Re: [ovirt-users] Using VDSM to edit management interface

2018-03-16 Thread Peter Hudec
Remove any settings about dns from the network manager adn the
/etc/resolv.conf won't be auto generated.

https://ma.ttias.be/centos-7-networkmanager-keeps-overwriting-etcresolv-conf/

Peter

On 16/03/2018 02:15, Kirin van der Veer wrote:
> Ďakujem Peter, but this doesn't seem to work in my case. 
> /etc/resolv.conf is regenerated by Network Manager after a reboot
> and my domain settings are lost. Your comments regarding the
> reliance on DNS make sense for most installations, but in my case
> oVirt is a secondary service that I would not expect to run unless
> our core infrastructure is working correctly. I'm hesitant to edit
> /etc/hosts directly, since that can lead to confusion when the
> underlying IP addresses change. For now I will hardcode the IPs of
> my servers. It's frustrating (and surprising) that there is not an
> easy way to do this.
> 
> Kirin.
> 
> On Thu, Mar 15, 2018 at 5:17 PM, Peter Hudec  > wrote:
> 
> Hi Kirin,
> 
> I suggest to do it old way and edit the /etc/resolv.conf manually.
> 
> And one advice. Do not relay on the DNS on infrastructure servers.
> Use /etc/hosts. If he DNS will not be accessible, you will have
> problem to put it infrastructure up/working. As side effect the
> hosts allow you to use short names to access servers.
> 
> If you are ansible positive, you could use
> 
> hudecof.resolv  https://galaxy.ansible.com/hudecof/resolv/ 
>  hudecof.hosts
> https://galaxy.ansible.com/hudecof/hosts/ 
> 
> 
> 
> Peter
> 
> On 15/03/2018 06:03, Kirin van der Veer wrote:
>> Hi oVirt people, I have setup a new cluster consisting of many 
>> oVirt Nodes with a single dedicated oVirt Engine machine. For
>> the most part things are working, however despite entering the
>> DNS search domain during install on the Nodes the management
>> interface is not aware of my search domain and it has not been
>> added to /etc/resolv.conf (perhaps that is unnecessary?). I
>> eventually worked out that the DNS search domain should be
>> included in /etc/sysconfig/network-scripts/ifcfg-ovirtmgmt
>> However as per the header/warning, that file is generated by
>> VDSM. I assumed that I should be able to edit the search domain
>> with vdsClient, but when I run "vdsClient -m" I don't see any
>> options related to network config. I found the following page on
>> DNS config:
>> 
> https://www.ovirt.org/develop/release-management/features/network/allowExplicitDnsConfiguration/
>
> 

>> 
>> 
> But it does not seem to offer a way of specifying the DNS search
> domain
>> (other than perhaps directly editing /etc/resolv.conf - which is 
>> generated/managed by Network Manager). nmcli reports that all of
>> my interfaces (including ovirtmgmt) are "unmanaged". Indeed when
>> I attempt to run nmtui there is nothing listed to configure.
>> This should be really simple! I just want to add my local search
>> domain so I can use the short name for my NFS server. I'd
>> appreciate any advice.
>> 
>> Thanks in advance, Kirin.
>> 
>> 
>> .
>> 
>> *IMPORTANT NOTE. *If you are NOT AN AUTHORISED RECIPIENT of this 
>> e-mail, please contact Planet Innovation Pty Ltd by return
>> e-mail or by telephone on +613 9945 7510
>> .  In
> this case, you should not
>> read, print, re-transmit, store or act in reliance on this
>> e-mail or any attachments, and should destroy all copies of them.
>> This e-mail and any attachments are confidential and may contain
>> legally privileged information and/or copyright material of
>> Planet Innovation Pty Ltd or third parties.  You should only
>> re-transmit, distribute or commercialise the material if you are
>> authorised to do so.  Although we use virus scanning software, we
>> deny all liability for viruses or alike in any message or
>> attachment. This notice should not be removed.
>> 
>> **
>> 
>> 
>> ___ Users mailing
>> list Users@ovirt.org 
> http://lists.ovirt.org/mailman/listinfo/users 
> 
>> 
> 
> 
> -- *Peter Hudec* Infraštruktúrny architekt phu...@cnc.sk
>   >
> 
> *CNC, a.s.* Borská 6, 841 04 Bratislava Recepcia: +421 2 35 000 100
> 
> 
> Mobil:+421 905 997 203  *www.cnc.sk
> * >
> 
> 
> 
> *IMPORTANT NOTE. *If you are NOT AN AUTHORISED RECIPIENT of this
> e-mail, please contact Planet Innovation Pty Ltd by return e-mail
> or by telephone on +613 9945 7510.  In this case, you should not
> read, print, re-transmit, store or act in reliance on this e-mail
> or any attachments, and should destroy all copies of them.  This
> 

Re: [ovirt-users] 4.2.2.2-1 Starting hosted engine on all hosts

2018-03-16 Thread Yaniv Kaul
On Mar 15, 2018 9:21 PM, "Maton, Brett"  wrote:

Ok cool, glad you already have enough information as it's trashed my
hosted-engine beyond recovery...


Why did it trash it?
Y.


On 15 March 2018 at 17:47, Gianluca Cecchi 
wrote:

>
> Il 15 Mar 2018 6:34 PM, "Simone Tiraboschi"  ha
> scritto:
>
>
>
> On Thu, Mar 15, 2018 at 8:18 AM, Yedidyah Bar David 
> wrote:
>
>> On Thu, Mar 15, 2018 at 8:50 AM, Maton, Brett 
>> wrote:
>> > The last three 4.2.2 release candidates that I've tried have been
>> starting
>> > self hosted engine all all physical hosts at the same time.
>> >
>> > Same with the latest RC, what logs  do you need to investigate the
>> problem?
>>
>
> It was this one: https://bugzilla.redhat.com/show_bug.cgi?id=1547479
>
> It got fixed today but still not available in RC4.
>
>
>>
>> /var/log/ovirt-hosted-engine-ha/*
>> /var/log/sanlock.log
>> /var/log/vdsm/*
>>
>> Adding Martin.
>>
>> Thanks and best regards,
>> --
>> Didi
>> __
>
>
> If I understood correctly, this kind of risk is not present in 4.1.x and
> in 4.2.y for every x and for y <= 1?
>
>
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users
>
>

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] 4.2.2.2-1 Starting hosted engine on all hosts

2018-03-16 Thread Maton, Brett
root (/) partition is now unreadable

On 16 March 2018 at 10:04, Yaniv Kaul  wrote:

>
>
> On Mar 15, 2018 9:21 PM, "Maton, Brett"  wrote:
>
> Ok cool, glad you already have enough information as it's trashed my
> hosted-engine beyond recovery...
>
>
> Why did it trash it?
> Y.
>
>
> On 15 March 2018 at 17:47, Gianluca Cecchi 
> wrote:
>
>>
>> Il 15 Mar 2018 6:34 PM, "Simone Tiraboschi"  ha
>> scritto:
>>
>>
>>
>> On Thu, Mar 15, 2018 at 8:18 AM, Yedidyah Bar David 
>> wrote:
>>
>>> On Thu, Mar 15, 2018 at 8:50 AM, Maton, Brett 
>>> wrote:
>>> > The last three 4.2.2 release candidates that I've tried have been
>>> starting
>>> > self hosted engine all all physical hosts at the same time.
>>> >
>>> > Same with the latest RC, what logs  do you need to investigate the
>>> problem?
>>>
>>
>> It was this one: https://bugzilla.redhat.com/show_bug.cgi?id=1547479
>>
>> It got fixed today but still not available in RC4.
>>
>>
>>>
>>> /var/log/ovirt-hosted-engine-ha/*
>>> /var/log/sanlock.log
>>> /var/log/vdsm/*
>>>
>>> Adding Martin.
>>>
>>> Thanks and best regards,
>>> --
>>> Didi
>>> __
>>
>>
>> If I understood correctly, this kind of risk is not present in 4.1.x and
>> in 4.2.y for every x and for y <= 1?
>>
>>
>> ___
>> Users mailing list
>> Users@ovirt.org
>> http://lists.ovirt.org/mailman/listinfo/users
>>
>>
>
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users
>
>
>
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] 4.2.2.2-1 Starting hosted engine on all hosts

2018-03-16 Thread Martin Sivak
>
> Why did it trash it?

