Re: [ovirt-users] oVirt Reports

2016-08-14 Thread Yedidyah Bar David
On Sun, Aug 14, 2016 at 6:57 PM, Fernando Fuentes  wrote:
> David,
>
> Thats exactly what I am trying to accomplish.
> When I re-run the ovirt setup on my 3.6 system, I give it the IP of my
> ovirt 4.0 machine, Do I leave the DB to the default name? Is there a db
> user and password on the 4.0 machine?
>
> Sorry for so many questions... This is not documented...

Not for 3.6 vs 4.0, but it actually is, here:

http://www.ovirt.org/develop/release-management/features/engine/separate-reports-host/

See also:

http://www.ovirt.org/develop/release-management/features/engine/separate-dwh-host/

In above, each of engine, dwh, reports is in its own machine.
You can do a similar thing with engine+dwh on one and reports on another.

Do not hesitate ping back if you are stuck!

Best,

>
> Thank you for all the help!
>
> Regards,
>
> --
> Fernando Fuentes
> ffuen...@txweather.org
> http://www.txweather.org
>
> On Sun, Aug 14, 2016, at 02:01 AM, Yedidyah Bar David wrote:
>> On Sat, Aug 13, 2016 at 10:38 PM, Fernando Fuentes 
>> wrote:
>> > Team,
>> >
>> > I got two oVirt Servers. One in 4.0.2 and one in 3.6.X
>> > I love the new 4.0 dashboard, But I need a way to continue to build
>> > reports with ease, 3.6 Can do this with ovirt-reports. How can I make my
>> > oVirt 4.0.2 send data for reports to my ovirt reports on 3.6?
>> >
>> > Thanks for the help team!
>>
>> I didn't try this myself, but pointing your reports setup to the 4.0 dwh
>> database should work. If you have problems, please give more details -
>> it's not clear what exactly you have on each machine.
>>
>> Generally speaking, oVirt does not currently provide tools to make
>> the engine or dwh "send data" elsewhere (a 3.6 reports or whatever).
>> You can try doing this yourself using generic postgresql means/tools.
>>
>> Best
>> --
>> Didi



-- 
Didi
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] ovirt 3.5.6: ERROR: duplicate key value violates unique constraint "pk_images" during import

2016-08-14 Thread Andrea Ghelardi
Hallo all,

I'm currently unable to import/activate VM due to error above.
It has been a long series of unfortunate events.
Long story short:
- VM running on storage on iscsi failing disks
- put storage and server in maint. Shut down server
- restart server.
- server has a misconfiguration on lvm/multipath rules (not due to ovirt)
- put storage and server active
- cluster goes down. Put storage in maintenance again. Detached storage from 
cluster (ach! That was unfortunate).
- cluster now ok. Storage ok. Activate storage.
- trying to import VM. Ovirt replies with error in subject and attached.

How can I recover from this situation?
It would be great to recover the entire VM, but I'm more interested in disks 
which are in unregistered state than VM itself.

Thank you all
2016-08-14 17:49:32,414 INFO  
[org.ovirt.engine.core.bll.ImportVmFromConfigurationCommand] 
(ajp--127.0.0.1-8702-9) [446f3b0e] Lock Acquired to object EngineLock [exclus
iveLocks= key: Hertz value: VM_NAME
, sharedLocks= key: 49950ad2-05cd-4c5a-bde7-b702199fa250 value: REMOTE_VM
]
2016-08-14 17:49:32,446 INFO  
[org.ovirt.engine.core.vdsbroker.irsbroker.DoesImageExistVDSCommand] 
(ajp--127.0.0.1-8702-9) [446f3b0e] START, DoesImageExistVDSCommand( s
toragePoolId = 0002-0002-0002-0002-009c, ignoreFailoverLimit = 
false, storageDomainId = 2103720d-5821-482e-a265-2152ec97eb0f, imageGroupId = 
29b97d45-e481-4
35d-a50a-f2a890a678bf, imageId = 0225fa05-be1e-44a6-9d9e-1203b8144933), log id: 
3d5b900c
2016-08-14 17:49:32,604 INFO  
[org.ovirt.engine.core.vdsbroker.irsbroker.DoesImageExistVDSCommand] 
(ajp--127.0.0.1-8702-9) [446f3b0e] FINISH, DoesImageExistVDSCommand,
return: true, log id: 3d5b900c
2016-08-14 17:49:32,605 INFO  
[org.ovirt.engine.core.vdsbroker.irsbroker.DoesImageExistVDSCommand] 
(ajp--127.0.0.1-8702-9) [446f3b0e] START, DoesImageExistVDSCommand( s
toragePoolId = 0002-0002-0002-0002-009c, ignoreFailoverLimit = 
false, storageDomainId = a074b2a8-0cd3-4d28-bc29-ad37587a8777, imageGroupId = 
bba3bd45-d02d-4
032-8bb0-e723b7acf23b, imageId = 20f9d5eb-b4d9-4a5d-b75e-3af013c56604), log id: 
464e234c
2016-08-14 17:49:32,792 INFO  
[org.ovirt.engine.core.vdsbroker.irsbroker.DoesImageExistVDSCommand] 
(ajp--127.0.0.1-8702-9) [446f3b0e] FINISH, DoesImageExistVDSCommand,
return: true, log id: 464e234c
2016-08-14 17:49:32,792 INFO  
[org.ovirt.engine.core.vdsbroker.irsbroker.DoesImageExistVDSCommand] 
(ajp--127.0.0.1-8702-9) [446f3b0e] START, DoesImageExistVDSCommand( s
toragePoolId = 0002-0002-0002-0002-009c, ignoreFailoverLimit = 
false, storageDomainId = 2103720d-5821-482e-a265-2152ec97eb0f, imageGroupId = 
6804229e-68f7-4
6a8-90d3-c065529f9624, imageId = 76b4f302-5182-478d-a7d3-cf4c8b6abe40), log id: 
254ca74a
2016-08-14 17:49:32,815 INFO  
[org.ovirt.engine.core.vdsbroker.irsbroker.DoesImageExistVDSCommand] 
(ajp--127.0.0.1-8702-9) [446f3b0e] FINISH, DoesImageExistVDSCommand,
return: true, log id: 254ca74a
2016-08-14 17:49:32,815 INFO  
[org.ovirt.engine.core.vdsbroker.irsbroker.DoesImageExistVDSCommand] 
(ajp--127.0.0.1-8702-9) [446f3b0e] START, DoesImageExistVDSCommand( s
toragePoolId = 0002-0002-0002-0002-009c, ignoreFailoverLimit = 
false, storageDomainId = 2103720d-5821-482e-a265-2152ec97eb0f, imageGroupId = 
217a34f9-ca8c-4a13-a2a2-9dde4c329c55, imageId = 
621c0b0c-c041-46e0-8c00-e69896fcf554), log id: 4b7afe67
2016-08-14 17:49:32,842 INFO  
[org.ovirt.engine.core.vdsbroker.irsbroker.DoesImageExistVDSCommand] 
(ajp--127.0.0.1-8702-9) [446f3b0e] FINISH, DoesImageExistVDSCommand, return: 
true, log id: 4b7afe67
2016-08-14 17:49:32,843 INFO  
[org.ovirt.engine.core.vdsbroker.irsbroker.DoesImageExistVDSCommand] 
(ajp--127.0.0.1-8702-9) [446f3b0e] START, DoesImageExistVDSCommand( 
storagePoolId = 0002-0002-0002-0002-009c, ignoreFailoverLimit = 
false, storageDomainId = 2103720d-5821-482e-a265-2152ec97eb0f, imageGroupId = 
efb67e0b-c592-406a-949c-121102eef796, imageId = 
44420cae-7c90-461a-bee1-7552758ecee9), log id: 77d442e7
2016-08-14 17:49:32,865 INFO  
[org.ovirt.engine.core.vdsbroker.irsbroker.DoesImageExistVDSCommand] 
(ajp--127.0.0.1-8702-9) [446f3b0e] FINISH, DoesImageExistVDSCommand,
2016-08-14 17:49:32,908 INFO  
[org.ovirt.engine.core.bll.ImportVmFromConfigurationCommand] 
(org.ovirt.thread.pool-8-thread-42) [446f3b0e] Running command: 
ImportVmFromConfigurationCommand internal: false. Entities affected :  ID: 
a074b2a8-0cd3-4d28-bc29-ad37587a8777 Type: StorageAction group IMPORT_EXPORT_VM 
with role type ADMIN,  ID: 2103720d-5821-482e-a265-2152ec97eb0f Type: 
StorageAction group IMPORT_EXPORT_VM with role type ADMIN,  ID: 
2103720d-5821-482e-a265-2152ec97eb0f Type: StorageAction group IMPORT_EXPORT_VM 
with role type ADMIN,  ID: 2103720d-5821-482e-a265-2152ec97eb0f Type: 
StorageAction group IMPORT_EXPORT_VM with role type ADMIN,  ID: 
2103720d-5821-482e-a265-2152ec97eb0f Type: StorageAction group IMPORT_EXPORT_VM 
with role type ADMIN
2016-08-14 17:49:33,079 INFO  

