[ovirt-users] Re: Correct recovery procedure of the oVirt Hosted Engine 4.0

2019-05-15 Thread aleksey . maksimov
Hi Simone. 
When can we expect a new version of the engine-backup with built-in cleaning 
helper?

05.10.2016, 13:52, "Simone Tiraboschi" :
> On Wed, Oct 5, 2016 at 12:40 PM,  wrote:
>> Ouch. It is beyond my understanding.
>>
>> Thus, it appears that described in the RHV4 guide 
>> (https://access.redhat.com/documentation/en/red-hat-virtualization/4.0/single/self-hosted-engine-guide/#sect-Restoring_SHE_bkup)
>>  recovery procedure in fact incomplete?
> Yes, you are right although this is a kind of special case since we are 
> moving/restoring to a different storage domain while you are not asked to 
> remove the old storage if you are restoring in place.
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users

--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se



--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se

___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/site/privacy-policy/
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/RGNOAQ5SKQSUBUWYCBIPOUM65KYI4BHI/


[ovirt-users] RE > Multiple export domains limit?

2019-05-14 Thread aleksey . maksimov
Hello oVirt guru`s!

http://lists.ovirt.org/pipermail/users/2015-November/036056.html

Is there a progress on this issue?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users

--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se



--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se

___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/site/privacy-policy/
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/ZBUJW6ARSA5BLXITUEBITYOR6FPW6HWY/


[ovirt-users] Re: Correct recovery procedure of the oVirt Hosted Engine 4.0

2019-05-14 Thread aleksey . maksimov
Simone, thank you for your work.
We will wait for the updates.

06.10.2016, 09:55, "Simone Tiraboschi" :
> On Thu, Oct 6, 2016 at 7:32 AM,  wrote:
>> Hi Simone.
>> When can we expect a new version of the engine-backup with built-in cleaning 
>> helper?
>
> That bug is targeted to 4.1
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users

--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se



--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se

___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/site/privacy-policy/
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/XFCZMT25ATKQAPHBDA62MRWXT4OCQV7I/


[ovirt-users] Re: Correct recovery procedure of the oVirt Hosted Engine 4.0

2019-05-14 Thread aleksey . maksimov
Well.
Then, in the case of conditions:

1) the vm is not available anymore due to storage corruption
2) an empty shared storage is available
3) engine backup exists
4) all VMs still running on the hosts in the cluster


The recovery plan will be like this (as I understand it):


1) On all the hosts (if they are still available):

# service ovirt-ha-broker stop
# service ovirt-ha-agent stop
# chkconfig --del ovirt-ha-broker
# chkconfig --del ovirt-ha-agent


2) On first host (if the original host is not available anymore, provision a 
new host from scratch and proceed on this new host):

  2.1) # hosted-engine --deploy

 ◾use same fqdn you had previously in the HE VM.
 ◾point to the new shared storage
 ◾provide the same admin password you used in previous setup
 ◾install the OS on the vm
 ◾confirm it has been installed

 on Hosted Engine VM:

  a) Install the ovirt-engine rpms on the vm but don't run engine-setup:
  # yum install http://resources.ovirt.org/pub/yum-repo/ovirt-release40.rpm
  # yum install epel-release
  # yum install ovirt-engine
  b) Restore the backup:
  # engine-backup --mode=restore --file=file_name --log=log_file_name 
--provision-db --provision-dwh-db --restore-permissions
  c) Run "engine-setup"

   2.2) Open Administration Portal and remove the all old hosts used for Hosted 
Engine

   2.3) Confirm that the engine has been installed (Return to the host and 
continue the hosted-engine deployment script by selecting option 1) and then 
finish the deploy.

   2.4) In Administration Portal activate new host


3) On all additional hosts run "hosted-engine --deploy".


Right?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users

--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se



--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se


___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/site/privacy-policy/
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/M6L3GTTW7KPCTEO55ACOQV4TEC6ANCMH/


[ovirt-users] Re: Correct recovery procedure of the oVirt Hosted Engine 4.0

2019-05-14 Thread aleksey . maksimov
Ouch. It is beyond my understanding.

Thus, it appears that described in the RHV4 guide 
(https://access.redhat.com/documentation/en/red-hat-virtualization/4.0/single/self-hosted-engine-guide/#sect-Restoring_SHE_bkup)
 recovery procedure in fact incomplete?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users

--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se



--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se

___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/site/privacy-policy/
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/SE3DDGNSSRCNMAGY6HSUL2TYIECZZTJL/


[ovirt-users] Slow first opening web portal when the ovirt-engine.service is restarted

2019-05-14 Thread aleksey . maksimov
Hello oVirt guru`s !

oVirt Engine Version: 4.0.4.4-1.el7.centos

After restarting the ovirt-engine.service, the web login page is available 
after a few seconds. That's good.
But when trying the first login, the portal web page open for 2-3 minutes

All subsequent logins are fast.

The question is: Why is the delay in the opening pages of the first call?

Do I understand correctly that this feature of JBoss web application?
Need some warming up of the web application?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users

--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se



--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se

___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/site/privacy-policy/
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/5XA5DI7IYU37UMZOAJOUOGALBUDD3CYZ/


[ovirt-users] Correct recovery procedure of the oVirt Hosted Engine 4.0

2019-05-14 Thread aleksey . maksimov
Hello oVirt guru`s!


My Hosted Engine VM located on a dedicated LUN FC Storage.

I do daily data backups (on NFS share) with the command:

/usr/bin/engine-backup --mode=backup --scope=all --file=$BcpFileName.xz 
--log=$BcpFileName.log --archive-compressor=xz --files-compressor=None

However, I don't know what would be the correct procedure to recover, because 
in different manuals outline the various steps.

For example, there is information that I have to do configure postgresql (with 
password from file files/etc/ovirt-engine/engine.conf.d/10-setup-database.conf) 
before restoring (engine-backup --mode=restore):
https://www.ovirt.org/documentation/admin-guide/hosted-engine-backup-and-restore/

And at the same time, in another document, there are no such steps:
https://access.redhat.com/documentation/en/red-hat-virtualization/4.0/single/self-hosted-engine-guide/#sect-Restoring_SHE_bkup

What should be the correct procedure for the recovery of Hosted Engine 4.0 ?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users

--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se



--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se

___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/site/privacy-policy/
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/QNKIG5STRTSBAHJ3ES65K2NEU5VJ4E53/


[ovirt-users] Re: Correct recovery procedure of the oVirt Hosted Engine 4.0

2019-05-14 Thread aleksey . maksimov
Weird. The RHV4 guides not contain the information that we need to clean the database from old storage domain before running the command engine-setup.What specific actions do we need?Eventually I want to get a full recovery plan at the moment for oVirt 4.0. 05.10.2016, 12:07, "Simone Tiraboschi" :  On Wed, Oct 5, 2016 at 10:30 AM,  wrote:Well.Then, in the case of conditions:1) the vm is not available anymore due to storage corruption2) an empty shared storage is available3) engine backup exists4) all VMs still running on the hosts in the clusterThe recovery plan will be like this (as I understand it):1) On all the hosts (if they are still available):# service ovirt-ha-broker stop# service ovirt-ha-agent stop# chkconfig --del ovirt-ha-broker# chkconfig --del ovirt-ha-agent2) On first host (if the original host is not available anymore, provision a new host from scratch and proceed on this new host):  2.1) # hosted-engine --deploy ◾use same fqdn you had previously in the HE VM. ◾point to the new shared storage ◾provide the same admin password you used in previous setup ◾install the OS on the vm I'd suggest to use the engine appliance also for this.You can just say No when it asks about automatically running engine-setup.   ◾confirm it has been installed on Hosted Engine VM:  a) Install the ovirt-engine rpms on the vm but don't run engine-setup:  # yum install http://resources.ovirt.org/pub/yum-repo/ovirt-release40.rpm  # yum install epel-release  # yum install ovirt-engine  b) Restore the backup:  # engine-backup --mode=restore --file=file_name --log=log_file_name --provision-db --provision-dwh-db --restore-permissions In order to let the engine auto-import the new hosted-engine storage domain, you have to remove the old one.The same for the engine VM. Unfortunately you cannot do that from the engine since they are somehow protected to avoid unintentional damages.The easiest way is to remove them from the DB before running engine-setup.I'm working on a helper utility to make it easiser:https://gerrit.ovirt.org/#/c/64966/I think I'll integrate it with engine-backup to simply do it with an additional CLI flag.    c) Run "engine-setup"   2.2) Open Administration Portal and remove the all old hosts used for Hosted Engine Right, we can also integrate this step in the HE cleaning helper. 2.3) Confirm that the engine has been installed (Return to the host and continue the hosted-engine deployment script by selecting option 1) and then finish the deploy.   2.4) In Administration Portal activate new host3) On all additional hosts run "hosted-engine --deploy". I strongly suggest to deploy them from the engine and not from CLI.CLI deploy support for additional HE host is deprecated an it will be removed in 4.1. Right?-- 
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se


-- 
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users
___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/site/privacy-policy/
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/IOWBZ2OSJNCRLMFF77V6FNCXU6YXXKF2/


[ovirt-users] Re: Slow first opening web portal when the ovirt-engine.service is restarted

2019-05-14 Thread aleksey . maksimov
Any thoughts on this? 

I found the systemd service example for a warm start:
https://github.com/geertj/ravstack/blob/master/share/ovirt-warmup.service

This is a good solution?


03.10.2016, 09:35, "aleksey.maksi...@it-kb.ru" :
> Hello oVirt guru`s !
>
> oVirt Engine Version: 4.0.4.4-1.el7.centos
>
> After restarting the ovirt-engine.service, the web login page is available 
> after a few seconds. That's good.
> But when trying the first login, the portal web page open for 2-3 minutes
>
> All subsequent logins are fast.
>
> The question is: Why is the delay in the opening pages of the first call?
>
> Do I understand correctly that this feature of JBoss web application?
> Need some warming up of the web application?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users

--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se



--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se

___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/site/privacy-policy/
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/OJD7HNDSEJKKEPDIIZGGWKUOOIDNH3EM/


[ovirt-users] Re: Slow first opening web portal when the ovirt-engine.service is restarted

2019-05-14 Thread aleksey . maksimov
Thank you, Sandro

03.10.2016, 15:48, "Sandro Bonazzola" :

>> But now the question arises, in what cases can be a helpful 
>> ovirt-warmup.service 
>> (https://github.com/geertj/ravstack/blob/master/share/ovirt-warmup.service) ?
>
> No idea, I guess ravstack developer wanted to ensure ovirt-engine was 
> responding before continuing the boot sequence.
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users

--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se



--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se

___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/site/privacy-policy/
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/OHUCG6MLCRLACIK442N4WYQ2XSIUGYQI/


[ovirt-users] Re: Slow first opening web portal when the ovirt-engine.service is restarted

2019-05-14 Thread aleksey . maksimov
Wow. I have installed and enabled the service on Hosted Engine VM:

# yum -y install haveged
# service haveged start
# systemctl enable haveged.service
# service haveged status

Redirecting to /bin/systemctl status  haveged.service
● haveged.service - Entropy Daemon based on the HAVEGE algorithm
   Loaded: loaded (/usr/lib/systemd/system/haveged.service; enabled; vendor 
preset: disabled)
   Active: active (running) since Mon 2016-10-03 12:56:24 MSK; 2min 12s ago
 Docs: man:haveged(8)
   http://www.issihosts.com/haveged/
 Main PID: 5304 (haveged)
   CGroup: /system.slice/haveged.service
   └─5304 /usr/sbin/haveged -w 1024 -v 1 --Foreground

Oct 03 12:56:24 KOM-AD01-OVIRT1 systemd[1]: Started Entropy Daemon based on the 
HAVEGE algorithm.
Oct 03 12:56:24 KOM-AD01-OVIRT1 systemd[1]: Starting Entropy Daemon based on 
the HAVEGE algorithm...
Oct 03 12:56:24 KOM-AD01-OVIRT1 haveged[5304]: haveged: ver: 1.9.1; arch: x86; 
vend: GenuineIntel; build: (gcc 4.8.2 ITV); collect: 128K
Oct 03 12:56:24 KOM-AD01-OVIRT1 haveged[5304]: haveged: cpu: (L4 VC); data: 32K 
(L2 L4 V); inst: 32K (L2 L4 V); idx: 21/40; sz: 32709/60538
Oct 03 12:56:24 KOM-AD01-OVIRT1 haveged[5304]: haveged: tot tests(BA8): A:1/1 
B:1/1 continuous tests(B):  last entropy estimate 8.00013
Oct 03 12:56:24 KOM-AD01-OVIRT1 haveged[5304]: haveged: fills: 0, generated: 0


And now after restarting the ovirt-engine.service, first open the web portal 
pages is instantaneous!
It works.
Thank you.

But now the question arises, in what cases can be a helpful 
ovirt-warmup.service 
(https://github.com/geertj/ravstack/blob/master/share/ovirt-warmup.service) ?

