[ovirt-users] Re: can hosted engine deploy use local repository mirrors instead of internet ones?

2024-02-02 Thread Sketch

On Mon, 22 Jan 2024, iuco...@gmail.com wrote:


Opening up access to the internet is a bureaucratic procedure for us, as 
would be for adding all the URLs to the proxy. We have a lot of repos 
mirrored locally - is it possible to get hosted-engine to use the local 
ones? Is there a list? I had a search for files that might contain these 
repos in various places, but to no avail.


It is possible, I've done it before. But there are a lot of repos and 
some of them tend to change every release so it becomes a bit of a cat and 
mouse game keeping the list updated. It may not be so bad now that oVirt 
is basically in maintenance mode and new releases are few and far between.


In short: install the ovirt-release45 package and take a note of all of 
the dependent packages.  Go through all of the .repo files installed by 
these packages in /etc/dnf.conf and for each entry with enabled=1 set 
create local equivalents and put them into your own local-ovirt.repo file. 
I see 9 such repos on my hosts currently running oVirt 4.5.4 so things 
aren't quite as bad as they were in the 4.3 days when I originally did 
this. Put this repo file on your host before you run the hosted engine 
deploy and it will find all of the packages it needs in your local repos.


What I ended up doing instead was just configuring dnf to use an HTTP 
proxy server has access to the centos repo mirrors. Again this is simpler 
than it used to be now that everything is consolidated on CentOS repo 
mirrors instead of spread out across ovirt.org and various copr repos and 
such.

___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/privacy-policy.html
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/2WPL4YZF4I3MOPXJYGV3DDNMQRM6X7R7/


[ovirt-users] Problem with ovirt-websocket-proxy updated certified.

2024-02-02 Thread Kalil de A. Carvalho
Hello all.
In my company we have a oVit 4.5.4 that was worrying fine until today when
the Apache certified expereid. Looking for how I can updated ti, followed
here:
https://lists.ovirt.org/archives/list/users@ovirt.org/thread/ZI5WNU6OB6FZMQNWAG5E4J2VGNDWMABZ/
I could access my engine.
A secunde problem apeready when me and my colleagues tried to access any VM
through noVNC
On the web tab show us this message:
"Something went wrong, connection is closed"
When I went on the engine discovery that Websocket-proxy certified was
expired too. I tried tha same procedure above but on the tab was the same
message but on /var/log/message show us this:
Feb  2 16:30:46 engine journal[5391]: 2024-02-02 16:30:46,072-0300
ovirt-websocket-proxy: INFO msg:601 handler exception: [SSL:
TLSV1_ALERT_UNKNOWN_C
A] tlsv1 alert unknown ca (_ssl.c:1129)
Feb  2 16:30:46 engine ovirt-websocket-proxy.py[5391]:
ovirt-websocket-proxy[5391] INFO msg:601 handler exception: [SSL:
TLSV1_ALERT_UNKNOWN_CA] tlsv
1 alert unknown ca (_ssl.c:1129)

I updated the CA-CERTIFITES, re-checked all paths to be sure that was
correct but nothing worked.

Has anyone passed through this problem?

Best regards,

-- 
Atenciosamente,
Kalil de A. Carvalho
___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/privacy-policy.html
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/6FTB5JWXFVVV4BY2GBOKD5BLTVHQFH7D/


[ovirt-users] Re: Upgrade from oVirt 4.5.4 to oVirt 4.5.5 - nothing provides selinux-policy >= 38.1.27-1.el9

2024-02-02 Thread Devin A. Bougie
Hi Zuhaimi,

I was able to update the selinux-policy packages using the link Sandro sent 
(https://kojihub.stream.centos.org/koji/buildinfo?buildID=2).  In our case, 
we created a new local yum repository for our oVirt cluster that contains the 
required packages specific to oVirt, but you should also be able to just 
download and update the packages manually.

