[ovirt-users] Re: can hosted engine deploy use local repository mirrors instead of internet ones?
On Mon, 22 Jan 2024, iuco...@gmail.com wrote: Opening up access to the internet is a bureaucratic procedure for us, as would be for adding all the URLs to the proxy. We have a lot of repos mirrored locally - is it possible to get hosted-engine to use the local ones? Is there a list? I had a search for files that might contain these repos in various places, but to no avail. It is possible, I've done it before. But there are a lot of repos and some of them tend to change every release so it becomes a bit of a cat and mouse game keeping the list updated. It may not be so bad now that oVirt is basically in maintenance mode and new releases are few and far between. In short: install the ovirt-release45 package and take a note of all of the dependent packages. Go through all of the .repo files installed by these packages in /etc/dnf.conf and for each entry with enabled=1 set create local equivalents and put them into your own local-ovirt.repo file. I see 9 such repos on my hosts currently running oVirt 4.5.4 so things aren't quite as bad as they were in the 4.3 days when I originally did this. Put this repo file on your host before you run the hosted engine deploy and it will find all of the packages it needs in your local repos. What I ended up doing instead was just configuring dnf to use an HTTP proxy server has access to the centos repo mirrors. Again this is simpler than it used to be now that everything is consolidated on CentOS repo mirrors instead of spread out across ovirt.org and various copr repos and such. ___ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-le...@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/2WPL4YZF4I3MOPXJYGV3DDNMQRM6X7R7/
[ovirt-users] Problem with ovirt-websocket-proxy updated certified.
Hello all. In my company we have a oVit 4.5.4 that was worrying fine until today when the Apache certified expereid. Looking for how I can updated ti, followed here: https://lists.ovirt.org/archives/list/users@ovirt.org/thread/ZI5WNU6OB6FZMQNWAG5E4J2VGNDWMABZ/ I could access my engine. A secunde problem apeready when me and my colleagues tried to access any VM through noVNC On the web tab show us this message: "Something went wrong, connection is closed" When I went on the engine discovery that Websocket-proxy certified was expired too. I tried tha same procedure above but on the tab was the same message but on /var/log/message show us this: Feb 2 16:30:46 engine journal[5391]: 2024-02-02 16:30:46,072-0300 ovirt-websocket-proxy: INFO msg:601 handler exception: [SSL: TLSV1_ALERT_UNKNOWN_C A] tlsv1 alert unknown ca (_ssl.c:1129) Feb 2 16:30:46 engine ovirt-websocket-proxy.py[5391]: ovirt-websocket-proxy[5391] INFO msg:601 handler exception: [SSL: TLSV1_ALERT_UNKNOWN_CA] tlsv 1 alert unknown ca (_ssl.c:1129) I updated the CA-CERTIFITES, re-checked all paths to be sure that was correct but nothing worked. Has anyone passed through this problem? Best regards, -- Atenciosamente, Kalil de A. Carvalho ___ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-le...@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/6FTB5JWXFVVV4BY2GBOKD5BLTVHQFH7D/
[ovirt-users] Re: Upgrade from oVirt 4.5.4 to oVirt 4.5.5 - nothing provides selinux-policy >= 38.1.27-1.el9
Hi Zuhaimi, I was able to update the selinux-policy packages using the link Sandro sent (https://kojihub.stream.centos.org/koji/buildinfo?buildID=2). In our case, we created a new local yum repository for our oVirt cluster that contains the required packages specific to oVirt, but you should also be able to just download and update the packages manually. I hope this helps! Devin > On Jan 30, 2024, at 1:02 PM, zuhaimi.musa--- via Users > wrote: > > Hi Devin, > > I'm facing same issue. How do you managed to update the selinux-policy to > 38.1.27-1.el9? Can you share the procedure you took? > > Thanks. > ___ > Users mailing list -- users@ovirt.org > To unsubscribe send an email to users-le...@ovirt.org > Privacy Statement: https://www.ovirt.org/privacy-policy.html > oVirt Code of Conduct: > https://www.ovirt.org/community/about/community-guidelines/ > List Archives: > https://lists.ovirt.org/archives/list/users@ovirt.org/message/OMWGU3FTCT4AG2TUSGBRZEOJUPK5UJX5/ ___ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-le...@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/KG74JNPLTC4UMANJR3YEETBOCZ5IF3DB/
[ovirt-users] oVirt 4.5.5 - Prb with qemu-kvm after upgrade
