*** ianychoi has quit IRC | 00:57 | |
*** ianychoi has joined #openstack-lbaas | 00:59 | |
*** hongbin has joined #openstack-lbaas | 01:04 | |
*** ricolin has joined #openstack-lbaas | 01:05 | |
*** dtruong has quit IRC | 01:24 | |
*** dtruong has joined #openstack-lbaas | 01:25 | |
*** sapd1_x has joined #openstack-lbaas | 02:07 | |
*** sapd1_x has quit IRC | 02:26 | |
*** sapd1_x has joined #openstack-lbaas | 02:28 | |
*** sapd1_x has quit IRC | 03:15 | |
*** psachin has joined #openstack-lbaas | 03:33 | |
*** ajay33 has joined #openstack-lbaas | 03:58 | |
*** hongbin has quit IRC | 04:06 | |
*** ramishra has joined #openstack-lbaas | 04:41 | |
*** sapd1_x has joined #openstack-lbaas | 05:33 | |
*** sapd1_x has quit IRC | 06:04 | |
*** ianychoi has quit IRC | 06:34 | |
*** ianychoi has joined #openstack-lbaas | 06:34 | |
cgoncalves | rm_work, johnsom: we can schedule a review-athon sometime this week or early next. I'll be on PTO from next Wednesday, back Sept 10th | 06:51 |
---|---|---|
rm_work | Kk, sooner is better I think | 06:52 |
cgoncalves | rm_work, you can start approving https://review.opendev.org/#/c/673337/ ;) | 06:53 |
rm_work | :D | 06:54 |
rm_work | ah cool was waiting on that recheck | 06:54 |
rm_work | +A | 06:54 |
rm_work | you could do https://review.opendev.org/#/c/675679/ | 06:55 |
rm_work | ;) | 06:55 |
*** ianychoi has quit IRC | 07:00 | |
*** ianychoi has joined #openstack-lbaas | 07:01 | |
*** gcheresh has joined #openstack-lbaas | 07:05 | |
*** gcheresh_ has joined #openstack-lbaas | 07:09 | |
*** gcheresh has quit IRC | 07:10 | |
*** trident has quit IRC | 07:10 | |
*** maciejjozefczyk has joined #openstack-lbaas | 07:12 | |
*** rcernin has quit IRC | 07:14 | |
cgoncalves | rm_work, reviewing it now | 07:17 |
*** trident has joined #openstack-lbaas | 07:17 | |
cgoncalves | approved | 07:22 |
*** sapd1_x has joined #openstack-lbaas | 07:25 | |
rm_work | :) | 07:27 |
cgoncalves | rm_work, believe it or not, last night I dreamed you were stepping down from core. one of the scariest nights of my life | 07:32 |
rm_work | lolol | 07:33 |
rm_work | i've been unemployed for 3 months and still stayed core, prolly good for a bit :D | 07:33 |
*** ivve has joined #openstack-lbaas | 07:39 | |
openstackgerrit | Merged openstack/octavia-lib master: Clean up octavia-lib docs and remove oslo.log https://review.opendev.org/675679 | 07:39 |
*** rpittau|afk is now known as rpittau | 07:40 | |
openstackgerrit | Adit Sarfaty proposed openstack/neutron-lbaas stable/stein: Prevent deletion of a listener attached to a pool https://review.opendev.org/677659 | 07:42 |
openstackgerrit | Adit Sarfaty proposed openstack/neutron-lbaas stable/stein: Prevent deletion of a listener attached to a pool https://review.opendev.org/677659 | 07:45 |
cgoncalves | this new job log output sucks. it even lost linked log lines | 07:46 |
rm_work | O_o | 07:47 |
rm_work | what changed? which thing are you looking at? | 07:48 |
cgoncalves | rm_work, https://storage.gra1.cloud.ovh.net/v1/AUTH_dcaab5e32b234d56b626f72581e3644c/logs_37/673337/12/check/octavia-v2-dsvm-scenario/bd1a54c/controller/logs/screen-n-api.txt.gz | 08:09 |
cgoncalves | colors were lost, not possible to get a link to a specific timestamp, not possible to filter by log level | 08:09 |
rm_work | huh, yeah that's odd | 08:11 |
rm_work | ah prolly it hasn't been copied over yet | 08:12 |
cgoncalves | our gate is broken. something broken in DIB | 08:12 |
rm_work | that's from a currently running job? | 08:12 |
rm_work | stuff just merged like a few hours ago :/ | 08:12 |
rm_work | oh wat | 08:13 |
rm_work | yeah wow they did totally refactor this | 08:13 |
cgoncalves | job had finished | 08:13 |
cgoncalves | another example: https://b248f48739a903c51cb9-a5dd36e49cc995ae671150d65cd732c0.ssl.cf1.rackcdn.com/659626/7/check/octavia-v2-dsvm-scenario/c0ad46c/controller/logs/screen-o-api.txt.gz | 08:13 |
