Monday, 2021-04-26

*** k_mouza_ has quit IRC00:10
*** LinPeiWen45 has joined #openstack-kolla00:55
*** mchlumsky has joined #openstack-kolla01:19
*** k_mouza has joined #openstack-kolla02:10
*** k_mouza has quit IRC02:15
*** zzzeek has quit IRC02:48
*** zzzeek has joined #openstack-kolla02:50
*** e0ne has joined #openstack-kolla02:57
*** e0ne has quit IRC02:57
*** LinPeiWen45 has quit IRC03:01
*** LinPeiWen74 has joined #openstack-kolla03:17
*** LinPeiWen74 has quit IRC03:31
*** LinPeiWen90 has joined #openstack-kolla04:51
*** vishalmanchanda has joined #openstack-kolla04:52
*** LinPeiWen90 has quit IRC05:00
*** cah_link has joined #openstack-kolla05:22
*** LinPeiWen92 has joined #openstack-kolla05:26
*** LinPeiWen92 has quit IRC05:31
*** strigazi has quit IRC05:37
*** strigazi has joined #openstack-kolla05:39
*** LinPeiWen has quit IRC05:48
*** LinPeiWen has joined #openstack-kolla05:49
yoctozeptomgoddard: yw05:59
yoctozeptomorning05:59
*** k_mouza has joined #openstack-kolla05:59
*** k_mouza has quit IRC06:04
*** luksky has joined #openstack-kolla06:09
*** LinPeiWen92 has joined #openstack-kolla06:17
*** luksky has quit IRC06:17
*** luksky has joined #openstack-kolla06:18
*** k_mouza has joined #openstack-kolla06:23
*** k_mouza has quit IRC06:27
mnasiadkamorning06:32
openstackgerritMichal Nasiadka proposed openstack/kayobe master: Use OpenStack Wallaby release  https://review.opendev.org/c/openstack/kayobe/+/78792307:04
*** andrewbonney has joined #openstack-kolla07:07
openstackgerritMichal Nasiadka proposed openstack/kayobe-config master: Sync kayobe-config with kayobe changes  https://review.opendev.org/c/openstack/kayobe-config/+/78792407:07
*** rpittau|afk is now known as rpittau07:12
mnasiadkamgoddard, yoctozepto: CI cephadm ubuntu job started failing, due to backlevel Ceph client version - https://review.opendev.org/c/openstack/kolla-ansible/+/78775307:16
yoctozeptomnasiadka: uh-oh, can we get newer clients in ubuntu perhaps?07:18
mnasiadkayoctozepto: well, we install them from distro packages, as on all other distros07:18
yoctozeptook, makes sense07:18
yoctozeptoUCA probably does not bump it then :D07:19
mnasiadkahttps://packages.ubuntu.com/focal-updates/python3-rbd07:19
mnasiadkaand 15.2.11 fixes a security flaw07:19
mnasiadkaprobably it will show up sooner or later in Ubuntu repos, but...07:19
yoctozeptooh well07:20
*** k_mouza has joined #openstack-kolla07:24
openstackgerritMerged openstack/kayobe master: Add release note for multiple environments  https://review.opendev.org/c/openstack/kayobe/+/78602307:24
yoctozepto"When this option is set to false, then an unpatched client will not be able to reconnect to the cluster after an intermittent network disruption breaking its connect to a monitor"07:26
yoctozeptohmm07:26
yoctozeptoI truly wonder how it applied to our CI07:26
*** bengates has joined #openstack-kolla07:26
yoctozeptoah07:26
yoctozeptoauth_expose_insecure_global_id_reclaim07:26
yoctozeptoso monitors are ugly here07:27
*** shyamb has joined #openstack-kolla07:27
*** shyam89 has joined #openstack-kolla07:28
*** k_mouza has quit IRC07:29
yoctozeptomgoddard: when you have a sec to make our gerrit bot more talkative https://review.opendev.org/c/openstack/project-config/+/78788707:33
openstackgerritMerged openstack/kolla-ansible master: Add global tag variables for Panko and Skydive  https://review.opendev.org/c/openstack/kolla-ansible/+/78252507:43
openstackgerritMerged openstack/kolla-ansible master: docs: Improve policy documentation  https://review.opendev.org/c/openstack/kolla-ansible/+/78380907:44
openstackgerritMerged openstack/kayobe master: zuul: add more irrelevant files  https://review.opendev.org/c/openstack/kayobe/+/78381907:44
*** openstack has joined #openstack-kolla07:53
*** ChanServ sets mode: +o openstack07:53
*** brinzhang_ has quit IRC07:55
*** dougsz has joined #openstack-kolla08:02
*** jbadiapa has joined #openstack-kolla08:02
*** shyam89 has quit IRC08:05
*** shyamb has quit IRC08:05
mnasiadkayoctozepto: btw, Debian seems to be special - https://packages.debian.org/search?keywords=python3-rbd08:08