Hello I have a standalone oVirt Manager 4.5.5-1.el8 and two small clusters. After upgrading ovir01001 in the "PreProd" cluster from AlmaLinux 8.8 to 8.9, the host was successfully activated but failed to take any VM. centos-release-ceph-pacific.noarch 1.0-2.el8 @cs8-extras centos-release-gluster10.noarch1.0-1.el8s @cs8-extras-common centos-release-nfv-common.noarch 1-3.el8 @cs8-extras centos-release-nfv-openvswitch.noarch 1-3.el8 @cs8-extras centos-release-opstools.noarch 1-12.el8@cs8-extras centos-release-ovirt45.noarch 8.9-1.el8s @cs8-extras-common centos-release-storage-common.noarch 2-2.el8 @cs8-extras centos-release-stream.x86_64 8.1-1.1911.0.7.el8 @cs8-extras centos-release-virt-common.noarch 1-2.el8 @cs8-extras vdsm.x86_644.50.5.1-1.el8 @centos-ovirt45 The problem has been "solved" by downgrading all qemu-* packages to the version in AlmaLinux 8.8 ie. qemu-kvm-6.2.0-40.module_el8.9.0+3681+41cbbcc0.1.alma.1 => qemu-kvm-6.2.0-33.module_el8.8.0+3612+f18d2b89.alma.1.x86_64 Please find the relevent log: - engine_when_failed.log https://pastebin.com/7MG6fYGY - engine_when_ok.loghttps://pastebin.com/MegqmMbg - vdsm_when_failed.log https://pastebin.com/ae4w0pix - vdsm_when_ok.log https://pastebin.com/d7P0BWDN Has someone tried to update to 8.9 ? Regards -- ,-~~-.___. ._. / | ' \| |. Christophe GRENIER ( ) 0 | || gren...@cgsecurity.org \_/-, ,'| || !_!-v---v--. / \-'~; .. TestDisk & PhotoRec / __/~| ._-""||| Data Recovery =( _|_|||| https://www.cgsecurity.org ___ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-le...@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/LTITYG3P252PMUBWQMHBBNFOIDU6TV62/
[ovirt-users] Re: Major screwup and now I can't bring anything up
Hi, It's always easy to wipe and start fresh but windows style of administration has a huge drawback - you don't know why and what happened to cause it.I have learned a lot while trying to recover from various problems and I would recommend you to at least give it a try.You have a symptom and a hypothesis. Regenerate the engine's and all hosts certificates and see how it will affect your setup. Best Regards,Strahil Nikolov On Fri, Feb 2, 2024 at 18:57, John Florian wrote: I have a small home oVirt 4.5 deployment that was struggling a bit and I think I've only made things worse. I was seeing some SSL errors in various places but couldn't find any evidence of an expired cert though maybe I overlooked something. At present, it looks like the most immediate problem is that the engine.log is showing SyncNetworkProviderCommand fails saying EngineException: (Failed with error Unsupported or unrecognized SSL message and code 5050). For now, I'm only concerning myself to one Host that had been running VMs until I tried restarting everything from a power off. I take it that the sync failure prevents this Host from becoming active. I had successfully been using this setup for many years. I do have my own web cert on the engine signed by my CA. While I was getting this same "code 5050" error before with things like ovirt-imageio (what prompted my initial digging), now I'm afraid I've only made things more complex. See, I was running FreeIPA on a pair of VMs. In the past, this pair of VMs would auto-start once the oVirt Engine and Hosts were going and I had no issue. But now I wonder to what extent OSCP being unreachable might affect the SSL errors. What's the best/easiest/safest way out of this mess? Should I just wipe ovirt-engine of all the non-rpm provided files in /etc/pki/ovirt-engine/ and redo the engine-setup? I'm afraid of making things worse before I begin attempting that. ___ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-le...@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/WLRBA2EXHCC7V6HZM35UDH25MBPXSIOC/ ___ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-le...@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/JQHXYITNM5IZLYQZKZR77UVJYEZF7IMS/
[ovirt-users] Re: Upgrade from oVirt 4.5.4 to oVirt 4.5.5 - nothing provides selinux-policy >= 38.1.27-1.el9
Hi Devin, I'm facing same issue. How do you managed to update the selinux-policy to 38.1.27-1.el9? Can you share the procedure you took? Thanks. ___ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-le...@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/OMWGU3FTCT4AG2TUSGBRZEOJUPK5UJX5/
[ovirt-users] Re: Hosted Engine Deploy Failure
Hello Gary, How did you found that there were 2 engine VMs competing? Mihai, ___ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-le...@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/4ENNYWI3R4NMZ6M3RB5W7EHI5UIBJU6C/
[ovirt-users] Major screwup and now I can't bring anything up
