I will be leaving this mailing list in a few days.
I am going to a new job and I will not be involved with Openstack at
least in the short term future.
Still, it was great working with the Openstack community in the past few years.
If you need to reach me about any bug/patch/review that
we route the Ceph storage network in the same fabric. We did not have
problems with that so far.
Il giorno gio 16 ago 2018 alle ore 10:43 Paul Browne
> Hi operators,
> I had a quick question for those operators who use a routed topology for
you can find information about other deployments reading the User Survey:
For blog posts with experiences from other operators check out:
https://superuser.openstack.org/ and http://planet.openstack.org/
> On Tue, Aug 7, 2018 at 9:30 AM, Saverio Proto wrote:
>> Hello Jimmy,
>> thanks for your help. If I understand correctly the answer you linked,
>> that helps if you operate the cloud and you have acce
> Once you get the release number, you have to look it up here to match
> the release date: https://releases.openstack.org/
> I had to use this the other day when taking the COA.
> Saverio Proto wrote:
> > Hello,
This is maybe a super trivial question bit I have to admit I could not
figure it out.
Can the user with the openstack cli client discover the version of
Openstack that is running ?
For example in kubernetes the kubectl version command returns the
version of the client and the version of
happen very often.
> Can it be RabbitMQ? I'm not sure where to check.
> On Fri, 2018-06-15 at 17:11 +0200, Saverio Proto wrote:
> Hello Radu,
> yours look more or less like a bug report. This you check existing
> open bugs for neutron
yours look more or less like a bug report. This you check existing
open bugs for neutron ? Also what version of openstack are you running
how did you configure enable_isolated_metadata and
enable_metadata_network options ?
2018-06-13 12:45 GMT+02:00 Radu Popescu | eMAG,
on redirect etc).
> What do you need to know?
> Le lun. 28 mai 2018 à 14:50, Saverio Proto a écrit :
>> Hello Chris,
>> I finally had the time to write about my deployment:
I finally had the time to write about my deployment:
in this blog post I explain why I use the kubernetes nginx-ingress
instead of Openstack LBaaS.
u Popescu | eMAG, Technology wrote:
> actually, I didn't know about that option. I'll enable it right now.
> Testing is done every morning at about 4:00AM ..so I'll know tomorrow
> morning if it changed anything.
> On Tue, 2018-05-
Sorry email went out incomplete.
make sure that Openstack rootwrap configured to work in daemon mode
2018-05-22 15:29 GMT+02:00 Saverio Proto <ziopr...@gmail.com>:
do you have the Openstack rootwrap configured to work in daemon mode ?
please read this article:
2018-05-18 10:21 GMT+02:00 Radu Popescu | eMAG, Technology
> so, nova says the VM is ACTIVE and actually boots with no network. We are
> setting some
what we suggest to our users, is to migrate a volume, and to create a
new VM from that volume.
the bad thing is that the new VM has a new IP address, so eventually
DNS records have to be updated by the users.
It works for me in Newton.
Try it at your own risk :)
2018-04-09 13:23 GMT+02:00 Anwar Durrani <durrani.an...@gmail.com>:
> No this is different one. should i try this one ? if it works ?
> On Mon, Apr 9, 2018 at 4:11 PM, Saverio Proto <ziopr...@gmail.com&g
are you talking about this script ?
it does not work for you ?
2018-04-09 11:53 GMT+02:00 Anwar Durrani :
> Hi All,
> Nova resources are out of sync in
I am also for +1
OpenStack-operators mailing list
it would interesting to know how this works. For instances ports,
those ports are created by openvswitch on the compute nodes, where the
neutron-agent will take care of the security groups enforcement (via
iptables or openvswitch rules).
the LBaaS is a namespace that lives where
My idea is that if delete_on_termination flag is set to False the
Volume should never be deleted by Nova.
my 2 cents
2018-03-14 15:10 GMT+01:00 Tim Bell :
> To add another scenario and make things even more difficult (sorry (), if the
> original volume has
> If you’re willing to, I could share with you a way to get a FrankeinCloud
> using a Docker method with kolla to get a pike/queens/whatever cloud at the
> same time that your Ocata one.
I am interested in knowing more about this. If you have any link /
blog post please share them :)
we have this working for Nova ephemeral images already, but Cinder did
not implement this spec:
Is anyone carrying an unmerged patch that implements this spec ?
