Tuesday, 2020-10-20

*** bsanjeewa has joined #openstack-kolla00:18
*** bsanjeewa has quit IRC01:09
*** zzzeek has quit IRC02:00
*** zzzeek has joined #openstack-kolla02:01
-openstackstatus- NOTICE: We are investigating an issue with our hosted Gerrit services. We will provide an update as soon as we can. If you want to follow the latest, feel free to join #opendev03:25
*** skramaja has joined #openstack-kolla03:27
*** skramaja_ has joined #openstack-kolla04:09
*** skramaja has quit IRC04:09
*** skramaja_ is now known as skramaja04:09
*** vishalmanchanda has joined #openstack-kolla04:26
-openstackstatus- NOTICE: We identified a possible vulnerability in Gerrit and are investigating the potential impact on our services. Out of an abundance of caution we have taken our OpenDev hosted Gerrit system offline. We will update with more information once we are able.04:30
*** evrardjp has quit IRC04:33
*** evrardjp has joined #openstack-kolla04:33
*** suryasingh has joined #openstack-kolla04:46
*** kemopq has joined #openstack-kolla05:20
*** gfidente has joined #openstack-kolla05:52
*** zzzeek has quit IRC06:01
*** zzzeek has joined #openstack-kolla06:04
*** cah_link has joined #openstack-kolla06:08
*** zzzeek has quit IRC06:32
*** zzzeek has joined #openstack-kolla06:36
*** wuchunyang has joined #openstack-kolla06:56
yoctozeptomorning06:58
yoctozeptohah, so much of my plans for a little upstream in the morning06:58
yoctozeptorescheduling eh06:59
*** rpittau|afk is now known as rpittau07:04
*** bengates has joined #openstack-kolla07:17
*** nikparasyr has joined #openstack-kolla07:20
*** shyamb has joined #openstack-kolla07:26
mnasiadkayoctozepto: well, let's hope they solve it soon07:27
*** dougsz has joined #openstack-kolla07:33
*** shyam89 has joined #openstack-kolla07:34
yoctozeptomnasiadka: infra is comparing backups now07:36
yoctozeptomnasiadka: so it just takes time07:36
yoctozeptono eta as far as I know though07:36
mnasiadkayoctozepto: I'm on #opendev, just read that :)07:36
yoctozeptomnasiadka: OK07:37
*** shyamb has quit IRC07:37
mnasiadkaanyway, let's hope summit platform works a bit better today :D07:37
osmanlicilegimorning07:39
yoctozeptomnasiadka: so far it works pretty well07:42
*** bsanjeewa has joined #openstack-kolla07:42
yoctozeptomnasiadka: it worked well yesterday as well but only after the keynotes07:42
mnasiadkathat's good, I had some other work to do at that time07:43
*** skramaja has quit IRC07:47
*** skramaja has joined #openstack-kolla07:47
mgoddardmorning07:49
*** e0ne has joined #openstack-kolla08:04
hrwwhich timezone CDT is? I can only imagine Polish name so not everyone will understand08:11
yoctozeptohrw: UTC is given as well08:18
yoctozepto"Central Daylight Time (CDT) is 5 hours behind Coordinated Universal Time (UTC)."08:19
hrwonce it load... 'There was a problem with our server, please contact admin.'08:19
yoctozeptogeez, again?08:19
hrwthis time it was privacy badger ;D08:19
yoctozeptoah, yeah; I just disabled it08:20
yoctozeptolet oif track me08:20
hrwI see that messages were written by same team which did translations for my coffee machine...08:21
hrw"Login Required!" "Refill tank!" "Add coffee beans!"08:21
hrw"whatever!" "sensible message!"08:22
mnasiadka"go to hell!" ? :)08:22
hrw'go to hell' is already aggressive08:22
hrwdoes not need '!'08:23
yoctozepto'go to heaven!' then08:23
mnasiadkaultra-aggressive :)08:23
yoctozeptoconfusing message, eh xD08:23
*** vishalmanchanda has quit IRC08:25
*** bengates has quit IRC08:30
hrwmeh. summit agenda is terrible08:30
hrwtitle, speaker, time. no more information08:30
*** bengates has joined #openstack-kolla08:31
mgoddardhrw: looks like that enum change might have caused a problem: https://zuul.opendev.org/t/openstack/build/b57032f2749b4048a5b74e50fc9a2ffc08:31
