*** zhanglong has joined #openstack-kolla | 00:39 | |
*** jcmdln has joined #openstack-kolla | 01:05 | |
*** suryasingh has joined #openstack-kolla | 01:06 | |
*** jcmdln has quit IRC | 01:36 | |
*** JamesBenson has joined #openstack-kolla | 01:39 | |
*** JamesBenson has quit IRC | 01:44 | |
*** jcmdln has joined #openstack-kolla | 01:54 | |
*** brinzhang has joined #openstack-kolla | 01:58 | |
*** JamesBenson has joined #openstack-kolla | 02:51 | |
*** JamesBenson has quit IRC | 02:56 | |
*** rphillips_ has quit IRC | 03:13 | |
*** rphillips has joined #openstack-kolla | 03:13 | |
*** skramaja has joined #openstack-kolla | 03:18 | |
*** zhanglong has quit IRC | 04:09 | |
*** dmsimard2 has joined #openstack-kolla | 04:12 | |
*** dmsimard has quit IRC | 04:13 | |
*** dmsimard2 is now known as dmsimard | 04:13 | |
*** zijlboot has joined #openstack-kolla | 04:21 | |
*** zijlboot has quit IRC | 04:26 | |
*** evrardjp has quit IRC | 04:33 | |
*** evrardjp has joined #openstack-kolla | 04:33 | |
*** logan- has joined #openstack-kolla | 04:40 | |
*** JamesBenson has joined #openstack-kolla | 04:53 | |
*** JamesBenson has quit IRC | 04:57 | |
*** zijlboot has joined #openstack-kolla | 05:15 | |
*** abdysn has joined #openstack-kolla | 05:18 | |
*** zijlboot has quit IRC | 05:21 | |
*** JamesBenson has joined #openstack-kolla | 05:36 | |
*** JamesBenson has quit IRC | 05:40 | |
*** Tony31 has joined #openstack-kolla | 05:47 | |
Tony31 | hi all. Hope you are all keeping safe and well. Would you have any pointers for me to get over an issue that I have? When running "kayobe overcloud host configure" the playbooks hang at the "gathering facts" for one compute host. | 05:49 |
---|---|---|
Tony31 | I've cleared the .ansible cache but it did not help. | 05:50 |
*** brinzhang has quit IRC | 05:51 | |
*** brinzhang has joined #openstack-kolla | 05:51 | |
*** zijlboot has joined #openstack-kolla | 05:56 | |
*** zijlboot has quit IRC | 05:56 | |
*** zijlboot has joined #openstack-kolla | 05:56 | |
Tony31 | I cleared the cache again on both the ansible host and destination host and now it is proceeding | 05:57 |
Tony31 | 🤓 | 05:57 |
*** zijlboot has quit IRC | 05:57 | |
*** zijlboot has joined #openstack-kolla | 05:58 | |
*** ricolin has quit IRC | 06:08 | |
*** weshay|pto has quit IRC | 06:12 | |
*** weshay_ has joined #openstack-kolla | 06:13 | |
*** nikparasyr has joined #openstack-kolla | 06:20 | |
Tony31 | oops stuck again | 06:21 |
*** cah_link has joined #openstack-kolla | 06:28 | |
*** zhanglong has joined #openstack-kolla | 06:31 | |
*** zhanglong has quit IRC | 06:36 | |
*** zhanglong has joined #openstack-kolla | 06:37 | |
*** bengates has joined #openstack-kolla | 07:11 | |
*** abdysn has quit IRC | 07:11 | |
*** abdysn has joined #openstack-kolla | 07:11 | |
*** hjensas has quit IRC | 07:27 | |
mgoddard | Tony31: hi. check if you can ssh to the machine as the stack & kolla users | 07:35 |
mgoddard | Tony31: if that works, see if you can find the remote ansible process on the compute node, to see what it's doing | 07:36 |
mgoddard | sometimes certain fact collectors may hang | 07:36 |
*** JamesBenson has joined #openstack-kolla | 07:37 | |
Tony31 | Hi @mgoddard how are you keeping? Thank you for the tips I'll do this | 07:40 |
