Friday, 2016-11-18

*** dminer has quit IRC00:06
*** catintheroof has joined #openstack-operators00:11
*** ducttape_ has joined #openstack-operators00:17
*** ducttape_ has quit IRC00:17
*** ducttape_ has joined #openstack-operators00:17
*** ducttape_ has quit IRC00:23
*** ducttape_ has joined #openstack-operators00:33
*** kstev has quit IRC00:51
*** catintheroof has quit IRC00:54
*** ducttape_ has quit IRC00:57
*** kstev has joined #openstack-operators01:03
*** ducttape_ has joined #openstack-operators01:05
*** kstev has quit IRC01:07
*** chlong has quit IRC01:11
*** kstev has joined #openstack-operators01:19
*** ducttape_ has quit IRC02:14
*** markvoelker has quit IRC02:18
*** kstev has quit IRC02:28
*** kstev has joined #openstack-operators02:41
*** ducttape_ has joined #openstack-operators03:01
*** fragatina has quit IRC03:03
*** fragatina has joined #openstack-operators03:05
*** fragatin_ has joined #openstack-operators03:09
*** fragatina has quit IRC03:09
*** fragatin_ has quit IRC03:14
*** Apoorva has quit IRC03:15
*** markvoelker has joined #openstack-operators03:19
*** mriedem has quit IRC03:23
*** markvoelker has quit IRC03:25
*** ducttape_ has quit IRC03:49
*** ducttape_ has joined #openstack-operators03:51
*** ducttape_ has quit IRC03:51
*** ducttape_ has joined #openstack-operators03:52
*** kstev has quit IRC03:54
*** ducttape_ has quit IRC03:56
*** haplo37_ has quit IRC04:00
*** armax has quit IRC04:26
*** udesale has joined #openstack-operators05:18
*** markvoelker has joined #openstack-operators05:20
*** I has joined #openstack-operators05:24
*** I is now known as Guest6625405:24
*** markvoelker has quit IRC05:25
*** Guest66254 has quit IRC05:29
*** ducttape_ has joined #openstack-operators05:30
*** ducttape_ has quit IRC05:34
*** twiggy has joined #openstack-operators05:36
*** haplo37 has joined #openstack-operators06:04
*** pilgrimstack has quit IRC06:06
*** pilgrimstack has joined #openstack-operators06:06
*** haplo37 has quit IRC06:13
*** mgagne has quit IRC06:18
*** hughsaunders has quit IRC06:20
*** timburke has quit IRC06:20
*** mgagne has joined #openstack-operators06:21
*** mgagne is now known as Guest5228506:21
*** timburke has joined #openstack-operators06:23
*** hughsaunders has joined #openstack-operators06:23
*** haplo37 has joined #openstack-operators06:26
*** tesseract has joined #openstack-operators07:18
*** tesseract is now known as Guest9031307:18
*** Miouge has joined #openstack-operators07:20
*** simon-AS5591 has quit IRC07:20
*** jsheeren has joined #openstack-operators07:44
*** pcaruana has joined #openstack-operators07:45
*** lukl has quit IRC07:49
*** belmoreira has joined #openstack-operators07:51
*** simon-AS559 has joined #openstack-operators07:52
*** sticker_ has joined #openstack-operators07:57
*** sticker has quit IRC08:00
*** openstackgerrit has quit IRC08:03
*** openstackgerrit has joined #openstack-operators08:03
*** matrohon has joined #openstack-operators08:11
*** belmoreira has quit IRC09:03
*** zz9pzza has left #openstack-operators09:04
*** paramite has joined #openstack-operators09:07
*** rmart04 has joined #openstack-operators09:12
*** derekh has joined #openstack-operators09:14
yankcrimeah, this is interesting - we're currently limiting at ~260k09:31
yankcrimeklindgren__: care to share your other conntrack-related tunables?09:31
yankcrimeif you haven't already?09:31
yankcrimemed_: we've had issues where shady (former) customers have been doing stuff like sending out spam09:32
yankcrimewe'd see behaviour like 1+ million DNS requests and then hundreds of thousands of outbound tcp connections to port 2509:33
yankcrimeanyway, because of that i'm reluctant to whack the limit right up - it's usually a symptom of someone Doing It Wrong ™ (i.e hacked) or generally up to no good, so early sight of that is useful09:35
