Re: [ovirt-users] Some questions about Ovirt REST API

2018-04-12 Thread gss...@pku.edu.cn
Do you mean @override getMytestsResource()  in BackendVmResource ?
I have done that, otherwise GET would not pass.
From: Ondra Machacek
Date: 2018-04-12 15:43
To: gss...@pku.edu.cn; users
Subject: Re: [ovirt-users] Some questions about Ovirt REST API
 
 
On 04/11/2018 08:19 AM, gss...@pku.edu.cn wrote:
> Hi,
> 
> I wants to creating my own service under ../vms/{vmid}/myservice.Here is 
> my methods:
> 
> 1. create VmMytestService in 
> /https://github.com/oVirt/ovirt-engine-api-model project./
> add/@Service VmMytestService mytests() in /VmService .java
> 2. mvn install it and change the root pom.xml 
> /4.3.9-SNAPSHOT / in my Ovirt project.
> 3.create BackendVmMytestService implements VmMytestResource
 
Did you also in BackendVmResource implemented 'mytests' method?
 
> 4.override /get() and add() /methods.
> 
> After that, I use /curl/  tool to send GET and POST request. GET is 
> working and return.
> However, I get this return after POST request.
> 
> Would you help me with that issue?
> 
> Thanks,
> wenzt
> 
> 
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users
> 
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Some questions about Ovirt REST API

2018-04-12 Thread gss...@pku.edu.cn
Sure.
I override get() and add() in my BackendVmMytestsResource.java
GET works and POST not.
 
From: Ondra Machacek
Date: 2018-04-12 16:25
To: gss...@pku.edu.cn; users
Subject: Re: [ovirt-users] Some questions about Ovirt REST API
Ah sorry, POST isn't working and GET works, I misread it.
 
Can you please share the generated file:
 
{project_path}/backend/manager/modules/restapi/interface/definition/target/generated-sources/model/org/ovirt/engine/api/resource/VmMytestResource.java
 
Maybe you can even send patches to review as draft for start, we could
better understand the patch then.
 
On 04/12/2018 10:14 AM, gss...@pku.edu.cn wrote:
> Do you mean /@override/ /getMytestsResource() / in BackendVmResource ?
> I have done that, otherwise GET would not pass.
> 
> *From:* Ondra Machacek 
> *Date:* 2018-04-12 15:43
> *To:* gss...@pku.edu.cn ; users
> 
> *Subject:* Re: [ovirt-users] Some questions about Ovirt REST API
> On 04/11/2018 08:19 AM, gss...@pku.edu.cn wrote:
>  > Hi,
>  >
>  > I wants to creating my own service under
> ../vms/{vmid}/myservice.Here is
>  > my methods:
>  >
>  > 1. create VmMytestService in
>  > /https://github.com/oVirt/ovirt-engine-api-model project./
>  > add/@Service VmMytestService mytests() in /VmService .java
>  > 2. mvn install it and change the root pom.xml
>  > /4.3.9-SNAPSHOT / in my Ovirt project.
>  > 3.create BackendVmMytestService implements VmMytestResource
> Did you also in BackendVmResource implemented 'mytests' method?
>  > 4.override /get() and add() /methods.
>  >
>  > After that, I use /curl/  tool to send GET and POST request. GET is
>  > working and return.
>  > However, I get this return after POST request.
>  >
>  > Would you help me with that issue?
>  >
>  > Thanks,
>  > wenzt
>  >
>  >
>  > ___
>  > Users mailing list
>  > Users@ovirt.org
>  > http://lists.ovirt.org/mailman/listinfo/users
>  >
> 


VmMytestResource.java
Description: Binary data
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] How to build ovirt-engine-appliance-xxx.rpm

2018-04-12 Thread Yedidyah Bar David
On Thu, Apr 12, 2018 at 4:12 AM,   wrote:
> Hi
>  How to build ovirt-engine-appliance-xxx.rpm,  I do not find docs and source
>  now I hava build ovirt-engine-appliance.ova by ovirt-appliance.

Check the automation/ directory inside the ovirt-appliance git repo.
This is how it's done in CI.
You can see the results e.g. here:

http://jenkins.ovirt.org/job/ovirt-appliance_master_build-artifacts-el7-x86_64/lastSuccessfulBuild/artifact/

>
>  someone give me some advise?
>
>  thanks
>
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users
>



-- 
Didi
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] admin account constantly gets locked

2018-04-12 Thread Käfer Marcel
Hello,

a few days ago I installed an ovirt-engine 4.2.2.6 following the steps of the 
documentation. After the installation I logged in to the admin page, configured 
a datadomain and changed the admin password. After a few hours I tried to login 
again, using the new password and got "Unable to log in because the user 
account is disabled or locked. Contact the system administrator." So I unlocked 
the admin account from the shell using "ovirt-aaa-jdbc-tool user unlock admin" 
which worked fine and I was able to continue working till the next login.

I traced the /var/log/ovirt-engine/engine.log and found this after unlocking 
the admin account again.

2018-04-12 09:06:19,984+02 INFO  
[org.ovirt.engine.core.bll.provider.network.SyncNetworkProviderCommand] 
(EE-ManagedThreadFactory-engineScheduled-Thread-87) [2ed5aa42] Lock Acquired to 
object 
'EngineLock:{exclusiveLocks='[e37c0b9e-09bc-4893-9b0c-c70f56d6ecfc=PROVIDER]', 
sharedLocks=''}'
2018-04-12 09:06:19,991+02 INFO  
[org.ovirt.engine.core.bll.provider.network.SyncNetworkProviderCommand] 
(EE-ManagedThreadFactory-engineScheduled-Thread-87) [2ed5aa42] Running command: 
SyncNetworkProviderCommand internal: true.
2018-04-12 09:06:20,102+02 INFO  
[org.ovirt.engine.extension.aaa.jdbc.core.Authentication] (default task-239) [] 
locking user: admin due to interval failures
2018-04-12 09:06:25,046+02 ERROR [org.ovirt.engine.core.sso.utils.SsoUtils] 
(default task-239) [] OAuthException access_denied: Cannot authenticate user 
'admin@internal': The username or password is incorrect..
2018-04-12 09:06:25,049+02 ERROR 
[org.ovirt.engine.core.bll.provider.network.SyncNetworkProviderCommand] 
(EE-ManagedThreadFactory-engineScheduled-Thread-87) [2ed5aa42] Command 
'org.ovirt.engine.core.bll.provider.network.SyncNetworkProviderCommand' failed: 
EngineException: (Failed with error Unauthorized and code 5050)
2018-04-12 09:06:25,050+02 INFO  
[org.ovirt.engine.core.bll.provider.network.SyncNetworkProviderCommand] 
(EE-ManagedThreadFactory-engineScheduled-Thread-87) [2ed5aa42] Lock freed to 
object 
'EngineLock:{exclusiveLocks='[e37c0b9e-09bc-4893-9b0c-c70f56d6ecfc=PROVIDER]', 
sharedLocks=''}'

It seems like the SyncNetworkProviderCommand is somehow locking the admin 
account. I already restarted the whole machine but it didn't help.

Can someone please point me in the right direction, where to find the error?

Thanks in advance
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Engine reports

2018-04-12 Thread Peter Hudec
back to this issue.

something went wrong ;( The status command got error. I'm not familiar
with openshift, so the log processing will took me a while.

[PROD] r...@dipostat01.cnc.sk: ~ # oc project logging
Already on project "logging" on server "https://metrics.ovirt.cnc.sk:8443;.
[PROD] r...@dipostat01.cnc.sk: ~ # oc adm policy add-scc-to-user
hostmount-anyuid \
>   system:serviceaccount:logging:aggregated-logging-elasticsearch
scc "hostmount-anyuid" added to:
["system:serviceaccount:logging:aggregated-logging-elasticsearch"]
[PROD] r...@dipostat01.cnc.sk: ~ # oc rollout cancel $( oc get -n
logging dc -l component=es -o name )
No rollout is in progress (latest rollout #2 failed 3 days ago)
[PROD] r...@dipostat01.cnc.sk: ~ # oc rollout latest $( oc get -n
logging dc -l component=es -o name )
deploymentconfig "logging-es-data-master-z6zbv4v2" rolled out
[PROD] r...@dipostat01.cnc.sk: ~ #  oc rollout status -w $( oc get -n
logging dc -l component=es -o name )
Waiting for rollout to finish: 0 of 1 updated replicas are available...
error: replication controller "logging-es-data-master-z6zbv4v2-3" has
failed progressing