Split brain and concurrent filesystem access...

The bug only happened in 4.2.2 and was never released officially apart
from development builds. And it should be fixed now.

Martin

On Fri, Mar 16, 2018 at 11:04 AM, Yaniv Kaul  wrote:
>
>
> On Mar 15, 2018 9:21 PM, "Maton, Brett"  wrote:
>
> Ok cool, glad you already have enough information as it's trashed my
> hosted-engine beyond recovery...
>
>
> Why did it trash it?
> Y.
>
>
> On 15 March 2018 at 17:47, Gianluca Cecchi 
> wrote:
>>
>>
>> Il 15 Mar 2018 6:34 PM, "Simone Tiraboschi"  ha
>> scritto:
>>
>>
>>
>> On Thu, Mar 15, 2018 at 8:18 AM, Yedidyah Bar David 
>> wrote:
>>>
>>> On Thu, Mar 15, 2018 at 8:50 AM, Maton, Brett 
>>> wrote:
>>> > The last three 4.2.2 release candidates that I've tried have been
>>> > starting
>>> > self hosted engine all all physical hosts at the same time.
>>> >
>>> > Same with the latest RC, what logs  do you need to investigate the
>>> > problem?
>>
>>
>> It was this one: https://bugzilla.redhat.com/show_bug.cgi?id=1547479
>>
>> It got fixed today but still not available in RC4.
>>
>>>
>>>
>>> /var/log/ovirt-hosted-engine-ha/*
>>> /var/log/sanlock.log
>>> /var/log/vdsm/*
>>>
>>> Adding Martin.
>>>
>>> Thanks and best regards,
>>> --
>>> Didi
>>> __
>>
>>
>> If I understood correctly, this kind of risk is not present in 4.1.x and
>> in 4.2.y for every x and for y <= 1?
>>
>>
>> ___
>> Users mailing list
>> Users@ovirt.org
>> http://lists.ovirt.org/mailman/listinfo/users
>>
>
>
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users
>
>
>
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users
>
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] 4.2.2.2-1 Starting hosted engine on all hosts

2018-03-16 Thread Maton, Brett
Yup, no big surprise really :)

On 16 March 2018 at 10:21, Martin Sivak  wrote:

> >
> > Why did it trash it?
>
> Split brain and concurrent filesystem access...
>
> The bug only happened in 4.2.2 and was never released officially apart
> from development builds. And it should be fixed now.
>
> Martin
>
> On Fri, Mar 16, 2018 at 11:04 AM, Yaniv Kaul  wrote:
> >
> >
> > On Mar 15, 2018 9:21 PM, "Maton, Brett" 
> wrote:
> >
> > Ok cool, glad you already have enough information as it's trashed my
> > hosted-engine beyond recovery...
> >
> >
> > Why did it trash it?
> > Y.
> >
> >
> > On 15 March 2018 at 17:47, Gianluca Cecchi 
> > wrote:
> >>
> >>
> >> Il 15 Mar 2018 6:34 PM, "Simone Tiraboschi"  ha
> >> scritto:
> >>
> >>
> >>
> >> On Thu, Mar 15, 2018 at 8:18 AM, Yedidyah Bar David 
> >> wrote:
> >>>
> >>> On Thu, Mar 15, 2018 at 8:50 AM, Maton, Brett <
> mat...@ltresources.co.uk>
> >>> wrote:
> >>> > The last three 4.2.2 release candidates that I've tried have been
> >>> > starting
> >>> > self hosted engine all all physical hosts at the same time.
> >>> >
> >>> > Same with the latest RC, what logs  do you need to investigate the
> >>> > problem?
> >>
> >>
> >> It was this one: https://bugzilla.redhat.com/show_bug.cgi?id=1547479
> >>
> >> It got fixed today but still not available in RC4.
> >>
> >>>
> >>>
> >>> /var/log/ovirt-hosted-engine-ha/*
> >>> /var/log/sanlock.log
> >>> /var/log/vdsm/*
> >>>
> >>> Adding Martin.
> >>>
> >>> Thanks and best regards,
> >>> --
> >>> Didi
> >>> __
> >>
> >>
> >> If I understood correctly, this kind of risk is not present in 4.1.x and
> >> in 4.2.y for every x and for y <= 1?
> >>
> >>
> >> ___
> >> Users mailing list
> >> Users@ovirt.org
> >> http://lists.ovirt.org/mailman/listinfo/users
> >>
> >
> >
> > ___
> > Users mailing list
> > Users@ovirt.org
> > http://lists.ovirt.org/mailman/listinfo/users
> >
> >
> >
> > ___
> > Users mailing list
> > Users@ovirt.org
> > http://lists.ovirt.org/mailman/listinfo/users
> >
>
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] Failed to synchronize networks of Provider ovirt-provider-ovn

2018-03-16 Thread Kapetanakis Giannis
Hi,

After upgrading to 4.2.1 I have problems with ovn provider.
I'm getting "Failed to synchronize networks of Provider ovirt-provider-ovn."

I use custom SSL certificate in apache and I guess this is the reason.

I've tried to update ovirt-provider-ovn.conf with
[OVIRT]
#ovirt-ca-file=/etc/pki/ovirt-engine/ca.pem
ovirt-ca-file=/etc/pki/ovirt-engine/apache-ca.pem

but still no go

Any tips on this?

thanks

G
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Failed to synchronize networks of Provider ovirt-provider-ovn

2018-03-16 Thread Kapetanakis Giannis
On 16/03/18 17:40, Kapetanakis Giannis wrote:
> On 16/03/18 15:21, Dominik Holler wrote:
>> On Fri, 16 Mar 2018 12:46:13 +0200
>> Kapetanakis Giannis  wrote:
>>
>>> Hi,
>>>
>>> After upgrading to 4.2.1 I have problems with ovn provider.
>>> I'm getting "Failed to synchronize networks of Provider
>>> ovirt-provider-ovn."
>>>
>>> I use custom SSL certificate in apache and I guess this is the reason.
>>>
>>> I've tried to update ovirt-provider-ovn.conf with
>>> [OVIRT]
>>> #ovirt-ca-file=/etc/pki/ovirt-engine/ca.pem
>>> ovirt-ca-file=/etc/pki/ovirt-engine/apache-ca.pem
>>>
>>> but still no go
> 
>>
>> Would you share the lines in engine.log produced by clicking the "Test"
>> button in the "Edit Provider" dialog?
>> On Clicking the test button, are you asked about "Import provider
>> certificate"?

SORRY wrong provider.

It asks for the cert.
Failed to communicate with the external provider, see log for additional 
details.

2018-03-16 17:44:08,262+02 INFO  
[org.ovirt.engine.core.bll.provider.ImportProviderCertificateCommand] (default 
task-52) [4731d25d-fce3-4408-99ea-8f9d1b5ee5b6] Running command: 
ImportProviderCertificateCommand internal: false. Entities affected :  ID: 
aaa0----123456789aaa Type: SystemAction group 
CREATE_STORAGE_POOL with role type ADMIN
2018-03-16 17:44:08,275+02 INFO  
[org.ovirt.engine.core.dal.dbbroker.auditloghandling.AuditLogDirector] (default 
task-52) [4731d25d-fce3-4408-99ea-8f9d1b5ee5b6] EVENT_ID: 
PROVIDER_CERTIFICATE_IMPORTED(213), Certificate for provider ovirt-provider-ovn 
was imported. (User: admin@internal)
2018-03-16 17:44:08,302+02 INFO  
[org.ovirt.engine.core.bll.provider.TestProviderConnectivityCommand] (default 
task-44) [f4b2c57b-60c7-4ef9-a59f-0c5b22fa0356] Running command: 
TestProviderConnectivityCommand internal: false. Entities affected :  ID: 
aaa0----123456789aaa Type: SystemAction group 
CREATE_STORAGE_POOL with role type ADMIN
2018-03-16 17:44:08,360+02 ERROR 
[org.ovirt.engine.core.bll.provider.network.openstack.BaseNetworkProviderProxy] 
(default task-44) [f4b2c57b-60c7-4ef9-a59f-0c5b22fa0356] Bad Gateway (OpenStack 
response error code: 502)
2018-03-16 17:44:08,360+02 ERROR 
[org.ovirt.engine.core.bll.provider.TestProviderConnectivityCommand] (default 
task-44) [f4b2c57b-60c7-4ef9-a59f-0c5b22fa0356] Command 
'org.ovirt.engine.core.bll.provider.TestProviderConnectivityCommand' failed: 
EngineException: (Failed with error PROVIDER_FAILURE and code 5050)

and in provider log:

2018-03-16 17:45:33,961 requests.packages.urllib3.connectionpool Starting new 
HTTPS connection (1): engine-host
2018-03-16 17:45:33,961 requests.packages.urllib3.connectionpool Starting new 
HTTPS connection (1): engine-host
2018-03-16 17:45:33,966 root [SSL: CERTIFICATE_VERIFY_FAILED] certificate 
verify failed (_ssl.c:579)
Traceback (most recent call last):
  File "/usr/share/ovirt-provider-ovn/handlers/base_handler.py", line 131, in 
_handle_request
method, path_parts, content)
  File "/usr/share/ovirt-provider-ovn/handlers/selecting_handler.py", line 175, 
in handle_request
return self.call_response_handler(handler, content, parameters)
  File "/usr/share/ovirt-provider-ovn/handlers/keystone.py", line 33, in 
call_response_handler
return response_handler(content, parameters)
  File "/usr/share/ovirt-provider-ovn/handlers/keystone_responses.py", line 62, 
in post_tokens
user_password=user_password)
  File "/usr/share/ovirt-provider-ovn/auth/plugin_facade.py", line 26, in 
create_token
return auth.core.plugin.create_token(user_at_domain, user_password)
  File "/usr/share/ovirt-provider-ovn/auth/plugins/ovirt/plugin.py", line 48, 
in create_token
timeout=self._timeout())
  File "/usr/share/ovirt-provider-ovn/auth/plugins/ovirt/sso.py", line 75, in 
create_token
username, password, engine_url, ca_file, timeout)
  File "/usr/share/ovirt-provider-ovn/auth/plugins/ovirt/sso.py", line 91, in 
_get_sso_token
timeout=timeout
  File "/usr/share/ovirt-provider-ovn/auth/plugins/ovirt/sso.py", line 54, in 
wrapper
response = func(*args, **kwargs)
  File "/usr/share/ovirt-provider-ovn/auth/plugins/ovirt/sso.py", line 47, in 
wrapper
raise BadGateway(e)
BadGateway: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed 
(_ssl.c:579)

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Failed to synchronize networks of Provider ovirt-provider-ovn

2018-03-16 Thread Dominik Holler
On Fri, 16 Mar 2018 17:46:36 +0200
Kapetanakis Giannis  wrote:

> On 16/03/18 17:40, Kapetanakis Giannis wrote:
> > On 16/03/18 15:21, Dominik Holler wrote:  
> >> On Fri, 16 Mar 2018 12:46:13 +0200
> >> Kapetanakis Giannis  wrote:
> >>  
> >>> Hi,
> >>>
> >>> After upgrading to 4.2.1 I have problems with ovn provider.
> >>> I'm getting "Failed to synchronize networks of Provider
> >>> ovirt-provider-ovn."
> >>>
> >>> I use custom SSL certificate in apache and I guess this is the
> >>> reason.
> >>>
> >>> I've tried to update ovirt-provider-ovn.conf with
> >>> [OVIRT]
> >>> #ovirt-ca-file=/etc/pki/ovirt-engine/ca.pem
> >>> ovirt-ca-file=/etc/pki/ovirt-engine/apache-ca.pem
> >>>
> >>> but still no go  
> >   
> >>
> >> Would you share the lines in engine.log produced by clicking the
> >> "Test" button in the "Edit Provider" dialog?
> >> On Clicking the test button, are you asked about "Import provider
> >> certificate"?  
> 
> SORRY wrong provider.
> 
> It asks for the cert.
> Failed to communicate with the external provider, see log for
> additional details.
> 
> 2018-03-16 17:44:08,262+02 INFO
> [org.ovirt.engine.core.bll.provider.ImportProviderCertificateCommand]
> (default task-52) [4731d25d-fce3-4408-99ea-8f9d1b5ee5b6] Running
> command: ImportProviderCertificateCommand internal: false. Entities
> affected :  ID: aaa0----123456789aaa Type:
> SystemAction group CREATE_STORAGE_POOL with role type ADMIN
> 2018-03-16 17:44:08,275+02 INFO
> [org.ovirt.engine.core.dal.dbbroker.auditloghandling.AuditLogDirector]
> (default task-52) [4731d25d-fce3-4408-99ea-8f9d1b5ee5b6] EVENT_ID:
> PROVIDER_CERTIFICATE_IMPORTED(213), Certificate for provider
> ovirt-provider-ovn was imported. (User: admin@internal) 2018-03-16
> 17:44:08,302+02 INFO
> [org.ovirt.engine.core.bll.provider.TestProviderConnectivityCommand]
> (default task-44) [f4b2c57b-60c7-4ef9-a59f-0c5b22fa0356] Running
> command: TestProviderConnectivityCommand internal: false. Entities
> affected :  ID: aaa0----123456789aaa Type:
> SystemAction group CREATE_STORAGE_POOL with role type ADMIN
> 2018-03-16 17:44:08,360+02 ERROR
> [org.ovirt.engine.core.bll.provider.network.openstack.BaseNetworkProviderProxy]
> (default task-44) [f4b2c57b-60c7-4ef9-a59f-0c5b22fa0356] Bad Gateway
> (OpenStack response error code: 502) 2018-03-16 17:44:08,360+02 ERROR
> [org.ovirt.engine.core.bll.provider.TestProviderConnectivityCommand]
> (default task-44) [f4b2c57b-60c7-4ef9-a59f-0c5b22fa0356] Command
> 'org.ovirt.engine.core.bll.provider.TestProviderConnectivityCommand'
> failed: EngineException: (Failed with error PROVIDER_FAILURE and code
> 5050)
> 
> and in provider log:
> 
> 2018-03-16 17:45:33,961 requests.packages.urllib3.connectionpool
> Starting new HTTPS connection (1): engine-host 2018-03-16
> 17:45:33,961 requests.packages.urllib3.connectionpool Starting new
> HTTPS connection (1): engine-host 2018-03-16 17:45:33,966 root [SSL:
> CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:579)
> Traceback (most recent call last): File
> "/usr/share/ovirt-provider-ovn/handlers/base_handler.py", line 131,
> in _handle_request method, path_parts, content) File
> "/usr/share/ovirt-provider-ovn/handlers/selecting_handler.py", line
> 175, in handle_request return self.call_response_handler(handler,
> content, parameters) File
> "/usr/share/ovirt-provider-ovn/handlers/keystone.py", line 33, in
> call_response_handler return response_handler(content, parameters)
> File "/usr/share/ovirt-provider-ovn/handlers/keystone_responses.py",
> line 62, in post_tokens user_password=user_password) File
> "/usr/share/ovirt-provider-ovn/auth/plugin_facade.py", line 26, in
> create_token return auth.core.plugin.create_token(user_at_domain,
> user_password) File
> "/usr/share/ovirt-provider-ovn/auth/plugins/ovirt/plugin.py", line
> 48, in create_token timeout=self._timeout()) File
> "/usr/share/ovirt-provider-ovn/auth/plugins/ovirt/sso.py", line 75,
> in create_token username, password, engine_url, ca_file, timeout)
> File "/usr/share/ovirt-provider-ovn/auth/plugins/ovirt/sso.py", line
> 91, in _get_sso_token timeout=timeout File
> "/usr/share/ovirt-provider-ovn/auth/plugins/ovirt/sso.py", line 54,
> in wrapper response = func(*args, **kwargs) File
> "/usr/share/ovirt-provider-ovn/auth/plugins/ovirt/sso.py", line 47,
> in wrapper raise BadGateway(e) BadGateway: [SSL:
> CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:579)
> 

Thanks. Yes, the ovirt-provider-ovn refuses to connect to ovirt-engine
for authentication because ovirt-provider-ovn does not trust the
ssl-certificate and propagates this as the BadGateway error.