03.10.2016, 12:32, "Sandro Bonazzola" :
> This looks like not enough entropy on the host / guest running ovirt-engine.
> If you're on Hosted Engine I suggest to install haveged (in EPEL repo) and 
> run it to ensure enough entropy is available for the VM.
> Adding Simone.
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users

--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se



--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se


___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/site/privacy-policy/
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/UDLXCONPVPXXOEAJPBCRH2PRYWMIAGMP/


[ovirt-users] Re: oVirt 4.0.4 and Active Directory Kerberos SSO for Administration/User Portal. Troubleshooting

2019-05-14 Thread aleksey . maksimov
Yes. Of course. Here are my configs.

=
# cat /etc/ovirt-engine/aaa/ovirt-sso.conf


RewriteEngine on
RewriteCond %{LA-U:REMOTE_USER} ^(.*)$
RewriteRule ^(.*)$ - [L,NS,P,E=REMOTE_USER:%1]
RequestHeader set X-Remote-User %{REMOTE_USER}s
AuthType Kerberos
AuthName "Kerberos Login"
Krb5Keytab /etc/httpd/s-oVirt-Krb.keytab
KrbAuthRealms AD.HOLDING.COM
#KrbMethodNegotiate on
#KrbMethodK5Passwd on
KrbMethodK5Passwd off
Require valid-user



# ls -la /etc/httpd/conf.d/ovirt-*

-rw-r--r--. 1 root root 33 Jul 26 16:42 
/etc/httpd/conf.d/ovirt-engine-root-redirect.conf
lrwxrwxrwx. 1 root root 36 Sep 30 00:06 /etc/httpd/conf.d/ovirt-sso.conf -> 
/etc/ovirt-engine/aaa/ovirt-sso.conf


=
# cat /etc/ovirt-engine/aaa/ad.holding.com.properties

include = 
vars.domain = ad.holding.com
pool.default.auth.simple.bindDN = s-oVirt-LS@${global:vars.domain}
pool.default.auth.simple.password = Passw0rd
pool.default.dc-resolve.enable = false
search.default.dc-resolve.enable = false
search.ad-resolve-upn.search-request.baseDN = DC=ad,DC=holding,DC=com
pool.default.serverset.type = failover
pool.default.serverset.failover.00.server = kom-dc01.${global:vars.domain}
pool.default.serverset.failover.01.server = kom-dc02.${global:vars.domain}
pool.default.serverset.failover.port = 636
pool.default.serverset.failover.domain = ${global:vars.domain}
pool.default.ssl.enable = true
pool.default.ssl.protocol = TLSv1.2
pool.default.ssl.truststore.file = ${local:_basedir}/${global:vars.domain}.jks
pool.default.ssl.truststore.password = changeit

=
# cat /etc/ovirt-engine/extensions.d/ad.holding.com-authz.properties

ovirt.engine.extension.name = ad.holding.com-authz
ovirt.engine.extension.bindings.method = jbossmodule
ovirt.engine.extension.binding.jbossmodule.module = 
org.ovirt.engine-extensions.aaa.ldap
ovirt.engine.extension.binding.jbossmodule.class = 
org.ovirt.engineextensions.aaa.ldap.AuthzExtension
ovirt.engine.extension.provides = org.ovirt.engine.api.extensions.aaa.Authz
config.profile.file.1 = ../aaa/ad.holding.com.properties

=
# cat /etc/ovirt-engine/extensions.d/ad.holding.com-http-authn.properties

ovirt.engine.extension.name = ad.holding.com-http-authn
ovirt.engine.extension.bindings.method = jbossmodule
ovirt.engine.extension.binding.jbossmodule.module = 
org.ovirt.engine-extensions.aaa.misc
ovirt.engine.extension.binding.jbossmodule.class = 
org.ovirt.engineextensions.aaa.misc.http.AuthnExtension
ovirt.engine.extension.provides = org.ovirt.engine.api.extensions.aaa.Authn
ovirt.engine.aaa.authn.profile.name = ad.holding.com-http
ovirt.engine.aaa.authn.authz.plugin = ad.holding.com-authz
ovirt.engine.aaa.authn.mapping.plugin = ad.holding.com-http-mapping
config.artifact.name = HEADER
config.artifact.arg = X-Remote-User

=
# cat /etc/ovirt-engine/extensions.d/ad.holding.com-http-mapping.properties

ovirt.engine.extension.name = ad.holding.com-http-mapping
ovirt.engine.extension.bindings.method = jbossmodule
ovirt.engine.extension.binding.jbossmodule.module = 
org.ovirt.engine-extensions.aaa.misc
ovirt.engine.extension.binding.jbossmodule.class = 
org.ovirt.engineextensions.aaa.misc.mapping.MappingExtension
ovirt.engine.extension.provides = org.ovirt.engine.api.extensions.aaa.Mapping
config.mapAuthRecord.type = regex
config.mapAuthRecord.regex.mustMatch = true
config.mapAuthRecord.regex.pattern = 
^(?.*?)(((?@)(?.*?)@.*)|(?@.*))$
config.mapAuthRecord.regex.replacement = ${user}${at}${suffix}${realm}


03.10.2016, 09:56, "Martin Perina" :

> ​Ahh, so kerberos SSO works fine for API, but not for portals. Could you 
> please share your Apache configuration with oVirt kerberos configuration? 
> Usually it's in /etc/ovirt-engine/aaa/ovirt-sso.conf
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users

--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se



--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se


___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: 

[ovirt-users] Re: oVirt 4.0.4 and Active Directory Kerberos SSO for Administration/User Portal. Troubleshooting

2019-05-14 Thread aleksey . maksimov
 Hello, Martin Before I wrote: Kerberos authentication FOR WINDOWS WEB SERVERS working successfully from Internet Explorer & Forefox.Kerberos authentication NOT working with oVirt Web-Portals. I expect that the users opening the oVirt web portal in the browser did not enter a password, and used instead of the transparent sign-on using Kerberos.It is impossible ?? 03.10.2016, 09:08, "Martin Perina" :Hi Aleksey,in your last email you wrote that everything works (at least that's my understanding, email pasted below). So what exactly doesn't work for you?RegardsMartin Perina> # kinit aleksey>> Password for alek...@ad.holding.com: ***>> # klist>> Ticket cache: KEYRING:persistent:0:krb_ccache_9W86VN9> Default principal: alek...@ad.holding.com>> Valid starting       Expires              Service principal> 09/30/2016 16:50:32  10/01/2016 02:50:32  krbtgt/ad.holding@ad.holding.com>         renew until 10/07/2016 16:50:29>>> # curl --negotiate -u : -X GET -H "Accept: application/xml" -k https://kom-ad01-ovirt1.ad.holding.com/ovirt-engine/api>> > >  ... output truncated ...> >> It Works.> The browsers are configured.> Kerberos authentication for Windows web servers working successfully from Internet Explorer & Forefox  On Mon, Oct 3, 2016 at 7:37 AM,  wrote: Up30.09.2016, 18:55, "aleksey.maksi...@it-kb.ru" :> Any other ideas?___Users mailing listUsers@ovirt.orghttp://lists.ovirt.org/mailman/listinfo/users-- 
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se


-- 
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users
___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/site/privacy-policy/
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/CEWJPPFFO3TK753A3Q3SI5O5RQPM3L4O/


[ovirt-users] Re: oVirt 4.0.4 and Active Directory Kerberos SSO for Administration/User Portal. Troubleshooting

2019-05-14 Thread aleksey . maksimov

Up

30.09.2016, 18:55, "aleksey.maksi...@it-kb.ru" :
> Any other ideas?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users

--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se



--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se

___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/site/privacy-policy/
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/IAGOCAMC3NPHIRHVYG2OKP475P4YN4TE/


[ovirt-users] Re: oVirt 4.0.4 and Active Directory Kerberos SSO for Administration/User Portal. Troubleshooting

2019-05-14 Thread aleksey . maksimov
Martin, thanks for the help. It works.

03.10.2016, 15:01, "Martin Perina" :
> ​Ahh, this is the issue. Above configuration is valid for oVirt 3.x, but in 
> 4.0 we have quite new OAuth base SSO, so you need to use following 
> configuration:
>
>  ^/ovirt-engine/sso/(interactive-login-negotiate|oauth/token-http-auth)|^/ovirt-engine/api>
>   
>     RewriteEngine on
>     RewriteCond %{LA-U:REMOTE_USER} ^(.*)$
>     RewriteRule ^(.*)$ - [L,NS,P,E=REMOTE_USER:%1]
>     RequestHeader set X-Remote-User %{REMOTE_USER}s
>     AuthType Kerberos
>     AuthName "Kerberos Login"
>     Krb5Keytab /etc/httpd/s-oVirt-Krb.keytab
>     KrbAuthRealms AD.HOLDING.COM
>     KrbMethodK5Passwd off
>     Require valid-user
>     ErrorDocument 401 " url=/ovirt-engine/sso/login-unauthorized\"/> href=\"/ovirt-engine/sso/login-unauthorized\">Here"
>   
> 
> ​
>
> ​Also as 4.0 is working on EL7 you may use mod_auth_gssapi/mod_session 
> instead of quite old mod_auth_krb. For mod_auth_gssapi/mod_sessions you need 
> to do following:
>
>   1. yum install mod_session mod_auth_gssapi
>   2. Use following Apache configuration ​
>
> ​ ^/ovirt-engine/sso/(interactive-login-negotiate|oauth/token-http-auth)|^/ovirt-engine/api>
>   
>     RewriteEngine on
>     RewriteCond %{LA-U:REMOTE_USER} ^(.*)$
>     RewriteRule ^(.*)$ - [L,NS,P,E=REMOTE_USER:%1]
>     RequestHeader set X-Remote-User %{REMOTE_USER}s
>
>     AuthType GSSAPI
>     AuthName "Kerberos Login"
>
>     # Modify to match installation
>     GssapiCredStore keytab:/etc/httpd/s-oVirt-Krb.keytab
>     GssapiUseSessions On
>     Session On
>     SessionCookieName ovirt_gssapi_session path=/private;httponly;secure;
>
>     Require valid-user
>     ErrorDocument 401 " url=/ovirt-engine/sso/login-unauthorized\"/> href=\"/ovirt-engine/sso/login-unauthorized\">Here"
>   
> ​
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users

--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se



--
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you 
choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se


___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/site/privacy-policy/
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/WGBMFGNJSJFFPAUFCK3AVEXLJUKHDFAY/


[ovirt-users] Re: oVirt 4.0.4 and Active Directory Kerberos SSO for Administration/User Portal. Troubleshooting

2019-05-14 Thread aleksey . maksimov
 > network.negotiate-auth.delegation-uris = .ad.holding.com > network.negotiate-auth.trusted-uris = .ad.holding.com Yes. Configured The URL https://kom-ad01-ovirt1.ad.holding.com/ovirt-engine/api in IE and Firefox opens without problems and without password prompts But when opening links from start page... https://kom-ad01-ovirt1.ad.holding.com/ovirt-engine/userportal/?locale=en_UShttps://kom-ad01-ovirt1.ad.holding.com/ovirt-engine/webadmin/?locale=en_US ...opens a oVirt form prompting for credentials with a single profile "internal"  03.10.2016, 09:37, "Martin Perina" :  On Mon, Oct 3, 2016 at 8:18 AM,  wrote: Hello, Martin Before I wrote: Kerberos authentication FOR WINDOWS WEB SERVERS working successfully from Internet Explorer & Forefox.Kerberos authentication NOT working with oVirt Web-Portals. I expect that the users opening the oVirt web portal in the browser did not enter a password, and used instead of the transparent sign-on using Kerberos.It is impossible ?? ​It's possible and it's working fine when everything is properly set up. But please bear in mind kerberos SSO is one of the most complicated oVirt setup, but usually the error is on kerberos side (environment issues on the client). So, you are saying that using curl you are able to access API using kerberos ticket but when you try to access the same API from the browser it does not work, right?I don't use IE, but you need to set following options in "about:config" URL for Firefox to work properly with kerberos: network.negotiate-auth.delegation-uris = .ad.holding.com network.negotiate-auth.trusted-uris = .ad.holding.com If you have those options set, what exactly happen when you try to access ​https://kom-ad01-ovirt1.ad.holding.com/ovirt-engine/api​ ​in Firefox? Martin Perina​ 03.10.2016, 09:08, "Martin Perina" :Hi Aleksey,in your last email you wrote that everything works (at least that's my understanding, email pasted below). So what exactly doesn't work for you?RegardsMartin Perina> # kinit aleksey>> Password for alek...@ad.holding.com: ***>> # klist>> Ticket cache: KEYRING:persistent:0:krb_ccache_9W86VN9> Default principal: alek...@ad.holding.com>> Valid starting       Expires              Service principal> 09/30/2016 16:50:32  10/01/2016 02:50:32  krbtgt/ad.holding@ad.holding.com>         renew until 10/07/2016 16:50:29>>> # curl --negotiate -u : -X GET -H "Accept: application/xml" -k​​https://kom-ad01-ovirt1.ad.holding.com/ovirt-engine/api>> > >  ... output truncated ...> >> It Works.> The browsers are configured.> Kerberos authentication for Windows web servers working successfully from Internet Explorer & Forefox  On Mon, Oct 3, 2016 at 7:37 AM,  wrote: Up30.09.2016, 18:55, "aleksey.maksi...@it-kb.ru" :> Any other ideas?___Users mailing listUsers@ovirt.orghttp://lists.ovirt.org/mailman/listinfo/users-- 
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se


-- 
IMPORTANT!
This message has been scanned for viruses and phishing links.
However, it is your responsibility to evaluate the links and attachments you choose to click.
If you are uncertain, we always try to help.
Greetings helpd...@actnet.se

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users
___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/site/privacy-policy/
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/ATPIRCDGWQPGJLEVBXGYS7YTHVWYHREU/


[ovirt-users] Re: oVirt HE 4.2.6 - Cannot upload a QCOW2 disk image via oVirt Administration Portal

2018-10-15 Thread Aleksey Maksimov
Hello, Nir

Thank you, we will wait for the release of version 4.2.7.
And special thanks for the workaround.