I have a small home oVirt 4.5 deployment that was struggling a bit and I think I've only made things worse. I was seeing some SSL errors in various places but couldn't find any evidence of an expired cert though maybe I overlooked something. At present, it looks like the most immediate problem is that the engine.log is showing SyncNetworkProviderCommand fails saying EngineException: (Failed with error Unsupported or unrecognized SSL message and code 5050). For now, I'm only concerning myself to one Host that had been running VMs until I tried restarting everything from a power off. I take it that the sync failure prevents this Host from becoming active. I had successfully been using this setup for many years. I do have my own web cert on the engine signed by my CA. While I was getting this same "code 5050" error before with things like ovirt-imageio (what prompted my initial digging), now I'm afraid I've only made things more complex. See, I was running FreeIPA on a pair of VMs. In the past, this pair of VMs would auto-start once the oVirt Engine and Hosts were going and I had no issue. But now I wonder to what extent OSCP being unreachable might affect the SSL errors. What's the best/easiest/safest way out of this mess? Should I just wipe ovirt-engine of all the non-rpm provided files in /etc/pki/ovirt-engine/ and redo the engine-setup? I'm afraid of making things worse before I begin attempting that. ___ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-le...@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/WLRBA2EXHCC7V6HZM35UDH25MBPXSIOC/
[ovirt-users] Host deploy failure: Configure OVN for oVirt
Good day, I am running into a problem during host deploy via the oVirt engine GUI since upgrading to ovirt-engine-4.5.5-1.el8. The "Configure OVN for oVirt" task seem to fail when trying to run the vdsm-tool ovn-config command. Host deploy used to work fine when the engine was on version 4.5.4. Anyone that can guide me on the right path to get past this issue? Does not seem to be a new problem - https://lists.ovirt.org/archives/list/users@ovirt.org/thread/IDLGSBQFX35EHHGBE2FLPVZANTL7U7BL/ Log extract: 2024-02-01 14:48:19 SAST - TASK [ovirt-provider-ovn-driver : Configure OVN for oVirt] * . . . "stdout" : "fatal: [mob-r1-l-ovirt-aa-1-23.x.fnb.co.za]: FAILED! => {\"changed\": true, \"cmd\": [\"vdsm-tool\", \"ovn-config\", \"192.168.2.100\", \"host23.mydomain.com\"], \"delta\": \"0:00:00.538143\", \"end \": \"2024-02-01 14:48:20.596823\", \"msg\": \"non-zero return code\", \"rc\": 1, \"start\": \"2024-02-01 14:48:20.058680\", \"stderr\": \"Traceback (most recent call last):\\n File \\\"/usr/lib/python3.6/site-packages/vdsm/t ool/ovn_config.py\\\", line 117, in get_network\\nreturn networks[net_name]\\nKeyError: 'host23.mydomain.com'\\n\\nDuring handling of the above exception, another exception occurred:\\n\\nTraceback (most rec ent call last):\\n File \\\"/usr/bin/vdsm-tool\\\", line 195, in main\\n return tool_command[cmd][\\\"command\\\"](*args)\\n File \\\"/usr/lib/python3.6/site-packages/vdsm/tool/ovn_config.py\\\", line 63, in ovn_config\\n ip_address = get_ip_addr(get_network(network_caps(), net_name))\\n File \\\"/usr/lib/python3.6/site-packages/vdsm/tool/ovn_config.py\\\", line 119, in get_network\\nraise NetworkNotFoundError(net_name)\\nvdsm.tool.ovn _config.NetworkNotFoundError: host23.mydomain.com\", \"stderr_lines\": [\"Traceback (most recent call last):\", \" File \\\"/usr/lib/python3.6/site-packages/vdsm/tool/ovn_config.py\\\", line 117, in get_network \", \"return networks[net_name]\", \"KeyError: 'host23.mydomain.com'\", \"\", \"During handling of the above exception, another exception occurred:\", \"\", \"Traceback (most recent call last):\", \" File \ \\"/usr/bin/vdsm-tool\\\", line 195, in main\", \"return tool_command[cmd][\\\"command\\\"](*args)\", \" File \\\"/usr/lib/python3.6/site-packages/vdsm/tool/ovn_config.py\\\", line 63, in ovn_config\", \"ip_address = get_ip_addr(get_network(network_caps(), net_name))\", \" File \\\"/usr/lib/python3.6/site-packages/vdsm/tool/ovn_config.py\\\", line 119, in get_network\", \"raise NetworkNotFoundError(net_name)\", \"vdsm.tool.ovn_config. NetworkNotFoundError: host23.mydomain.com\"], \"stdout\": \"\", \"stdout_lines\": []}", Thanks in advance!! Stephan ___ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-le...@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/FSGWGSNKABHU45DNJQPBY4HIHR6QUFSU/
[ovirt-users] Re: [ovirt-devel] Foreman needs a release of ovirt-engine-sdk-ruby
The oVirt Engine Ruby SDK 4.6.0 is now available[1][2], allowing Foreman to keep working with oVirt for the next Foreman's releases. [1] https://github.com/oVirt/ovirt-engine-sdk-ruby/releases/tag/4.6.0 [2] https://rubygems.org/gems/ovirt-engine-sdk ___ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-le...@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/JGK2ODIANQ364Z66NUFGLZCBX4KFSPTM/