openstackgerrit | Michael Johnson proposed openstack/neutron-lbaas master: Neutron-LBaaS to Octavia migration tool https://review.openstack.org/578942 | 00:38 |
---|---|---|
*** longkb has joined #openstack-lbaas | 00:40 | |
*** kobis has joined #openstack-lbaas | 01:11 | |
*** kobis has quit IRC | 01:16 | |
*** hongbin has joined #openstack-lbaas | 01:16 | |
*** annp has joined #openstack-lbaas | 01:55 | |
*** huangshan has joined #openstack-lbaas | 03:16 | |
*** ramishra has joined #openstack-lbaas | 03:39 | |
*** numans has quit IRC | 03:56 | |
*** kobis has joined #openstack-lbaas | 04:25 | |
*** kobis has quit IRC | 04:29 | |
*** hongbin has quit IRC | 04:38 | |
*** AlexStaf has joined #openstack-lbaas | 04:45 | |
*** numans has joined #openstack-lbaas | 05:22 | |
*** ianychoi has joined #openstack-lbaas | 05:34 | |
*** kobis has joined #openstack-lbaas | 06:45 | |
*** kobis has quit IRC | 06:49 | |
*** yboaron has joined #openstack-lbaas | 06:52 | |
*** ispp has joined #openstack-lbaas | 07:09 | |
*** kobis has joined #openstack-lbaas | 07:14 | |
*** yamamoto has quit IRC | 07:18 | |
*** ispp has quit IRC | 07:20 | |
*** peereb has joined #openstack-lbaas | 07:22 | |
*** nmanos has joined #openstack-lbaas | 07:24 | |
*** yboaron has quit IRC | 07:25 | |
*** ispp has joined #openstack-lbaas | 07:26 | |
*** yamamoto has joined #openstack-lbaas | 07:26 | |
*** ispp has quit IRC | 07:39 | |
*** yamamoto has quit IRC | 07:42 | |
*** ktibi has joined #openstack-lbaas | 07:48 | |
*** rcernin has quit IRC | 07:54 | |
*** ispp has joined #openstack-lbaas | 08:00 | |
*** yamamoto has joined #openstack-lbaas | 08:10 | |
*** yboaron has joined #openstack-lbaas | 08:13 | |
*** yboaron_ has joined #openstack-lbaas | 08:31 | |
*** yboaron has quit IRC | 08:34 | |
*** cvm has quit IRC | 08:36 | |
openstackgerrit | yanpuqing proposed openstack/python-octaviaclient master: Add some filter options to load balancer list command https://review.openstack.org/580322 | 08:54 |
*** ispp has quit IRC | 08:55 | |
*** AlexStaf has quit IRC | 08:55 | |
*** velizarx has joined #openstack-lbaas | 09:10 | |
velizarx | Hi folks. I want to use octavia with barbican (TLS-terminated load balancer) for customers, but I'm confused. In documentation (https://docs.openstack.org/octavia/latest/user/guides/basic-cookbook.html#deploy-a-tls-terminated-https-load-balancer) I see step "Grant the admin user access to the tls_secret1 barbican resource", but I don't understand, how the user should get admin_id? The simple user don't know anything about admin account. It's | 09:12 |
velizarx | very strange case. I tried to configure barbicans' policy so that octavia will have access for getting any sertificates by default, but RBAC policy can't be configured so. And it is the very unsecure way. How to use this functionality? | 09:12 |
*** kobis has quit IRC | 09:23 | |
cgoncalves | velizarx, hi. this is a known issue. right now users are required to know octavia's user id which is only accessible to admins | 09:34 |
cgoncalves | velizarx, patch https://review.openstack.org/#/c/552549/ should fix this. sadly it's not yet ready to be merged | 09:34 |
cgoncalves | it works, though, in case you want to test it out | 09:35 |
velizarx | cgoncalves, hm, thank you, I will test this patch in local installation | 09:38 |
velizarx | Do you consider the possibility of using user's token for authorization in barbican's API? For example, so magnum works. | 09:38 |
cgoncalves | velizarx, that is the approach we're taking. see https://review.openstack.org/#/c/552549/9/octavia/certificates/common/auth/barbican_acl.py@87 | 09:39 |
velizarx | cgoncalves, ok, thank you! | 09:42 |
*** kiennt26 has joined #openstack-lbaas | 09:43 | |
*** huangshan has quit IRC | 09:47 | |
openstackgerrit | ZhaoBo proposed openstack/octavia master: UDP jinja template https://review.openstack.org/525420 | 09:50 |
openstackgerrit | ZhaoBo proposed openstack/octavia master: WIP:UDP for [2] https://review.openstack.org/529651 | 09:50 |
