seongsoocho | After upgrade from ocata to train, there are some trouble with object-replicator. The sync method failed when the suffixes variable set to empty. https://github.com/openstack/swift/blob/stable/train/swift/obj/replicator.py#L685 . I'm not sure why this happens. Have you ever had a similar experience? | 01:11 |
---|---|---|
*** gyee has quit IRC | 02:10 | |
openstackgerrit | Tim Burke proposed openstack/swift master: py3: Fix up probe tests https://review.opendev.org/705578 | 03:26 |
openstackgerrit | Tim Burke proposed openstack/swift master: probe tests: Work when fronted by a TLS terminator https://review.opendev.org/705579 | 03:26 |
openstackgerrit | Tim Burke proposed openstack/swift master: WIP: run probe tests on CentOS 8 https://review.opendev.org/690717 | 05:29 |
*** evrardjp has quit IRC | 05:33 | |
*** evrardjp has joined #openstack-swift | 05:34 | |
openstackgerrit | Tim Burke proposed openstack/swift master: WIP: run probe tests on CentOS 8 https://review.opendev.org/690717 | 05:50 |
manuvakery | clayg: seongsoocho i renamed the .lock dir to .lock_tmp and the replicator took care of the rest. Thanks for the help | 05:58 |
timburke | manuvakery, did you spot-check some of the .data files in the moved directory to see that they were really present in the other locations? | 06:04 |
manuvakery | timburke: no didn't spot check it. just verified the partition has filled with some data after the next replication pass | 06:18 |
manuvakery | timburke: /srv/node/disk5/objects/210847/.lock_tmp/3ff/a35ecc1c99345924233861cf1b1533ff/1575652643.51670.data this is one of the data file present in the .lock directory .. How can i check if the same data present in another location using any swift tools? | 06:47 |
*** mugsie has quit IRC | 07:37 | |
manuvakery | timburke: yes i verified that the same data is available in another locations, all 3 copies are present under partition 167291 | 07:38 |
*** mugsie has joined #openstack-swift | 07:41 | |
*** evrardjp has quit IRC | 07:46 | |
*** evrardjp has joined #openstack-swift | 07:50 | |
*** rdejoux has joined #openstack-swift | 08:11 | |
*** tkajinam has quit IRC | 08:17 | |
*** tesseract has joined #openstack-swift | 08:27 | |
*** rpittau|afk is now known as rpittau | 08:33 | |
*** mikecmpbll has joined #openstack-swift | 09:03 | |
*** hoonetorg has quit IRC | 09:06 | |
*** hoonetorg has joined #openstack-swift | 09:18 | |
openstackgerrit | Merged openstack/swift master: added value and notes to a sample config file for s3token https://review.opendev.org/625082 | 10:18 |
*** odyssey4me has joined #openstack-swift | 11:10 | |
odyssey4me | hey folks, I need some help understanding how to use swift container ACLs properly - I tried applying https://docs.openstack.org/swift/latest/overview_acl.html#example-public-container to a container, but when trying to list containers using alternative credentials I get an auth failure | 11:11 |
odyssey4me | apologies - not an auth failure, a 403 forbidden failure | 11:11 |
* odyssey4me waves at mattoliverau :) | 11:13 | |
*** hoonetorg has quit IRC | 11:14 | |
*** rdejoux has quit IRC | 11:14 | |
*** mugsie has quit IRC | 11:14 | |
*** irclogbot_3 has quit IRC | 11:14 | |
*** zaitcev has quit IRC | 11:14 | |
*** abelur has quit IRC | 11:14 | |
*** aluria has quit IRC | 11:14 | |
*** godog has quit IRC | 11:14 | |
*** Anticimex has quit IRC | 11:14 | |
*** viks___ has quit IRC | 11:14 | |
*** Jeffrey4l has quit IRC | 11:14 | |
*** StevenK has quit IRC | 11:14 | |
*** mvkr has quit IRC | 11:14 | |
*** cjloader has quit IRC | 11:14 | |
*** pawan-gupta has quit IRC | 11:14 | |
*** cwright has quit IRC | 11:14 | |
*** szaher has quit IRC | 11:14 | |
*** ab-a has quit IRC | 11:14 | |
*** donnyd has quit IRC | 11:14 | |
*** fyx has quit IRC | 11:14 | |
*** sorrison has quit IRC | 11:14 | |
*** openstackstatus has quit IRC | 11:16 | |
*** mikecmpbll has quit IRC | 11:17 | |
*** irclogbot_2 has joined #openstack-swift | 11:17 | |
*** godog has joined #openstack-swift | 11:17 | |
*** Anticimex has joined #openstack-swift | 11:17 | |
*** mahatic has quit IRC | 11:18 | |
*** kota_ has quit IRC | 11:18 | |
*** rickflare has quit IRC | 11:18 | |
*** dcourtoi has quit IRC | 11:18 | |
*** timburke has quit IRC | 11:18 | |
*** tristanC has quit IRC | 11:18 | |
*** mathiasb has quit IRC | 11:18 | |
*** hoonetorg has joined #openstack-swift | 11:18 | |
*** rdejoux has joined #openstack-swift | 11:18 | |
*** mugsie has joined #openstack-swift | 11:18 | |
*** zaitcev has joined #openstack-swift | 11:18 | |
*** abelur has joined #openstack-swift | 11:18 | |
*** orwell.freenode.net sets mode: +v zaitcev | 11:18 | |
*** aluria has joined #openstack-swift | 11:18 | |
*** viks___ has joined #openstack-swift | 11:19 | |
*** Jeffrey4l has joined #openstack-swift | 11:19 | |
*** StevenK has joined #openstack-swift | 11:19 | |
*** mvkr has joined #openstack-swift | 11:19 | |
*** cjloader has joined #openstack-swift | 11:19 | |
*** pawan-gupta has joined #openstack-swift | 11:19 | |
*** cwright has joined #openstack-swift | 11:19 | |
*** szaher has joined #openstack-swift | 11:19 | |
*** fyx has joined #openstack-swift | 11:19 | |
*** ab-a has joined #openstack-swift | 11:19 | |
*** donnyd has joined #openstack-swift | 11:19 | |
*** sorrison has joined #openstack-swift | 11:19 | |
*** timburke has joined #openstack-swift | 11:20 | |
*** ChanServ sets mode: +v timburke | 11:21 | |
*** kota_ has joined #openstack-swift | 11:21 | |
*** ChanServ sets mode: +v kota_ | 11:21 | |
*** donnyd has quit IRC | 11:21 | |
*** tesseract has quit IRC | 11:22 | |
*** abelur has quit IRC | 11:23 | |
*** tristanC has joined #openstack-swift | 11:23 | |
*** donnyd has joined #openstack-swift | 11:23 | |
*** mikecmpbll has joined #openstack-swift | 11:24 | |
*** abelur has joined #openstack-swift | 11:24 | |
*** tesseract has joined #openstack-swift | 11:24 | |
*** tesseract has quit IRC | 11:56 | |
*** jvisser has quit IRC | 12:07 | |
*** tesseract has joined #openstack-swift | 12:26 | |
*** tesseract has quit IRC | 12:29 | |
*** tesseract has joined #openstack-swift | 12:31 | |
*** tesseract has quit IRC | 12:37 | |
*** tesseract has joined #openstack-swift | 12:38 | |
*** tesseract has quit IRC | 12:40 | |
*** tesseract has joined #openstack-swift | 12:40 | |
clayg | odyssey4me: what tools are you using to set and check acls? | 12:45 |
clayg | Can you try with python-swift client CLI to verify and we’ll debit from there? | 12:46 |
clayg | Err... Debug | 12:46 |
odyssey4me | clayg: I just managed to get it all worked out. The issue I had was that I wasn't providing the storage url from the sharing user. Now that's correct, it's working as expected. | 12:50 |
*** tesseract has quit IRC | 12:50 | |
manuvakery | clayg: i am trying to play with s3API acls. I have tried to set the bucket acl to public-read with the command "aws s3api put-bucket-acl --bucket manu-test-acls-2 --acl public-read " | 12:51 |
manuvakery | when i try to get the bucket-acl i can see the proper grants | 12:52 |
manuvakery | https://www.irccloud.com/pastebin/2NKp7yY2/ | 12:52 |
manuvakery | now how can i access an object in the bucket via s3 API without the ec2 creds . as far as i know s3api derive the account name from the ec2 creds .. little confused here 🙄 | 12:54 |
*** odyssey4me has left #openstack-swift | 12:58 | |
*** tesseract has joined #openstack-swift | 13:03 | |
clayg | Yup, public bucket in s3api is a bit difficult. Kota or timburke might have some ideas. | 13:03 |
*** tesseract has quit IRC | 13:07 | |
*** tesseract has joined #openstack-swift | 13:15 | |
*** jvisser has joined #openstack-swift | 13:26 | |
*** tkajinam has joined #openstack-swift | 13:34 | |
*** pcaruana has quit IRC | 13:43 | |
*** tkajinam has quit IRC | 14:32 | |
*** pcaruana has joined #openstack-swift | 14:56 | |
*** mpasserini has joined #openstack-swift | 15:29 | |
*** mpasserini has left #openstack-swift | 15:30 | |
*** gyee has joined #openstack-swift | 16:17 | |
*** mikecmpbll has quit IRC | 16:26 | |
*** mikecmpbll has joined #openstack-swift | 16:31 | |
timburke | good morning | 16:39 |