PS: I was able to load the disk image after I converted it to RAW format
___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/site/privacy-policy/
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/EWXXF2MODQOTEDW5WTJS6HGZUP23XUSA/


[ovirt-users] oVirt HE 4.2.6 - Cannot upload a QCOW2 disk image via oVirt Administration Portal

2018-10-13 Thread Aleksey Maksimov
Hello, oVirt Team

I have oVirt Hosted Engine 4.2.6.4-1.el7

I cannot upload a QCOW2 disk image via oVirt Administration Portal 
(Storage\Disks\Upload). 
"Test Connection" in upload disk dialog works but the upload is changed to 
"Paused by System" after upload ~8GB from 30GB disk

-
Log from Hosted Engine:

[root@KOM-OVIRT1 ~]# tail -f /var/log/ovirt-imageio-proxy/image-proxy.log

(MainThread) INFO 2018-10-13 19:15:49,379 image_proxy:35:root:(main) Server 
shut down, exiting
(MainThread) INFO 2018-10-13 19:15:50,807 image_proxy:26:root:(main) Server 
started, successfully notified systemd
(Thread-2  ) INFO 2018-10-13 19:56:11,121 auth:187:auth2:(add_signed_ticket) 
Adding new ticket: https://kom-vm14.holding.com:54322' timeout=35997.87838792801 at 
0x7fa43b30e410>
(Thread-3  ) INFO 2018-10-13 19:56:14,160 
connectionpool:735:requests.packages.urllib3.connectionpool:(_new_conn) 
Starting new HTTPS connection (1): kom-vm14.holding.com
(Thread-4  ) INFO 2018-10-13 19:56:18,209 
connectionpool:735:requests.packages.urllib3.connectionpool:(_new_conn) 
Starting new HTTPS connection (1): kom-vm14.holding.com
...

...
(Thread-102) INFO 2018-10-13 20:02:26,311 
connectionpool:735:requests.packages.urllib3.connectionpool:(_new_conn) 
Starting new HTTPS connection (1): kom-vm14.holding.com
(Thread-103) INFO 2018-10-13 20:02:26,339 
connectionpool:735:requests.packages.urllib3.connectionpool:(_new_conn) 
Starting new HTTPS connection (1): kom-vm14.holding.com
(Thread-103) ERROR 2018-10-13 20:02:26,357 web:136:web:(log_error) ERROR 
[10.160.0.142] PUT /images/5438fcde-a614-4123-a2d5-f4fb067c6453 [500] Failed 
response from host: 500 {"explanation": "The server has either erred or is 
incapable of performing the requested operation.", "code": 500, "detail": 
"[Errno 22] Invalid argument", "title": "Internal Server Error"} 
[request=0.027293]
Traceback (most recent call last):
  File "/usr/lib64/python2.7/site-packages/ovirt_imageio_common/web.py", line 
99, in __call__
resp = self.dispatch(request, clock)
  File "/usr/lib64/python2.7/site-packages/ovirt_imageio_common/web.py", line 
128, in dispatch
return method(*match.groups())
  File "/usr/lib/python2.7/site-packages/ovirt_imageio_proxy/http_helper.py", 
line 86, in wrapper
return func(self, *args)
  File "/usr/lib/python2.7/site-packages/ovirt_imageio_proxy/http_helper.py", 
line 59, in wrapper
ret = func(self, *args)
  File "/usr/lib/python2.7/site-packages/ovirt_imageio_proxy/images.py", line 
153, in put
read_timeout=self.config.imaged_read_timeout_sec)
  File "/usr/lib/python2.7/site-packages/ovirt_imageio_proxy/images.py", line 
239, in make_imaged_request
raise exc.status_map[imaged_resp.status_code](s)
HTTPInternalServerError: Failed response from host: 500 {"explanation": "The 
server has either erred or is incapable of performing the requested 
operation.", "code": 500, "detail": "[Errno 22] Invalid argument", "title": 
"Internal Server Error"}
(Thread-104) INFO 2018-10-13 20:02:29,463 
connectionpool:735:requests.packages.urllib3.connectionpool:(_new_conn) 
Starting new HTTPS connection (1): kom-vm14.holding.com
(Thread-104) ERROR 2018-10-13 20:02:29,475 web:136:web:(log_error) ERROR 
[10.160.0.142] PUT /images/5438fcde-a614-4123-a2d5-f4fb067c6453 [500] Failed 
response from host: 500 {"explanation": "The server has either erred or is 
incapable of performing the requested operation.", "code": 500, "detail": 
"[Errno 22] Invalid argument", "title": "Internal Server Error"} 
[request=0.013473]
Traceback (most recent call last):
  File "/usr/lib64/python2.7/site-packages/ovirt_imageio_common/web.py", line 
99, in __call__
resp = self.dispatch(request, clock)
  File "/usr/lib64/python2.7/site-packages/ovirt_imageio_common/web.py", line 
128, in dispatch
return method(*match.groups())
  File "/usr/lib/python2.7/site-packages/ovirt_imageio_proxy/http_helper.py", 
line 86, in wrapper
return func(self, *args)
  File "/usr/lib/python2.7/site-packages/ovirt_imageio_proxy/http_helper.py", 
line 59, in wrapper
ret = func(self, *args)
  File "/usr/lib/python2.7/site-packages/ovirt_imageio_proxy/images.py", line 
153, in put
read_timeout=self.config.imaged_read_timeout_sec)
  File "/usr/lib/python2.7/site-packages/ovirt_imageio_proxy/images.py", line 
239, in make_imaged_request
raise exc.status_map[imaged_resp.status_code](s)
HTTPInternalServerError: Failed response from host: 500 {"explanation": "The 
server has either erred or is incapable of performing the requested 
operation.", "code": 500, "detail": "[Errno 22] Invalid argument", "title": 
"Internal Server Error"}
...

-
Log from Host (kom-vm14.holding.com):

[root@KOM-VM14 ~]# tail -f  /var/log/ovirt-imageio-daemon/daemon.log

2018-09-20 15:28:24,885 INFO(MainThread) [server] Starting (pid=1311, 
version=1.4.4)
2018-09-20 15:28:24,892 INFO(MainThread) [server] 

[ovirt-users] Re: oVirt 4.2.5 : VM snapshot creation does not work : command HSMGetAllTasksStatusesVDS failed: Could not acquire resource

2018-08-17 Thread Aleksey Maksimov
Hello Nir

Many thanks for your help.
The problem is solved.
___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/site/privacy-policy/
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/SHF2S65YU3RMFBOM7OY7RHEO76HIBE7E/


[ovirt-users] Re: oVirt node 4.2.x - custom multipath.conf and external storage availability

2018-08-13 Thread Aleksey Maksimov
Hello Roberto

I solved a similar problem by adding an additional line "# VDSM PRIVATE" to the 
beginning of the file /etc/multipath.conf
For example, the beginning of the file looks like this:

# VDSM REVISION 1.3
# VDSM PRIVATE
…

This prevents configuration overwriting.
___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/site/privacy-policy/
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/IOWGFZVXP7OY6YILBU7ACCOUKJASJAKQ/


[ovirt-users] oVirt 4.2.5 : VM snapshot creation does not work : command HSMGetAllTasksStatusesVDS failed: Could not acquire resource

2018-08-13 Thread Aleksey Maksimov
Hello

We use oVirt 4.2.5.2-1.el7 (Hosted engine / 4 hosts in cluster / about twenty 
virtual machines)
Virtual machine disks are located on the Data Domain from FC SAN.
Snapshots of all virtual machines are created normally. But for one virtual 
machine, we can not create a snapshot.

When we try to create a snapshot in the oVirt web console, we see such errors:

Aug 13, 2018, 1:05:06 PM Failed to complete snapshot 'KOM-APP14_BACKUP01' 
creation for VM 'KOM-APP14'. 
Aug 13, 2018, 1:05:01 PM VDSM KOM-VM14 command HSMGetAllTasksStatusesVDS 
failed: Could not acquire resource. Probably resource factory threw an 
exception.: () 
Aug 13, 2018, 1:05:00 PM Snapshot 'KOM-APP14_BACKUP01' creation for VM 
'KOM-APP14' was initiated by pe...@sub.holding.com@sub.holding.com-authz. 

At this time on the server with the role of "SPM" in the vdsm.log we see this:

...
2018-08-13 05:05:06,471-0500 INFO  (jsonrpc/0) [jsonrpc.JsonRpcServer] RPC call 
VM.getStats succeeded in 0.00 seconds (__init__:573)
2018-08-13 05:05:06,478-0500 INFO  (jsonrpc/5) [jsonrpc.JsonRpcServer] RPC call 
Image.deleteVolumes succeeded in 0.05 seconds (__init__:573)
2018-08-13 05:05:06,478-0500 INFO  (tasks/3) [storage.ThreadPool.WorkerThread] 
START task bb45ae7e-77e9-4fec-9ee2-8e1f0ad3d589 (cmd=>, args=None) 
(threadPool:208)
2018-08-13 05:05:07,009-0500 WARN  (tasks/3) [storage.ResourceManager] Resource 
factory failed to create resource 
'01_img_6db73566-0f7f-4438-a9ef-6815075f45ea.cdf1751b-64d3-42bc-b9ef-b0174c7ea068'.
 Canceling request. (resourceManager:543)
Traceback (most recent call last):
  File "/usr/lib/python2.7/site-packages/vdsm/storage/resourceManager.py", line 
539, in registerResource
obj = namespaceObj.factory.createResource(name, lockType)
  File "/usr/lib/python2.7/site-packages/vdsm/storage/resourceFactories.py", 
line 193, in createResource
lockType)
  File "/usr/lib/python2.7/site-packages/vdsm/storage/resourceFactories.py", 
line 122, in __getResourceCandidatesList
imgUUID=resourceName)
  File "/usr/lib/python2.7/site-packages/vdsm/storage/image.py", line 213, in 
getChain
if srcVol.isLeaf():
  File "/usr/lib/python2.7/site-packages/vdsm/storage/volume.py", line 1430, in 
isLeaf
return self._manifest.isLeaf()
  File "/usr/lib/python2.7/site-packages/vdsm/storage/volume.py", line 139, in 
isLeaf
return self.getVolType() == sc.type2name(sc.LEAF_VOL)
  File "/usr/lib/python2.7/site-packages/vdsm/storage/volume.py", line 135, in 
getVolType
self.voltype = self.getMetaParam(sc.VOLTYPE)
  File "/usr/lib/python2.7/site-packages/vdsm/storage/volume.py", line 119, in 
getMetaParam
meta = self.getMetadata()
  File "/usr/lib/python2.7/site-packages/vdsm/storage/blockVolume.py", line 
112, in getMetadata
md = VolumeMetadata.from_lines(lines)
  File "/usr/lib/python2.7/site-packages/vdsm/storage/volumemetadata.py", line 
103, in from_lines
"Missing metadata key: %s: found: %s" % (e, md))
MetaDataKeyNotFoundError: Meta Data key not found error: ("Missing metadata 
key: 'DOMAIN': found: {'NONE': 
'##'}",)
2018-08-13 05:05:07,010-0500 WARN  (tasks/3) [storage.ResourceManager.Request] 
(ResName='01_img_6db73566-0f7f-4438-a9ef-6815075f45ea.cdf1751b-64d3-42bc-b9ef-b0174c7ea068',
 ReqID='3d924e5e-60d1-47b0-86a7-c63585b56f09') Tried to cancel a processed 
request (resourceManager:187)
2018-08-13 05:05:07,010-0500 ERROR (tasks/3) [storage.TaskManager.Task] 
(Task='bb45ae7e-77e9-4fec-9ee2-8e1f0ad3d589') Unexpected error (task:875)
Traceback (most recent call last):
  File "/usr/lib/python2.7/site-packages/vdsm/storage/task.py", line 882, in 
_run
return fn(*args, **kargs)
  File "/usr/lib/python2.7/site-packages/vdsm/storage/task.py", line 336, in run
return self.cmd(*self.argslist, **self.argsdict)
  File "/usr/lib/python2.7/site-packages/vdsm/storage/securable.py", line 79, 
in wrapper
return method(self, *args, **kwargs)
  File "/usr/lib/python2.7/site-packages/vdsm/storage/sp.py", line 1966, in 
deleteVolume
with rm.acquireResource(img_ns, imgUUID, rm.EXCLUSIVE):
  File "/usr/lib/python2.7/site-packages/vdsm/storage/resourceManager.py", line 
1025, in acquireResource
return _manager.acquireResource(namespace, name, lockType, timeout=timeout)
  File "/usr/lib/python2.7/site-packages/vdsm/storage/resourceManager.py", line 
475, in acquireResource
raise se.ResourceAcqusitionFailed()
ResourceAcqusitionFailed: Could not acquire resource. Probably resource factory 
threw an exception.: ()

Re: [ovirt-users] How can I import VMWare OVA file to oVirt 4.0?

