Monday, 2015-11-16

openstackgerritAngus Salkeld proposed openstack/kolla: Spec: Deploy Kolla images using Mesos  https://review.openstack.org/24108600:03
*** sacharya has quit IRC00:20
*** alisonh has quit IRC00:45
*** alisonh has joined #kolla00:50
*** vilobhmm has joined #kolla00:53
*** tfukushima has joined #kolla00:56
*** tzn has quit IRC01:15
*** weiyu_ has joined #kolla01:16
*** sdake has quit IRC01:18
*** kjelly has joined #kolla01:22
*** cloudnull has quit IRC01:34
*** ArchiFleKs has quit IRC01:35
*** ArchiFleKs has joined #kolla01:37
*** cloudkiller has joined #kolla01:38
openstackgerritAngus Salkeld proposed openstack/kolla-mesos: add config generation script and some examples  https://review.openstack.org/24291201:49
*** sdake has joined #kolla02:02
*** dims has joined #kolla02:06
*** jasonsb has quit IRC02:15
*** jasonsb has joined #kolla02:15
*** jasonsb has quit IRC02:36
*** jasonsb has joined #kolla02:37
*** cloudkiller is now known as cloudnull02:38
*** unicell has joined #kolla03:01
*** vilobhmm has quit IRC03:23
*** klint has joined #kolla03:41
*** vilobhmm has joined #kolla03:44
*** dims has quit IRC03:47
*** dims has joined #kolla03:48
*** vilobhmm has quit IRC03:49
*** vilobhmm has joined #kolla03:49
*** vilobhmm has quit IRC03:50
*** weiyu_ has quit IRC03:54
*** dims has quit IRC04:08
*** weiyu has joined #kolla04:10
*** sacharya has joined #kolla04:15
*** daneyon has joined #kolla04:21
*** weiyu has quit IRC04:45
*** vbel has quit IRC04:57
*** vbel has joined #kolla04:58
*** daneyon has quit IRC04:59
*** weiyu has joined #kolla05:24
*** sacharya has quit IRC05:28
*** weiyu has quit IRC05:36
*** sdake has quit IRC05:38
*** sdake has joined #kolla05:41
*** weiyu_ has joined #kolla06:15
*** pbourke has quit IRC06:17
*** pbourke has joined #kolla06:18
*** shakamunyi has joined #kolla06:21
*** sacharya has joined #kolla06:29
*** sacharya has quit IRC06:34
*** vilobhmm has joined #kolla06:38
*** shakamunyi has quit IRC06:39
*** vilobhmm has quit IRC06:40
openstackgerritMichal Rostecki proposed openstack/kolla-mesos: Rename package from kolla-mesos to kolla_mesos  https://review.openstack.org/24527606:42
openstackgerritMichal Rostecki proposed openstack/kolla-mesos: Install kolla-mesos package in Vagrant  https://review.openstack.org/24559106:49
*** vilobhmm has joined #kolla06:53
*** shakamunyi has joined #kolla06:54
*** nihilifer has quit IRC07:02
*** nihilifer has joined #kolla07:03
*** suro-patz has joined #kolla07:04
*** SamYaple_ has joined #kolla07:11
*** vincent_1dk has joined #kolla07:11
*** slagle_ has joined #kolla07:11
*** slagle has quit IRC07:15
*** vincent_vdk has quit IRC07:15
*** SamYaple has quit IRC07:15
*** harmw has quit IRC07:15
*** harmw has joined #kolla07:21
*** suro-patz has quit IRC07:30
*** Chandra has joined #kolla07:31
*** rmart04 has joined #kolla07:32
*** rmart04 has quit IRC07:37
*** jmccarthy has quit IRC07:38
Chandrahi , i have local docker registry running at 192.168.1.100:8080 and i need to push all images to local registry .07:40
Chandrahow to make it work . i tried using kolla-build --registry 192.168.1.100:8080 --push07:41
Chandrabut it dint work . tried with port 5000 also . anyone have solution , please help . i am trying to deploy multi node07:42
kjellyChandra: what's the error message ?07:42
kjellyChandra: the command you use is correct.07:43
ChandraERROR:kolla.cmd.build:Error: Status 502 trying to push repository kollaglue/ubuntu-source-gnocchi-statsd: "<html>\r\n<head><title>502 Bad Gateway</title></head>\r\n<body bgcolor=\"white\">\r\n<center><h1>502 Bad Gateway</h1></center>\r\n<hr><center>nginx/1.4.6 (Ubuntu)</center>\r\n</body>\07:43
kjellyChandra: Do you set insecure-registry ?07:43
Chandrano . i added ssh certs and when i login into docker with https on other nodes it works07:44
Chandrashould i need to set insecure-registry ?07:44
Chandracould you please help me , where i can set this in ubuntu ?07:45
kjellyChandra: yes. https://github.com/openstack/kolla/blob/master/doc/image-building.rst#docker-insecure-registry-config07:45
Chandramy deploy host is running on ubuntu .07:45
