*** skyraven has quit IRC | 00:09 | |
*** arnoldoree has joined #openstack | 00:13 | |
*** arnoldoree has joined #openstack | 00:16 | |
*** gyee has quit IRC | 00:50 | |
*** rvd has joined #openstack | 00:54 | |
*** skyraven has joined #openstack | 02:05 | |
*** skyraven has quit IRC | 02:10 | |
*** tips has quit IRC | 02:11 | |
*** chenhaw has quit IRC | 02:15 | |
*** chenhaw has joined #openstack | 02:15 | |
*** skme9 has joined #openstack | 02:18 | |
*** rcernin has quit IRC | 02:50 | |
*** arnoldoree has quit IRC | 02:54 | |
*** rcernin has joined #openstack | 02:59 | |
*** josephillips has quit IRC | 03:19 | |
*** stac- has quit IRC | 03:32 | |
*** stac_ has joined #openstack | 03:33 | |
*** Euph0ria has quit IRC | 03:34 | |
*** arnoldoree has joined #openstack | 03:38 | |
*** user_19173783170 has joined #openstack | 03:46 | |
user_19173783170 | i want to ask some question, is someone online? | 03:46 |
---|---|---|
*** user_19173783170 has quit IRC | 03:47 | |
*** zbsarash1 has quit IRC | 03:53 | |
*** alexusono has quit IRC | 04:00 | |
*** alexusono has joined #openstack | 04:01 | |
*** skyraven has joined #openstack | 04:06 | |
*** skyraven has quit IRC | 04:12 | |
*** user_19173783170 has joined #openstack | 04:39 | |
*** def_jam has joined #openstack | 04:40 | |
user_19173783170 | i want to ask some question, is someone online? | 04:40 |
*** eb0t_ has joined #openstack | 04:40 | |
*** eb0t has quit IRC | 04:40 | |
*** eblip has quit IRC | 04:41 | |
user_19173783170 | 111 | 04:41 |
user_19173783170 | 222 | 04:41 |
user_19173783170 | hello | 04:41 |
*** user_19173783170 has left #openstack | 04:42 | |
*** servagem has quit IRC | 04:44 | |
*** pieguy128_ has joined #openstack | 04:52 | |
*** pieguy128 has quit IRC | 04:52 | |
*** bersace has quit IRC | 05:00 | |
*** matt_kosut has joined #openstack | 05:01 | |
*** bocaneri has joined #openstack | 05:11 | |
*** noogie has quit IRC | 05:13 | |
*** jtomasek has joined #openstack | 05:17 | |
*** noogie has joined #openstack | 05:21 | |
*** jtomasek has quit IRC | 05:22 | |
*** skyraven has joined #openstack | 05:36 | |
*** zbsarash1 has joined #openstack | 05:57 | |
*** cah_link has joined #openstack | 06:13 | |
*** ysastri has joined #openstack | 06:19 | |
*** qchris has quit IRC | 06:21 | |
*** ysastri has quit IRC | 06:23 | |
*** idlemind_ has joined #openstack | 06:25 | |
*** idlemind has quit IRC | 06:26 | |
*** imega has joined #openstack | 06:31 | |
*** qchris has joined #openstack | 06:33 | |
*** marc2 has quit IRC | 06:39 | |
*** alexusono has quit IRC | 06:41 | |
*** slaweq has joined #openstack | 06:44 | |
*** imega has quit IRC | 06:49 | |
*** aelshamouty has joined #openstack | 06:55 | |
*** benfelin has quit IRC | 06:57 | |
*** jtomasek has joined #openstack | 07:00 | |
*** benfelin has joined #openstack | 07:03 | |
*** zbsarash1 has quit IRC | 07:08 | |
*** bengates has joined #openstack | 07:15 | |
*** tesseract has joined #openstack | 07:17 | |
*** imega has joined #openstack | 07:24 | |
*** lkoranda has quit IRC | 07:36 | |
*** jcapitao has joined #openstack | 07:42 | |
*** sergiuw has quit IRC | 07:45 | |
*** sergiuw has joined #openstack | 07:45 | |
*** tesseract has quit IRC | 07:55 | |
*** tesseract has joined #openstack | 07:56 | |
*** skme9 has quit IRC | 07:56 | |
*** CeeMac has joined #openstack | 