rm_work | though it looks more useful by defauly | 08:13 |
cgoncalves | I'll have a look at DIB | 08:13 |
rm_work | *default | 08:13 |
rm_work | once they work out this kink | 08:14 |
rm_work | the first page shows me something *actually relevant* | 08:14 |
cgoncalves | hmm, maybe not DIB but infra. they have DIB elements somewhere | 08:14 |
cgoncalves | https://review.opendev.org/#/c/676120/ | 08:16 |
cgoncalves | this is what broke our gate | 08:16 |
rm_work | :/ | 08:17 |
rm_work | aha yeah | 08:17 |
rm_work | bbiab | 08:20 |
cgoncalves | FYI, fix approved and merging now | 08:28 |
*** tkajinam has quit IRC | 08:29 | |
*** ianychoi has quit IRC | 08:32 | |
*** ianychoi has joined #openstack-lbaas | 08:33 | |
*** gcheresh has joined #openstack-lbaas | 08:36 | |
*** gcheresh_ has quit IRC | 08:36 | |
rm_work | Cool lol | 08:44 |
rm_work | Can you do rechecks on the two (?) patches that failed in gate? | 08:45 |
cgoncalves | gate is still running on those two | 08:46 |
rm_work | grr ... Rebase? :D | 08:47 |
rm_work | Maybe I can do it in a sec | 08:47 |
rm_work | My impatience is palpable | 08:48 |
rm_work | And +A | 08:48 |
*** ccamposr__ has quit IRC | 08:50 | |
*** ccamposr__ has joined #openstack-lbaas | 08:50 | |
*** ccamposr__ has quit IRC | 08:51 | |
*** ccamposr__ has joined #openstack-lbaas | 08:51 | |
*** yamamoto has joined #openstack-lbaas | 08:53 | |
openstackgerrit | Adit Sarfaty proposed openstack/neutron-lbaas stable/stein: Prevent deletion of a listener attached to a pool https://review.opendev.org/677659 | 09:07 |
*** gcheresh_ has joined #openstack-lbaas | 09:14 | |
*** gcheresh has quit IRC | 09:15 | |
*** yamamoto has quit IRC | 09:28 | |
*** sapd1_x has quit IRC | 09:53 | |
ivve | hey there, im trying to create a https_terminated listener according to octavia docs(https://docs.openstack.org/octavia/latest/user/guides/basic-cookbook.html). i've created a test-self-signed certificate and key, converted it to a pkcs12 file and uploaded it to barbican, but i'm getting: could not read x509 from PEM from octavia. | 09:54 |
ivve | https://hastebin.com/qugopixale.rb | 09:56 |
ivve | here is how i did it | 09:56 |
ivve | i can't really spot what i did wrong, i verified the certificate is valid and responds to the key | 09:58 |
ivve | guessing it has to do with the password request | 10:08 |
ivve | also tried just creating the listener to an existing LB | 10:10 |
ivve | openstack loadbalancer listener create --protocol-port 443 --protocol TERMINATED_HTTPS --name listener1 --default-tls-container=$(openstack secret list | awk '/ tls_secret / {print $2}') elk01-loadbalancer_kibana | 10:10 |
ivve | same error occurs.. Could not read X509 from PEM (HTTP 500) | 10:10 |
openstackgerrit | Adit Sarfaty proposed openstack/neutron-lbaas stable/stein: Prevent deletion of a listener attached to a pool https://review.opendev.org/677659 | 10:11 |
*** rpittau is now known as rpittau|bbl | 10:14 | |
rm_work | ivve: is this your cloud? do you have access to logs? | 10:24 |
*** yamamoto has joined #openstack-lbaas | 10:36 | |
ivve | rm_work: yesbox | 10:40 |
ivve | ill get the traceback from heat and octavia | 10:41 |
ivve | here is the traceback form heat (request) | 10:42 |
ivve | https://hastebin.com/apoqegapot.sql | 10:42 |
ivve | this is directly from octavia-api.log | 10:47 |
ivve | https://hastebin.com/efezumaqof.sql | 10:47 |
rm_work | Whelp, that's not very informative | 10:54 |
*** yamamoto has quit IRC | 10:55 | |
cgoncalves | ivve, which octavia version is it running? | 11:05 |
cgoncalves | ivve, could you add "-nodes" to "openssl pkcs12" command and retry? | 11:08 |
ivve | cgoncalves: when adding -nodes i get the exact same error | 11:16 |
ivve | openssl pkcs12 -nodes -export -inkey key.pem -in cert.pem -passout pass: -out secret.p12 | 11:16 |
ivve | Could not read X509 from PEM (HTTP 500) | 11:17 |
