mgagne | ok, I found something interesting for people using cells: https://github.com/openstack/nova/blob/master/nova/compute/cells_api.py#L188-L193 | 00:00 |
---|---|---|
mgagne | this function shadows one found in api.py which does network validation at the API level: https://github.com/openstack/nova/blob/master/nova/compute/api.py#L504-L514 | 00:01 |
mgagne | this means if you have more than one network, you should get AmbiguousNetwork exception if you don't provide any network. But if you use cells, this validation is not done and user doesn't get the error right away. It crashes later at the compute node and user only sees "No valid host found". | 00:02 |
*** zhangjn has joined #openstack-operators | 00:02 | |
*** krobzaur has joined #openstack-operators | 00:04 | |
*** SimonChung1 has quit IRC | 00:04 | |
*** lhcheng has quit IRC | 00:07 | |
*** signed8bit is now known as signed8bit_ZZZzz | 00:10 | |
*** sorrison has quit IRC | 00:15 | |
*** signed8bit_ZZZzz is now known as signed8bit | 00:15 | |
*** krobzaur has quit IRC | 00:16 | |
*** openstackgerrit has quit IRC | 00:16 | |
*** openstackgerrit has joined #openstack-operators | 00:17 | |
*** zhangjn has quit IRC | 00:19 | |
*** mdorman has quit IRC | 00:25 | |
*** dminer has quit IRC | 00:32 | |
*** signed8bit is now known as signed8bit_ZZZzz | 00:37 | |
*** rebase has quit IRC | 00:39 | |
*** miyagishi_t has joined #openstack-operators | 00:52 | |
*** zhangjn has joined #openstack-operators | 01:00 | |
*** zhangjn has quit IRC | 01:00 | |
*** zhangjn has joined #openstack-operators | 01:01 | |
*** elo has joined #openstack-operators | 01:03 | |
*** zhangjn has quit IRC | 01:12 | |
*** krobzaur has joined #openstack-operators | 01:13 | |
*** rebase has joined #openstack-operators | 01:15 | |
*** zhangjn has joined #openstack-operators | 01:20 | |
*** zhangjn_ has joined #openstack-operators | 01:27 | |
*** zhangjn has quit IRC | 01:29 | |
*** krobzaur has quit IRC | 01:53 | |
*** SimonChung has joined #openstack-operators | 01:55 | |
*** SimonChung1 has joined #openstack-operators | 01:57 | |
*** SimonChung has quit IRC | 02:00 | |
*** Vinsh_ has joined #openstack-operators | 02:00 | |
*** Vinsh has quit IRC | 02:04 | |
*** ducttape_ has joined #openstack-operators | 02:09 | |
*** signed8bit_ZZZzz is now known as signed8bit | 02:19 | |
*** sorrison has joined #openstack-operators | 02:20 | |
*** kencjohnston has joined #openstack-operators | 02:27 | |
*** signed8bit has quit IRC | 02:32 | |
*** Marga_ has quit IRC | 02:33 | |
*** gfa_ is now known as gfa | 02:34 | |
*** david-ly_ has quit IRC | 02:36 | |
*** dims has joined #openstack-operators | 02:40 | |
*** Vinsh_ has quit IRC | 02:42 | |
*** ducttape_ has quit IRC | 02:48 | |
*** ducttape_ has joined #openstack-operators | 02:53 | |
*** rebase has quit IRC | 02:56 | |
*** ducttape_ has quit IRC | 03:06 | |
*** harshs has quit IRC | 03:08 | |
*** Marga_ has joined #openstack-operators | 03:09 | |
*** Marga_ has quit IRC | 03:14 | |
*** dims has quit IRC | 03:17 | |
*** ducttape_ has joined #openstack-operators | 03:19 | |
*** Vinsh has joined #openstack-operators | 03:21 | |
*** dims has joined #openstack-operators | 03:22 | |
*** Vinsh has quit IRC | 03:26 | |
*** pcaruana has quit IRC | 03:27 | |
*** rick_ has joined #openstack-operators | 03:32 | |
*** kencjohnston has quit IRC | 03:34 | |
*** Vinsh has joined #openstack-operators | 03:34 | |
*** dims has quit IRC | 03:35 | |
*** ducttape_ has quit IRC | 03:44 | |
*** kencjohnston has joined #openstack-operators | 03:48 | |
*** ducttape_ has joined #openstack-operators | 03:49 | |
*** ducttape_ has quit IRC | 03:50 | |
*** zhangjn_ has quit IRC | 04:02 | |
*** sanjayu has joined #openstack-operators | 04:07 | |
*** david-lyle has joined #openstack-operators | 04:08 | |
*** ducttape_ has joined #openstack-operators | 04:19 | |
*** zhangjn has joined #openstack-operators | 04:22 | |
*** ducttape_ has quit IRC | 04:24 | |
*** ducttape_ has joined #openstack-operators | 04:36 | |
*** zhangjn has quit IRC | 04:44 | |
*** mageshgv has joined #openstack-operators | 04:54 | |
*** maishsk has quit IRC | 04:56 | |
*** maishsk has joined #openstack-operators | 04:56 | |
*** jmccrory has quit IRC | 04:58 | |
*** maishsk has quit IRC | 04:59 | |
*** jmccrory has joined #openstack-operators | 05:00 | |
*** maishsk has joined #openstack-operators | 05:08 | |
*** rcernin has joined #openstack-operators | 05:15 | |
*** Marga_ has joined #openstack-operators | 05:16 | |
*** ducttape_ has quit IRC | 05:18 | |
*** zhangjn has joined #openstack-operators | 05:23 | |
*** kencjohnston has quit IRC | 05:32 | |
*** rcernin has quit IRC | 05:34 | |
*** beddari has quit IRC | 05:38 | |
*** maishsk has quit IRC | 05:41 | |
*** beddari has joined #openstack-operators | 05:42 | |
*** pcaruana has joined #openstack-operators | 05:49 | |
*** Marga_ has quit IRC | 06:09 | |
*** Marga_ has joined #openstack-operators | 06:10 | |
*** pasquier-s has quit IRC | 06:13 | |
*** pasquier-s has joined #openstack-operators | 06:14 | |
*** rcernin has joined #openstack-operators | 06:18 | |
*** liverpooler has joined #openstack-operators | 06:19 | |
*** pcaruana has quit IRC | 06:28 | |
*** rick_ has quit IRC | 06:53 | |
*** rick_ has joined #openstack-operators | 07:31 | |
*** bvandenh has joined #openstack-operators | 07:34 | |
*** matrohon has joined #openstack-operators | 07:49 | |
*** bvandenh has quit IRC | 08:16 | |
*** rick_ has quit IRC | 08:33 | |
*** subscope has joined #openstack-operators | 08:36 | |
*** subscope has quit IRC | 08:48 | |
*** subscope has joined #openstack-operators | 08:52 | |
*** berendt has joined #openstack-operators | 08:54 | |
*** Marga_ has quit IRC | 08:58 | |
*** Marga_ has joined #openstack-operators | 09:02 | |
*** GonZo2000 has quit IRC | 09:06 | |
*** boyvinall has quit IRC | 09:07 | |
*** subscope has quit IRC | 09:09 | |
*** subscope has joined #openstack-operators | 09:10 | |
*** derekh has joined #openstack-operators | 09:10 | |
*** openstackgerrit has quit IRC | 09:16 | |
*** openstackgerrit has joined #openstack-operators | 09:17 | |
*** subscope has quit IRC | 09:37 | |
*** bvandenh has joined #openstack-operators | 09:44 | |
*** Marga_ has quit IRC | 09:46 | |
*** zhangjn has quit IRC | 09:48 | |
*** lhcheng has joined #openstack-operators | 09:54 | |
*** Marga_ has joined #openstack-operators | 09:54 | |
*** maishsk has joined #openstack-operators | 09:55 | |
*** Marga_ has quit IRC | 10:09 | |
*** Marga_ has joined #openstack-operators | 10:09 | |
*** Marga_ has quit IRC | 10:19 | |
*** subscope has joined #openstack-operators | 10:30 | |
*** subscope has quit IRC | 10:41 | |
*** maishsk has quit IRC | 10:59 | |
*** dims has joined #openstack-operators | 11:06 | |
*** rcernin is now known as rcernin|lunch | 11:13 | |
*** toddnni has quit IRC | 11:19 | |
*** toddnni has joined #openstack-operators | 11:22 | |
*** subscope has joined #openstack-operators | 12:00 | |
*** mageshgv has quit IRC | 12:03 | |
*** GonZo2000 has joined #openstack-operators | 12:05 | |
*** GonZo2000 has quit IRC | 12:05 | |
*** GonZo2000 has joined #openstack-operators | 12:05 | |
*** boyvinall has joined #openstack-operators | 12:06 | |
*** subscope has quit IRC | 12:13 | |
*** subscope has joined #openstack-operators | 12:14 | |
*** zhangjn has joined #openstack-operators | 12:18 | |
*** zhangjn has quit IRC | 12:18 | |
*** zhangjn has joined #openstack-operators | 12:19 | |
*** zhangjn has quit IRC | 12:20 | |
*** miyagishi_t has quit IRC | 12:20 | |
*** zhangjn has joined #openstack-operators | 12:20 | |
*** zhangjn has quit IRC | 12:20 | |
*** zhangjn has joined #openstack-operators | 12:21 | |
*** zhangjn has quit IRC | 12:22 | |
*** zhangjn has joined #openstack-operators | 12:22 | |
*** zhangjn has quit IRC | 12:23 | |
*** zhangjn has joined #openstack-operators | 12:29 | |
*** zhangjn has quit IRC | 12:33 | |
*** zhangjn has joined #openstack-operators | 12:34 | |
*** alejandrito has joined #openstack-operators | 12:34 | |
*** rcernin|lunch is now known as rcernin | 12:36 | |
*** subscope has quit IRC | 12:44 | |
*** maishsk has joined #openstack-operators | 12:45 | |
*** subscope has joined #openstack-operators | 12:46 | |
*** lhcheng_ has joined #openstack-operators | 12:51 | |
*** lhcheng has quit IRC | 12:51 | |
*** ducttape_ has joined #openstack-operators | 12:55 | |
*** _nick has quit IRC | 12:57 | |
*** _nick has joined #openstack-operators | 13:02 | |
*** lhcheng_ has quit IRC | 13:09 | |
*** _nick has quit IRC | 13:14 | |
*** _nick has joined #openstack-operators | 13:15 | |
*** lhcheng has joined #openstack-operators | 13:20 | |
*** ducttape_ has quit IRC | 13:20 | |
*** bvandenh has quit IRC | 13:24 | |
*** markvoelker has quit IRC | 13:35 | |
*** markvoelker has joined #openstack-operators | 13:53 | |
*** sleinen-AS559 has joined #openstack-operators | 13:56 | |
*** maishsk has quit IRC | 13:58 | |
*** zhangjn has quit IRC | 14:00 | |
*** subscope has quit IRC | 14:00 | |
*** maishsk has joined #openstack-operators | 14:01 | |
*** rcernin has quit IRC | 14:03 | |
*** subscope has joined #openstack-operators | 14:04 | |
*** pilgrimstack has quit IRC | 14:07 | |
*** pilgrimstack has joined #openstack-operators | 14:10 | |
*** subscope has quit IRC | 14:10 | |
*** subscope has joined #openstack-operators | 14:11 | |
*** ctrath has joined #openstack-operators | 14:11 | |
*** subscope has quit IRC | 14:13 | |
*** ducttape_ has joined #openstack-operators | 14:13 | |
*** subscope has joined #openstack-operators | 14:13 | |
*** ducttape_ has quit IRC | 14:14 | |
*** subscope has quit IRC | 14:16 | |
*** ducttape_ has joined #openstack-operators | 14:16 | |
*** subscope has joined #openstack-operators | 14:17 | |
*** pilgrimstack has quit IRC | 14:18 | |
*** ctrath has left #openstack-operators | 14:19 | |
*** pilgrimstack has joined #openstack-operators | 14:19 | |
*** krobzaur has joined #openstack-operators | 14:20 | |
*** dminer has joined #openstack-operators | 14:22 | |
*** regXboi has joined #openstack-operators | 14:23 | |
*** mriedem_away is now known as mriedem | 14:33 | |
*** ToMiles has joined #openstack-operators | 14:35 | |
*** bvandenh has joined #openstack-operators | 14:36 | |
*** sanjayu has quit IRC | 14:37 | |
*** kencjohnston has joined #openstack-operators | 14:40 | |
*** krobzaur has quit IRC | 14:44 | |
*** krobzaur has joined #openstack-operators | 14:46 | |
*** dims_ has joined #openstack-operators | 15:08 | |
*** dims has quit IRC | 15:09 | |
*** mdorman has joined #openstack-operators | 15:16 | |
*** markvoelker has quit IRC | 15:18 | |
*** markvoelker has joined #openstack-operators | 15:18 | |
*** subscope has quit IRC | 15:26 | |
*** maishsk has quit IRC | 15:27 | |
*** maishsk has joined #openstack-operators | 15:27 | |
*** maishsk has joined #openstack-operators | 15:30 | |
*** subscope