I could not believe
probably someone here is using stuff like Kibana to look at Openstack
logs. We are trying here to use the json logging, and we are surprised
that the request-id is not printed in the json output.
I wrote this email to the devs:
it makes sense and it is very valuable !
Il 19 dic 2017 4:59 PM, "Matt Riedemann" ha scritto:
> During discussion in the TC channel today , we got talking about how
> there is a perception that you must upgrade all of the services together
> for anything
we have this recurring problem with our users.
An advanced user deletes all the default security groups to create his
own. This user will define only ingress rules.
Because there is no egress rule, the cloud-init will fail to open a
connection to the metadata service.
The user will open
here an example of a trivial patch that is important for people that
do operations, and they have to troubleshoot stuff.
with the old Stable Release thinking this patch would not be accepted
on old stable branches.
Let's see if this gets accepted back to stable/newton
The 1 year release cycle makes a lot of sense to me too. +1
OpenStack-operators mailing list
check out this:
2017-10-16 20:45 GMT+02:00 Christopher Hull :
> Running Liberty.
> I'd like to be able to create new volumes from old ones.
I found this link in my browser history:
Is it the same messages that you are seeing in Xenial ?
2017-10-12 23:26 GMT+02:00 Blair Bethwaite :
> Hi all,
> Has anyone seen guest
; Ah, nice, wasn’t aware. Mateusz is one of the Horizon experts here at CERN
>> I was referring to :)
>> On 25 Sep 2017, at 10:41, Massimo Sgaravatto
>> <massimo.sgarava...@gmail.com> wrote:
>> Just found that there is already this one:
starting 1000 instances in production works for me already. We are on
I described my configuration here:
If things blow up for you with hundreds, probably there is a
I agree this feature of injecting a new keypair is something of great
use. We are always dealing with users that cant access their VMs
But AFAIU here we are talking about injecting a new key at REBUILD. So
it does not fit the scenario of a staff member that leaves !
les if you’re interested.
>> On 25 Sep 2017, at 09:58, Saverio Proto <ziopr...@gmail.com> wrote:
>> I am pinging on IRC robcresswell from the Horizon project. He is still
>> PTL I think.
>> If you are on IRC please jo
> Thanks, Massimo
> 2017-09-25 9:50 GMT+02:00 Saverio Proto <ziopr...@gmail.com>:
>> Hello Massimo,
>> what is your version of Openstack ??
>> thank you
>> 2017-09-25 9:13 GMT
what is your version of Openstack ??
2017-09-25 9:13 GMT+02:00 Massimo Sgaravatto :
> In our OpenStack cloud we have two backends for Cinder (exposed using two
> volume types), and we set different quotas for these two
> The actual fix for this is trivial:
Why the change is called:
Ignore original retried hosts when live migrating
Isn't it implementing the opposite ? Dont Ignore ?
> checking http://169.254.169.254/2009-04-04/instance-id
> failed 1/20: up 188.93. request failed
> failed 2/20: up 191.21. request failed
> failed 3/20: up 193.36. request failed
> failed 4/20: up 195.54. request failed
> failed 5/20: up 197.68. request failed
> failed 6/20: up 199.83. request
openstack console log show
you can check if it is really the dhclient failing to have an address.
it is usually also good to have a look at the nova-compute.log file in
the compute node where the instance is scheduled.
2017-08-31 19:55 GMT+02:00 Divneet Singh
I jump late on the conversation because I was away from the mailing
lists last week.
We run Openstack with both nova ephemeral root disks and cinder volume
boot disks. Both are with ceph rbd backend. It is the user that flags
"boot from volume" in Horizon when starting an instance.
[image: Google Plus]
> <https://plus.google.com/104062177220750809525/posts> [image: Blog]
> 751 Arbor Way, Hillcrest I, Suite 150, Blue Bell, PA 19422
> *P:* 215.297.4400 x232 <(215)%20297-4400> // *F: *215.297.4401
a common problem is packets being dropped when they pass from the
hypervisor to the instance. There is bottleneck there.
check the 'virsh dumpxml' of one of the instances that is dropping
packets. Check for the interface section, should look like:
Kekane, Abhishek <abhishek.kek...@nttdata.com>:
> Hi Saverio,
> Thank you for reply.
> Currently we are using Ocata release for Openstack.
