*** luksky has quit IRC | 00:07 | |
*** schwicht has quit IRC | 00:51 | |
*** schwicht has joined #openstack-kolla | 00:52 | |
openstackgerrit | James Kirsch proposed openstack/kolla-ansible master: Add support for LetsEncrypt-managed certs https://review.opendev.org/c/openstack/kolla-ansible/+/741340 | 01:06 |
---|---|---|
*** zhanglong has joined #openstack-kolla | 01:34 | |
*** schwicht has quit IRC | 02:34 | |
*** zhanglong has quit IRC | 03:51 | |
*** skramaja has joined #openstack-kolla | 03:58 | |
*** vishalmanchanda has joined #openstack-kolla | 04:09 | |
*** schwicht has joined #openstack-kolla | 04:18 | |
*** schwicht has quit IRC | 04:23 | |
*** dmsimard has quit IRC | 05:14 | |
*** dmsimard has joined #openstack-kolla | 05:14 | |
*** zhanglong has joined #openstack-kolla | 05:31 | |
*** ricolin_ has joined #openstack-kolla | 06:17 | |
*** ricolin_ has quit IRC | 06:23 | |
*** Luzi has joined #openstack-kolla | 06:34 | |
*** zhanglong has quit IRC | 06:51 | |
*** amoralej|off is now known as amoralej | 07:01 | |
*** bengates has joined #openstack-kolla | 07:10 | |
*** bengates has quit IRC | 07:10 | |
*** bengates has joined #openstack-kolla | 07:11 | |
*** bengates has quit IRC | 07:16 | |
*** zhanglong has joined #openstack-kolla | 07:23 | |
*** zhanglong has quit IRC | 07:33 | |
*** e0ne has joined #openstack-kolla | 07:57 | |
*** zhanglong has joined #openstack-kolla | 08:10 | |
*** rpittau|afk is now known as rpittau | 08:13 | |
*** e0ne has quit IRC | 08:15 | |
*** bengates has joined #openstack-kolla | 08:20 | |
*** andrewbonney has joined #openstack-kolla | 08:24 | |
*** gfidente|afk is now known as gfidente | 08:35 | |
*** kevko has joined #openstack-kolla | 08:36 | |
openstackgerrit | Michal Nasiadka proposed openstack/kayobe master: Bump max Ansible version to 2.10 https://review.opendev.org/c/openstack/kayobe/+/780898 | 08:40 |
*** zhanglong has quit IRC | 08:46 | |
mgoddard | morning | 08:46 |
mgoddard | yoctozepto: just to add to the drama, quay.io was down 5 hours ago | 08:46 |
yoctozepto | mgoddard: yeah, I love the drama <3 | 08:46 |
yoctozepto | might be they are fixing the bugs I have reported lol | 08:47 |
yoctozepto | (or falling under the rule of kolla) | 08:47 |
mnasiadka | yoctozepto: doesn't look like it was planned - https://status.quay.io/incidents/vfs19hmq660h | 08:49 |
yoctozepto | mnasiadka: aws :-( | 08:49 |
hrw | want container registry in azure? | 08:56 |
yoctozepto | god forbid | 08:57 |
yoctozepto | it would probably make most sense to have one decentralized for our own case, hosted by all the openstack ci resource donators | 08:58 |
openstackgerrit | Mark Goddard proposed openstack/kayobe master: CI: Fix baremetal SSH https://review.opendev.org/c/openstack/kayobe/+/782324 | 09:23 |
*** imcsk8 has quit IRC | 09:24 | |
openstackgerrit | Mark Goddard proposed openstack/kayobe master: CI: Enable bare metal testing for Ubuntu https://review.opendev.org/c/openstack/kayobe/+/782273 | 09:25 |
*** imcsk8 has joined #openstack-kolla | 09:26 | |
*** vishalmanchanda has quit IRC | 09:28 | |
*** wuchunyang has joined #openstack-kolla | 09:29 | |
*** zhanglong has joined #openstack-kolla | 09:33 | |
*** schwicht has joined #openstack-kolla | 09:42 | |
openstackgerrit | Marcin Juszkiewicz proposed openstack/kolla stable/ussuri: Debian: use QEMU 5 from buster-backports https://review.opendev.org/c/openstack/kolla/+/782386 | 09:45 |
openstackgerrit | Mark Goddard proposed openstack/kolla-ansible master: DNM: CI: Enable TLS in all jobs https://review.opendev.org/c/openstack/kolla-ansible/+/782387 | 09:47 |
openstackgerrit | Mark Goddard proposed openstack/kolla-ansible master: DNM: CI: Enable TLS in all jobs https://review.opendev.org/c/openstack/kolla-ansible/+/782387 | 09:48 |