I hope this helps!
Devin

> On Jan 30, 2024, at 1:02 PM, zuhaimi.musa--- via Users  
> wrote:
>
> Hi Devin,
>
> I'm facing same issue. How do you managed to update the selinux-policy to 
> 38.1.27-1.el9? Can you share the procedure you took?
>
> Thanks.
> ___
> Users mailing list -- users@ovirt.org
> To unsubscribe send an email to users-le...@ovirt.org
> Privacy Statement: https://www.ovirt.org/privacy-policy.html
> oVirt Code of Conduct: 
> https://www.ovirt.org/community/about/community-guidelines/
> List Archives: 
> https://lists.ovirt.org/archives/list/users@ovirt.org/message/OMWGU3FTCT4AG2TUSGBRZEOJUPK5UJX5/

___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/privacy-policy.html
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/KG74JNPLTC4UMANJR3YEETBOCZ5IF3DB/


[ovirt-users] oVirt 4.5.5 - Prb with qemu-kvm after upgrade

2024-02-02 Thread Christophe GRENIER via Users

Hello

I have a standalone oVirt Manager 4.5.5-1.el8 and two small clusters.
After upgrading ovir01001 in the "PreProd" cluster from AlmaLinux 8.8 to 8.9, 
the host was successfully activated but failed to take any VM.

centos-release-ceph-pacific.noarch 1.0-2.el8   @cs8-extras
centos-release-gluster10.noarch1.0-1.el8s  @cs8-extras-common
centos-release-nfv-common.noarch   1-3.el8 @cs8-extras
centos-release-nfv-openvswitch.noarch  1-3.el8 @cs8-extras
centos-release-opstools.noarch 1-12.el8@cs8-extras
centos-release-ovirt45.noarch  8.9-1.el8s  @cs8-extras-common
centos-release-storage-common.noarch   2-2.el8 @cs8-extras
centos-release-stream.x86_64   8.1-1.1911.0.7.el8  @cs8-extras
centos-release-virt-common.noarch  1-2.el8 @cs8-extras
vdsm.x86_644.50.5.1-1.el8  @centos-ovirt45

The problem has been "solved" by downgrading all qemu-* packages to the version 
in AlmaLinux 8.8
ie. qemu-kvm-6.2.0-40.module_el8.9.0+3681+41cbbcc0.1.alma.1 => 
qemu-kvm-6.2.0-33.module_el8.8.0+3612+f18d2b89.alma.1.x86_64


Please find the relevent log:
- engine_when_failed.log https://pastebin.com/7MG6fYGY
- engine_when_ok.loghttps://pastebin.com/MegqmMbg
- vdsm_when_failed.log  https://pastebin.com/ae4w0pix
- vdsm_when_ok.log  https://pastebin.com/d7P0BWDN

Has someone tried to update to 8.9 ?

Regards

--
   ,-~~-.___. ._.
  / |  ' \| |.   Christophe GRENIER
 (  ) 0   | || gren...@cgsecurity.org
  \_/-, ,'| ||
  !_!-v---v--.
 /  \-'~;  ..   TestDisk & PhotoRec
/  __/~| ._-""|||   Data Recovery
  =(  _|_||||   https://www.cgsecurity.org
___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/privacy-policy.html
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/LTITYG3P252PMUBWQMHBBNFOIDU6TV62/


[ovirt-users] Re: Major screwup and now I can't bring anything up

2024-02-02 Thread Strahil Nikolov via Users
Hi,
It's always easy to wipe and start fresh but windows style of administration 
has a huge drawback - you don't know why and what happened to cause it.I have 
learned a lot while trying to recover from various problems and I would 
recommend you to at least give it a try.You have a symptom and a hypothesis. 
Regenerate the engine's and all hosts certificates and see how it will affect 
your setup.
Best Regards,Strahil Nikolov
 
 
  On Fri, Feb 2, 2024 at 18:57, John Florian wrote:   I 
have a small home oVirt 4.5 deployment that was struggling a bit and I think 
I've only made things worse.  I was seeing some SSL errors in various places 
but couldn't find any evidence of an expired cert though maybe I overlooked 
something.  At present, it looks like the most immediate problem is that the 
engine.log is showing SyncNetworkProviderCommand fails saying EngineException: 
(Failed with error Unsupported or unrecognized SSL message and code 5050).  For 
now, I'm only concerning myself to one Host that had been running VMs until I 
tried restarting everything from a power off.  I take it that the sync failure 
prevents this Host from becoming active.

