router. this /16 is also set as external network using physnet1 | 06:57 |
sorin-mihai | what is the best way to add multiple public subnets so that i can use/manage them in openstack, including with designate, but still keep them monitored through the IDS that is in front of the openstack server? maybe it's a multiprocess, maybe this question looks incomplete, i'm stil trying to wrap my head around the issue, trying to keep the IDS in front of the openstack, use the private /16 for both physical and virtual | 07:03 |
sorin-mihai | devices, but to still be able to expose certain instances to the internet. it looks like designate at least will nork properly if i do NAT, so what would be the best way to achieve all these? | 07:03 |
sorin-mihai | s/nork/not\ work/ | 07:08 |
*** bengates has joined #openstack-kolla | 07:09 | |
mnasiadka | morning | 07:09 |
*** dougsz has joined #openstack-kolla | 07:14 | |
*** born2bake has joined #openstack-kolla | 07:28 | |
*** wuchunyang has joined #openstack-kolla | 07:31 | |
*** wuchunyang has quit IRC | 07:41 | |
*** amoralej|off is now known as amoralej | 07:42 | |
*** iniazi_ has quit IRC | 07:56 | |
*** kevko has joined #openstack-kolla | 07:58 | |
kevko | hi, i have few notes on the kolla debian binary install - horizon | 08:04 |
kevko | when kolla installed with debian binary , it is unable to login to horizon | 08:05 |
kevko | it is caused by default cache set by a package in /etc/kolla/local_settings.d/ | 08:05 |
kevko | i think everything under local_settings.d/ what is installing debian packages should be removed and installed by a kolla | 08:06 |
kevko | another note is regarding static_root ... when i remove all local_settings.d/* from debian package ..kolla should be installed OK .. but is not ..after this removal STATIC_URL pointing to /var/lib/openstack-dasjboard/static is missing in local_settings.py | 08:07 |
kevko | on ubuntu it is working because they are doing symlinks .. | 08:07 |
kevko | another note is regarding symlink local_settings -> local_settings.py in /etc/openstack-dashboard ..it is working ..but it is ugly .. i think better will be if symlink to /etc/openstack-dashboard/local_settings.py provided by debian/ubuntu packages will be replaced to symlink to local_settings directly | 08:09 |
kevko | and last note is that debian package is symlinking policy files direct to /etc/openstack-dashboard/policy ..kolla have option where it is overriden to /etc/openstack-dashboard , it is OK , but /etc/openstack-dashboard/policy is unused .. | 08:10 |
kevko | i think above should be fixed firstly because it is not working under debian/binary ..and secondly for better look in /etc/openstack-dashboard/ | 08:11 |
*** radek has joined #openstack-kolla | 08:13 | |
*** e0ne has joined #openstack-kolla | 08:15 | |
*** ykarel is now known as ykarel|lunch | 08:23 | |
*** eliaswimmer has quit IRC | 08:24 | |
mnasiadka | mgoddard: https://review.opendev.org/#/c/710213/ - I see Dincer is happy to merge it - any last minute thoughts? :) | 08:30 |
patchbot | patch 710213 - kolla-ansible - Custom haproxy script for monitoring galera - 56 patch sets | 08:30 |
mgoddard | mnasiadka: I'll take a looksie | 08:33 |
mgoddard | sorin-mihai: how about just using the firewall as a firewall, removing the NAT, and giving the /28 to openstack to use as a public network? | 08:46 |
mgoddard | sorin-mihai: as soon as you add NAT, your floating/public IPs are no longer directly accessible | 08:47 |
sorin-mihai | mgoddard, that's what i want to do, to get rid of the NAT but i'm not sure how nor where is the problem now | 08:47 |
mgoddard | sorin-mihai: here's a old blog: https://www.mirantis.com/blog/configuring-floating-ip-addresses-networking-openstack-public-private-clouds/#:~:text=But%20OpenStack%20also%20introduces%20another,reachable%20from%20the%20outside%20world. | 08:49 |
mgoddard | sorin-mihai: you normally just have one (or more) external networks which are marked as external=true in neutron. You can create floating IPs on these | 08:49 |
