Tuesday, 2020-09-01

*** baojg has quit IRC00:57
*** baojg has joined #openstack-swift00:58
*** baojg has quit IRC01:29
*** baojg has joined #openstack-swift01:29
mattoliverauoh nice timburke, doodled my time01:59
*** rcernin has quit IRC02:40
*** gyee has quit IRC03:13
*** rcernin has joined #openstack-swift03:14
*** rcernin has quit IRC03:19
*** rcernin has joined #openstack-swift03:19
*** baojg has quit IRC03:34
*** baojg has joined #openstack-swift03:35
zaitcevok doodled04:04
*** evrardjp has quit IRC04:33
*** evrardjp has joined #openstack-swift04:33
*** m75abrams has joined #openstack-swift05:23
*** djhankb has quit IRC05:49
*** djhankb has joined #openstack-swift05:50
*** renich has quit IRC06:16
*** dsariel has joined #openstack-swift07:11
*** baojg has quit IRC07:14
*** baojg has joined #openstack-swift07:15
*** rcernin has quit IRC07:36
*** rcernin has joined #openstack-swift07:59
*** djhankb has quit IRC08:01
*** rcernin has quit IRC08:02
*** djhankb has joined #openstack-swift08:02
*** adriant has quit IRC08:03
*** adriant has joined #openstack-swift08:03
*** viks____ has joined #openstack-swift09:02
*** tkajinam has quit IRC09:54
*** tkajinam has joined #openstack-swift09:55
*** baojg has quit IRC10:07
*** baojg has joined #openstack-swift10:08
*** mgagne has quit IRC10:39
*** tonyb has quit IRC11:05
*** tonyb has joined #openstack-swift11:31
*** dsariel has quit IRC12:46
*** dsariel has joined #openstack-swift12:47
*** baojg has quit IRC13:07
*** baojg has joined #openstack-swift13:08
*** baojg has quit IRC13:30
*** baojg has joined #openstack-swift13:31
*** baojg has quit IRC15:06
*** baojg has joined #openstack-swift15:06
*** m75abrams has quit IRC15:11
*** baojg has quit IRC15:39
*** baojg has joined #openstack-swift15:40
*** baojg has quit IRC16:13
*** baojg has joined #openstack-swift16:31
*** gyee has joined #openstack-swift16:38
*** baojg has quit IRC16:51
*** manuvakery has joined #openstack-swift16:51
*** baojg has joined #openstack-swift17:40
*** tonyb has quit IRC17:44
*** adriant has quit IRC17:44
*** djhankb has quit IRC17:44
*** TViernion has quit IRC17:44
*** aluria has quit IRC17:44
*** DHE has quit IRC17:44
*** tonyb has joined #openstack-swift17:46
*** adriant has joined #openstack-swift17:46
*** djhankb has joined #openstack-swift17:46
*** TViernion has joined #openstack-swift17:46
*** aluria has joined #openstack-swift17:46
*** DHE has joined #openstack-swift17:46
*** djhankb has quit IRC17:46
*** djhankb has joined #openstack-swift17:47
*** josephillips has quit IRC17:47
*** noonedeadpunk has quit IRC17:48
*** josephillips has joined #openstack-swift17:50
*** noonedeadpunk has joined #openstack-swift17:51
*** baojg has quit IRC17:53
*** baojg has joined #openstack-swift17:54
openstackgerritTim Burke proposed openstack/swift master: proxy: Include thread_locals when spawning _fragment_GET_request  https://review.opendev.org/74937618:18
*** baojg has quit IRC18:22
*** baojg has joined #openstack-swift18:23
*** baojg has quit IRC19:20
*** openstackgerrit has quit IRC19:21
*** viks____ has quit IRC19:28
*** manuvakery has quit IRC19:40
*** openstackgerrit has joined #openstack-swift19:44
openstackgerritTim Burke proposed openstack/swift master: wip: s3api: Make quota-exceeded errors more obvious  https://review.opendev.org/74938219:44
*** renich has joined #openstack-swift19:52
renichgood day, everyone! :D20:00
timburkerenich, o/ how's the TLS connection going?20:12
renichtimburke: well, trying, now, to implement wsgi for swift. It never worked. Some issue with SSL of some kind.20:25
renichI'm using wildcard LetsEncrypt certs and they work with keystone + wsgi + apache20:26
renichfor some reason, they don't work with swift-proxy (ussuri)20:26
timburke:-/ and this is just using cert_file/key_file in proxy-server.conf? fwiw, i typically use an external terminator like haproxy or hitch20:29
renichtimburke: yeah, I was considering that. I followed the Ubuntu guide, though, and configured stuff without having much of an idea of what I was doing, quite honestly.20:30
renichI'm just starting to learn how stuff works, hehe.20:30
* renich prefers nginx and haproxy over apache20:30
renichs/and/or/20:30
renichtimburke: yes, I was using only cert_file/key_file. My theory is that it might get funky because I am using keystone... who knows.20:31
renichI got keystone, as I said, to work with SSL without too much hassle. I had to re-configure the endpoints and change the openrc file for admin, though.20:31
renichStill, it worked fine. No idea of why swift-proxy refuses to work. I am sure it has the same cert; it has read permissions and all.20:32
renichAnd the logs, even in DEBUG, don't show anything.20:32
renichI'm following this guide, somewhat, for the proxy: https://docs.openstack.org/swift/ussuri/apache_deployment_guide.html.20:34
renichI've made some progress, just stuck on some odd behavior. I'm getting timeouts now. https://paste.centos.org/view/3e0f25f920:34
renich^^ The logs.20:35
timburkeoh! ok -- if you've got Apache handling client traffic, that's where you'll want to configure SSL -- you should be able to leave cert_file/key_file blank in proxy-server.conf those are mainly for simple development/testing20:41