kjellyChandra: you need to set it in the node which is used for deploy and building image.07:45
Chandraok . thanks you kjelly . let me give a try07:46
Chandrathanks for helping out07:46
kjellyChandra: :)07:46
*** weiyu_ has quit IRC07:51
*** vilobhmm has quit IRC07:52
*** weiyu has joined #kolla07:53
*** akwasnie1 has joined #kolla07:53
*** Chandra has quit IRC07:59
*** stvnoyes has quit IRC08:01
*** stvnoyes has joined #kolla08:01
*** egonzalez has joined #kolla08:07
*** rmart04 has joined #kolla08:09
*** egonzalez has quit IRC08:20
openstackgerritMichal Rostecki proposed openstack/kolla: [WIP] Add Python 3.x support  https://review.openstack.org/24565908:22
*** egonzalez has joined #kolla08:34
*** tobe has joined #kolla08:34
*** weiyu has quit IRC08:38
*** kjelly has quit IRC08:40
*** shardy has joined #kolla08:40
*** weiyu has joined #kolla08:42
*** weiyu has quit IRC08:44
openstackgerritAngus Salkeld proposed openstack/kolla-mesos: Add config generation script and some examples  https://review.openstack.org/24291208:48
*** exploreshaifali has joined #kolla08:50
*** weiyu_ has joined #kolla08:54
*** jmccarthy has joined #kolla08:57
*** kproskurin has joined #kolla09:02
*** kproskurin has quit IRC09:02
*** kproskurin has joined #kolla09:06
*** rmart04 has quit IRC09:16
*** slotti has joined #kolla09:20
*** athomas has joined #kolla09:22
*** gfidente has joined #kolla09:23
*** gfidente has joined #kolla09:23
*** weiyu_ has quit IRC09:35
*** kjelly has joined #kolla09:35
*** weiyu_ has joined #kolla09:38
*** tobe has quit IRC09:44
*** tobe has joined #kolla09:45
*** tzn has joined #kolla09:56
*** mbound has joined #kolla10:00
*** tfukushima has quit IRC10:07
*** openstackgerrit has quit IRC10:16
*** openstackgerrit has joined #kolla10:16
*** inc0 has joined #kolla10:20
inc0Hey10:20
openstackgerritMerged openstack/kolla: Remove unused tox jobs  https://review.openstack.org/24509610:20
inc0Good news, I'm about to come back to work:)10:21
*** tobe has quit IRC10:36
akwasnie1but unfortunately not in PL, inc0 :( how was your flight? :)10:37
inc0Pretty bad10:37
inc0We missed connecting flight (last one) in Washington10:38
akwasnie1uu..so you had to stay there, in Washington?10:40
*** exploreshaifali has quit IRC10:49
*** exploreshaifali has joined #kolla10:53
inc0Yup, we had to get hotel10:59
*** mbound has quit IRC11:03
openstackgerritMichal Rostecki proposed openstack/kolla-mesos: Install kolla-mesos package in Vagrant  https://review.openstack.org/24559111:08
*** dims has joined #kolla11:12
*** weiyu_ has quit IRC11:15
*** cemmason has joined #kolla11:23
*** exploreshaifali has quit IRC11:28
*** mbound has joined #kolla11:31
*** cemmason has quit IRC11:43
*** mbound has quit IRC11:45
*** mbound has joined #kolla11:45
openstackgerritPaul Bourke proposed openstack/kolla: Drop root for rsyslog  https://review.openstack.org/24573311:51
*** masterbound has joined #kolla12:06
*** mbound has quit IRC12:06
*** cemmason has joined #kolla12:11
*** cemmason has quit IRC12:26
*** rhallisey_ has joined #kolla12:39
*** openstack has joined #kolla12:51
-cameron.freenode.net- [freenode-info] channel flooding and no channel staff around to help? Please check with freenode support: http://freenode.net/faq.shtml#gettinghelp12:51
*** inc0_ has joined #kolla12:56
*** inc0 has quit IRC12:56
*** inc0 has joined #kolla12:56
*** inc0_ has joined #kolla12:58
*** inc0_ has quit IRC12:58
*** inc0 has quit IRC12:59
*** inc0_ has joined #kolla12:59
*** inc0 has joined #kolla13:00
*** inc0_ has quit IRC13:03
*** exploreshaifali has joined #kolla13:12
*** cemmason has joined #kolla13:34
*** cemmason has quit IRC13:38
*** kjelly_ has joined #kolla13:39
*** ubuntu1 is now known as anteaya13:52
*** klint has quit IRC14:00
*** vincent_1dk is now known as vincent_vdk14:00
openstackgerritPaul Bourke proposed openstack/kolla: Drop root for rsyslog  https://review.openstack.org/24573314:17
*** sacharya has joined #kolla14:17
openstackgerritMerged openstack/kolla-mesos: Rename package from kolla-mesos to kolla_mesos  https://review.openstack.org/24527614:19
*** achanda has joined #kolla14:19
*** sacharya has quit IRC14:22
openstackgerritPaul Bourke proposed openstack/kolla: Drop root for rsyslog  https://review.openstack.org/24573314:23