mnasiadka | hmm, ceph is moving to quay.io as well with their container images | 09:49 |
*** wuchunyang has quit IRC | 09:59 | |
*** luksky has joined #openstack-kolla | 10:07 | |
*** Mareo has quit IRC | 10:14 | |
*** e0ne has joined #openstack-kolla | 10:16 | |
*** zhanglong has quit IRC | 10:20 | |
openstackgerrit | Mark Goddard proposed openstack/kolla-ansible master: CI: octavia: check load balancer HTTP response https://review.opendev.org/c/openstack/kolla-ansible/+/782404 | 10:33 |
yoctozepto | mnasiadka: because dockerhub bad | 10:37 |
yoctozepto | docker bad | 10:37 |
yoctozepto | quay good | 10:37 |
yoctozepto | podman good | 10:38 |
yoctozepto | buildah good | 10:38 |
yoctozepto | ;-) | 10:38 |
openstackgerrit | Pierre Riteau proposed openstack/kayobe master: Update seed VM image to CentOS 8.3 https://review.opendev.org/c/openstack/kayobe/+/772700 | 10:38 |
openstackgerrit | Mark Goddard proposed openstack/kayobe master: CI: Fix baremetal SSH https://review.opendev.org/c/openstack/kayobe/+/782324 | 10:46 |
mgoddard | yoctozepto: you on the RH payroll? | 10:46 |
yoctozepto | mgoddard: haha, noo but it was meant to sound like from RH so I guess I succeeded there | 10:47 |
*** schwicht has quit IRC | 10:50 | |
*** yoctozepto has quit IRC | 11:02 | |
*** yoctozepto has joined #openstack-kolla | 11:03 | |
openstackgerrit | Mark Goddard proposed openstack/kayobe master: Ubuntu: AppArmor config for seed VM provisioning https://review.opendev.org/c/openstack/kayobe/+/782272 | 11:07 |
*** glanciano has joined #openstack-kolla | 11:09 | |
hrw | added some notes into whiteboard about current state | 11:10 |
hrw | yoctozepto: you forgot skopeo | 11:10 |
hrw | mgoddard: erlang bump is separate from nova failure | 11:11 |
hrw | mgoddard: nova failure will get fixed once we sort out infra issues at Linaro | 11:11 |
mgoddard | hrw: agreed, but I'd like to see a passing job | 11:11 |
*** vishalmanchanda has joined #openstack-kolla | 11:11 | |
hrw | mgoddard: me too | 11:11 |
hrw | mgoddard: I also need some updates in ussuri. erlang is one of them ;D | 11:13 |
openstackgerrit | Marcin Juszkiewicz proposed openstack/kolla master: WIP: move to Debian 'bullseye' https://review.opendev.org/c/openstack/kolla/+/772479 | 11:25 |
yoctozepto | mgoddard: see!? someone on RH payroll would not forget about skopeo :D | 11:26 |
yoctozepto | we have a classifier | 11:26 |
hrw | yoctozepto: just do not ask me how to use it, ok? | 11:27 |
*** dardelean has joined #openstack-kolla | 11:38 | |
yoctozepto | hahahaha | 11:49 |
*** glanciano18 has joined #openstack-kolla | 11:51 | |
*** glanciano18 has quit IRC | 11:52 | |
*** glanciano has quit IRC | 11:52 | |
*** brinzhang has quit IRC | 11:56 | |
*** brinzhang has joined #openstack-kolla | 11:57 | |
openstackgerrit | Mark Goddard proposed openstack/kayobe master: CI: Fix IP address detection in baremetal compute test https://review.opendev.org/c/openstack/kayobe/+/782324 | 12:07 |
mnasiadka | yoctozepto: maybe just because this is red hat :) | 12:23 |
*** amoralej is now known as amoralej|lunch | 12:32 | |
*** e0ne has quit IRC | 12:36 | |
openstackgerrit | Mark Goddard proposed openstack/kolla-ansible master: DNM: CI: Enable TLS in all jobs https://review.opendev.org/c/openstack/kolla-ansible/+/782387 | 12:38 |
openstackgerrit | Merged openstack/kolla master: centos: enable PowerTools repo in images which needs it https://review.opendev.org/c/openstack/kolla/+/781494 | 12:45 |
yoctozepto | mnasiadka: blue edition | 12:47 |
yoctozepto | da boo dee da boo dye | 12:47 |
mnasiadka | yoctozepto: yeah well, I ,,bled blue'' for 10 years and then I luckily left ;) | 12:48 |
yoctozepto | lol | 12:48 |
mnasiadka | 4 years later I nearly have no PTSD over IBM :D | 12:49 |
yoctozepto | "nearly" | 12:51 |