Please not that engine-setup creates the file
/etc/ovirt-provider-ovn/conf.d/10-setup-ovirt-provider-ovn.conf
which overwrites the default values from
/etc/ovirt-provider-ovn/ovirt-provider-ovn.conf

If you want to check if the referenced
/etc/pki/ovirt-engine/apache-ca.pem is 

[ovirt-users] Hosted engine : rebuild without backups ?

2018-03-16 Thread spfma . tech
Hi,
   In case of a total failure of the hosted engine VM, it is recommended to 
recreate a new one and restore a backup. I hope it works, I will probably have 
to do this very soon.   But is there some kind of "plug and play" features, 
able to rebuild configuration by browsing storage domains, if the restore 
process doesn't work ?   Something like identifying VMs and their snapshots in 
the subdirectories, and the guess what is linked to what, ... ?I have a few 
machines but if I have to rebuild all the engine setup and content, I would 
like to be able to identify resources easily.   A few times ago, I was doing 
some experiments with XenServer and destroyed/recreated some setup items : I 
ended with a lot of oprhan resources, and it was a mess to reattach snapshots 
to their respective VMs. So if oVirt is more helpful in that way ...   Regards 

-
FreeMail powered by mail.fr
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Failed to synchronize networks of Provider ovirt-provider-ovn

2018-03-16 Thread Kapetanakis Giannis
On 16/03/18 15:21, Dominik Holler wrote:
> On Fri, 16 Mar 2018 12:46:13 +0200
> Kapetanakis Giannis  wrote:
> 
>> Hi,
>>
>> After upgrading to 4.2.1 I have problems with ovn provider.
>> I'm getting "Failed to synchronize networks of Provider
>> ovirt-provider-ovn."
>>
>> I use custom SSL certificate in apache and I guess this is the reason.
>>
>> I've tried to update ovirt-provider-ovn.conf with
>> [OVIRT]
>> #ovirt-ca-file=/etc/pki/ovirt-engine/ca.pem
>> ovirt-ca-file=/etc/pki/ovirt-engine/apache-ca.pem
>>
>> but still no go

> 
> Would you share the lines in engine.log produced by clicking the "Test"
> button in the "Edit Provider" dialog?
> On Clicking the test button, are you asked about "Import provider
> certificate"?
> 


I get ok in test:
Test succeeded, managed to access provider.

2018-03-16 17:35:20,024+02 INFO  
[org.ovirt.engine.core.bll.provider.TestProviderConnectivityCommand] (default 
task-28) [9920f622-b878-45e1-a421-e76c0ab23470] Running command: 
TestProviderConnectivityCommand internal: false. Entities affected :  ID: 
aaa0----123456789aaa Type: SystemAction group 
CREATE_STORAGE_POOL with role type ADMIN

However a little bit later:
ovirt-provider-ovn.log:

2018-03-16 17:37:27,827 requests.packages.urllib3.connectionpool Starting new 
HTTPS connection (1): engine-host
2018-03-16 17:37:27,827 requests.packages.urllib3.connectionpool Starting new 
HTTPS connection (1): engine-host
2018-03-16 17:37:27,832 root [SSL: CERTIFICATE_VERIFY_FAILED] certificate 
verify failed (_ssl.c:579)
Traceback (most recent call last):
  File "/usr/share/ovirt-provider-ovn/handlers/base_handler.py", line 131, in 
_handle_request
method, path_parts, content)
  File "/usr/share/ovirt-provider-ovn/handlers/selecting_handler.py", line 175, 
in handle_request
return self.call_response_handler(handler, content, parameters)
  File "/usr/share/ovirt-provider-ovn/handlers/keystone.py", line 33, in 
call_response_handler
return response_handler(content, parameters)
  File "/usr/share/ovirt-provider-ovn/handlers/keystone_responses.py", line 62, 
in post_tokens
user_password=user_password)
  File "/usr/share/ovirt-provider-ovn/auth/plugin_facade.py", line 26, in 
create_token
return auth.core.plugin.create_token(user_at_domain, user_password)
  File "/usr/share/ovirt-provider-ovn/auth/plugins/ovirt/plugin.py", line 48, 
in create_token
timeout=self._timeout())
  File "/usr/share/ovirt-provider-ovn/auth/plugins/ovirt/sso.py", line 75, in 
create_token
username, password, engine_url, ca_file, timeout)
  File "/usr/share/ovirt-provider-ovn/auth/plugins/ovirt/sso.py", line 91, in 
_get_sso_token
timeout=timeout
  File "/usr/share/ovirt-provider-ovn/auth/plugins/ovirt/sso.py", line 54, in 
wrapper
response = func(*args, **kwargs)
  File "/usr/share/ovirt-provider-ovn/auth/plugins/ovirt/sso.py", line 47, in 
wrapper
raise BadGateway(e)
BadGateway: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed 
(_ssl.c:579)

and in engine log:
2018-03-16 17:37:27,834+02 ERROR 
[org.ovirt.engine.core.bll.provider.network.SyncNetworkProviderCommand] 
(EE-ManagedThreadFactory-engineScheduled-Thread-27) [621c2b23] Command 
'org.ovirt.engine.core.bll.provider.network.SyncNetworkProviderCommand' failed: 
EngineException: (Failed with error PROVIDER_FAILURE and code 5050)
2018-03-16 17:37:27,850+02 ERROR 
[org.ovirt.engine.core.dal.dbbroker.auditloghandling.AuditLogDirector] 
(EE-ManagedThreadFactory-engineScheduled-Thread-27) [621c2b23] EVENT_ID: 
PROVIDER_SYNCHRONIZED_FAILED(216), Failed to synchronize networks of Provider 
ovirt-provider-ovn.

So the engine can talk with ovn but not the other way around as I understand.

I think it might have to do with [SSL] settings of ovirt-provider-ovn.conf

G


___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] Trunk'd Network

2018-03-16 Thread Andy
Community,
I am trying to trunk two VLAN's to a VM on OVIRT 4.2 and all the research/docs 
I have seen is to create a standard VM network and to NOT tag anything.  That 
is "Supposed" to pass all traffic where the attached VM will need to tag said 
traffic.  Everything I have tried has been unsuccessful and I am not seeing any 
traffic pass to the VM.  Has anyone successfully accomplished sending mulitple 
VLAN's downstream (vswitch) to a VM?  On the VMWARE side the 4095 VLAN would 
accomplish this and I can do so in my VMWARE test lab.  
thanks
Andy  
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] VM has been paused due to NO STORAGE SPACE ERROR ?!?!?!?!

2018-03-16 Thread Nicolas Ecarnot

Le 16/03/2018 à 15:48, Alex Crow a écrit :

On 16/03/18 13:46, Nicolas Ecarnot wrote:

Le 16/03/2018 à 13:28, Karli Sjöberg a écrit :



Den 16 mars 2018 12:26 skrev Enrico Becchetti 
:


   Dear All,
    Does someone had seen that error ?


Yes, I experienced it dozens of times on 3.6 (my 4.2 setup has 
insufficient workload to trigger such event).

And in every case, there was no actual lack of space.


    Enrico Becchetti Servizio di Calcolo e Reti
I think I remember something to do with thin provisioning and not 
being able to grow fast enough, so out of space. Are the VM's disk 
thick or thin?


All our storage domains are thin-prov. and served by iSCSI (Equallogic 
PS6xxx and 4xxx).


Enrico, do you know if a bug has been filed about this?

Did the VM remain paused? In my experience the VM just gets temporarily 
paused while the storage is expanded. RH confirmed to me in a ticket 
that this is expected behaviour.


AFAIR, most of them went back up and running by themselves (we had to 
manually some of them from times to times).

The storage side weakness is an interesting trail to follow.
We also experienced this behavior when migrating lots of VMs at once, 
yet using a dedicated storage network.


Being on this mailing list since long, I remember we already discussed 
several times about how some users feel how oVirt can appear sensitive 
to storage latencies. On my side, the site where most of our workload 
resides is still in 3.6, so I can not yet witness the efforts oVirt devs 
have made to cope with this in 4.2 but I'm sure they did.