Re: [ovirt-users] Move VM disks from gluster storage to local storage

2016-08-14 Thread Siavash Safi
On Sun, Aug 14, 2016 at 10:04 PM Nir Soffer  wrote:

> On Sun, Aug 14, 2016 at 8:10 PM, Siavash Safi 
> wrote:
> >
> >
> > On Sun, Aug 14, 2016 at 8:07 PM Nir Soffer  wrote:
> >>
> >> On Sun, Aug 14, 2016 at 5:55 PM, Siavash Safi 
> >> wrote:
> >> > Hi,
> >> >
> >> > An unknown bug broke our gluster storage (dom_md/ids is corrupted) and
> >> > oVirt
> >> > no longer activates the storage(I tried to recover it using the
> similar
> >> > issues reported in mailing list but it didn't work).
> >>
> >> Can you explain what you did?
> >
> > cd /mnt/4697fbde-45fb-4f91-ac4c-5516bc59f683/dom_md/
> > rm ids
> > touch ids
> > sanlock direct init -s 4697fbde-45fb-4f91-ac4c-5516bc59f683:0:ids:1048576
>
> The offset parameter should be 0, not 1048576:
>
> sanlock direct init -s 4697fbde-45fb-4f91-ac4c-5516bc59f683:0:ids:0
>
> See
> http://lists.ovirt.org/pipermail/users/2016-February/038046.html
>
> Please retry this.
>
> I didn't know what the number at the end of the sring does ;)


> Also, are you using replica 3? These issues  typically happened when people
> used replica 2 gluster volumes.
>
Actually we removed one of the broken nodes from gluster and tried to setup
local storage.
I wiped the storage and added the bricks back to gluster.

Thanks Nir, recreating the ids file with correct offset and resizing
gluster to replica 3 fixed the issue :)

>
> >> The best way to fix this is to initialize the corrupt id file and
> >> activate the domain.
> >
> > This would be great!
> >>
> >>
> >>
> >> > As I checked VM disk images are still accessible when I mount the
> >> > gluster
> >> > storage manually.
> >> > How can we manually move the VM disk images to local storage? (oVirt
> >> > complains about gluster storage being inactive when using the web
> >> > interface
> >> > for move/copy)
> >>
> >> You can easily copy the images to another file based storage (nfs,
> >> gluster) like this:
> >>
> >> 1. activate other storage domain using engine
> >> 2. mount gluster domain manually
> >> 3. copy the image from gluster domain to the other domain:
> >>
> >> cp -r gluster-domain-mountpoint/images/image-uuid
> >> /rhev/data-center/mnt/server:_path/other-domain-uuid/images/
> >>
> >> But the images will not be available since engine does know them.
> >> Maybe this can be
> >> fixed by modifying engine database.
> >>
> > How complicated is it?
>
> I never tried this, lets try the simple way first.
>
> >> Another solution (if you are using ovirt 4.0), is to upload the images
> >> to a new disk,
> >> and attach the disk to the vm instead of the missing disk.
> >
> > We are running 3.6
>
> Maybe consider an upgrade?
>
> Nir
>
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Move VM disks from gluster storage to local storage

2016-08-14 Thread Nir Soffer
On Sun, Aug 14, 2016 at 8:10 PM, Siavash Safi  wrote:
>
>
> On Sun, Aug 14, 2016 at 8:07 PM Nir Soffer  wrote:
>>
>> On Sun, Aug 14, 2016 at 5:55 PM, Siavash Safi 
>> wrote:
>> > Hi,
>> >
>> > An unknown bug broke our gluster storage (dom_md/ids is corrupted) and
>> > oVirt
>> > no longer activates the storage(I tried to recover it using the similar
>> > issues reported in mailing list but it didn't work).
>>
>> Can you explain what you did?
>
> cd /mnt/4697fbde-45fb-4f91-ac4c-5516bc59f683/dom_md/
> rm ids
> touch ids
> sanlock direct init -s 4697fbde-45fb-4f91-ac4c-5516bc59f683:0:ids:1048576

The offset parameter should be 0, not 1048576:

sanlock direct init -s 4697fbde-45fb-4f91-ac4c-5516bc59f683:0:ids:0

See
http://lists.ovirt.org/pipermail/users/2016-February/038046.html

Please retry this.

Also, are you using replica 3? These issues  typically happened when people
used replica 2 gluster volumes.

>> The best way to fix this is to initialize the corrupt id file and
>> activate the domain.
>
> This would be great!
>>
>>
>>
>> > As I checked VM disk images are still accessible when I mount the
>> > gluster
>> > storage manually.
>> > How can we manually move the VM disk images to local storage? (oVirt
>> > complains about gluster storage being inactive when using the web
>> > interface
>> > for move/copy)
>>
>> You can easily copy the images to another file based storage (nfs,
>> gluster) like this:
>>
>> 1. activate other storage domain using engine
>> 2. mount gluster domain manually
>> 3. copy the image from gluster domain to the other domain:
>>
>> cp -r gluster-domain-mountpoint/images/image-uuid
>> /rhev/data-center/mnt/server:_path/other-domain-uuid/images/
>>
>> But the images will not be available since engine does know them.
>> Maybe this can be
>> fixed by modifying engine database.
>>
> How complicated is it?

I never tried this, lets try the simple way first.

>> Another solution (if you are using ovirt 4.0), is to upload the images
>> to a new disk,
>> and attach the disk to the vm instead of the missing disk.
>
> We are running 3.6

Maybe consider an upgrade?

Nir
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] How to open vm console by API ?