[PROD] r...@dipostat01.cnc.sk: ~ # oc get pods
NAME   READY STATUSRESTARTS
 AGE
logging-curator-1-c894f1/1   Running   9045d
logging-es-data-master-z6zbv4v2-2-deploy   0/1   Error 0  3d
logging-fluentd-x9vzs  1/1   Running   1  5d
logging-kibana-1-6bvvw 2/2   Running   2  5d
logging-mux-1-xxmdj1/1   Running   1  5d
[PROD] r...@dipostat01.cnc.sk: ~ # oc get pods
NAME   READY STATUSRESTARTS
 AGE
logging-curator-1-c894f1/1   Running   9045d
logging-es-data-master-z6zbv4v2-2-deploy   0/1   Error 0  3d
logging-fluentd-x9vzs  1/1   Running   1  5d
logging-kibana-1-6bvvw 2/2   Running   2  5d
logging-mux-1-xxmdj1/1   Running   1  5d
[PROD] r...@dipostat01.cnc.sk: ~ # oc get pods
NAME   READY STATUSRESTARTS
 AGE
logging-curator-1-c894f1/1   Running   9045d
logging-es-data-master-z6zbv4v2-2-deploy   0/1   Error 0  3d
logging-fluentd-x9vzs  1/1   Running   1  5d
logging-kibana-1-6bvvw 2/2   Running   2  5d
logging-mux-1-xxmdj1/1   Running   1  5d
[PROD] r...@dipostat01.cnc.sk: ~ # oc get svc
NAMETYPECLUSTER-IP   EXTERNAL-IP
PORT(S) AGE
logging-es  ClusterIP   172.30.249.174   
9200/TCP5d
logging-es-cluster  ClusterIP   172.30.114.201   
9300/TCP5d
logging-es-prometheus   ClusterIP   172.30.203.113   
443/TCP 5d
logging-kibana  ClusterIP   172.30.29.192
443/TCP 5d
logging-mux ClusterIP   172.30.170.158   192.168.16.17
24284/TCP   5d


On 07/04/2018 01:09, Rich Megginson wrote:
> Great!
> 
> On 04/06/2018 04:43 PM, Peter Hudec wrote:
>> Ansible playbook finished OK. The next step after weekend.
>>
>> thanks
>>     Peter
>>
>> On 06/04/2018 23:34, Rich Megginson wrote:
>>> On 04/06/2018 03:08 PM, Peter Hudec wrote:
 Hi,

 https://tools.apps.hudecof.net/paste/view/1d493d52

 The difference is
 - I used latest ansible 2.5 from PIPY source, since the RPM package do
 not fit requirements
 - I used GIT repo for openshift-ansible.

 I could start it over with the RPM based openshift-ansible
>>> I recommend that you start over with the RPM based openshift-ansible,
>>> which is what the instructions say, which is what I have tested
>>>
>>> alternately - if you want to go the more experimental route, you could
>>> enable the epel-testing yum repo - ansible-2.5 is in epel-testing which
>>> I've been told by the openshift-ansible guys should work
>>>
  Peter

 On 06/04/2018 20:23, Rich Megginson wrote:
> I'm assuming you are running on a CentOS7 machine, recently updated to
> the latest base packages. Please confirm.
>
> Please provide the output of the following commands:
>
> sudo yum repolist
>
> sudo rpm -q ansible
>
> sudo yum repoquery -i ansible
>
> sudo rpm -q openshift-ansible
>
> sudo yum repoquery -i openshift-ansible
>
> sudo rpm -q origin
>
> sudo yum repoquery -i origin
>
> sudo cat
> /usr/share/ansible/openshift-ansible/roles/lib_utils/callback_plugins/aa_version_requirement.py
>
>
>
>
> sudo ls -alrtF /etc/origin/logging
>
> Please confirm that you followed the steps listed in the link below,
> including the use of the ansible inventory, vars.yaml.template, and

Re: [ovirt-users] Some questions about Ovirt REST API

2018-04-12 Thread Ondra Machacek



On 04/11/2018 08:19 AM, gss...@pku.edu.cn wrote:

Hi,

I wants to creating my own service under ../vms/{vmid}/myservice.Here is 
my methods:


1. create VmMytestService in 
/https://github.com/oVirt/ovirt-engine-api-model project./

add/@Service VmMytestService mytests() in /VmService .java
2. mvn install it and change the root pom.xml 
/4.3.9-SNAPSHOT / in my Ovirt project.

3.create BackendVmMytestService implements VmMytestResource


Did you also in BackendVmResource implemented 'mytests' method?


4.override /get() and add() /methods.

After that, I use /curl/  tool to send GET and POST request. GET is 
working and return.

However, I get this return after POST request.

Would you help me with that issue?

Thanks,
wenzt


___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] How to build ovirt-engine-appliance-xxx.rpm

2018-04-12 Thread Barak Korren
On 12 April 2018 at 10:17, Yedidyah Bar David  wrote:
> On Thu, Apr 12, 2018 at 4:12 AM,   wrote:
>> Hi
>>  How to build ovirt-engine-appliance-xxx.rpm,  I do not find docs and source
>>  now I hava build ovirt-engine-appliance.ova by ovirt-appliance.
>
> Check the automation/ directory inside the ovirt-appliance git repo.
> This is how it's done in CI.
> You can see the results e.g. here:
>
> http://jenkins.ovirt.org/job/ovirt-appliance_master_build-artifacts-el7-x86_64/lastSuccessfulBuild/artifact/
>
>>
>>  someone give me some advise?
>>

You can also use the `mock_runner.sh` tool [1] to emulate what the CI
does locally. This would work for any oVirt project.

[1]: 
http://ovirt-infra-docs.readthedocs.io/en/latest/CI/Using_mock_runner/index.html


-- 
Barak Korren
RHV DevOps team , RHCE, RHCi
Red Hat EMEA
redhat.com | TRIED. TESTED. TRUSTED. | redhat.com/trusted
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Some questions about Ovirt REST API

2018-04-12 Thread Ondra Machacek

Ah sorry, POST isn't working and GET works, I misread it.

Can you please share the generated file:

{project_path}/backend/manager/modules/restapi/interface/definition/target/generated-sources/model/org/ovirt/engine/api/resource/VmMytestResource.java

Maybe you can even send patches to review as draft for start, we could
better understand the patch then.

On 04/12/2018 10:14 AM, gss...@pku.edu.cn wrote:

Do you mean /@override/ /getMytestsResource() / in BackendVmResource ?
I have done that, otherwise GET would not pass.

*From:* Ondra Machacek 
*Date:* 2018-04-12 15:43
*To:* gss...@pku.edu.cn ; users

*Subject:* Re: [ovirt-users] Some questions about Ovirt REST API
On 04/11/2018 08:19 AM, gss...@pku.edu.cn wrote:
 > Hi,
 >
 > I wants to creating my own service under
../vms/{vmid}/myservice.Here is
 > my methods:
 >
 > 1. create VmMytestService in
 > /https://github.com/oVirt/ovirt-engine-api-model project./
 > add/@Service VmMytestService mytests() in /VmService .java
 > 2. mvn install it and change the root pom.xml
 > /4.3.9-SNAPSHOT / in my Ovirt project.
 > 3.create BackendVmMytestService implements VmMytestResource
Did you also in BackendVmResource implemented 'mytests' method?
 > 4.override /get() and add() /methods.
 >
 > After that, I use /curl/  tool to send GET and POST request. GET is
 > working and return.
 > However, I get this return after POST request.
 >
 > Would you help me with that issue?
 >
 > Thanks,
 > wenzt
 >
 >
 > ___
 > Users mailing list
 > Users@ovirt.org
 > http://lists.ovirt.org/mailman/listinfo/users
 >


___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] admin account constantly gets locked

2018-04-12 Thread Eitan Raviv
The sync network command is probably unrelated.
Can you attach the full engine and the setup logs?

Martin, this looks a bit like [1]. Any idea?

Thanks


[1] https://bugzilla.redhat.com/show_bug.cgi?id=1410955

On Thu, Apr 12, 2018 at 10:22 AM, Käfer Marcel 
wrote:

> Hello,
>
> a few days ago I installed an ovirt-engine 4.2.2.6 following the steps of
> the documentation. After the installation I logged in to the admin page,
> configured a datadomain and changed the admin password. After a few hours I
> tried to login again, using the new password and got "Unable to log in
> because the user account is disabled or locked. Contact the system
> administrator." So I unlocked the admin account from the shell using
> "ovirt-aaa-jdbc-tool user unlock admin" which worked fine and I was able to
> continue working till the next login.
>
> I traced the /var/log/ovirt-engine/engine.log and found this after
> unlocking the admin account again.
>
> 2018-04-12 09:06:19,984+02 INFO  [org.ovirt.engine.core.bll.
> provider.network.SyncNetworkProviderCommand] 
> (EE-ManagedThreadFactory-engineScheduled-Thread-87)
> [2ed5aa42] Lock Acquired to object 'EngineLock:{exclusiveLocks='[
> e37c0b9e-09bc-4893-9b0c-c70f56d6ecfc=PROVIDER]', sharedLocks=''}'
> 2018-04-12 09:06:19,991+02 INFO  [org.ovirt.engine.core.bll.
> provider.network.SyncNetworkProviderCommand] 
> (EE-ManagedThreadFactory-engineScheduled-Thread-87)
> [2ed5aa42] Running command: SyncNetworkProviderCommand internal: true.
> 2018-04-12 09:06:20,102+02 INFO  
> [org.ovirt.engine.extension.aaa.jdbc.core.Authentication]
> (default task-239) [] locking user: admin due to interval failures
> 2018-04-12 09:06:25,046+02 ERROR [org.ovirt.engine.core.sso.utils.SsoUtils]
> (default task-239) [] OAuthException access_denied: Cannot authenticate
> user 'admin@internal': The username or password is incorrect..
> 2018-04-12 09:06:25,049+02 ERROR [org.ovirt.engine.core.bll.
> provider.network.SyncNetworkProviderCommand] 
> (EE-ManagedThreadFactory-engineScheduled-Thread-87)
> [2ed5aa42] Command 
> 'org.ovirt.engine.core.bll.provider.network.SyncNetworkProviderCommand'
> failed: EngineException: (Failed with error Unauthorized and code 5050)
> 2018-04-12 09:06:25,050+02 INFO  [org.ovirt.engine.core.bll.
> provider.network.SyncNetworkProviderCommand] 
> (EE-ManagedThreadFactory-engineScheduled-Thread-87)
> [2ed5aa42] Lock freed to object 'EngineLock:{exclusiveLocks='[
> e37c0b9e-09bc-4893-9b0c-c70f56d6ecfc=PROVIDER]', sharedLocks=''}'
>
> It seems like the SyncNetworkProviderCommand is somehow locking the admin
> account. I already restarted the whole machine but it didn't help.
>
> Can someone please point me in the right direction, where to find the
> error?
>
> Thanks in advance
>
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users
>
>


-- 
Eitan Raviv
IRC: erav (#ovirt #vdsm #devel #rhev-dev)
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Some questions about Ovirt REST API

2018-04-12 Thread gss...@pku.edu.cn
Sorry for one more question.