*** mgoddard has quit IRC | 12:53 | |
*** amoralej|lunch is now known as amoralej | 13:33 | |
*** suff has quit IRC | 13:38 | |
*** suff has joined #openstack-kolla | 13:40 | |
*** e0ne has joined #openstack-kolla | 13:44 | |
openstackgerrit | Pierre Riteau proposed openstack/kolla-ansible master: Add global tag variables for Panko and Skydive https://review.opendev.org/c/openstack/kolla-ansible/+/782525 | 13:50 |
*** dmsimard has quit IRC | 13:53 | |
*** dmsimard has joined #openstack-kolla | 13:54 | |
*** mgoddard has joined #openstack-kolla | 13:57 | |
*** e0ne has quit IRC | 14:00 | |
*** gfidente has quit IRC | 14:16 | |
*** Luzi has quit IRC | 14:53 | |
openstackgerrit | Michal Arbet proposed openstack/kolla-ansible master: Refactor mariadb to support shards https://review.opendev.org/c/openstack/kolla-ansible/+/766952 | 15:23 |
openstackgerrit | Michal Arbet proposed openstack/kolla-ansible master: Rename role haproxy to loadbalancer https://review.opendev.org/c/openstack/kolla-ansible/+/770618 | 15:23 |
kevko | mgoddard: ^^ :) | 15:23 |
openstackgerrit | Michal Arbet proposed openstack/kolla-ansible master: Add proxysql support for database https://review.opendev.org/c/openstack/kolla-ansible/+/770215 | 15:24 |
openstackgerrit | Michal Arbet proposed openstack/kolla-ansible master: Edit services roles to support database sharding https://review.opendev.org/c/openstack/kolla-ansible/+/770216 | 15:24 |
openstackgerrit | Michal Arbet proposed openstack/kolla-ansible master: [CI] Test ProxySQL with shards in the nova cells scenario https://review.opendev.org/c/openstack/kolla-ansible/+/770621 | 15:24 |
openstackgerrit | Michal Arbet proposed openstack/kolla-ansible master: Add mariadb arbitrator to mariadb role https://review.opendev.org/c/openstack/kolla-ansible/+/780811 | 15:24 |
openstackgerrit | Michal Arbet proposed openstack/kolla-ansible master: [CI] Test Mariadb-Arbitrator with shards in the nova cells scenario https://review.opendev.org/c/openstack/kolla-ansible/+/780970 | 15:24 |
openstackgerrit | Mark Goddard proposed openstack/kayobe master: Ubuntu: AppArmor config for seed VM provisioning https://review.opendev.org/c/openstack/kayobe/+/782272 | 15:28 |
*** Wasaac has quit IRC | 15:35 | |
*** ebbex has quit IRC | 15:35 | |
*** dosaboy has quit IRC | 15:35 | |
*** oklhost has quit IRC | 15:36 | |
*** Wasaac has joined #openstack-kolla | 15:36 | |
*** bengates has quit IRC | 15:36 | |
*** dosaboy has joined #openstack-kolla | 15:37 | |
*** frickler has quit IRC | 15:37 | |
*** ebbex has joined #openstack-kolla | 15:37 | |
*** irclogbot_1 has quit IRC | 15:37 | |
*** irclogbot_2 has quit IRC | 15:37 | |
*** frickler has joined #openstack-kolla | 15:37 | |
*** irclogbot_0 has joined #openstack-kolla | 15:38 | |
*** bengates has joined #openstack-kolla | 15:38 | |
*** irclogbot_3 has joined #openstack-kolla | 15:39 | |
kevko | mgoddard: here ? | 15:41 |
mgoddard | kevko: depends :p | 15:41 |
kevko | mgoddard: i've uploaded patch for mariadb ..hope this is one of last change :D | 15:42 |
openstackgerrit | Mark Goddard proposed openstack/kayobe master: Ubuntu: AppArmor config for seed VM provisioning https://review.opendev.org/c/openstack/kayobe/+/782272 | 15:43 |
yoctozepto | kevko: then he ain't around :D | 15:44 |
kevko | :'( | 15:44 |
yoctozepto | :P | 15:45 |
*** irclogbot_3 has quit IRC | 15:51 | |
*** irclogbot_0 has quit IRC | 15:51 | |
*** irclogbot_1 has joined #openstack-kolla | 15:52 | |
*** irclogbot_2 has joined #openstack-kolla | 15:52 | |
kevko | yoctozepto: you can check it also :D | 15:55 |
yoctozepto | kevko: I will, just not today | 15:56 |
yoctozepto | not enough time :-( | 15:56 |
openstackgerrit | Mark Goddard proposed openstack/kolla-ansible master: DNM: CI: Enable TLS in all jobs https://review.opendev.org/c/openstack/kolla-ansible/+/782387 | 15:56 |
kevko | it's infinite :( | 15:57 |