mgoddard | then other neutron networks are generally internal | 08:50 |
sorin-mihai | do i need to change the external VIP to be from that /28? | 08:50 |
sorin-mihai | for some reason i can't add another external network, as i have flat network and only 1 physnet available | 08:51 |
sorin-mihai | maybe i'm doing it the wrong way | 08:51 |
mgoddard | sorin-mihai: you can only have one flat network per physnet. You either need multiple physnets or use VLANs | 08:53 |
mgoddard | external VIP is separate to neutron. | 08:53 |
mgoddard | it could be on the same subnet, if it is excluded from the allocation pool | 08:53 |
sorin-mihai | that's how i did it, i kept some of that /16 out of the pool | 08:54 |
sorin-mihai | but to be sure i got it right, given the current flat network setup, i have no way to use the /28 inside openstack? | 08:56 |
hrw | kevko: ideas look good. can you help with it? | 08:57 |
hrw | kevko: to be honest I never used debian/binary target as I target aarch64 not x86-64 | 08:58 |
hrw | morning | 08:58 |
*** k_mouza has joined #openstack-kolla | 09:02 | |
mgoddard | sorin-mihai: you can have multiple subnets per network | 09:05 |
mgoddard | not sure if it will cause issues though | 09:06 |
*** sheldonhu has joined #openstack-kolla | 09:06 | |
sorin-mihai | i tried to add the public /28 as a 2nd subnet to the external network along the /16 one, adding it as subnet worked, added a floating IP to a instance and made sure there's no NAT for that IP, but it's not working. i suspect it could also be a thing related to the firewall limitations and the flat network setup, not sure what to look into | 09:10 |
*** ykarel|lunch is now known as ykarel | 09:10 | |
*** wuchunyang has joined #openstack-kolla | 09:11 | |
*** e0ne_ has joined #openstack-kolla | 09:11 | |
*** muhaha has joined #openstack-kolla | 09:11 | |
*** e0ne has quit IRC | 09:11 | |
mgoddard | yoctozepto: thanks for pushing on the neutron issue. I spoke to slaweq about it last week but didn't have time to investigate myself | 09:11 |
*** gfidente has joined #openstack-kolla | 09:12 | |
mgoddard | sorin-mihai: I don't think you want to expose the /16 as external do you? | 09:12 |
sorin-mihai | the /16 being behind firewall and set as DMZ i'm using it as external so that i can access all floating IPs over a vpn that is set in the firewall | 09:13 |
sorin-mihai | but this forces me to use NAT if i want to expose any of the floating IPs to the internet | 09:14 |
kevko | hrw: yes , of course, i will proces it , i give a task to my brother ( now he is working with us in our company :) ) and we together will send a patchsets to review | 09:16 |
*** seco has quit IRC | 09:18 | |
openstackgerrit | Mark Goddard proposed openstack/kayobe master: Fix external API interface with out an IP address https://review.opendev.org/731754 | 09:18 |
*** e0ne_ has quit IRC | 09:19 | |
sorin-mihai | from my point of view, with the current flat setup, i have external public IPs (static, usable only with NAT), external private IPs (DHCP pool, floating, same /16 for all domains/projects) and internal private IPs (DHCP, unique /24 per project, didn't test if it could overlap with the /16) | 09:19 |
hrw | kevko: thanks! | 09:20 |
kevko | hrw: last 2 questions | 09:20 |
hrw | kevko: do not ask to ask but ask | 09:21 |
*** sheldonhu has quit IRC | 09:22 | |
*** e0ne has joined #openstack-kolla | 09:22 | |
*** jbadiapa has joined #openstack-kolla | 09:23 | |
kevko | hrw: kolla is installing policy files to /etc/openstack-dashboard/ , i'm just wondering that maybe it would be nice to use conf folder directly as it is in upstream https://github.com/openstack/horizon/tree/master/openstack_dashboard/conf | 09:23 |
kevko | and have symlink to /etc/openstack-dashboard/policy | 09:23 |
kevko | no need to change local settings and overriding policy path ..and + ist that when i check /etc/openstack-dashboard ..there is no mess in config files ... | 09:24 |