*** akwasnie1 has quit IRC14:27
rhalliseypbourke, one more comment I left in there14:32
rhalliseythen I think it looks good14:32
pbourkerhallisey: cheers14:32
*** sdake has quit IRC14:48
openstackgerritSam Yaple proposed openstack/kolla: Remove unused tox jobs  https://review.openstack.org/24580314:53
*** dwalsh has joined #kolla14:56
*** jtriley has joined #kolla15:06
*** achanda has quit IRC15:13
*** chandra has joined #kolla15:15
chandrahi , when i am trying to deploy multi node i am getting bellow error . someone please help me ..15:16
chandraTASK: [common | Starting log_data container] ********************************** failed: [control01] => {"error": "APIError(HTTPError(u'500 Server Error: Internal Server Error for url: http+docker://localunixsocket/v1.20/auth',),)", "failed": true} msg: failed to login to the remote registry, check your username/password. failed: [network01] => {"error": "APIError(HTTPError(u'500 Server Error: Internal Server Error for url: http+docker:/15:16
*** achanda has joined #kolla15:16
SamYaple_hellow everyone15:16
pbourkehey SamYaple_15:17
pbourkechandra: it looks like docker isn't configured correctly15:17
SamYaple_chandra: that looks pretty straightforward, it looks like you are either trying to use authentication na your registry doesnt have it, or you have the wrong user name and password15:17
*** SamYaple_ is now known as SamYaple15:17
SamYapleinc0: when do you start working again?15:19
chandraok. default which user it will consider. should i need to mention docker user and password in globals.yml file ?15:19
SamYaplehey core guys, this is a fairly servious regression that I would like to get approved and backport https://review.openstack.org/#/c/244768/15:20
SamYaplechandra: by default there is no authertcation15:20
SamYaplechandra: so no username or password hsould be specified15:20
SamYaplerhallisey: pbourke: inc0: coolsvap: quick poll, how many of your would be opposed to a local copy of the docker module for ansible. That we maintain.15:21
SamYapleif we had that, then we woudnt have this problem of the 1.8.2 docker cap, and we could fix issues much much faster15:21
chandranow i am getting below error15:21
chandraTASK: [common | Starting log_data container] ********************************** failed: [network01] => {"error": "APIError(HTTPError(u'500 Server Error: Internal Server Error for url: http+docker://localunixsocket/v1.20/images/create?tag=latest&fromImage=192.168.1.50%3A4000%2Fkollaglue%2Fubuntu-source-data',),)", "failed": true} msg: Failed to pull the specified image: 192.168.1.50:4000/kollaglue/ubuntu-source-data:latest failed: [contr15:21
SamYaplechandra: what does `docker pull 192.168.1.50:4000/kollaglue/ubuntu-source-data:latest` give you?15:22
chandraroot@ubuntu:~/kolla# docker pull 192.168.1.50:4000/kollaglue/ubuntu-source-data:latest Pulling repository 192.168.1.50:4000/kollaglue/ubuntu-source-data 57710fd4eaaa: Download complete 2332d8973c93: Download complete ea358092da77: Download complete a467a7c6794f: Download complete ca4d7b1b9a51: Download complete e8cae89d8c86: Download complete Status: Image is up to date for 192.168.1.50:4000/kollaglue/ubuntu-source-data:latest15:22
*** masterbound is now known as mbound15:23
pbourkeSamYaple: doesn't sound worth it to me15:23
pbourkeSamYaple: if you want to do that why not just move to beta version of ansible in kolla-ansible15:23
chandraSamYaple : pull worked fine15:23
SamYaplepbourke: we cant require a beta version of ansible for kolla15:24
SamYaplepbourke: and they are never snapping a new 1.9.x release15:24
SamYaplewe will most certainly run into this problem in the future15:24
SamYaplemy issue is when we envitably hit a bug like this again we will have no recourse. What if version 2.1.1 of ansible has a fix for a bug, but a broken version of docker?15:25
SamYaplewe can't consume both fixes15:25
pbourkeah yes this is ansible on the deploy host not kolla-ansible15:26
SamYaplecorrect15:26
kjelly_chandra: do you set insecure-registry to all the node you use ?15:26
SamYaplekjelly_: thats probably it15:26