has joined #openstack-operators | 15:36 | |
*** maishsk has quit IRC | 15:36 | |
*** Marga_ has joined #openstack-operators | 15:38 | |
*** subscope has quit IRC | 15:40 | |
*** subscope has joined #openstack-operators | 15:57 | |
*** subscope has quit IRC | 15:59 | |
*** VW has joined #openstack-operators | 16:01 | |
*** VW has quit IRC | 16:02 | |
*** krobzaur has quit IRC | 16:04 | |
*** matrohon has quit IRC | 16:16 | |
*** rcernin has joined #openstack-operators | 16:16 | |
*** harshs has joined #openstack-operators | 16:24 | |
*** lhcheng_ has joined #openstack-operators | 16:29 | |
*** rebase has joined #openstack-operators | 16:30 | |
*** dims_ has quit IRC | 16:30 | |
*** lhcheng has quit IRC | 16:32 | |
*** matrohon has joined #openstack-operators | 16:32 | |
*** rebase has quit IRC | 16:34 | |
*** krobzaur has joined #openstack-operators | 16:35 | |
*** signed8bit has joined #openstack-operators | 16:40 | |
*** dims has joined #openstack-operators | 16:46 | |
*** ToMiles has quit IRC | 16:50 | |
*** VW has joined #openstack-operators | 17:03 | |
*** VW has quit IRC | 17:10 | |
*** dims has quit IRC | 17:18 | |
*** dims_ has joined #openstack-operators | 17:18 | |
*** regXboi has quit IRC | 17:19 | |
*** david-ly_ has joined #openstack-operators | 17:19 | |
*** matrohon has quit IRC | 17:19 | |
*** david-l__ has joined #openstack-operators | 17:23 | |
*** david-ly_ has quit IRC | 17:23 | |
*** david-lyle has quit IRC | 17:23 | |
*** harshs has quit IRC | 17:26 | |
*** david-l__ has quit IRC | 17:30 | |
*** SimonChung1 has quit IRC | 17:33 | |
*** derekh has quit IRC | 17:35 | |
*** ducttape_ has quit IRC | 17:40 | |
*** Marga_ has quit IRC | 17:42 | |
*** david-lyle has joined #openstack-operators | 17:44 | |
*** Marga_ has joined #openstack-operators | 17:46 | |
*** electrofelix has joined #openstack-operators | 17:46 | |
*** maishsk has joined #openstack-operators | 17:49 | |
*** SimonChung has joined #openstack-operators | 17:50 | |
*** Marga_ has quit IRC | 17:51 | |
*** maishsk has quit IRC | 17:56 | |
*** SimonChung has quit IRC | 18:03 | |
*** SimonChung has joined #openstack-operators | 18:03 | |
*** david-lyle has quit IRC | 18:03 | |
*** SimonChung1 has joined #openstack-operators | 18:03 | |
*** SimonChung has quit IRC | 18:03 | |
*** SimonChung has joined #openstack-operators | 18:05 | |
*** SimonChung1 has quit IRC | 18:05 | |
*** SimonChung1 has joined #openstack-operators | 18:05 | |
*** SimonChung has quit IRC | 18:05 | |
*** wasmum has joined #openstack-operators | 18:11 | |
*** david-lyle has joined #openstack-operators | 18:11 | |
*** Marga_ has joined #openstack-operators | 18:14 | |
*** mriedem has quit IRC | 18:17 | |
*** mriedem has joined #openstack-operators | 18:21 | |
*** liverpooler has quit IRC | 18:27 | |
*** harshs has joined #openstack-operators | 18:30 | |
*** pilgrimstack has quit IRC | 18:49 | |
*** SimonChung has joined #openstack-operators | 18:57 | |
*** SimonChung1 has quit IRC | 18:57 | |
*** SimonChung has quit IRC | 18:57 | |
*** SimonChung1 has joined #openstack-operators | 18:57 | |
*** VW has joined #openstack-operators | 19:10 | |
*** alejandrito has quit IRC | 19:10 | |
*** signed8bit is now known as signed8bit_ZZZzz | 19:13 | |
j^2 | I'm pretty crazy surprised that I have 8 nominations for the OpenStack Board already | 19:14 |
j^2 | anyone else willing to help out? | 19:14 |
j^2 | https://www.openstack.org/community/members/profile/19802 | 19:14 |
*** VW has quit IRC | 19:15 | |
*** signed8bit_ZZZzz is now known as signed8bit | 19:23 | |
dmsimard | j^2: http://i.imgur.com/0Ixp8uQ.jpg ? :) | 19:27 |