ivve | version is stein, getting the exact one in a sec | 11:17 |
ivve | octavia-api is 4.0.0 | 11:18 |
ivve | python-octaviaclient==1.8.0 | 11:19 |
*** salmankhan has joined #openstack-lbaas | 11:19 | |
ivve | no errors from barbican | 11:23 |
ivve | had no problems uploading and downloading the .p12 file, tested that | 11:24 |
ivve | creating loadbalancers without the terminated_https works perfectly also | 11:25 |
*** dayou has quit IRC | 11:28 | |
cgoncalves | ivve, can you check if you can open the pkcs12 file? "openssl pkcs12 -info -in secret.p12" | 11:30 |
ivve | cgoncalves: i can, but it queries for password | 11:31 |
ivve | and i think thats where the problem is | 11:31 |
ivve | but im not sure | 11:31 |
ivve | it does spit out some error regarding the keys tho, due to password being too short | 11:32 |
ivve | so im guessing the creation of the .p12 file is incorrect | 11:34 |
*** salmankhan has quit IRC | 11:38 | |
*** dayou has joined #openstack-lbaas | 11:39 | |
ivve | is there any way to get the cert/key to octavia without pkcs12 ? | 11:45 |
ivve | seems pkcs12 is a hassle since the password becomes "" instead of NULL or undefined | 11:46 |
ivve | think i solved it | 11:56 |
ivve | not fully verified yet, but seems -certfile is needed in addition to -in when converting to pkcs12 | 11:59 |
cgoncalves | ah, probably yeah | 12:01 |
cgoncalves | "openssl pkcs12 -export -nodes -inkey testcert.key -in testcert.pem -certfile ca.cert.pem -passout pass: -out testcert.p12" | 12:02 |
cgoncalves | ^ this is what I use for testing | 12:02 |
ivve | i just used cert.pem on both -in and -certfile | 12:02 |
ivve | since i only have cert and key | 12:02 |
*** rpittau|bbl is now known as rpittau | 12:10 | |
ivve | cgoncalves: would you know what this means? | 12:21 |
ivve | Amphora agent returned unexpected result code 400 with response {u'message': u'Invalid request', u'details': u"[ALERT] 232/120913 (1626) : http frontend '51fb899a-c461-4118-9b3a-4c1af5f15822' (/var/lib/octavia/51fb899a-c461-4118-9b3a-4c1af5f15822/haproxy.cfg.new:23) tries to use incompatible tcp backend 'd8cdcddb-128c-4157-ba30-ae73e6f11e49' (/var/lib/octavia/51fb899a-c461-4118-9b3a-4c1af5f15822/haproxy.cfg.new:32) as its default backend (see | 12:22 |
ivve | 'mode').\n[WARNING] 232/120913 (1626) : Setting tune.ssl.default-dh-param to 1024 by default, if your workload permits it you should set it to at least 2048. Please set a value >= 1024 to make this warning disappear.\n[ALERT] 232/120913 (1626) : Fatal errors found in configuration.\n"} | 12:22 |
ivve | am i still having issues with my cert or is this something else? | 12:22 |
ivve | so strange | 12:32 |
ivve | heat can't find the pool once it is created | 12:32 |
ivve | Resource Create Failed: Notfound: Resources.Pool Kibana: Not Found (Http Fcb7c9bc-1743-4ea3-81cf-827042052d54 Not Found) | 12:33 |
ivve | it was a pool configuration error | 13:01 |
rm_work | Can you ssh into the amp and pastebin that haproxy.cfg.new ? | 13:01 |
ivve | i had it set to https | 13:01 |
ivve | but should be http | 13:01 |
rm_work | Ah, ok | 13:01 |
ivve | so just a brainfart from my side | 13:02 |
rm_work | But we really shouldn't allow an invalid config to get that far | 13:02 |
rm_work | So it's a bug on our side IMO | 13:02 |
rm_work | I wonder if we fixed it in master yet... | 13:02 |
ivve | if protocol: HTTPS it does that | 13:02 |
rm_work | What was the exact config that caused that? | 13:02 |
rm_work | Ahh TLS TERM listener and HTTPS pool | 13:03 |
ivve | pasting | 13:03 |
rm_work | Yeah ok | 13:03 |
ivve | yes | 13:03 |
rm_work | We shouldn't allow that at the API layer, I think | 13:03 |
rm_work | We might have merged better validation... Or maybe it's still pending... But I remember reviewing a patch that seems maybe related | 13:04 |
rm_work | I bet it's still open :/ | 13:04 |