I want add an Action like .../vms/{vm:ID}/myaction
So,
1. I add api in api-model project and mvn clean install.
2. After mvn clean install my ovirt engine project. I get the generated file : 
VmResource
In that file I get 
 
Question: I cant find href  'myaction'   in GET request feedback.xml  

I must have misunderstood sth.

 
From: Ondra Machacek
Date: 2018-04-12 16:25
To: gss...@pku.edu.cn; users
Subject: Re: [ovirt-users] Some questions about Ovirt REST API
Ah sorry, POST isn't working and GET works, I misread it.
 
Can you please share the generated file:
 
{project_path}/backend/manager/modules/restapi/interface/definition/target/generated-sources/model/org/ovirt/engine/api/resource/VmMytestResource.java
 
Maybe you can even send patches to review as draft for start, we could
better understand the patch then.
 
On 04/12/2018 10:14 AM, gss...@pku.edu.cn wrote:
> Do you mean /@override/ /getMytestsResource() / in BackendVmResource ?
> I have done that, otherwise GET would not pass.
> 
> *From:* Ondra Machacek 
> *Date:* 2018-04-12 15:43
> *To:* gss...@pku.edu.cn ; users
> 
> *Subject:* Re: [ovirt-users] Some questions about Ovirt REST API
> On 04/11/2018 08:19 AM, gss...@pku.edu.cn wrote:
>  > Hi,
>  >
>  > I wants to creating my own service under
> ../vms/{vmid}/myservice.Here is
>  > my methods:
>  >
>  > 1. create VmMytestService in
>  > /https://github.com/oVirt/ovirt-engine-api-model project./
>  > add/@Service VmMytestService mytests() in /VmService .java
>  > 2. mvn install it and change the root pom.xml
>  > /4.3.9-SNAPSHOT / in my Ovirt project.
>  > 3.create BackendVmMytestService implements VmMytestResource
> Did you also in BackendVmResource implemented 'mytests' method?
>  > 4.override /get() and add() /methods.
>  >
>  > After that, I use /curl/  tool to send GET and POST request. GET is
>  > working and return.
>  > However, I get this return after POST request.
>  >
>  > Would you help me with that issue?
>  >
>  > Thanks,
>  > wenzt
>  >
>  >
>  > ___
>  > Users mailing list
>  > Users@ovirt.org
>  > http://lists.ovirt.org/mailman/listinfo/users
>  >
> 
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] admin account constantly gets locked

2018-04-12 Thread Martin Perina
On Thu, Apr 12, 2018 at 12:44 PM, Eitan Raviv  wrote:

> The recurring denied access for every SyncNetworkProvider might be because
> you changed the admin password on the engine but not on the provider.
>
> Dominik, will updating to the same password on the provider solve the
> denied access?
> Martin, does the engine lock out the admin user for failed retries?
>

​Of course, after 5 incorrect logins the account is locked. But I looked at
logs and I can't see any login errors, so currently trying to reproduce to
find out what's going on ...
​


>
>
> HTH
>
>
> On Thu, Apr 12, 2018 at 12:29 PM, Käfer Marcel  > wrote:
>
>> Here are the logfiles…
>>
>>
>>
>> Thanks
>>
>>
>>
>> *Von:* Eitan Raviv [mailto:era...@redhat.com]
>> *Gesendet:* Donnerstag, 12. April 2018 11:12
>> *An:* Käfer Marcel
>> *Cc:* users@ovirt.org; Martin Perina
>> *Betreff:* Re: [ovirt-users] admin account constantly gets locked
>>
>>
>>
>> The sync network command is probably unrelated.
>>
>> Can you attach the full engine and the setup logs?
>>
>> Martin, this looks a bit like [1]. Any idea?
>>
>> Thanks
>>
>>
>>
>> [1] https://bugzilla.redhat.com/show_bug.cgi?id=1410955
>>
>>
>>
>> On Thu, Apr 12, 2018 at 10:22 AM, Käfer Marcel <
>> marcel.kae...@putzbrunn.de> wrote:
>>
>> Hello,
>>
>> a few days ago I installed an ovirt-engine 4.2.2.6 following the steps of
>> the documentation. After the installation I logged in to the admin page,
>> configured a datadomain and changed the admin password. After a few hours I
>> tried to login again, using the new password and got "Unable to log in
>> because the user account is disabled or locked. Contact the system
>> administrator." So I unlocked the admin account from the shell using
>> "ovirt-aaa-jdbc-tool user unlock admin" which worked fine and I was able to
>> continue working till the next login.
>>
>> I traced the /var/log/ovirt-engine/engine.log and found this after
>> unlocking the admin account again.
>>
>> 2018-04-12 09:06:19,984+02 INFO  [org.ovirt.engine.core.bll.pro
>> vider.network.SyncNetworkProviderCommand] 
>> (EE-ManagedThreadFactory-engineScheduled-Thread-87)
>> [2ed5aa42] Lock Acquired to object 'EngineLock:{exclusiveLocks='[
>> e37c0b9e-09bc-4893-9b0c-c70f56d6ecfc=PROVIDER]', sharedLocks=''}'
>> 2018-04-12 09:06:19,991+02 INFO  [org.ovirt.engine.core.bll.pro
>> vider.network.SyncNetworkProviderCommand] 
>> (EE-ManagedThreadFactory-engineScheduled-Thread-87)
>> [2ed5aa42] Running command: SyncNetworkProviderCommand internal: true.
>> 2018-04-12 09:06:20,102+02 INFO  
>> [org.ovirt.engine.extension.aaa.jdbc.core.Authentication]
>> (default task-239) [] locking user: admin due to interval failures
>> 2018-04-12 09:06:25,046+02 ERROR [org.ovirt.engine.core.sso.utils.SsoUtils]
>> (default task-239) [] OAuthException access_denied: Cannot authenticate
>> user 'admin@internal': The username or password is incorrect..
>> 2018-04-12 09:06:25,049+02 ERROR [org.ovirt.engine.core.bll.pro
>> vider.network.SyncNetworkProviderCommand] 
>> (EE-ManagedThreadFactory-engineScheduled-Thread-87)
>> [2ed5aa42] Command 'org.ovirt.engine.core.bll.pro
>> vider.network.SyncNetworkProviderCommand' failed: EngineException:
>> (Failed with error Unauthorized and code 5050)
>> 2018-04-12 09:06:25,050+02 INFO  [org.ovirt.engine.core.bll.pro
>> vider.network.SyncNetworkProviderCommand] 
>> (EE-ManagedThreadFactory-engineScheduled-Thread-87)
>> [2ed5aa42] Lock freed to object 'EngineLock:{exclusiveLocks='[
>> e37c0b9e-09bc-4893-9b0c-c70f56d6ecfc=PROVIDER]', sharedLocks=''}'
>>
>> It seems like the SyncNetworkProviderCommand is somehow locking the admin
>> account. I already restarted the whole machine but it didn't help.
>>
>> Can someone please point me in the right direction, where to find the
>> error?
>>
>> Thanks in advance
>>
>>
>> ___
>> Users mailing list
>> Users@ovirt.org
>> http://lists.ovirt.org/mailman/listinfo/users
>>
>>
>>
>>
>> --
>>
>> Eitan Raviv
>> IRC: erav (#ovirt #vdsm #devel #rhev-dev)
>>
>
>
>
> --
> Eitan Raviv
> IRC: erav (#ovirt #vdsm #devel #rhev-dev)
>



-- 
Martin Perina
Associate Manager, Software Engineering
Red Hat Czech s.r.o.
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Some questions about Ovirt REST API

2018-04-12 Thread gss...@pku.edu.cn
Here is my patches.
 
From: gss...@pku.edu.cn
Date: 2018-04-12 16:45
To: omachace; users
Subject: Re: Re: [ovirt-users] Some questions about Ovirt REST API
Sure.
I override get() and add() in my BackendVmMytestsResource.java
GET works and POST not.
 
From: Ondra Machacek
Date: 2018-04-12 16:25
To: gss...@pku.edu.cn; users
Subject: Re: [ovirt-users] Some questions about Ovirt REST API
Ah sorry, POST isn't working and GET works, I misread it.
 
Can you please share the generated file:
 
{project_path}/backend/manager/modules/restapi/interface/definition/target/generated-sources/model/org/ovirt/engine/api/resource/VmMytestResource.java
 
Maybe you can even send patches to review as draft for start, we could
better understand the patch then.
 