2016-08-14 Thread Juan Hernández
On 08/14/2016 01:26 PM, Nicolás wrote:
> Hi,
> 
> This has been asked a short time ago, you can find the thread in [1].
> 
> In [2] you can find an unofficial oVirt project written in Python + QT5
> that already does that, it connects to the API, gets a list of available
> VMs for the supplied credentials and then you can open a VM console to
> any of these machines (using virt-viewer).
> 
> Regards.
> 
>   [1]: http://lists.ovirt.org/pipermail/users/2016-June/040222.html
>   [2]: https://github.com/nkovacne/ovirt-desktop-client
> 

In addition to what Nicolás suggests you can also take inspiration from
how the "console" command is implemented in the "ovirt-engine-cli" tool:


https://github.com/oVirt/ovirt-engine-cli/blob/master/src/ovirtcli/command/console.py

That code shows how to obtain the required VM. Information (display
address, display port, etc). Then the virt-viewer configuration file is
created here:


https://github.com/oVirt/ovirt-engine-cli/blob/master/src/ovirtcli/platform/posix/spice.py

Note also that recent versions of the engine (including 3.6) can
generate the virt-viewer configutation file for you. For example, if you
know the id of the VM you can get the virt-viewer configuration file and
then launch the "remote-viewer" program with a simple script like this:

---8<---
#!/bin/bash -ex

# Connection parameters:
url="https://engine36.local/ovirt-engine/api;
user="admin@internal"
password="..."

# The identifier of the VM:
vm="3235367b-9bae-4ff1-87ed-b42446e97046"

# The name of the protocol, encoded in hexadecimal, it will
# be 5350494345 for SPICE and 564e43 for VNC:
protocol="5350494345"

# Download the "virt-viewer" configuration file:
curl \
--verbose \
--cacert /etc/pki/ovirt-engine/ca.pem \
--request GET \
--user "${user}:${password}" \
--header "Version: 3" \
--header "Accept: application/x-virt-viewer" \
--output "${vm}.vv" \
"${url}/vms/${vm}/graphicsconsoles/${protocol}"

# Launch the "virt-viewer" program (it will automatically delete
# the configuration file once loaded):
remote-viewer "${vm}.vv"
--->8---

> El 12/08/16 a las 07:59, Wang Evan escribió:
>>
>> Hi :
>>
>>  
>>
>> I want to integrate oVirt-engine into our system platform. In
>> reference to ovirt rest API , I have finished added host and create
>> virtual machine. But I can't find the way to open vm console by API or
>> CLI ,so what should I do ?
>>
>>  
>>
>> Thanks !
>>
>>  
>>
>> Evan
>>

-- 
Dirección Comercial: C/Jose Bardasano Baos, 9, Edif. Gorbea 3, planta
3ºD, 28016 Madrid, Spain
Inscrita en el Reg. Mercantil de Madrid – C.I.F. B82657941 - Red Hat S.L.
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Move VM disks from gluster storage to local storage

2016-08-14 Thread Siavash Safi
On Sun, Aug 14, 2016 at 8:07 PM Nir Soffer  wrote:

> On Sun, Aug 14, 2016 at 5:55 PM, Siavash Safi 
> wrote:
> > Hi,
> >
> > An unknown bug broke our gluster storage (dom_md/ids is corrupted) and
> oVirt
> > no longer activates the storage(I tried to recover it using the similar
> > issues reported in mailing list but it didn't work).
>
> Can you explain what you did?
>
cd /mnt/4697fbde-45fb-4f91-ac4c-5516bc59f683/dom_md/
rm ids
touch ids
sanlock direct init -s 4697fbde-45fb-4f91-ac4c-5516bc59f683:0:ids:1048576

>
> The best way to fix this is to initialize the corrupt id file and
> activate the domain.

This would be great!

>
>
> As I checked VM disk images are still accessible when I mount the gluster
> > storage manually.
> > How can we manually move the VM disk images to local storage? (oVirt
> > complains about gluster storage being inactive when using the web
> interface
> > for move/copy)
>
> You can easily copy the images to another file based storage (nfs,
> gluster) like this:
>
> 1. activate other storage domain using engine
> 2. mount gluster domain manually
> 3. copy the image from gluster domain to the other domain:
>
> cp -r gluster-domain-mountpoint/images/image-uuid
> /rhev/data-center/mnt/server:_path/other-domain-uuid/images/
>
> But the images will not be available since engine does know them.
> Maybe this can be
> fixed by modifying engine database.
>
> How complicated is it?


> Another solution (if you are using ovirt 4.0), is to upload the images
> to a new disk,
> and attach the disk to the vm instead of the missing disk.

We are running 3.6


>
>
Nir
>
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] oVirt Reports

2016-08-14 Thread Fernando Fuentes
David,

Thats exactly what I am trying to accomplish.
When I re-run the ovirt setup on my 3.6 system, I give it the IP of my
ovirt 4.0 machine, Do I leave the DB to the default name? Is there a db
user and password on the 4.0 machine?

Sorry for so many questions... This is not documented...

Thank you for all the help!

Regards,

-- 
Fernando Fuentes
ffuen...@txweather.org
http://www.txweather.org

On Sun, Aug 14, 2016, at 02:01 AM, Yedidyah Bar David wrote:
> On Sat, Aug 13, 2016 at 10:38 PM, Fernando Fuentes 
> wrote:
> > Team,
> >
> > I got two oVirt Servers. One in 4.0.2 and one in 3.6.X
> > I love the new 4.0 dashboard, But I need a way to continue to build
> > reports with ease, 3.6 Can do this with ovirt-reports. How can I make my
> > oVirt 4.0.2 send data for reports to my ovirt reports on 3.6?
> >
> > Thanks for the help team!
> 
> I didn't try this myself, but pointing your reports setup to the 4.0 dwh
> database should work. If you have problems, please give more details -
> it's not clear what exactly you have on each machine.
> 
> Generally speaking, oVirt does not currently provide tools to make
> the engine or dwh "send data" elsewhere (a 3.6 reports or whatever).
> You can try doing this yourself using generic postgresql means/tools.
> 
> Best
> -- 
> Didi
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] LVM2 Thinprovisioned

2016-08-14 Thread Yaniv Kaul
On Thu, Aug 11, 2016 at 8:27 PM, Fernando Frediani <
fernando.fredi...@upx.com.br> wrote:

> Really ? That's pretty bad and another downside unfortunately.
>
> The fact that the only option for block storage is LVM (so there is not
> suitable Clustered Filesystem to run QCOW2 files) and now that LVM2
> Thinprovisioned is not supported can be a real issue where Thinprovisioned
> LUNs are not available in the Storage Controller.
>

I think you are missing the design of the oVirt storage sub-system. There
is no need to running a clustered filesystem - oVirt ensures only one host
access a logical volume (disk) at any given time.

I don't see exactly how LVM2 thin provisioning would have helped if the
storage controller does not support thin provisioning - if you give 1TB to
oVirt, why does it matter if it uses LVM TP or not? (and we can use qcow2
over LVM). Perhaps I'm missing something here.

Note that you can provision some LUN and when needed, just add more LUNs to
the storage domain. You can also extend it, of course.


> Have these topics ever came up in the feature/product management meetings
> are any of them something being considered ?
> The same way CPU and Memory overprovision are key features in order to
> justify the overall solution cost Storage Thinprovision equally necessary
> otherwise the Storage stuff end up costing more than half of whole platform
> solution.
>
> Thanks for the answer anyway. Hopefully at least LVM2 Thinprovisioning
> comes up anytime soon.