hrw | kevko: I have to admit that I mostly work on building part (kolla) while it looks like you ask about installing part (kolla-ansible) | 09:25 |
hrw | mgoddard: ^^ | 09:25 |
kevko | second question is ..that if it is really good solution to have include to custom_local_settings ..firstly horizon upstream RECOMMENDS to use local_settings.d ... secondly .. local_settings.d has bigger priority ..or let's say it is overriden | 09:25 |
mgoddard | kevko: I didn't know about local_settings.d. That sounds better. We're probably stuck with custom_ for backwards compat reasons though | 09:26 |
mgoddard | we could drop it into .d though | 09:26 |
mgoddard | kevko: on the policies, we ended up doing some massaging to make things consistent between different distros and source/binary. Possibly it could be better | 09:27 |
kevko | mgoddard: well, i think it is more clear to use default horizon path and just symlink to /etc/openstack-dashboard/ as defining it in local_settings.py | 09:29 |
kevko | sorry /etc/openstack-dashboard/policy for example | 09:29 |
kevko | mgoddard: local_settings.d is in horizon for a long time ... https://github.com/openstack/horizon/tree/master/openstack_dashboard/local/local_settings.d | 09:30 |
kevko | mgoddard: it is loading configs in alphabetical order .. so kolla should have somehing like _9999_kolla_custom_config.py | 09:30 |
mgoddard | kevko: is there a problem that this would fix? | 09:31 |
* hrw out | 09:31 | |
kevko | mgoddard: well, half of my ideas is fixing small problem with debian binary ..and half is cosmetic things .. i can omit cosmetic things and only fix a problem ..read above what i wrote ...it is "kevko 10:04:46" | 09:36 |
openstackgerrit | Mark Goddard proposed openstack/kolla stable/ussuri: Switch to RDO Ussuri release on CentOS https://review.opendev.org/731798 | 09:38 |
*** yankcrime has joined #openstack-kolla | 09:39 | |
*** ricolin_ has joined #openstack-kolla | 09:44 | |
*** ricolin has quit IRC | 09:47 | |
*** seco has joined #openstack-kolla | 09:50 | |
*** chenyingnan01 has joined #openstack-kolla | 09:55 | |
mgoddard | kevko: ok, if there are genuine issues we should fix them | 09:55 |
*** seco has quit IRC | 09:56 | |
mgoddard | kevko: in general I've found that the debian packages seem to go in their own direction | 09:56 |
kevko | mgoddard: well, i am author of redefining debian package ..because it was bad in both dists ubuntu and debian | 09:59 |
*** chenyingnan01 has quit IRC | 10:00 | |
kevko | mgoddard: this is that ugly thing which i fixed by rework -> http://paste.openstack.org/show/794199/ symlink from usr share to python libraries :/ | 10:00 |
*** sorin-mihai_ has joined #openstack-kolla | 10:04 | |
*** sorin-mihai has quit IRC | 10:05 | |
*** wuchunyang has quit IRC | 10:09 | |
*** e0ne has quit IRC | 10:15 | |
*** k_mouza has quit IRC | 10:18 | |
*** witek has joined #openstack-kolla | 10:23 | |
*** e0ne has joined #openstack-kolla | 10:29 | |
mnasiadka | mgoddard, yoctozepto: Is this the neutron ovslib error we've been chasing? https://zuul.opendev.org/t/openstack/build/f5e8a73e3eae4c519bca060332c55dba/log/primary/logs/kolla/all-ERROR.txt#224 | 10:32 |
yoctozepto | mnasiadka: yeah, I handled this and Terry found a fix https://bugs.launchpad.net/neutron/+bug/1881424 | 10:33 |
openstack | Launchpad bug 1881424 in kolla-ansible victoria "Neutron ovs agent fails on rpc_loop iteration:1" [Critical,Triaged] | 10:33 |
mnasiadka | meh, so then let's wait | 10:33 |
yoctozepto | mgoddard, mnasiadka: we can temp-pin ovsdbapp to 1.1.0 to fix our gate | 10:34 |
yoctozepto | or wait for release with fix | 10:34 |
yoctozepto | but it could take some time | 10:34 |
yoctozepto | their CI fubar | 10:34 |
mnasiadka | let me go kick somebody | 10:35 |
mnasiadka | yoctozepto: yeah, let's temp-pin... seems it's not gonna go in today (or probably even this week) | 10:37 |
yoctozepto | mnasiadka: ok, doing it | 10:37 |
openstackgerrit | Radosław Piliszek proposed openstack/kolla master: [to-revert] Pin ovsdbapp in neutron to 1.1.0 https://review.opendev.org/732153 | 10:40 |