*** JamesBenson has quit IRC | 07:41 | |
*** dougsz has joined #openstack-kolla | 07:45 | |
*** e0ne has joined #openstack-kolla | 07:46 | |
mgoddard | Tony31: all fine here thanks. How about you? | 07:51 |
Tony31 | OK here at the moment thank you | 07:54 |
Tony31 | @mgoddard when i press ctrl c to cancel the hanging job I get this as the last command: ansible-playbook -i /etc/kolla/inventory/overcloud -e @/etc/kolla/globals.yml -e @/etc/kolla/passwords.yml -e CONFIG_DIR=/etc/kolla -e virtualenv=/opt/kayobe/venvs/kolla-ansible -e ansible_python_interpreter=/opt/kayobe/venvs/kayobe/bin/python -e ansible_user=cv-user -e kolla_action=bootstrap-servers /home/cv-user/kayobe-project/venvs/kolla-an | 08:04 |
Tony31 | sible/share/kolla-ansible/ansible/kolla-host.yml | 08:04 |
Tony31 | I'm using cv-user as the user to connect to the remote machines but I see in /etc/kolla/inventory/overcloud/hosts has: [overcloud:vars] | 08:05 |
Tony31 | ansible_user=kolla | 08:05 |
Tony31 | is it benign? | 08:05 |
mgoddard | Tony31: we use cv-user to bootstrap kolla user before it exists | 08:06 |
Tony31 | I'm wary about making changes because this was working a few months ago and no changes have been made since it was successfully deployed | 08:06 |
mgoddard | try running ps axf on the remote node, to see what it is doing | 08:06 |
Tony31 | ok will try that. Thank you | 08:07 |
*** evrardjp has quit IRC | 08:14 | |
*** JamesBenson has joined #openstack-kolla | 08:14 | |
*** born2bake has joined #openstack-kolla | 08:14 | |
*** JamesBenson has quit IRC | 08:19 | |
*** evrardjp has joined #openstack-kolla | 08:21 | |
*** Abdallahyas has joined #openstack-kolla | 08:23 | |
*** zhanglong has quit IRC | 08:26 | |
*** gfidente has joined #openstack-kolla | 08:26 | |
Tony31 | I tried doing "kayobe control host bootstrap" and this is giving a big red failure with regards to python 3.6/3.7 - maybe this is the issue | 08:26 |
*** evrardjp has quit IRC | 08:26 | |
*** evrardjp has joined #openstack-kolla | 08:27 | |
*** zhanglong has joined #openstack-kolla | 08:27 | |
Tony31 | second time it ran though | 08:30 |
hrw | yoctozepto: commented on infra wheels patch | 08:38 |
*** hjensas has joined #openstack-kolla | 08:48 | |
*** eliaswimmer has quit IRC | 08:55 | |
mgoddard | Tony31: python3.7? have you installed that manually? | 09:03 |
Tony31 | nop! and it's not installed. might be a one-off weird error:: | 09:06 |
Tony31 | don't match your environment\nIgnoring asyncio: markers 'python_version == \"3.7\"' don't match your environment\nIgnoring sphinxcontrib-jsmath: markers 'python_version == \"3.4\"' don't match your environment\nIgnoring sphinxcontrib-jsmath: markers 'python_version == \"3.5\"' don't match your environment\nIgnoring sphinxcontrib-jsmath: markers 'python_version == \"3.6\"' don't match your environment\nIgnoring sphinxcontrib-jsmath | 09:06 |
Tony31 | : markers 'python_version == \"3.7\"' don't match your environment\nIgnoring sphinxcontrib-serializinghtml: markers 'python_version == \"3.4\"' don't match your env | 09:06 |
Tony31 | re-running the same command again completed successfully, so a little bit weird | 09:06 |
yoctozepto | hrw: did the fixed wheel url boost aarch64 centos8 builds? | 09:06 |
hrw | yoctozepto: not checked | 09:08 |