*** krobzaur_ has joined #openstack-operators | 19:42 | |
*** krobzaur has quit IRC | 19:42 | |
*** Marga_ has quit IRC | 19:45 | |
*** regXboi has joined #openstack-operators | 19:46 | |
*** krobzaur_ has quit IRC | 19:52 | |
*** dims has joined #openstack-operators | 19:53 | |
*** dims_ has quit IRC | 19:56 | |
*** krobzaur_ has joined #openstack-operators | 19:59 | |
*** kencjohnston has quit IRC | 20:04 | |
*** signed8bit is now known as signed8bit_ZZZzz | 20:14 | |
*** signed8bit_ZZZzz is now known as signed8bit | 20:16 | |
*** bvandenh has quit IRC | 20:17 | |
j^2 | dmsimard: exactly | 20:21 |
xavpaice | "this candidate has already received 10 nominations" | 20:23 |
*** krobzaur has joined #openstack-operators | 20:29 | |
*** krobzaur_ has quit IRC | 20:32 | |
wasmum | i'll be, my bouncer came back online. | 20:45 |
*** ducttape_ has joined #openstack-operators | 20:45 | |
*** ducttape_ has quit IRC | 20:45 | |
*** ducttape_ has joined #openstack-operators | 20:45 | |
*** kencjohnston has joined #openstack-operators | 20:50 | |
mriedem | anyone here care about the performance of nova's unshelve operation? https://review.openstack.org/#/c/135387/ | 20:51 |
*** maishsk has joined #openstack-operators | 20:58 | |
*** lhcheng_ has quit IRC | 21:01 | |
*** VW has joined #openstack-operators | 21:06 | |
*** VW has quit IRC | 21:12 | |
wasmum | mriedem: definitely interested, just read the specs and blueprints - i'll keep watching this, thanks! | 21:13 |
mriedem | i totally don't understand why a config option is necessary here | 21:16 |
mriedem | if you're on shared storage, leave the disk so unshelve is faster | 21:17 |
*** regXboi has quit IRC | 21:25 | |
klindgren_ | I thought the whole point of unshelve was to move storage from in theory more expensive disks to also in theory less expensive object storage | 21:33 |
klindgren_ | otherwise why not just stop the vm and leave it in a shutdown state? | 21:34 |
*** Marga_ has joined #openstack-operators | 21:37 | |
*** dims has quit IRC | 21:37 | |
*** dims has joined #openstack-operators | 21:38 | |
*** Marga_ has quit IRC | 21:42 | |
*** elo has quit IRC | 21:46 | |
*** jaypipes has quit IRC | 21:47 | |
xavpaice | I thought it was because shutdown instances still consume resources on a hypervisor, but if you shelve it then other instances can use that cpu/ram/etc | 21:53 |
xavpaice | s/consume/reserve/ | 21:54 |
*** elo has joined #openstack-operators | 21:54 | |
*** maishsk has quit IRC | 21:55 | |
*** Marga_ has joined #openstack-operators | 21:55 | |
*** SimonChung has joined #openstack-operators | 21:56 | |
*** SimonChung1 has quit IRC | 21:56 | |
*** dminer has quit IRC | 21:57 | |
*** Marga_ has quit IRC | 21:57 | |
*** lhcheng has joined #openstack-operators | 21:57 | |
*** Marga_ has joined #openstack-operators | 21:58 | |
*** SimonChung1 has joined #openstack-operators | 22:00 | |
*** SimonChung has quit IRC | 22:00 | |
*** kencjohnston has quit IRC | 22:02 | |
*** kencjohnston has joined #openstack-operators | 22:03 | |
mriedem | xavpaice: yeah, that | 22:05 |
mriedem | shelve offload snapshots the instance and destroys the instance from the hypervisor | 22:05 |
mriedem | the instance is still in the nova db though, | 22:05 |
mriedem | so when you unshelve, you can re-use that instance and it's network/bdm information and original image | 22:05 |
xavpaice | do people charge customers for 'shutdown' instances at all, given that they still reserve stuff on the hypervisor? | 22:10 |
xavpaice | we decided not to, but when we're telling customers to shut down their instances to save them money, we still can't re-use that resource for another customer | 22:11 |