pbourkecan we do a docker image for ansible15:26
SamYaplewhta do you mean?15:27
kproskurinsounds interesting15:27
pbourkemake a docker image that has working beta version of ansible15:27
pbourkeinstruct users to use that instead15:27
SamYaplewe could actually wrap docker into the kolla-ansible container! but it would be kinda messy15:28
SamYapleanother thing our own self written dockerm odule would get us is better use of DRY15:29
SamYapleyou know those options we specify each time that dont change every?15:29
SamYaplewe wouldnt have to do that15:29
SamYaplehttps://github.com/openstack/kolla/blob/master/ansible/roles/glance/tasks/start.yml#L4-L1315:29
SamYapleand then the env part too15:30
SamYaplewe wouldnt have to write those out each time15:30
pbourkehave you engaged much with ansible about fixing it15:31
pbourkebefore forking15:31
chandraThanks SamYaple and kjeelly15:31
chandrait worked. after configuring insecure-registry in all nodes it worked15:32
chandraThanks a lot. :-)15:32
SamYaplepbourke: simple fact is they 100% are not snapping another 1.9.x tag15:32
SamYaplewe are completely at thier mercy here15:33
pbourkeare they far off snapping a 2.015:33
SamYapleit doesnt matter, we cant use 2.0 for liberty15:33
SamYapleit requires playbook changes15:33
pbourkeso just limit liberty at 1.8.215:33
SamYaplewell master is limited at 1.8.2 right now as well :)15:34
SamYaplethe real issue is we can't have ansible determining the progress of kolla-ansible15:34
pbourkeyes but if we're patient, give them a chance to release 2.0 and then mitaka = ansible 2.0 + docker latest15:34
SamYapleand when that doesnt work?15:35
SamYaplei would be shocked if ansible 2.0 works for us on initial version15:35
pbourkeok that's all the arguments I've got :p15:36
pbourkei dont think the docker module is that big anyhow15:37
SamYaplethese are valid arguments, and i agree with you15:37
SamYaplesdake is all over this "our own docker module" thing15:37
SamYapleoh right, another big thing is they have no intention of making thier docker module work with the docker v1 registry anymore15:37
SamYaplethey said no to patching in support for that since it broke in 1.8.315:38
SamYapleand i dont want to use v2 registry until it, you know, works15:38
pbourkeyeah15:39
pbourkeI wouldnt be thrilled about backporting that though15:40
pbourkeunless that's not the intention15:40
SamYapleim not sure. I think backport was on the table. maybe idk15:42
SamYapleits not my intention15:42
*** blahRus has joined #kolla15:46
*** exploreshaifali has quit IRC15:47
pbourkerhallisey: are you sure '/usr/bin/rm rsyslog\: blah' locks that rm to the rsyslog user?15:51
rhalliseypbourke, pretty sure why15:52
pbourkerhallisey: cause it doesn't seem to be working and looking more closely rabbitmq only does it for chown commands15:52
rhallisey/usr/bin/rm -rf rsyslog15:53
rhalliseyyou need all the flags15:53
rhalliseyI didn't realize that when I was doing it15:53
*** mbound has quit IRC15:54
rhalliseypbourke, try that15:54
pbourketrying15:55
rhalliseykk15:55
*** mbound has joined #kolla15:55
SamYapleรท/win 3315:57
pbourkerhallisey: still asking for password :( the syntax seems really weird, did you come across any useful examples online when doing yours?15:59
*** chandra has quit IRC16:03
*** masterbound has joined #kolla16:09
*** mbound has quit IRC16:11
rhalliseypbourke, I did.  Let me look...16:13
*** kjelly_ has quit IRC16:17
*** absubram has joined #kolla16:18
pbourke# glance image-list16:25
pbourkeAn auth plugin is required to fetch a token16:25
pbourkewtf does this mean16:25
pbourkeproxy woes again it seems16:26
rhalliseypbourke, I can't find the example I used.  Still looking16:30
rhalliseypbourke, I left a comment on what I think might work16:32
pbourkerhallisey: thanks16:32
*** suro-patz has joined #kolla16:34
pbourkeglance seems busted16:36
pbourkewith file backend16:37
pbourkeeveryone is using ceph?16:37
openstackgerritRyan Hallisey proposed openstack/kolla: [WIP} Drop root privileges for openvswitch  https://review.openstack.org/24536616:37
*** sacharya has joined #kolla16:42
*** achanda has quit IRC16:51
*** daneyon has joined #kolla16:54
*** sdake has joined #kolla16:56
sdakemorning16:56