manuvakery | @timburke: any ideas on public bucket in s3api | 17:03 |
*** rdejoux has quit IRC | 17:03 | |
*** tesseract has quit IRC | 17:04 | |
*** rpittau is now known as rpittau|afk | 17:27 | |
*** evrardjp has quit IRC | 17:33 | |
*** evrardjp has joined #openstack-swift | 17:34 | |
*** mikecmpbll has quit IRC | 17:38 | |
*** gyee has quit IRC | 19:00 | |
*** godog has quit IRC | 19:00 | |
*** Anticimex has quit IRC | 19:00 | |
*** gyee has joined #openstack-swift | 19:02 | |
*** godog has joined #openstack-swift | 19:02 | |
*** Anticimex has joined #openstack-swift | 19:02 | |
*** mcape has joined #openstack-swift | 20:22 | |
mcape | Hello, do you think I can downgrade account/container servers without risk of losing data? Want to go from Train to Rocky, hit strange problems with s3 signatures | 20:23 |
mcape | I've set location = US as advised in Release doc, and some clients are OK with it, but some clients are not. I'm seeing a lot of unsuccessful requests to http://controller:35357/v3/s3tokens when my upgraded proxy is up along with old Rocky proxies | 20:25 |
mcape | I have sharding enabled. | 20:25 |
clayg | yikes, that a big jump backwards - *I* wouldn't want to downgrade if I could avoid it, we make hardly any effort to test downgrades even from N to N-1 | 20:38 |
clayg | maybe you could downgrade a small set of proxies that are only exposed to the effected clients assuming that would be easier/quicker than diagnosing the actual problem | 20:40 |
clayg | mcape: what kind of "unsuccessful requests" are you seeing | 20:41 |
mcape | i start to see a lot of | 20:45 |
mcape | 2020-02-04 19:01:06.338 29458 INFO keystone.common.wsgi [req-bae4dcd1-8748-47f2-9173-1db0004ba436 - - - - -] POST http://172.30.3.202:35357/v3/s3tokens | 20:45 |
mcape | 2020-02-04 19:01:06.344 29458 WARNING keystone.common.wsgi [req-bae4dcd1-8748-47f2-9173-1db0004ba436 - - - - -] Authorization failed. The request you have made requires authentication. from 172.31.3.6: Unauthorized: The request you have made requires authentication. | 20:45 |
mcape | what is strange, that it is Rocky proxies that start to produce a lot of such errors | 20:46 |
mcape | in case of Train proxy present in load balancer | 20:46 |
mcape | the process behind is s3cmd clients trying to sync directories with Swift via s3api | 20:47 |
mcape | if I disable Train proxies, I still see auth errors, but they don't flood up Keystone | 20:49 |
mcape | so this request fails | 20:50 |
mcape | DEBUG: Sending request method_string='GET', uri=u'/logs-prod/?location', | 20:50 |
mcape | but that is probably relevant to functioning of s3cmd on client side | 20:52 |
mcape | the gist is in "normal mode" part of s3cmd requests are failing, but it manages to finish sync | 20:52 |
mcape | but with Train proxy, it does not | 20:53 |
mcape | i have 4 proxies, two are upgraded, two are not | 20:53 |
mcape | maybe i can just add two new Rocky proxies (along with account/container servers), wait for replication, and then delete Rocky ones? | 20:54 |
mcape | How s3 request is being processed? The request goes to proxy, which asks Keystone, which replies with ACK/DENY? Or there are more checks? | 21:02 |
*** mcape has quit IRC | 21:41 | |
*** mcape has joined #openstack-swift | 21:42 | |
*** rdejoux has joined #openstack-swift | 21:50 | |
*** jvisser has quit IRC | 21:52 | |
*** rdejoux has quit IRC | 21:54 | |
*** rdejoux has joined #openstack-swift | 21:55 | |
mattoliverau | morning | 21:56 |
mattoliverau | odyssey4me: o/ sorry I missed ya, but glad you worked it out | 21:57 |
*** rdejoux has quit IRC | 22:00 | |
*** jvisser has joined #openstack-swift | 22:05 | |
*** UnfairFunction has joined #openstack-swift | 23:03 | |
*** jvisser has quit IRC | 23:08 | |
*** tkajinam has joined #openstack-swift | 23:09 | |
*** UnfairFunction has quit IRC | 23:24 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!