*** shyamb has joined #openstack-kolla | 09:08 | |
shyamb | Hi | 09:08 |
shyamb | I see 'nova' user id and group id is fixed - 42436 | 09:09 |
shyamb | in nova-api and nova compute containers | 09:09 |
shyamb | Any advantage of this approach? | 09:09 |
yoctozepto | shyamb: sanity | 09:10 |
shyamb | yoctozepto: Sorry, can you elaborate it. | 09:11 |
hrw | shyamb: we wanted to be sure that userid is consistent between containers/distros | 09:12 |
hrw | Tony31: the 'python_version == \"3.4\"' don't match your env' message is harmless | 09:14 |
Tony31 | thank you @hrw | 09:15 |
shyamb | hrw: okay, thank you. | 09:16 |
yoctozepto | shyamb: containers mandate some level of reproducibility, relying on automatic id assignment just makes it harder | 09:16 |
hrw | Tony31: python package lists python 3.[4567] as supported. then you run 'pip install thatpackage' and pip checks which python it runs and lists each other one as not maching | 09:16 |
shyamb | yoctozepto: okay. thank you. That makes sense. | 09:17 |
hrw | shyamb: this way also we do not have conflicts on service owned files in potentially shared filesystems. | 09:17 |
hrw | shyamb: as nova userid != neutron userid where in containers they could be the same by system | 09:17 |
*** eliaswimmer has joined #openstack-kolla | 09:18 | |
hrw | yoctozepto: in https://zuul.openstack.org/builds?job_name=kolla-build-centos8-source-aarch64 I see that it is fast with or without | 09:18 |
shyamb | hrw: yes, in shared file system, definitely it creates conflict . | 09:19 |
Tony31 | Thank you again. I'm trying to figure out why the ansible playbook is hanging when trying to communicate with one of the hosts I have. I had previously successfully deployed openstack 1 or 2 months back. Now I am unable to do the "kayobe overcloud host configure" which is before openstack deployment. There have been no changes to the host or config. The hanging will hang from Friday until Monday at which point i pressed ctrl+c | 09:19 |
*** hjensas has quit IRC | 09:19 | |
shyamb | Hi, One more quick query | 09:23 |
shyamb | I am not able to find which code is responsible to create log directory for particular service | 09:24 |
shyamb | Does this line creates directory and assigns permissions | 09:24 |
shyamb | https://github.com/openstack/kolla-ansible/blob/stable/ussuri/ansible/roles/cinder/templates/cinder-volume.json.j2#L45 | 09:24 |
shyamb | or just assigns permissions? | 09:24 |
yoctozepto | hrw: ack | 09:34 |
*** eliaswimmer has quit IRC | 09:38 | |
*** hjensas has joined #openstack-kolla | 09:51 | |
*** eliaswimmer has joined #openstack-kolla | 09:58 | |
*** iniazi_ has quit IRC | 10:11 | |
*** zijlboot has quit IRC | 10:12 | |
*** JamesBenson has joined #openstack-kolla | 10:15 | |
mgoddard | Tony31: can you provide logs? | 10:15 |
*** JamesBenson has quit IRC | 10:22 | |
*** shyamb has quit IRC | 10:24 | |
*** evrardjp has quit IRC | 10:29 | |
*** evrardjp has joined #openstack-kolla | 10:35 | |
*** eliaswimmer has quit IRC | 10:38 | |
*** ladrua has joined #openstack-kolla | 10:40 | |
*** evrardjp has quit IRC | 10:48 | |
*** shyamb has joined #openstack-kolla | 10:53 | |
*** vishalmanchanda has joined #openstack-kolla | 10:57 | |
*** zhanglong has quit IRC | 11:01 | |
*** bengates has quit IRC | 11:04 | |
*** brinzhang_ has joined #openstack-kolla | 11:05 | |
*** brinzhang has quit IRC | 11:08 | |
*** bengates has joined #openstack-kolla | 11:08 | |
*** bengates has quit IRC | 11:11 | |
*** k_mouza has joined #openstack-kolla | 11:12 | |
*** bengates has joined #openstack-kolla | 11:21 | |
*** eliaswimmer has joined #openstack-kolla | 11:23 | |
*** dougsz has quit IRC | 11:28 | |
*** eliaswimmer has quit IRC | 11:32 | |
shyamb | Hi | 11:35 |