pbourkesdake: hi16:57
pbourkesdake: do you use ceph for a glance backend?16:57
*** sdake has quit IRC17:01
*** sdake has joined #kolla17:02
*** slotti has quit IRC17:05
*** sdake has quit IRC17:06
*** sdake has joined #kolla17:06
SamYaplemorning17:09
SamYaplepbourke: we dont have an ha glance backend, so ceph is our only ha solution17:10
pbourkeSamYaple: right but it should work without ha17:10
SamYapleit _should_ work yes17:10
SamYaplebut i dont know how often its tested17:10
pbourkecan fix quick enough17:12
SamYaplewats broken on it?17:15
pbourkethe drop root broke it17:15
pbourkeas it can't create it17:15
pbourkeon start17:15
SamYapleoh yea that sounds right17:15
SamYaplei dont think sdake tested it17:15
SamYaplei mean the file backend17:15
sdakewhat17:16
sdakei test eerything guys17:16
sdakei didn't do glance17:16
SamYapleqoute of the day tehre17:16
SamYaple17:17:47 < sdake> i test eerything guys17:16
SamYaple;)17:16
sdakeeverything i personally author i  do test 1000%17:17
pbourkebd9e8c22d79f28d1bc74eeaa4f7f8563a8e9da6d17:17
SamYaplelies i have quotes from yesterday saying otherwise17:17
pbourkedum dum DUM17:17
sdakeSamYaple thta wasn'tpersonally authored17:18
pbourkethe good news is I uncovered it with tempest17:18
pbourkewill be nice for uncovering these kind of things17:18
pbourkethough image creation is a basic one so surprised no one hit it17:19
SamYaple21:53:45 < SamYaple> you should have probably tested that master to liberty repo change patch17:20
SamYaple21:53:55 < sdake_> y no beuno17:20
SamYaple21:54:01 < sdake_> your right i should have17:20
SamYaplejust sayin17:20
SamYaple21:54:09 < sdake_> bad move on my part17:20
sdakethat was xomeone elses patch i approved17:20
sdakenot self-auhored17:20
sdakeanyway I don think i did glance17:21
SamYaplehttps://review.openstack.org/#/c/242877/17:22
SamYapleits ok man17:23
SamYapleyou can make mistakes17:23
SamYaplewe all do17:23
SamYaplejust own up to it17:23
pbourkepopcorn.gif17:23
sdakeguss i did glance17:23
sdakebut it does look correct17:23
pbourkesdake: it's an edge case17:24
pbourkesdake: got another one - in sudoers.d, 'chown user\: foo'17:25
pbourkethe user\: is just part of the chown cmd right?17:25
pbourkenot, "only user can run this command"17:25
SamYaplepbourke: correct17:25
pbourkethat's what I thought17:25
pbourkerhallisey: ^17:25
SamYaplebasically you are saying this user can do this command EXACTLY LIKE THAT17:25
SamYapleany deviation and it wont allow it17:26
sdakewithout the backslace of course17:26
pbourkeyeah but you can't do something like:17:26
pbourkerm -rf user\: foo17:26
sdakesudo needs colons escaped17:26
SamYaplepbourke: you can, but it will try to remove 'user:' as a file17:26
*** unicell has quit IRC17:26
*** masterbound has quit IRC17:27
*** suro-patz has quit IRC17:29
*** dmsimard is now known as dmsimard|food17:29
*** sdake_ has joined #kolla17:31
*** dans_ has joined #kolla17:31
SamYaplerhallisey: you cannot drop privleges for openvswitch. this causes the socket (which is accessible from the host system) to have uid:guid mappings that can be insecure17:32
SamYapleit must run as root17:32
SamYaplewe can circle back around on this when we can take advantage of the docker uid mapping in 1.9.0, but until then it can't drop its user like you are trying to do17:32
pbourkeeither im doing something wrong or glance with file backend is fubared17:32
SamYapleyes17:33
pbourkeit mounts glance_data into glance_registry17:33
pbourkebut its the api that needs to access the data store?17:33
SamYaplepbourke: is that a question or a statement?17:33
sdake_ok guys rhallisey needs custom repos17:33
sdake_and i need custom repos17:33
sdake_so lets have a discussion about that17:33
*** sdake has quit IRC17:33
SamYaplei dont know where the images live, in the api container or the registry17:33
*** slagle_ is now known as slagle17:33
dans_Anyone know how to enable support of network namespaces inside an LXC container? I got this error "TRACE neutron.agent.dhcp.agent Stderr: mount --make-shared "/var/run/netns failed": Permission denied" I'm running neutron inside of an LXC container. Any idea? Thanks for the help!!17:34