On 04/12/2018 10:14 AM, gss...@pku.edu.cn wrote:
> Do you mean /@override/ /getMytestsResource() / in BackendVmResource ?
> I have done that, otherwise GET would not pass.
> 
> *From:* Ondra Machacek 
> *Date:* 2018-04-12 15:43
> *To:* gss...@pku.edu.cn ; users
> 
> *Subject:* Re: [ovirt-users] Some questions about Ovirt REST API
> On 04/11/2018 08:19 AM, gss...@pku.edu.cn wrote:
>  > Hi,
>  >
>  > I wants to creating my own service under
> ../vms/{vmid}/myservice.Here is
>  > my methods:
>  >
>  > 1. create VmMytestService in
>  > /https://github.com/oVirt/ovirt-engine-api-model project./
>  > add/@Service VmMytestService mytests() in /VmService .java
>  > 2. mvn install it and change the root pom.xml
>  > /4.3.9-SNAPSHOT / in my Ovirt project.
>  > 3.create BackendVmMytestService implements VmMytestResource
> Did you also in BackendVmResource implemented 'mytests' method?
>  > 4.override /get() and add() /methods.
>  >
>  > After that, I use /curl/  tool to send GET and POST request. GET is
>  > working and return.
>  > However, I get this return after POST request.
>  >
>  > Would you help me with that issue?
>  >
>  > Thanks,
>  > wenzt
>  >
>  >
>  > ___
>  > Users mailing list
>  > Users@ovirt.org
>  > http://lists.ovirt.org/mailman/listinfo/users
>  >
> 


mytests-api-model.patch
Description: Binary data


mytests-ovirt-project.patch
Description: Binary data
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] admin account constantly gets locked

2018-04-12 Thread Eitan Raviv
The recurring denied access for every SyncNetworkProvider might be because
you changed the admin password on the engine but not on the provider.

Dominik, will updating to the same password on the provider solve the
denied access?
Martin, does the engine lock out the admin user for failed retries?


HTH


On Thu, Apr 12, 2018 at 12:29 PM, Käfer Marcel 
wrote:

> Here are the logfiles…
>
>
>
> Thanks
>
>
>
> *Von:* Eitan Raviv [mailto:era...@redhat.com]
> *Gesendet:* Donnerstag, 12. April 2018 11:12
> *An:* Käfer Marcel
> *Cc:* users@ovirt.org; Martin Perina
> *Betreff:* Re: [ovirt-users] admin account constantly gets locked
>
>
>
> The sync network command is probably unrelated.
>
> Can you attach the full engine and the setup logs?
>
> Martin, this looks a bit like [1]. Any idea?
>
> Thanks
>
>
>
> [1] https://bugzilla.redhat.com/show_bug.cgi?id=1410955
>
>
>
> On Thu, Apr 12, 2018 at 10:22 AM, Käfer Marcel 
> wrote:
>
> Hello,
>
> a few days ago I installed an ovirt-engine 4.2.2.6 following the steps of
> the documentation. After the installation I logged in to the admin page,
> configured a datadomain and changed the admin password. After a few hours I
> tried to login again, using the new password and got "Unable to log in
> because the user account is disabled or locked. Contact the system
> administrator." So I unlocked the admin account from the shell using
> "ovirt-aaa-jdbc-tool user unlock admin" which worked fine and I was able to
> continue working till the next login.
>
> I traced the /var/log/ovirt-engine/engine.log and found this after
> unlocking the admin account again.
>
> 2018-04-12 09:06:19,984+02 INFO  [org.ovirt.engine.core.bll.
> provider.network.SyncNetworkProviderCommand] 
> (EE-ManagedThreadFactory-engineScheduled-Thread-87)
> [2ed5aa42] Lock Acquired to object 'EngineLock:{exclusiveLocks='[
> e37c0b9e-09bc-4893-9b0c-c70f56d6ecfc=PROVIDER]', sharedLocks=''}'
> 2018-04-12 09:06:19,991+02 INFO  [org.ovirt.engine.core.bll.
> provider.network.SyncNetworkProviderCommand] 
> (EE-ManagedThreadFactory-engineScheduled-Thread-87)
> [2ed5aa42] Running command: SyncNetworkProviderCommand internal: true.
> 2018-04-12 09:06:20,102+02 INFO  
> [org.ovirt.engine.extension.aaa.jdbc.core.Authentication]
> (default task-239) [] locking user: admin due to interval failures
> 2018-04-12 09:06:25,046+02 ERROR [org.ovirt.engine.core.sso.utils.SsoUtils]
> (default task-239) [] OAuthException access_denied: Cannot authenticate
> user 'admin@internal': The username or password is incorrect..
> 2018-04-12 09:06:25,049+02 ERROR [org.ovirt.engine.core.bll.
> provider.network.SyncNetworkProviderCommand] 
> (EE-ManagedThreadFactory-engineScheduled-Thread-87)
> [2ed5aa42] Command 
> 'org.ovirt.engine.core.bll.provider.network.SyncNetworkProviderCommand'
> failed: EngineException: (Failed with error Unauthorized and code 5050)
> 2018-04-12 09:06:25,050+02 INFO  [org.ovirt.engine.core.bll.
> provider.network.SyncNetworkProviderCommand] 
> (EE-ManagedThreadFactory-engineScheduled-Thread-87)
> [2ed5aa42] Lock freed to object 'EngineLock:{exclusiveLocks='[
> e37c0b9e-09bc-4893-9b0c-c70f56d6ecfc=PROVIDER]', sharedLocks=''}'
>
> It seems like the SyncNetworkProviderCommand is somehow locking the admin
> account. I already restarted the whole machine but it didn't help.
>
> Can someone please point me in the right direction, where to find the
> error?
>
> Thanks in advance
>
>
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users
>
>
>
>
> --
>
> Eitan Raviv
> IRC: erav (#ovirt #vdsm #devel #rhev-dev)
>



-- 
Eitan Raviv
IRC: erav (#ovirt #vdsm #devel #rhev-dev)
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Decrease downtime for HA

2018-04-12 Thread Daniel Menzel

Hi there,

does anyone have an idea how to decrease a virtual machine's downtime?

Best
Daniel


On 06.04.2018 13:34, Daniel Menzel wrote:


Hi Michal,

(sorry for misspelling your name in my first mail).

The settings for the VMs are the following (oVirt 4.2):

 1. HA checkbox enabled of course
 2. "Target Storage Domain for VM Lease" -> left empty
 3. "Resume Behavior" -> AUTO_RESUME
 4. Priority for Migration -> High
 5. "Watchdog Model" -> No-Watchdog

For testing we did not kill any VM but the host. So basically we 
simulated an instantaneous crash by manually turning the machine off 
via IPMI-Interface (not via operating system!) and ping the guest(s). 
What happens then?


 1. 2-3 seconds after the we press the host's shutdown button we lose
ping contact to the VM(s).
 2. After another 20s oVirt changes the host's status to "connecting",
the VM's status is set to a question mark.
 3. After ~1:30 the host is flagged to "non responsive"
 4. After ~2:10 the host's reboot is initiated by oVirt, 5-10s later
the guest is back online.

So, there seems to be one mistake I made in the first mail: The 
downtime is "only" 2.5min. But still I think this time can be 
decreased as for some services it is still quite a long time.


Best
Daniel


On 06.04.2018 12:49, Michal Skrivanek wrote:

On 6 Apr 2018, at 12:45, Daniel Menzel  wrote:

Hi Michael,
thanks for your mail. Sorry, I forgot to write that. Yes, we have power 
management and fencing enabled on all hosts. We also tested this and found out 
that it works perfectly. So this cannot be the reason I guess.

Hi Daniel,
ok, then it’s worth looking into details. Can you describe in more detail what 
happens? What exact settings you’re using for such VM? Are you killing the HE 
VM or other VMs or both? Would be good to narrow it down a bit and then review 
the exact flow

Thanks,
michal


Daniel



On 06.04.2018 11:11, Michal Skrivanek wrote:

On 4 Apr 2018, at 15:36, Daniel Menzel  wrote:

Hello,

we're successfully using a setup with 4 Nodes and a replicated Gluster for 
storage. The engine is self hosted. What we're dealing with at the moment is 
the high availability: If a node fails (for example simulated by a forced power 
loss) the engine comes back up online withing ~2min. But guests (having the HA 
option enabled) come back online only after a very long grace time of ~5min. As 
we have a reliable network (40 GbE) and reliable servers I think that the 
default grace times are way too high for us - is there any possibility to 
change those values?

And do you have Power Management(iLO, iDRAC,etc) configured for your hosts? 
Otherwise we have to resort to relatively long timeouts to make sure the host 
is really dead
Thanks,
michal

Thanks in advance!
Daniel

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users






___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] vdsm hook noipspoof on interface level

2018-04-12 Thread Peter Hudec
Hi,

I would like to restrict of usage IP address on VMs. Thos could be
achied by usinf clear-filter instead of vdsm-no-mac-spoofing.

I have found noipspoof vdsm hook,
https://github.com/oVirt/vdsm/tree/master/vdsm_hooks/noipspoof.

This hook but set the filtering on all interfaces, the setting is on VM
level, not interface level. So if the there are more interfaces on all
of them. I would like just restrict the WAN interface on multi homed VMs.