shyamb | TrilioVault need to create a rabbitmq user in openstack | 11:36 |
shyamb | During it's deployment | 11:36 |
shyamb | mgoddard: I see rabbitmq is a separate role | 11:37 |
shyamb | If I need to create a rabbitmq user from my ansible role, what are my options? | 11:37 |
*** JamesBenson has joined #openstack-kolla | 11:45 | |
*** shyamb has quit IRC | 11:45 | |
*** JamesBenson has quit IRC | 11:46 | |
*** JamesBenson has joined #openstack-kolla | 11:46 | |
*** bengates has quit IRC | 11:46 | |
*** bengates has joined #openstack-kolla | 11:47 | |
*** k_mouza has quit IRC | 11:52 | |
*** bengates has quit IRC | 11:52 | |
*** abdysn has quit IRC | 11:58 | |
*** Abdallahyas has quit IRC | 11:58 | |
*** abdysn has joined #openstack-kolla | 11:59 | |
*** bengates has joined #openstack-kolla | 12:07 | |
*** brinzhang0 has joined #openstack-kolla | 12:14 | |
*** brinzhang_ has quit IRC | 12:18 | |
mgoddard | shyamb: https://docs.ansible.com/ansible/latest/modules/rabbitmq_user_module.html | 12:19 |
*** dougsz has joined #openstack-kolla | 12:24 | |
*** eliaswimmer has joined #openstack-kolla | 12:33 | |
*** jopdorp has joined #openstack-kolla | 12:41 | |
*** zijlboot has joined #openstack-kolla | 12:41 | |
*** e0ne_ has joined #openstack-kolla | 12:45 | |
*** e0ne has quit IRC | 12:49 | |
*** jopdorp has quit IRC | 13:03 | |
*** jopdorp has joined #openstack-kolla | 13:03 | |
*** ricolin has joined #openstack-kolla | 13:22 | |
*** TrevorV has joined #openstack-kolla | 13:23 | |
*** Guest49795 has joined #openstack-kolla | 13:30 | |
Guest49795 | Yo everyone! | 13:31 |
*** Fl1nt has quit IRC | 13:33 | |
*** Guest49795 is now known as Fl1nt | 13:34 | |
Fl1nt | aaaah nick's back ^^ love the ghost command :D | 13:34 |
Fl1nt | QQ: When I want to build grafana image, kolla try to also build monasca-grafana, how can I stop that behavior? | 13:35 |
*** hongbin has joined #openstack-kolla | 13:40 | |
*** kevko has joined #openstack-kolla | 13:48 | |
*** ewimmer_ has joined #openstack-kolla | 13:59 | |
*** eliaswimmer has quit IRC | 14:02 | |
*** ewimmer_ has quit IRC | 14:04 | |
*** abdysn has quit IRC | 14:06 | |
*** eliaswimmer has joined #openstack-kolla | 14:07 | |
*** hongbin has quit IRC | 14:14 | |
*** brinzhang_ has joined #openstack-kolla | 14:27 | |
*** e0ne has joined #openstack-kolla | 14:28 | |
*** e0ne_ has quit IRC | 14:29 | |
*** brinzhang0 has quit IRC | 14:30 | |
*** brinzhang has joined #openstack-kolla | 14:31 | |
*** brinzhang_ has quit IRC | 14:33 | |
*** hongbin has joined #openstack-kolla | 14:39 | |
*** eliaswimmer has quit IRC | 14:48 | |
*** eliaswimmer has joined #openstack-kolla | 14:48 | |
*** e0ne_ has joined #openstack-kolla | 14:56 | |
mgoddard | Fl1nt: ^grafana | 14:57 |
mgoddard | mgoddard mnasiadka hrw egonzalez yoctozepto rafaelweingartne cosmicsound osmanlicilegi bbezak | 14:58 |