pbourkeSamYaple: question17:34
pbourkeSamYaple: which glance service should write image data to the file backend17:34
SamYaplepbourke: 17:35:19 < SamYaple> i dont know where the images live, in the api container or the registry17:35
pbourkeSamYaple: ok thanks17:35
SamYapletesting would be my suggestion17:35
SamYaplei thought ti was the registry17:35
sdake_images are in registry17:35
SamYaplesdake_: the api recieves the data and sends it to the registry.... how?17:36
SamYapleover rabbit?17:36
SamYapledans_: what is the context here as relates to Kolla?17:36
*** athomas has quit IRC17:36
SamYapledans_: also some distros symlink /var/run -> /run and that might cause you mount problems with lxc17:36
*** inc0 has quit IRC17:38
dans_SamYaple: Thanks for the tip. Just thought someone here might know17:38
*** inc0 has joined #kolla17:38
SamYapledans_: yea we dont do alot with LXC here since this is all docker. I have a fair amout of experince with LXC17:42
SamYaplemay i ask what you are trying to do dans_ ?17:42
SamYapleif its share namespace made from within containers to the host, that will not work17:42
sdake_SamYaple i beliee the flow is the api stores metadata and registry stores actual data17:47
sdake_but i dont think it involves rabbitmq17:47
sdake_i am not quite sure how it works17:47
SamYaplesdake_: how does the data get from the api (where all the data is received) to the metadata store?17:47
sdake_no idea17:48
dans_SamYaple: I was referred here by @dasm after asking in #neutron17:49
SamYapledans_: depending on what you are trying to do we may have the information to help you. But the LXC folks are #openstack-ansible . I may be able to tell you what you need to know.... if i know what yo uare trying to do. Why are you trying to share the host /run/netns with the container?17:50
*** kproskurin has quit IRC17:52
dans_I have neutron in a container and it wants to create a namespace for DHCP, however my LXC container won't let me.17:53
dans_ip netns add test mount --make-shared /var/run/netns failed: Permission denied17:53
sdake_sudo17:54
dans_:P still nope17:54
dans_sudo ip netns add test17:54
dans_sudo: PERM_SUDOERS: setresuid(-1, 1, -1): Operation not permitted17:54
sdake_i'm out of ideas ;)17:54
SamYapledans_: im fairly certain youll need to create that in a privleged container17:55
dans_ok. thanks tho! i was root before too :)17:55
*** egonzalez has quit IRC17:55
SamYaplebecause it has to create a second mountpoint17:55
SamYaplecloudnull and #openstack-ansible will be able to help yuo here17:55
dans_Great! I'll a privaleged container :) thanks!17:56
*** jasonsb has quit IRC17:57
openstackgerritPaul Bourke proposed openstack/kolla: Fix issues in Glance filesystem backend  https://review.openstack.org/24591217:58
openstackgerritPaul Bourke proposed openstack/kolla: Fix issues in Glance filesystem backend  https://review.openstack.org/24591218:02
*** tzn has quit IRC18:03
*** unicell has joined #kolla18:07
rhalliseysorry back18:08
openstackgerritPaul Bourke proposed openstack/kolla: Drop root for rsyslog  https://review.openstack.org/24573318:08
rhalliseySamYaple, so there is nothing I can do at all for openvswitch?18:09
dans_SamYaple: my teammate just figured it! We had to add "lxc.aa_profile = unconfined" to the lxc config18:10
rhalliseysdake_, I think we just need a flag in build.py '--repo-url'18:10
*** suro-patz has joined #kolla18:10
rhalliseythink I have a patch around for this..18:10
sdake_we need a file import - may need more then one repo18:10
rhalliseyoh you want to go that way18:11
rhalliseyok I see where you're coming18:11
rhalliseyfrom18:11
SamYapledans_: ah ok that would also make sense. apparmor is no bueno18:12
SamYapledans_: but you should see logs about those denials in the host system logs18:13
rhalliseypbourke, did the those changes work?18:13
* rhallisey reads backlog18:13
SamYaplerhallisey: im not sure what all can be done with openvswitch to make it "more secure" but I don't think we can change any part of the users stuff18:13
sdake_ya just a note lets not make things more secure at the expense of breaking things18:14