*** derekjhyang has quit IRC09:51
*** AlexeyAbashkin has joined #openstack-operators09:53
*** AlexeyAbashkin has quit IRC10:16
*** belmoreira has joined #openstack-operators10:17
*** electrofelix has joined #openstack-operators10:33
*** fragatina has joined #openstack-operators10:35
*** fragatina has quit IRC10:36
*** fragatina has joined #openstack-operators10:37
*** simon-AS559 has quit IRC10:41
*** udesale has quit IRC10:50
*** chaology has quit IRC11:31
*** chaology has joined #openstack-operators11:33
*** ducttape_ has joined #openstack-operators11:35
*** chaology has quit IRC11:36
*** chaology has joined #openstack-operators11:37
*** ducttape_ has quit IRC11:39
*** chaology has quit IRC11:45
*** chaology has joined #openstack-operators11:45
*** mjrichardson has quit IRC11:47
*** mjrichardson has joined #openstack-operators11:47
*** derekjhyang has joined #openstack-operators12:21
logan-yankcrime: yep @ tcp/25. we do hashlimit policing on tcp/25 per /32 and also 2mil conntrack_max. +1 interested in seeing what other conntrack/net tunables folks have implemented. I can think of a few setup/teardown ones I'd like to get added that we use to harden other infra (ie. ddos scrubbing boxes)12:29
yankcrimethanks logan- - good info12:29
*** ducttape_ has joined #openstack-operators12:36
*** vijaykc4 has joined #openstack-operators12:38
*** vijaykc4 has quit IRC12:40
*** ducttape_ has quit IRC12:40
*** simon-AS559 has joined #openstack-operators13:01
*** stupidnic has quit IRC13:02
*** stupidnic has joined #openstack-operators13:02
*** ducttape_ has joined #openstack-operators13:08
*** simon-AS559 has quit IRC13:13
mnaseryankcrime do you use provider networks for public internet (directly connected) or via nats?13:15
mnaserlogan- thats interesting, we never thought about doing something like that, do you implement it on the compute/hv side?13:17
logan-yes. my env is calico so internet traffic is routed straight to/from the computes. the hashlimit runs on the compute iptables and polices down outbound syn on tcp/25 to some threshold per /32.13:18
logan-then logs exceeded hits, aggregate and counts them, and posts to #abuse on our slack periodically :P13:20
mnaserlogan- thats pretty badass13:22
mnasersince looking at calico i've really wanted to try it but..13:22
mnaserthere's no way we're going to even think about migrating our env to that13:22
yankcrimemnaser: the latter13:22
mnaserah, i think that's a bigger challenge with iptables13:23
mnasererr13:23
mnaserconntrack tables13:23
yankcrimeyeah, interesting to hear what people's approaches are though for mitigating this kind of problem13:24
*** simon-AS559 has joined #openstack-operators13:29
*** simon-AS559 has quit IRC13:39
*** mriedem has joined #openstack-operators13:40
*** ducttape_ has quit IRC13:48
*** dminer has joined #openstack-operators13:48
*** markvoelker has joined #openstack-operators13:49
*** baffle has quit IRC13:51
*** baffle has joined #openstack-operators13:52
*** ducttape_ has joined #openstack-operators14:24
*** mriedem has quit IRC14:30
*** derekjhyang has quit IRC14:31
*** jsheeren has quit IRC14:35
*** jsheeren has joined #openstack-operators14:36
*** jsheeren has quit IRC14:37
*** jsheeren has joined #openstack-operators14:37
*** jsheeren has quit IRC14:39
*** ducttape_ has quit IRC14:40
*** jsheeren has joined #openstack-operators14:41
*** jsheeren has quit IRC14:42
*** dansmith is now known as superdan14:42
*** jsheeren has joined #openstack-operators14:42
*** jsheeren has quit IRC14:42
*** jsheeren has joined #openstack-operators14:43
*** chlong has joined #openstack-operators14:53
*** simon-AS559 has joined #openstack-operators15:02
*** simon-AS559 has quit IRC15:08
*** mriedem has joined #openstack-operators15:12
*** kstev has joined #openstack-operators15:12
*** ducttape_ has joined #openstack-operators15:14
*** simon-AS559 has joined #openstack-operators15:22
*** dminer has quit IRC15:24
*** slaweq has quit IRC15:26
*** simon-AS559 has quit IRC15:28
*** simon-AS559 has joined #openstack-operators15:31
klindgren__we do that in other ways, like we have TC running on all of our public vm's.  So that we can ratelimit specific things that we have learned over time through our VPS products15:37
klindgren__we also setup mgmt ports into the hv's as notrack rules so we can always ssh into the servers, same with RMQ connectivity and our monitoring stuff15:38