Don't think so. Why? As a replacement of qcow2? Not sure it's worth the
effort (you'll also need to get snapshots and all under LVM2 - what is the
clear benefit here?).
Y.


>
> Fernando
>
>
>
> Em 11/08/2016 12:54, Nir Soffer escreveu:
>
>> On Tue, Aug 9, 2016 at 3:16 PM, Fernando Frediani
>>  wrote:
>>
>>> Hello all.
>>>
>>> When you use oVirt with a Block Storage the only option available to
>>> store
>>> de VMs is LVM.
>>>
>>> Does LVM in oVirt use Thinprovisoned (supported in LVM2) instead of
>>> having
>>> to use the SAN Thinprovisioned features ?
>>>
>> No, we use regular lvs. thin pool are not supported in a cluster.
>>
>> Using thin provisioned LUN for ovirt storage domain is the best option
>> (supported
>> since 4.0). We discard removed lvs, so you get back the storage on the
>> storage
>> server and can use it for other thin provisioned LUNs.
>>
>> Nir
>>
>
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users
>
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] Move VM disks from gluster storage to local storage

2016-08-14 Thread Siavash Safi
Hi,

An unknown bug broke our gluster storage (dom_md/ids is corrupted) and
oVirt no longer activates the storage(I tried to recover it using the
similar issues reported in mailing list but it didn't work).
As I checked VM disk images are still accessible when I mount the gluster
storage manually.
How can we manually move the VM disk images to local storage? (oVirt
complains about gluster storage being inactive when using the web interface
for move/copy)

Thanks,
Siavash
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] General system updates policy

2016-08-14 Thread David Gossage
On Sun, Aug 14, 2016 at 5:49 AM, Yaniv Dary  wrote:

> We try to keep up with latest releases, so it should be quite safe.
>

Ok, thanks


>
> Yaniv Dary
> Technical Product Manager
> Red Hat Israel Ltd.
> 34 Jerusalem Road
> Building A, 4th floor
> Ra'anana, Israel 4350109
>
> Tel : +972 (9) 7692306
> 8272306
> Email: yd...@redhat.com
> IRC : ydary
>
>
> On Fri, Aug 12, 2016 at 9:01 PM, David Gossage <
> dgoss...@carouselchecks.com> wrote:
>
>> Is it considered safe from an ovirt stability standpoint to apply yum
>> updates to the hosts and engine as centos/redhat release them?
>>
>> For example the recent https://rhn.redhat.com/errata/RHSA-2016-1606.html
>> update for qemu.  If I run yum update and update that is their any worry
>> for me that it has not been tested with oVirt and so versions will break
>> something.  Same with kernels, libraries etc..
>>
>>
>> *David Gossage*
>> *Carousel Checks Inc. | System Administrator*
>> *Office* 708.613.2284
>>
>> ___
>> Users mailing list
>> Users@ovirt.org
>> http://lists.ovirt.org/mailman/listinfo/users
>>
>>
>
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] HostedEngine with HA

2016-08-14 Thread Roy Golan
On 12 August 2016 at 20:23, Carlos Rodrigues  wrote:

> Hello,
>
> I have one cluster with two hosts with power management correctly
> configured and one virtual machine with HostedEngine over shared
> storage with FiberChannel.
>
> When i shutdown the network of host with HostedEngine VM,  it should be
> possible the HostedEngine VM migrate automatically to another host?
>
> migrate on which network?


> What is the expected behaviour on this HA scenario?
>

After a few minutes your vm will be shutdown by the High Availability
agent, as it can't see network, and started on another host.

>
> Regards,
>
> --
> Carlos Rodrigues
>
> Engenheiro de Software Sénior
>
> Eurotux Informática, S.A. | www.eurotux.com
> (t) +351 253 680 300 (m) +351 911 926 110
>
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users
>
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] oVirt 4.0 and multipath.conf for HPE 3PAR. What do you advise?

2016-08-14 Thread Nir Soffer
On Sat, Aug 13, 2016 at 4:03 PM,   wrote:
> Hello, oVirt guru's !
>
> I installed oVirt 4.0 on several servers HP ProLiant DL360 G5 with 
> QLogic/Emulex 4G dual-port HBAs.
> These servers have multipath connection to the storage system HP 3PAR 7200.
>
> Before installing oVirt to servers I set up the configuration file 
> /etc/multipath.conf according to the vendor recommendations from document 
> "HPE 3PAR Red Hat Enterprise Linux and Oracle Linux Implementation Guide 
> (emr_na-c04448818-9.pdf)"
> https://blog.it-kb.ru/2016/06/12/configuring-device-mapper-multipathing-dm-multipat-mpio-in-centos-linux-7-2-with-emulex-and-qlogic-fc-hba-connecting-over-san-storage-hp-3par-7200-3par-os-3-2-2/
>
> Before installing oVirt my multipath.conf was the:
>
> ---> start of /etc/multipath.conf <-
>
> defaults {
> polling_interval 10

This will cause delays in path checking, better use the default from vdsm conf

> user_friendly_names no
> find_multipaths yes

This ensures that devices with single path will not be detected by ovirt, unless
the device is listed in the "multipaths" section. This means you will have to
update multipath.conf manually on all hosts each time you want to add
a new device.
It is recommended to keep the default from vdsm.conf

> }
> blacklist {
> devnode "^cciss\/c[0-9]d[0-9]*"

Not sure why you need this, but this seems harmless

> }
> multipaths {
>multipath {
>wwid   360002ac00016cec9
>alias  3par-vv2
>}
>multipath {
>wwid   360002ac00017cec9
>alias  3par-vv1
>   }
> }
> devices {
> device {
> vendor "3PARdata"
> product "VV"
> path_grouping_policy group_by_prio
> path_selector "round-robin 0"
> path_checker tur
> features "0"
> hardware_handler "1 alua"
> prio alua
> failback immediate
> rr_weight uniform
> no_path_retry 18

This means 18 retries, and with polling internal of 10 seconds, 180 second
timeout when all paths has become faulty. This will cause long timeouts in
various vdsm operations, leading to timeouts on engine side, and also
increase the chance of a host becoming non-operational because of delay
in storage monitoring.

It is recommended to use small number of retries, like 4, to avoid long delays
in vdsm.

> rr_min_io_rq 1
> detect_prio yes
> }
> }
> ---> end of /etc/multipath.conf <-
>
> But after installing oVirt file multipath.conf has changed to:
>
> ---> start of /etc/multipath.conf <-
> defaults {
> polling_interval5
> no_path_retry   fail

You can change this to small number like 4, to match other configuration.

> user_friendly_names no
> flush_on_last_del   yes
> fast_io_fail_tmo5
> dev_loss_tmo30
> max_fds 4096

You should keep these values, unless the storage vendor has
a good reason to change them.

> }
> devices {
> device {
> all_devsyes
> no_path_retry   fail

I would change this to:

no_path_retry 4

> }
> }
> ---> end of /etc/multipath.conf <-
>
> Now I'm not sure that this configuration is optimal. What do you advise?

1. Add your changes to the file created by vdsm
2. Update no_path_retry to small number (e.g 4)
3. Add "# VDSM PRIVATE" to the second line - the first 2 lines should be:

# VDSM REVISION 1.2
# VDSM PRIVATE

With the "# VDSM PRIVATE" tag, vdsm will never overwrite multipath.conf.
You need to update this file on all hosts manually.