Peter

-- 
*Peter Hudec*
Infraštruktúrny architekt
phu...@cnc.sk 

*CNC, a.s.*
Borská 6, 841 04 Bratislava
Recepcia: +421 2  35 000 100

Mobil:+421 905 997 203
*www.cnc.sk* 

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] admin account constantly gets locked

2018-04-12 Thread Martin Perina
On Thu, Apr 12, 2018 at 1:04 PM, Martin Perina  wrote:

>
>
> On Thu, Apr 12, 2018 at 12:44 PM, Eitan Raviv  wrote:
>
>> The recurring denied access for every SyncNetworkProvider might be
>> because you changed the admin password on the engine but not on the
>> provider.
>>
>> Dominik, will updating to the same password on the provider solve the
>> denied access?
>> Martin, does the engine lock out the admin user for failed retries?
>>
>
> ​Of course, after 5 incorrect logins the account is locked. But I looked
> at logs and I can't see any login errors, so currently trying to reproduce
> to find out what's going on ...
>

​OK, so confirmed. If you change password for admin@internal using
aaa-jdbc-tool and you don't change immediately for OVN provider, then
admin@interal account is locked.

We should probably change logic in OVN provider to shutdown the OVN
provider service if authentication failure to engine is raised. Using this
we will break OVN provider, but
it seems to me much less severe than locking admin@internal account.
Dominik, what do you think?
​


> ​
>
>
>>
>>
>> HTH
>>
>>
>> On Thu, Apr 12, 2018 at 12:29 PM, Käfer Marcel <
>> marcel.kae...@putzbrunn.de> wrote:
>>
>>> Here are the logfiles…
>>>
>>>
>>>
>>> Thanks
>>>
>>>
>>>
>>> *Von:* Eitan Raviv [mailto:era...@redhat.com]
>>> *Gesendet:* Donnerstag, 12. April 2018 11:12
>>> *An:* Käfer Marcel
>>> *Cc:* users@ovirt.org; Martin Perina
>>> *Betreff:* Re: [ovirt-users] admin account constantly gets locked
>>>
>>>
>>>
>>> The sync network command is probably unrelated.
>>>
>>> Can you attach the full engine and the setup logs?
>>>
>>> Martin, this looks a bit like [1]. Any idea?
>>>
>>> Thanks
>>>
>>>
>>>
>>> [1] https://bugzilla.redhat.com/show_bug.cgi?id=1410955
>>>
>>>
>>>
>>> On Thu, Apr 12, 2018 at 10:22 AM, Käfer Marcel <
>>> marcel.kae...@putzbrunn.de> wrote:
>>>
>>> Hello,
>>>
>>> a few days ago I installed an ovirt-engine 4.2.2.6 following the steps
>>> of the documentation. After the installation I logged in to the admin page,
>>> configured a datadomain and changed the admin password. After a few hours I
>>> tried to login again, using the new password and got "Unable to log in
>>> because the user account is disabled or locked. Contact the system
>>> administrator." So I unlocked the admin account from the shell using
>>> "ovirt-aaa-jdbc-tool user unlock admin" which worked fine and I was able to
>>> continue working till the next login.
>>>
>>> I traced the /var/log/ovirt-engine/engine.log and found this after
>>> unlocking the admin account again.
>>>
>>> 2018-04-12 09:06:19,984+02 INFO  [org.ovirt.engine.core.bll.pro
>>> vider.network.SyncNetworkProviderCommand] 
>>> (EE-ManagedThreadFactory-engineScheduled-Thread-87)
>>> [2ed5aa42] Lock Acquired to object 'EngineLock:{exclusiveLocks='[
>>> e37c0b9e-09bc-4893-9b0c-c70f56d6ecfc=PROVIDER]', sharedLocks=''}'
>>> 2018-04-12 09:06:19,991+02 INFO  [org.ovirt.engine.core.bll.pro
>>> vider.network.SyncNetworkProviderCommand] 
>>> (EE-ManagedThreadFactory-engineScheduled-Thread-87)
>>> [2ed5aa42] Running command: SyncNetworkProviderCommand internal: true.
>>> 2018-04-12 09:06:20,102+02 INFO  
>>> [org.ovirt.engine.extension.aaa.jdbc.core.Authentication]
>>> (default task-239) [] locking user: admin due to interval failures
>>> 2018-04-12 09:06:25,046+02 ERROR [org.ovirt.engine.core.sso.utils.SsoUtils]
>>> (default task-239) [] OAuthException access_denied: Cannot authenticate
>>> user 'admin@internal': The username or password is incorrect..
>>> 2018-04-12 09:06:25,049+02 ERROR [org.ovirt.engine.core.bll.pro
>>> vider.network.SyncNetworkProviderCommand] 
>>> (EE-ManagedThreadFactory-engineScheduled-Thread-87)
>>> [2ed5aa42] Command 'org.ovirt.engine.core.bll.pro
>>> vider.network.SyncNetworkProviderCommand' failed: EngineException:
>>> (Failed with error Unauthorized and code 5050)
>>> 2018-04-12 09:06:25,050+02 INFO  [org.ovirt.engine.core.bll.pro
>>> vider.network.SyncNetworkProviderCommand] 
>>> (EE-ManagedThreadFactory-engineScheduled-Thread-87)
>>> [2ed5aa42] Lock freed to object 'EngineLock:{exclusiveLocks='[
>>> e37c0b9e-09bc-4893-9b0c-c70f56d6ecfc=PROVIDER]', sharedLocks=''}'
>>>
>>> It seems like the SyncNetworkProviderCommand is somehow locking the
>>> admin account. I already restarted the whole machine but it didn't help.
>>>
>>> Can someone please point me in the right direction, where to find the
>>> error?
>>>
>>> Thanks in advance
>>>
>>>
>>> ___
>>> Users mailing list
>>> Users@ovirt.org
>>> http://lists.ovirt.org/mailman/listinfo/users
>>>
>>>
>>>
>>>
>>> --
>>>
>>> Eitan Raviv
>>> IRC: erav (#ovirt #vdsm #devel #rhev-dev)
>>>
>>
>>
>>
>> --
>> Eitan Raviv
>> IRC: erav (#ovirt #vdsm #devel #rhev-dev)
>>
>
>
>
> --
> Martin Perina
> Associate Manager, Software Engineering
> Red Hat Czech s.r.o.
>



-- 
Martin Perina
Associate Manager, Software Engineering
Red Hat Czech s.r.o.

Re: [ovirt-users] admin account constantly gets locked

2018-04-12 Thread Dominik Holler
On Thu, 12 Apr 2018 13:57:45 +0200
Martin Perina  wrote:

> On Thu, Apr 12, 2018 at 1:04 PM, Martin Perina 
> wrote:
> 
> >
> >
> > On Thu, Apr 12, 2018 at 12:44 PM, Eitan Raviv 
> > wrote: 
> >> The recurring denied access for every SyncNetworkProvider might be
> >> because you changed the admin password on the engine but not on the
> >> provider.
> >>
> >> Dominik, will updating to the same password on the provider solve
> >> the denied access?
> >> Martin, does the engine lock out the admin user for failed retries?
> >>  
> >
> > ​Of course, after 5 incorrect logins the account is locked. But I
> > looked at logs and I can't see any login errors, so currently
> > trying to reproduce to find out what's going on ...
> >  
> 
> ​OK, so confirmed. If you change password for admin@internal using
> aaa-jdbc-tool and you don't change immediately for OVN provider, then
> admin@interal account is locked.
> 
> We should probably change logic in OVN provider to shutdown the OVN
> provider service if authentication failure to engine is raised. Using
> this we will break OVN provider, but
> it seems to me much less severe than locking admin@internal account.
> Dominik, what do you think?
> ​

If we would shutdown the provider an authentication failure, and
engine's admin has no access to engine's host super user shell, there is
no way to recover for engine's admin.
Even the authentication failure might be triggered from outside oVirt
engine, shutting down the provider will disable the start of VMs with
OVN networks.

What is you opinion about the approach if the request comes from inside
engine, e.g. by SyncNetworkProviderCommand or other operations, the
provider object inside engine would be marked as invalid on
authentication error and block all interaction until the
credentials is updated?


