Sunday, 2011-01-09

vishyxenith: yes and yes00:03
*** miclorb has joined #openstack00:11
*** MarkAtwood has quit IRC00:25
*** rogue780 has joined #openstack00:28
*** MarkAtwood has joined #openstack00:40
*** miclorb has quit IRC00:45
*** rogue780 has quit IRC00:49
*** rogue780 has joined #openstack00:57
Xenithvishy: Great, just wanted to make sure.01:07
*** rogue780 has quit IRC01:09
*** jfluhmann__ has joined #openstack01:19
*** jfluhmann has quit IRC01:23
*** rogue780 has joined #openstack01:29
uvirtbotNew bug: #700530 in nova "Doc make broken by rev530 nova version change " [Undecided,New]
*** zul has quit IRC01:38
*** jimbaker has joined #openstack01:43
*** trin_cz has quit IRC02:01
*** leted has quit IRC02:06
*** rogue780 has quit IRC02:08
*** opengeard has joined #openstack02:13
*** leted has joined #openstack02:13
*** rogue780 has joined #openstack02:23
*** Xenith has quit IRC02:33
*** Xenith has joined #openstack02:34
*** reldan has quit IRC03:10
*** rogue780 has quit IRC03:40
*** leted has quit IRC04:11
*** dovetaildan has quit IRC04:20
*** dovetaildan has joined #openstack04:23
*** joearnold has joined #openstack04:26
*** reldan has joined #openstack04:27
*** reldan has quit IRC04:30
*** joearnold has quit IRC04:30
*** jimbaker has quit IRC04:35
*** joearnold has joined #openstack04:47
*** joearnold has quit IRC04:52
*** arcane has joined #openstack05:06
*** joearnold has joined #openstack05:08
*** rchavik has joined #openstack06:23
*** ksteward has quit IRC06:36
*** ksteward has joined #openstack06:51
*** Abd4llA has joined #openstack07:06
*** Abd4llA1 has joined #openstack07:27
*** Abd4llA has quit IRC07:30
*** Abd4llA1 is now known as Abd4llA07:35
*** joearnold has quit IRC07:38
*** allsystemsarego has joined #openstack07:51
*** allsystemsarego has joined #openstack07:51
*** leted has joined #openstack08:56
*** reldan has joined #openstack09:49
*** rchavik has quit IRC10:02
*** miclorb has joined #openstack10:11
*** reldan has quit IRC10:22
*** reldan has joined #openstack10:27
*** miclorb has quit IRC10:28
*** leted has quit IRC10:29
*** reldan has quit IRC10:29
*** reldan has joined #openstack10:30
*** anotherjesse has quit IRC10:31
*** anotherjesse has joined #openstack10:31
*** hky has joined #openstack10:35
*** reldan has quit IRC10:35
*** Abd4llA has quit IRC10:47
*** reldan has joined #openstack10:48
*** reldan has quit IRC10:52
*** Abd4llA has joined #openstack10:59
*** jfluhmann__ has quit IRC11:09
*** cw has quit IRC11:09
*** jfluhmann_ has quit IRC11:09
*** filler has quit IRC11:09
*** jeremyb has quit IRC11:09
*** glenc_ has quit IRC11:09
*** lool has quit IRC11:09
*** chmouel has quit IRC11:09
*** antonym has quit IRC11:09
*** taihen has quit IRC11:09
*** glenc_ has joined #openstack11:11
*** lool has joined #openstack11:11
*** chmouel has joined #openstack11:11
*** antonym has joined #openstack11:11
*** taihen has joined #openstack11:11
*** sets mode: +v antonym11:11
*** jfluhmann__ has joined #openstack11:11
*** cw has joined #openstack11:11
*** jfluhmann_ has joined #openstack11:11
*** filler has joined #openstack11:11
*** jeremyb has joined #openstack11:11
*** adiantum has joined #openstack11:45
*** Abd4llA has quit IRC12:06
*** fabiand_ has joined #openstack12:43
*** trin_cz has joined #openstack12:50
*** fabiand_ has quit IRC12:57
*** jfluhmann has joined #openstack13:21
*** jfluhmann__ has quit IRC13:23
*** charlvn has joined #openstack14:40
*** bhulver has joined #openstack14:46
*** bhulver has left #openstack14:48
*** bhulver has joined #openstack14:52
*** burris has quit IRC16:02
*** michaeldreamhost has quit IRC16:08
*** burris has joined #openstack16:08
*** dendrobates is now known as dendro-afk16:24
*** dendro-afk is now known as dendrobates16:31