yoctozepto | mnasiadka, mgoddard: ^ | 10:41 |
mgoddard | yoctozepto: what about binary? | 10:44 |
*** witek has quit IRC | 10:45 | |
*** k_mouza has joined #openstack-kolla | 10:54 | |
*** kevko has quit IRC | 10:56 | |
*** kemopq has joined #openstack-kolla | 10:56 | |
*** rgogunskiy has joined #openstack-kolla | 10:57 | |
*** kevko has joined #openstack-kolla | 10:58 | |
*** e0ne has quit IRC | 10:59 | |
yoctozepto | mgoddard: binary not released afaik | 11:01 |
*** kevko_ has joined #openstack-kolla | 11:01 | |
*** kevko has quit IRC | 11:04 | |
*** faizy98 has joined #openstack-kolla | 11:04 | |
*** sorin-mihai_ has quit IRC | 11:05 | |
*** sorin-mihai has joined #openstack-kolla | 11:08 | |
*** also_stingrayza is now known as stingrayza | 11:11 | |
*** e0ne has joined #openstack-kolla | 11:14 | |
*** e0ne_ has joined #openstack-kolla | 11:17 | |
*** e0ne has quit IRC | 11:17 | |
*** e0ne_ has quit IRC | 11:19 | |
*** e0ne has joined #openstack-kolla | 11:20 | |
*** wuchunyang has joined #openstack-kolla | 11:22 | |
*** seco has joined #openstack-kolla | 11:26 | |
*** xinliang has joined #openstack-kolla | 11:34 | |
*** e0ne has quit IRC | 11:36 | |
*** e0ne has joined #openstack-kolla | 11:40 | |
*** amoralej is now known as amoralej|lunch | 11:41 | |
*** sorin-mihai has quit IRC | 11:48 | |
yoctozepto | mgoddard: rdo released, thankfully we are not blocked by binary | 11:52 |
*** e0ne has quit IRC | 11:59 | |
*** dmellado has quit IRC | 12:02 | |
*** e0ne has joined #openstack-kolla | 12:02 | |
*** xinliang has quit IRC | 12:03 | |
*** dmellado has joined #openstack-kolla | 12:06 | |
yoctozepto | does etherpad work for you? | 12:07 |
yoctozepto | ok, it works for me, but takes a looong time to load | 12:07 |
yoctozepto | ;/ | 12:07 |
*** wuchunyang has quit IRC | 12:11 | |
*** amoralej|lunch is now known as amoralej | 12:19 | |
*** skramaja has quit IRC | 12:20 | |
*** wuchunyang has joined #openstack-kolla | 12:25 | |
mnasiadka | mgoddard: will be a bit late for PTG | 12:26 |
*** wuchunyang has quit IRC | 12:30 | |
*** ricolin_ is now known as ricolin | 12:31 | |
*** erolg has joined #openstack-kolla | 12:34 | |
dcapone2004 | I am trying out a hyper-converged openstack train deployment and I am running into a network issue …. I think / thought I have everything configured correctly however my internal networks are receiving DHCP addresses, so maybe I am misunderstand how neutron works with VLANs... | 12:38 |
dcapone2004 | 3 node setup with Ceph on the backend for storage, 2 physical network interfaces, eno2 is external and mapped to physnet1 and eno1 which is all the other interfaces (including the ceph public network) | 12:39 |
dcapone2004 | eno2 is connected to an external network switch that has the switch in access mode, eno1 is connected to the same switch with its ports configured in trunk mode to allow VLANS 800-900 and a native vlan port that is the same as the the other interfaces | 12:40 |
dcapone2004 | ml2_conf.ini was overridden and contains.... https://pastebin.com/hASKPKy8 | 12:42 |
*** sorin-mihai has joined #openstack-kolla | 12:45 | |
dcapone2004 | I love this channel....it has a magically power that the moment I start typing an issue I'm stuck on for over an hour to it, I suddenly realize my error | 12:47 |
yoctozepto | dcapone2004: not many folks around because ptg (project team gathering) is in 13 minutes | 12:47 |
yoctozepto | dcapone2004: but I'm glad you solved your issue using the rubber duck method :-) | 12:47 |
*** priteau has joined #openstack-kolla | 12:48 | |
yoctozepto | https://etherpad.opendev.org/p/kolla-victoria-ptg etherpad for ptg | 12:48 |
dking | Also, it's not a bad idea to post the solution, even if it became obvious, if nothing more than potentially helping somebody else. | 12:48 |
yoctozepto | ^ ++ | 12:48 |
*** ykarel is now known as ykarel|afk | 12:51 | |
openstackgerrit | Radosław Piliszek proposed openstack/kolla stable/ussuri: Switch to RDO Ussuri release on CentOS https://review.opendev.org/731798 | 12:53 |