I had successfully been using this setup for many years.  I do have my own web 
cert on the engine signed by my CA.  While I was getting this same "code 5050" 
error before with things like ovirt-imageio (what prompted my initial digging), 
now I'm afraid I've only made things more complex.  See, I was running FreeIPA 
on a pair of VMs.  In the past, this pair of VMs would auto-start once the 
oVirt Engine and Hosts were going and I had no issue.  But now I wonder to what 
extent OSCP being unreachable might affect the SSL errors.

What's the best/easiest/safest way out of this mess?  Should I just wipe 
ovirt-engine of all the non-rpm provided files in /etc/pki/ovirt-engine/ and 
redo the engine-setup?  I'm afraid of making things worse before I begin 
attempting that.
___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/privacy-policy.html
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/WLRBA2EXHCC7V6HZM35UDH25MBPXSIOC/
  
___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/privacy-policy.html
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/JQHXYITNM5IZLYQZKZR77UVJYEZF7IMS/


[ovirt-users] Re: Upgrade from oVirt 4.5.4 to oVirt 4.5.5 - nothing provides selinux-policy >= 38.1.27-1.el9

2024-02-02 Thread zuhaimi.musa--- via Users
Hi Devin, 

I'm facing same issue. How do you managed to update the selinux-policy to 
38.1.27-1.el9? Can you share the procedure you took?

Thanks.
___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/privacy-policy.html
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/OMWGU3FTCT4AG2TUSGBRZEOJUPK5UJX5/


[ovirt-users] Re: Hosted Engine Deploy Failure

2024-02-02 Thread Mihai Puha via Users
Hello Gary, 

How did you found that there were 2 engine VMs competing? 

Mihai, 
___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/privacy-policy.html
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/4ENNYWI3R4NMZ6M3RB5W7EHI5UIBJU6C/


[ovirt-users] Major screwup and now I can't bring anything up

2024-02-02 Thread John Florian
I have a small home oVirt 4.5 deployment that was struggling a bit and I think 
I've only made things worse.  I was seeing some SSL errors in various places 
but couldn't find any evidence of an expired cert though maybe I overlooked 
something.  At present, it looks like the most immediate problem is that the 
engine.log is showing SyncNetworkProviderCommand fails saying EngineException: 
(Failed with error Unsupported or unrecognized SSL message and code 5050).  For 
now, I'm only concerning myself to one Host that had been running VMs until I 
tried restarting everything from a power off.  I take it that the sync failure 
prevents this Host from becoming active.

I had successfully been using this setup for many years.  I do have my own web 
cert on the engine signed by my CA.  While I was getting this same "code 5050" 
error before with things like ovirt-imageio (what prompted my initial digging), 
now I'm afraid I've only made things more complex.  See, I was running FreeIPA 
on a pair of VMs.  In the past, this pair of VMs would auto-start once the 
oVirt Engine and Hosts were going and I had no issue.  But now I wonder to what 
extent OSCP being unreachable might affect the SSL errors.

What's the best/easiest/safest way out of this mess?  Should I just wipe 
ovirt-engine of all the non-rpm provided files in /etc/pki/ovirt-engine/ and 
redo the engine-setup?  I'm afraid of making things worse before I begin 
attempting that.
___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/privacy-policy.html
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/WLRBA2EXHCC7V6HZM35UDH25MBPXSIOC/


[ovirt-users] Host deploy failure: Configure OVN for oVirt

2024-02-02 Thread stephan.badenhorst--- via Users
Good day,

I am running into a problem during host deploy via the oVirt engine GUI since 
upgrading to ovirt-engine-4.5.5-1.el8. The "Configure OVN for oVirt" task seem 
to fail when trying to run the vdsm-tool ovn-config command. Host deploy used 
to work fine when the engine was on version 4.5.4. 