--
Nicolas ECARNOT
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] dns vm and ovirt

2018-03-16 Thread Christopher Cox

On 03/16/2018 07:58 AM, Nathanaël Blanchet wrote:

Hi all,

I'd need some piece of good practice about dealing a DNS server in or 
out of ovirt.
Until now we never wanted to integrate the DNS vm into ovirt because of 
the strong dependency. if the DNS server fails for any reason, it 
becomes difficult ot join the webadmin (except with a static etc hosts) 
and the nodes may become unvailable if they had been configured with fqdn.
We could consider a DNS failover setup, but in a self hosted engine 
setup (and more globally an hyperconverged setup) , it doesn't make 
sense of setting up a stand alone DNS vm outside of ovirt.


So what about imitating engine vm status in a hosted engine setup? Is 
there a way to install the DNS vm outside of ovirt but on the ovirt host 
(and why not in a HA mode)?
Second option could be installing the named service on the hosted engine 
vm?


Any suggestion or return of experience would be much appreciated.



You are wise to think of this as a dependency problem.  When dealing 
with any "in band" vs. "out of band" type of scenario you want to 
properly address how things work "without" the dependency.


So.. for example, you could maintain a static host table setup for your 
ovirt nodes.  Thus, they could find each other without DNS.  Also, those 
nodes might have an external DNS configured for lookups (something you 
don't own) just so things like updates can happen.


There are risks to everything.  Putting key (normally) out of band 
infrastructure into your oVirt, including the engine, always involves 
more risk.


With that said, if you think about you key infrastructure being as a 
separate oVirt datacenter, it would have things like the "static host" 
maps and such.  Some of the infrastructure VMs housed there could 
include the engine for the "general" datacenters (the ones not providing 
VMs for key infrastructure).  This these "general" purpose datacenters 
would house the normal VMs and use potentially VMs out of the 
"infrastructure" datacenter.  Does that make sense?


It's not unlike how a lot of cloud providers operate.  In fact, one well 
known provider used to house their core cloud infrastructure in VMware 
and use "cheaper" hypervisors for their cloud clients.


Summary:
static confs for infrastructure ovirt datacenter containing key core 
infrastructure VMs (including things like DNS, DHCP, Active Directory, 
and oVirt engines) used by general purpose ovirt datacenters.


Obviously the infrastructure datacenter becomes very important, much 
like your base network and should be thought of as "first" priority, 
much like the network.  And much like the network, depends on some 
kickstarter static configs.

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] dns vm and ovirt

2018-03-16 Thread Nathanaël Blanchet

Thanks for precious advices!

So  it means that people who thought about hosted engine feature didn't 
get into your philosophy of running the engine into a second datacenter



Le 16/03/2018 à 16:48, Christopher Cox a écrit :

On 03/16/2018 07:58 AM, Nathanaël Blanchet wrote:

Hi all,

I'd need some piece of good practice about dealing a DNS server in or 
out of ovirt.
Until now we never wanted to integrate the DNS vm into ovirt because 
of the strong dependency. if the DNS server fails for any reason, it 
becomes difficult ot join the webadmin (except with a static etc 
hosts) and the nodes may become unvailable if they had been 
configured with fqdn.
We could consider a DNS failover setup, but in a self hosted engine 
setup (and more globally an hyperconverged setup) , it doesn't make 
sense of setting up a stand alone DNS vm outside of ovirt.


So what about imitating engine vm status in a hosted engine setup? Is 
there a way to install the DNS vm outside of ovirt but on the ovirt 
host (and why not in a HA mode)?
Second option could be installing the named service on the hosted 
engine vm?


Any suggestion or return of experience would be much appreciated.



You are wise to think of this as a dependency problem.  When dealing 
with any "in band" vs. "out of band" type of scenario you want to 
properly address how things work "without" the dependency.


So.. for example, you could maintain a static host table setup for 
your ovirt nodes.  Thus, they could find each other without DNS. Also, 
those nodes might have an external DNS configured for lookups 
(something you don't own) just so things like updates can happen.


There are risks to everything.  Putting key (normally) out of band 
infrastructure into your oVirt, including the engine, always involves 
more risk.


With that said, if you think about you key infrastructure being as a 
separate oVirt datacenter, it would have things like the "static host" 
maps and such.  Some of the infrastructure VMs housed there could 
include the engine for the "general" datacenters (the ones not 
providing VMs for key infrastructure).  This these "general" purpose 
datacenters would house the normal VMs and use potentially VMs out of 
the "infrastructure" datacenter.  Does that make sense?


It's not unlike how a lot of cloud providers operate.  In fact, one 
well known provider used to house their core cloud infrastructure in 
VMware and use "cheaper" hypervisors for their cloud clients.


Summary:
static confs for infrastructure ovirt datacenter containing key core 
infrastructure VMs (including things like DNS, DHCP, Active Directory, 
and oVirt engines) used by general purpose ovirt datacenters.


Obviously the infrastructure datacenter becomes very important, much 
like your base network and should be thought of as "first" priority, 
much like the network.  And much like the network, depends on some 
kickstarter static configs.

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


--
Nathanaël Blanchet

Supervision réseau
Pôle Infrastrutures Informatiques
227 avenue Professeur-Jean-Louis-Viala
34193 MONTPELLIER CEDEX 5   
Tél. 33 (0)4 67 54 84 55
Fax  33 (0)4 67 54 84 14
blanc...@abes.fr

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Setting up a LDAP conf

2018-03-16 Thread Jose Fernandes
Thanks Machacek!


De: Ondra Machacek 
Enviado: sexta-feira, 16 de março de 2018 12:32:38
Para: Jose Fernandes; users@ovirt.org
Assunto: Re: [ovirt-users] Setting up a LDAP conf

On 03/16/2018 12:26 AM, Jose Fernandes wrote:
> Hello,
>
>
> I have an OpenDJ LDAP server, and I need some help to do query on a
> specific filter search.

I remember I used to setup OpenDJ some time ago, please check this blog
post:

  http://machacekondra.blogspot.cz/2015/05/saml-and-ovirt-35.html

The important part there for you is the file:

  /usr/share/ovirt-engine-extension-aaa-ldap/profiles/opendj.properties

Then you can use it as 'include = ' in authz/authn.

>
>
> We can't figure out how to create a "aaa/profile1.properties" file with
> these configs.
>
>
> This is how we can filter the users with ldapsearch on our ldap server:
>
>
> -H ldaps://server:port-D uid=user,ou=OU,dc=SERVER,dc=com,dc=br -W -b
> ou=aa,dc=bb,dc=cc,dc=dd uid=jose.fernandes
>
>
>   - My configuration does not permit I search the users on base, so I
> need to do this filter on "ou=aa,dc=bb,dc=cc,dc=dd"
>
>   - Port is different from common.
>
>
> Someone can help me to create the config file?
>
>
> Regards,
>
> José Fernandes
>
>
>
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users
>
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Hosted-Engine Agent broken

2018-03-16 Thread Martin Sivak
Hi,

make sure you have at least ovirt-hosted-engine-ha-2.2.1 and the
service was properly restarted.

The situation you are describing can happen when you run older hosted
engine agent with 4.2 ovirt-engine.