mgoddard | meeting in 2 minutes ^ | 14:58 |
*** e0ne has quit IRC | 14:59 | |
*** jovial[m] has joined #openstack-kolla | 14:59 | |
*** priteau has joined #openstack-kolla | 14:59 | |
mgoddard | #startmeeting kolla | 15:00 |
openstack | Meeting started Wed Aug 12 15:00:10 2020 UTC and is due to finish in 60 minutes. The chair is mgoddard. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:00 |
*** openstack changes topic to " (Meeting topic: kolla)" | 15:00 | |
openstack | The meeting name has been set to 'kolla' | 15:00 |
mgoddard | #topic rollcall | 15:00 |
*** openstack changes topic to "rollcall (Meeting topic: kolla)" | 15:00 | |
mgoddard | o/ | 15:00 |
*** cah_link has quit IRC | 15:00 | |
jovial[m] | hi everybody | 15:01 |
*** cah_link has joined #openstack-kolla | 15:01 | |
yoctozepto | o/ | 15:01 |
yoctozepto | hi jovial[m] | 15:01 |
hrw | \o | 15:01 |
mgoddard | #topic agenda | 15:03 |
*** openstack changes topic to "agenda (Meeting topic: kolla)" | 15:03 | |
mgoddard | * Roll-call | 15:03 |
priteau | o/ | 15:03 |
mgoddard | * Announcements | 15:03 |
mgoddard | ** Kolla klub tomorrow | 15:03 |
mgoddard | * Review action items from last meeting | 15:03 |
mgoddard | * CI status | 15:03 |
mgoddard | * Victoria release planning (kayobe) | 15:03 |
mgoddard | * Victoria release planning (kolla & kolla ansible) | 15:03 |
mgoddard | * Kolla klub and kall | 15:03 |
mgoddard | #topic announcements | 15:03 |
*** openstack changes topic to "announcements (Meeting topic: kolla)" | 15:03 | |
bbezak | o/ | 15:04 |
mgoddard | #info Taking a break from Kolla Klub meetings for a while. The next meeting will be 10th September | 15:04 |
mgoddard | Any others? | 15:04 |
hrw | nope | 15:05 |
mgoddard | #info PTL away next week Tuesday - Thursday | 15:05 |
mgoddard | Looking for someone to chair the meeting, and kolla kall | 15:06 |
yoctozepto | \o/ | 15:06 |
yoctozepto | two hands | 15:07 |
mgoddard | thanks yoctozepto | 15:07 |
mgoddard | #topic Review action items from last meeting | 15:07 |
*** openstack changes topic to "Review action items from last meeting (Meeting topic: kolla)" | 15:07 | |
mgoddard | mnasiadka to look into kolla stein ironic-conductor failure | 15:07 |
mgoddard | mgoddard to message openstack-discuss about focal & victoria upgrade | 15:07 |
mgoddard | I didn't see anything from mnasiadka about it | 15:08 |
mgoddard | I started an email but didn't hit send.... | 15:08 |
mgoddard | #action mgoddard to message openstack-discuss about focal & victoria upgrade | 15:08 |
mgoddard | #topic CI status | 15:08 |
*** openstack changes topic to "CI status (Meeting topic: kolla)" | 15:08 | |
mgoddard | We had a few issues recently | 15:09 |
mgoddard | Ansible breaking changes | 15:09 |
mgoddard | Looks like the whiteboard needs updating | 15:09 |
yoctozepto | handled for ci | 15:09 |
mgoddard | yoctozepto: I think master and ussuri are fixed? | 15:09 |
yoctozepto | yes, these | 15:09 |
yoctozepto | the rest are red | 15:10 |
yoctozepto | the wb is up-to-dat | 15:10 |
yoctozepto | e | 15:10 |
yoctozepto | haha, true that | 15:10 |
mgoddard | I think that bifrost on train issue is still present | 15:12 |
*** cah_link has quit IRC | 15:13 | |
mgoddard | any other CI issues we should discuss? | 15:13 |