mnasiadkastill on Nautilus08:08
yoctozeptooh, duck my cluster08:08
yoctozeptowell, nautilus performs well08:08
*** parallax has joined #openstack-kolla08:08
*** k_mouza has joined #openstack-kolla08:09
mnasiadkawell, 14.2.20 has the security fix, but it's only in Sid08:09
mnasiadkahttps://docs.ceph.com/en/latest/security/CVE-2021-20288/08:09
yoctozeptoperhaps not enough ceph love there08:09
yoctozeptowe don't even test ceph on debian08:10
openstackgerritPierre Riteau proposed openstack/kayobe master: Use released version of mrlesmithjr.mdadm  https://review.opendev.org/c/openstack/kayobe/+/78793408:10
*** e0ne has joined #openstack-kolla08:10
*** openstackgerrit has quit IRC08:11
*** hrw has joined #openstack-kolla08:21
*** hrw has joined #openstack-kolla08:22
*** openstackgerrit has joined #openstack-kolla08:23
openstackgerritPierre Riteau proposed openstack/kayobe stable/stein: Use released version of mrlesmithjr.mdadm  https://review.opendev.org/c/openstack/kayobe/+/78793608:23
hrwmorning08:23
*** lxkong has quit IRC08:24
*** emccormick has quit IRC08:25
openstackgerritPierre Riteau proposed openstack/kayobe stable/train: Use released version of mrlesmithjr.mdadm  https://review.opendev.org/c/openstack/kayobe/+/78793708:25
*** PrinzElvis has quit IRC08:25
openstackgerritPierre Riteau proposed openstack/kayobe stable/ussuri: Use released version of mrlesmithjr.mdadm  https://review.opendev.org/c/openstack/kayobe/+/78793808:25
openstackgerritPierre Riteau proposed openstack/kayobe stable/victoria: Use released version of mrlesmithjr.mdadm  https://review.opendev.org/c/openstack/kayobe/+/78793908:26
*** gfidente|afk is now known as gfidente08:26
*** emccormick has joined #openstack-kolla08:29
*** PrinzElvis has joined #openstack-kolla08:30
priteauAnother week, another CI breakage /o\08:30
*** lxkong has joined #openstack-kolla08:30
*** k_mouza has quit IRC08:31
mnasiadkapriteau: somehow we need to reach 80% firefighting :)08:35
hrwtia08:41
openstackgerritMichal Nasiadka proposed openstack/kayobe master: Use OpenStack Wallaby release  https://review.opendev.org/c/openstack/kayobe/+/78792308:45
yoctozeptoI'm not saying anything08:45
mgoddardFIRE! FIRE! FIRE!08:45
yoctozeptohere he comes08:46
mgoddardEVERYONE CALM DOWN!08:46
mgoddardTHERE'S A SMALL FIRE WE NEED TO PUT OUT08:46
mnasiadkait's not small, it's on all branches! ;)08:46
yoctozeptois it only me or is mgoddard acting like I should?08:46
mgoddardPANIC! PANIC! PANIC!08:46
* mgoddard segfaults08:47
mnasiadkayoctozepto: mgoddard is in yoctozepto emulation mode08:47
mnasiadkaare all the CI Issues on the whiteboard valid, or are we just putting stuff in there and never removing?08:47
yoctozeptoso I'm now getting implemented, huh?08:48
yoctozeptonice08:48
yoctozeptomnasiadka: the cephadm one is likely fixed08:48
mnasiadkayoctozepto: it fixed itself08:48
yoctozeptoothers true08:48
mnasiadka:D08:48
*** shyamb has joined #openstack-kolla08:48
*** shyam89 has joined #openstack-kolla08:48
yoctozepto:D08:49
yoctozeptonow, that's what we call self-healing08:49
mgoddardwell we normally go through them in the IRC meeting, hopefully cleaning things up08:50
hrwhttps://review.opendev.org/q/topic:%22prepare-for-kolla-wallaby-release%22+(status:open%20OR%20status:merged) - any review plans?08:55
hrwas it looks like only patches are there now ;D08:55
*** shyam89 has quit IRC09:03
*** shyamb has quit IRC09:03
*** shyam89 has joined #openstack-kolla09:03
*** shyamb has joined #openstack-kolla09:03
*** k_mouza has joined #openstack-kolla09:04
hrwyoctozepto: as you dropped neutron plugins from source images, then maybe it is time to drop them from binary too? that way one relnote09:06
yoctozeptohrw: relnote talks about source only09:08
yoctozeptoand also about mlnx and ansible09:08
yoctozeptoansible never in binary09:08
yoctozeptomlnx still in binary09:08
*** k_mouza has quit IRC09:08
hrwI meant 'drop from binary and then one note will cover both'09:10
openstackgerritMark Goddard proposed openstack/kolla-ansible stable/wallaby: docs: Improve policy documentation  https://review.opendev.org/c/openstack/kolla-ansible/+/78784909:11