*** ccamposr__ has quit IRC | 13:04 | |
*** ccamposr__ has joined #openstack-lbaas | 13:05 | |
ivve | https://hastebin.com/yuqevoyaxu.py | 13:05 |
ivve | i did some searches but couldn't find any hits (from the errormessage) | 13:07 |
ivve | i would gladly input my log here if you find it | 13:08 |
ivve | if its still open | 13:08 |
rm_work | I'll look later | 13:09 |
rm_work | But yeah, that isn't acceptable for us to take the request and ERROR on something that we can totally tell is wrong at validation time | 13:10 |
rm_work | Should have thrown back a 400 on the original request | 13:11 |
rm_work | Not put the LB in error 😡 | 13:11 |
rm_work | Almost positive there's a pool validation patch up somewhere | 13:12 |
ivve | ok, let me know if you want me to add info to the issue | 13:13 |
ivve | or create a new bug if it doesn't exist | 13:13 |
rm_work | https://review.opendev.org/#/c/594040/ | 13:13 |
rm_work | Found it | 13:13 |
rm_work | Yeah we're aware that combination is bad | 13:13 |
rm_work | I think we just need to review that patch again and get it fixed or merged | 13:14 |
ivve | ok great | 13:19 |
*** tesseract has joined #openstack-lbaas | 13:22 | |
*** tesseract has quit IRC | 13:22 | |
*** ccamposr__ has quit IRC | 13:38 | |
*** ccamposr__ has joined #openstack-lbaas | 13:38 | |
*** pvradu has joined #openstack-lbaas | 14:00 | |
*** pvradu has quit IRC | 14:05 | |
*** gregwork has quit IRC | 14:14 | |
*** coreycb has quit IRC | 14:14 | |
*** dougwig has quit IRC | 14:15 | |
*** xgerman_ has quit IRC | 14:16 | |
*** logan- has quit IRC | 14:16 | |
*** irclogbot_2 has quit IRC | 14:17 | |
*** logan_ has joined #openstack-lbaas | 14:17 | |
*** irclogbot_0 has joined #openstack-lbaas | 14:18 | |
openstackgerrit | Merged openstack/octavia master: Remove amphora-agent build deps https://review.opendev.org/639155 | 14:18 |
*** dougwig has joined #openstack-lbaas | 14:18 | |
*** logan_ is now known as logan- | 14:18 | |
*** xgerman_ has joined #openstack-lbaas | 14:18 | |
*** coreycb has joined #openstack-lbaas | 14:18 | |
*** gregwork has joined #openstack-lbaas | 14:18 | |
*** pvradu has joined #openstack-lbaas | 14:36 | |
*** Vorrtex has joined #openstack-lbaas | 14:41 | |
*** pvradu has quit IRC | 14:51 | |
xgerman_ | https://usercontent.irccloud-cdn.com/file/cakevptf/Screen%20Shot%202019-08-21%20at%208.02.22%20AM.png | 15:02 |
*** ccamposr__ has quit IRC | 15:12 | |
*** ccamposr__ has joined #openstack-lbaas | 15:12 | |
cgoncalves | no pressure | 15:13 |
cgoncalves | xgerman_, hallo! how is it going? | 15:14 |
*** ccamposr__ has quit IRC | 15:16 | |
*** ccamposr__ has joined #openstack-lbaas | 15:16 | |
xgerman_ | going ok — was trying to catch Adam when I am going to Asia next month but... | 15:16 |
xgerman_ | otherwise not much Open Source - glad to see things are still going strong here :-) | 15:16 |
*** gcheresh_ has quit IRC | 15:18 | |
*** ataraday_ has joined #openstack-lbaas | 15:20 | |
*** ivve has quit IRC | 15:21 | |
*** pvradu has joined #openstack-lbaas | 15:25 | |
*** ccamposr__ has quit IRC | 15:26 | |
*** ccamposr__ has joined #openstack-lbaas | 15:26 | |
colin- | do you guys all have sr-iov enabled computes in your fleets? | 15:46 |
*** pvradu has quit IRC | 15:58 | |
johnsom | #startmeeting Octavia | 16:01 |
openstack | Meeting started Wed Aug 21 16:01:32 2019 UTC and is due to finish in 60 minutes. The chair is johnsom. Information about MeetBot at http://wiki.debian.org/MeetBot. | 16:01 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 16:01 |
*** openstack changes topic to " (Meeting topic: Octavia)" | 16:01 | |
openstack | The meeting name has been set to 'octavia' | 16:01 |
johnsom | Sorry I was late... | 16:01 |
ataraday_ | hi | 16:01 |
cgoncalves | hi | 16:01 |
colin- | o/ | 16:02 |
johnsom | I was working to try to put an agenda together... | 16:02 |
johnsom | #link https://wiki.openstack.org/wiki/Octavia/Weekly_Meeting_Agenda#Meeting_2019-08-21 | 16:02 |