2016-12-14 Thread aleksey . maksimov
Derek, thank you for participating.

In the end, I completed the task (OVA imported).
The root of the problem is that I tried to use the import with thin provision. 
But there is a known issue https://bugzilla.redhat.com/show_bug.cgi?id=1382404
Workaround: Import VM from OVA as preallocated
It's not a very good solution, but it is better than nothing

14.12.2016, 17:50, "Derek Atkins" :
> Hi Aleksey,
>
> One more question for debugging purposes: How long does the import go
> before it dies? Do you have enough time to run:
>
>   ps aux | grep virt-v2v
>
> On the import host while it's running? This might help us determine
> where it's trying to store the data. It should be storing it in the
> target storage, but it's possible that it's using temp space and then
> running out.
>
> -derek
>
> aleksey.maksi...@it-kb.ru writes:
>
>>  Hi Shahar.
>>
>>  Look at the attached screenshot
>>
>>  14.12.2016, 12:15, "Shahar Havivi" :
>>
>>  Hi,
>>  I was able to import your VMs with storage domain that had 350GB free.
>>  Your ova have a disk with 1GB actual size and 256 virtual size - when I
>>  try to import to a storage with 50G I got the error that you had.
>>
>>  if you will look at /var/log/vdsm/import/... you will see the logs of 
>> each
>>  import,
>>  In the one that fail I found this line:
>>  qemu-img: error while writing sector 423174528: No space left on device
>>
>>  virt-v2v try to convert via qemu-img the img from vmdk to qcow and
>>  encountered free space issue in the storage domain.
>>
>>  Please consider asking the mailing list  libgues...@redhat.com about 
>> this
>>  issue or try to increase your storage domain if you want a quick fix.
>>
>>  The reason that I think you where able to import via the virt-v2v 
>> command
>>  is the usage of 'virt-v2v -o null' which is not writing to the disk.
>>
>>  Shahar.
>>
>>  On Tue, Dec 13, 2016 at 12:54 PM,  wrote:
>>
>>  Engine - oVirt Engine Version: 4.0.5.5-1.el7.centos (CentOS 7.2)
>>
>>  All Hosts:
>>  OS Version:RHEL - 7 - 2.1511.el7.centos.2.10
>>  OS Description:CentOS Linux 7 (Core)
>>  Kernel Version:3.10.0 - 327.36.3.el7.x86_64
>>  KVM Version:2.3.0 - 31.el7.16.1
>>  LIBVIRT Version:libvirt-2.0.0-10.el7_3.2
>>  VDSM Version:vdsm-4.18.15.3-1.el7.centos
>>  SPICE Version:0.12.4 - 15.el7_2.2
>>  GlusterFS Version:[N/A]
>>  CEPH Version:librbd1-0.80.7-3.el7
>>
>>  [root@KOM-AD01-VM31 ~]# virt-v2v -V
>>  virt-v2v 1.28.1
>>
>>  13.12.2016, 13:20, "Shahar Havivi" :
>>
>>  version of Engine and Host and virt-v2v (which is running on 
>> your
>>  host)
>>  and are you running on Fedora, Centos ext?
>>
>>  On Tue, Dec 13, 2016 at 12:08 PM, 
>>  wrote:
>>
>>  1. No. This is an unacceptable option for me
>>  2. No. This is my first experience
>>  3. Versions where? On Engine or on Host ?
>>  4. Yes.
>>
>>  13.12.2016, 13:03, "Shahar Havivi" :
>>
>>  Thanks you,
>>  Several questions:
>>  1. did you try to import the disk target as preallocate?
>>  2. did you try to import other ova files?
>>  3. can you please send us version of virt-v2v, vdsm and
>>  engine and the os that you are running with.
>>  4. Is it possible for you to share the ova file?
>>
>>  Thank you,
>>   Shahar.
>>
>>  On Tue, Dec 13, 2016 at 11:23 AM, <
>>  aleksey.maksi...@it-kb.ru> wrote:
>>
>>  Log attached
>>
>>  13.12.2016, 11:32, "Shahar Havivi" 
>> >  >:
>>
>>  Thank you,
>>  We need the vdsm log as well please - its the 
>> host
>>  that you try to import the ova from under 
>> /var/log
>>  /vdsm/vdsm.log
>>
>>   Shahar.
>>
>>  On Tue, Dec 13, 2016 at 9:58 AM, <
>>  aleksey.maksi...@it-kb.ru> wrote:
>>
>>  Log attached
>>
>>  13.12.2016, 10:04, "Shahar Havivi" <
>>  shav...@redhat.com>:
>>
>>  Please attach the log and will see what
>>  the error is.
>>
>>  On Tue, Dec 13, 2016 at 9:01 AM, <
>>  

Re: [ovirt-users] How can I import VMWare OVA file to oVirt 4.0?

2016-12-13 Thread aleksey . maksimov
No. The problem is not solved. I still can not import OVA in oVirt.
And the problem is not a lack of disk space.

13.12.2016, 18:58, "Derek Atkins" :
> Hi,
>
> aleksey.maksi...@it-kb.ru writes:
>
>>  # LIBGUESTFS_BACKEND=direct virt-v2v -v -x -i ova
>>  /tmp/rhel_Vsp-4.4.0.GA-53.ova -of raw -o null
>>
>>  
>>  fsync /dev/sda
>>  guestfsd: main_loop: proc 282 (internal_autosync) took 0.01 seconds
>>  libguestfs: trace: internal_autosync = 0
>>  libguestfs: sending SIGTERM to process 3338
>>  libguestfs: trace: shutdown = 0
>>  libguestfs: trace: close
>>  libguestfs: closing guestfs handle 0x2880a10 (state 0)
>>  libguestfs: command: run: rm
>>  libguestfs: command: run: \ -rf /tmp/libguestfsrxuByo
>>  [ 99.0] Checking if the guest needs BIOS or UEFI to boot
>>  [ 99.0] Copying disk 1/1 to /var/tmp/null.lP6vGa/sda (raw)
>>  target_file = /var/tmp/null.lP6vGa/sda
>>  target_format = raw
>>  target_estimated_size = 13480052354
>>  target_overlay = /var/tmp/v2vovle81937.qcow2
>>  target_overlay.ov_source = 
>> /var/tmp/ova.zJ6ks8/rhel_Vsp-4.4.0.GA-53-disk1.vmdk
>>  qemu-img convert -p -n -f qcow2 -O 'raw' '/var/tmp/v2vovle81937.qcow2'
>>  '/var/tmp/null.lP6vGa/sda'
>>  (100.00/100%)
>>  virtual copying rate: 95364.1 M bits/sec
>>  real copying rate: 811.7 M bits/sec
>>  sda: estimate 13480052354 (12.6G) versus actual 2339610624 (2.2G): 476.2%
>>  [ 126.0] Creating output metadata
>>  [ 126.0] Finishing off
>>
>>  The output is very voluminous. Errors are seen.
>
> So it estimates that it will require 13GB. Do you have 13GB free on
> /var/tmp?
>
> You say "Errors are seen." What errors do you see? It *looks* like
> this finished successfully.
>
> -derek
> --
>    Derek Atkins 617-623-3745
>    de...@ihtfp.com www.ihtfp.com
>    Computer and Internet Security Consultant
___
Users mailing list
Users@ovirt.org
http://lists.phx.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] How can I import VMWare OVA file to oVirt 4.0?

2016-12-13 Thread aleksey . maksimov
Engine - oVirt Engine Version: 4.0.5.5-1.el7.centos (CentOS 7.2)All Hosts:OS Version:RHEL - 7 - 2.1511.el7.centos.2.10OS Description:CentOS Linux 7 (Core)Kernel Version:3.10.0 - 327.36.3.el7.x86_64KVM Version:2.3.0 - 31.el7.16.1LIBVIRT Version:libvirt-2.0.0-10.el7_3.2VDSM Version:vdsm-4.18.15.3-1.el7.centosSPICE Version:0.12.4 - 15.el7_2.2GlusterFS Version:[N/A]CEPH Version:librbd1-0.80.7-3.el7 [root@KOM-AD01-VM31 ~]# virt-v2v -Vvirt-v2v 1.28.1  13.12.2016, 13:20, "Shahar Havivi" :version of Engine and Host and virt-v2v (which is running on your host)and are you running on Fedora, Centos ext?  On Tue, Dec 13, 2016 at 12:08 PM,  wrote:1. No. This is an unacceptable option for me2. No. This is my first experience3. Versions where? On Engine or on Host ?4. Yes.  13.12.2016, 13:03, "Shahar Havivi" :Thanks you,Several questions:1. did you try to import the disk target as preallocate?2. did you try to import other ova files?3. can you please send us version of virt-v2v, vdsm and engine and the os that you are running with.4. Is it possible for you to share the ova file? Thank you, Shahar. On Tue, Dec 13, 2016 at 11:23 AM,  wrote:Log attached 13.12.2016, 11:32, "Shahar Havivi" :Thank you,We need the vdsm log as well please - its the host that you try to import the ova from under /var/log/vdsm/vdsm.log  Shahar. On Tue, Dec 13, 2016 at 9:58 AM,  wrote:Log attached 13.12.2016, 10:04, "Shahar Havivi" :Please attach the log and will see what the error is. On Tue, Dec 13, 2016 at 9:01 AM,  wrote:Preallocated ?I'm trying to import image of virtual appliance "HP 3PAR Virtual Service Processor"This virtual machine has drive 256GB. But really, this is a 40GB disk never grows. I don't want to waste that much disk space. There is no other way ? 13.12.2016, 09:53, "Shahar Havivi" :Okso try to import as preallocated and attach the log if you have any errors. Shahar. On Tue, Dec 13, 2016 at 8:47 AM,  wrote: All my Data-Domains - FC SAN. Not ISCSI.  13.12.2016, 09:41, "Shahar Havivi" :What is the type of the target storage domain that you try to import to?(nfs or iscsi)if its iscsi try to change it to preallocate instead of thin-provision,also please attach the engine log if you have more problems.  Shahar. On Tue, Dec 13, 2016 at 7:08 AM,  wrote:# LIBGUESTFS_BACKEND=direct virt-v2v -v -x -i ova /tmp/rhel_Vsp-4.4.0.GA-53.ova -of raw -o nullfsync /dev/sdaguestfsd: main_loop: proc 282 (internal_autosync) took 0.01 secondslibguestfs: trace: internal_autosync = 0libguestfs: sending SIGTERM to process 3338libguestfs: trace: shutdown = 0libguestfs: trace: closelibguestfs: closing guestfs handle 0x2880a10 (state 0)libguestfs: command: run: rmlibguestfs: command: run: \ -rf /tmp/libguestfsrxuByo[  99.0] Checking if the guest needs BIOS or UEFI to boot[  99.0] Copying disk 1/1 to /var/tmp/null.lP6vGa/sda (raw)target_file = /var/tmp/null.lP6vGa/sdatarget_format = rawtarget_estimated_size = 13480052354target_overlay = /var/tmp/v2vovle81937.qcow2target_overlay.ov_source = /var/tmp/ova.zJ6ks8/rhel_Vsp-4.4.0.GA-53-disk1.vmdkqemu-img convert -p -n -f qcow2 -O 'raw' '/var/tmp/v2vovle81937.qcow2' '/var/tmp/null.lP6vGa/sda'    (100.00/100%)virtual copying rate: 95364.1 M bits/secreal copying rate: 811.7 M bits/secsda: estimate 13480052354 (12.6G) versus actual 2339610624 (2.2G): 476.2%[ 126.0] Creating output metadata[ 126.0] Finishing offThe output is very voluminous. Errors are seen.13.12.2016, 07:59, "aleksey.maksi...@it-kb.ru" :> -bash: annotate-output: command not found>> 12.12.2016, 21:26, "Derek Atkins" :>>  Hi,  What happened when you ran the virt-v2v command I suggested?  -derek  On Mon, December 12, 2016 12:32 pm, aleksey.maksi...@it-kb.ru wrote:>>>   I mount 5TB nfs-share to my host and tried to import OVA from this>>>   mount-point.>>>   Exact same error.>>   Do the import process attempts to use 256G inside the Engine virtual>>>   machine ???>>   12.12.2016, 18:01, "aleksey.maksi...@it-kb.ru">>>   :   1.2G is real OVA image size.   256G is virtual disk size.   Could this be a problem?   But before I start the import, in the settings I choose "Thin provision"   (see the attached screenshot)   12.12.2016, 17:47, "aleksey.maksi...@it-kb.ru"   :>    Hi Derek>>    # df -H /tmp/>>    Filesystem Size Used Avail Use% Mounted on>    /dev/cciss/c0d0p2 53G 5.7G 45G 12% />>    But my OVA file size - 1.2G>>    12.12.2016, 17:26, "Derek Atkins" :>> Hi, Did you perhaps run out of disk space in /tmp? I'm not sure where>>   the>>  

Re: [ovirt-users] How can I import VMWare OVA file to oVirt 4.0?