hrwhm. 3.25GB container image is not small... but nicer than 11GB before08:31
hrwERROR:kolla.common.utils.tempest:Failed to download archive: status_code 40408:32
hrwERROR:kolla.common.utils.tempest:Failed turning any plugins into a plugins archive08:32
hrwso it failed08:32
*** shyam89 has quit IRC08:32
hrw'./tools/build.py tempest' - let's check08:33
*** bengates has quit IRC08:35
-openstackstatus- NOTICE: We identified a possible vulnerability in Gerrit and are investigating the potential impact on our services. Out of an abundance of caution we have taken our OpenDev hosted Gerrit system offline. We will update with more information once we are able.08:37
*** ChanServ changes topic to "We identified a possible vulnerability in Gerrit and are investigating the potential impact on our services. Out of an abundance of caution we have taken our OpenDev hosted Gerrit system offline. We will update with more information once we are able."08:37
*** jonaspaulo has joined #openstack-kolla08:41
hrwINFO:kolla.common.utils.base:Successfully tagged kolla/centos-source-base:10.1.008:41
hrwINFO:kolla.common.utils.base:Built at 2020-10-20 10:41:37.021220 (took 0:00:02.704517)08:41
hrwI like how infra change made base image being same for binary/source08:42
*** bengates has joined #openstack-kolla08:45
*** priteau has joined #openstack-kolla08:46
mgoddardhrw: I mean the JSON error at the bottom of the page. I think it is failing due to enum.Status08:50
hrwmgoddard: thanks. wrote a fix.08:51
mgoddardcool08:51
hrwhttps://paste.centos.org/view/0821bb3208:51
hrwERROR:kolla.common.utils:tempest Failed with status: error08:52
mgoddardhrw: yeah I have a fix for that. Just waiting for gerrit to return from holiday08:53
hrwmgoddard: I pasted that it works after fix ;D (works as: shows error properly)08:54
mgoddardah, nice08:54
*** k_mouza has joined #openstack-kolla08:56
*** bengates has quit IRC09:10
priteauShould we start emailing patches like in the good old days? ;-)09:11
*** bengates has joined #openstack-kolla09:12
*** bengates has quit IRC09:13
mgoddardpriteau: I have printed one out and posted it to you09:13
*** shyamb has joined #openstack-kolla09:23
wuchunyangcould you open review.opendev.org ?09:32
yoctozeptowuchunyang: down for maintenance09:33
wuchunyangyoctozepto thanks :-)09:37
*** shyam89 has joined #openstack-kolla09:39
*** bengates has joined #openstack-kolla09:40
*** shyamb has quit IRC09:42
*** bsanjeewa has quit IRC09:43
*** bengates has quit IRC09:44
*** bsanjeewa has joined #openstack-kolla09:45
*** bengates has joined #openstack-kolla09:45
*** bsanjeewa has quit IRC09:51
*** shyam89 has quit IRC10:02
*** shyamb has joined #openstack-kolla10:03
*** kevko has joined #openstack-kolla10:05
*** bengates_ has joined #openstack-kolla10:05
kevkohi guys, can someone advise me how to solve problem with "keystone | creating services" if i turned on ssl on all places ? keystone is reconfigured ..and if i source admin.rc with https://ip:35357/v3 it's working ..but kolla-toolbox creating services failed :(10:06
kevko(turned on and ran reconfigure )10:06
*** bengates_ has quit IRC10:07
*** bengates has quit IRC10:07
*** bengates has joined #openstack-kolla10:08
mgoddardkevko: have you added your private CA cert to the containers?10:12
mgoddardkevko: https://docs.openstack.org/kolla-ansible/latest/admin/tls.html#adding-ca-certificates-to-the-service-containers10:13
kevkoi've added this to globals.yml10:13
kevko  kolla_enable_tls_internal: "yes"10:13
kevko  kolla_enable_tls_external: "yes"10:13
kevko  kolla_enable_tls_backend: "yes"10:13
kevko  kolla_copy_ca_into_containers: "yes"10:13
mgoddardand copied the private CA to /etc/kolla/certificates/ca?10:14