klindgren__we monitor conntrack and have an auto-rememdiation to clear cruft out of the tables if they are full15:39
*** simon-AS559 has quit IRC15:40
*** dminer has joined #openstack-operators15:41
*** cheetah has quit IRC15:43
*** pcaruana has quit IRC15:50
*** HenryG has quit IRC15:50
*** HenryG has joined #openstack-operators15:51
*** simon-AS559 has joined #openstack-operators15:52
*** armax has joined #openstack-operators15:55
*** kstev has quit IRC15:57
*** belmoreira has quit IRC15:57
*** simon-AS559 has quit IRC16:01
*** jamesdenton has joined #openstack-operators16:02
logan-thats good stuff re: the notrack klindgren__16:02
*** klindgren__ is now known as klindgren16:02
*** jsheeren has quit IRC16:03
logan-i remember the tc stuff you did.. still been wanting to implement some of that fair queueing stuff on our hvs but no time :(16:03
klindgrenI think the team that did that was looking at moving it to some other thing so that we dont blow stuff up.16:04
klindgrenI should say that we have to create an ifb device per vm16:05
klindgrenand we have to have a program come along and nuke the ifb devices on occasion.16:05
klindgrenIf we get too many ifb devices legacy monitoring systems start to have issues16:06
klindgrenlike snmp polling finds a few thousand network devices16:06
klindgrenor it takes a long time for some other actions to run16:06
klindgreneitherway IIRC the code and the cronjob script our on our github16:07
*** kstev has joined #openstack-operators16:07
klindgrenhttps://github.com/godaddy/openstack-traffic-shaping16:08
*** Guest90313 has quit IRC16:09
*** Oku_OS is now known as Oku_OS-away16:10
*** kstev has quit IRC16:11
*** kstev has joined #openstack-operators16:22
*** uxdanielle has joined #openstack-operators16:33
mnaserklindgren cant you shape traffic directly with a libvirt feature?16:35
*** simon-AS559 has joined #openstack-operators16:35
mnaserlet me try to remember the flavor settings16:35
*** rmart04 has quit IRC16:36
klindgrenthats not shaping16:36
klindgrenthats policing16:36
mnaserooo16:37
mnaseryou're right16:37
klindgrentheir is a subtle but very important difference between policing and shaping.16:37
mnaseri thought there was extra spec keys for policing too16:37
*** cheetah has joined #openstack-operators16:39
*** makowals has quit IRC16:49
*** makowals has joined #openstack-operators16:50
mnaserwhile we're on the topic of networks16:53
mnaserhow has everyone dealt with large l2 domain if you arent using nat'd setups / more of a provider network setup16:53
*** makowals has quit IRC16:53
*** makowals has joined #openstack-operators16:54
*** makowals has quit IRC16:58
*** Miouge has quit IRC17:01
*** Miouge has joined #openstack-operators17:02
*** Miouge has quit IRC17:02
*** pilgrimstack has quit IRC17:04
*** matrohon has quit IRC17:13
*** Miouge has joined #openstack-operators17:15
*** paramite has quit IRC17:18
*** derekh has quit IRC17:24
*** mriedem has quit IRC17:29
Guest52285anyone running rundeck, ansible tower or any similar tool so one can trigger a task without having direct access to secrets or production network?17:33
*** Guest52285 is now known as mgagne17:33
*** mgagne has quit IRC17:33
*** mgagne has joined #openstack-operators17:33
mgagnewas me ^17:37
*** rmart04 has joined #openstack-operators17:43
logan-i've looked at rundeck a little bit but seemed like it was going to take quite a bit of work to get that all going17:44
logan-ansible-semaphore is another one i've heard of people using17:44
*** rmart04_ has joined #openstack-operators17:46
*** rmart04_ has quit IRC17:48
*** rmart04 has quit IRC17:48
*** Miouge has quit IRC18:00
*** dbecker has quit IRC18:04
*** Apoorva has joined #openstack-operators18:09
*** Miouge has joined #openstack-operators18:10
mgagneI tried ansible-semaphore once and I found it to be complex to setup and lacking "finishing". clearly not user friendly tbh.18:13
mgagnewe are currently using Jenkins to trigger those tasks, not the best tool and it comes (in our case) with a lot of legacy settings18:13