> Please let me know if you get any update.
> Thank you,
> -----Original Message-
I am sorry I dont have an answer for your question. I would have to
try my self everything to give answer because I never experienced this
use case you describe.
I would suggest also to specify what version of Openstack you are
working with. Because the behaviour can change a lot
Allison I clicked on "Add Deployment" and I got a 404 page (with a cat)
The URL I was redirected to is:
2017-06-26 23:44 GMT+02:00 Allison Price :
> Hi everyone,
do you mean the instance has booted from volume ?
when is booted from volume this 0 bytes glance image is created
together with a cinder snapshot.
I wrote about it for my openstack users here:
I think that is by
It is true that we are refreshing something that rarely changes. But
if you deliver a cloud service for several years, at one point you
might have to do these parameters changes.
Something that should not change rarely are the secrets of the ceph
users to talk to the ceph cluster.
I patched this back in liberty.
What version of Openstack are you using ?
2017-06-08 19:36 GMT+02:00 Grant Morley :
> Ignore that now all,
> Managed to fix it by restarting the l3-agent. Looks like it must have been
> cached in memory.
> We use provider networks to essentially take neutron-l3 out of the equation.
> Generally they are shared on all compute hosts, but usually there aren't huge
> numbers of computes.
we have a datacenter completely L3, routing to the host.
to implement the provider networks we are using
is the instance scheduled to an hypervisor ? check this with openstack
server show uuid
if yes check nova-compute.log on the hypervisor. maybe you find some good
information to debug
Il 03 mag 2017 2:16 AM, "Steve Powell" ha
h 1.5.0-1.el7 @3rdParty7
> On 5/2/17, 12:39 PM, "Saverio Proto" <ziopr...@gmail.com> wrote:
> Hello Edgar,
> what is the version of the openstack client ?
> did you export this?
if anyone is interested I have problems with Heat and the Newton upgrade.
I sent an email about this here:
If anyone already faced this issue any help would be appreciated !
I got the mail about the Poll for OpenStack R Release Naming
I am shocked that there are proposed names like Raspberry or Root !
Think about troubleshooting and searching on google:
Openstack Raspberry "string of log file"
The Raspberry or Root words are anti-google words that will
we use rclone a lot, and we are happy with it.
the real problem I would say is that a lot of these tools use the
latest AWS4 signature.
AFAIK the radosgw with Ceph Jewel and Openstack keystone integration
supports only AWS2 signature because of this bug:
floating IPs is the real issue.
When using horizon it is very easy for users to allocate floating ips
but it is also very difficult to release them.
In our production cloud we had to change the default from 50 to 2. We
have to be very conservative with floatingips quota because our
what version of openstack ?
is the instance booting from ephemeral disk or booting from cinder volume ?
When you boot from volume, that will be the root disk of your
instance. The user could have clicked on "Delete Volume on Instance
Delete". It can be selected when creating a new
thank you for the great event. Mariano & all the people from Milano
made an excellent work.
thanks all to all of you that helped moderating the sessions and
contributing to the etherpads.
it was really a great event and I am looking forward for the next ones.
there was a discussion about this here:
we had several sponsor requests to make presentations. We agreed that as
long as the sponsor presentations are strongly technical everybody
> Can someone please put together a list of urls to all the sessions, there are
> so many urls flying around.
you can find the list here:
OpenStack-operators mailing list
I am Italian speaking.
Does not make any sense to have the log messages translated. I think
everything has already being said.
2017-03-11 9:20 GMT+01:00 George Shuklin :
> Whole idea with log translation is half-backed anyway. About the half of
I prepared the skeleton for the session about Upgrades Patches and Packaging
Please contribute to the etherpad with stuff like:
* patches that you are carrying in production
* patches that you dont manage to get
before doing the upgrade, when still in Mitaka (tag 13.1.3), I am
running the folllwing command:
nova-manage db online_data_migrations
I get this output:
Option "verbose" from group "DEFAULT" is deprecated for removal. Its
value may be silently ignored in the future.
Hello Kendall Nelson,
thanks for you email about Story Board. I did not understand if as
Openstack operators, are we supposed to open bugs on storyboard
instead of Launchpad ? When this starts ?
2017-03-03 20:49 GMT+01:00 Kendall Nelson :
us | active
> | tags |
> | updated_at | 2016-12-07T16:01:45Z
> | virtual_size | None
> | visibility | public
Can you share with us the output of:
openstack image show
for that image ?