openstackgerritMark Goddard proposed openstack/kolla-ansible stable/victoria: docs: Improve policy documentation  https://review.opendev.org/c/openstack/kolla-ansible/+/78785009:12
openstackgerritMark Goddard proposed openstack/kolla-ansible stable/ussuri: docs: Improve policy documentation  https://review.opendev.org/c/openstack/kolla-ansible/+/78785109:13
openstackgerritMark Goddard proposed openstack/kolla-ansible stable/train: docs: Improve policy documentation  https://review.opendev.org/c/openstack/kolla-ansible/+/78785209:13
openstackgerritMarcin Juszkiewicz proposed openstack/kolla master: docs: deprecate ppc64le in Wallaby  https://review.opendev.org/c/openstack/kolla/+/78794709:15
mnasiadkayoctozepto: do we want mlnx to be still in binary? :D09:17
mnasiadkayoctozepto: and by the way, mlnx has no branch, but has a Wallaby tag :D09:17
openstackgerritMarcin Juszkiewicz proposed openstack/kolla master: docs: deprecate ppc64le in Wallaby  https://review.opendev.org/c/openstack/kolla/+/78794709:17
openstackgerritMarcin Juszkiewicz proposed openstack/kolla master: Drop ppc64le support  https://review.opendev.org/c/openstack/kolla/+/78726509:17
yoctozeptomnasiadka: yeah, it's a mess09:17
hrwthis way drop depends on deprecate09:17
openstackgerritMarcin Juszkiewicz proposed openstack/kolla master: drop leftovers of RHEL support  https://review.opendev.org/c/openstack/kolla/+/78556909:19
hrwyoctozepto: replied to your commend in APT keys change09:27
openstackgerritMichal Nasiadka proposed openstack/kayobe-config master: Sync kayobe-config with kayobe changes  https://review.opendev.org/c/openstack/kayobe-config/+/78792409:30
yoctozeptomgoddard: replied on project-config09:33
openstackgerritMichal Nasiadka proposed openstack/kayobe-config master: Sync kayobe-config with kayobe changes  https://review.opendev.org/c/openstack/kayobe-config/+/78792409:37
*** shyam89 has quit IRC09:39
*** shyamb has quit IRC09:39
openstackgerritMarcin Juszkiewicz proposed openstack/kolla master: drop leftovers of RHEL support  https://review.opendev.org/c/openstack/kolla/+/78556909:44
yoctozeptomgoddard: replied again, there was a misunderstanding09:44
hrwyoctozepto: thx for comments09:44
yoctozeptohrw: yw09:44
yoctozeptohrw: you forgot about metatype in docs still09:45
hrwah09:46
openstackgerritMarcin Juszkiewicz proposed openstack/kolla master: drop leftovers of RHEL support  https://review.opendev.org/c/openstack/kolla/+/78556909:47
openstackgerritMarcin Juszkiewicz proposed openstack/kolla master: drop leftovers of RHEL support  https://review.opendev.org/c/openstack/kolla/+/78556910:20
hrwtox fixed10:22
*** k_mouza has joined #openstack-kolla10:23
*** k_mouza has quit IRC10:27
*** shyam89 has joined #openstack-kolla10:27
*** shyamb has joined #openstack-kolla10:27
*** shyamb has quit IRC10:29
*** shyamb has joined #openstack-kolla10:30
*** shyamb has quit IRC10:31
*** shyamb has joined #openstack-kolla10:31
*** k_mouza has joined #openstack-kolla10:32
*** shyam89 has quit IRC10:32
*** shyam89 has joined #openstack-kolla10:33
*** k_mouza has quit IRC10:36
openstackgerritMerged openstack/kolla-ansible master: Avoid an Ansible quirk in hacluster role  https://review.opendev.org/c/openstack/kolla-ansible/+/78785810:37
openstackgerritMerged openstack/kolla-ansible stable/victoria: docs: Improve policy documentation  https://review.opendev.org/c/openstack/kolla-ansible/+/78785010:37
openstackgerritMerged openstack/kolla-ansible stable/ussuri: docs: Improve policy documentation  https://review.opendev.org/c/openstack/kolla-ansible/+/78785110:37
openstackgerritMerged openstack/kolla-ansible stable/train: docs: Improve policy documentation  https://review.opendev.org/c/openstack/kolla-ansible/+/78785210:37
openstackgerritMerged openstack/kolla-ansible stable/wallaby: docs: Improve policy documentation  https://review.opendev.org/c/openstack/kolla-ansible/+/78784910:37
openstackgerritMerged openstack/kolla master: docs: deprecate ppc64le in Wallaby  https://review.opendev.org/c/openstack/kolla/+/78794710:37