*** pvradu has joined #openstack-lbaas | 16:02 | |
gthiemonge | hi | 16:02 |
johnsom | Hi everyone | 16:02 |
*** KeithMnemonic1 has joined #openstack-lbaas | 16:02 | |
johnsom | #topic Announcements | 16:02 |
*** openstack changes topic to "Announcements (Meeting topic: Octavia)" | 16:02 | |
*** KeithMnemonic has quit IRC | 16:03 | |
johnsom | First up, the ranked list for the "U" cycle name is posted. Once the legal review is done the "U" name will be announced. | 16:03 |
johnsom | FYI, the zuul log archive is now different. I mentioned this last week, but I have seen some questions about it. | 16:03 |
johnsom | #link http://lists.openstack.org/pipermail/openstack-discuss/2019-August/008313.html | 16:03 |
johnsom | What I have found is that if you use the top "Logs" tab, then the logs still have links and can be filtered. | 16:04 |
johnsom | It seems slower IMO, but at least it still works. | 16:04 |
johnsom | Personally I think the old way was better, but.... | 16:05 |
*** rpittau is now known as rpittau|afk | 16:05 | |
cgoncalves | I had not noticed the "Logs" tab. thank you! | 16:05 |
johnsom | Finally my weekly reminder: | 16:05 |
cgoncalves | yeah, me too | 16:05 |
johnsom | Feature freeze is rapidly approaching. We must have features merged by Sept 2nd for library changes and Sept. 9th for everything else. | 16:05 |
*** pvradu has quit IRC | 16:05 | |
*** ricolin has quit IRC | 16:05 | |
johnsom | Any other announcements today? | 16:06 |
johnsom | #topic Brief progress reports / bugs needing review | 16:06 |
*** openstack changes topic to "Brief progress reports / bugs needing review (Meeting topic: Octavia)" | 16:06 | |
cgoncalves | more like a personal announcement that I will be on PTO and miss the next two meetings | 16:06 |
johnsom | Ok, enjoy! | 16:06 |
ataraday_ | cgoncalves, have a good vacation! | 16:07 |
johnsom | I have been focusing on re-working the failover flow. We know there are some pretty major issues in the flow and now is the time to fix those. | 16:07 |
johnsom | I have added sub-flow retries, task retries, passive failures, support for missing amps, and code to fix the VIP so far, but there is much left to do.... | 16:08 |
johnsom | Also, ataraday_ I poked the Oslo folks and your fix for the mysql column storage mereged: | 16:09 |
johnsom | #link https://review.opendev.org/675388 | 16:09 |
ataraday_ | I continue work on taskflow to db obj to dicts, bug in taskflow is merged so this is ready for review again https://review.opendev.org/#/c/662791/ | 16:09 |
ataraday_ | johnsom, thanks a lot! | 16:09 |
johnsom | It may still be a week or two before it is released in a package and upper constraints updated | 16:09 |
cgoncalves | it is a very good start! are you going to push it all in one patch? | 16:09 |
johnsom | There are many patches open last time I checked | 16:10 |
johnsom | #link https://review.opendev.org/#/c/662791/ | 16:10 |
cgoncalves | johnsom, I meant for the failover flow work | 16:10 |
johnsom | Added a link so it is highlighted in the meeting notes | 16:11 |
colin- | https://review.opendev.org/#/c/673518/ saw adam's comment in here about testing, going to try cherry picking this down for some basic workflow validation this week | 16:11 |
johnsom | Ah, failover. A strong maybe..... | 16:11 |
colin- | but, don't wait on us :) | 16:11 |
cgoncalves | colin-, awesome! | 16:11 |
johnsom | colin- Please also pull down the child patch: | 16:12 |
johnsom | #link https://review.opendev.org/#/c/675063/1 | 16:12 |
cgoncalves | we have not yet been able to test it down due to last minute CI/infra issues | 16:12 |
colin- | ah interesting, good note thx | 16:12 |
johnsom | ataraday_ I did not get a chance to look at the listener patch yet. Still on my list. | 16:13 |
cgoncalves | the VIP ACL patch is now ready for reviews | 16:13 |
cgoncalves | #link https://review.opendev.org/#/c/659626/ | 16:13 |