hrw | what is meeting password? | 12:53 |
*** ricolin has quit IRC | 12:54 | |
*** ricolin has joined #openstack-kolla | 12:55 | |
openstackgerrit | Radosław Piliszek proposed openstack/kolla stable/ussuri: Switch to RDO Ussuri release on CentOS https://review.opendev.org/731798 | 12:55 |
openstackgerrit | Mark Goddard proposed openstack/kolla stable/ussuri: Switch to RDO Ussuri release on CentOS https://review.opendev.org/731798 | 12:56 |
openstackgerrit | Radosław Piliszek proposed openstack/kolla stable/ussuri: Switch to RDO Ussuri release on CentOS https://review.opendev.org/731798 | 12:56 |
mgoddard | yoctozepto: I think we are fighting over it ^ | 12:56 |
yoctozepto | mgoddard: loll, sorry, did not notice you | 12:57 |
dcapone2004 | the solution was I defined the wrong physical interface in ml2_conf.ini … I defined the external network interface (which wasn't configured for trunking) … still in the process of reconfiguring the deployment to ensure that brings a resolution but it makes sense as the problem :-) | 12:57 |
yoctozepto | mgoddard: but hmm it's actually you did not notice me | 12:57 |
erolg | hrw +1 | 12:58 |
hrw | mgoddard: what is meeting password? | 12:58 |
mgoddard | hrw: PTG2020 | 12:58 |
PrinzElvis | Hi all | 12:59 |
hrw | thx | 13:00 |
mnasiadka | Is zoom working for anybody? mine just says "Connecting..." for 5 minutes :D | 13:05 |
*** TrevorV has joined #openstack-kolla | 13:06 | |
dougsz | mnasiadka: seems fine | 13:07 |
hrw | works fine | 13:07 |
hrw | mnasiadka: 17 people joined so far | 13:07 |
kplant | hey whoever thought to add container specific footers and a generic footer to the dockerfiles: thank you! | 13:07 |
kplant | some good forethought | 13:08 |
mnasiadka | does not work for me, zoom enters some diabolical loop and stops responding | 13:08 |
hrw | mnasiadka: use a phone? | 13:08 |
mnasiadka | hrw: come on, it can't be so simple | 13:08 |
*** mattia has joined #openstack-kolla | 13:12 | |
*** arxcruz is now known as arxcruz|qa_room | 13:14 | |
mgoddard | #kolla now reflection | 13:28 |
yoctozepto | mgoddard: reflecting on my life | 13:32 |
mgoddard | dangerous | 13:32 |
yoctozepto | mgoddard: :O I said mine, not yours | 13:33 |
mnasiadka | so, it seems latest security update on Mac has killed Zoom - if anybody has a similar problem :) | 13:34 |
*** JamesBenson has joined #openstack-kolla | 13:40 | |
dcapone2004 | ok, so the problem I have is definitely the wrong interface being defined in ml2_conf.ini, however, I cannot figure out what is the correct physical interface name to use in ml2_conf.ini that references the other interface …. in looking at ovs-vsctl I see port eno2 added to br-ex and the mapping for physnet1 to br-ex, but I do not see eno1 | 13:59 |
dcapone2004 | defined in any bridges | 13:59 |
dcapone2004 | do I create another mapping for physnet2:br-int and use that or physnet2:br-tun? or something completely different | 14:05 |
*** e0ne has quit IRC | 14:11 | |
*** e0ne has joined #openstack-kolla | 14:12 | |
dmsimard | is zoom available without a client ? i.e, browser based ? | 14:16 |
noxoid | yes but they make it difficult to find in my experience | 14:17 |
noxoid | ive only seen the link when i click "open zoom client" or whatever and wait a few seconds. they'll display the browser link at that point | 14:17 |
hrw | dmsimard: yes | 14:17 |
openstackgerrit | Merged openstack/kolla master: [to-revert] Pin ovsdbapp in neutron to 1.1.0 https://review.opendev.org/732153 | 14:18 |
kplant | is there a relay to less-evil software? | 14:19 |
kplant | or a dial in number | 14:19 |
dmsimard | noxoid: wow yeah they'd really prefer you use the client | 14:19 |
*** Torel has joined #openstack-kolla | 14:21 | |
dmsimard | kplant: I see a phone call option when joining over the browser | 14:21 |
dcapone2004 | I think zoom was founded on the premise of specifically not using a browser based interface..one of the reasons the founder left Cisco/webex to create zoom | 14:24 |
kplant | i don't understand how zoom is still thriving with all of the security holes | 14:25 |