openstackgerrit | ZhaoBo proposed openstack/octavia master: UDP for [3][5][6] https://review.openstack.org/539391 | 09:50 |
*** ispp has joined #openstack-lbaas | 09:50 | |
*** yboaron_ has quit IRC | 09:57 | |
*** kobis has joined #openstack-lbaas | 10:24 | |
*** kobis has quit IRC | 10:24 | |
*** annp has quit IRC | 10:25 | |
*** annp has joined #openstack-lbaas | 10:26 | |
*** annp has quit IRC | 10:38 | |
*** kiennt26 has quit IRC | 10:41 | |
*** kobis has joined #openstack-lbaas | 10:46 | |
*** kobis has quit IRC | 10:46 | |
*** yboaron_ has joined #openstack-lbaas | 10:48 | |
*** velizarx has quit IRC | 10:49 | |
*** annp has joined #openstack-lbaas | 10:49 | |
*** velizarx has joined #openstack-lbaas | 10:49 | |
*** annp has quit IRC | 10:54 | |
*** kobis has joined #openstack-lbaas | 11:03 | |
*** longkb has quit IRC | 11:36 | |
*** amuller has joined #openstack-lbaas | 11:59 | |
*** velizarx has quit IRC | 12:00 | |
*** fnaval has quit IRC | 12:00 | |
*** velizarx has joined #openstack-lbaas | 12:06 | |
*** fnaval has joined #openstack-lbaas | 12:21 | |
*** nmanos has quit IRC | 12:32 | |
*** nmanos has joined #openstack-lbaas | 12:49 | |
*** nmanos has quit IRC | 13:38 | |
*** apuimedo has quit IRC | 13:42 | |
*** ispp has quit IRC | 14:08 | |
*** ispp has joined #openstack-lbaas | 14:09 | |
*** ktibi has quit IRC | 14:27 | |
mnaser | hi | 14:39 |
mnaser | we can't fail over a failed load balancer? :\ | 14:39 |
johnsom | mnaser Say what? | 14:53 |
mnaser | a loadbalancer was in 'ERROR' state | 14:53 |
mnaser | and it wouldnt let you fail it over :p | 14:53 |
johnsom | Hmm, some cases that is valid, like if the VIP neutron port got nuked. | 14:53 |
*** Swami has joined #openstack-lbaas | 14:54 | |
*** velizarx has quit IRC | 14:55 | |
*** kobis has quit IRC | 14:55 | |
*** yboaron_ has quit IRC | 14:57 | |
mnaser | it did get nuked in this | 14:57 |
mnaser | in a failed-failover | 14:57 |
johnsom | Hmmm, can you pastebin the HM logs? | 14:58 |
johnsom | You are running queens? | 14:58 |
*** apuimedo has joined #openstack-lbaas | 15:05 | |
*** peereb has quit IRC | 15:22 | |
*** Swami has quit IRC | 15:44 | |
openstackgerrit | Merged openstack/octavia master: Add exception handling for housekeeping service https://review.openstack.org/576388 | 16:10 |
*** ispp has quit IRC | 16:32 | |
colin- | any precedent for amphora nodes to be spun in the tenant they are serving versus a shared one? | 16:33 |
*** kobis has joined #openstack-lbaas | 16:36 | |
johnsom | Not that I know of. We all run it with a service account. | 16:36 |
johnsom | Amps are intended to be hidden from users as an implementation detail of the driver. | 16:36 |
*** kobis has quit IRC | 16:44 | |
jiteka | johnsom: to followup on colin- questions, how do you handle quota restriction as vip back with amphora also consume compute resources (that could be used for VMs) | 16:45 |
johnsom | jiteka Well, since Octavia is running as a service account, you can adjust the quotas up for that service account. | 16:47 |
jiteka | johnsom: so you need as cloud ops to determin from the quota you allow to your user the chunk of compute ressource that will be consumed by the backend right ? | 16:50 |
johnsom | jiteka Right, but load balancer resources have their own quota for the user. They are billed differently than a compute resource, so the design was to handle them independent of the user account. For example, if you offer both the octavia driver and a vendor driver, the octavia driver would use compute quota, but the vendor wouldn't as it is typically a hardware appliance. | 16:52 |
jiteka | johnsom: so in case of using octavia driver, do you recommand using a dedicated host aggregate to keep amps VMs on specific node or it's better to have them spread on the whole fleet ? | 17:03 |
jiteka | johnsom: thinking about throughput where compute nodes may need better bandwidth to support demanding services | 17:04 |