> 
> 
> > ​
> >
> >  
> >>
> >>
> >> HTH
> >>
> >>
> >> On Thu, Apr 12, 2018 at 12:29 PM, Käfer Marcel <  
> >> marcel.kae...@putzbrunn.de> wrote:  
> >>  
> >>> Here are the logfiles…
> >>>
> >>>
> >>>
> >>> Thanks
> >>>
> >>>
> >>>
> >>> *Von:* Eitan Raviv [mailto:era...@redhat.com]
> >>> *Gesendet:* Donnerstag, 12. April 2018 11:12
> >>> *An:* Käfer Marcel
> >>> *Cc:* users@ovirt.org; Martin Perina
> >>> *Betreff:* Re: [ovirt-users] admin account constantly gets locked
> >>>
> >>>
> >>>
> >>> The sync network command is probably unrelated.
> >>>
> >>> Can you attach the full engine and the setup logs?
> >>>
> >>> Martin, this looks a bit like [1]. Any idea?
> >>>
> >>> Thanks
> >>>
> >>>
> >>>
> >>> [1] https://bugzilla.redhat.com/show_bug.cgi?id=1410955
> >>>
> >>>
> >>>
> >>> On Thu, Apr 12, 2018 at 10:22 AM, Käfer Marcel <  
> >>> marcel.kae...@putzbrunn.de> wrote:  
> >>>
> >>> Hello,
> >>>
> >>> a few days ago I installed an ovirt-engine 4.2.2.6 following the
> >>> steps of the documentation. After the installation I logged in to
> >>> the admin page, configured a datadomain and changed the admin
> >>> password. After a few hours I tried to login again, using the new
> >>> password and got "Unable to log in because the user account is
> >>> disabled or locked. Contact the system administrator." So I
> >>> unlocked the admin account from the shell using
> >>> "ovirt-aaa-jdbc-tool user unlock admin" which worked fine and I
> >>> was able to continue working till the next login.
> >>>
> >>> I traced the /var/log/ovirt-engine/engine.log and found this after
> >>> unlocking the admin account again.
> >>>
> >>> 2018-04-12 09:06:19,984+02 INFO  [org.ovirt.engine.core.bll.pro
> >>> vider.network.SyncNetworkProviderCommand]
> >>> (EE-ManagedThreadFactory-engineScheduled-Thread-87) [2ed5aa42]
> >>> Lock Acquired to object
> >>> 'EngineLock:{exclusiveLocks='[ 
> >>> e37c0b9e-09bc-4893-9b0c-c70f56d6ecfc=PROVIDER]',
> >>> sharedLocks=''}' 2018-04-12 09:06:19,991+02 INFO
> >>> [org.ovirt.engine.core.bll.pro
> >>> vider.network.SyncNetworkProviderCommand]
> >>> (EE-ManagedThreadFactory-engineScheduled-Thread-87) [2ed5aa42]
> >>> Running command: SyncNetworkProviderCommand internal: true.
> >>> 2018-04-12 09:06:20,102+02 INFO
> >>> [org.ovirt.engine.extension.aaa.jdbc.core.Authentication]
> >>> (default task-239) [] locking user: admin due to interval
> >>> failures 2018-04-12 09:06:25,046+02 ERROR
> >>> [org.ovirt.engine.core.sso.utils.SsoUtils] (default task-239) []
> >>> OAuthException access_denied: Cannot authenticate user
> >>> 'admin@internal': The username or password is incorrect..
> >>> 2018-04-12 09:06:25,049+02 ERROR [org.ovirt.engine.core.bll.pro
> >>> vider.network.SyncNetworkProviderCommand]
> >>> (EE-ManagedThreadFactory-engineScheduled-Thread-87) [2ed5aa42]
> >>> Command 'org.ovirt.engine.core.bll.pro
> >>> vider.network.SyncNetworkProviderCommand' failed:
> >>> EngineException: (Failed with error Unauthorized and code 5050)
> >>> 2018-04-12 09:06:25,050+02 INFO  [org.ovirt.engine.core.bll.pro
> >>> vider.network.SyncNetworkProviderCommand]
> >>> 

[ovirt-users] [ANN] oVirt 4.2.3 First Release Candidate is now available

2018-04-12 Thread Lev Veyde
The oVirt Project is pleased to announce the availability of the oVirt
4.2.3 First
Release Candidate, as of April 12th, 2018

This update is a release candidate of the third in a series of
stabilization updates to the 4.2
series.
This is pre-release software. This pre-release should not to be used in
production.

This release is available now for:
* Red Hat Enterprise Linux 7.4 or later
* CentOS Linux (or similar) 7.4 or later

This release supports Hypervisor Hosts running:
* Red Hat Enterprise Linux 7.4 or later
* CentOS Linux (or similar) 7.4 or later
* oVirt Node 4.2

See the release notes [1] for installation / upgrade instructions and
a list of new features and bugs fixed.

Notes:
- oVirt Appliance is available
- oVirt Node is available [2]

Additional Resources:
* Read more about the oVirt 4.2.3 release highlights:
http://www.ovirt.org/release/4. 2
. 
3 /

* Get more oVirt Project updates on Twitter: https://twitter.com/ovirt
* Check out the latest project news on the oVirt blog:
http://www.ovirt.org/blog/

[1] http://www.ovirt.org/release/4. 2
. 
3 /

[2] http://resources.ovirt.org/pub/ovirt-4.
2
-pre
/iso/


-- 

Lev Veyde

Software Engineer, RHCE | RHCVA | MCITP

Red Hat Israel



l...@redhat.com | lve...@redhat.com

TRIED. TESTED. TRUSTED. 
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Frequent vm migration failure

2018-04-12 Thread Michal Skrivanek


> On 12 Apr 2018, at 18:26, Stefano Stagnaro 
>  wrote:
> 
> Hi,
> 
> I recently upgraded an oVirt deployment from 3.6 to 4.0 and then 4.1.9 (my 
> actual release). Since then, when migrating many hosts simultaneously I 
> always experience few migrations failure like 1 on 10 vms. The failure can 
> occur on any host; moreover, after a couple of failure the destination host 
> fall in Error status and I have to manually re-activate or wait 30 min.
> 
> Tipical error found on vdsm log is (from the source host):
> 2018-04-12 17:01:32,097+0200 ERROR (migsrc/3192dfe7) [virt.vm] 
> (vmId='3192dfe7-eeac-4626-8c86-e49facc9006f') migration destination error: 
> Fatal error during migration (migration:287)
> 
> Please find the logs of source host (v15.ovirt), destination host (v14.ovirt) 
> and engine here: 
> https://www.dropbox.com/sh/xhf8ry4ih40poxd/AABxiFCIxDe14HSx2DqLE61ya?dl=0
> 
> Some of the vm affected from the migration failure are:
> svn   3192dfe7-eeac-4626-8c86-e49facc9006f
> wood  a8e83ff0-dfed-4074-b6b6-e947b8ebb952
> qnx66 5697c4a4-9e40-4dd6-aba2-c8ab9904a584

can you also include qemu log from /var/log/libvirt/qemu/?

btw you seem to be using the legacy migration policy throttling the speed 
significantly. Please read into the migration enhancements in 4.0
https://www.ovirt.org/develop/release-management/features/virt/migration-enhancements/
 


Thanks,
michal

> 
> Thank you very much for your help.
> 
> -- 
> Stefano Stagnaro
> 
> Prisma Telecom Testing S.r.l.
> Via Petrocchi, 4
> 20127 Milano – Italy
> 
> Tel. 02 26113507 int 339
> e-mail: stefa...@prismatelecomtesting.com
> skype: stefano.stagnaro
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] Frequent vm migration failure

2018-04-12 Thread Stefano Stagnaro
Hi,

I recently upgraded an oVirt deployment from 3.6 to 4.0 and then 4.1.9 (my 
actual release). Since then, when migrating many hosts simultaneously I always 
experience few migrations failure like 1 on 10 vms. The failure can occur on 
any host; moreover, after a couple of failure the destination host fall in 
Error status and I have to manually re-activate or wait 30 min.

Tipical error found on vdsm log is (from the source host):
2018-04-12 17:01:32,097+0200 ERROR (migsrc/3192dfe7) [virt.vm] 
(vmId='3192dfe7-eeac-4626-8c86-e49facc9006f') migration destination error: 
Fatal error during migration (migration:287)

Please find the logs of source host (v15.ovirt), destination host (v14.ovirt) 
and engine here: 
https://www.dropbox.com/sh/xhf8ry4ih40poxd/AABxiFCIxDe14HSx2DqLE61ya?dl=0

Some of the vm affected from the migration failure are:
svn 3192dfe7-eeac-4626-8c86-e49facc9006f
wooda8e83ff0-dfed-4074-b6b6-e947b8ebb952
qnx66   5697c4a4-9e40-4dd6-aba2-c8ab9904a584

Thank you very much for your help.

-- 
Stefano Stagnaro

Prisma Telecom Testing S.r.l.
Via Petrocchi, 4
20127 Milano – Italy

Tel. 02 26113507 int 339
e-mail: stefa...@prismatelecomtesting.com
skype: stefano.stagnaro
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] New Install Issues

2018-04-12 Thread Talk Jesus
Having some strange issues.

First: Admin panel loads very slow using subdomain.mydomain.com

However, this is a brand new server with 64GB RAM, SSD disks and dual octo
core Xeons. 

Second: I get this.

[ INFO  ] Stage: Setup validation
[WARNING] Cannot validate host name settings, reason: resolved host does not
match any of the local addresses
  During execution engine service will be stopped (OK, Cancel) [OK]:

Third: when admin panel finally loads, I use admin@internal plus my root
password set during installation setup. I get this:

Unable to log in. Verify your login information or contact the system
administrator.