*** Luzi has joined #openstack-kolla10:40
*** ivan_lin has joined #openstack-kolla11:00
*** k_mouza has joined #openstack-kolla11:00
*** LinPeiWen has quit IRC11:02
openstackgerritPierre Riteau proposed openstack/kayobe stable/stein: Use released version of mrlesmithjr.mdadm  https://review.opendev.org/c/openstack/kayobe/+/78793611:02
*** strigazi has quit IRC11:05
hrwguys: can we finally merge bullseye patch?11:10
hrwor should I send patch to disable trove for buster?11:10
hrwas I would like to see debian-binary green on CI and would like to know which way to fix it11:11
hrwanyway we need trove disable for victoria11:14
openstackgerritMarcin Juszkiewicz proposed openstack/kolla master: Disable trove for Debian/binary  https://review.opendev.org/c/openstack/kolla/+/78795811:17
openstackgerritMark Goddard proposed openstack/kayobe master: Ubuntu: define implied VLAN parent interfaces in networkd  https://review.opendev.org/c/openstack/kayobe/+/78796011:34
*** shyamb has quit IRC11:36
*** shyam89 has quit IRC11:36
*** shyam89 has joined #openstack-kolla11:36
*** shyamb has joined #openstack-kolla11:36
openstackgerritMark Goddard proposed openstack/kayobe master: Ubuntu: define implied VLAN parent interfaces in networkd  https://review.opendev.org/c/openstack/kayobe/+/78796011:41
openstackgerritMark Goddard proposed openstack/kolla stable/wallaby: docs: deprecate ppc64le in Wallaby  https://review.opendev.org/c/openstack/kolla/+/78785511:45
hrw+211:46
*** jamesbenson has joined #openstack-kolla11:50
*** jamesbenson has quit IRC11:58
*** jamesbenson1 has joined #openstack-kolla11:58
*** shyam89 has quit IRC12:02
*** shyamb has quit IRC12:02
*** k_mouza has quit IRC12:04
*** shyamb has joined #openstack-kolla12:09
*** shyam89 has joined #openstack-kolla12:09
*** jamesbenson1 has quit IRC12:19
*** k_mouza has joined #openstack-kolla12:27
*** shyam89 has quit IRC12:28
*** shyamb has quit IRC12:28
yoctozeptomgoddard: https://review.opendev.org/c/openstack/project-config/+/78788712:29
*** shyamb has joined #openstack-kolla12:29
*** shyam89 has joined #openstack-kolla12:29
*** k_mouza has quit IRC12:32
ozzzois there a searchable archive of this channel?12:35
ozzzoor I guess I should ask; how can I search the archive?12:36
yoctozeptomgoddard: https://review.opendev.org/c/openstack/bifrost/+/787605 - y no approve?12:37
yoctozeptoozzzo: there is not afaik12:37
mgoddardyoctozepto: the job failed12:37
priteauozzzo: try using "site:eavesdrop.openstack.org kolla <your-query>", though I can't guarantee you will find what you are looking for12:38
priteauYou can also download all of http://eavesdrop.openstack.org/irclogs/%23openstack-kolla/ using recursive wget and search into that12:38
yoctozeptomgoddard: good catch12:38
ozzzook I'll try that, ty12:39
*** shyam89 has quit IRC12:42
*** shyamb has quit IRC12:42
*** shyamb has joined #openstack-kolla12:43
*** shyam89 has joined #openstack-kolla12:43
*** shyam89 has quit IRC12:44
*** shyamb has quit IRC12:44
*** wuchunyang has joined #openstack-kolla12:59
openstackgerritRadosław Piliszek proposed openstack/kolla-ansible stable/wallaby: Avoid an Ansible quirk in hacluster role  https://review.opendev.org/c/openstack/kolla-ansible/+/78797613:00
*** k_mouza has joined #openstack-kolla13:01
openstackgerritMerged openstack/kolla stable/wallaby: docs: deprecate ppc64le in Wallaby  https://review.opendev.org/c/openstack/kolla/+/78785513:04
hrwhttps://review.opendev.org/c/openstack/kolla/+/787958 waits for brave cores13:12
mnasiadkahrw: support matrix? ;)13:17
hrwgood point13:23
mnasiadkaactually it's already N :D13:24
hrwmnasiadka: yep13:25
hrwtrove--13:27
openstackgerritwu.chunyang proposed openstack/kolla-ansible master: Fix incorrect config of linuxbridge multiple external networks  https://review.opendev.org/c/openstack/kolla-ansible/+/78799613:31
*** Anthraxs has joined #openstack-kolla13:32
AnthraxsHello all,13:35
AnthraxsCan anyone help me debug the following problem?13:35