*** bengates has quit IRC | 15:59 | |
*** bengates has joined #openstack-kolla | 15:59 | |
openstackgerrit | Mark Goddard proposed openstack/kolla-ansible master: cinder: fix condition to copy backend TLS certs https://review.opendev.org/c/openstack/kolla-ansible/+/782546 | 16:00 |
*** dking has quit IRC | 16:01 | |
*** amoralej is now known as amoralej|off | 16:04 | |
*** LinPeiWen has quit IRC | 16:06 | |
*** skramaja has quit IRC | 16:08 | |
mgoddard | kevko: we didn't really finish our conversation yesterday | 16:16 |
mgoddard | kevko: if using haproxy, are multiple shards supported, and if so, what happens with shards other than the default? | 16:17 |
*** kevko has quit IRC | 16:29 | |
*** schwicht has joined #openstack-kolla | 16:47 | |
openstackgerrit | James Kirsch proposed openstack/kolla-ansible master: Add support for LetsEncrypt-managed certs https://review.opendev.org/c/openstack/kolla-ansible/+/741340 | 16:47 |
*** bengates has quit IRC | 16:49 | |
*** bengates has joined #openstack-kolla | 16:50 | |
openstackgerrit | Michal Nasiadka proposed openstack/kayobe master: Bump max Ansible version to 2.10 https://review.opendev.org/c/openstack/kayobe/+/780898 | 16:51 |
openstackgerrit | Michal Nasiadka proposed openstack/kolla-ansible master: Add missing octavia-driver-agent https://review.opendev.org/c/openstack/kolla-ansible/+/761872 | 16:55 |
*** bengates has quit IRC | 16:55 | |
*** rouk has joined #openstack-kolla | 17:04 | |
rouk | FYI ubuntu cloud repos moved from 3.1 to 4.2 qemu mid-release, and have broken migrations for all users of epyc that didnt tag their qemu chipset to 3.1 | 17:04 |
rouk | as qemu backported some breaking changes to epyc features, funny huh. in other news, i cant seem to find the most graceful way to add repo keys to kolla? | 17:05 |
*** jonaspaulo has joined #openstack-kolla | 17:19 | |
*** rpittau is now known as rpittau|afk | 17:26 | |
openstackgerrit | Martin Chlumsky proposed openstack/kolla-ansible master: Switch octavia-api to wsgi running under apache. https://review.opendev.org/c/openstack/kolla-ansible/+/779893 | 18:10 |
*** andrewbonney has quit IRC | 18:12 | |
*** vishalmanchanda has quit IRC | 18:17 | |
sean-k-mooney | rouk: with a template-orveriede liek this https://github.com/openstack/kolla/blob/master/contrib/template-override/ovs-dpdk.j2 | 18:25 |
rouk | yeah, i got it all working, still cant workaround this lovely bug, 4.2 includes empty machine types for 5.0, but 3.1 doesnt have empty for 4.2, so unsupported machine type 'pc-i440fx-4.2' | 18:26 |
sean-k-mooney | you just need to look at the docker files for blocks like this https://github.com/openstack/kolla/blob/master/docker/nova/nova-libvirt/Dockerfile.j2#L6 | 18:26 |
rouk | looks like ill have to compile qemu afterall. | 18:26 |
rouk | unless you know of a last ditch method to fix this. | 18:27 |
sean-k-mooney | oh well that example compiles and install ovs-dpdk | 18:27 |
sean-k-mooney | so it would be similar | 18:27 |
rouk | i have debian repos i can throw stuff on, so i can build it externally just fine. | 18:27 |
rouk | not sure how well whatever qemu build process would fit in here. | 18:28 |
rouk | hopefully its just make | 18:28 |
sean-k-mooney | it is more or less | 18:28 |
sean-k-mooney | one sec | 18:28 |
rouk | sean-k-mooney: any final ideas before i go fork qemu and remove that patch? | 18:28 |
sean-k-mooney | i dont properly maintain this anymore but https://opendev.org/x/devstack-plugin-libvirt-qemu/src/branch/master/devstack/libs/libvirt | 18:29 |
sean-k-mooney | has all you need | 18:29 |
sean-k-mooney | not other then aw vm reboot | 18:29 |
rouk | cpu_map doesnt work, cant remove features there, machine type cant be changed unless reboot, same problem as before, anything else i can try? | 18:29 |