4. Copy multipath.conf to all hosts
5. Reload multipathd on all hosts:

systemctl reload multipathd

Nir
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] General system updates policy

2016-08-14 Thread Gianluca Cecchi
On Sun, Aug 14, 2016 at 12:49 PM, Yaniv Dary  wrote:

> We try to keep up with latest releases, so it should be quite safe.
>
> Yaniv Dary
>
>
> On Fri, Aug 12, 2016 at 9:01 PM, David Gossage <
> dgoss...@carouselchecks.com> wrote:
>
>> Is it considered safe from an ovirt stability standpoint to apply yum
>> updates to the hosts and engine as centos/redhat release them?
>>
>> For example the recent https://rhn.redhat.com/errata/RHSA-2016-1606.html
>> update for qemu.  If I run yum update and update that is their any worry
>> for me that it has not been tested with oVirt and so versions will break
>> something.  Same with kernels, libraries etc..
>>
>>
>>
>>
>
Just to notice that for this particular errata actually the package
deployed in oVirt is of kind qemu-kvm-ev and not qemu-kvm and its version,
at least for oVirt 3.6 on CentOS is
currently qemu-kvm-ev-2.3.0-31.el7_2.10.1.x86_64 and
not qemu-kvm-1.5.3-105.el7_2.7.x86_64.rpm
I don't know if it is affected too and in that case the expected release
date
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Storage for my Environment

2016-08-14 Thread Elad Ben Aharon
As Yaniv suggested, the Gluster Hyper-Converged solution [1] will give you
the ability to have all hosts access the storage.

[1]
http://www.ovirt.org/develop/release-management/features/engine/self-hosted-engine-hyper-converged-gluster-support/

On Sun, Aug 14, 2016 at 1:52 PM, Elad Ben Aharon 
wrote:

> Hi Michael,
>
> You can create a local storage domain using the host's local storage
> drive. But, by design, local Data-Centers can have only a single host (i.e,
> you can't have other hosts using this storage).
>
> For local storage deployment, first create a directory on the file system
> of the host's local drive (#mkdir ), change dir owner to vdsm:kvm
> (#chown vdsm:kvm ). Then, put the host in maintenance, create a
> new Data-Center of local storage type, add a cluster to it and add the host
> you put in maintenance to the cluster. Activate the host and create a local
> storage domain.
>
>
>
> Elad
>
> On Fri, Aug 12, 2016 at 12:45 PM, Michael Cooper 
> wrote:
>
>> Hello Guys,
>>
>> I am sorry ask a stupid question again, however I am not sure how
>> to add storage to the environment that I have at the moment. I have 4
>> Servers 3 of them are AMD and one Intel Core i7, on my servers I have 2
>> Dell SC1435's and one HP DL385 G5
>>
>> I have the Engine Running and I have added a node as well, Both of them
>> are Physical servers they both have 1 tb drives, I would like to add the
>> drive in the node as storage how would I accomplish that?
>>
>> Thank you very much in advance,
>> --
>> *Michael Cooper*
>> http://www.coopfire.com
>> Linux/VMWare Certified Professional
>>
>> ___
>> Users mailing list
>> Users@ovirt.org
>> http://lists.ovirt.org/mailman/listinfo/users
>>
>>
>
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] oVirt 4.0 and multipath.conf for HPE 3PAR. What do you advise?

2016-08-14 Thread Yaniv Dary
Changing multpath  conf is not supported, since this file is managed by
VDSM.
It should work well for the oVirt use case. Configuration should be changed
via the manager if needed and not via the conf.

Yaniv Dary
Technical Product Manager
Red Hat Israel Ltd.
34 Jerusalem Road
Building A, 4th floor
Ra'anana, Israel 4350109

Tel : +972 (9) 7692306
8272306
Email: yd...@redhat.com
IRC : ydary


On Sat, Aug 13, 2016 at 4:03 PM,  wrote:

> Hello, oVirt guru's !
>
> I installed oVirt 4.0 on several servers HP ProLiant DL360 G5 with
> QLogic/Emulex 4G dual-port HBAs.
> These servers have multipath connection to the storage system HP 3PAR 7200.
>
> Before installing oVirt to servers I set up the configuration file
> /etc/multipath.conf according to the vendor recommendations from document
> "HPE 3PAR Red Hat Enterprise Linux and Oracle Linux Implementation Guide
> (emr_na-c04448818-9.pdf)"
> https://blog.it-kb.ru/2016/06/12/configuring-device-mapper-
> multipathing-dm-multipat-mpio-in-centos-linux-7-2-with-
> emulex-and-qlogic-fc-hba-connecting-over-san-storage-
> hp-3par-7200-3par-os-3-2-2/
>
> Before installing oVirt my multipath.conf was the:
>
> ---> start of /etc/multipath.conf <-
>
> defaults {
> polling_interval 10
> user_friendly_names no
> find_multipaths yes
> }
> blacklist {
> devnode "^cciss\/c[0-9]d[0-9]*"
> }
> multipaths {
>multipath {
>wwid   360002ac00016cec9
>alias  3par-vv2
>}
>multipath {
>wwid   360002ac00017cec9
>alias  3par-vv1
>   }
> }
> devices {
> device {
> vendor "3PARdata"
> product "VV"
> path_grouping_policy group_by_prio
> path_selector "round-robin 0"
> path_checker tur
> features "0"
> hardware_handler "1 alua"
> prio alua
> failback immediate
> rr_weight uniform
> no_path_retry 18
> rr_min_io_rq 1
> detect_prio yes
> }
> }
> ---> end of /etc/multipath.conf <-
>
> But after installing oVirt file multipath.conf has changed to:
>
> ---> start of /etc/multipath.conf <-
> defaults {
> polling_interval5
> no_path_retry   fail
> user_friendly_names no
> flush_on_last_del   yes
> fast_io_fail_tmo5
> dev_loss_tmo30
> max_fds 4096
> }
> devices {
> device {
> all_devsyes
> no_path_retry   fail
> }
> }
> ---> end of /etc/multipath.conf <-
>
> Now I'm not sure that this configuration is optimal. What do you advise?
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users
>
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] xml config file being used in ovirt different from virsh?

2016-08-14 Thread Yaniv Dary
You should only use the management to keep changes.
We added network filtering options in 4.0.
There is also a option of VDSM hook for things that are not supported via
the manager.

Yaniv Dary
Technical Product Manager
Red Hat Israel Ltd.
34 Jerusalem Road
Building A, 4th floor
Ra'anana, Israel 4350109

Tel : +972 (9) 7692306
8272306
Email: yd...@redhat.com
IRC : ydary


On Sat, Aug 13, 2016 at 12:15 AM, Bill Bill  wrote:

> It seems like when starting the VM through the oVirt dashboard, it’s
> either overwriting or removing those values.
>
>
>
> *From: *Bill Bill 
> *Sent: *Friday, August 12, 2016 3:04 PM
> *To: *users@ovirt.org
> *Subject: *xml config file being used in ovirt different from virsh?
>
>
>
> I have a VM with network filtering enabled, specifically the clean-traffic
> filter.
>
>
>
> Through virsh, I modify the configuration to reflect changes like this:
>
>
>
>  
>
> 
>
> 
>
>   
>
>
>
> This only allows those two specified IP’s to communicate on the VM. I’ve
> defined the xml through virsh.
>
>
>
> Now, if I start the VM directly through virsh, those rules apply and work
> correctly. I can add any other random IP from the same subnet and it does
> not work, as expected. Only the two Ip’s specified above will respond.
>
>
>
> This unfortunately, makes the VM appear to be down from with the ovirt
> dashboard if it’s started manually through virsh.
>
>
>
> If I edit the machine through virsh but do not start it and then go onto
> oVirt to start the VM, it seems the configuration is not loaded – does
> oVirt load a different configuration file other than
> /etc/libvirt/qemu/machine.xml?
>
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users
>
>
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Storage for my Environment

2016-08-14 Thread Elad Ben Aharon
Hi Michael,

You can create a local storage domain using the host's local storage drive.
But, by design, local Data-Centers can have only a single host (i.e, you
can't have other hosts using this storage).