07:59 | |
*** shyamb has joined #openstack | 08:03 | |
*** shyam89 has joined #openstack | 08:13 | |
*** shyamb has quit IRC | 08:15 | |
*** skme9 has joined #openstack | 08:15 | |
*** jcapitao has quit IRC | 08:27 | |
*** rcernin has quit IRC | 08:35 | |
*** jcapitao has joined #openstack | 08:36 | |
*** imega has quit IRC | 08:37 | |
*** jcapitao has quit IRC | 08:41 | |
*** jcapitao has joined #openstack | 08:42 | |
*** jtomasek has quit IRC | 08:45 | |
*** slaweq has quit IRC | 08:46 | |
*** SecOpsNinja has joined #openstack | 08:48 | |
*** slaweq has joined #openstack | 08:49 | |
*** slaweq has quit IRC | 08:50 | |
*** aj_mailing has quit IRC | 08:54 | |
*** gmoro has joined #openstack | 08:55 | |
*** abdysn has joined #openstack | 08:59 | |
*** manuvakery has joined #openstack | 09:06 | |
*** shyam89 has quit IRC | 09:07 | |
*** vexorg has quit IRC | 09:24 | |
*** vexorg has joined #openstack | 09:27 | |
*** shyamb has joined #openstack | 09:29 | |
*** epheo has joined #openstack | 09:31 | |
*** skme9_ has joined #openstack | 09:38 | |
*** skme9 has quit IRC | 09:42 | |
*** pcaruana has quit IRC | 09:51 | |
*** imega has joined #openstack | 10:09 | |
*** cah_link has quit IRC | 10:17 | |
*** slaweq has joined #openstack | 10:20 | |
*** StevenK has quit IRC | 10:21 | |
*** sergiuw has quit IRC | 10:22 | |
*** Lucas_Gray has joined #openstack | 10:32 | |
*** rcernin has joined #openstack | 10:38 | |
*** malevolent_ has joined #openstack | 10:43 | |
*** shyamb has quit IRC | 10:44 | |
*** malevolent has quit IRC | 10:45 | |
*** shyamb has joined #openstack | 10:59 | |
*** StevenK_ has joined #openstack | 11:19 | |
*** jcapitao is now known as jcapitao_lunch | 11:21 | |
*** StevenK_ is now known as StevenK | 11:23 | |
*** omegapoint has joined #openstack | 11:24 | |
*** epheo has quit IRC | 11:24 | |
omegapoint | hey, i have a pretty odd question regarding neutron. We have an openstack deployment (neutron l3 + ml2 with linuxbridge for network) purely for testing MQTT software, which means we have many TCP connections that are established quickly and stay open for longer periods of time. therefore, we often run into conntrack issues. this telco WG request has been largely inactive https://bugs.launchpad.net/neutron/+bu | 11:27 |
omegapoint | g/1506076 so i'm wondering: would it be possible to simply disable conntrack for all my compute nodes entirely with a single iptables rule or something? we don't require any real filtering / security because everything runs in a private network anyway. | 11:27 |
omegapoint | i have tried tweaking conntrack hashtable & hash sizes and we also disable port security in the test deployments but no matter what we have a hard limit on connections we can establish per second and keep open and conntrack seems to be the culprit from the host metrics. | 11:28 |
*** shyamb has quit IRC | 11:43 | |
*** shyamb has joined #openstack | 11:43 | |
*** aelshamouty has quit IRC | 11:47 | |
*** shyamb has quit IRC | 11:52 | |
*** servagem has joined #openstack | 11:56 | |
DHE | omegapoint: from a purely linux standpoint if conntrack is loaded then everything gets tracked. rules to not make use of the data doesn't change that | 12:01 |