shyambHi10:15
kevkoi've run kolla-ansible -i inventory certificates ...so these files was generated by kolla-ansible ..so i assume it is ok10:15
shyambDoes kolla-ansible ussuri supports TLS on all endpoints?10:15
shyambmgoddard: ^^10:15
mgoddardshyamb: yes10:15
mgoddardkevko: that should work then10:16
kevkoi think yes it should work10:17
*** wuchunyang has quit IRC10:17
shyambmgoddard: okay, thanks.10:17
kevkomaybe it's problem in kolla-toolbox container ? not imported ca ?10:18
mgoddardkevko: check in /usr/local/share/ca-certificates/10:18
mgoddardkevko: have you set openstack_cacert?10:19
mgoddardhttps://docs.openstack.org/kolla-ansible/latest/admin/tls.html#configuring-a-ca-bundle10:19
shyambmgoddard: Please point me to the TLS configuration doc, if you have it handy10:19
mgoddardshyamb: very handy - I just posted two links to it :)10:20
mgoddardhttps://docs.openstack.org/kolla-ansible/latest/admin/tls.html10:20
shyambmgoddard: great, thanks. :)10:20
kevkomgoddard: yes, problem was openstack_cacert missing10:22
mgoddardkevko: if you think the tls doc needs to be clearer, feel free to make suggestions10:42
mgoddardkevko: it's still fresh10:42
*** k_mouza has quit IRC10:53
*** bengates has quit IRC10:58
-openstackstatus- NOTICE: Update on gerrit downtime: After investigation, we believe the incident is related to a compromised Gerrit user account rather than a vulnerability in Gerrit software. We are continuing to review activity to verify the integrity of git data and expect to have an additional update with possible service restoration in approximately 2 hours.11:05
*** ChanServ changes topic to "Update on gerrit downtime: After investigation, we believe the incident is related to a compromised Gerrit user account rather than a vulnerability in Gerrit software. We are continuing to review activity to verify the integrity of git data and expect to have an additional update with possible service restoration in approximately 2 hours."11:05
*** shyamb has quit IRC11:07
*** bengates has joined #openstack-kolla11:07
*** shyamb has joined #openstack-kolla11:10
*** vishalmanchanda has joined #openstack-kolla11:13
*** wuchunyang has joined #openstack-kolla11:14
mgoddardyoctozepto: have you heard anything from infra about Dockerhub? I'm getting worried we will be hit badly soon11:34
*** shyamb has quit IRC11:36
*** kevko has quit IRC11:38
*** k_mouza has joined #openstack-kolla11:44
yoctozeptomgoddard: nothing; considering recent bad luck you might be true ;p11:47
*** bsanjeewa has joined #openstack-kolla11:51
*** k_mouza has quit IRC11:54
*** kevko has joined #openstack-kolla11:59
*** wuchunyang has quit IRC12:02
*** bsanjeewa has quit IRC12:03
*** kevko has quit IRC12:03
*** dardelean has joined #openstack-kolla12:07
*** bsanjeewa has joined #openstack-kolla12:09
*** weshay|ruck has joined #openstack-kolla12:14
*** k_mouza has joined #openstack-kolla12:50
*** Luzi has joined #openstack-kolla12:55
*** bengates has quit IRC13:00
*** bengates has joined #openstack-kolla13:01
*** bengates_ has joined #openstack-kolla13:01
*** bengates_ has quit IRC13:01
*** bengates_ has joined #openstack-kolla13:02
*** bengates has quit IRC13:03
*** Fl1nt has joined #openstack-kolla13:04
Fl1ntHi everyone, good afternoon!13:04
Fl1ntmgoddard, when you deployed cloudkitty using ES backend, did you used prometheus as a collector too by any chance?13:05
mgoddardFl1nt: nope, using gnocchi13:06
mgoddardI think we had issues with prometheus collector, although it wasn't me that tried13:06
Fl1ntarff, bad luck :( I get an error too: voluptuous.error.MultipleInvalid: required key not provided @ data['extra_args'] was your issue close to that for instance?13:07
Fl1ntHold on... I think I know where that come from.13:08