---
This email has been checked for viruses by Avast antivirus software.
https://www.avast.com/antivirus

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Decrease downtime for HA

2018-04-12 Thread Michal Skrivanek


> On 12 Apr 2018, at 13:13, Daniel Menzel  
> wrote:
> 
> Hi there,
> 
> does anyone have an idea how to decrease a virtual machine's downtime?
> 
> Best
> Daniel
> 
> On 06.04.2018 13:34, Daniel Menzel wrote:
>> Hi Michal,
>> 
>> 

Hi Daniel,
adding Martin to review fencing behavior
>> (sorry for misspelling your name in my first mail).
>> 
>> 

that’s not the reason I’m replying late!:-))

>> The settings for the VMs are the following (oVirt 4.2):
>> 
>> HA checkbox enabled of course
>> "Target Storage Domain for VM Lease" -> left empty

if you need faster reactions then try to use VM Leases as well, it won’t make a 
difference in this case but will help in case of network issues. E.g. if you 
use iSCSI and the storage connection breaks while host connection still works 
it would restart the VM in about 80s; otherwise it would take >5 mins. 
>> "Resume Behavior" -> AUTO_RESUME
>> Priority for Migration -> High
>> "Watchdog Model" -> No-Watchdog
>> For testing we did not kill any VM but the host. So basically we simulated 
>> an instantaneous crash by manually turning the machine off via 
>> IPMI-Interface (not via operating system!) and ping the guest(s). What 
>> happens then?
>> 
>> 2-3 seconds after the we press the host's shutdown button we lose ping 
>> contact to the VM(s).
>> After another 20s oVirt changes the host's status to "connecting", the VM's 
>> status is set to a question mark.
>> After ~1:30 the host is flagged to "non responsive”

that sounds about right. Now fencing action should have been initiated, if you 
can share the engine logs we can confirm that. IIRC we first try soft fencing - 
try to ssh to that host, that might take some time to time out I guess. Martin?
>> After ~2:10 the host's reboot is initiated by oVirt, 5-10s later the guest 
>> is back online.
>> So, there seems to be one mistake I made in the first mail: The downtime is 
>> "only" 2.5min. But still I think this time can be decreased as for some 
>> services it is still quite a long time.
>> 
>> 

these values can be tuned down, but then you may be more susceptible to fencing 
power cycling a host in case of shorter network outages. It may be ok…depending 
on your requirements.
>> Best
>> Daniel
>> 
>> On 06.04.2018 12:49, Michal Skrivanek wrote:
 On 6 Apr 2018, at 12:45, Daniel Menzel  
  wrote:
 
 Hi Michael,
 thanks for your mail. Sorry, I forgot to write that. Yes, we have power 
 management and fencing enabled on all hosts. We also tested this and found 
 out that it works perfectly. So this cannot be the reason I guess.
>>> Hi Daniel,
>>> ok, then it’s worth looking into details. Can you describe in more detail 
>>> what happens? What exact settings you’re using for such VM? Are you killing 
>>> the HE VM or other VMs or both? Would be good to narrow it down a bit and 
>>> then review the exact flow
>>> 
>>> Thanks,
>>> michal
>>> 
 Daniel
 
 
 
 On 06.04.2018 11:11, Michal Skrivanek wrote:
>> On 4 Apr 2018, at 15:36, Daniel Menzel  
>>  wrote:
>> 
>> Hello,
>> 
>> we're successfully using a setup with 4 Nodes and a replicated Gluster 
>> for storage. The engine is self hosted. What we're dealing with at the 
>> moment is the high availability: If a node fails (for example simulated 
>> by a forced power loss) the engine comes back up online withing ~2min. 
>> But guests (having the HA option enabled) come back online only after a 
>> very long grace time of ~5min. As we have a reliable network (40 GbE) 
>> and reliable servers I think that the default grace times are way too 
>> high for us - is there any possibility to change those values?
> And do you have Power Management(iLO, iDRAC,etc) configured for your 
> hosts? Otherwise we have to resort to relatively long timeouts to make 
> sure the host is really dead
> Thanks,
> michal
>> Thanks in advance!
>> Daniel
>> 
>> ___
>> Users mailing list
>> Users@ovirt.org 
>> http://lists.ovirt.org/mailman/listinfo/users 
>> 
>> 
>> 
>> 
>> 
>> 
>> ___
>> Users mailing list
>> Users@ovirt.org 
>> http://lists.ovirt.org/mailman/listinfo/users 
>> 
> 
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] how do you backup VM - Citrix Xen Migrate too!

2018-04-12 Thread Zip
Hi Peter,

Have a look at my solution here.

https://github.com/zipurman/oVIRT_Simple_Backup

Is a full backup solution and a migration utility from Xen(Citrix) to oVirt.

Cheers

Zip

From:   on behalf of Peter Hudec 
Organization:  CNC, a.s.
Reply-To:  "phu...@cnc.sk" 
Date:  Friday, April 6, 2018 at 5:53 AM
To:  users 
Subject:  [ovirt-users] how do you backup VM

Hi,

one general question. See the $SUBJ.

I have found https://github.com/openbacchus/bacchus, that good as start
point, but still missing some features. i was thinking to contribute
here, but first I want to known another solutions.

regards
Peter
-- 
*Peter Hudec*
Infraštruktúrny architekt
phu...@cnc.sk 

*CNC, a.s.*
Borská 6, 841 04 Bratislava
Recepcia: +421 2  35 000 100

Mobil:+421 905 997 203
*www.cnc.sk* 

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users



___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Engine reports

2018-04-12 Thread Rich Megginson

sudo ls -alrtF -Z /var/lib/elasticsearch

oc logs logging-es-data-master-z6zbv4v2-2-deploy

oc describe pod logging-es-data-master-z6zbv4v2-2-deploy

sudo grep type=AVC /var/log/audit/audit.log | tail

On 04/12/2018 02:32 AM, Peter Hudec wrote:

back to this issue.

something went wrong ;( The status command got error. I'm not familiar
with openshift, so the log processing will took me a while.

[PROD] r...@dipostat01.cnc.sk: ~ # oc project logging
Already on project "logging" on server "https://metrics.ovirt.cnc.sk:8443;.
[PROD] r...@dipostat01.cnc.sk: ~ # oc adm policy add-scc-to-user
hostmount-anyuid \

   system:serviceaccount:logging:aggregated-logging-elasticsearch

scc "hostmount-anyuid" added to:
["system:serviceaccount:logging:aggregated-logging-elasticsearch"]
[PROD] r...@dipostat01.cnc.sk: ~ # oc rollout cancel $( oc get -n
logging dc -l component=es -o name )
No rollout is in progress (latest rollout #2 failed 3 days ago)
[PROD] r...@dipostat01.cnc.sk: ~ # oc rollout latest $( oc get -n
logging dc -l component=es -o name )
deploymentconfig "logging-es-data-master-z6zbv4v2" rolled out
[PROD] r...@dipostat01.cnc.sk: ~ #  oc rollout status -w $( oc get -n
logging dc -l component=es -o name )
Waiting for rollout to finish: 0 of 1 updated replicas are available...
error: replication controller "logging-es-data-master-z6zbv4v2-3" has
failed progressing


[PROD] r...@dipostat01.cnc.sk: ~ # oc get pods
NAME   READY STATUSRESTARTS
  AGE
logging-curator-1-c894f1/1   Running   9045d
logging-es-data-master-z6zbv4v2-2-deploy   0/1   Error 0  3d
logging-fluentd-x9vzs  1/1   Running   1  5d
logging-kibana-1-6bvvw 2/2   Running   2  5d
logging-mux-1-xxmdj1/1   Running   1  5d
[PROD] r...@dipostat01.cnc.sk: ~ # oc get pods
NAME   READY STATUSRESTARTS
  AGE
logging-curator-1-c894f1/1   Running   9045d
logging-es-data-master-z6zbv4v2-2-deploy   0/1   Error 0  3d
logging-fluentd-x9vzs  1/1   Running   1  5d
logging-kibana-1-6bvvw 2/2   Running   2  5d
logging-mux-1-xxmdj1/1   Running   1  5d
[PROD] r...@dipostat01.cnc.sk: ~ # oc get pods
NAME   READY STATUSRESTARTS
  AGE
logging-curator-1-c894f1/1   Running   9045d
logging-es-data-master-z6zbv4v2-2-deploy   0/1   Error 0  3d
logging-fluentd-x9vzs  1/1   Running   1  5d
logging-kibana-1-6bvvw 2/2   Running   2  5d
logging-mux-1-xxmdj1/1   Running   1  5d
[PROD] r...@dipostat01.cnc.sk: ~ # oc get svc
NAMETYPECLUSTER-IP   EXTERNAL-IP
PORT(S) AGE
logging-es  ClusterIP   172.30.249.174   
9200/TCP5d
logging-es-cluster  ClusterIP   172.30.114.201   
9300/TCP5d
logging-es-prometheus   ClusterIP   172.30.203.113   
443/TCP 5d
logging-kibana  ClusterIP   172.30.29.192
443/TCP 5d
logging-mux ClusterIP   172.30.170.158   192.168.16.17
24284/TCP   5d


On 07/04/2018 01:09, Rich Megginson wrote:

Great!

On 04/06/2018 04:43 PM, Peter Hudec wrote:

Ansible playbook finished OK. The next step after weekend.

 thanks
     Peter

On 06/04/2018 23:34, Rich Megginson wrote:

On 04/06/2018 03:08 PM, Peter Hudec wrote:

Hi,

https://tools.apps.hudecof.net/paste/view/1d493d52

The difference is
- I used latest ansible 2.5 from PIPY source, since the RPM package do
not fit requirements
- I used GIT repo for openshift-ansible.

I could start it over with the RPM based openshift-ansible

I recommend that you start over with the RPM based openshift-ansible,
which is what the instructions say, which is what I have tested

alternately - if you want to go the more experimental route, you could
enable the epel-testing yum repo - ansible-2.5 is in epel-testing which
I've been told by the openshift-ansible guys should work


  Peter

On 06/04/2018 20:23, Rich Megginson wrote:

I'm assuming you are running on a CentOS7 machine, recently updated to
the latest base packages. Please confirm.