kplant | dmsimard: you said you got it to prompt you to join via browser? | 14:25 |
dmsimard | kplant: yeah it only displays a link at the bottom to join with your browser as a last resort | 14:26 |
kplant | i've been sitting here for a few minutes | 14:26 |
kplant | no join from browser link | 14:26 |
dmsimard | like it will try to open the app with xdg-open, you respectfully decline and it will show a link at the bottom | 14:26 |
dmsimard | what browser ? it wouldn't work for me in firefox, had to use chrome | 14:26 |
kplant | ah, have to try the manual download option first | 14:27 |
*** Limech has quit IRC | 14:27 | |
yoctozepto | kplant: "I don't understand how google is still thriving despite we all know how much info it gathers on us" | 14:28 |
dcapone2004 | lol | 14:28 |
yoctozepto | just paraphrased | 14:28 |
dmsimard | yoctozepto: privacy is a nightmare nowadays :( | 14:28 |
yoctozepto | what is privacy? :D | 14:28 |
kplant | fair enough | 14:28 |
kplant | although zoom is not an ecosystem | 14:28 |
yoctozepto | true that, and not that monopolist | 14:29 |
yoctozepto | but still, got popular, stayed popular | 14:29 |
*** sorin-mihai has quit IRC | 14:30 | |
openstackgerrit | Radosław Piliszek proposed openstack/kolla master: Revert "[to-revert] Pin ovsdbapp in neutron to 1.1.0" https://review.opendev.org/732391 | 14:30 |
*** sorin-mihai has joined #openstack-kolla | 14:31 | |
*** abdysn has quit IRC | 14:36 | |
kplant | lol | 14:47 |
*** ykarel|afk is now known as ykarel | 14:58 | |
*** e0ne_ has joined #openstack-kolla | 14:58 | |
*** e0ne has quit IRC | 14:59 | |
*** diurnalist has joined #openstack-kolla | 15:06 | |
dmsimard | I don't have to bandwidth to be core but I'm hoping to help in different ways | 15:08 |
hrw | good | 15:08 |
*** e0ne_ has quit IRC | 15:11 | |
*** dcapone2004 has quit IRC | 15:17 | |
*** rgogunskiy has quit IRC | 15:22 | |
*** Torel has quit IRC | 15:24 | |
*** Torel has joined #openstack-kolla | 15:26 | |
*** rm_work has joined #openstack-kolla | 15:45 | |
*** ykarel is now known as ykarel|away | 15:45 | |
*** wuchunyang has joined #openstack-kolla | 15:46 | |
*** dcapone2004 has joined #openstack-kolla | 15:54 | |
dcapone2004 | idk if anyone responded to my question as my IRC session disconnected ... | 15:54 |
hrw | dmsimard: ask it again? | 15:55 |
hrw | dcapone2004: but consider that we are in virtual PTG mode so most of us is either busy on zoom or at break in it | 15:56 |
dcapone2004 | yeah I was here earlier for that notice :-) | 15:56 |
dcapone2004 | essentially, I am looking to setup a hyper-converged openstack environment.....I only have 2 interface eno1 and eno2 (for the moment in the lab situation)….eno2 is assigned as the neutron external interface | 15:57 |
dcapone2004 | eno1 is the public interface for the ceph cluster only running on this 3 node deployment and is where the internal/external VIP is for openstack….can I also use that interface for the internal network to network traffic for neutron internal networks using vlans? | 15:58 |
dcapone2004 | I cannot find the physnet name assigned that interface to override ml2_conf.ini and update the ml_type_vlan section and the network_vlan_ranges option | 16:00 |
*** wuchunyang has quit IRC | 16:07 | |
*** seco has quit IRC | 16:15 | |
*** dougsz has quit IRC | 16:22 | |
*** sluna has joined #openstack-kolla | 16:24 | |
*** bornie2bake has joined #openstack-kolla | 16:27 | |
bornie2bake | Hi, is octavia-api broken in ussuri? http://paste.openstack.org/show/794211/ | 16:28 |
*** slunav has joined #openstack-kolla | 16:29 | |
*** sluna has quit IRC | 16:29 | |
bornie2bake | cant create lb via horizon HttpException: 500: Server Error for url: http://10.0.1.5:9876/v2.0/lbaas/loadbalancers, Internal Server Error | 16:29 |
johnsom | That error implies that the [service_auth] or [neutron] section in the Octavia API configuration file is not correct: https://docs.openstack.org/octavia/latest/configuration/configref.html#service-auth | 16:34 |