*** Piet has quit IRC | 22:16 | |
*** krobzaur has quit IRC | 22:16 | |
*** signed8b_ has joined #openstack-operators | 22:20 | |
*** signed8bit has quit IRC | 22:20 | |
*** signed8b_ has quit IRC | 22:32 | |
*** signed8bit has joined #openstack-operators | 22:38 | |
*** mriedem has quit IRC | 22:38 | |
mgagne | I don't see why you wouldn't charge someone renting a car but leaving it in his driveway. Meanwhile, the service provider can't rent it to someone else :-/ | 22:42 |
serverascode | xavpaice: yeah we have that problem too, ha, we haven't completely figured out what we are going to do yet, but we can't just let ppl take up resources and not charge them, so have to figure something out... | 22:44 |
mgagne | IPv4 isn't free either =) | 22:45 |
jamespd | ^^ heh. | 22:45 |
* jamespd is constantly arguing for a floating ip price increase. | 22:45 | |
* klindgren_ reserves all the floating ip's. | 22:46 | |
mgagne | yep | 22:46 |
klindgren_ | can I get those routed to another datacenter as well? | 22:46 |
mgagne | you reserve, you pay. that's my philosophy | 22:46 |
jamespd | ^^ totally | 22:46 |
mgagne | if you can get neutron to support inter-region, why not =) | 22:46 |
mgagne | assuming you have different neutron installs per dc | 22:46 |
klindgren_ | I think you found a new business model for HP | 22:47 |
mgagne | if you are using NAT, that's an other story IMO | 22:47 |
mgagne | but private IPv4 aren't infinite either | 22:47 |
klindgren_ | /24 leases on their 2 /8's of space | 22:47 |
*** kencjohnston has quit IRC | 22:49 | |
*** krobzaur has joined #openstack-operators | 22:56 | |
*** Marga_ has quit IRC | 22:57 | |
*** Marga_ has joined #openstack-operators | 22:59 | |
*** krobzaur has quit IRC | 23:02 | |
*** harshs has quit IRC | 23:03 | |
*** harshs has joined #openstack-operators | 23:08 | |
*** SimonChung has joined #openstack-operators | 23:09 | |
*** SimonChung1 has quit IRC | 23:09 | |
*** VW has joined #openstack-operators | 23:09 | |
*** bvandenh has joined #openstack-operators | 23:14 | |
*** VW has quit IRC | 23:14 | |
*** signed8bit is now known as signed8bit_ZZZzz | 23:20 | |
*** dims_ has joined #openstack-operators | 23:28 | |
*** ducttape_ has quit IRC | 23:29 | |
*** dims has quit IRC | 23:29 | |
*** lhcheng_ has joined #openstack-operators | 23:29 | |
*** lhcheng has quit IRC | 23:30 | |
*** sanjayu has joined #openstack-operators | 23:35 | |
*** bvandenh has quit IRC | 23:35 | |
*** signed8bit_ZZZzz is now known as signed8bit | 23:36 | |
mgagne | klindgren_ are you guys using UUID token format? | 23:37 |
*** SimonChung1 has joined #openstack-operators | 23:38 | |
*** SimonChung has quit IRC | 23:38 | |
klindgren_ | inded! | 23:38 |
klindgren_ | indeed** | 23:38 |
mgagne | klindgren_ happy with it? | 23:38 |
mgagne | klindgren_ much traffic? | 23:38 |
*** SimonChung1 has quit IRC | 23:38 | |
klindgren_ | as happy as I can be given the options | 23:38 |
*** SimonChung has joined #openstack-operators | 23:38 | |
mgagne | klindgren_ we are having issues with PKI token (with stripped catalog) and Heat | 23:38 |
mgagne | hehe | 23:38 |
klindgren_ | we see some traffic but - honestly for us it doesn't seem to cause an issue | 23:39 |
mgagne | klindgren_ it's one of the deepest rabbit hole I have been in recently | 23:39 |
*** SimonChung has quit IRC | 23:39 | |
*** SimonChung1 has joined #openstack-operators | 23:39 | |
klindgren_ | I assumed you wanted pki tokens due to the ability for services to verify the token themselves without going to keystone? | 23:40 |
mgagne | yep | 23:40 |
