[Openstack-operators] How to deal with MTU issue on routers servicing vxlan tenant networks? (openstack-ansible with LXC containers)

2017-12-05 Thread David Young
Hi all, I'm running Openstack Ocata (Deployed with openstack-ansible), with the following configuration: * Compute nodesrunning nova and neutron agent * 2 x Controllersrunning neutronserver/agents in LXC containers (as deployed by openstack-ansible playbooks) * Underlying hosts have a single

Re: [Openstack-operators] Security Groups and Metadata Service

2017-12-05 Thread Jeremy Stanley
On 2017-12-05 10:32:10 +0100 (+0100), Saverio Proto wrote: [...] > Because there is no egress rule, the cloud-init will fail to open a > connection to the metadata service. [...] > Does anyone has a good solution to prevent the user from setting the > system in a such a way that does not work ?? P

[Openstack-operators] Security Groups and Metadata Service

2017-12-05 Thread Saverio Proto
Hello, we have this recurring problem with our users. An advanced user deletes all the default security groups to create his own. This user will define only ingress rules. Because there is no egress rule, the cloud-init will fail to open a connection to the metadata service. The user will open

Re: [Openstack-operators] Problem getting cloudkitty to connect to keystone via ssl

2017-12-05 Thread Christophe Sauthier
Hello Ghezal Would it be possible that you paste somewhere yours cloudkitty configuration file ? But also the whole cloudkitty-processor Traceback ? Thanks in advance Christophe Sauthier Christophe Sauthier CEO Objectif Libre : Au service de votre Cloud +33 (0) 6 16 98 63