It was tracked as: https://bugzilla.redhat.com/1518887

Best regards

Martin Sivak


On Fri, Mar 16, 2018 at 2:09 PM, Sven Achtelik  wrote:
> Hi All,
>
>
>
> after upgrading my engine to 4.2 and upgrading my hosts to the latest
> versions the HA for the hosted engine is not working anymore. The Agent
> fails with the following errors. Did I miss anything while upgrading ? The
> Engine is still running – what would be the correct approach to get the HA
> services up and running ?
>
>
>
> ovirt-ha-agent ovirt_hosted_engine_ha.agent.agent.Agent ERROR Traceback
> (most recent call last):
>
> File
> "/usr/lib/python2.7/site-packages/ovirt_hosted_engine_ha/agent/agent.py",
> line 191, in _run_agent
>
>
> return action(he)
>
> File
> "/usr/lib/python2.7/site-packages/ovirt_hosted_engine_ha/agent/agent.py",
> line 64, in action_proper
>
>
> return he.start_monitoring()
>
> File
> "/usr/lib/python2.7/site-packages/ovirt_hosted_engine_ha/agent/hosted_engine.py",
> line 421, in start_monitoring
>
>
> self._config.refresh_vm_conf()
>
> File
> "/usr/lib/python2.7/site-packages/ovirt_hosted_engine_ha/env/config.py",
> line 496, in refresh_vm_conf
>
>
> content_from_ovf = self._get_vm_conf_content_from_ovf_store()
>
> File
> "/usr/lib/python2.7/site-packages/ovirt_hosted_engine_ha/env/config.py",
> line 438, in _get_vm_conf_content_from_ovf_store
>
>
> conf = ovf2VmParams.confFromOvf(heovf)
>
> File
> "/usr/lib/python2.7/site-packages/ovirt_hosted_engine_ha/lib/ovf/ovf2VmParams.py",
> line 283, in confFromOvf
>
>
> vmConf = toDict(ovf)
>
> File
> "/usr/lib/python2.7/site-packages/ovirt_hosted_engine_ha/lib/ovf/ovf2VmParams.py",
> line 210, in toDict
>
>
> vmParams['vmId'] = tree.find('Content/Section').attrib[OVF_NS + 'id']
>
> File
> "lxml.etree.pyx", line 2272, in lxml.etree._Attrib.__getitem__
> (src/lxml/lxml.etree.c:55336)
>
>
> KeyError: '{http://schemas.dmtf.org/ovf/envelope/1/}id'
>
> ovirt-ha-agent ovirt_hosted_engine_ha.agent.agent.Agent ERROR Trying to
> restart agent
>
> ovirt-ha-agent ovirt_hosted_engine_ha.agent.hosted_engine.HostedEngine ERROR
> Unable to refresh vm.conf from the shared storage. Has this HE cluster
> correctly reached 3.6 level?
>
>
>
> If anyone could give a hint on where to look at would be very helpful.
>
>
>
> Thank you,
>
> Sven
>
>
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users
>
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Failed to synchronize networks of Provider ovirt-provider-ovn

2018-03-16 Thread Dominik Holler
On Fri, 16 Mar 2018 12:46:13 +0200
Kapetanakis Giannis  wrote:

> Hi,
> 
> After upgrading to 4.2.1 I have problems with ovn provider.
> I'm getting "Failed to synchronize networks of Provider
> ovirt-provider-ovn."
> 
> I use custom SSL certificate in apache and I guess this is the reason.
> 
> I've tried to update ovirt-provider-ovn.conf with
> [OVIRT]
> #ovirt-ca-file=/etc/pki/ovirt-engine/ca.pem
> ovirt-ca-file=/etc/pki/ovirt-engine/apache-ca.pem
> 
> but still no go
> 
> Any tips on this?
> 
> thanks
> 
> G
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users

Would you share the lines in engine.log produced by clicking the "Test"
button in the "Edit Provider" dialog?
On Clicking the test button, are you asked about "Import provider
certificate"?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Setting up a LDAP conf

2018-03-16 Thread Ondra Machacek

On 03/16/2018 12:26 AM, Jose Fernandes wrote:

Hello,


I have an OpenDJ LDAP server, and I need some help to do query on a 
specific filter search.


I remember I used to setup OpenDJ some time ago, please check this blog
post:

 http://machacekondra.blogspot.cz/2015/05/saml-and-ovirt-35.html

The important part there for you is the file:

 /usr/share/ovirt-engine-extension-aaa-ldap/profiles/opendj.properties

Then you can use it as 'include = ' in authz/authn.




We can't figure out how to create a "aaa/profile1.properties" file with 
these configs.



This is how we can filter the users with ldapsearch on our ldap server:


-H ldaps://server:port-D uid=user,ou=OU,dc=SERVER,dc=com,dc=br -W -b 
ou=aa,dc=bb,dc=cc,dc=dd uid=jose.fernandes



  - My configuration does not permit I search the users on base, so I 
need to do this filter on "ou=aa,dc=bb,dc=cc,dc=dd"


  - Port is different from common.


Someone can help me to create the config file?


Regards,

José Fernandes



___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] change CD not working

2018-03-16 Thread Alex Crow

On 15/03/18 18:55, Junaid Jadoon wrote:



Ovirt engine and node version are 4.2.

"Error while executing action Change CD: Failed to perform "Change CD" 
operation, CD might be still in use by the VM.
Please try to manually detach the CD from withing the VM:
1. Log in to the VM
2 For Linux VMs, un-mount the CD using umount command;
For Windows VMs, right click on the CD drive and click 'Eject';"

Initially its working fine suddenly it giving above error.

Logs are attached.

please help me out

Regards,

Junaid

Detach and re-attach of the ISO domain should resolve this. It worked 
for me.


Alex

--
This message is intended only for the addressee and may contain
confidential information. Unless you are that person, you may not
disclose its contents or use it in any way and are requested to delete
the message along with any attachments and notify us immediately.
This email is not intended to, nor should it be taken to, constitute advice.
The information provided is correct to our knowledge & belief and must not
be used as a substitute for obtaining tax, regulatory, investment, legal or
any other appropriate advice.

"Transact" is operated by Integrated Financial Arrangements Ltd.
29 Clement's Lane, London EC4N 7AE. Tel: (020) 7608 4900 Fax: (020) 7608 5300.
(Registered office: as above; Registered in England and Wales under
number: 3727592). Authorised and regulated by the Financial Conduct
Authority (entered on the Financial Services Register; no. 190856).___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] VM has been paused due to NO STORAGE SPACE ERROR ?!?!?!?!

2018-03-16 Thread Alex Crow

On 16/03/18 13:46, Nicolas Ecarnot wrote:

Le 16/03/2018 à 13:28, Karli Sjöberg a écrit :



Den 16 mars 2018 12:26 skrev Enrico Becchetti 
:


   Dear All,
    Does someone had seen that error ?


Yes, I experienced it dozens of times on 3.6 (my 4.2 setup has 
insufficient workload to trigger such event).

And in every case, there was no actual lack of space.


    Enrico Becchetti Servizio di Calcolo e Reti
I think I remember something to do with thin provisioning and not 
being able to grow fast enough, so out of space. Are the VM's disk 
thick or thin?


All our storage domains are thin-prov. and served by iSCSI (Equallogic 
PS6xxx and 4xxx).


Enrico, do you know if a bug has been filed about this?

Did the VM remain paused? In my experience the VM just gets temporarily 
paused while the storage is expanded. RH confirmed to me in a ticket 
that this is expected behaviour.


If you need high write performance your VM disks should always be 
preallocated. We only use Thin Provision for VMs where we know that disk 
writes are low (eg network services, CPU-bound apps, etc).


Alex
--
This message is intended only for the addressee and may contain
confidential information. Unless you are that person, you may not
disclose its contents or use it in any way and are requested to delete
the message along with any attachments and notify us immediately.
This email is not intended to, nor should it be taken to, constitute advice.
The information provided is correct to our knowledge & belief and must not
be used as a substitute for obtaining tax, regulatory, investment, legal or
any other appropriate advice.

"Transact" is operated by Integrated Financial Arrangements Ltd.
29 Clement's Lane, London EC4N 7AE. Tel: (020) 7608 4900 Fax: (020) 7608 5300.
(Registered office: as above; Registered in England and Wales under
number: 3727592). Authorised and regulated by the Financial Conduct
Authority (entered on the Financial Services Register; no. 190856).
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Quick question about oVirt 3.6 and vdsm log in DEBUG mode (apprently by default??)

2018-03-16 Thread Christopher Cox

On 03/14/2018 09:10 AM, Christopher Cox wrote:

On 03/14/2018 01:34 AM, Yaniv Kaul wrote:



On Mar 13, 2018 11:48 PM, "Christopher Cox" > wrote:


...snip...


    What we are seeing more and more is that if we do an operation 
like expose a
    new LUN and configure a new storage domain, that all of the 
hyervisors go
    "red triangle" and "Connecting..." and it takes a very long time 
(all day)

    to straighten out.

    My guess is that there's too much to look at vdsm wise and so it's 
waiting a
    short(er) period of time for a completed response than what vdsm 
is going to

    us, and it just cycles over and over until it just happens to work.


Please upgrade. We have solved issues and improved performance and scale
substantially since 3.6.
You may also wish to apply lvm filters.
Y.


Oh, we know and are looking at what we'll have to do to upgrade.  With 
that said, is there more information on what you mentioned as "lvm 
filters" posted somewhere?


Also, would VM reduction, and IMHO, virtual disk reduction help this 
problem?


Is there and engine config parameters that might help as well?

Thanks for any help on this.