AnthraxsI have an all in one installation and I'm have deployed Octavia using the dev. env. guidelines (https://docs.openstack.org/kolla-ansible/latest/reference/networking/octavia.html#development-or-testing). When creating a new load balancer it's getting stuck in pending create and from what I can see, the octavia-worked cannot connect to the amphora:13:35
Anthraxs2021-04-26 13:34:12.374 18 WARNING octavia.amphorae.drivers.haproxy.rest_api_driver [-] Could not connect to instance. Retrying.: requests.exceptions.ConnectionError: HTTPSConnectionPool(host='10.0.0.40', port=9443): Max retries exceeded with url: // (Caused by NewConnectionError('<urllib3.connection.HTTPSConnection object at 0x7f9e29ac7400>:13:35
AnthraxsFailed to establish a new connection: [Errno 113] No route to host'))13:35
*** Luzi has quit IRC13:38
openstackgerritwu.chunyang proposed openstack/kolla-ansible master: [doc] fix a typo  https://review.opendev.org/c/openstack/kolla-ansible/+/78799813:40
*** vishalmanchanda has quit IRC13:41
*** Anthraxs has quit IRC13:46
yoctozeptomgoddard: https://review.opendev.org/c/openstack/bifrost/+/787605 green14:02
*** jamesbenson has joined #openstack-kolla14:04
*** vishalmanchanda has joined #openstack-kolla14:21
*** openstackgerrit has quit IRC14:23
wuchunyangAnthraxs  Is it out of time ?14:24
wuchunyangand if your distro is centos8, you may need to set flavor vcpu greater than 1 core. there is a know issue about this.14:28
*** jamesbenson has quit IRC14:37
*** antonym has quit IRC14:37
*** antonym has joined #openstack-kolla14:39
yoctozeptoI wonder if we started any work on retrying pulls? mnasiadka?14:45
yoctozeptoit seems they can sometimes fail, possibly due to mirror being overloaded14:45
yoctozeptohttps://044ee3b17e71d562c28d-27ba51e152f37c2c550101a1da9a359d.ssl.cf2.rackcdn.com/787976/1/check/kolla-ansible-centos8s-source-upgrade/fc70b4b/primary/logs/ansible/pull14:45
mnasiadkayoctozepto: I guess not14:47
yoctozeptohmm, perhaps I just dreamed of them14:47
*** openstackgerrit has joined #openstack-kolla14:57
openstackgerritMerged openstack/kolla-ansible master: [doc] fix a typo  https://review.opendev.org/c/openstack/kolla-ansible/+/78799814:57
*** kevko has joined #openstack-kolla14:58
kevkohi14:58
*** Fl1nt has joined #openstack-kolla15:01
Fl1ntHowdy everyone!15:01
kevkohmm, I'm not possible to create multi-region edge-cloud with Google as authentification/authorization ... 800 ms latence between region , am I ?15:05
*** jamesbenson has joined #openstack-kolla15:05
openstackgerritLin PeiWen proposed openstack/kolla master: Modify healthcheck_mariadb  https://review.opendev.org/c/openstack/kolla/+/78540115:08
*** wuchunyang has quit IRC15:13
*** jamesbenson has quit IRC15:31
*** jamesbenson has joined #openstack-kolla15:35
*** rpittau is now known as rpittau|afk15:55
*** jamesbenson has quit IRC15:58
*** jamesbenson1 has joined #openstack-kolla15:58
*** jamesbenson1 has quit IRC16:02
*** dciabrin_ has quit IRC16:13
*** jamesbenson has joined #openstack-kolla16:13
Fl1ntkevko, depends on your services.16:15
kevkowell, we have potentional customer ..but he has 15 areas worldwide with ~850ms latency16:16
Fl1ntwhat does that means? 850ms between regions? between all of them? Google is no longer than few ms away from anyone anywhere in the world.16:17
kevkoFl1nt: so, he probably want 15 separate openstacks .. separate mariadbs, rabbitmqs, etc etc etc ..but to be able authentify/authorize on some keystone and have token valid on another keystone in another region..16:17
kevkoFl1nt: well, google is google :D16:18
Fl1ntno no no, Google is not the important part in here OpenID Connect is made from your browser and the whole authentication process wait for your response before login in, so even if 15s away, it work.16:19
Fl1ntthe question is rather16:19
Fl1ntdoes it want 15 keystone?16:19
Fl1ntor one spanned across 15 locations?16:19
hrwor 15 synchronizing?16:20
kevkothey want 15 keystones ..16:20
kevkoand has regions as independent as they can be from each others ...16:20
Fl1ntso what's the issue here?16:20
Fl1nthrw, keystone federation of keystones is... a nightmare ^^16:21