johnsom | jiteka You can specify things like host aggregates with the dedicated nova "flavor". In general we like them spread out for HA. For example if you are using Active/Standby you can enable the anti-affinity configuration setting and nova will force the master and backup amphora to different compute hosts. This way one compute outage doesn't take the load balancer down. | 17:07 |
*** ramishra has quit IRC | 17:13 | |
jiteka | johnsom: that's exactly what I'm looking for, having dedicated flavor mapped on host-aggregate with anti-affinity scheduling rules :) | 17:15 |
jiteka | johnsom: thanks a lot for the help ! | 17:15 |
johnsom | Sure, NP | 17:16 |
openstackgerrit | Michael Johnson proposed openstack/neutron-lbaas master: Neutron-LBaaS to Octavia migration tool https://review.openstack.org/578942 | 17:18 |
*** apuimedo has quit IRC | 17:35 | |
openstackgerrit | German Eichberger proposed openstack/neutron-lbaas master: Gate API test for the lbaasv2-proxy plugin https://review.openstack.org/539350 | 17:40 |
*** kobis has joined #openstack-lbaas | 18:19 | |
*** kobis has quit IRC | 18:43 | |
*** abaindur has joined #openstack-lbaas | 19:03 | |
*** abaindur has quit IRC | 19:04 | |
*** abaindur has joined #openstack-lbaas | 19:04 | |
*** kbyrne has joined #openstack-lbaas | 19:05 | |
*** abaindur_ has joined #openstack-lbaas | 19:28 | |
*** abaindur has quit IRC | 19:28 | |
*** kbyrne has quit IRC | 19:42 | |
*** kbyrne has joined #openstack-lbaas | 19:45 | |
openstackgerrit | Michael Johnson proposed openstack/neutron-lbaas master: Neutron-LBaaS to Octavia migration tool https://review.openstack.org/578942 | 19:55 |
*** kobis has joined #openstack-lbaas | 19:58 | |
cgoncalves | supports-upgrade & supports-accessible-upgrade approved \o/ | 20:02 |
johnsom | Yep, still stuck in the post gates, but on it's way! | 20:02 |
*** amuller has quit IRC | 20:02 | |
xgerman_ | @cgoncalves you will be in Berlin? | 20:14 |
*** aojea_ has joined #openstack-lbaas | 20:19 | |
*** dmellado has quit IRC | 20:28 | |
*** kobis has quit IRC | 20:49 | |
*** aojea_ has quit IRC | 20:56 | |
*** abaindur_ has quit IRC | 21:00 | |
*** aojea has joined #openstack-lbaas | 21:01 | |
openstackgerrit | German Eichberger proposed openstack/neutron-lbaas master: Gate API test for the lbaasv2-proxy plugin https://review.openstack.org/539350 | 21:08 |
nmagnezi | dayou_, around? | 21:22 |
nmagnezi | I guess not | 21:23 |
nmagnezi | So a question to johnsom :) | 21:23 |
johnsom | o/ | 21:23 |
nmagnezi | johnsom, re: https://review.openstack.org/#/c/572975/9/octavia/amphorae/backends/agent/api_server/amphora_info.py | 21:23 |
nmagnezi | That pylint error | 21:23 |
nmagnezi | What was the issue exactly? | 21:23 |
nmagnezi | Also no one answered this (might also be related to the same thing) https://review.openstack.org/#/c/572975/9/octavia/common/keystone.py | 21:24 |
johnsom | The new pylint this patch brings in (needed for py3) requires it be moved out of the second block. | 21:24 |
nmagnezi | Got it, but just so I'll learn from this, why? | 21:25 |
johnsom | Yeah, the other is the same. | 21:26 |
johnsom | Why, well, I have no idea really. I would think it should be part of the second block myself, but pylint doesn't like it | 21:26 |
nmagnezi | Fair enough. If, we'll see it's just an error in pylint we can always change that in the future | 21:27 |
nmagnezi | Removing my -1 | 21:27 |
johnsom | Yeah, we need the new pylint for the py3 support, so it's either go with the new scheme or disable that check all together | 21:28 |
nmagnezi | Not sure why I placed a comma after the "If".. maybe it's too late for me :D | 21:28 |
johnsom | If you are still curious, pull down the patch tomorrow and put it back then run the pep8 tox and see which rule it's complaining about. | 21:29 |
nmagnezi | johnsom, I don't want to block it just for something that might be broken on pylint, we can always followup on this | 21:30 |
nmagnezi | johnsom, +2 W+! | 21:30 |
nmagnezi | johnsom, +2 W+1 | 21:30 |
johnsom | Thanks! | 21:30 |
nmagnezi | johnsom, btw as for the active standby stuff I'm still looking at this, but I was able to reproduce this with ubuntu based amps. So it's not specific to some ancient keepalived version on centos or something | 21:31 |