yoctozepto | yeah, i haven't looked into it, left ironic to ironic experts :-) | 15:13 |
yoctozepto | nah, etcd3gw being handled right now | 15:14 |
yoctozepto | we could discuss the non-ci approach to new ansible behaviour | 15:14 |
yoctozepto | but I guess they will be reverting it for now, so only need for future versions | 15:14 |
yoctozepto | ansible-lint might start alerting soon | 15:15 |
*** skramaja has quit IRC | 15:16 | |
mgoddard | #topic Victoria release planning (kayobe) | 15:16 |
*** openstack changes topic to "Victoria release planning (kayobe) (Meeting topic: kolla)" | 15:16 | |
mgoddard | priteau jovial[m] dougsz | 15:16 |
priteau | o/ | 15:17 |
mgoddard | anything happening in kayobe land? | 15:17 |
priteau | Not much at the moment :( | 15:17 |
jovial[m] | sorry, been on holiday, so no updates from me | 15:17 |
mgoddard | ok | 15:17 |
mgoddard | #topic Victoria release planning (kolla & kolla ansbile) | 15:18 |
*** openstack changes topic to "Victoria release planning (kolla & kolla ansbile) (Meeting topic: kolla)" | 15:18 | |
mgoddard | nice to see focal merge | 15:18 |
yoctozepto | ++ | 15:18 |
mgoddard | is there more we need to do there? | 15:18 |
yoctozepto | I turned to optimisations and refactoring | 15:18 |
yoctozepto | I guess clean up after the workaround | 15:19 |
yoctozepto | but it's included | 15:19 |
yoctozepto | otherwise focal seems focally working | 15:19 |
hrw | infra images are boring | 15:19 |
hrw | I rebased them and iirc they even passed zuul | 15:19 |
hrw | have to sit one day and take a look what needs to be done | 15:20 |
mgoddard | that's good, we should aim to focus on those soon | 15:20 |
hrw | as I am losing track | 15:20 |
*** nikparasyr has left #openstack-kolla | 15:21 | |
mgoddard | Any other things to discuss? | 15:22 |
mgoddard | we should try to look at wuchunyang's octavia patch too | 15:22 |
hrw | and recheck victoria 'priorities' | 15:22 |
hrw | which ones will go and which postpone | 15:23 |
wuchunyang | now , neutron plugin linuxbridge has some problem with multi nodes | 15:23 |
mgoddard | I am operating at 1/2 speed. It is 33C here | 15:23 |
yoctozepto | mgoddard: similar issues here :-( | 15:24 |
wuchunyang | is anyone good at neutron ? | 15:24 |
yoctozepto | wuchunyang: I guess me and mnasiadka | 15:25 |
wuchunyang | i will message you after meeting. | 15:25 |
yoctozepto | I just never really touched octavia | 15:25 |
yoctozepto | I will be out but yeah, give me a ping about it | 15:26 |
mgoddard | I haven't really used linuxbridge | 15:26 |
wuchunyang | yes ,i have not use linuxbridge.. but we support it | 15:26 |
yoctozepto | we do | 15:26 |
wuchunyang | ovs tests well .. | 15:26 |
wuchunyang | i works with multi nodes . | 15:27 |
*** bengates has quit IRC | 15:28 | |
wuchunyang | mgoddard what about we don't support linxubridge neutron plugin agent when network type is tenant ? | 15:28 |
mgoddard | wuchunyang: that would be fine for me | 15:29 |
mgoddard | we can document it, if someone wants to improve, they can | 15:29 |
wuchunyang | ok, i will remove the linuxbridge network code .i someone needed , use provider network instead.. | 15:30 |
mgoddard | has anyone looked at the lets encrypt patches yet? | 15:30 |
headphoneJames | started to | 15:30 |
yoctozepto | wuchunyang: and what about ovn? | 15:31 |