sdake_some processes just have to run as root and that is all there is to it18:14
rhalliseyagreed18:14
SamYaplefor the record, not running as root in the container doesn't make it more secure18:15
*** inc0_ has joined #kolla18:16
*** inc0 has quit IRC18:18
sdake_it makes the container more immutable ;)18:23
sdake_in some cases18:23
sdake_which could imply some security benefit18:23
sdake_but ya this exercise of ddropping root is a little disappointing - i had expected more18:23
sdake_(bang for the buck)18:24
openstackgerritSteve Noyes proposed openstack/kolla: initial spec for kolla rest api client  https://review.openstack.org/24591718:24
*** jtriley has quit IRC18:25
sdake_stvnoyes your patch has alot of whitespce problems - can you fix pleases18:28
sdake_all the red makes people hangry :)18:28
*** ssurana has joined #kolla18:29
*** vilobhmm has joined #kolla18:34
sdake_SamYaple let me pick your brain18:36
sdake_instead of a base from centos718:36
sdake_i want a from steaks-startup.org/centos718:37
sdake_what would you recommend18:37
sdake_carry variance in a forked repo or make it an upstream feature?18:37
sdake_i think this is something alot of folks will want going forward18:38
sdake_and thats the argument against carrying variance18:38
*** jasonsb has joined #kolla18:39
*** vilobhmm has quit IRC18:40
*** vilobhmm has joined #kolla18:40
*** vilobhmm has quit IRC18:41
*** vilobhmm has joined #kolla18:41
*** vilobhmm has quit IRC18:41
*** vilobhmm has joined #kolla18:42
SamYaplesdake_: you can do whatever you want, I dont agree with changing the Kolla base repo away from vanilla things18:42
sdake_d oyou mean hte trieplo repo overrides?18:43
sdake_I wasnt talking about that, I was talking about the FROM line18:43
SamYapleso was i18:43
sdake_i think repo overrides make alot of sense- your opinion?18:44
SamYaplethe repo overrides are fine18:44
sdake_but not from overrides?18:44
SamYaplelets talk about one thing at a time18:45
sdake_ya18:45
sdake_ok lets talk about from overrides then :)18:45
SamYaplethe sources.list/repo overrides I am +2 on18:45
SamYaplethe FROM override I am also ok with, but we don't need alot of change to make that work18:45
SamYapleslight tweak to build.py18:45
SamYapleI do not agree with changing to steaks-startup.org/centos7 in the main kolla repo18:46
SamYaplei do agree with making an option so _you_ can build from that18:46
sdake_oh i see18:46
sdake_I misunderstood your objection18:46
sdake_on same page now18:46
sdake_you said slight tweak to build.py - any more information on the slight tweak needed?18:48
sdake_should we allow -b to override?18:48
sdake_or add a new option18:48
sdake_i am really anti new options18:48
*** jasonsb has quit IRC18:48
sdake_i think our build options re off the hook already18:48
SamYapleso we have a --base-tag option18:49
SamYaplewe need a similar option for --base-repo name18:49
SamYaplei know i know, but you want new features this is how you get them18:50
sdake_wow we have lag :)18:50
sdake_pbourke that bug with the registry data container18:51
sdake_can you make a special snowflake patch for stable/liberty?18:51
SamYaplesdake_: i never have lag. i think its just you18:51
sdake_ya agree sam i think so too18:52
SamYapleyou should setup a cloud server running irrsi or something18:52
sdake_i'm good18:52
sdake_SamYaple the base-tag, atm defaults to latest18:55
SamYapleas it should18:56
sdake_how would you propose changing it to get steaks-startup.org/centos18:56
SamYapleno no, thats the tag18:56
SamYapleas in :latest18:56
sdake_yup i know18:56
SamYapleyou want to change the image name18:56
SamYaplesteaks-startup.org/centos:latest18:57
sdake_right - which is -b atm18:57
SamYaplebut we use -b as the control for all our if logic18:57
sdake_i know18:57
sdake_so we need a new flag?18:57
SamYapleso either we need to add a base meta flag for centos18:57
SamYapleor we need to add a new flag to override18:57
SamYapleim not sure which18:57
*** jtriley has joined #kolla18:58
SamYaplewe can usurp -b/--base to accept steaks-startup.org/centos (old functionality style still intact)18:58