colin- | nice | 16:13 |
johnsom | Yay! | 16:14 |
cgoncalves | I know the AAP driver misses some test coverage, hence the Workflow-1. but don't feel discourage to review it | 16:14 |
cgoncalves | next I will be working on a tempest test, but will take me some time till I get to it | 16:15 |
johnsom | Any other updates today? | 16:16 |
cgoncalves | the amphora image size should now be noticable smaller | 16:16 |
cgoncalves | #link https://review.opendev.org/#/c/639155/ | 16:16 |
cgoncalves | *noticeable | 16:16 |
ataraday_ | johnsom, I checked today - rebase when well, there was an issue with my devstack. But there is an issue with cascade delete, which I point on the 9th patch set. And probably the fix for it should a bit bigger than I though. | 16:16 |
cgoncalves | we also switched taskflow engine to parallel. that should accelerate some flow operations like active-standby LB creation | 16:17 |
cgoncalves | #link https://review.opendev.org/#/c/676379/ | 16:17 |
johnsom | ataraday_ Ok, do you still want me to look at it, or do you have that covered? | 16:17 |
johnsom | #link http://tarballs.openstack.org/octavia/test-images/ | 16:17 |
johnsom | FYI, this is how I look at image sizes | 16:18 |
cgoncalves | I have some patches open in DIB to reduce the footprint of yum-minimal images | 16:18 |
cgoncalves | #link https://review.opendev.org/#/q/topic:yum-reduce-footprint | 16:18 |
johnsom | Cool | 16:19 |
ataraday_ | johnsom, I think I will make it work and than ask for review, no worries for now | 16:19 |
johnsom | ataraday_ Ok, thank you. Sorry I have been so busy on other tasks. | 16:19 |
johnsom | #topic Community goals | 16:20 |
*** openstack changes topic to "Community goals (Meeting topic: Octavia)" | 16:20 | |
johnsom | There are three community goals for Train. I wanted to review those real quick as we are getting close to feature freeze, etc. | 16:20 |
johnsom | First up is the python3 (3.7) goal. | 16:21 |
johnsom | #link https://governance.openstack.org/tc/goals/train/python3-updates.html | 16:21 |
johnsom | I think we are done/good here. Does anyone think otherwise? | 16:21 |
johnsom | We have had python3 gates for some time, I think the main change here was adding 3.7 | 16:22 |
johnsom | Ok then, we are already marked as done there, so happy dance. | 16:23 |
johnsom | Second is PDF docs | 16:23 |
johnsom | #link https://governance.openstack.org/tc/goals/train/pdf-doc-generation.html | 16:23 |
johnsom | I took lead on this, but the job infrastructure for this goal is still not really ready. | 16:24 |
johnsom | I have created an etherpad to track our test results: | 16:24 |
johnsom | #link https://etherpad.openstack.org/p/pdf-goal-train-octavia | 16:24 |
johnsom | There is also a overall tracking etherpad: | 16:25 |
johnsom | #link https://etherpad.openstack.org/p/train-pdf-support-goal | 16:25 |
johnsom | I will continue to track this work, but I consider this goal at-risk for train. | 16:25 |
johnsom | Any questions/comments on this goal? | 16:26 |
*** ccamposr__ has quit IRC | 16:26 | |
cgoncalves | does it need to be completed by feature freeze? | 16:26 |
johnsom | Technically, probably not as it's just a docs job. | 16:26 |
cgoncalves | what I am understanding is that it is at risk but not blocked on us | 16:26 |
*** ccamposr has joined #openstack-lbaas | 16:27 | |
johnsom | Correct, it is blocked on the infrastructure/jobs being functional for us to try/use | 16:27 |
cgoncalves | right | 16:27 |
johnsom | This is part of what is blocking: | 16:27 |
johnsom | #link https://review.opendev.org/#/c/664555/ | 16:27 |
johnsom | Finally the IPv6 goal: | 16:28 |
johnsom | #link https://governance.openstack.org/tc/goals/train/ipv6-support-and-testing.html | 16:28 |
johnsom | I think we had some proposed patches for this. | 16:28 |
cgoncalves | #link https://review.opendev.org/#/c/594078/ | 16:28 |