Based on a different older thread about having lots of virtual networks 
which sounded somewhat similar, I have increased our vdsTimeout value. 
Any opinions on whether or not that might help?  Right now I'm forced to 
tell my management that we'll have to "roll the dice" to find out.  But 
kind of hoping to hear someone "say" it should help. Anyone?


Just looking for something more substantial...

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] VM has been paused due to NO STORAGE SPACE ERROR ?!?!?!?!

2018-03-16 Thread Enrico Becchetti
yes ... it's a thin provisioning , in fact with preallocated disk type I 
haven't any problem.

Thanks you so much
Best Regards
Enrico

Il 16/03/2018 13:28, Karli Sjöberg ha scritto:



Den 16 mars 2018 12:26 skrev Enrico Becchetti 
:


  Dear All,
Does someone had seen that error ? When I run this command from my
virtual machine:

# time dd if=/dev/zero of=enrico.dd bs=4k count=1000

VM was paused due to kind a storage error/problem. Strange message
because tell about "no storage space error" but ovirt puts virtual
machine in
a paused state.

Inside events  from  ovirt web interface  I see this:

"VM has been paused due to lack of storage space"

but no ERROR found in /var/log/vdsm.log.

My oVirt enviroment 4.2.1 has three hypervivosr with FC storage and
before now
I haven't see any other problem during the normal functioning of
the vm
, it's seem
that this error occurs only when there is massive I/O.

Any ideas ?
Thanks a lot.
Best Regards
Enrico


-- 
___


Enrico Becchetti Servizio di Calcolo e Reti

Istituto Nazionale di Fisica Nucleare - Sezione di Perugia
Via Pascoli,c/o Dipartimento di Fisica 06123 Perugia (ITALY)
Phone:+39 075 5852777 Mail: Enrico.Becchettipg.infn.it
__

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


I think I remember something to do with thin provisioning and not 
being able to grow fast enough, so out of space. Are the VM's disk 
thick or thin?


/K
  Dear All,
Does someone had seen that error ? When I run this command from my
virtual machine:

# time dd if=/dev/zero of=enrico.dd bs=4k count=1000

VM was paused due to kind a storage error/problem. Strange message
because tell about "no storage space error" but ovirt puts virtual
machine in
a paused state.

Inside events  from  ovirt web interface  I see this:

"VM has been paused due to lack of storage space"

but no ERROR found in /var/log/vdsm.log.

My oVirt enviroment 4.2.1 has three hypervivosr with FC storage and
before now
I haven't see any other problem during the normal functioning of the vm
, it's seem
that this error occurs only when there is massive I/O.

Any ideas ?
Thanks a lot.
Best Regards
Enrico

--
___

Enrico Becchetti Servizio di Calcolo e Reti

Istituto Nazionale di Fisica Nucleare - Sezione di Perugia
Via Pascoli,c/o Dipartimento di Fisica 06123 Perugia (ITALY)
Phone:+39 075 5852777 Mail: Enrico.Becchettipg.infn.it
__

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users



--
___

Enrico BecchettiServizio di Calcolo e Reti

Istituto Nazionale di Fisica Nucleare - Sezione di Perugia
Via Pascoli,c/o Dipartimento di Fisica  06123 Perugia (ITALY)
Phone:+39 075 5852777 Mail: Enrico.Becchettipg.infn.it
__

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] Hosted-Engine Agent broken

2018-03-16 Thread Sven Achtelik
Hi All,

after upgrading my engine to 4.2 and upgrading my hosts to the latest  versions 
the HA for the hosted engine is not working anymore. The Agent fails with the 
following errors. Did I miss anything while upgrading ? The Engine is still 
running - what would be the correct approach to get the HA services up and 
running ?

ovirt-ha-agent ovirt_hosted_engine_ha.agent.agent.Agent ERROR Traceback (most 
recent call last):
File 
"/usr/lib/python2.7/site-packages/ovirt_hosted_engine_ha/agent/agent.py", line 
191, in _run_agent
  
return action(he)
File 
"/usr/lib/python2.7/site-packages/ovirt_hosted_engine_ha/agent/agent.py", line 
64, in action_proper
  
return he.start_monitoring()
File 
"/usr/lib/python2.7/site-packages/ovirt_hosted_engine_ha/agent/hosted_engine.py",
 line 421, in start_monitoring
  
self._config.refresh_vm_conf()
File 
"/usr/lib/python2.7/site-packages/ovirt_hosted_engine_ha/env/config.py", line 
496, in refresh_vm_conf
  
content_from_ovf = self._get_vm_conf_content_from_ovf_store()
File 
"/usr/lib/python2.7/site-packages/ovirt_hosted_engine_ha/env/config.py", line 
438, in _get_vm_conf_content_from_ovf_store
  conf 
= ovf2VmParams.confFromOvf(heovf)
File 
"/usr/lib/python2.7/site-packages/ovirt_hosted_engine_ha/lib/ovf/ovf2VmParams.py",
 line 283, in confFromOvf
  
vmConf = toDict(ovf)
File 
"/usr/lib/python2.7/site-packages/ovirt_hosted_engine_ha/lib/ovf/ovf2VmParams.py",
 line 210, in toDict
  
vmParams['vmId'] = tree.find('Content/Section').attrib[OVF_NS + 'id']
File 
"lxml.etree.pyx", line 2272, in lxml.etree._Attrib.__getitem__ 
(src/lxml/lxml.etree.c:55336)
  KeyError: 
'{http://schemas.dmtf.org/ovf/envelope/1/}id'
ovirt-ha-agent ovirt_hosted_engine_ha.agent.agent.Agent ERROR Trying to restart 
agent
ovirt-ha-agent ovirt_hosted_engine_ha.agent.hosted_engine.HostedEngine ERROR 
Unable to refresh vm.conf from the shared storage. Has this HE cluster 
correctly reached 3.6 level?

If anyone could give a hint on where to look at would be very helpful.

Thank you,
Sven
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] dns vm and ovirt

2018-03-16 Thread Nathanaël Blanchet

Hi all,

I'd need some piece of good practice about dealing a DNS server in or 
out of ovirt.
Until now we never wanted to integrate the DNS vm into ovirt because of 
the strong dependency. if the DNS server fails for any reason, it 
becomes difficult ot join the webadmin (except with a static etc hosts) 
and the nodes may become unvailable if they had been configured with fqdn.
We could consider a DNS failover setup, but in a self hosted engine 
setup (and more globally an hyperconverged setup) , it doesn't make 
sense of setting up a stand alone DNS vm outside of ovirt.


So what about imitating engine vm status in a hosted engine setup? Is 
there a way to install the DNS vm outside of ovirt but on the ovirt host 
(and why not in a HA mode)?

Second option could be installing the named service on the hosted engine vm?

Any suggestion or return of experience would be much appreciated.

--
Nathanaël Blanchet

Supervision réseau
Pôle Infrastrutures Informatiques
227 avenue Professeur-Jean-Louis-Viala
34193 MONTPELLIER CEDEX 5   
Tél. 33 (0)4 67 54 84 55
Fax  33 (0)4 67 54 84 14
blanc...@abes.fr

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] VM has been paused due to NO STORAGE SPACE ERROR ?!?!?!?!

2018-03-16 Thread Nicolas Ecarnot

Le 16/03/2018 à 13:28, Karli Sjöberg a écrit :



Den 16 mars 2018 12:26 skrev Enrico Becchetti :

   Dear All,
Does someone had seen that error ?


Yes, I experienced it dozens of times on 3.6 (my 4.2 setup has 
insufficient workload to trigger such event).

And in every case, there was no actual lack of space.


Enrico Becchetti Servizio di Calcolo e Reti
I think I remember something to do with thin provisioning and not being 
able to grow fast enough, so out of space. Are the VM's disk thick or thin?


All our storage domains are thin-prov. and served by iSCSI (Equallogic 
PS6xxx and 4xxx).


Enrico, do you know if a bug has been filed about this?

--
Nicolas ECARNOT
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] dns vm and ovirt

2018-03-16 Thread Christopher Cox



On 03/16/2018 12:28 PM, Nathanaël Blanchet wrote:

Thanks for precious advices!

So  it means that people who thought about hosted engine feature didn't 
get into your philosophy of running the engine into a second datacenter


Again, strictly a "risk" thing.  Hosted engine is by definition a 
"chicken and egg" thing.  It's great for learning and for lab... but if 
you're going to run production, I'd at least consider the latter option 
I presented.