Fl1ntmgoddard, from my understanding of the cloudkitty doc, it seems like metrics.yml is required for some collector such as prometheus, do we want to include the cloudkitty: /etc/cloudkitty/metrics.yml default file within CK role?13:29
Fl1ntthey themselves provide it, so I guess it should: https://opendev.org/openstack/cloudkitty/src/branch/master/etc/cloudkitty/metrics.yml13:30
mgoddardFl1nt: using a custom metrics.yml is supported13:31
mgoddard/etc/kolla/config/cloudkitty/metrics.yml13:31
Fl1ntI know, it need to be validated, but I think it is a requirement to already be there for prometheus (currently checking) so if it's a requirement, we should include it and upload it to the host when prometheus collector is selected.13:32
Fl1ntIMHO, any kolla-ansible role should work out of the box as soon as the ops use a supported option, so as I'm working to get prometheus and ES as available options for CK out of the box I think it may be there too.13:33
Fl1ntat least the default one.13:33
-openstackstatus- NOTICE: We've confirmed that known compromised identities have been reset or had their accounts disabled, and we are auditing other service accounts for signs of compromise before we prepare to restore Gerrit to working order. We will update again in roughly 2 hours.13:33
*** ChanServ changes topic to "We've confirmed that known compromised identities have been reset or had their accounts disabled, and we are auditing other service accounts for signs of compromise before we prepare to restore Gerrit to working order. We will update again in roughly 2 hours."13:34
Fl1ntwooow13:36
*** TrevorV has joined #openstack-kolla13:37
*** k_mouza has quit IRC13:56
*** k_mouza has joined #openstack-kolla13:57
*** bengates_ has quit IRC14:00
*** bengates has joined #openstack-kolla14:01
*** cah_link has quit IRC14:09
*** kevko has joined #openstack-kolla14:10
kevkoguys, did someone meet this error while openstack switched to TLS ?14:12
kevkoline 2641, in _build_resources reason=six.text_type(exc)) nova.exception.BuildAbortException: Build of instance d7ddd907-67f2-47d9-b4ee-797ac24e601c aborted: Unable to establish connection to http://192.168.205.254:9696/v2.0/ports/aaf04bfc-64e9-4a46-9b00-7893b956efd4: ('Connection aborted.', RemoteDisconnected('Remote end closed connection without response'))14:12
kevko(i really don't know why it is trying to connect to http://) ..14:12
kevkogrepped /etc/kolla on all hosts to match http:// <- nothing , restarted controllers ..nothing .. check endpoints ..nothing14:13
kevkolist ports via openstack port list <- ok ..i really don't know what to do ..14:13
kevkoflushed memcached ..restarted keystones .. no way14:14
kevkoany advice ?14:14
mnasiadkais this internal tls?14:14
kevkomnasiadka: kolla_enable_tls_internal: "yes"14:15
kevkokolla_enable_tls_external: "yes"14:15
kevkokolla_copy_ca_into_containers: "yes"14:15
kevkokolla_enable_tls_backend: "yes"14:15
kevkoopenstack_cacert: "/etc/ssl/certs/ca-certificates.crt"14:15
kevkoyes14:15
mnasiadkaand it's https:// on the internal endpoint in keystone catalog?14:15
kevkoyes !14:16
ozzzokevko: what do you get from: openstack endpoint list|grep 969614:17
priteauDid you restart nova itself?14:17
kevkopriteau: yes14:17
kevkohttp://paste.openstack.org/show/799212/  << endpoints 969614:18
*** k_mouza has quit IRC14:22
kevkoit looks like when nova is creating session it is using http schema instead of https ..14:22
*** cah_link has joined #openstack-kolla14:22
*** bsanjeewa has quit IRC14:33
*** cah_link has quit IRC14:47
*** cmorey has joined #openstack-kolla14:54
dmsimarddoes anyone have an implementation of "nova-manage db archive_deleted_rows" in kolla-ansible ? I'm otherwise trying to find the right pattern to enable it on a single controller14:58