*** skrusty has quit IRC16:53
*** skrusty has joined #openstack17:06
*** dendrobates is now known as dendro-afk17:10
*** adiantum has quit IRC17:28
*** dendro-afk is now known as dendrobates17:46
*** rogue780 has joined #openstack17:57
*** fabiand_ has joined #openstack17:57
*** fabiand_ has quit IRC18:03
*** fabiand_ has joined #openstack18:04
*** bhulver has quit IRC18:04
*** dendrobates is now known as dendro-afk18:04
*** joearnold has joined #openstack18:19
*** hggdh has quit IRC18:46
*** joearnold has quit IRC19:07
*** dendro-afk is now known as dendrobates19:10
*** cruciform has quit IRC19:20
*** Abd4llA has joined #openstack19:34
*** dendrobates is now known as dendro-afk19:36
*** leted has joined #openstack19:38
*** WonTu has joined #openstack19:39
*** WonTu has left #openstack19:39
*** leted has quit IRC20:01
*** rdw has quit IRC20:03
*** rdw has joined #openstack20:04
*** leted has joined #openstack20:04
*** rogue780 has quit IRC20:10
*** rogue780 has joined #openstack20:11
*** hggdh has joined #openstack20:12
*** jt_zg has joined #openstack20:18
jt_zghey all20:18
openstackhudsonYippie, build fixed!20:19
openstackhudsonProject nova build #372: FIXED in 1 min 19 sec:
jt_zgWhat would cause me to get the following error message, "Update failed: 503 Service Unavailable" when running "swift-auth-add-user -K devauth -a system root testpass" (with the proper values subbed in)?20:20
jt_zgI've checked that all my IPs are right and file-permissions correct20:20
*** dovetaildan has quit IRC20:41
*** dovetaildan has joined #openstack20:44
*** dovetaildan has quit IRC20:51
*** leted has quit IRC20:52
*** dovetaildan has joined #openstack20:53
*** opengeard has quit IRC20:58
*** damon__ has joined #openstack20:59
notmynamejt_zg: check syslog (or wherever you have logs going, if you customized it)21:05
*** rogue780 has quit IRC21:05
jt_zgnotmyname, Here is my output:
notmynameso it looks like the error is not in the auth-server but in the account server. grep for account-server instead21:06
jt_zgPerhaps I'm mixing the terms up? Is the account server not relegated to reside on the auth server?21:07
notmynameare you running the saio or a multi-machne setup?21:08
jt_zggrepping for account-server produced nothing on the auth server syslog21:08
notmynameok. can you describe your cluster?21:09
jt_zgSure, I have 5 storage servers, 1 auth server, 1 proxy server as per the instructions at
notmynameand the more general answer is that no, the account servers don't have to live on the auth server (or vice versa)21:10
jt_zgGotcha, good to knw21:10
notmynameis that 6 separate machines?21:10
jt_zgAnd yup, all separate...that was fun to setup :S21:10
notmynameerr, ya. math fail21:10
jt_zghaha, no judgement21:11
notmynameso the storage servers are running the account, container, and object servers?21:11
jt_zgyes sir21:11
notmynamefrom your paste, check the logs on
jt_zgfor account-server?21:12
notmynameis that a storage node or your proxy?21:12
notmynamegrep for proxy-server21:13
notmynameand you have allow_account_management = true set in the proxy config?21:13
jt_zgand proxy-server yielded nothing of concern. I can pastebin it if you'd like21:14
notmynameya, I would guess that would give a 400 error not 50021:14
notmynameya, that's rather boring21:14
notmynamebut it seems that you have no connections received there21:15
notmynameif you make a request to the proxy do you get a 404 with somethng in the logs?21:15
jt_zgI'm wondering if its a mix up between me using internal and external IPs int he wrong place? I used the proxy's internal IP for the auth servers configs21:15
notmynameif the auth server can access it, should be no problem21:16
jt_zghost ext-IP int-IP21:17
notmynamemake a request to the proxy21:17