2016-12-13 Thread aleksey . maksimov
1. No. This is an unacceptable option for me2. No. This is my first experience3. Versions where? On Engine or on Host ?4. Yes.  13.12.2016, 13:03, "Shahar Havivi" :Thanks you,Several questions:1. did you try to import the disk target as preallocate?2. did you try to import other ova files?3. can you please send us version of virt-v2v, vdsm and engine and the os that you are running with.4. Is it possible for you to share the ova file? Thank you, Shahar. On Tue, Dec 13, 2016 at 11:23 AM,  wrote:Log attached 13.12.2016, 11:32, "Shahar Havivi" :Thank you,We need the vdsm log as well please - its the host that you try to import the ova from under /var/log/vdsm/vdsm.log  Shahar. On Tue, Dec 13, 2016 at 9:58 AM,  wrote:Log attached 13.12.2016, 10:04, "Shahar Havivi" :Please attach the log and will see what the error is. On Tue, Dec 13, 2016 at 9:01 AM,  wrote:Preallocated ?I'm trying to import image of virtual appliance "HP 3PAR Virtual Service Processor"This virtual machine has drive 256GB. But really, this is a 40GB disk never grows. I don't want to waste that much disk space. There is no other way ? 13.12.2016, 09:53, "Shahar Havivi" :Okso try to import as preallocated and attach the log if you have any errors. Shahar. On Tue, Dec 13, 2016 at 8:47 AM,  wrote: All my Data-Domains - FC SAN. Not ISCSI.  13.12.2016, 09:41, "Shahar Havivi" :What is the type of the target storage domain that you try to import to?(nfs or iscsi)if its iscsi try to change it to preallocate instead of thin-provision,also please attach the engine log if you have more problems.  Shahar. On Tue, Dec 13, 2016 at 7:08 AM,  wrote:# LIBGUESTFS_BACKEND=direct virt-v2v -v -x -i ova /tmp/rhel_Vsp-4.4.0.GA-53.ova -of raw -o nullfsync /dev/sdaguestfsd: main_loop: proc 282 (internal_autosync) took 0.01 secondslibguestfs: trace: internal_autosync = 0libguestfs: sending SIGTERM to process 3338libguestfs: trace: shutdown = 0libguestfs: trace: closelibguestfs: closing guestfs handle 0x2880a10 (state 0)libguestfs: command: run: rmlibguestfs: command: run: \ -rf /tmp/libguestfsrxuByo[  99.0] Checking if the guest needs BIOS or UEFI to boot[  99.0] Copying disk 1/1 to /var/tmp/null.lP6vGa/sda (raw)target_file = /var/tmp/null.lP6vGa/sdatarget_format = rawtarget_estimated_size = 13480052354target_overlay = /var/tmp/v2vovle81937.qcow2target_overlay.ov_source = /var/tmp/ova.zJ6ks8/rhel_Vsp-4.4.0.GA-53-disk1.vmdkqemu-img convert -p -n -f qcow2 -O 'raw' '/var/tmp/v2vovle81937.qcow2' '/var/tmp/null.lP6vGa/sda'    (100.00/100%)virtual copying rate: 95364.1 M bits/secreal copying rate: 811.7 M bits/secsda: estimate 13480052354 (12.6G) versus actual 2339610624 (2.2G): 476.2%[ 126.0] Creating output metadata[ 126.0] Finishing offThe output is very voluminous. Errors are seen.13.12.2016, 07:59, "aleksey.maksi...@it-kb.ru" :> -bash: annotate-output: command not found>> 12.12.2016, 21:26, "Derek Atkins" :>>  Hi,  What happened when you ran the virt-v2v command I suggested?  -derek  On Mon, December 12, 2016 12:32 pm, aleksey.maksi...@it-kb.ru wrote:>>>   I mount 5TB nfs-share to my host and tried to import OVA from this>>>   mount-point.>>>   Exact same error.>>   Do the import process attempts to use 256G inside the Engine virtual>>>   machine ???>>   12.12.2016, 18:01, "aleksey.maksi...@it-kb.ru">>>   :   1.2G is real OVA image size.   256G is virtual disk size.   Could this be a problem?   But before I start the import, in the settings I choose "Thin provision"   (see the attached screenshot)   12.12.2016, 17:47, "aleksey.maksi...@it-kb.ru"   :>    Hi Derek>>    # df -H /tmp/>>    Filesystem Size Used Avail Use% Mounted on>    /dev/cciss/c0d0p2 53G 5.7G 45G 12% />>    But my OVA file size - 1.2G>>    12.12.2016, 17:26, "Derek Atkins" :>> Hi, Did you perhaps run out of disk space in /tmp? I'm not sure where>>   the>> virt-v2v does it work, but the error "Conversion of VM from exteral>> enironment failed: copy-disk stream closed unexpectedly" seems to>>   imply an>> error there. I had no issues myself on 4.0.5 (modulo setfiles taking a very long>>   time>> in a few cases). -derek On Mon, December 12, 2016 9:19 am, aleksey.maksi...@it-kb.ru wrote:>>>  Hello oVirt guru`s!>>  In the process of importing from OVA file (from>>>  /tmp/rhel_Vsp-4.4.0.GA-53.ova in one of hosts) VM first appears in>>>   the web>>>  console, then disappears.>>  In the oVirt 

Re: [ovirt-users] How can I import VMWare OVA file to oVirt 4.0?

2016-12-12 Thread aleksey . maksimov
Log attached 13.12.2016, 10:04, "Shahar Havivi" :Please attach the log and will see what the error is. On Tue, Dec 13, 2016 at 9:01 AM,  wrote:Preallocated ?I'm trying to import image of virtual appliance "HP 3PAR Virtual Service Processor"This virtual machine has drive 256GB. But really, this is a 40GB disk never grows. I don't want to waste that much disk space. There is no other way ? 13.12.2016, 09:53, "Shahar Havivi" :Okso try to import as preallocated and attach the log if you have any errors. Shahar. On Tue, Dec 13, 2016 at 8:47 AM,  wrote: All my Data-Domains - FC SAN. Not ISCSI.  13.12.2016, 09:41, "Shahar Havivi" :What is the type of the target storage domain that you try to import to?(nfs or iscsi)if its iscsi try to change it to preallocate instead of thin-provision,also please attach the engine log if you have more problems.  Shahar. On Tue, Dec 13, 2016 at 7:08 AM,  wrote:# LIBGUESTFS_BACKEND=direct virt-v2v -v -x -i ova /tmp/rhel_Vsp-4.4.0.GA-53.ova -of raw -o nullfsync /dev/sdaguestfsd: main_loop: proc 282 (internal_autosync) took 0.01 secondslibguestfs: trace: internal_autosync = 0libguestfs: sending SIGTERM to process 3338libguestfs: trace: shutdown = 0libguestfs: trace: closelibguestfs: closing guestfs handle 0x2880a10 (state 0)libguestfs: command: run: rmlibguestfs: command: run: \ -rf /tmp/libguestfsrxuByo[  99.0] Checking if the guest needs BIOS or UEFI to boot[  99.0] Copying disk 1/1 to /var/tmp/null.lP6vGa/sda (raw)target_file = /var/tmp/null.lP6vGa/sdatarget_format = rawtarget_estimated_size = 13480052354target_overlay = /var/tmp/v2vovle81937.qcow2target_overlay.ov_source = /var/tmp/ova.zJ6ks8/rhel_Vsp-4.4.0.GA-53-disk1.vmdkqemu-img convert -p -n -f qcow2 -O 'raw' '/var/tmp/v2vovle81937.qcow2' '/var/tmp/null.lP6vGa/sda'    (100.00/100%)virtual copying rate: 95364.1 M bits/secreal copying rate: 811.7 M bits/secsda: estimate 13480052354 (12.6G) versus actual 2339610624 (2.2G): 476.2%[ 126.0] Creating output metadata[ 126.0] Finishing offThe output is very voluminous. Errors are seen.13.12.2016, 07:59, "aleksey.maksi...@it-kb.ru" :> -bash: annotate-output: command not found>> 12.12.2016, 21:26, "Derek Atkins" :>>  Hi,  What happened when you ran the virt-v2v command I suggested?  -derek  On Mon, December 12, 2016 12:32 pm, aleksey.maksi...@it-kb.ru wrote:>>>   I mount 5TB nfs-share to my host and tried to import OVA from this>>>   mount-point.>>>   Exact same error.>>   Do the import process attempts to use 256G inside the Engine virtual>>>   machine ???>>   12.12.2016, 18:01, "aleksey.maksi...@it-kb.ru">>>   :   1.2G is real OVA image size.   256G is virtual disk size.   Could this be a problem?   But before I start the import, in the settings I choose "Thin provision"   (see the attached screenshot)   12.12.2016, 17:47, "aleksey.maksi...@it-kb.ru"   :>    Hi Derek>>    # df -H /tmp/>>    Filesystem Size Used Avail Use% Mounted on>    /dev/cciss/c0d0p2 53G 5.7G 45G 12% />>    But my OVA file size - 1.2G>>    12.12.2016, 17:26, "Derek Atkins" :>> Hi, Did you perhaps run out of disk space in /tmp? I'm not sure where>>   the>> virt-v2v does it work, but the error "Conversion of VM from exteral>> enironment failed: copy-disk stream closed unexpectedly" seems to>>   imply an>> error there. I had no issues myself on 4.0.5 (modulo setfiles taking a very long>>   time>> in a few cases). -derek On Mon, December 12, 2016 9:19 am, aleksey.maksi...@it-kb.ru wrote:>>>  Hello oVirt guru`s!>>  In the process of importing from OVA file (from>>>  /tmp/rhel_Vsp-4.4.0.GA-53.ova in one of hosts) VM first appears in>>>   the web>>>  console, then disappears.>>  In the oVirt Engine log:>>  ...>>>  2016-12-12 16:55:20,209 INFO>>>  [org.ovirt.engine.core.bll.exportimport.ImportVmFromOvaCommand]>>>   (default>>>  task-28) [6179021a] Lock Acquired to object>>>  'EngineLock:{exclusiveLocks='[rhel_Vsp-4.4.0.GA-53=>>  ACTION_TYPE_FAILED_NAME_ALREADY_USED>,>>>  2a3d20f9-502a-4c60-8c14-371456cd4c99=>>  ACTION_TYPE_FAILED_VM_IS_BEING_IMPORTED$VmName>>>   rhel_Vsp-4.4.0.GA-53>]',>>>  sharedLocks='null'}'>>>  2016-12-12 16:55:20,326 WARN>>>  [org.ovirt.engine.core.dal.job.ExecutionMessageDirector]>>>  (org.ovirt.thread.pool-6-thread-35) [6179021a] The message key>>>  'ImportVmFromOva' is missing from 'bundles/ExecutionMessages'>>>  ...>>>  

Re: [ovirt-users] How can I import VMWare OVA file to oVirt 4.0?