bornie2bake | http://paste.openstack.org/show/794212/ octavia conf file | 16:36 |
*** dougsz has joined #openstack-kolla | 16:36 | |
bornie2bake | ls /etc/kolla/config/octavia/ | 16:37 |
bornie2bake | client_ca.cert.pem client.cert-and-key.pem server_ca.cert.pem server_ca.key.pem | 16:37 |
johnsom | It might be worth setting up the openstack client with those credentials and see if the account can list the neutron extensions. | 16:42 |
*** sluna has joined #openstack-kolla | 16:43 | |
bornie2bake | octavia account cant access openstack :/ hm... | 16:44 |
*** bengates has quit IRC | 16:57 | |
*** bengates has joined #openstack-kolla | 17:00 | |
*** bornie2bake has quit IRC | 17:01 | |
*** jonaspaulo has joined #openstack-kolla | 17:01 | |
*** k_mouza has quit IRC | 17:03 | |
*** also_stingrayza has joined #openstack-kolla | 17:03 | |
*** bengates has quit IRC | 17:04 | |
*** stingrayza has quit IRC | 17:06 | |
*** dougsz has quit IRC | 17:08 | |
*** muhaha has quit IRC | 17:14 | |
*** k_mouza has joined #openstack-kolla | 17:16 | |
mgoddard | born2bake: we recently merged https://review.opendev.org/#/c/720243/, which I had suspicions might cause problems. Could you try adding the octavia user to the admin project and try again? | 17:16 |
patchbot | patch 720243 - kolla-ansible - Remove octavia user from admin project (MERGED) - 8 patch sets | 17:16 |
mgoddard | born2bake: there is also https://review.opendev.org/#/c/727160/, which is related (read the comments) | 17:17 |
patchbot | patch 727160 - kolla-ansible - Make sure octavia uses service project in service_... - 1 patch set | 17:17 |
*** sorin-mihai_ has joined #openstack-kolla | 17:17 | |
*** amoralej is now known as amoralej|off | 17:18 | |
*** sorin-mihai has quit IRC | 17:18 | |
born2bake | mgoddard thank you, will do | 17:19 |
*** sorin-mihai__ has joined #openstack-kolla | 17:19 | |
*** k_mouza has quit IRC | 17:20 | |
*** sorin-mihai_ has quit IRC | 17:22 | |
*** TrevorV has quit IRC | 17:23 | |
born2bake | johnsom https://prnt.sc/sru9dj I ve created certs via off guide...does it mean that I did something wrong during certs creation? | 17:23 |
johnsom | born2bake Yes, one moment and I can probably figure out the step that has the issue | 17:24 |
johnsom | born2bake So, in your octavia.conf, [certificates] section, there are two setting related to the error you see. ca_private_key and ca_private_key_passphrase. | 17:28 |
*** TrevorV has joined #openstack-kolla | 17:28 | |
born2bake | yeah, both are there :) http://paste.openstack.org/show/794212/ | 17:28 |
johnsom | born2bake Here is a command line to test the values: openssl rsa -in /etc/octavia/certs/server_ca.key.pem and use the ca_private_key_passphrase as the passphrase. You should see the key output in PEM format (text). Also, double check your file permissions such that the account the Octavia process is running under has permission to read the file. | 17:31 |
born2bake | ohh right...permissions. let me check. passphrase is fine just checked | 17:32 |
*** sluna has quit IRC | 17:34 | |
*** gfidente is now known as gfidente|afk | 17:45 | |
*** erolg has quit IRC | 18:03 | |
*** e0ne has joined #openstack-kolla | 18:11 | |
born2bake | johnsom dunno set perms to 700...passphrase is the correct one :/ hm | 18:22 |
born2bake | getting same error... does anybody tried ussuri k-a octavia? | 18:22 |
johnsom | Are the files and directories to get there owned by "octavia" and are the octavia processes running under the "octavia" account? | 18:23 |
*** kplant has quit IRC | 18:23 | |
*** kplant has joined #openstack-kolla | 18:23 | |
johnsom | born2bake Sorry, I don't use kolla. | 18:23 |
born2bake | http://paste.openstack.org/show/794216/ | 18:28 |
*** ricolin has quit IRC | 18:33 | |
johnsom | born2bake and "ps -U octavia" shows the worker process? | 18:33 |
mgoddard | born2bake: did you try my suggestion? | 18:34 |