notmynamecurl -i
jt_zgusing this string: swift-auth-add-user -K *mysecretkey* -a system root *myrootpass*  ?21:18
jt_zgcouldn't connect to host21:18
jt_zgused internal and external IP with curl21:19
notmynameso that's the first place to look21:19
notmynameadd :808021:19
notmynameif that's what you're running for the proxy21:19
notmynameanything in the proxy logs?21:20
jt_zgnothing new/different21:20
notmynameare you using ssl or not?21:21
jt_zgI am21:21
notmynameok, htn https21:21
notmynamecurl -i
notmynameperhaps with the -k if needed21:21
jt_zgsorry about that21:21
*** miclorb has joined #openstack21:22
jt_zgroot@auth:/etc/swift# curl -i -k
jt_zgHTTP/1.1 200 OK21:22
jt_zgContent-Type: text/plain; charset=UTF-821:22
jt_zgContent-Length: 221:22
jt_zgDate: Sun, 09 Jan 2011 21:22:33 GMT21:22
jt_zginternal and external both work21:23
notmynamenow, if you do something like "curl -i -k" you should get a 40421:23
jt_zg404 is in the proxy syslogs too21:24
notmynamealso, you can add log_level = DEBUG to /etc/swift/proxy-server.conf under the [app:proxy-server] section21:24
notmynameare you running those commands from the auth server?21:24
jt_zgThose last few? Yup21:25
jt_zgadded the debug option21:25
notmynamegood. that means there is no network issues between the servers. one less thing to worry about21:25
notmynamerestart the proxy to make sure the config is updated21:25
notmynameyou can add the log_level option to the auth server too21:26
jt_zgdone and restarted21:27
notmynameok, rerun the add user command and see what happens in the logs21:27
jt_zg403 error returned, no syslog update on proxy server21:28
notmyname403? can you paste it? last time it was 50321:28
jt_zgUpdate failed: 403 Forbidden21:28
jt_zgyup, last time was a 50321:28
jt_zgIts a 503 again. The add user command I used was incorrect. Giving me 503's again21:33
notmynameand no change in the auth server logs?21:35
jt_zg most recent /var/log/syslog on auth server21:36
*** reldan has joined #openstack21:40
jt_zgAppreciate it :D21:40
jt_zgAlmost tempted to rebuild the auth and proxy servers to rule out any sloppy configs I may have setup :S21:41
notmynamegive me a moment21:48
*** reldan has quit IRC21:49
*** reldan has joined #openstack21:52
notmynamei see a 503 on my saio, so something is similar in our configs. I haven't looked at this part in a while, so I'm trying to figure out why I can't add accounts either21:52
jt_zgI really appreciate the effort. I literally only made my first efforts in using/testing Openstack last night so I'm a little lost21:53
jt_zgWhat is saio anyways?21:54
notmynameswift all in one21:55
jt_zggotcha. So, basically a just more compressed setup?21:55
notmynamenot really, just all running on one VM or one machine21:55
jt_zgthats pretty cool21:56
*** reldan has quit IRC21:57
notmynameok, I got mine to work22:01
jt_zgHow did you pull that off?22:01
notmynameI had to change the default_storage_url in auth-server.conf22:02
notmynameit may not be related to your setup. let me check one more thing22:02
*** reldan has joined #openstack22:03
notmynamein your proxy conf, what's in the pipeline?22:04
jt_zgpipeline = healthcheck cache auth proxy-server22:04
notmynameya, ok. different issue. I was running some additional middleware that didn't like my mismatch of default_storage_url in auth-server.conf and in the middleware for the proxy-server (the middleware is the cname and domain remap ones--not really important here)22:05
*** rlucio has joined #openstack22:05
*** fabiand_ has quit IRC22:06
jt_zghmm, I wonder what is causing this then22:07
*** reldan has quit IRC22:07
*** dendro-afk is now known as dendrobates22:07
notmynameso you've checked permissions on /etc/swift/auth.db22:07
jt_zgyup, its set to swift and I restarted22:08