Fl1ntkevko, simple way to do that, get a kolla-config repository, fork 15 differents repos from it, one per region, get your identity federation individually set on each of them ^^ end of your trouble ^^16:22
kevkoFl1nt: well yes, that was my idea before I asked :D16:23
kevkoFl1nt: but, I have to also modify fernet-push script in fernet rotate container, right ?16:23
Fl1ntnope, why that?16:23
Fl1ntIf you can't get a spanned network in between location that gave you at least a sub 30ms response time, then don't do replicated/synced keystone, goes with independent regions and a central identity manager such as your plan.16:25
Fl1ntIf your customer can afford a globally spanned sub 30ms network, then get a spawn (main) region and every other part of it.16:26
kevkoFl1nt: well, honestly I am not biggest keystone expert :P16:27
Fl1ntfernet token don't need to be synced between regions as long as those regions are autonomous, the only issue that your users will face will be that they'll have different token granted for each region, meaning16:28
Fl1ntif you authenticate to region A16:28
Fl1ntthen want to perform an action on region B16:28
kevkoFl1nt: but my colleguage said they want to have also some service user which has to be authentified/authorized against random keystone ... and therefore has to have synced fernets16:28
Fl1ntyou'll need to authenticate again.16:28
kevkoFl1nt: well, I think this is exactly what they want proabably ..16:29
Fl1ntnot possible the way you want to implement your regions.16:29
kevko*also16:29
Fl1ntexcept to use an underlying shared storage16:29
openstackgerritMerged openstack/kolla master: Disable trove for Debian/binary  https://review.opendev.org/c/openstack/kolla/+/78795816:29
*** bengates has quit IRC16:29
kevkoIf I understood correctly16:29
Fl1ntwhich isn't recommended at all16:29
Fl1ntas it would then screw your rotation process.16:30
kevkoFl1nt: well, what If i will rotate to every keystone in every region ?16:30
*** bengates has joined #openstack-kolla16:30
Fl1ntyou can't do it like that with the current shape of the rotation script.16:30
Fl1ntI did it once16:31
*** gouthamr has joined #openstack-kolla16:31
kevkoFl1nt: i was checking k-a code and there is for cycle through keystone group in inventory ..so If i modify that script ..I am ok ..16:31
*** gouthamr has quit IRC16:31
*** gouthamr has joined #openstack-kolla16:31
*** gouthamr has quit IRC16:31
kevkoam I right ? or what do you mean by "current shape " ?16:31
Fl1ntusing a third party tool in between (hashicorp consul) but it's definitely an ugly solution as is drastically increase your platform complexity.16:31
*** gouthamr has joined #openstack-kolla16:31
Fl1ntthis is for multi-region deployment where you have one central keystone for all regions.16:32
*** gouthamr has joined #openstack-kolla16:32
Fl1ntor even multinode on one region16:32
*** gouthamr has joined #openstack-kolla16:33
Fl1ntbut then you'll have an issue where you'll need to create a monstruous script that will check each of your repos inventory, then cycle through them, but even there, it doesn't solve the issue that each region will at time16:33
*** gouthamr has quit IRC16:33
Fl1ntrotate the fernet_keys16:33
Fl1ntand then your regions are unsynced16:33
*** gouthamr has joined #openstack-kolla16:34
*** gouthamr has quit IRC16:34
Fl1ntfernet_token is a special token that craft a payload containing your token lifetime and other informations in it, it's derivated and controlled with those so called fernet_keys16:34
Fl1nthence why they periodically rotate16:34
Fl1ntin order to avoid an attacker to be able to forge tokens16:35
*** gouthamr has joined #openstack-kolla16:35
*** bengates has quit IRC16:35
kevkohmm16:35
Fl1ntso tokens on Region A have two requirements16:35
Fl1ntbeing rotated periodically16:35
Fl1ntand16:36
Fl1ntif you want to share them a global shared storage amoung regions16:36
Fl1ntwhich with 850ms is unrealistic16:36
kevkounderstand :/16:36
Fl1ntyou'll also need to only get one keystone node to rotate the keys at the same time.16:36