2016-12-12 Thread aleksey . maksimov
Preallocated ?I'm trying to import image of virtual appliance "HP 3PAR Virtual Service Processor"This virtual machine has drive 256GB. But really, this is a 40GB disk never grows. I don't want to waste that much disk space. There is no other way ? 13.12.2016, 09:53, "Shahar Havivi" :Okso try to import as preallocated and attach the log if you have any errors. Shahar. On Tue, Dec 13, 2016 at 8:47 AM,  wrote: All my Data-Domains - FC SAN. Not ISCSI.  13.12.2016, 09:41, "Shahar Havivi" :What is the type of the target storage domain that you try to import to?(nfs or iscsi)if its iscsi try to change it to preallocate instead of thin-provision,also please attach the engine log if you have more problems.  Shahar. On Tue, Dec 13, 2016 at 7:08 AM,  wrote:# LIBGUESTFS_BACKEND=direct virt-v2v -v -x -i ova /tmp/rhel_Vsp-4.4.0.GA-53.ova -of raw -o nullfsync /dev/sdaguestfsd: main_loop: proc 282 (internal_autosync) took 0.01 secondslibguestfs: trace: internal_autosync = 0libguestfs: sending SIGTERM to process 3338libguestfs: trace: shutdown = 0libguestfs: trace: closelibguestfs: closing guestfs handle 0x2880a10 (state 0)libguestfs: command: run: rmlibguestfs: command: run: \ -rf /tmp/libguestfsrxuByo[  99.0] Checking if the guest needs BIOS or UEFI to boot[  99.0] Copying disk 1/1 to /var/tmp/null.lP6vGa/sda (raw)target_file = /var/tmp/null.lP6vGa/sdatarget_format = rawtarget_estimated_size = 13480052354target_overlay = /var/tmp/v2vovle81937.qcow2target_overlay.ov_source = /var/tmp/ova.zJ6ks8/rhel_Vsp-4.4.0.GA-53-disk1.vmdkqemu-img convert -p -n -f qcow2 -O 'raw' '/var/tmp/v2vovle81937.qcow2' '/var/tmp/null.lP6vGa/sda'    (100.00/100%)virtual copying rate: 95364.1 M bits/secreal copying rate: 811.7 M bits/secsda: estimate 13480052354 (12.6G) versus actual 2339610624 (2.2G): 476.2%[ 126.0] Creating output metadata[ 126.0] Finishing offThe output is very voluminous. Errors are seen.13.12.2016, 07:59, "aleksey.maksi...@it-kb.ru" :> -bash: annotate-output: command not found>> 12.12.2016, 21:26, "Derek Atkins" :>>  Hi,  What happened when you ran the virt-v2v command I suggested?  -derek  On Mon, December 12, 2016 12:32 pm, aleksey.maksi...@it-kb.ru wrote:>>>   I mount 5TB nfs-share to my host and tried to import OVA from this>>>   mount-point.>>>   Exact same error.>>   Do the import process attempts to use 256G inside the Engine virtual>>>   machine ???>>   12.12.2016, 18:01, "aleksey.maksi...@it-kb.ru">>>   :   1.2G is real OVA image size.   256G is virtual disk size.   Could this be a problem?   But before I start the import, in the settings I choose "Thin provision"   (see the attached screenshot)   12.12.2016, 17:47, "aleksey.maksi...@it-kb.ru"   :>    Hi Derek>>    # df -H /tmp/>>    Filesystem Size Used Avail Use% Mounted on>    /dev/cciss/c0d0p2 53G 5.7G 45G 12% />>    But my OVA file size - 1.2G>>    12.12.2016, 17:26, "Derek Atkins" :>> Hi, Did you perhaps run out of disk space in /tmp? I'm not sure where>>   the>> virt-v2v does it work, but the error "Conversion of VM from exteral>> enironment failed: copy-disk stream closed unexpectedly" seems to>>   imply an>> error there. I had no issues myself on 4.0.5 (modulo setfiles taking a very long>>   time>> in a few cases). -derek On Mon, December 12, 2016 9:19 am, aleksey.maksi...@it-kb.ru wrote:>>>  Hello oVirt guru`s!>>  In the process of importing from OVA file (from>>>  /tmp/rhel_Vsp-4.4.0.GA-53.ova in one of hosts) VM first appears in>>>   the web>>>  console, then disappears.>>  In the oVirt Engine log:>>  ...>>>  2016-12-12 16:55:20,209 INFO>>>  [org.ovirt.engine.core.bll.exportimport.ImportVmFromOvaCommand]>>>   (default>>>  task-28) [6179021a] Lock Acquired to object>>>  'EngineLock:{exclusiveLocks='[rhel_Vsp-4.4.0.GA-53=>>  ACTION_TYPE_FAILED_NAME_ALREADY_USED>,>>>  2a3d20f9-502a-4c60-8c14-371456cd4c99=>>  ACTION_TYPE_FAILED_VM_IS_BEING_IMPORTED$VmName>>>   rhel_Vsp-4.4.0.GA-53>]',>>>  sharedLocks='null'}'>>>  2016-12-12 16:55:20,326 WARN>>>  [org.ovirt.engine.core.dal.job.ExecutionMessageDirector]>>>  (org.ovirt.thread.pool-6-thread-35) [6179021a] The message key>>>  'ImportVmFromOva' is missing from 'bundles/ExecutionMessages'>>>  ...>>>  2016-12-12 16:57:34,758 INFO>>>  [org.ovirt.engine.core.bll.exportimport.ConvertVmCallback]>>>  (DefaultQuartzScheduler4) [27df05b8] Conversion of VM from exteral>>>  

Re: [ovirt-users] How can I import VMWare OVA file to oVirt 4.0?

2016-12-12 Thread aleksey . maksimov
 All my Data-Domains - FC SAN. Not ISCSI.  13.12.2016, 09:41, "Shahar Havivi" :What is the type of the target storage domain that you try to import to?(nfs or iscsi)if its iscsi try to change it to preallocate instead of thin-provision,also please attach the engine log if you have more problems.  Shahar. On Tue, Dec 13, 2016 at 7:08 AM,  wrote:# LIBGUESTFS_BACKEND=direct virt-v2v -v -x -i ova /tmp/rhel_Vsp-4.4.0.GA-53.ova -of raw -o nullfsync /dev/sdaguestfsd: main_loop: proc 282 (internal_autosync) took 0.01 secondslibguestfs: trace: internal_autosync = 0libguestfs: sending SIGTERM to process 3338libguestfs: trace: shutdown = 0libguestfs: trace: closelibguestfs: closing guestfs handle 0x2880a10 (state 0)libguestfs: command: run: rmlibguestfs: command: run: \ -rf /tmp/libguestfsrxuByo[  99.0] Checking if the guest needs BIOS or UEFI to boot[  99.0] Copying disk 1/1 to /var/tmp/null.lP6vGa/sda (raw)target_file = /var/tmp/null.lP6vGa/sdatarget_format = rawtarget_estimated_size = 13480052354target_overlay = /var/tmp/v2vovle81937.qcow2target_overlay.ov_source = /var/tmp/ova.zJ6ks8/rhel_Vsp-4.4.0.GA-53-disk1.vmdkqemu-img convert -p -n -f qcow2 -O 'raw' '/var/tmp/v2vovle81937.qcow2' '/var/tmp/null.lP6vGa/sda'    (100.00/100%)virtual copying rate: 95364.1 M bits/secreal copying rate: 811.7 M bits/secsda: estimate 13480052354 (12.6G) versus actual 2339610624 (2.2G): 476.2%[ 126.0] Creating output metadata[ 126.0] Finishing offThe output is very voluminous. Errors are seen.13.12.2016, 07:59, "aleksey.maksi...@it-kb.ru" :> -bash: annotate-output: command not found>> 12.12.2016, 21:26, "Derek Atkins" :>>  Hi,  What happened when you ran the virt-v2v command I suggested?  -derek  On Mon, December 12, 2016 12:32 pm, aleksey.maksi...@it-kb.ru wrote:>>>   I mount 5TB nfs-share to my host and tried to import OVA from this>>>   mount-point.>>>   Exact same error.>>   Do the import process attempts to use 256G inside the Engine virtual>>>   machine ???>>   12.12.2016, 18:01, "aleksey.maksi...@it-kb.ru">>>   :   1.2G is real OVA image size.   256G is virtual disk size.   Could this be a problem?   But before I start the import, in the settings I choose "Thin provision"   (see the attached screenshot)   12.12.2016, 17:47, "aleksey.maksi...@it-kb.ru"   :>    Hi Derek>>    # df -H /tmp/>>    Filesystem Size Used Avail Use% Mounted on>    /dev/cciss/c0d0p2 53G 5.7G 45G 12% />>    But my OVA file size - 1.2G>>    12.12.2016, 17:26, "Derek Atkins" :>> Hi, Did you perhaps run out of disk space in /tmp? I'm not sure where>>   the>> virt-v2v does it work, but the error "Conversion of VM from exteral>> enironment failed: copy-disk stream closed unexpectedly" seems to>>   imply an>> error there. I had no issues myself on 4.0.5 (modulo setfiles taking a very long>>   time>> in a few cases). -derek On Mon, December 12, 2016 9:19 am, aleksey.maksi...@it-kb.ru wrote:>>>  Hello oVirt guru`s!>>  In the process of importing from OVA file (from>>>  /tmp/rhel_Vsp-4.4.0.GA-53.ova in one of hosts) VM first appears in>>>   the web>>>  console, then disappears.>>  In the oVirt Engine log:>>  ...>>>  2016-12-12 16:55:20,209 INFO>>>  [org.ovirt.engine.core.bll.exportimport.ImportVmFromOvaCommand]>>>   (default>>>  task-28) [6179021a] Lock Acquired to object>>>  'EngineLock:{exclusiveLocks='[rhel_Vsp-4.4.0.GA-53=>>  ACTION_TYPE_FAILED_NAME_ALREADY_USED>,>>>  2a3d20f9-502a-4c60-8c14-371456cd4c99=>>  ACTION_TYPE_FAILED_VM_IS_BEING_IMPORTED$VmName>>>   rhel_Vsp-4.4.0.GA-53>]',>>>  sharedLocks='null'}'>>>  2016-12-12 16:55:20,326 WARN>>>  [org.ovirt.engine.core.dal.job.ExecutionMessageDirector]>>>  (org.ovirt.thread.pool-6-thread-35) [6179021a] The message key>>>  'ImportVmFromOva' is missing from 'bundles/ExecutionMessages'>>>  ...>>>  2016-12-12 16:57:34,758 INFO>>>  [org.ovirt.engine.core.bll.exportimport.ConvertVmCallback]>>>  (DefaultQuartzScheduler4) [27df05b8] Conversion of VM from exteral>>>  enironment failed: copy-disk stream closed unexpectedly>>>  2016-12-12 16:57:35,761 ERROR>>>  [org.ovirt.engine.core.bll.exportimport.ConvertOvaCommand]>>>  (DefaultQuartzScheduler8) [77b50303] Ending command>>>  'org.ovirt.engine.core.bll.exportimport.ConvertOvaCommand' with>>>   failure.>>>  2016-12-12 16:57:35,827 INFO>>>  [org.ovirt.engine.core.dal.dbbroker.auditloghandling.AuditLogDirector]>>> 

Re: [ovirt-users] How can I import VMWare OVA file to oVirt 4.0?

2016-12-12 Thread aleksey . maksimov
# LIBGUESTFS_BACKEND=direct virt-v2v -v -x -i ova /tmp/rhel_Vsp-4.4.0.GA-53.ova 
-of raw -o null


fsync /dev/sda
guestfsd: main_loop: proc 282 (internal_autosync) took 0.01 seconds
libguestfs: trace: internal_autosync = 0
libguestfs: sending SIGTERM to process 3338
libguestfs: trace: shutdown = 0
libguestfs: trace: close
libguestfs: closing guestfs handle 0x2880a10 (state 0)
libguestfs: command: run: rm
libguestfs: command: run: \ -rf /tmp/libguestfsrxuByo
[  99.0] Checking if the guest needs BIOS or UEFI to boot
[  99.0] Copying disk 1/1 to /var/tmp/null.lP6vGa/sda (raw)
target_file = /var/tmp/null.lP6vGa/sda
target_format = raw
target_estimated_size = 13480052354
target_overlay = /var/tmp/v2vovle81937.qcow2
target_overlay.ov_source = /var/tmp/ova.zJ6ks8/rhel_Vsp-4.4.0.GA-53-disk1.vmdk
qemu-img convert -p -n -f qcow2 -O 'raw' '/var/tmp/v2vovle81937.qcow2' 
'/var/tmp/null.lP6vGa/sda'
(100.00/100%)
virtual copying rate: 95364.1 M bits/sec
real copying rate: 811.7 M bits/sec
sda: estimate 13480052354 (12.6G) versus actual 2339610624 (2.2G): 476.2%
[ 126.0] Creating output metadata
[ 126.0] Finishing off


The output is very voluminous. Errors are seen.



13.12.2016, 07:59, "aleksey.maksi...@it-kb.ru" :
> -bash: annotate-output: command not found
>
> 12.12.2016, 21:26, "Derek Atkins" :
>>  Hi,
>>
>>  What happened when you ran the virt-v2v command I suggested?
>>
>>  -derek
>>
>>  On Mon, December 12, 2016 12:32 pm, aleksey.maksi...@it-kb.ru wrote:
>>>   I mount 5TB nfs-share to my host and tried to import OVA from this
>>>   mount-point.
>>>   Exact same error.
>>>
>>>   Do the import process attempts to use 256G inside the Engine virtual
>>>   machine ???
>>>
>>>   12.12.2016, 18:01, "aleksey.maksi...@it-kb.ru"
>>>   :
   1.2G is real OVA image size.
   256G is virtual disk size.
   Could this be a problem?