*** ducttape_ has joined #openstack-operators | 23:40 | |
mgagne | but I'm not emotionally attached to PKI | 23:41 |
klindgren_ | I saw a presentation at tokyo that seemed to indicate that is not 100% the case | 23:41 |
mgagne | but some of my coworkers are and I'm looking for more empirical evidences that UUID aren't that bad | 23:41 |
mgagne | klindgren_ yea, I found that | 23:41 |
mgagne | some services are poking back for god knows what reasons | 23:41 |
klindgren_ | seems like they are still querry keystone to ensure the token is valid before accepting it | 23:42 |
klindgren_ | IE not expired/revoked | 23:42 |
jamespd | but... you can't really validate a PKI token offline, given that you need to check the revocation list. | 23:42 |
sorrison | we use PKI tokens | 23:42 |
jamespd | heh. what klindgren_ said. | 23:42 |
*** rcernin has quit IRC | 23:42 | |
mgagne | jamespd revocation list is synced every X seconds | 23:42 |
sorrison | it doesn't need to talk to keystone to validate the token | 23:42 |
sorrison | but it downloads the CRL from keystone alot! | 23:43 |
mgagne | yep | 23:43 |
jamespd | ah | 23:43 |
sorrison | we want to disable CRL checking as we don't care, we have small ttl on our tokens | 23:43 |
* jamespd nods. | 23:44 | |
klindgren_ | though I keep hearing stuff about some issue with pki tokens thats has a security embargo on it. Not sure wtf thats about. | 23:48 |
xavpaice | PKI tokens have caused all manner of other pain though | 23:48 |
klindgren_ | anyway mgagne if we were going to switch we might go to fernet tokens | 23:48 |
xavpaice | the sheer size of them, and the effect that has on the keystone db, is a problem in itself | 23:48 |
mgagne | klindgren_ there is not much reason to move to PKI those days when UUID and fernet exist | 23:48 |
xavpaice | +1 | 23:49 |
mgagne | xavpaice worked to some extend (until today): http://blog.mgagne.ca/reducing-keystone-pki-token-size/ | 23:49 |
klindgren_ | one thing I do notice is that most of the API reuqests that I see in services (now that I have wsgi logs logging user/tenant) is actually between the configured admin accounts | 23:50 |
klindgren_ | I would imagine that configuring that as a trusted auth source not having to go through keystone would cut down on a number of calls | 23:50 |
klindgren_ | with uuid/fernet | 23:50 |
stevemar | klindgren_: yeah, avoid PKI, i'll be sending out an email to the operator mailing list about things we're gonna deprecate in Mitaka | 23:50 |
stevemar | PKI is among that list | 23:50 |
klindgren_ | talking about nova <-> neutron nova <-> glance interactions | 23:51 |
klindgren_ | stevemar, cool - it would be good to have some real details asside from this nebulous - chatter around pki tokens and not using them. But we can't say why | 23:52 |
stevemar | klindgren_: there is a bug filed against them, which the vulnerability management team is handling. | 23:53 |
stevemar | klindgren_: i'm not sure we can go public with the info until we release an OSSN/OSSA | 23:54 |
klindgren_ | stevemar, no - I get that. Just wanting to read why is all. | 23:55 |
stevemar | klindgren_ i understand, i'll prioritize that stuff next week when folks are around | 23:56 |
klindgren_ | do people on the security pre-warning mailing list get more info ahead of time? | 23:56 |
klindgren_ | IE we can start planning on making shifts to public clouds before we have an "oh crap moment" | 23:57 |
klindgren_ | without actually knowing the end's and out's of the actual vunerability | 23:57 |
*** signed8bit is now known as signed8bit_ZZZzz | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!