Please provide the output of the following commands:

sudo yum repolist

sudo rpm -q ansible

sudo yum repoquery -i ansible

sudo rpm -q openshift-ansible

sudo yum repoquery -i openshift-ansible

sudo rpm -q origin

sudo yum repoquery -i origin

sudo cat
/usr/share/ansible/openshift-ansible/roles/lib_utils/callback_plugins/aa_version_requirement.py




sudo ls -alrtF /etc/origin/logging

Please confirm that you followed the steps listed in the link below,
including the use of the ansible inventory, vars.yaml.template, and
repo
files:

[ovirt-users] ansible failure during host install

2018-04-12 Thread Young, Matthew (Numerical Algorithms Group)
Hello all,

I have been working on adding a new host to an oVirt cluster.  The installation 
is failing in the ansible portion, specifically installing the ansible 
elasticsearch ca cert.  I have no experience with ansible.  Does anyone know 
what is causing this issue?  Or how to create this ca cert?

 from ansible log
...
2018-04-12 09:32:18,114 p=56616 u=ovirt |  TASK 
[oVirt.ovirt-fluentd/fluentd-setup : Create fluentd.conf] *
2018-04-12 09:32:18,730 p=56616 u=ovirt |  ok: [10.222.10.156] => {
"changed": false,
"checksum": "c9f88b60cd12ab8e3f3ffce1ae07654c89b06ef6",
"gid": 0,
"group": "root",
"mode": "0640",
"owner": "root",
"path": "/etc/fluentd/fluent.conf",
"secontext": "system_u:object_r:etc_t:s0",
"size": 58,
"state": "file",
"uid": 0
}
2018-04-12 09:32:18,739 p=56616 u=ovirt |  TASK 
[oVirt.ovirt-fluentd/fluentd-setup : Install fluentd certificate] *
2018-04-12 09:32:18,759 p=56616 u=ovirt |  skipping: [10.222.10.156] => {
"changed": false,
"skip_reason": "Conditional result was False"
}
2018-04-12 09:32:18,768 p=56616 u=ovirt |  TASK 
[oVirt.ovirt-fluentd/fluentd-setup : Install fluentd elasticsearch CA 
certificate] ***
2018-04-12 09:32:18,810 p=56616 u=ovirt |  fatal: [10.222.10.156]: FAILED! => {
"changed": false
}

MSG:

src (or content) is required

2018-04-12 09:32:18,812 p=56616 u=ovirt |  PLAY RECAP 
*
2018-04-12 09:32:18,812 p=56616 u=ovirt |  10.222.10.156  : ok=33   
changed=4unreachable=0failed=1


___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] New Install Issues

2018-04-12 Thread Alexander Wels
On Thursday, April 12, 2018 1:33:20 PM EDT Talk Jesus wrote:
> Having some strange issues.
> 
> First: Admin panel loads very slow using subdomain.mydomain.com
> 
> However, this is a brand new server with 64GB RAM, SSD disks and dual octo
> core Xeons.
> 
> Second: I get this.
> 
> [ INFO  ] Stage: Setup validation
> [WARNING] Cannot validate host name settings, reason: resolved host does not
> match any of the local addresses
>   During execution engine service will be stopped (OK, Cancel) [OK]:
> 
> Third: when admin panel finally loads, I use admin@internal plus my root
> password set during installation setup. I get this:
> 
> Unable to log in. Verify your login information or contact the system
> administrator.
> 

This is highly likely a DNS issue, the engine tries to resolve itself and if 
it can't, it takes a long time to load the webadmin (Not sure why it does 
this, but fixing the DNS will fix the slow loading).

> 
> ---
> This email has been checked for viruses by Avast antivirus software.
> https://www.avast.com/antivirus
> 
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users




___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] New Install Issues

2018-04-12 Thread Yaniv Kaul
On Thu, Apr 12, 2018, 9:21 PM Alexander Wels  wrote:

> On Thursday, April 12, 2018 1:33:20 PM EDT Talk Jesus wrote:
> > Having some strange issues.
> >
> > First: Admin panel loads very slow using subdomain.mydomain.com
> >
> > However, this is a brand new server with 64GB RAM, SSD disks and dual
> octo
> > core Xeons.
> >
> > Second: I get this.
> >
> > [ INFO  ] Stage: Setup validation
> > [WARNING] Cannot validate host name settings, reason: resolved host does
> not
> > match any of the local addresses
> >   During execution engine service will be stopped (OK, Cancel)
> [OK]:
> >
> > Third: when admin panel finally loads, I use admin@internal plus my root
> > password set during installation setup. I get this:
> >
> > Unable to log in. Verify your login information or contact the system
> > administrator.
> >
>
> This is highly likely a DNS issue, the engine tries to resolve itself and
> if
> it can't, it takes a long time to load the webadmin (Not sure why it does
> this, but fixing the DNS will fix the slow loading).
>

I agree.
It happens because of the TLS layer validation.
Y.


> >
> > ---
> > This email has been checked for viruses by Avast antivirus software.
> > https://www.avast.com/antivirus
> >
> > ___
> > Users mailing list
> > Users@ovirt.org
> > http://lists.ovirt.org/mailman/listinfo/users
>
>
>
>
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users
>
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] I broke my ovirt real good....

2018-04-12 Thread ~Stack~
Greetings,

So I did a over-confident-admin-makes-rookie-mistake. I changed a bunch
of things all back-to-back and thus don't actually know what broke. :-D

The only two real "big" changes were:
* Upgrade from 4.2.1 to 4.2.2
* change my ovirtmgmt network

The update I followed the upgrade procedures and I thought it all went
pretty well. Because I am moving it from a testing into what I hope will
be a more heavily used environment, I changed my ovirtmgmt network from
192.168.100.0/24 to 192.168.101.0/24 via the web-gui.

That was a touch tricker than just a change as I had to poke the
management engine host to be reachable on both network for a while, then
it just seemed OK.

What's happening is:
* I can no longer migrate a vm from one host to the other.
* If I try to do a "reinstall" it dies.
* There is some serious network lag between my hosts on a 10Gb network.
* I've got all kinds of python2.4 failures in my vdsm and mom logs.

Those are least the biggies.

So while I was planning on moving this to a more active use case, right
now - it is all still my play ground. I would REALLY hate to lose the
VM's but everything else can go and be rebuilt.

Given that I've somehow really broke this system pretty good, would it
be more advisable to blow away and rebuild it ALL or can I simply delete
the hypervisor hosts and rebuild them?

Thoughts?

Thanks!
~Stack~




signature.asc
Description: OpenPGP digital signature
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] ansible failure during host install

2018-04-12 Thread Shirly Radco
Hi,

What version of ovirt-engine-metrics are you using?

Did you already setup the OpenShift based metrics store to connect to?

Have you configured /etc/ovirt-engine-metrics/config.yml?


--

SHIRLY RADCO

BI SENIOR SOFTWARE ENGINEER

Red Hat Israel


TRIED. TESTED. TRUSTED.



On Thu, Apr 12, 2018, 21:35 Young, Matthew (Numerical Algorithms Group) <
matthew.you...@bp.com> wrote:

> Hello all,
>
>
>
> I have been working on adding a new host to an oVirt cluster.  The
> installation is failing in the ansible portion, specifically installing the
> ansible elasticsearch ca cert.  I have no experience with ansible.  Does
> anyone know what is causing this issue?  Or how to create this ca cert?
>
>
>
>  from ansible log
>
> …
>
> 2018-04-12 09:32:18,114 p=56616 u=ovirt |  TASK
> [oVirt.ovirt-fluentd/fluentd-setup : Create fluentd.conf] *
>
> 2018-04-12 09:32:18,730 p=56616 u=ovirt |  ok: [10.222.10.156] => {
>
> "changed": false,
>
> "checksum": "c9f88b60cd12ab8e3f3ffce1ae07654c89b06ef6",
>
> "gid": 0,
>
> "group": "root",
>
> "mode": "0640",
>
> "owner": "root",
>
> "path": "/etc/fluentd/fluent.conf",
>
> "secontext": "system_u:object_r:etc_t:s0",
>
> "size": 58,
>
> "state": "file",
>
> "uid": 0
>
> }
>
> 2018-04-12 09:32:18,739 p=56616 u=ovirt |  TASK
> [oVirt.ovirt-fluentd/fluentd-setup : Install fluentd certificate] *
>
> 2018-04-12 09:32:18,759 p=56616 u=ovirt |  skipping: [10.222.10.156] => {
>
> "changed": false,
>
> "skip_reason": "Conditional result was False"
>
> }
>
> 2018-04-12 09:32:18,768 p=56616 u=ovirt |  TASK
> [oVirt.ovirt-fluentd/fluentd-setup : Install fluentd elasticsearch CA
> certificate] ***
>
> 2018-04-12 09:32:18,810 p=56616 u=ovirt |  fatal: [10.222.10.156]: FAILED!
> => {
>
> "changed": false
>
> }
>
>
>
> MSG:
>
>
>
> src (or content) is required
>
>
>
> 2018-04-12 09:32:18,812 p=56616 u=ovirt |  PLAY RECAP
> *
>
> 2018-04-12 09:32:18,812 p=56616 u=ovirt |  10.222.10.156  :
> ok=33   changed=4unreachable=0failed=1
>
>
>
> 
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users
>
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users