nmagnezi | johnsom, as promised, will keep you posted | 21:31 |
johnsom | ok | 21:31 |
cgoncalves | xgerman_, I don't know yet | 21:33 |
cgoncalves | xgerman_, are you? | 21:33 |
cgoncalves | in case you do and I don't, come to Heidelberg and we grab a beer | 21:34 |
xgerman_ | Not sure - but wanted to submit a few talks | 21:34 |
*** abaindur has joined #openstack-lbaas | 21:47 | |
johnsom | Wahoo: https://governance.openstack.org/tc/reference/tags/assert_supports-accessible-upgrade.html | 21:54 |
johnsom | The post jobs are done, it's official | 21:54 |
xgerman_ | Sweet!!! | 21:54 |
*** ivve has quit IRC | 21:55 | |
cgoncalves | good job, team! | 21:56 |
*** rcernin has joined #openstack-lbaas | 22:00 | |
openstackgerrit | Michael Johnson proposed openstack/neutron-lbaas master: Neutron-LBaaS to Octavia migration tool https://review.openstack.org/578942 | 22:05 |
*** aojea has quit IRC | 22:23 | |
nmagnezi | johnsom, still around? | 22:35 |
johnsom | Yes | 22:35 |
nmagnezi | johnsom, I have a question about backup members (looking at this patch now) | 22:35 |
johnsom | The client patch? | 22:36 |
nmagnezi | johnsom, I tested it now and I think I see something off. I checked the member db table and I don't see "backup" column | 22:37 |
nmagnezi | Am I missing something here? | 22:37 |
nmagnezi | Was it not implemented in the server side yet? | 22:37 |
nmagnezi | Yes, the client patch | 22:37 |
johnsom | Yeah, the server side is here: https://review.openstack.org/#/c/552632/ | 22:37 |
johnsom | I have the backup column in my db.... | 22:38 |
nmagnezi | Checking again | 22:38 |
*** aojea_ has joined #openstack-lbaas | 22:39 | |
johnsom | If you didn't restack, but just pulled down a new version of Octavia you need to run the DB migration yourself (devstack usually handles that for you). | 22:39 |
johnsom | octavia-db-manage --config-file /etc/octavia/octavia.conf upgrade head | 22:40 |
nmagnezi | The server side patch was merged 3 months ago | 22:40 |
nmagnezi | The server side patch got merged 3 months ago, I should have it | 22:40 |
johnsom | Yeah, it's been there a while | 22:40 |
nmagnezi | Oh, that was a devstack I reserved for testing something in queens | 22:41 |
* nmagnezi facepalm | 22:41 | |
nmagnezi | That explains it | 22:41 |
nmagnezi | sorry. | 22:41 |
johnsom | +1 | 22:41 |
*** fnaval has quit IRC | 22:49 | |
nmagnezi | johnsom, okay. So created a member with --enable-backup but ends up with backup False.. http://paste.openstack.org/show/725162/ | 22:49 |
johnsom | Try putting it before the "pool1" | 22:50 |
*** abaindur has quit IRC | 22:50 | |
johnsom | Technically the pool is the last parameter of the command | 22:50 |
nmagnezi | johnsom, argparse should be able to handle it | 22:53 |
nmagnezi | johnsom, but in any case, I get the same result http://paste.openstack.org/show/725163/ | 22:53 |
johnsom | nmagnezi Yeah, it looks like it's not in the POST body | 22:54 |
*** aojea_ has quit IRC | 22:55 | |
*** fnaval has joined #openstack-lbaas | 22:55 | |
*** rcernin has quit IRC | 22:58 | |
*** rcernin has joined #openstack-lbaas | 23:01 | |
*** ianychoi_ has joined #openstack-lbaas | 23:01 | |
openstackgerrit | Merged openstack/octavia master: fix tox python3 overrides https://review.openstack.org/572975 | 23:01 |
*** ianychoi has quit IRC | 23:04 | |
*** abaindur has joined #openstack-lbaas | 23:09 | |
openstackgerrit | Merged openstack/octavia master: Move from platform.linux_distribution to distro.id https://review.openstack.org/579288 | 23:16 |
*** aojea has joined #openstack-lbaas | 23:16 | |
*** aojea has quit IRC | 23:21 | |
*** aojea has joined #openstack-lbaas | 23:46 | |
openstackgerrit | Michael Johnson proposed openstack/neutron-lbaas master: Neutron-LBaaS to Octavia migration tool https://review.openstack.org/578942 | 23:47 |
*** aojea has quit IRC | 23:50 | |
*** abaindur has quit IRC | 23:59 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!