   But before I start the import, in the settings I choose "Thin provision"
   (see the attached screenshot)

   12.12.2016, 17:47, "aleksey.maksi...@it-kb.ru"
   :
>    Hi Derek
>
>    # df -H /tmp/
>
>    Filesystem Size Used Avail Use% Mounted on
>    /dev/cciss/c0d0p2 53G 5.7G 45G 12% /
>
>    But my OVA file size - 1.2G
>
>    12.12.2016, 17:26, "Derek Atkins" :
>> Hi,
>>
>> Did you perhaps run out of disk space in /tmp? I'm not sure where
>>   the
>> virt-v2v does it work, but the error "Conversion of VM from exteral
>> enironment failed: copy-disk stream closed unexpectedly" seems to
>>   imply an
>> error there.
>>
>> I had no issues myself on 4.0.5 (modulo setfiles taking a very long
>>   time
>> in a few cases).
>>
>> -derek
>>
>> On Mon, December 12, 2016 9:19 am, aleksey.maksi...@it-kb.ru wrote:
>>>  Hello oVirt guru`s!
>>>
>>>  In the process of importing from OVA file (from
>>>  /tmp/rhel_Vsp-4.4.0.GA-53.ova in one of hosts) VM first appears in
>>>   the web
>>>  console, then disappears.
>>>
>>>  In the oVirt Engine log:
>>>
>>>  ...
>>>  2016-12-12 16:55:20,209 INFO
>>>  [org.ovirt.engine.core.bll.exportimport.ImportVmFromOvaCommand]
>>>   (default
>>>  task-28) [6179021a] Lock Acquired to object
>>>  'EngineLock:{exclusiveLocks='[rhel_Vsp-4.4.0.GA-53=>>  ACTION_TYPE_FAILED_NAME_ALREADY_USED>,
>>>  2a3d20f9-502a-4c60-8c14-371456cd4c99=>>  ACTION_TYPE_FAILED_VM_IS_BEING_IMPORTED$VmName
>>>   rhel_Vsp-4.4.0.GA-53>]',
>>>  sharedLocks='null'}'
>>>  2016-12-12 16:55:20,326 WARN
>>>  [org.ovirt.engine.core.dal.job.ExecutionMessageDirector]
>>>  (org.ovirt.thread.pool-6-thread-35) [6179021a] The message key
>>>  'ImportVmFromOva' is missing from 'bundles/ExecutionMessages'
>>>  ...
>>>  2016-12-12 16:57:34,758 INFO
>>>  [org.ovirt.engine.core.bll.exportimport.ConvertVmCallback]
>>>  (DefaultQuartzScheduler4) [27df05b8] Conversion of VM from exteral
>>>  enironment failed: copy-disk stream closed unexpectedly
>>>  2016-12-12 16:57:35,761 ERROR
>>>  [org.ovirt.engine.core.bll.exportimport.ConvertOvaCommand]
>>>  (DefaultQuartzScheduler8) [77b50303] Ending command
>>>  'org.ovirt.engine.core.bll.exportimport.ConvertOvaCommand' with
>>>   failure.
>>>  2016-12-12 16:57:35,827 INFO
>>>  
>>> [org.ovirt.engine.core.dal.dbbroker.auditloghandling.AuditLogDirector]
>>>  (DefaultQuartzScheduler8) [77b50303] Correlation ID: 3187db75,
>>>   Call Stack:
>>>  null, Custom Event ID: -1, Message: Failed to convert Vm
>>>  rhel_Vsp-4.4.0.GA-53
>>>  ...
>>>  2016-12-12 16:57:38,458 INFO
>>>   

Re: [ovirt-users] How can I import VMWare OVA file to oVirt 4.0?

2016-12-12 Thread aleksey . maksimov
-bash: annotate-output: command not found


12.12.2016, 21:26, "Derek Atkins" :
> Hi,
>
> What happened when you ran the virt-v2v command I suggested?
>
> -derek
>
> On Mon, December 12, 2016 12:32 pm, aleksey.maksi...@it-kb.ru wrote:
>>  I mount 5TB nfs-share to my host and tried to import OVA from this
>>  mount-point.
>>  Exact same error.
>>
>>  Do the import process attempts to use 256G inside the Engine virtual
>>  machine ???
>>
>>  12.12.2016, 18:01, "aleksey.maksi...@it-kb.ru"
>>  :
>>>  1.2G is real OVA image size.
>>>  256G is virtual disk size.
>>>  Could this be a problem?
>>>
>>>  But before I start the import, in the settings I choose "Thin provision"
>>>  (see the attached screenshot)
>>>
>>>  12.12.2016, 17:47, "aleksey.maksi...@it-kb.ru"
>>>  :
   Hi Derek

   # df -H /tmp/

   Filesystem Size Used Avail Use% Mounted on
   /dev/cciss/c0d0p2 53G 5.7G 45G 12% /

   But my OVA file size - 1.2G

   12.12.2016, 17:26, "Derek Atkins" :
>    Hi,
>
>    Did you perhaps run out of disk space in /tmp? I'm not sure where
>  the
>    virt-v2v does it work, but the error "Conversion of VM from exteral
>    enironment failed: copy-disk stream closed unexpectedly" seems to
>  imply an
>    error there.
>
>    I had no issues myself on 4.0.5 (modulo setfiles taking a very long
>  time
>    in a few cases).
>
>    -derek
>
>    On Mon, December 12, 2016 9:19 am, aleksey.maksi...@it-kb.ru wrote:
>> Hello oVirt guru`s!
>>
>> In the process of importing from OVA file (from
>> /tmp/rhel_Vsp-4.4.0.GA-53.ova in one of hosts) VM first appears in
>>  the web
>> console, then disappears.
>>
>> In the oVirt Engine log:
>>
>> ...
>> 2016-12-12 16:55:20,209 INFO
>> [org.ovirt.engine.core.bll.exportimport.ImportVmFromOvaCommand]
>>  (default
>> task-28) [6179021a] Lock Acquired to object
>> 'EngineLock:{exclusiveLocks='[rhel_Vsp-4.4.0.GA-53=> ACTION_TYPE_FAILED_NAME_ALREADY_USED>,
>> 2a3d20f9-502a-4c60-8c14-371456cd4c99=> ACTION_TYPE_FAILED_VM_IS_BEING_IMPORTED$VmName
>>  rhel_Vsp-4.4.0.GA-53>]',
>> sharedLocks='null'}'
>> 2016-12-12 16:55:20,326 WARN
>> [org.ovirt.engine.core.dal.job.ExecutionMessageDirector]
>> (org.ovirt.thread.pool-6-thread-35) [6179021a] The message key
>> 'ImportVmFromOva' is missing from 'bundles/ExecutionMessages'
>> ...
>> 2016-12-12 16:57:34,758 INFO
>> [org.ovirt.engine.core.bll.exportimport.ConvertVmCallback]
>> (DefaultQuartzScheduler4) [27df05b8] Conversion of VM from exteral
>> enironment failed: copy-disk stream closed unexpectedly
>> 2016-12-12 16:57:35,761 ERROR
>> [org.ovirt.engine.core.bll.exportimport.ConvertOvaCommand]
>> (DefaultQuartzScheduler8) [77b50303] Ending command
>> 'org.ovirt.engine.core.bll.exportimport.ConvertOvaCommand' with
>>  failure.
>> 2016-12-12 16:57:35,827 INFO
>> 
>> [org.ovirt.engine.core.dal.dbbroker.auditloghandling.AuditLogDirector]
>> (DefaultQuartzScheduler8) [77b50303] Correlation ID: 3187db75,
>>  Call Stack:
>> null, Custom Event ID: -1, Message: Failed to convert Vm
>> rhel_Vsp-4.4.0.GA-53
>> ...
>> 2016-12-12 16:57:38,458 INFO
>> [org.ovirt.engine.core.vdsbroker.vdsbroker.DeleteV2VJobVDSCommand]
>> (DefaultQuartzScheduler8) [5237b44a] FINISH,
>>  DeleteV2VJobVDSCommand, log
>> id: 1a69f33d
>> 2016-12-12 16:57:38,459 WARN
>> [org.ovirt.engine.core.bll.lock.InMemoryLockManager]
>> (DefaultQuartzScheduler8) [5237b44a] Trying to release exclusive
>>  lock
>> which does not exist, lock key:
>>  '2a3d20f9-502a-4c60-8c14-371456cd4c99VM'
>> 2016-12-12 16:57:38,459 INFO
>> [org.ovirt.engine.core.bll.exportimport.ConvertOvaCommand]
>> (DefaultQuartzScheduler8) [5237b44a] Lock freed to object
>> 
>> 'EngineLock:{exclusiveLocks='[2a3d20f9-502a-4c60-8c14-371456cd4c99=> ACTION_TYPE_FAILED_VM_IS_BEING_IMPORTED$VmName
>>  rhel_Vsp-4.4.0.GA-53>]',
>> sharedLocks='null'}'
>> 2016-12-12 16:57:38,463 ERROR
>> 
>> [org.ovirt.engine.core.dal.dbbroker.auditloghandling.AuditLogDirector]
>> (DefaultQuartzScheduler8) [5237b44a] Correlation ID: 3187db75,
>>  Call Stack:
>> null, Custom Event ID: -1, Message: Failed to import Vm
>> rhel_Vsp-4.4.0.GA-53 to Data Center Default, Cluster Default
>>
>> What could be the problem?
>> ___
>> Users mailing list
>> Users@ovirt.org
>> 

Re: [ovirt-users] How can I import VMWare OVA file to oVirt 4.0?

2016-12-12 Thread aleksey . maksimov
I mount 5TB nfs-share to my host and tried to import OVA from this mount-point.
Exact same error.

Do the import process attempts to use 256G inside the Engine virtual machine ???

12.12.2016, 18:01, "aleksey.maksi...@it-kb.ru" :
> 1.2G is real OVA image size.
> 256G is virtual disk size.
> Could this be a problem?
>
> But before I start the import, in the settings I choose "Thin provision" (see 
> the attached screenshot)
>
> 12.12.2016, 17:47, "aleksey.maksi...@it-kb.ru" :
>>  Hi Derek
>>
>>  # df -H /tmp/
>>
>>  Filesystem Size Used Avail Use% Mounted on
>>  /dev/cciss/c0d0p2 53G 5.7G 45G 12% /
>>
>>  But my OVA file size - 1.2G
>>
>>  12.12.2016, 17:26, "Derek Atkins" :
>>>   Hi,
>>>
>>>   Did you perhaps run out of disk space in /tmp? I'm not sure where the
>>>   virt-v2v does it work, but the error "Conversion of VM from exteral
>>>   enironment failed: copy-disk stream closed unexpectedly" seems to imply an
>>>   error there.
>>>
>>>   I had no issues myself on 4.0.5 (modulo setfiles taking a very long time
>>>   in a few cases).
>>>
>>>   -derek
>>>
>>>   On Mon, December 12, 2016 9:19 am, aleksey.maksi...@it-kb.ru wrote:
    Hello oVirt guru`s!

    In the process of importing from OVA file (from
    /tmp/rhel_Vsp-4.4.0.GA-53.ova in one of hosts) VM first appears in the 
 web
    console, then disappears.

    In the oVirt Engine log:

    ...
    2016-12-12 16:55:20,209 INFO
    [org.ovirt.engine.core.bll.exportimport.ImportVmFromOvaCommand] (default
    task-28) [6179021a] Lock Acquired to object
    'EngineLock:{exclusiveLocks='[rhel_Vsp-4.4.0.GA-53=,
    2a3d20f9-502a-4c60-8c14-371456cd4c99=]',
    sharedLocks='null'}'
    2016-12-12 16:55:20,326 WARN
    [org.ovirt.engine.core.dal.job.ExecutionMessageDirector]
    (org.ovirt.thread.pool-6-thread-35) [6179021a] The message key
    'ImportVmFromOva' is missing from 'bundles/ExecutionMessages'
    ...
    2016-12-12 16:57:34,758 INFO
    [org.ovirt.engine.core.bll.exportimport.ConvertVmCallback]
    (DefaultQuartzScheduler4) [27df05b8] Conversion of VM from exteral
    enironment failed: copy-disk stream closed unexpectedly
    2016-12-12 16:57:35,761 ERROR
    [org.ovirt.engine.core.bll.exportimport.ConvertOvaCommand]
    (DefaultQuartzScheduler8) [77b50303] Ending command
    'org.ovirt.engine.core.bll.exportimport.ConvertOvaCommand' with failure.
    2016-12-12 16:57:35,827 INFO
    [org.ovirt.engine.core.dal.dbbroker.auditloghandling.AuditLogDirector]
    (DefaultQuartzScheduler8) [77b50303] Correlation ID: 3187db75, Call 
 Stack:
    null, Custom Event ID: -1, Message: Failed to convert Vm
    rhel_Vsp-4.4.0.GA-53
    ...
    2016-12-12 16:57:38,458 INFO
    [org.ovirt.engine.core.vdsbroker.vdsbroker.DeleteV2VJobVDSCommand]
    (DefaultQuartzScheduler8) [5237b44a] FINISH, DeleteV2VJobVDSCommand, log
    id: 1a69f33d
    2016-12-12 16:57:38,459 WARN
    [org.ovirt.engine.core.bll.lock.InMemoryLockManager]
    (DefaultQuartzScheduler8) [5237b44a] Trying to release exclusive lock
    which does not exist, lock key: '2a3d20f9-502a-4c60-8c14-371456cd4c99VM'
    2016-12-12 16:57:38,459 INFO
    [org.ovirt.engine.core.bll.exportimport.ConvertOvaCommand]
    (DefaultQuartzScheduler8) [5237b44a] Lock freed to object
    'EngineLock:{exclusiveLocks='[2a3d20f9-502a-4c60-8c14-371456cd4c99=]',
    sharedLocks='null'}'
    2016-12-12 16:57:38,463 ERROR
    [org.ovirt.engine.core.dal.dbbroker.auditloghandling.AuditLogDirector]
    (DefaultQuartzScheduler8) [5237b44a] Correlation ID: 3187db75, Call 
 Stack:
    null, Custom Event ID: -1, Message: Failed to import Vm
    rhel_Vsp-4.4.0.GA-53 to Data Center Default, Cluster Default

    What could be the problem?
    ___
    Users mailing list
    Users@ovirt.org
    http://lists.phx.ovirt.org/mailman/listinfo/users
>>>
>>>   --
>>>  Derek Atkins 617-623-3745
>>>  de...@ihtfp.com www.ihtfp.com
>>>  Computer and Internet Security Consultant
___
Users mailing list
Users@ovirt.org
http://lists.phx.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] How can I import VMWare OVA file to oVirt 4.0?