*** dougsz has quit IRC16:37
Fl1ntat some point, when you build cloud that span across the world openstack or any other services, (even kubernetes) aren't made for that, because they lack efficient P2P shared services layers because of the DB Backend used.16:39
Fl1ntOne of my previous employer spanned across the globe, then asked MariaDB for a solution as they use active/active mariadb clusters and a distributed keystone. Even MDB engineers told them it's not currently possible without at least using proxysql16:41
Fl1ntwhich bring other issues ^^16:41
Fl1ntanother solution would have been to use galera segments but meh ^^16:43
admin0does kolla setup ceph in the latest version or not ?16:44
admin0and if not and ceph+rgw is setup via ceph-ansible, does kolla adds rgw endpoints in keystone for swift16:45
Fl1ntnope16:45
Fl1ntadmin0, but I've a downstream patch for that.16:45
kevkook Fl1nt , thank you for examplanation :)16:46
openstackgerritMerged openstack/kayobe stable/stein: Use released version of mrlesmithjr.mdadm  https://review.opendev.org/c/openstack/kayobe/+/78793616:46
admin0i want to know how to enable swift apis with ceph backend16:46
admin0starting with adding the entries in keystone16:46
*** jamesbenson has quit IRC16:47
Fl1ntyou just create entrypoint on haproxy config, then point your keystone swift service to that entrypoint, if you've correctly set your ceph RGW then it will be able to serve Object-Storate16:47
Fl1ntstorage16:48
Fl1ntkevko, you're welcome :D16:50
*** jamesbenson has joined #openstack-kolla16:51
Fl1nthrw, I've digged a bit about this live migration thingy on nova. It's not (from my understanding and research) possible to split live migration interface from the nova-compute used my_ip interface without breaking cold migration and instance resize.16:54
openstackgerritRadosław Piliszek proposed openstack/kolla master: Pin erlang  https://review.opendev.org/c/openstack/kolla/+/78804516:54
*** k_mouza has quit IRC16:57
*** jamesbenson has quit IRC16:57
openstackgerritRadosław Piliszek proposed openstack/kolla stable/ussuri: rabbitmq: Move to packagecloud  https://review.opendev.org/c/openstack/kolla/+/78798416:57
*** jamesbenson has joined #openstack-kolla16:58
*** jamesbenson has quit IRC17:01
openstackgerritRadosław Piliszek proposed openstack/kolla stable/ussuri: rabbitmq: Move to packagecloud  https://review.opendev.org/c/openstack/kolla/+/78798417:03
openstackgerritRadosław Piliszek proposed openstack/kolla stable/ussuri: rabbitmq: Move to packagecloud  https://review.opendev.org/c/openstack/kolla/+/78798417:06
openstackgerritRadosław Piliszek proposed openstack/kolla stable/train: rabbitmq: Move to packagecloud  https://review.opendev.org/c/openstack/kolla/+/78798517:08
*** gfidente is now known as gfidente|afk17:09
*** jonaspaulo has joined #openstack-kolla17:19
*** kevko has quit IRC17:21
openstackgerritRadosław Piliszek proposed openstack/kolla stable/train: rabbitmq: Move to packagecloud  https://review.opendev.org/c/openstack/kolla/+/78798517:23
openstackgerritMerged openstack/kayobe stable/train: Use released version of mrlesmithjr.mdadm  https://review.opendev.org/c/openstack/kayobe/+/78793717:31
*** andrewbonney has quit IRC17:37
openstackgerritMarcin Juszkiewicz proposed openstack/kolla stable/victoria: Disable trove for Debian/binary  https://review.opendev.org/c/openstack/kolla/+/78798617:41
openstackgerritRadosław Piliszek proposed openstack/kolla stable/wallaby: Disable trove for Debian/binary  https://review.opendev.org/c/openstack/kolla/+/78798717:56
openstackgerritGaël THEROND proposed openstack/kolla-ansible master: [WIP] - Fix broken cold_migration based actions when using migration_interface value which differ from the nova-compute host_ip.  https://review.opendev.org/c/openstack/kolla-ansible/+/78805817:59
openstackgerritMerged openstack/kayobe stable/ussuri: Use released version of mrlesmithjr.mdadm  https://review.opendev.org/c/openstack/kayobe/+/78793818:00
openstackgerritMarcin Juszkiewicz proposed openstack/kolla master: move to Debian 'bullseye'  https://review.opendev.org/c/openstack/kolla/+/77247918:03