rouk | alright, ill build 4.2 without the feature then. | 18:30 |
rouk | 3 days lost, and this will make the victoria migration take an extra 3 months of lead time for me :( | 18:30 |
sean-k-mooney | you will have to patch either qemu or nova i guess | 18:30 |
rouk | qemu seems like the more graceful target. | 18:31 |
sean-k-mooney | while im here. has anyone deployed openstack with kolla-ansible runing all service on port 80/443 bar keysonte | 18:33 |
sean-k-mooney | i know you can basically run all service as subdomain or in sub directores | 18:33 |
sean-k-mooney | but i have not seen docs of how to do that with kolla | 18:33 |
rouk | youre probably in custom haproxy config land | 18:33 |
rouk | though, it should be possible, assuming no client has root url references. | 18:34 |
rouk | sadly, when i looked at it, haproxy configs cant be overriden cleanly, and additional services will get overriden by the default ones if they overlap, so youll probably have to just fork the template. | 18:35 |
sean-k-mooney | ya that is what i was affarid of | 18:37 |
rouk | well, i guess the other question is, what are you trying to solve? | 18:38 |
rouk | no client should see anything except the keystone url. | 18:38 |
sean-k-mooney | i dont want to port forward a bunch of port through my firewall | 18:38 |
sean-k-mooney | so have everythin on 443 bar keystone so that endpoint discovery works | 18:38 |
sean-k-mooney | i can do it by adding new endpoints and just deploying a revers proxy server | 18:39 |
sean-k-mooney | i was going to use traefik for that like i do now to do | 18:40 |
sean-k-mooney | just hoped there was a simple way to have kolla create the correct endpoints | 18:40 |
rouk | i wonder how many of these urls/ports are exposed as vars. | 18:40 |
rouk | probably most/all | 18:40 |
sean-k-mooney | yes i think they are | 18:41 |
rouk | issue is they would be separate vhosts, and would crash on listening on the same port | 18:41 |
sean-k-mooney | i look at this before and tough it sould be doable but never tired and its been 2 years | 18:41 |
sean-k-mooney | well i dont ming if the internal ones are on differnt ports | 18:41 |
sean-k-mooney | just that the external endpoints are shared | 18:41 |
rouk | yeah, i just mean that the way the haproxy config is generated, each service is its own host, on its own port listen | 18:42 |
rouk | if you make the template instead sub-path them, and play with the vars, it might work | 18:42 |
rouk | problem is, theres probably no path var, and its just port. | 18:42 |
sean-k-mooney | well theyer is the fqdn https://github.com/openstack/kolla-ansible/blob/master/ansible/group_vars/all.yml#L260 | 18:45 |
sean-k-mooney | per service | 18:45 |
sean-k-mooney | so i can use subdomains | 18:45 |
sean-k-mooney | and this is how it is used https://github.com/openstack/kolla-ansible/blob/f0e4b582f7073408d9b9f875183a48af9337ad5c/ansible/roles/aodh/defaults/main.yml#L195 | 18:45 |
sean-k-mooney | so i think i can make it work | 18:45 |
sean-k-mooney | i was just hoping there was a document or example of doing it | 18:46 |
sean-k-mooney | at least for subdomains which is not hard i can wildcared *.api.seanmooney.info as a cname | 18:47 |
sean-k-mooney | or list them directly i guess but more work | 18:47 |
sean-k-mooney | im proably going to try setting that up when i redeploy | 18:48 |
sean-k-mooney | if i get it to work ill try and document it | 18:49 |
rouk | id be interested in it, cause yeah, one port would be cool for firewall consistency, instead of ensuring a dmz | 19:00 |
yoctozepto | someone was already working on the dns approach afair | 19:02 |
yoctozepto | the alternative is the path-based approach | 19:02 |
yoctozepto | it should be easy to deliver this in haproxy | 19:04 |
rouk | dns approach? like, SNI? keystone.myopenstack.com? | 19:04 |