*** sergiuw has joined #openstack | 12:03 | |
*** tesseract has quit IRC | 12:03 | |
omegapoint | DHE: alright then, would our setup work without loading the conntrack module at all? from my understanding other setups like ones that use ovs rely on conntrack to work at all, but i'm not sure if the l3+ linuxbridge setup requires conntrack in any way | 12:04 |
DHE | L3 agent hosts (routers) need it because NAT doesn't work at all without conntrack | 12:05 |
*** arxcruz|ruck is now known as arxcruz|pto | 12:05 | |
DHE | I honestly don't know how dedicated compute nodes would react to not having conntrack. it's rather necessary for security groups to work | 12:05 |
*** tesseract has joined #openstack | 12:05 | |
omegapoint | alright that makes sense, so we have to keep it on infra nodes; well we don't use security groups at all anyway (no port security) so i guess i could give it a try at least | 12:07 |
omegapoint | i'm curious to know how calico can selectively disable conntrack and get a performance gain out of it though ( https://www.projectcalico.org/when-linux-conntrack-is-no-longer-your-friend/ ) | 12:08 |
DHE | it can be disabled with iptables. there are two chains listed when you run `iptables -t raw -L` and you can insert a `-j NOTRACK` rule into these. packets matching will not be processed by conntrack. note that you would have to get both directions to be effective | 12:13 |
DHE | also note that a cursory look at neutron source does suggest it may insert its own rules so I don't know how well this will scale. and manual rule insertion does rather defeat the point of VM automation | 12:14 |
*** jcapitao_lunch is now known as jcapitao | 12:16 | |
*** Euph0ria has joined #openstack | 12:17 | |
*** ccha has joined #openstack | 12:22 | |
*** imega has quit IRC | 12:30 | |
*** jangutter_ has joined #openstack | 12:36 | |
*** jangutter has quit IRC | 12:39 | |
*** imega has joined #openstack | 12:42 | |
*** imega has quit IRC | 12:51 | |
*** imega has joined #openstack | 12:51 | |
*** imega has quit IRC | 13:15 | |
*** cgfbee has quit IRC | 13:16 | |
*** jangutter has joined #openstack | 13:22 | |
*** cgfbee has joined #openstack | 13:23 | |
*** jangutter_ has quit IRC | 13:25 | |
*** Goneri has joined #openstack | 13:26 | |
*** tips has joined #openstack | 13:30 | |
*** jangutter_ has joined #openstack | 13:31 | |
*** jangutter has quit IRC | 13:34 | |
*** jangutte_ has joined #openstack | 13:34 | |
*** imega has joined #openstack | 13:35 | |
*** belmoreira has quit IRC | 13:36 | |
*** jangutter_ has quit IRC | 13:37 | |
*** zbsarash1 has joined #openstack | 14:05 | |
*** Euph0ria has quit IRC | 14:18 | |
*** Euph0ria has joined #openstack | 14:22 | |
*** jtomasek has joined #openstack | 14:23 | |
*** morazi_ has quit IRC | 14:58 | |
*** jangutter has joined #openstack | 15:02 | |
*** jangutter has quit IRC | 15:03 | |
*** Euph0ria has quit IRC | 15:03 | |
*** Euph0ria has joined #openstack | 15:03 | |
*** morazi has joined #openstack | 15:03 | |
*** jangutter has joined #openstack | 15:03 | |
*** jangutte_ has quit IRC | 15:05 | |
*** random_yanek has quit IRC | 15:14 | |
*** vultaire has joined #openstack | 15:15 | |
*** __ministry1 has joined #openstack | 15:15 | |
*** __ministry1 has quit IRC | 15:16 | |
*** random_yanek has joined #openstack | 15:21 | |
*** jangutter_ has joined #openstack | 15:30 | |
*** jangutter has quit IRC | 15:33 | |
*** arnoldoree has quit IRC | 15:34 | |
*** rcernin has