With that said, we run dedicated engines today, not hosted.  Remember, 
ovirt nodes run even while the engine is down.  So you can tolerate an 
engine outage for a time period, just can't have reliability in case of 
node failures, etc.  So for us, most of the risk is in rebuilding a new 
engine if we have to... but certainly considered a "rare" case.


Putting key infrastructure inside the very thing that needs the key 
infrastructure to run is just fraught with problems.


Everything has costs and typically, the more robust/reliable your setup, 
the more it's going to cost.  I just wanted to present an "in between" 
style setup that gives you more reliability, but perhaps not the "best", 
while keeping costs way down.


To me, if you're running any datacenter cluster (for example), you need 
to have a minimum of 3 nodes.  People might not like that, but it's my 
minimum for reliability and flexibility.


So... if wanted to use VMs for core infrastructure, that's 3 nodes. 
That core infrastructure datacenter might have a hosted engine, but 
likely also has "static definitions".  It's part of the "core", at least 
several parts of it are.  But the idea is it could hold: DNS, DHCP, 
Active Directory/LDAP, files shares (even storage domains for other 
datacenters), etc.  Obviously a "core" failure is a "core" failure and 
thus needs the same treatment as whatever you consider to be "core" today.


(thus on total "outage" bring up, you bring up the core, which now
includes this core infrastructure datacenter... your core "tests" are 
run to verify, and then the rest is brought up)


Then each general production datacenter cluster would have 3 nodes with 
the engine(s) being a VM(s) off the infrastructure datacenter using core 
infrastructure off that infrastructure datacenter as well.  Again, this 
is very much like most cloud service providers today.


Again, just ideas, mainly thinking on the "cheap", though some might not 
think so (you'll just have to trust me, what I'm presenting here is

incredibly cheap for the reliability and flexibility it provides).

Just my opinion.
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Failed to synchronize networks of Provider ovirt-provider-ovn

2018-03-16 Thread Kapetanakis Giannis

On 17/03/18 01:20, Kapetanakis Giannis wrote:

On 16/03/18 18:40, Dominik Holler wrote:

Thanks. Yes, the ovirt-provider-ovn refuses to connect to ovirt-engine
for authentication because ovirt-provider-ovn does not trust the
ssl-certificate and propagates this as the BadGateway error.

Please not that engine-setup creates the file
/etc/ovirt-provider-ovn/conf.d/10-setup-ovirt-provider-ovn.conf
which overwrites the default values from
/etc/ovirt-provider-ovn/ovirt-provider-ovn.conf


Thanks,

I didn't notice the conf.d dir.
Changing ovirt-ca-file there fixed it

regards,

G 


In advance, it would make sense to change the default to
/etc/pki/ovirt-engine/apache-ca.pem
since by default it's a symlink to ca.pem (which is now the default)

So default/custom cert would all work

G
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Failed to synchronize networks of Provider ovirt-provider-ovn

2018-03-16 Thread Kapetanakis Giannis

On 16/03/18 18:40, Dominik Holler wrote:

Thanks. Yes, the ovirt-provider-ovn refuses to connect to ovirt-engine
for authentication because ovirt-provider-ovn does not trust the
ssl-certificate and propagates this as the BadGateway error.

Please not that engine-setup creates the file
/etc/ovirt-provider-ovn/conf.d/10-setup-ovirt-provider-ovn.conf
which overwrites the default values from
/etc/ovirt-provider-ovn/ovirt-provider-ovn.conf


Thanks,

I didn't notice the conf.d dir.
Changing ovirt-ca-file there fixed it

regards,

G
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] ovirt node pxe and thinpool errror in status

2018-03-16 Thread Gianluca Cecchi
Hello,
I'm experimenting to install ovirt ng node 4.2 via pxe and it seems all
went ok.
Only problem I have is that opening terminal session I get this traceback
that seems related to thinpool

Traceback (most recent call last):
  File "/usr/lib64/python2.7/runpy.py", line 162, in
_run_module_as_main
"__main__", fname, loader, pkg_name)
  File "/usr/lib64/python2.7/runpy.py", line 72, in _run_code
exec code in run_globals
  File "/usr/lib/python2.7/site-packages/nodectl/__main__.py", line
42, in 
CliApplication()
  File "/usr/lib/python2.7/site-packages/nodectl/__init__.py", line
200, in CliApplication
return cmdmap.command(args)
  File "/usr/lib/python2.7/site-packages/nodectl/__init__.py", line
118, in command
return self.commands[command](**kwargs)
  File "/usr/lib/python2.7/site-packages/nodectl/__init__.py", line
101, in motd
Motd(Status(Health(self.imgbased).status(),
  File "/usr/lib/python2.7/site-packages/imgbased/plugins/core.py",
line 358, in status
status.results.append(group().run())
  File "/usr/lib/python2.7/site-packages/imgbased/plugins/core.py",
line 385, in check_thin
pool = self.app.imgbase._thinpool()
  File "/usr/lib/python2.7/site-packages/imgbased/imgbase.py", line
120, in _thinpool
return LVM.Thinpool.from_tag(self.thinpool_tag)
  File "/usr/lib/python2.7/site-packages/imgbased/lvm.py", line 191,
in from_tag
assert len(lvs) == 1
AssertionError
Admin Console: https://192.168.122.196:9090/


[root@localhost ~]#

Current disk layout is

[root@localhost ~]# fdisk -l /dev/vda

Disk /dev/vda: 53.7 GB, 53687091200 bytes, 104857600 sectors
Units = sectors of 1 * 512 = 512 bytes
Sector size (logical/physical): 512 bytes / 512 bytes
I/O size (minimum/optimal): 512 bytes / 512 bytes
Disk label type: dos
Disk identifier: 0x000a3595

   Device Boot  Start End  Blocks   Id  System
/dev/vda1   *2048 2099199 1048576   83  Linux
/dev/vda2 2099200   10485759951379200   8e  Linux LVM

[root@localhost ~]# pvs
  PV VG Fmt  Attr PSize   PFree
  /dev/vda2  centos lvm2 a--  <49.00g 9.80g

[root@localhost ~]# vgs
  VG #PV #LV #SN Attr   VSize   VFree
  centos   1   3   0 wz--n- <49.00g 9.80g

[root@localhost ~]# lvs
  LV VG Attr   LSize   Pool   Origin Data%  Meta%  Move Log
Cpy%Sync Convert
  pool00 centos twi-aotz-- <34.16g   10.28
9.18
  root   centos Vwi-aotz-- <34.16g pool00
10.28
  swap   centos -wi-ao
5.00g
[root@localhost ~]#

Any hint?

I installed from 4.2 iso and then applied the
ovirt-node-ng-image-update-4.2.1.1-1.el7.centos.noarch yum update
The problem remains

At the moment it is not linked with any engine, also installed.
I can go to the Admin Console web page and I see, clicking inside
"Virtualization" left tab, that on the right dashboard I have a yellow
triangle to the right of the "Health" word...
But I don't exactly understand the source of the warning...

Thanks for any hint related,

Gianluca
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] VM has been paused due to NO STORAGE SPACE ERROR ?!?!?!?!

2018-03-16 Thread Enrico Becchetti

  Dear All,
Does someone had seen that error ? When I run this command from my 
virtual machine:


# time dd if=/dev/zero of=enrico.dd bs=4k count=1000

VM was paused due to kind a storage error/problem. Strange message
because tell about "no storage space error" but ovirt puts virtual 
machine in

a paused state.

Inside events  from  ovirt web interface  I see this:

"VM has been paused due to lack of storage space"

but no ERROR found in /var/log/vdsm.log.

My oVirt enviroment 4.2.1 has three hypervivosr with FC storage and 
before now
I haven't see any other problem during the normal functioning of the vm 
, it's seem

that this error occurs only when there is massive I/O.

Any ideas ?
Thanks a lot.
Best Regards
Enrico


--
___

Enrico BecchettiServizio di Calcolo e Reti

Istituto Nazionale di Fisica Nucleare - Sezione di Perugia
Via Pascoli,c/o Dipartimento di Fisica  06123 Perugia (ITALY)
Phone:+39 075 5852777 Mail: Enrico.Becchettipg.infn.it
__

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users