For local storage deployment, first create a directory on the file system
of the host's local drive (#mkdir ), change dir owner to vdsm:kvm
(#chown vdsm:kvm ). Then, put the host in maintenance, create a
new Data-Center of local storage type, add a cluster to it and add the host
you put in maintenance to the cluster. Activate the host and create a local
storage domain.



Elad

On Fri, Aug 12, 2016 at 12:45 PM, Michael Cooper 
wrote:

> Hello Guys,
>
> I am sorry ask a stupid question again, however I am not sure how
> to add storage to the environment that I have at the moment. I have 4
> Servers 3 of them are AMD and one Intel Core i7, on my servers I have 2
> Dell SC1435's and one HP DL385 G5
>
> I have the Engine Running and I have added a node as well, Both of them
> are Physical servers they both have 1 tb drives, I would like to add the
> drive in the node as storage how would I accomplish that?
>
> Thank you very much in advance,
> --
> *Michael Cooper*
> http://www.coopfire.com
> Linux/VMWare Certified Professional
>
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users
>
>
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] General system updates policy

2016-08-14 Thread Yaniv Dary
We try to keep up with latest releases, so it should be quite safe.

Yaniv Dary
Technical Product Manager
Red Hat Israel Ltd.
34 Jerusalem Road
Building A, 4th floor
Ra'anana, Israel 4350109

Tel : +972 (9) 7692306
8272306
Email: yd...@redhat.com
IRC : ydary


On Fri, Aug 12, 2016 at 9:01 PM, David Gossage 
wrote:

> Is it considered safe from an ovirt stability standpoint to apply yum
> updates to the hosts and engine as centos/redhat release them?
>
> For example the recent https://rhn.redhat.com/errata/RHSA-2016-1606.html
> update for qemu.  If I run yum update and update that is their any worry
> for me that it has not been tested with oVirt and so versions will break
> something.  Same with kernels, libraries etc..
>
>
> *David Gossage*
> *Carousel Checks Inc. | System Administrator*
> *Office* 708.613.2284
>
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users
>
>
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Storage for my Environment

2016-08-14 Thread Yaniv Dary
Only via local DC or HCI with Gluster storage.
There blogs on how to deploy with HCI. I would look them up in the past of
this mailing list.

Yaniv Dary
Technical Product Manager
Red Hat Israel Ltd.
34 Jerusalem Road
Building A, 4th floor
Ra'anana, Israel 4350109

Tel : +972 (9) 7692306
8272306
Email: yd...@redhat.com
IRC : ydary


On Fri, Aug 12, 2016 at 12:45 PM, Michael Cooper 
wrote:

> Hello Guys,
>
> I am sorry ask a stupid question again, however I am not sure how
> to add storage to the environment that I have at the moment. I have 4
> Servers 3 of them are AMD and one Intel Core i7, on my servers I have 2
> Dell SC1435's and one HP DL385 G5
>
> I have the Engine Running and I have added a node as well, Both of them
> are Physical servers they both have 1 tb drives, I would like to add the
> drive in the node as storage how would I accomplish that?
>
> Thank you very much in advance,
> --
> *Michael Cooper*
> http://www.coopfire.com
> Linux/VMWare Certified Professional
>
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users
>
>
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] ovirt4.0.1 and new node, migration fails

2016-08-14 Thread Yaniv Dary
Did you open a bug like Michal asked?

Yaniv Dary
Technical Product Manager
Red Hat Israel Ltd.
34 Jerusalem Road
Building A, 4th floor
Ra'anana, Israel 4350109

Tel : +972 (9) 7692306
8272306
Email: yd...@redhat.com
IRC : ydary


On Fri, Aug 12, 2016 at 2:23 AM, Bill James  wrote:

> just fyi, I tried updating to ovirt-engine-4.0.2.6-1.el7.centos.noarch
> and still same story, it won't let me select a specific host to deploy a
> VM to, and doesn't tell me why not.
>
> However I can migrate the VM from one node to the other one just fine.
>
> Any ideas why?
>
> I provided logs earlier.
>
>
>
>
> On 08/03/2016 02:32 PM, Bill James wrote:
>
>> opened bug 1363900.
>> It also includes recent logs from all 3 servers.
>>
>> Also tried updating vdsm to 4.18.10-1 and restarted ovirt-engine.
>> No change in results.
>>
>> I can migrate VMs to new node but not initially assign VMs to that node.
>>
>>
>> On 07/29/2016 09:31 AM, Bill James wrote:
>>
>>> ok, I will raise a bug. Yes it is very frustrating just having button
>>> not work without explanation.
>>> I don't know if this is related, the new host that I am having troubles
>>> with is running 4.0.1.1-1,
>>> other other host is running 4.0.0.6-1
>>>
>>> I was planning on migrating VMs then upgrade the older host.
>>> Also Cluster is still in 3.6 mode, also waiting for upgrade of older
>>> node.
>>> All storage domains are on older node, its the NFS server.
>>>
>>>
>>> hmm, just retried migration so I could get vdsm logs from both hosts.
>>> 1 VM worked, the other 3 failed.
>>> And I still can't assign VMs to new node.
>>>
>>> VM that worked: f4cd4891-977d-44c2-8554-750ce86da7c9
>>>
>>> Not sure what's special about it.
>>> It and 45f4f24b-2dfa-401b-8557-314055a4662c are clones from same
>>> template.
>>>
>>>
>>> Attaching logs from 2 nodes and engine now.
>>>
>>>
>>>
>>> On 7/29/16 4:00 AM, Michal Skrivanek wrote:
>>>
 On 28 Jul 2016, at 18:37, Bill James  wrote:
>
> I'm trying to test out ovirt4.0.1.
> I added a new hardware node to the cluster. Its status is Up.
> But for some reason when I create a new VM and try to select "Specific
> Host" the radio button doesn't let me select it so I can't assign a VM to
> new node.
>
 please raise that as a bug if there is no explanation why

 When I try to migrate a VM to new node it fails with:
>
> MigrationError: Domain not found: no domain with matching uuid
> '45f4f24b-2dfa-401b-8557-314055a4662c'
>
>
> What did I miss?
>
 for migration issues you always need to include vdsm logs from both
 source and destination host. Hard to say otherwise. Anything special about
 your deployment?

 ovirt-engine-4.0.1.1-1.el7.centos.noarch
> vdsm-4.18.6-1.el7.centos.x86_64
>
> storage is NFS.
>
> Attached logs.
>
> ___
>
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users
>

>>>
>>
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users
>
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] How to open vm console by API ?

2016-08-14 Thread Wang Evan
Hi :

I want to integrate oVirt-engine into our system platform. In reference to 
ovirt rest API , I have finished added host and create virtual machine. But I 
can't find the way to open vm console by API or CLI ,so what should I do ?

Thanks !