dougsz | sorry - working on a deployment atm | 15:31 |
wuchunyang | now i only work on openvswitch. .. | 15:31 |
yoctozepto | ok | 15:33 |
wuchunyang | # Valid options are [ openvswitch, linuxbridge, vmware_nsxv, vmware_nsxv3, vmware_dvs ] | 15:33 |
wuchunyang | # if vmware_nsxv3 is selected, enable_openvswitch MUST be set to "no" (default is yes) | 15:33 |
wuchunyang | neutron_plugin_agent: "linuxbridge" | 15:33 |
wuchunyang | do we support ovn ? | 15:33 |
mgoddard | Looks like globals.yml needs updating | 15:35 |
wuchunyang | add ovn to Valid options ? | 15:35 |
mgoddard | yes | 15:35 |
wuchunyang | ok, i add it now .. | 15:36 |
mgoddard | thanks | 15:36 |
mgoddard | Any other Victoria features to discuss? | 15:37 |
headphoneJames | I will look more into letsencrypt this week | 15:37 |
headphoneJames | we will likely need a new command to generate certs from letsencrypt | 15:38 |
mgoddard | headphoneJames: a new command? | 15:38 |
headphoneJames | the command needs to first deploy containers (including web server to respond to certbot), then execute certbot | 15:39 |
headphoneJames | assuming this happens prior to openstack deploy | 15:39 |
mgoddard | is this not something we can just integrate into the existing flow? | 15:39 |
mgoddard | I might be missing something | 15:40 |
headphoneJames | or I might be :) | 15:40 |
headphoneJames | the "certificates" command does not execute any deployment | 15:40 |
mgoddard | I thought that you could just deploy certbot and have it request and rotate certs in the background? | 15:41 |
mgoddard | or perhaps under cron | 15:41 |
mgoddard | haven't used it directly | 15:41 |
headphoneJames | I believe there needs to be a webserver component as well | 15:41 |
mgoddard | yes | 15:41 |
mgoddard | for the challenge | 15:41 |
hrw | certbot can listen on it's own for challenge | 15:41 |
headphoneJames | that letsencrypt uses to validate the challenge | 15:41 |
headphoneJames | hrw: ok, I'll look into that | 15:42 |
mgoddard | we should probably read the patch and then discuss | 15:42 |
headphoneJames | however, certbot needs to run on the server that the domain name is pointing to | 15:42 |
headphoneJames | that still required a container running certbot | 15:43 |
mgoddard | right, I think it needs to run wherever haproxy runs? | 15:43 |
headphoneJames | yes | 15:43 |
mgoddard | and we would have a haproxy rule to forward a certain path to certbot | 15:43 |
headphoneJames | so, how would this integrate into our "certificates" role, which is execute before deployment? | 15:44 |
mgoddard | I'm sure we aren't the first people to try this. We should look for other examples of good practise | 15:44 |
mgoddard | does this need to integrate with the certificates role? | 15:45 |
headphoneJames | no, but thats what the patch indicates | 15:45 |
mgoddard | ok | 15:46 |
mgoddard | let's move on as I don't know what I'm talking about | 15:46 |
mgoddard | Any other V topics? | 15:46 |
mgoddard | #topic Open discussion | 15:48 |
*** openstack changes topic to "Open discussion (Meeting topic: kolla)" | 15:48 | |
headphoneJames | https://review.opendev.org/#/c/745214/ | 15:49 |
patchbot | patch 745214 - kolla-ansible - Add Keep Alive Timeout for httpd - 2 patch sets | 15:49 |