Anyone that can guide me on the right path to get past this issue? 

Does not seem to be a new problem - 
https://lists.ovirt.org/archives/list/users@ovirt.org/thread/IDLGSBQFX35EHHGBE2FLPVZANTL7U7BL/

Log extract:

2024-02-01 14:48:19 SAST - TASK [ovirt-provider-ovn-driver : Configure OVN for 
oVirt] *
.
.
.
  "stdout" : "fatal: [mob-r1-l-ovirt-aa-1-23.x.fnb.co.za]: FAILED! => 
{\"changed\": true, \"cmd\": [\"vdsm-tool\", \"ovn-config\", \"192.168.2.100\", 
\"host23.mydomain.com\"], \"delta\": \"0:00:00.538143\", \"end
\": \"2024-02-01 14:48:20.596823\", \"msg\": \"non-zero return code\", \"rc\": 
1, \"start\": \"2024-02-01 14:48:20.058680\", \"stderr\": \"Traceback (most 
recent call last):\\n  File \\\"/usr/lib/python3.6/site-packages/vdsm/t
ool/ovn_config.py\\\", line 117, in get_network\\nreturn 
networks[net_name]\\nKeyError: 'host23.mydomain.com'\\n\\nDuring handling of 
the above exception, another exception occurred:\\n\\nTraceback (most rec
ent call last):\\n  File \\\"/usr/bin/vdsm-tool\\\", line 195, in main\\n
return tool_command[cmd][\\\"command\\\"](*args)\\n  File 
\\\"/usr/lib/python3.6/site-packages/vdsm/tool/ovn_config.py\\\", line 63, in 
ovn_config\\n
ip_address = get_ip_addr(get_network(network_caps(), net_name))\\n  File 
\\\"/usr/lib/python3.6/site-packages/vdsm/tool/ovn_config.py\\\", line 119, in 
get_network\\nraise NetworkNotFoundError(net_name)\\nvdsm.tool.ovn
_config.NetworkNotFoundError: host23.mydomain.com\", \"stderr_lines\": 
[\"Traceback (most recent call last):\", \"  File 
\\\"/usr/lib/python3.6/site-packages/vdsm/tool/ovn_config.py\\\", line 117, in 
get_network
\", \"return networks[net_name]\", \"KeyError: 'host23.mydomain.com'\", 
\"\", \"During handling of the above exception, another exception occurred:\", 
\"\", \"Traceback (most recent call last):\", \"  File \
\\"/usr/bin/vdsm-tool\\\", line 195, in main\", \"return 
tool_command[cmd][\\\"command\\\"](*args)\", \"  File 
\\\"/usr/lib/python3.6/site-packages/vdsm/tool/ovn_config.py\\\", line 63, in 
ovn_config\", \"ip_address =
get_ip_addr(get_network(network_caps(), net_name))\", \"  File 
\\\"/usr/lib/python3.6/site-packages/vdsm/tool/ovn_config.py\\\", line 119, in 
get_network\", \"raise NetworkNotFoundError(net_name)\", 
\"vdsm.tool.ovn_config.
NetworkNotFoundError: host23.mydomain.com\"], \"stdout\": \"\", 
\"stdout_lines\": []}",

Thanks in advance!!
Stephan
___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/privacy-policy.html
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/FSGWGSNKABHU45DNJQPBY4HIHR6QUFSU/


[ovirt-users] Re: [ovirt-devel] Foreman needs a release of ovirt-engine-sdk-ruby

2024-02-02 Thread Sandro Bonazzola
The oVirt Engine Ruby SDK 4.6.0 is now available[1][2], allowing Foreman to 
keep working with oVirt for the next Foreman's releases.

[1] https://github.com/oVirt/ovirt-engine-sdk-ruby/releases/tag/4.6.0
[2] https://rubygems.org/gems/ovirt-engine-sdk
___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/privacy-policy.html
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/JGK2ODIANQ364Z66NUFGLZCBX4KFSPTM/