Evan
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] IP Address Stealing

2016-08-14 Thread Edward Haas
On Fri, Aug 12, 2016 at 8:17 PM, Bill Bill  wrote:

> Cool. It looks like that works. Perhaps it would be good for oVirt to have
> a few text fields in the nic properties to enter IP addresses into which
> can match the rules being used. For example, when enabling the
> clean-traffic filter it appears the VM can only have 1 IP address, even if
> another IP is added legitimately, it still only works with the original IP
> address.
>
>
>
> Something like this: http://i.imgur.com/9BUZRCN.jpg
>
>
>
> So essentially, traffic would be blocked on that VM for any other IP space
> other than the IP’s entered into the text fields, which then edit/work with
> the netfilter rules. The idea would be to click “click to add more” would
> add another text field.
>

That could have been a nice option indeed.
Could you please open an RFE on bugzilla so we can consider and manage this?

Thanks,
Edy.


>
>
>
>
>
>
> *From: *Edward Haas 
> *Sent: *Thursday, August 4, 2016 3:47 AM
> *To: *Subhendu Ghosh 
> *Cc: *Bill Bill ; users 
> *Subject: *Re: [ovirt-users] IP Address Stealing
>
>
>
>
> On Thu, Aug 4, 2016 at 6:27 AM, Subhendu Ghosh  wrote:
>
>> Not built into ovirt AFAIK,  but an ebtables rule can allow you to filter
>> out mac+ip combinations
>>
>> Look at the anti-spoofing rules on ebtables.netfilter.org
>>
>> It doesn't prevent the user adding it in the vm, but the infrastructure
>> blocks it's usage.
>>
>> --
>> *From:* Bill Bill 
>> *Sent:* Aug 3, 2016 22:40
>> *To:* users@ovirt.org
>> *Subject:* [ovirt-users] IP Address Stealing
>>
>> Hello,
>>
>>
>>
>> It is possible to prevent a VM from adding an IP? For example, if we
>> provision a VM with one IP, if the user has root access they can simply add
>> random IP’s from within the same range as sub interfaces: eth0:0 eth0:1
>> eth0:2 so on and so forth.
>>
>>
>>
>> Subnetting is not ideal in this situation because it’s a huge waste of IP
>> space.
>>
>
> In oVirt 4.0, you can choose a vnic libvirt filter from a list (at the
> vnic profile settings).
> You can check the clean-traffic filter which uses multiple other more
> specific filters.
> Ref: https://libvirt.org/formatnwfilter.html
>
> Thanks,
> Edy.
>
>
>>
>> ___
>> Users mailing list
>> Users@ovirt.org
>> http://lists.ovirt.org/mailman/listinfo/users
>>
>>
>
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] oVirt 4 with custom SSL-certificate and SPICE HTML5 browser client -> WebSocket error: Can't connect to websocket on URL: wss://ovirt.engine.fqdn:6100/

2016-08-14 Thread Nicolás

We have a pretty likely configuration, with just one additional option:

FORCE_DATA_VERIFICATION=False

If it doesn't work, make sure the SSL_CERTIFICATE has the full bundle of 
your certificate, including intermediate certs, not just the public 
certificate. Then make sure to restart the ovirt-websocket-proxy daemon 
(not ovirt-engine).


El 14/08/16 a las 06:59, aleksey.maksi...@it-kb.ru escribió:

Hi Jiri.
But your variant does not work, too

# cat /etc/ovirt-engine/ovirt-websocket-proxy.conf.d/10-setup.conf
PROXY_PORT=6100
SSL_CERTIFICATE=/etc/pki/ovirt-engine/apache-ca.pem
SSL_KEY=/etc/pki/ovirt-engine/keys/apache.key.nopass
CERT_FOR_DATA_VERIFICATION=/etc/pki/ovirt-engine/certs/engine.cer
SSL_ONLY=True

Some error:
WebSocket error: Can't connect to websocket on URL: 
wss://ovirt.engine.fqdn:6100/eyJ...0=[object Event]

any ideas how to trablshut problem?

14.08.2016, 01:53, "Jiri Belka" :

I have different files for those variables, maybe this is the case?

Review again.

j.

- Original Message -
From: "aleksey maksimov" 
To: "Jiri Belka" 
Cc: "users" 
Sent: Saturday, August 13, 2016 4:57:45 PM
Subject: Re: [ovirt-users] oVirt 4 with custom SSL-certificate and SPICE HTML5 
browser client -> WebSocket error: Can't connect to websocket on URL: 
wss://ovirt.engine.fqdn:6100/

I changed my file /etc/ovirt-engine/ovirt-websocket-proxy.conf.d/10-setup.conf 
to:

PROXY_PORT=6100
#SSL_CERTIFICATE=/etc/pki/ovirt-engine/certs/websocket-proxy.cer
#SSL_KEY=/etc/pki/ovirt-engine/keys/websocket-proxy.key.nopass
#CERT_FOR_DATA_VERIFICATION=/etc/pki/ovirt-engine/certs/engine.cer
SSL_CERTIFICATE=/etc/pki/ovirt-engine/certs/apache.cer
SSL_KEY=/etc/pki/ovirt-engine/keys/apache.key.nopass
CERT_FOR_DATA_VERIFICATION=/etc/pki/ovirt-engine/apache-ca.pem
SSL_ONLY=True

...and restart HostedEngine VM.
Problem still exists.

13.08.2016, 17:52, "aleksey.maksi...@it-kb.ru" :

  It does not work for me. any ideas?

  02.08.2016, 17:22, "Jiri Belka" :

   This works for me:

   # cat /etc/ovirt-engine/ovirt-websocket-proxy.conf.d/10-setup.conf
   PROXY_PORT=6100
   SSL_CERTIFICATE=/etc/pki/ovirt-engine/apache-ca.pem
   SSL_KEY=/etc/pki/ovirt-engine/keys/apache.key.nopass
   CERT_FOR_DATA_VERIFICATION=/etc/pki/ovirt-engine/certs/engine.cer
   SSL_ONLY=True

   - Original Message -
   From: "aleksey maksimov" 
   To: "users" 
   Sent: Monday, August 1, 2016 12:13:38 PM
   Subject: [ovirt-users] oVirt 4 with custom SSL-certificate and SPICE HTML5 
browser client -> WebSocket error: Can't connect to websocket on URL: 
wss://ovirt.engine.fqdn:6100/

   Hello oVirt guru`s !

   I have successfully replaced the oVirt 4 site SSL-certificate according to the 
instructions from "Replacing oVirt SSL Certificate"
   section in "oVirt Administration Guide"
   http://www.ovirt.org/documentation/admin-guide/administration-guide/

   3 files have been replaced:

   /etc/pki/ovirt-engine/certs/apache.cer
   /etc/pki/ovirt-engine/keys/apache.key.nopass
   /etc/pki/ovirt-engine/apache-ca.pem

   Now the oVirt site using my certificate and everything works fine, but when I try to 
use SPICE HTML5 browser client in Firefox or Chrome I see a gray screen and message under 
the button "Toggle messages output":

   WebSocket error: Can't connect to websocket on URL: 
wss://ovirt.engine.fqdn:6100/eyJ...0=[object Event]

   Before replacing certificates SPICE HTML5 browser client works.
   Native SPICE client works fine.