johnsom | As you know, we have IPv6 tempest scenarios already. This goal, for us, is about the control plane. | 16:29 |
johnsom | I.e. calling out to the other services using IPv6 and running the lb-mgmt-net as pure IPv6. | 16:29 |
johnsom | How is that going? | 16:30 |
* johnsom hears crickets | 16:30 | |
cgoncalves | it isn't from my side. haven't had cycles to work on that. rm_work seemed to have picked up the work for a while | 16:30 |
johnsom | Ok, maybe we can get an update from him when he is back online. | 16:31 |
johnsom | Any other questions/comments/updates on the community goals? | 16:31 |
johnsom | #topic Open Discussion | 16:32 |
*** openstack changes topic to "Open Discussion (Meeting topic: Octavia)" | 16:32 | |
johnsom | Ok, any other topics for today? | 16:32 |
colin- | what is the best way to visualize the data a healthmonitor is receiving from a given member? | 16:32 |
colin- | are the GETs/POSTs and corresponding replies logged somewhere i am missing? | 16:33 |
johnsom | Some of that data is logged at the debug level | 16:33 |
colin- | is the amphora-agent carying it out? i checked its log in hopes of finding it (not debug) and didn't see | 16:34 |
johnsom | I.e. | 16:34 |
johnsom | Aug 12 07:04:33 devstack octavia-health-manager[14967]: DEBUG octavia.controller.healthmanager.health_drivers.update_db [-] Listener 34e6feee-6ced-4296-8652-4668a87d2350 / Amphora 8b556645-e8b0-4101-a69e-6e8c5f5a70c4 stats: {'bytes_in': 146, 'bytes_out': 157, 'active_connections': 0, 'total_connections': 2, 'request_errors': 0} {{(pid=29660) _update_stats | 16:34 |
johnsom | /opt/stack/octavia/octavia/controller/healthmanager/health_drivers/update_db.py:543}} | 16:34 |
* cgoncalves has a hard stop now. o/ | 16:35 | |
johnsom | There is also acknowledgment of a packet received: | 16:35 |
johnsom | Aug 12 07:04:43 devstack octavia-health-manager[14967]: DEBUG octavia.amphorae.drivers.health.heartbeat_udp [-] Received packet from ('192.168.0.74', 64717) {{(pid=15515) dorecv /opt/stack/octavia/octavia/amphorae/drivers/health/heartbeat_udp.py:189}} | 16:35 |
johnsom | But I don't think we dump the status payload into the debug log. | 16:35 |
colin- | so for context i'm setting up a healthmonitor and playing around with url_path trying to get my monitor healthy | 16:36 |
colin- | and it's just challenging when i'm not sure what the monitor is seeing | 16:36 |
johnsom | Oh, sorry, my bad. I was thinking health manager.... sigh | 16:36 |
colin- | ;) | 16:36 |
johnsom | Health monitor.... This is done by the haproxy engine. It is not done by the amphora agent. Any messages about those will be in the tenant flow logs in the new log offloading. | 16:37 |
colin- | absent the offloading (not runnint it locally yet) do i have any other options? | 16:38 |
colin- | i guess crank up the debug/logging on haproxy | 16:38 |
johnsom | Yeah, you can look directly at the haproxy logs inside the amphora. All health monitoring results and state transitions are listed there. | 16:38 |
colin- | got it, thanks | 16:39 |
johnsom | If you want to see the content of the health monitor check, you would need to run tcpdump inside the network namespace. (remember to bring up lo interface) | 16:39 |
johnsom | Actually for tcpdump, you may not need the lo up | 16:40 |
johnsom | Ok, any other topics today? | 16:41 |
johnsom | Alright. Thank you folks! Have a great week. | 16:43 |
johnsom | #endmeeting | 16:43 |
*** openstack changes topic to "Discussions for OpenStack Octavia | Priority bug review list: https://etherpad.openstack.org/p/octavia-priority-reviews" | 16:43 | |
openstack | Meeting ended Wed Aug 21 16:43:06 2019 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 16:43 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/octavia/2019/octavia.2019-08-21-16.01.html | 16:43 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/octavia/2019/octavia.2019-08-21-16.01.txt | 16:43 |