yoctozepto | not so much behind | 19:04 |
sean-k-mooney | im pretty sure the dns apparoch can just work if you set all the fqdns in your global.yaml | 19:04 |
sean-k-mooney | rouk: bassicaly ya | 19:04 |
yoctozepto | not really, I'm afraid you need to also tweak the ports | 19:04 |
yoctozepto | and haproxy is not aware of dns-based resolution atm | 19:05 |
rouk | would be interesting, would fall over with my wildcard certs, though, multi-level wildcard certs are hard to get. | 19:05 |
sean-k-mooney | not if you set them all to 80/443 | 19:05 |
yoctozepto | it cares only about ip address and the port | 19:05 |
rouk | if you set them all to 80, youll just error and crash | 19:05 |
yoctozepto | yeah, but you have to set them ;-) | 19:05 |
rouk | unless it will automatically combine them into a single sni listener... | 19:05 |
yoctozepto | you can create multiple with letsencrypt | 19:05 |
yoctozepto | but it's all beyond the current scope of things | 19:06 |
yoctozepto | we only really suport | 19:06 |
yoctozepto | multiplexing via ports | 19:06 |
rouk | yer. ive been playing with getting multi-region working with a single central cert for keystone, and the rest on their own region certs, been fun. | 19:06 |
sean-k-mooney | ya which is fine for most usecause | 19:06 |
rouk | getting kolla to use arbitrary certs per service has sucked. | 19:07 |
rouk | certs get wacky once youre multi-region | 19:07 |
sean-k-mooney | i guess the main issue is https://github.com/openstack/kolla-ansible/blob/master/ansible/roles/nova/defaults/main.yml#L178 | 19:09 |
sean-k-mooney | nova_public_base_endpoint: "{{ public_protocol }}://{{ nova_external_fqdn | put_address_in_context('url') }}:{{ nova_api_port }}" | 19:09 |
sean-k-mooney | while i can cahnge the nova_api_port i cant change it just for the public interface | 19:09 |
rouk | some services have different internal/external ports, is that just something unique to nova? | 19:10 |
rouk | maybe thats something that should be split/defaulted. | 19:11 |
sean-k-mooney | setting nova_public_endpoint diretly would work however | 19:11 |
sean-k-mooney | well these are role defults | 19:12 |
sean-k-mooney | if i define them in global.yaml | 19:12 |
sean-k-mooney | it will have higher precidnce | 19:12 |
rouk | yeah, i just know some services kolla deploys have different external/internal ports, so it might be something that should be done for nova too. | 19:12 |
sean-k-mooney | so i can hard code them or even use templates in my gobal.yaml or inventory | 19:12 |
rouk | like, keystone has different internal/external | 19:13 |
sean-k-mooney | in genral i dont think its need but ya its just been on my todo list to play with | 19:13 |
sean-k-mooney | ya keysonte is slightly different https://github.com/openstack/kolla-ansible/blob/2ba4c88c8dcef579824b58e0ad2a13ae6e187f3b/ansible/group_vars/all.yml#L825-L827 | 19:14 |
sean-k-mooney | its only in all.yml and not defiend in the role defaults | 19:15 |
sean-k-mooney | the internal and publick enpoint both use the same port however | 19:15 |
sean-k-mooney | its only the admin one that is different | 19:15 |
rouk | ah so it is. | 19:15 |
rouk | i know cause i had issues with it recently, cause keystoneclient uses the admin port by default, the only client to do so. | 19:16 |
rouk | blocked admin port from clients, big explosion. | 19:16 |
sean-k-mooney | if i figure it out ill update https://docs.openstack.org/kolla-ansible/latest/admin/advanced-configuration.html#fully-qualified-domain-name-configuration with per service examples | 19:18 |
*** suff has quit IRC | 19:49 | |
*** jonaspaulo has quit IRC | 20:20 | |
*** sean-k-mooney has quit IRC | 20:24 | |
ozzzo | trying to install kolla-ansible train today; I get some kind of download error: | 20:27 |