openstackgerritMarcin Juszkiewicz proposed openstack/kolla master: Debian/Ubuntu: handle APT keys in proper way  https://review.opendev.org/c/openstack/kolla/+/78492318:03
openstackgerritMarcin Juszkiewicz proposed openstack/kolla master: base: do not overwrite APT sources.list  https://review.opendev.org/c/openstack/kolla/+/78693818:03
*** jamesbenson has joined #openstack-kolla18:08
admin0Fl1nt, can i see the patch ?18:15
admin0of ceph, endpoints etc18:15
Fl1ntadmin0, not today ^^ I need to transfer it from our downstream repo first.18:16
admin0ok18:17
Fl1ntmp me your mail and I'll make you a CC of the patch18:19
Fl1ntadmin0, -î18:19
admin0shashi.eu@gmail.com18:19
* admin0 waits for spam from other bots :) 18:19
*** vishalmanchanda has quit IRC18:21
Fl1ntI'll be kind and not do that ^^18:21
Fl1ntanyway, see ya folks, and GN18:22
*** Fl1nt has quit IRC18:22
*** bsanjeewa has joined #openstack-kolla18:25
*** jamesbenson has quit IRC18:29
openstackgerritVerification of a change to openstack/kolla failed: rabbitmq: Move to packagecloud  https://review.opendev.org/c/openstack/kolla/+/78738318:35
*** stand has joined #openstack-kolla18:42
*** jamesbenson has joined #openstack-kolla18:43
*** jamesbenson has quit IRC18:58
*** k_mouza has joined #openstack-kolla18:58
*** jamesbenson1 has joined #openstack-kolla18:58
*** k_mouza has quit IRC19:02
*** jamesbenson1 has quit IRC19:10
*** Chaserjim has joined #openstack-kolla19:14
*** jamesbenson has joined #openstack-kolla19:16
*** jamesbenson has quit IRC19:18
*** jamesbenson has joined #openstack-kolla19:19
*** cah_link has quit IRC19:23
*** zzzeek has quit IRC19:44
*** jamesbenson has quit IRC19:46
*** zzzeek has joined #openstack-kolla19:47
*** bsanjeewa has quit IRC19:50
*** jamesbenson has joined #openstack-kolla19:54
*** jamesbenson has quit IRC19:58
*** jamesbenson1 has joined #openstack-kolla19:58
*** jamesbenson1 has quit IRC20:00
*** jamesbenson has joined #openstack-kolla20:04
*** zzzeek has quit IRC20:09
openstackgerritStanislav Dmitriev proposed openstack/kolla master: Add Swift lock path in Swift containers  https://review.opendev.org/c/openstack/kolla/+/78807320:16
*** zzzeek has joined #openstack-kolla20:16
*** jamesbenson has quit IRC20:20
*** jamesbenson has joined #openstack-kolla20:23
*** jamesbenson has quit IRC20:32
*** jamesbenson has joined #openstack-kolla20:34
*** zzzeek has quit IRC20:40
*** zzzeek has joined #openstack-kolla20:41
*** zzzeek has quit IRC20:46
*** zzzeek has joined #openstack-kolla20:48
*** bsanjeewa has joined #openstack-kolla20:53
*** e0ne has quit IRC20:55
openstackgerritMerged openstack/kayobe stable/victoria: Use released version of mrlesmithjr.mdadm  https://review.opendev.org/c/openstack/kayobe/+/78793921:01
openstackgerritBuddhika Sanjeewa proposed openstack/kayobe stable/stein: Document Update Specify Branch When Cloning  https://review.opendev.org/c/openstack/kayobe/+/78808121:02
openstackgerritBuddhika Sanjeewa proposed openstack/kayobe stable/train: Document Update Specify Branch When Cloning  https://review.opendev.org/c/openstack/kayobe/+/78808221:03
openstackgerritBuddhika Sanjeewa proposed openstack/kayobe stable/ussuri: Document Update Specify Branch When Cloning  https://review.opendev.org/c/openstack/kayobe/+/78808321:03
openstackgerritBuddhika Sanjeewa proposed openstack/kayobe stable/victoria: Document Update Specify Branch When Cloning  https://review.opendev.org/c/openstack/kayobe/+/78808421:04
openstackgerritBuddhika Sanjeewa proposed openstack/kayobe stable/victoria: Document Update Specify Branch When Cloning  https://review.opendev.org/c/openstack/kayobe/+/78808421:08
*** bsanjeewa has quit IRC21:33
*** jamesbenson has quit IRC21:34
*** jonaspaulo has quit IRC21:41
*** jamesbenson has joined #openstack-kolla22:29
*** jamesbenson has quit IRC22:30
*** bsanjeewa has joined #openstack-kolla22:36
*** zzzeek has quit IRC22:42
*** zzzeek has joined #openstack-kolla22:43
*** k_mouza has joined #openstack-kolla22:58
*** k_mouza has quit IRC23:03
*** bsanjeewa has quit IRC23:17
*** jobewan has joined #openstack-kolla23:39

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!