timburkeso i think in the <VirtualHost *:8080> config you'll want `SSLEngine on`, `SSLCertificateFile ...`, etc.20:43
*** baojg has joined #openstack-swift21:44
renichtimburke: yep, that's what I have right now. https://paste.centos.org/view/ef037dfa21:48
timburkerenich, at that point, you shouldn't need to do anything with your proxy-server.conf -- cert_file and key_file are only for running with the integral web front-end21:50
renichtimburke: so, leave proxy-server.conf untouched?21:51
renichI had some certfile setting in the s3token section.21:54
renichI'm removing that.21:55
timburkeyeah, see how that goes. still connect to https://...:8080, apache should be listening, unwrap the tls connection, and forward everything else on to swift21:55
timburkethe s3token option may still be needed -- depends on whether you installed the CA cert system-wide or not21:57
renichI am using letsencrypt certificates21:59
renichno CA on my side. Should be part of the system-wide CA, right?21:59
openstackgerritTim Burke proposed openstack/swift master: proxy: Put storage policy index in object-server responses  https://review.opendev.org/74940021:59
openstackgerritTim Burke proposed openstack/swift master: s3api: Ensure backend headers make it through s3api  https://review.opendev.org/74940121:59
timburkegood point -- yeah, i wouldn't worry about it then22:00
renichWhat I don't really get it's lines 12 and onwards: https://paste.centos.org/view/3e0f25f922:01
renichTo get to line 12, I need to wait a long time before it times out. Probably like 2 or 3 minutes.22:02
renichThen, the rest of the messages pop out.22:03
timburkethe thing that makes me suspicious is line 18 -- it seems like somebody's not holding up their end of the SSL conversation (before we even get to http and wsgi)22:06
renichOK, let me check endpoints and ssl configs everywhere.22:06
timburkei mean, i may well be barking up the wrong tree -- i don't deploy apache, so it's mostly guesswork from me22:08
renichBingo! I think I found the culprit!22:15
renich[Tue Sep 01 22:15:39.769594 2020] [wsgi:alert] [pid 433347:tid 140444798610496] (2)No such file or directory: mod_wsgi (pid=433347): Unable to change working directory to home directory '/var/lib/swift' for uid=118.22:15
renichthe wsgi user cannot use /var/lib/swift for some reason. I dunno if that even exists.22:16
renichhah! it works!22:16
timburkeoh! interesting...22:16
timburke\o/22:16
renichyeah! Man, you've saved my life like many times. I owe you!22:17
timburkethis one was all you, i think ;-)22:17
renichWell, you always help me bounce off ideas and stuff. I appreciate your support and thank you sincerely.22:18
renichThese things are hard...22:18
timburkeif there's anything that could make those apache-deployment docs better, please do propose improvements! idk the last time anyone ran through them :-(22:18
renichSure thing. I think they do need a bit of love since the official howto sets up apache for keystone at least.22:19
renichI need to re-group and figure out all I did, so I can have a clearer procedure in my head before I do.22:19
renichWhere should I go to propose the doc changes?22:20
renichgitea?22:20
timburkewe review code through gerrit; there's a quickstart guide at https://docs.openstack.org/contributors/code-and-documentation/quick-start.html22:23
renichright on, will check it. Thanks!22:24
timburkeif that proves a heavy lift (it's not exactly an insignificant amount of work to get set up :-/ ), you can also submit a bug report -- there's a bug link in the upper/lower-right corners of each page of the docs22:31
renichnah, I started my affiliation already.22:35
renichI'll go through it. It's the least I can do in order to be able to contribute some to the project.22:35
renichwill wait for the affiliation confirmation. I'll continue reading about the process.22:36
renichOne question, does Gerrit support ed25519 ssh keys?22:42
renichah... it doesn't22:43
*** rcernin has joined #openstack-swift23:01
*** renich has quit IRC23:07
*** renich has joined #openstack-swift23:24
renichOK, managed to build my own docs; cloned from review.opendev.org. OK, So, now, just to learn the procedure of submitting.23:24
* renich already installed git-review23:24
*** djhankb has quit IRC23:27
*** djhankb has joined #openstack-swift23:27
*** baojg has quit IRC23:30
*** baojg has joined #openstack-swift23:30
openstackgerritTim Burke proposed openstack/swift master: s3api: Make quota-exceeded errors more obvious  https://review.opendev.org/74938223:41
timburkenice! if you've gotten that far, it shouldn't be too far off now :-) should just be a matter of committing and running `git review`23:42
renichRight on. I, still, need to create my commits with meaningful messages and stuff. I've done several changes to the apache deployment guide :S23:48
renichAnd, I can infer some of the editing guidelines, but I'd like to read the docs about them...23:48
mattoliveraumorning23:50
renichIt might be a good idea to add an .editorconfig at doc/: https://editorconfig.org/23:52
renichAnd some editors seem to support the max line length feature: https://github.com/editorconfig/editorconfig/wiki/EditorConfig-Properties#supported-by-a-limited-number-of-editors23:55
renich... vim does ;D23:55

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!