SamYapleand add a new flag --base-distro centos18:58
SamYapleso you would have to do --base steaks-startup.org/centos --base-distro centos18:59
SamYaplefor the if statements to work18:59
SamYapleanyway, youll have to figure something out but ^^ that would work18:59
SamYaplei personally dont care unless it changes existing behaviour18:59
sdake_SamYaple cool sounds good dude19:03
* sdake_ has a neverending backlog19:04
*** jtriley has quit IRC19:07
*** vilobhmm1 has joined #kolla19:07
*** vilobhmm has quit IRC19:09
*** sdake_ is now known as sdake19:10
*** bmace has quit IRC19:16
*** bmace has joined #kolla19:17
*** jtriley has joined #kolla19:21
openstackgerritSteve Noyes proposed openstack/kolla: initial spec for kolla rest api client  https://review.openstack.org/24591719:26
*** dmsimard|food is now known as dmsimard19:31
openstackgerritMichal Rostecki proposed openstack/kolla: Add Python 3.x support  https://review.openstack.org/24565919:37
*** vilobhmm1 has quit IRC19:39
*** vilobhmm has joined #kolla19:39
*** vilobhmm has quit IRC19:41
*** vilobhmm has joined #kolla19:42
*** jtriley has quit IRC19:51
*** jtriley has joined #kolla19:55
*** dwalsh_ has joined #kolla19:57
*** dwalsh has quit IRC19:58
openstackgerritMichal Rostecki proposed openstack/kolla-mesos: Add config generation script and some examples  https://review.openstack.org/24291219:58
*** kproskurin has joined #kolla20:00
*** gfidente has quit IRC20:02
openstackgerritMichal Rostecki proposed openstack/kolla-mesos: Add config generation script and some examples  https://review.openstack.org/24291220:06
kproskurinHello guys, did someone asked you already about Docker zombie problem? I mean: https://blog.phusion.nl/2015/01/20/docker-and-the-pid-1-zombie-reaping-problem/20:06
SamYaplekproskurin: wasnt that a docker 1.5.0 bug20:07
SamYaplesdake: you dealt with that 1.5.0 bug stuff, comments?20:07
kproskurinAfaik it's still persist20:08
sdakedocker does indeed have a pid 1 problem20:09
sdakeall the process reaping in kolla does not work correctly imo20:09
kproskurinyep20:09
kproskurinIt could be a problem20:09
openstackgerritMichal Rostecki proposed openstack/kolla-mesos: Install kolla-mesos package in Vagrant  https://review.openstack.org/24559120:17
*** dans_ has quit IRC20:25
*** inc0_ has quit IRC20:34
*** mbound has joined #kolla20:37
*** suro-patz has quit IRC20:45
*** suro-patz has joined #kolla20:47
*** mwheckmann has joined #kolla20:49
openstackgerritSam Yaple proposed openstack/kolla: Fix namespace regression for neutron  https://review.openstack.org/24476820:56
*** tzn has joined #kolla21:04
*** tzn has quit IRC21:10
*** suro-patz has quit IRC21:33
*** suro-patz has joined #kolla21:33
*** shardy has quit IRC21:33
sdakestvnoyes nice job cutting your teeth on a spec for Kolla :)  Welcome to the pain machine :)  I left some comments in the spec.  I think you would do well to remove the inception style thoughts - these are all part of tripleo and a big reason IMO tripleo has failed.  inception dependencies are almost as bad as circular ones :)21:38
*** sdake has quit IRC21:44
*** sdake has joined #kolla21:44
*** sdake has quit IRC21:57
*** vilobhmm has quit IRC22:03
*** vilobhmm has joined #kolla22:03
*** rhallisey has quit IRC22:03
*** jtriley has quit IRC22:14
stvnoyessdake: thanks for the feedback, I'll go through an update & repost22:22
*** jtriley has joined #kolla22:24
*** dwalsh_ has quit IRC22:29
*** vilobhmm has quit IRC22:33
*** daneyon has quit IRC22:34
*** vilobhmm has joined #kolla22:34
*** kproskurin has quit IRC22:54
*** kproskurin has joined #kolla22:54
*** ryansb_ has joined #kolla22:58
*** ryansb_ has quit IRC22:58
*** ryansb_ has joined #kolla22:58
*** blahRus1 has joined #kolla22:58
*** ssurana1 has joined #kolla23:00
*** jtriley has quit IRC23:01
*** ssurana has quit IRC23:06
*** blahRus has quit IRC23:06
*** ryansb has quit IRC23:06
*** kproskurin has quit IRC23:06
*** ryansb_ is now known as ryansb23:06
*** sacharya has quit IRC23:15
*** blahRus1 has quit IRC23:21
*** mwheckmann has quit IRC23:26
*** jtriley has joined #kolla23:33
*** absubram has quit IRC23:34

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!