yoctozeptodmsimard: are you trying to have it run on a schedule?15:00
dmsimardyeah, probably weekly in our case15:00
dmsimardI mean, I could probably set up a cron "manually" on a controller that does a "docker exec -it nova_api nova-manage db archive_deleted_rows" but I don't know if that's an antipattern :p15:01
dmsimardI saw there were crons for things like fernet tokens or elasticsearch curators and I'm not sure if I should follow that or not15:03
*** bsanjeewa has joined #openstack-kolla15:05
dmsimarda wild mgoddard has appeared in the keynote :D15:28
mgoddardw00p15:29
mgoddarddmsimard: I have wondered if we need something like that15:29
*** skramaja has quit IRC15:30
*** bsanjeewa_ has joined #openstack-kolla15:31
*** bsanjeewa_ has quit IRC15:37
*** kevko has quit IRC15:37
*** bsanjeewa has quit IRC15:37
-openstackstatus- NOTICE: Auditing is progressing but not particularly quickly. We'll keep updating every 2 hours or so.15:41
*** ChanServ changes topic to "Auditing is progressing but not particularly quickly. We'll keep updating every 2 hours or so."15:41
*** bengates has quit IRC15:44
*** bsanjeewa has joined #openstack-kolla15:45
*** bsanjeewa_ has joined #openstack-kolla15:45
*** e0ne has quit IRC15:55
*** dardelean has quit IRC16:06
*** dougsz has quit IRC16:31
*** KurtB has joined #openstack-kolla16:36
*** rpittau is now known as rpittau|afk16:38
yoctozeptodmsimard: do I need a masterball to have a reasonable chance to catch the legendary mgoddard?16:55
yoctozeptoif he's in his cave, I might go away with a bunch of dusk balls...16:56
*** cmorey has quit IRC17:00
*** Luzi has quit IRC17:09
dmsimardhaha17:18
*** williampiv has quit IRC17:34
*** bsanjeewa has quit IRC17:49
*** bsanjeewa_ has quit IRC17:49
-openstackstatus- NOTICE: Gerrit is offline due to a security compromise. Please refer to https://review.opendev.org/maintenance.html or #opendev for the latest updates.18:01
*** ChanServ changes topic to "Gerrit is offline due to a security compromise. Please refer to https://review.opendev.org/maintenance.html or #opendev for the latest updates."18:01
*** gfidente is now known as gfidente|afk18:02
*** Tengu has quit IRC18:06
*** Tengu has joined #openstack-kolla18:08
*** bsanjeewa_ has joined #openstack-kolla18:20
*** bsanjeewa has joined #openstack-kolla18:20
*** Tengu has quit IRC18:21
*** bsanjeewa_ has quit IRC18:27
*** bsanjeewa has quit IRC18:27
*** Tengu has joined #openstack-kolla18:27
*** bsanjeewa has joined #openstack-kolla18:31
*** bsanjeewa_ has joined #openstack-kolla18:31
*** JamesBenson has joined #openstack-kolla18:32
*** JamesBenson has quit IRC18:36
*** stingrayza has joined #openstack-kolla18:37
*** bsanjeewa_ has quit IRC18:37
*** bsanjeewa has quit IRC18:38
*** also_stingrayza has quit IRC18:40
*** vishalmanchanda has quit IRC18:53
*** nikparasyr has left #openstack-kolla18:53
*** williampiv has joined #openstack-kolla18:59
*** williampiv has quit IRC19:09
*** priteau has quit IRC19:16
*** kemopq has quit IRC19:48
*** williampiv has joined #openstack-kolla20:00
*** williampiv has quit IRC20:10
*** cah_link has joined #openstack-kolla20:40
*** JamesBenson has joined #openstack-kolla20:40
*** cah_link1 has joined #openstack-kolla20:44
*** cah_link has quit IRC20:44
*** cah_link1 is now known as cah_link20:44
*** TrevorV has quit IRC20:55
*** gfidente|afk has quit IRC21:28
*** Fl1nt has quit IRC21:32
*** williampiv has joined #openstack-kolla21:35
*** e0ne has joined #openstack-kolla21:47
*** JamesBenson has quit IRC21:54
*** e0ne has quit IRC22:06
*** jonaspaulo has quit IRC22:37
*** cah_link has quit IRC22:46
*** jbadiapa has quit IRC22:54

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!