2017-03-02 13:54 GMT+01:00 Grant Morley <gr...@absolutedevops.io>:
> Unfortunately not, I still get the same error.
> On 02/03/17 12:54, Saverio Proto wrote:
> If you
If you pass the uuid of the image does it work ?
2017-03-02 13:49 GMT+01:00 Grant Morley <gr...@absolutedevops.io>:
> Hi Saverio,
> We are running Mitaka - sorry forgot to mention that.
> On 02/03/17 12:45, Saverio Proto wrote:
> What ve
What version of Openstack are we talking about ?
2017-03-02 12:11 GMT+01:00 Grant Morley :
> Hi All,
> Not sure if anyone can help, but as of today we are unable to launch any
> instances and I have traced back the error to glance. Whenever I try and
I would fill a bug on launchpad for this issue.
114 VMs is not much. Can you identify how to trigger the issue to
reproduce it ? or it just happens randomly ?
When you say rebooting the network node, do you mean the server
running the neutron-server process ?
what version and
I have no idea from this log file. Trying to make nova-compute more
verbose if you dont find anything in the logs
2017-02-20 7:50 GMT+01:00 Anwar Durrani <durrani.an...@gmail.com>:
> On Thu, Feb 16, 2017 at 1:44 PM, Saverio Proto <ziopr...@gmail.com> wrote:
The three new compute nodes that you added are empty, so most likely
the new instances are scheduled to those three (3 attempts) and
something goes wrong.
with admin rights do:
openstack server show uuid
this should give you the info about the compute node where the
instance was scheduled. Check
the ops midcycle is in a about 1 month:
If you need a invitation letter for VISA to Italy please send an email
to egiannu...@enter.eu and Cc: ziopr...@gmail.com .
We will help you will the Italian forms to fill.
ENTER that is hosting
So far I am just learning. I wrote down some notes based on my
experience of this week.
I am looking forward to the Milano Ops Mid-cycle to chat face to face
with more operators interested in Kolla.
The key point is how to grow the Kolla
this feature you describe makes sense only if the tenant VMs are also
aggregated in the same rack. Is this your scenario ?
Given that you could have 3 network nodes running the L3-agent, then
you can make some scripting to stick the specific router (linux
namespace) to the specific
Did you try to restart memcached after chaning the configuration to HA ?
there are two sections where you can configure, memcached_servers
how your config looks like ?
2017-01-24 6:48 GMT+01:00 Chris Apsey :
in the upgrade did the version of ovs change ?
what Openstack distribution are you using ?
2017-01-10 16:30 GMT+01:00 Telmo Morais :
> Hi All,
> We are currently on the process of upgrading from Mitaka to Newton, and on
> the upgraded compute
in the osops-tools-contrib repo so far I proposed always python
scripts that are contained in a single file.
Now I have this file:
that I reuse in many scripts, look at this:
but maybe is not the best idea to commit this generic
> Many thanks for the reply, I'll answer your queries below;
> On 01/12/16 12:49, Saverio Proto wrote:
>> while the problem is in place, you should share the output of
>> ip rule show
>> ip route show table 1
while the problem is in place, you should share the output of
ip rule show
ip route show table 1
It could be just a problem in your ruleset
and, which one is your webserver ? can you tcpdump to make sure reply
packets get out on the NIC with src address 10.0.16.11 ?
snapshot are meant to be backups.
I would not install software on a machine, and then use the snapshot
as a glance image to start many new instances.
you could just create machines with a clean glance image and install
the necessary software with ansible/puppet
if the installation time
look at the log files !
2016-11-09 17:54 GMT+01:00 suresh kumar :
> Hi All,
> I am unable to delete a security group in my kilo environment, this security
> group is not associated to any instances or LB
> nova secgroup-delete Test
we just had the Ops Meetup Team IRC meeting.
There are two possible venues for the next OpenStack Operators
Mid-Cycle meetup: Milano and Tokyo.
To select the venue we created
t time? It is normally 10AM my time which will be 13:00 UTC on the
> By the way, the Barcelona hosting offer has been updated with possible week
> day slots, see
if the instance is booted from Volume, when you "nova snapshot" in the
glance repo you find a image of 0 bytes, that just contains metadata.
you need to make cinder volume snapshots.