ozzzo | https://paste.centos.org/view/194782d5 | 20:27 |
ozzzo | is something broken, or is it just me? | 20:27 |
ozzzo | hostname 'files.pythonhosted.org' doesn't match either of 'r.ssl.fastly.net', '*.catchpoint.com',... | 20:28 |
ozzzo | I can successfully pull the file with wget; I end up with pbr-5.5.1.tar.gz | 20:30 |
ozzzo | but that doesn't make the install work | 20:31 |
rouk | sure youre not getting proxied? | 20:33 |
rouk | also whats a pip install ./kolla-ansible? | 20:35 |
rouk | is that some local fork of kolla-ansible? what are you trying to do? | 20:35 |
*** e0ne has joined #openstack-kolla | 20:36 | |
ozzzo | I'm installing it in a venv | 20:44 |
rouk | is the venv ./kolla-ansible | 20:45 |
ozzzo | that's the dir that I downloaded it into | 20:45 |
ozzzo | this normally works but today I'm seeing this download error | 20:45 |
rouk | does the same happen when you just install if from pypi into your venv? | 20:46 |
rouk | just pip install kolla-ansible==[version you want] | 20:46 |
ozzzo | I can try it; do you know the version number for train? | 20:47 |
rouk | could also install from git, if you want latest train specifically. pip install git+https://opendev.org/openstack/kolla-ansible.git@stable/train | 20:48 |
ozzzo | this is how I'm installing it: https://paste.centos.org/view/e052df0a | 20:48 |
ozzzo | yes, that throws the same error | 20:49 |
rouk | you sure you dont have some corporate proxy or something eating your connections? | 20:49 |
ozzzo | no, but if I did, I think the file download would fail when I use wget | 20:50 |
rouk | well, something must be different, as files.pythonhosted.org has a cert for *.pythonhosted.org, not whatever that cert is youre getting. | 20:51 |
ozzzo | yes, something is different | 20:52 |
ozzzo | I'm trying to figure out what has changed | 20:52 |
ozzzo | AFAIK my network didn't change since Friday | 20:52 |
ozzzo | according to this page kolla-ansible Train is version 9: https://releases.openstack.org/teams/kolla.html | 20:58 |
ozzzo | I'll try that | 20:58 |
rouk | not going to change getting the wrong cert for pythonhosted.org, heh | 20:59 |
ozzzo | that installed something; do you know how to check the version of kolla-ansible? | 21:00 |
rouk | kolla-ansible --version? | 21:00 |
ozzzo | tried that | 21:01 |
rouk | well, could just ask pip | 21:03 |
ozzzo | it says: kolla-ansible==9.0.0 | 21:08 |
openstackgerrit | Marcin Juszkiewicz proposed openstack/kolla master: enable 'libvirt' repo for images with python*-libvirt https://review.opendev.org/c/openstack/kolla/+/782606 | 21:08 |
rouk | theres 9.3.1, probably dont want the .0 version, heh. | 21:08 |
ozzzo | ok trying that | 21:09 |
hrw | you always want X.*.* one | 21:09 |
hrw | latest released one | 21:09 |
hrw | for that branch | 21:09 |
ozzzo | ok that seems to have worked | 21:10 |
rouk | i dont see how this could be any different for your pythonhosted issues. | 21:10 |
* hrw out | 21:10 | |
ozzzo | I don't either | 21:24 |
ozzzo | so far nobody on my end is aware of any recent network changes | 21:28 |
*** e0ne has quit IRC | 21:31 | |
*** e0ne has joined #openstack-kolla | 21:32 | |
*** e0ne has quit IRC | 21:35 | |
*** kevko has joined #openstack-kolla | 21:39 | |
ozzzo | turns out I had to install a newer version of setuptools | 21:41 |
*** jbadiapa has quit IRC | 21:45 | |
openstackgerrit | James Kirsch proposed openstack/kolla-ansible master: Add support for LetsEncrypt-managed certs https://review.opendev.org/c/openstack/kolla-ansible/+/741340 | 22:11 |
openstackgerrit | Marcin Juszkiewicz proposed openstack/kolla master: Debian: install newer firmware for qemu/aarch64 https://review.opendev.org/c/openstack/kolla/+/782619 | 22:12 |
*** schwicht has quit IRC | 23:09 | |
*** luksky has quit IRC | 23:22 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!