*** sorin-mihai__ has quit IRC | 18:35 | |
*** sorin-mihai has joined #openstack-kolla | 18:37 | |
*** e0ne has joined #openstack-kolla | 18:37 | |
*** also_stingrayza is now known as stingrayza | 18:38 | |
*** TrevorV has quit IRC | 19:03 | |
*** e0ne has quit IRC | 19:03 | |
*** e0ne has joined #openstack-kolla | 19:03 | |
born2bake | johnsom | 19:06 |
born2bake | (octavia-worker)[octavia@zhavoronok /etc/octavia/certs]$ ps -U octavia | 19:06 |
born2bake | PID TTY TIME CMD | 19:06 |
born2bake | 1 ? 00:00:00 dumb-init | 19:06 |
born2bake | 6 ? 00:00:04 octavia-worker: | 19:06 |
born2bake | 20 ? 00:00:02 octavia-worker: | 19:06 |
born2bake | 23 ? 00:00:00 octavia-worker: | 19:06 |
born2bake | 35 pts/0 00:00:00 bash | 19:06 |
born2bake | 79 pts/0 00:00:00 ps | 19:06 |
*** arxcruz|qa_room is now known as arxcruz | 19:07 | |
born2bake | mgoddard I didnt update k-a but I ve added octavia user to admin proj...I can start creation of lb now but getting that error - https://prnt.sc/sru9dj | 19:07 |
johnsom | Ok, so that should be ok. Hmm, maybe I am reading the context of the error wrong. Can you do "openssl rsa -in client.cert-and-key.pem" and get output without a pass phrase? | 19:09 |
*** dcapone2004 has quit IRC | 19:11 | |
johnsom | I don't think that is the problem, it still seems like there is something wrong with that key file, but thought I would check | 19:12 |
born2bake | openssl rsa -in client.cert-and-key.pem - yeah all good without passphrase | 19:14 |
johnsom | Also, check that the output from the other command, with the pass phrase, outputs "-----BEGIN RSA PRIVATE KEY-----". This would make sure the key isn't in DER format or something strange like that. | 19:14 |
born2bake | writing RSA key | 19:15 |
born2bake | -----BEGIN RSA PRIVATE KEY----- | 19:15 |
johnsom | Yeah, that is what you should get for both commands | 19:15 |
born2bake | hm weird... I will try to create new certs from scratch and re-deploy k-a | 19:15 |
*** e0ne has quit IRC | 19:16 | |
johnsom | Yeah, pretty puzzled. All I can think is there is some permission issue, but if you su - octavia and can read the key with a passphrase, .... Or a typo in the key file path in the config maybe. | 19:16 |
*** TrevorV has joined #openstack-kolla | 19:18 | |
openstackgerrit | Merged openstack/kolla-ansible master: [Community goal] Update the contributor guide https://review.opendev.org/729642 | 19:21 |
*** diurnalist has quit IRC | 19:29 | |
*** jonaspaulo has quit IRC | 19:55 | |
*** diurnalist has joined #openstack-kolla | 20:02 | |
*** radek has quit IRC | 20:04 | |
diurnalist | mgoddard: i have interest in a few kolla topics, but have a lot of conflicts during the Kolla meeting times. tomorrow i can likely only make it to the back half of the first session, and the front half of the next. I have some agenda items to weigh in on, so I will plan on being in the meeting to say hello then | 20:05 |
diurnalist | i am not sure of the agenda for each session but i suppose it is proceeding down the etherpad, in which case this should still allow me to participate in the federation/letsencrypt/tls bit | 20:06 |
*** dcapone2004 has joined #openstack-kolla | 20:13 | |
*** priteau has quit IRC | 20:38 | |
*** dcapone2004 has quit IRC | 20:44 | |
*** rouk has joined #openstack-kolla | 20:46 | |
born2bake | mgoddard johnsom added k-a patches, created certs from scratch https://docs.openstack.org/octavia/latest/admin/guides/certificates.html ; same issue octavia.common.exceptions.CertificateGenerationException: Could not sign the certificate request: Bad decrypt. Incorrect password? I will wait in case if someone will try to deploy octavia in ussuri... | 20:57 |
johnsom | born2bake Ok. Many of us have it going with the Ussuri release, just not necessarily via Kolla. So curious | 20:59 |
*** k_mouza has joined #openstack-kolla | 21:04 | |
*** k_mouza has quit IRC | 21:08 | |
*** vishalmanchanda has quit IRC | 21:24 | |
*** diurnalist has quit IRC | 22:22 | |
*** TrevorV has quit IRC | 22:37 | |
*** diurnalist has joined #openstack-kolla | 22:56 | |
*** diurnalist has quit IRC | 23:50 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!