headphoneJames | anything left to do in this patch? | 15:49 |
mgoddard | headphoneJames: it has my +2... | 15:49 |
* hrw off | 15:51 | |
mgoddard | ok, let's end it there | 15:52 |
mgoddard | thanks everyone | 15:52 |
mgoddard | #endmeeting | 15:52 |
*** openstack changes topic to "Vote on Victoria priorities https://bit.ly/2ActPtx | IRC meetings on Wednesdays @ 15:00 UTC - agenda @ https://goo.gl/OXB0DL | Whiteboard: https://bit.ly/2MM7mWF | IRC channel is *LOGGED* @ http://goo.gl/3mzZ7b" | 15:52 | |
openstack | Meeting ended Wed Aug 12 15:52:09 2020 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:52 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/kolla/2020/kolla.2020-08-12-15.00.html | 15:52 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/kolla/2020/kolla.2020-08-12-15.00.txt | 15:52 |
openstack | Log: http://eavesdrop.openstack.org/meetings/kolla/2020/kolla.2020-08-12-15.00.log.html | 15:52 |
* mgoddard melting | 15:52 | |
wuchunyang | hi yoctozepto ? | 15:54 |
*** eliaswimmer has quit IRC | 15:56 | |
*** eliaswimmer has joined #openstack-kolla | 16:03 | |
*** dougsz has quit IRC | 16:33 | |
*** hongbin has quit IRC | 16:43 | |
*** mgoddard has quit IRC | 16:56 | |
*** hongbin has joined #openstack-kolla | 17:00 | |
*** mgoddard has joined #openstack-kolla | 17:02 | |
*** kevko has quit IRC | 17:15 | |
*** priteau has quit IRC | 17:27 | |
*** mgoddard has quit IRC | 17:28 | |
*** mgoddard has joined #openstack-kolla | 17:34 | |
*** e0ne_ has quit IRC | 17:41 | |
*** e0ne has joined #openstack-kolla | 17:42 | |
*** dking has joined #openstack-kolla | 17:43 | |
*** e0ne has quit IRC | 17:44 | |
*** e0ne has joined #openstack-kolla | 17:49 | |
*** mgoddard has quit IRC | 17:55 | |
*** mgoddard has joined #openstack-kolla | 18:02 | |
*** jopdorp has quit IRC | 18:02 | |
*** jopdorp has joined #openstack-kolla | 18:02 | |
*** wuchunyang has quit IRC | 18:05 | |
*** vkmc_ has joined #openstack-kolla | 18:13 | |
*** kevko has joined #openstack-kolla | 18:13 | |
*** gouthamr has quit IRC | 18:20 | |
*** vkmc has quit IRC | 18:20 | |
*** vkmc_ is now known as vkmc | 18:20 | |
*** gouthamr has joined #openstack-kolla | 18:22 | |
*** mgoddard has quit IRC | 18:23 | |
*** e0ne has quit IRC | 18:23 | |
*** ricolin has quit IRC | 18:23 | |
*** mgoddard has joined #openstack-kolla | 18:25 | |
*** kevko has quit IRC | 18:28 | |
*** jopdorp has quit IRC | 18:29 | |
*** e0ne has joined #openstack-kolla | 18:29 | |
*** jonaspaulo has joined #openstack-kolla | 18:57 | |
*** k_mouza has joined #openstack-kolla | 19:23 | |
*** hongbin has quit IRC | 19:26 | |
*** k_mouza has quit IRC | 19:27 | |
*** hongbin has joined #openstack-kolla | 19:44 | |
*** e0ne has quit IRC | 19:49 | |
*** numans has quit IRC | 19:51 | |
oncall-pokemon | Is it possible to add a label to the containers that are prebuilt? | 20:11 |
*** jonaspaulo has quit IRC | 20:17 | |
*** TrevorV has quit IRC | 20:24 | |
*** e0ne has joined #openstack-kolla | 20:40 | |
*** e0ne has quit IRC | 21:15 | |
*** vishalmanchanda has quit IRC | 21:55 | |
*** zijlboot has quit IRC | 22:06 | |
*** zijlboot has joined #openstack-kolla | 22:07 | |
*** gfidente has quit IRC | 22:16 | |
*** zijlboot has quit IRC | 22:17 | |
*** born2bake has quit IRC | 22:51 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!