This is a recurring FAQ for the users of our cloud, I wrote something
about it here:
Is the '@' character allowed in the tenant/project names ?
2016-10-05 23:36 GMT+02:00 Steve Martinelli :
> There are some restrictions.
> 1. The project name cannot be longer than 64 characters.
> 2. Within a domain, the project name is unique. So you can have
> Alternatively, you could drop the 'external' attribute and attach your
> instances directly to the provider network (no routers or private networks).
I can't. Because in my network design I do not have all the compute
nodes on a common L2 segment.
I have a l3 fabric between the compute nodes.
>  http://beyondtheclouds.github.io
> - Mail original -
>> De: "Saverio Proto" <ziopr...@gmail.com>
>> À: "stig openstack" <stig.openst...@telf
sorry I will not make it today
Il 04 ott 2016 4:42 PM, "Melvin Hillsman" ha scritto:
> Melvin Hillsman
> Ops Technical Lead
> OpenStack Innovation Center
> phone: (210)
Sorry I missed the Mailing List in the Cc:
2016-10-03 9:15 GMT+02:00 Saverio Proto <ziopr...@gmail.com>:
> Hello Kevin,
> thanks for your answer.
> so far I managed to make the network not shared just by making it not
> external. Because I dont need NAT and flo
> How are you creating the provider (external) network?
> On Thu, Sep 29, 2016 at 6:01 AM, Saverio Proto <ziopr...@gmail.com> wrote:
>> - openstack liberty
>> - ubuntu trusty
>> - neutron net
If your setup has a single user database, so all users are under the
same administrative domain, what you describe is like having different
Openstack Regions, or different Nova Cells.
I would suggest to look into Multi Region that is the easier to implement.
In NYC we had this session:
It came out that most of us configure Nagios to be less noisy, and
there are Warning strings that most people just ignore, because these
warnings are harmless and you dont want an email for each
- openstack liberty
- ubuntu trusty
- neutron networking with vxlan tunnels
we have been running Openstack with a single external network so far.
Now we have a specific VLAN in our datacenter with some hardware boxes
that need a connection to a specific tenant network.
At GARR in Rome there will be an event shortly before Barcelona about
Openstack and Identity Federation.
This is a use case that is very important for NREN running public
cloud for Universities, where a Identity Federation is already
once I had a very weird problem with quotas. Usually the quota is per
tenant/project. But somehow you can limit the quota per specific user.
Please can you check in your nova database if this table is empty:
mysql> describe project_user_quotas;
Il 08 set 2016 9:07 AM, "Saverio Proto" <ziopr...@gmail.com> ha scritto:
> Sorry you are on Liberty Centos !!
> Did you try openstack quota show ?
> What do you see ?
> Then try to create a Volume from the CLI. Usually you get better
Sorry you are on Liberty Centos !!
Did you try openstack quota show ?
What do you see ?
Then try to create a Volume from the CLI. Usually you get better errore
Il 08 set 2016 9:05 AM, "Saverio Proto" <ziopr...@gmail.com> ha scritto:
> please tell us a
please tell us at least the version of openstack :)
Il 07 set 2016 4:31 PM, "William Josefsson" ha
> When I create projects with quotas configured, e.g. number volumes 8, and
> try to provision a VM, I get:
> *The requested instance cannot
I am looking at the same problem today.
I am running Liberty, and I am not sure Puppet is doing the right
thing for Ubuntu here:
Should this patch be backported
Is the connection to the database properly working ?
2016-09-07 5:01 GMT+02:00 :
> Hi Everyone,
> I'm trying to install identify service on Ubuntu 16.04 LTS. The guide I use:
> When I
:00 Logan V. <lo...@protiumit.com>:
> Have been using it since kilo. It was a clean pick into Liberty and worked
> great for me.
> On Friday, September 2, 2016, Saverio Proto <ziopr...@gmail.com> wrote:
this is merged upstream in Mitaka:
anyone already did a cherry pick in Liberty and is running this in production ?
I plan to test this soon. Any feedback is appreciated !
if you changed the cinder host name you need also to reflect this
change in the database for the existing volumes.
in mysql you have to do something like:
update volumes set host='newhostname#DEFAULT' where host =
update volumes set host='newhostname' where
1 - 100 of 160 matches
Mail list logo