   Tell me what to do with SPICE HTML5 browser client?
   ___
   Users mailing list
   Users@ovirt.org
   http://lists.ovirt.org/mailman/listinfo/users

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] import qcow2 image to ovirt

2016-08-14 Thread Amit Aviram
On Thu, Aug 11, 2016 at 5:44 PM, Gianluca Cecchi 
wrote:

> On Thu, Aug 11, 2016 at 4:40 PM, Amit Aviram  wrote:
>
>>
>> On Thu, Aug 11, 2016 at 5:39 PM, Amit Aviram  wrote:
>>
>>> Due to bug:
>>> https://bugzilla.redhat.com/show_bug.cgi?id=1365451
>>>
>>> There will need to be special configurations to do, in order to run
>>> ovirt-imageio-proxy after upgrade. we are making best efforts to publish
>>> this fix asap
>>>
>>
>> ​(patch is merged in master, will be available in the next build)​
>>
>>
>>>
>>>
> Ok, I read the bug. for the missing pki. In fact in conf file I see
> reference to missing
>
> # Key file for SSL connections
> ssl_key_file = /etc/pki/ovirt-engine/keys/imageio-proxy.key.nopass
>
> # Certificate file for SSL connections
> ssl_cert_file = /etc/pki/ovirt-engine/certs/imageio-proxy.cer
>
>
> In the mean time I see that if I change the default in
>  /etc/ovirt-imageio-proxy/ovirt-imageio-proxy.conf
> from
>
> # Wrap incoming connections with SSL
> use_ssl = true
>
> to
>
> # Wrap incoming connections with SSL
> use_ssl = false
>
> The service starts and it seems it listens to tcp port 54323.
> Could it be a workaround (wit the limitations of not secure trasnport) or
> is it anyway designed to only work through SSL?
>
> ​
Yes, supposed to work. if not for HTTPS connection to ovirt, probably for
HTTP.
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] oVirt Reports

2016-08-14 Thread Yedidyah Bar David
On Sat, Aug 13, 2016 at 10:38 PM, Fernando Fuentes  wrote:
> Team,
>
> I got two oVirt Servers. One in 4.0.2 and one in 3.6.X
> I love the new 4.0 dashboard, But I need a way to continue to build
> reports with ease, 3.6 Can do this with ovirt-reports. How can I make my
> oVirt 4.0.2 send data for reports to my ovirt reports on 3.6?
>
> Thanks for the help team!

I didn't try this myself, but pointing your reports setup to the 4.0 dwh
database should work. If you have problems, please give more details -
it's not clear what exactly you have on each machine.

Generally speaking, oVirt does not currently provide tools to make
the engine or dwh "send data" elsewhere (a 3.6 reports or whatever).
You can try doing this yourself using generic postgresql means/tools.

Best
-- 
Didi
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] oVirt 4 with custom SSL-certificate and SPICE HTML5 browser client -> WebSocket error: Can't connect to websocket on URL: wss://ovirt.engine.fqdn:6100/

2016-08-14 Thread aleksey . maksimov

Hi Jiri.
But your variant does not work, too

# cat /etc/ovirt-engine/ovirt-websocket-proxy.conf.d/10-setup.conf
PROXY_PORT=6100
SSL_CERTIFICATE=/etc/pki/ovirt-engine/apache-ca.pem
SSL_KEY=/etc/pki/ovirt-engine/keys/apache.key.nopass
CERT_FOR_DATA_VERIFICATION=/etc/pki/ovirt-engine/certs/engine.cer
SSL_ONLY=True

Some error:
WebSocket error: Can't connect to websocket on URL: 
wss://ovirt.engine.fqdn:6100/eyJ...0=[object Event]

any ideas how to trablshut problem?

14.08.2016, 01:53, "Jiri Belka" :
> I have different files for those variables, maybe this is the case?
>
> Review again.
>
> j.
>
> - Original Message -
> From: "aleksey maksimov" 
> To: "Jiri Belka" 
> Cc: "users" 
> Sent: Saturday, August 13, 2016 4:57:45 PM
> Subject: Re: [ovirt-users] oVirt 4 with custom SSL-certificate and SPICE 
> HTML5 browser client -> WebSocket error: Can't connect to websocket on URL: 
> wss://ovirt.engine.fqdn:6100/
>
> I changed my file 
> /etc/ovirt-engine/ovirt-websocket-proxy.conf.d/10-setup.conf to:
>
> PROXY_PORT=6100
> #SSL_CERTIFICATE=/etc/pki/ovirt-engine/certs/websocket-proxy.cer
> #SSL_KEY=/etc/pki/ovirt-engine/keys/websocket-proxy.key.nopass
> #CERT_FOR_DATA_VERIFICATION=/etc/pki/ovirt-engine/certs/engine.cer
> SSL_CERTIFICATE=/etc/pki/ovirt-engine/certs/apache.cer
> SSL_KEY=/etc/pki/ovirt-engine/keys/apache.key.nopass
> CERT_FOR_DATA_VERIFICATION=/etc/pki/ovirt-engine/apache-ca.pem
> SSL_ONLY=True
>
> ...and restart HostedEngine VM.
> Problem still exists.
>
> 13.08.2016, 17:52, "aleksey.maksi...@it-kb.ru" :
>>  It does not work for me. any ideas?
>>
>>  02.08.2016, 17:22, "Jiri Belka" :
>>>   This works for me:
>>>
>>>   # cat /etc/ovirt-engine/ovirt-websocket-proxy.conf.d/10-setup.conf
>>>   PROXY_PORT=6100
>>>   SSL_CERTIFICATE=/etc/pki/ovirt-engine/apache-ca.pem
>>>   SSL_KEY=/etc/pki/ovirt-engine/keys/apache.key.nopass
>>>   CERT_FOR_DATA_VERIFICATION=/etc/pki/ovirt-engine/certs/engine.cer
>>>   SSL_ONLY=True
>>>
>>>   - Original Message -
>>>   From: "aleksey maksimov" 
>>>   To: "users" 
>>>   Sent: Monday, August 1, 2016 12:13:38 PM
>>>   Subject: [ovirt-users] oVirt 4 with custom SSL-certificate and SPICE 
>>> HTML5 browser client -> WebSocket error: Can't connect to websocket on URL: 
>>> wss://ovirt.engine.fqdn:6100/
>>>
>>>   Hello oVirt guru`s !
>>>
>>>   I have successfully replaced the oVirt 4 site SSL-certificate according 
>>> to the instructions from "Replacing oVirt SSL Certificate"
>>>   section in "oVirt Administration Guide"
>>>   http://www.ovirt.org/documentation/admin-guide/administration-guide/
>>>
>>>   3 files have been replaced:
>>>
>>>   /etc/pki/ovirt-engine/certs/apache.cer
>>>   /etc/pki/ovirt-engine/keys/apache.key.nopass
>>>   /etc/pki/ovirt-engine/apache-ca.pem
>>>
>>>   Now the oVirt site using my certificate and everything works fine, but 
>>> when I try to use SPICE HTML5 browser client in Firefox or Chrome I see a 
>>> gray screen and message under the button "Toggle messages output":
>>>
>>>   WebSocket error: Can't connect to websocket on URL: 
>>> wss://ovirt.engine.fqdn:6100/eyJ...0=[object Event]
>>>
>>>   Before replacing certificates SPICE HTML5 browser client works.
>>>   Native SPICE client works fine.
>>>
>>>   Tell me what to do with SPICE HTML5 browser client?
>>>   ___
>>>   Users mailing list
>>>   Users@ovirt.org
>>>   http://lists.ovirt.org/mailman/listinfo/users
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users