notmynameand you have user=swift everywhere (like in auth-server.conf)22:08
*** joearnold has joined #openstack22:09
notmynamesince you can talk to the proxy from the auth server (our previous curl commands), I suspect that it is related to passwords or permissions somewhere22:12
jt_zgI thought so too22:13
jt_zgCould this string be the problem:22:13
jt_zgswift-auth-add-user -K devauth -a system root testpass22:13
jt_zgI sub in my key for devauth and testpass for my root users password22:13
notmyname"devauth" is the only key there22:13
jt_zgso I don't sub my pass into testpass?22:14
notmynamethe system/root/password have nothing to do with anything outside of swift22:14
notmynameso you can use test tester testing or jt_zg jt_zg hunter222:15
jt_zgI tried again with swift-auth-add-user -K *MYKEY*  -a system root testpass  - still getting 50322:15
notmynameit will be what you use to get an auth token before you make authenticated requests to the proxy server22:15
notmynameand you are running that command as the system user swift?22:16 swift you mean?22:16
notmynameah. I think that's your problem22:16
notmynamewhat are the permissions on /ets/swift/auth.db?22:16
jt_zg-rw-r--r--  1 swift swift 9216 2011-01-09 17:14 auth.db22:17
notmynameif only the "swift" user can write to it, you need to run swift-auth-add-user as swift22:17
notmynameok, ya22:17
notmynameswift-auth-add-user does the work of updating the db and calling the proxy server to create the account in the storage cluster22:17
notmynameso sudo -u swift should fix everything22:18
jt_zgno swift user22:19
*** fabiand_ has joined #openstack22:19
notmynamebased on the permissions you have on auth.db there is :-)22:20
jt_zgyup, it exists. Just checked...22:20
jt_zgusing sudo -u swift just spits out the sudo usage instructions22:21
jt_zgok, I sorted out my confusion. 503 error22:22
notmynamejust for fun, chmod it to 666 and try again22:23
jt_zgthe auth.db?22:23
jt_zgno luck, 50322:24
notmynamestill using your key, not devauth in the -K flag, right?22:25
notmynameya, that wouldn't give a 50322:25
*** whaley has quit IRC22:26
jt_zgAt a loss. Curl is playing nicely but adding a user isn't22:26
jt_zgand I've checked my configs far too many times22:26
notmynameI think the issue is on your auth server somwhere22:27
jt_zg*nod* I think so too22:27
notmynamenothing weird like you have https in the cluster url but no certs defined?22:30
*** dragondm has joined #openstack22:30
jt_zgcerts are there22:30
notmynameyou are using IP addresses not hostnames? so no lookup issues22:31
jt_zgIPs only22:31
*** whaley has joined #openstack22:32
notmynameoh, if you got the user issues figured out, you should probably set the auth.db permissions back to 64422:34
jt_zgoh ya, thanks :P22:35
notmynameare you running the latest code or one of the 1.1 release?22:36
notmynames/one of//22:36
jt_zgmost recent22:36
*** dendrobates is now known as dendro-afk22:36
*** fabiand_ has quit IRC22:37
notmynamethe auth server is pretty basic. not much to mess up in the configs22:38
jt_zgcould it be the proxy server, not starting correctly?22:39
notmynameperhaps. do you see a "proxy-server started" line in syslog22:40
jt_zgYup, quite a few22:40
notmynamecan you paste your auth-server.conf? (obfuscate the admin key, if you want)22:41
notmynameand your proxy-server.conf?22:43
*** lionel has joined #openstack22:48
notmynamejt_zg: sorry. I've been a single parent for the last 4 days and my wife just got home. I'm out22:50
jt_zgI understand. Thanks for the help so far though22:50
*** dragondm has quit IRC23:02
*** allsystemsarego has quit IRC23:04
*** chilts has joined #openstack23:16
*** joearnold has quit IRC23:41

Generated by 2.14.0 by Marius Gedminas - find it at!