*** Miouge has quit IRC18:14
*** Miouge has joined #openstack-operators18:16
*** simon-AS559 has quit IRC18:21
*** slaweq_ has quit IRC18:22
*** slaweq has joined #openstack-operators18:24
*** slaweq has quit IRC18:31
*** uxdanielle has quit IRC18:31
*** slaweq has joined #openstack-operators18:33
mnaser mgagne what sort of tasks would these be?  why not just tap into openstack and implement api extensions if they are service oriented18:38
mnaserthats what we did for a while18:38
*** kstev1 has joined #openstack-operators18:38
mgagnemnaser: ansible playbook and bash scripts. I think I will go with a new Jenkins install without legacy junk and lock it down.18:39
mnaseri wonder if RH got around open sourcing tower18:40
mgagnenot yet afaik. we have been waiting for it for months. for me, it's time to move on for now and will revisit later.18:40
jlksoon...18:55
*** mriedem has joined #openstack-operators18:55
jlkbut not soon enough18:55
*** Miouge has quit IRC19:00
*** Miouge has joined #openstack-operators19:01
mgagneyea, I don't mind waiting if I know I can refactor a temp solution later19:07
*** Miouge has quit IRC19:08
*** Miouge has joined #openstack-operators19:09
*** Miouge has quit IRC19:13
*** Miouge has joined #openstack-operators19:22
jlkthe intent is definitely to opensource it.19:25
jlkat least from what I gather both public and private conversations19:25
*** Miouge has quit IRC19:27
*** zul has quit IRC19:30
*** Miouge has joined #openstack-operators19:38
*** Miouge has quit IRC19:42
*** Miouge has joined #openstack-operators19:47
*** zul has joined #openstack-operators19:49
*** cheetah has quit IRC19:53
*** twiggy has quit IRC19:58
*** electrofelix has quit IRC20:05
*** Miouge has quit IRC20:19
*** piet has joined #openstack-operators20:19
*** Miouge has joined #openstack-operators20:33
*** chlong has quit IRC20:53
dmsimardmgagne: I've recently used git-crypt and was pleasantly surprised about it -- perhaps that with a combination of the ansible no_log parameter ?20:55
*** dminer has quit IRC20:56
*** twiggy has joined #openstack-operators20:57
dmsimardex: https://github.com/CentOS/centos-cloud/commit/ad7a646a6489bead9d4dcfc48f05b21d596ae3cc && https://github.com/CentOS/centos-cloud/commit/c0ece0c5b58f0780023a138d545268a61e629e3420:57
mgagnedmsimard: the end user would still have to get network access to the deployed infra (if using ansible)20:59
dmsimardcan wrap it inside jenkins, using a gpg deploy key stored as a jenkins credential binding (for example)21:00
dmsimardprobably needs some hacking (i.e, passing the gpg key passphrase) but maybe it'd work, I don't know.21:02
*** fragatina has quit IRC21:11
*** Miouge has quit IRC21:18
*** Miouge has joined #openstack-operators21:23
*** catintheroof has joined #openstack-operators21:31
*** Miouge has quit IRC21:32
*** fragatina has joined #openstack-operators21:41
catintheroofHi ! quick question, talking about how to do ha on openstack with pacemaker, if i have database on host1, host2 & host 3 but i have keystone on host4, host5 & host6, what is the right way on a single cluster of pacemaker, to tell that mysql resource should only happen on db hosts and keystone resource only occurs on keystone servers ? so that i can then define the orders ? i mean, what is the right way because when i clo21:41
catintheroofne a resource, it happens everywhere and then i have to "ban" hosts for those resources not to happen there.21:41
*** twiggy has quit IRC21:51
klindgrenmgagne, I looked at rundeck22:05
klindgrenbut quickly scrapped it when I found I couldnt do something as simple as pass variables between 2 work flow actions22:05
klindgrenWe are actively looking at stackstorm22:06
*** kstev has quit IRC22:08
*** jamesdenton has quit IRC22:26
*** ckonstanski has quit IRC22:38
*** slaweq has quit IRC22:43
*** ducttape_ has quit IRC22:43
*** ducttape_ has joined #openstack-operators23:45
*** fragatin_ has joined #openstack-operators23:50
*** ducttape_ has quit IRC23:53
*** fragatina has quit IRC23:53

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!