openstack | Log: http://eavesdrop.openstack.org/meetings/octavia/2019/octavia.2019-08-21-16.01.log.html | 16:43 |
*** ivve has joined #openstack-lbaas | 16:56 | |
*** psachin has quit IRC | 17:04 | |
*** salmankhan has joined #openstack-lbaas | 18:23 | |
*** ramishra has quit IRC | 18:24 | |
*** maciejjozefczyk has quit IRC | 18:56 | |
openstackgerrit | Merged openstack/octavia master: Lookup interfaces by MAC directly https://review.opendev.org/673337 | 18:59 |
*** gcheresh_ has joined #openstack-lbaas | 19:00 | |
*** salmankhan has quit IRC | 19:17 | |
openstackgerrit | Swaminathan Vasudevan proposed openstack/octavia master: Update osutil support for SUSE distro https://review.opendev.org/541811 | 19:26 |
rm_work | https://www.irccloud.com/pastebin/9t7iTHqE | 20:12 |
rm_work | Damnit | 20:12 |
rm_work | Uhhh cgoncalves does that mean you'll be on vacation through feature freeze? So ... that's a little concerning since we have stuff we'll need reviews on and the only other cores are volunteer / mostly absent. :/ | 20:14 |
rm_work | Enjoy your vacation though... lol | 20:14 |
*** salmankhan has joined #openstack-lbaas | 20:23 | |
*** ajay33 has quit IRC | 20:27 | |
*** gcheresh_ has quit IRC | 20:53 | |
*** altlogbot_2 has quit IRC | 21:16 | |
*** rcernin has joined #openstack-lbaas | 21:27 | |
*** altlogbot_1 has joined #openstack-lbaas | 21:37 | |
*** altlogbot_1 has quit IRC | 21:38 | |
*** altlogbot_3 has joined #openstack-lbaas | 21:41 | |
*** altlogbot_3 has quit IRC | 21:42 | |
colin- | how is octavia meant to read barbican secret containers from other projects? | 21:48 |
colin- | the API is logging "4xx Client error: Not Found: Not Found. Sorry but your secret is in another castle." | 21:49 |
johnsom | colin- When you add a barbican container to a listener, we use the user token of the user creating the listener to add an ACL rule to barbican allowing Octavia access. | 21:54 |
johnsom | So the user adding it to the listener, needs to be the one that stored it in barbican | 21:54 |
colin- | interesting, it's all being done within a single terraform execution scoped as the same individual user (me) in another, non-octavia customer project which is where the container exists | 21:55 |
colin- | (secret container list shows the container there) | 21:55 |
colin- | but when i authenticate to the octavia user i don't see it | 21:55 |
*** ivve has quit IRC | 21:57 | |
johnsom | colin- Wait, what version of Octavia are you running? | 21:58 |
colin- | oh crap | 21:59 |
johnsom | You need rocky or newer for the ACL magic | 21:59 |
colin- | oh yeah i have rocky let me get version number | 21:59 |
johnsom | Ok, then any version of Rocky should be fine | 21:59 |
colin- | and i _should_ be able to see it from the octavia account by virtue of the ACL you mentioned despite the octavia account not being the one that create it? | 22:03 |
colin- | i guess i need to check for that property on the container | 22:03 |
*** salmankhan has quit IRC | 22:09 | |
*** vishalmanchanda has quit IRC | 22:12 | |
openstackgerrit | Swaminathan Vasudevan proposed openstack/octavia master: (WIP):Enable devstack octavia plugin to support SUSE distros https://review.opendev.org/498909 | 22:12 |
openstackgerrit | Swaminathan Vasudevan proposed openstack/octavia master: (WIP):Enable devstack octavia plugin to support SUSE distros https://review.opendev.org/498909 | 22:15 |
openstackgerrit | Swaminathan Vasudevan proposed openstack/octavia master: (WIP):Enable devstack octavia plugin to support SUSE distros https://review.opendev.org/498909 | 22:22 |
*** threestrands has joined #openstack-lbaas | 22:34 | |
*** rcernin has quit IRC | 22:40 | |
*** rcernin has joined #openstack-lbaas | 22:43 | |
*** tkajinam has joined #openstack-lbaas | 22:56 | |
*** Vorrtex has quit IRC | 23:01 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!