quit IRC | 15:50 | |
*** Lucas_Gray has quit IRC | 15:52 | |
*** bengates has quit IRC | 15:58 | |
*** spiral has joined #openstack | 16:14 | |
*** jcapitao has quit IRC | 16:16 | |
*** jadonn has quit IRC | 16:19 | |
*** hamalq has joined #openstack | 16:32 | |
*** sergiuw has quit IRC | 16:38 | |
*** abdysn has quit IRC | 16:38 | |
*** imega has quit IRC | 16:42 | |
*** cp- has quit IRC | 16:52 | |
*** cp- has joined #openstack | 16:57 | |
*** gyee has joined #openstack | 17:03 | |
*** SecOpsNinja has left #openstack | 17:09 | |
*** errantekarmico has joined #openstack | 17:13 | |
*** tonyb has quit IRC | 17:15 | |
*** errantekarmico has quit IRC | 17:18 | |
*** skme9_ has quit IRC | 17:31 | |
*** tesseract has quit IRC | 17:31 | |
*** skme9_ has joined #openstack | 17:31 | |
*** skatsaounis has joined #openstack | 17:33 | |
*** skatsaounis has quit IRC | 17:33 | |
*** Lucas_Gray has joined #openstack | 17:42 | |
*** tonyb has joined #openstack | 17:57 | |
*** skme9_ has quit IRC | 18:05 | |
*** manuvakery has quit IRC | 18:05 | |
*** skme9_ has joined #openstack | 18:08 | |
*** omegapoint has quit IRC | 18:09 | |
*** gmann is now known as gmann_afk | 18:11 | |
*** skme9_ has quit IRC | 18:25 | |
*** errantekarmico has joined #openstack | 18:46 | |
*** mikecmpbll has quit IRC | 18:59 | |
*** marc2 has joined #openstack | 19:15 | |
*** sergiuw has joined #openstack | 19:19 | |
*** hamalq_ has joined #openstack | 19:23 | |
*** hamalq has quit IRC | 19:24 | |
*** Euph0ria has quit IRC | 19:47 | |
*** Euph0ria has joined #openstack | 19:51 | |
*** slaweq has quit IRC | 19:53 | |
*** jangutter has joined #openstack | 19:53 | |
*** jangutter has quit IRC | 19:54 | |
*** jangutter_ has quit IRC | 19:54 | |
*** jangutter has joined #openstack | 19:54 | |
*** matt_kosut has quit IRC | 20:06 | |
*** rs09 has joined #openstack | 20:49 | |
*** errantekarmico has quit IRC | 20:50 | |
*** errantekarmico has joined #openstack | 20:53 | |
*** errantekarmico has quit IRC | 20:55 | |
rs09 | I have an OpenStack environment that's configured with Federated Keystone (saml2 with ADFS). It works fine, but I'm having trouble when trying to authenticate while using the OpenStack CLI. ADFS also has multi-factor authentication enabled. Does the OpenStack CLI support MFA? For what it's worth, this is the error I'm encountering:# openstack token | 21:06 |
rs09 | issue/S:Envelope/S:Header/ecp:Response/@AssertionConsumerServiceURL should provide a single element list | 21:06 |
*** jtomasek has quit IRC | 21:11 | |
*** scanepa has joined #openstack | 21:35 | |
*** sergiuw has quit IRC | 21:45 | |
*** Goneri has quit IRC | 21:49 | |
*** rs09 has quit IRC | 22:08 | |
*** rs09 has joined #openstack | 22:17 | |
*** rs09 has quit IRC | 22:18 | |
*** vexorg has quit IRC | 22:26 | |
*** skyraven has quit IRC | 22:31 | |
*** Lucas_Gray has quit IRC | 22:35 | |
*** tips has quit IRC | 22:45 | |
*** gmann_afk is now known as gmann | 22:49 | |
*** spiral has quit IRC | 22:53 | |
*** rcernin has joined #openstack | 22:57 | |
*** rcernin has quit IRC | 22:59 | |
*** rcernin has joined #openstack | 22:59 | |
*** benfelin has quit IRC | 23:11 | |
*** skyraven has joined #openstack | 23:43 | |
*** random_yanek has quit IRC | 23:47 | |
*** skyraven has quit IRC | 23:55 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!