2016-12-12 Thread aleksey . maksimov
1.2G is real OVA image size. 
256G is virtual disk size.
Could this be a problem?

But before I start the import, in the settings I choose "Thin provision" (see 
the attached screenshot)


12.12.2016, 17:47, "aleksey.maksi...@it-kb.ru" :
> Hi Derek
>
> # df -H /tmp/
>
> Filesystem Size Used Avail Use% Mounted on
> /dev/cciss/c0d0p2 53G 5.7G 45G 12% /
>
> But my OVA file size - 1.2G
>
> 12.12.2016, 17:26, "Derek Atkins" :
>>  Hi,
>>
>>  Did you perhaps run out of disk space in /tmp? I'm not sure where the
>>  virt-v2v does it work, but the error "Conversion of VM from exteral
>>  enironment failed: copy-disk stream closed unexpectedly" seems to imply an
>>  error there.
>>
>>  I had no issues myself on 4.0.5 (modulo setfiles taking a very long time
>>  in a few cases).
>>
>>  -derek
>>
>>  On Mon, December 12, 2016 9:19 am, aleksey.maksi...@it-kb.ru wrote:
>>>   Hello oVirt guru`s!
>>>
>>>   In the process of importing from OVA file (from
>>>   /tmp/rhel_Vsp-4.4.0.GA-53.ova in one of hosts) VM first appears in the web
>>>   console, then disappears.
>>>
>>>   In the oVirt Engine log:
>>>
>>>   ...
>>>   2016-12-12 16:55:20,209 INFO
>>>   [org.ovirt.engine.core.bll.exportimport.ImportVmFromOvaCommand] (default
>>>   task-28) [6179021a] Lock Acquired to object
>>>   'EngineLock:{exclusiveLocks='[rhel_Vsp-4.4.0.GA-53=>>   ACTION_TYPE_FAILED_NAME_ALREADY_USED>,
>>>   2a3d20f9-502a-4c60-8c14-371456cd4c99=>>   ACTION_TYPE_FAILED_VM_IS_BEING_IMPORTED$VmName rhel_Vsp-4.4.0.GA-53>]',
>>>   sharedLocks='null'}'
>>>   2016-12-12 16:55:20,326 WARN
>>>   [org.ovirt.engine.core.dal.job.ExecutionMessageDirector]
>>>   (org.ovirt.thread.pool-6-thread-35) [6179021a] The message key
>>>   'ImportVmFromOva' is missing from 'bundles/ExecutionMessages'
>>>   ...
>>>   2016-12-12 16:57:34,758 INFO
>>>   [org.ovirt.engine.core.bll.exportimport.ConvertVmCallback]
>>>   (DefaultQuartzScheduler4) [27df05b8] Conversion of VM from exteral
>>>   enironment failed: copy-disk stream closed unexpectedly
>>>   2016-12-12 16:57:35,761 ERROR
>>>   [org.ovirt.engine.core.bll.exportimport.ConvertOvaCommand]
>>>   (DefaultQuartzScheduler8) [77b50303] Ending command
>>>   'org.ovirt.engine.core.bll.exportimport.ConvertOvaCommand' with failure.
>>>   2016-12-12 16:57:35,827 INFO
>>>   [org.ovirt.engine.core.dal.dbbroker.auditloghandling.AuditLogDirector]
>>>   (DefaultQuartzScheduler8) [77b50303] Correlation ID: 3187db75, Call Stack:
>>>   null, Custom Event ID: -1, Message: Failed to convert Vm
>>>   rhel_Vsp-4.4.0.GA-53
>>>   ...
>>>   2016-12-12 16:57:38,458 INFO
>>>   [org.ovirt.engine.core.vdsbroker.vdsbroker.DeleteV2VJobVDSCommand]
>>>   (DefaultQuartzScheduler8) [5237b44a] FINISH, DeleteV2VJobVDSCommand, log
>>>   id: 1a69f33d
>>>   2016-12-12 16:57:38,459 WARN
>>>   [org.ovirt.engine.core.bll.lock.InMemoryLockManager]
>>>   (DefaultQuartzScheduler8) [5237b44a] Trying to release exclusive lock
>>>   which does not exist, lock key: '2a3d20f9-502a-4c60-8c14-371456cd4c99VM'
>>>   2016-12-12 16:57:38,459 INFO
>>>   [org.ovirt.engine.core.bll.exportimport.ConvertOvaCommand]
>>>   (DefaultQuartzScheduler8) [5237b44a] Lock freed to object
>>>   'EngineLock:{exclusiveLocks='[2a3d20f9-502a-4c60-8c14-371456cd4c99=>>   ACTION_TYPE_FAILED_VM_IS_BEING_IMPORTED$VmName rhel_Vsp-4.4.0.GA-53>]',
>>>   sharedLocks='null'}'
>>>   2016-12-12 16:57:38,463 ERROR
>>>   [org.ovirt.engine.core.dal.dbbroker.auditloghandling.AuditLogDirector]
>>>   (DefaultQuartzScheduler8) [5237b44a] Correlation ID: 3187db75, Call Stack:
>>>   null, Custom Event ID: -1, Message: Failed to import Vm
>>>   rhel_Vsp-4.4.0.GA-53 to Data Center Default, Cluster Default
>>>
>>>   What could be the problem?
>>>   ___
>>>   Users mailing list
>>>   Users@ovirt.org
>>>   http://lists.phx.ovirt.org/mailman/listinfo/users
>>
>>  --
>> Derek Atkins 617-623-3745
>> de...@ihtfp.com www.ihtfp.com
>> Computer and Internet Security Consultant___
Users mailing list
Users@ovirt.org
http://lists.phx.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] How can I import VMWare OVA file to oVirt 4.0?

2016-12-12 Thread aleksey . maksimov

Hi Derek

# df -H /tmp/

Filesystem  Size  Used Avail Use% Mounted on
/dev/cciss/c0d0p2   53G  5.7G   45G  12% /

But my OVA file size - 1.2G

12.12.2016, 17:26, "Derek Atkins" :
> Hi,
>
> Did you perhaps run out of disk space in /tmp? I'm not sure where the
> virt-v2v does it work, but the error "Conversion of VM from exteral
> enironment failed: copy-disk stream closed unexpectedly" seems to imply an
> error there.
>
> I had no issues myself on 4.0.5 (modulo setfiles taking a very long time
> in a few cases).
>
> -derek
>
> On Mon, December 12, 2016 9:19 am, aleksey.maksi...@it-kb.ru wrote:
>>  Hello oVirt guru`s!
>>
>>  In the process of importing from OVA file (from
>>  /tmp/rhel_Vsp-4.4.0.GA-53.ova in one of hosts) VM first appears in the web
>>  console, then disappears.
>>
>>  In the oVirt Engine log:
>>
>>  ...
>>  2016-12-12 16:55:20,209 INFO
>>  [org.ovirt.engine.core.bll.exportimport.ImportVmFromOvaCommand] (default
>>  task-28) [6179021a] Lock Acquired to object
>>  'EngineLock:{exclusiveLocks='[rhel_Vsp-4.4.0.GA-53=>  ACTION_TYPE_FAILED_NAME_ALREADY_USED>,
>>  2a3d20f9-502a-4c60-8c14-371456cd4c99=>  ACTION_TYPE_FAILED_VM_IS_BEING_IMPORTED$VmName rhel_Vsp-4.4.0.GA-53>]',
>>  sharedLocks='null'}'
>>  2016-12-12 16:55:20,326 WARN
>>  [org.ovirt.engine.core.dal.job.ExecutionMessageDirector]
>>  (org.ovirt.thread.pool-6-thread-35) [6179021a] The message key
>>  'ImportVmFromOva' is missing from 'bundles/ExecutionMessages'
>>  ...
>>  2016-12-12 16:57:34,758 INFO
>>  [org.ovirt.engine.core.bll.exportimport.ConvertVmCallback]
>>  (DefaultQuartzScheduler4) [27df05b8] Conversion of VM from exteral
>>  enironment failed: copy-disk stream closed unexpectedly
>>  2016-12-12 16:57:35,761 ERROR
>>  [org.ovirt.engine.core.bll.exportimport.ConvertOvaCommand]
>>  (DefaultQuartzScheduler8) [77b50303] Ending command
>>  'org.ovirt.engine.core.bll.exportimport.ConvertOvaCommand' with failure.
>>  2016-12-12 16:57:35,827 INFO
>>  [org.ovirt.engine.core.dal.dbbroker.auditloghandling.AuditLogDirector]
>>  (DefaultQuartzScheduler8) [77b50303] Correlation ID: 3187db75, Call Stack:
>>  null, Custom Event ID: -1, Message: Failed to convert Vm
>>  rhel_Vsp-4.4.0.GA-53
>>  ...
>>  2016-12-12 16:57:38,458 INFO
>>  [org.ovirt.engine.core.vdsbroker.vdsbroker.DeleteV2VJobVDSCommand]
>>  (DefaultQuartzScheduler8) [5237b44a] FINISH, DeleteV2VJobVDSCommand, log
>>  id: 1a69f33d
>>  2016-12-12 16:57:38,459 WARN
>>  [org.ovirt.engine.core.bll.lock.InMemoryLockManager]
>>  (DefaultQuartzScheduler8) [5237b44a] Trying to release exclusive lock
>>  which does not exist, lock key: '2a3d20f9-502a-4c60-8c14-371456cd4c99VM'
>>  2016-12-12 16:57:38,459 INFO
>>  [org.ovirt.engine.core.bll.exportimport.ConvertOvaCommand]
>>  (DefaultQuartzScheduler8) [5237b44a] Lock freed to object
>>  'EngineLock:{exclusiveLocks='[2a3d20f9-502a-4c60-8c14-371456cd4c99=>  ACTION_TYPE_FAILED_VM_IS_BEING_IMPORTED$VmName rhel_Vsp-4.4.0.GA-53>]',
>>  sharedLocks='null'}'
>>  2016-12-12 16:57:38,463 ERROR
>>  [org.ovirt.engine.core.dal.dbbroker.auditloghandling.AuditLogDirector]
>>  (DefaultQuartzScheduler8) [5237b44a] Correlation ID: 3187db75, Call Stack:
>>  null, Custom Event ID: -1, Message: Failed to import Vm
>>  rhel_Vsp-4.4.0.GA-53 to Data Center Default, Cluster Default
>>
>>  What could be the problem?
>>  ___
>>  Users mailing list
>>  Users@ovirt.org
>>  http://lists.phx.ovirt.org/mailman/listinfo/users
>
> --
>    Derek Atkins 617-623-3745
>    de...@ihtfp.com www.ihtfp.com
>    Computer and Internet Security Consultant
___
Users mailing list
Users@ovirt.org
http://lists.phx.ovirt.org/mailman/listinfo/users


[ovirt-users] How can I import VMWare OVA file to oVirt 4.0?

2016-12-12 Thread aleksey . maksimov


Hello oVirt guru`s!

In the process of importing from OVA file (from /tmp/rhel_Vsp-4.4.0.GA-53.ova 
in one of hosts) VM first appears in the web console, then disappears.

In the oVirt Engine log:


...
2016-12-12 16:55:20,209 INFO  
[org.ovirt.engine.core.bll.exportimport.ImportVmFromOvaCommand] (default 
task-28) [6179021a] Lock Acquired to object 
'EngineLock:{exclusiveLocks='[rhel_Vsp-4.4.0.GA-53=, 
2a3d20f9-502a-4c60-8c14-371456cd4c99=]', 
sharedLocks='null'}'
2016-12-12 16:55:20,326 WARN  
[org.ovirt.engine.core.dal.job.ExecutionMessageDirector] 
(org.ovirt.thread.pool-6-thread-35) [6179021a] The message key 
'ImportVmFromOva' is missing from 'bundles/ExecutionMessages'
...
2016-12-12 16:57:34,758 INFO  
[org.ovirt.engine.core.bll.exportimport.ConvertVmCallback] 
(DefaultQuartzScheduler4) [27df05b8] Conversion of VM from exteral enironment 
failed: copy-disk stream closed unexpectedly
2016-12-12 16:57:35,761 ERROR 
[org.ovirt.engine.core.bll.exportimport.ConvertOvaCommand] 
(DefaultQuartzScheduler8) [77b50303] Ending command 
'org.ovirt.engine.core.bll.exportimport.ConvertOvaCommand' with failure.
2016-12-12 16:57:35,827 INFO  
[org.ovirt.engine.core.dal.dbbroker.auditloghandling.AuditLogDirector] 
(DefaultQuartzScheduler8) [77b50303] Correlation ID: 3187db75, Call Stack: 
null, Custom Event ID: -1, Message: Failed to convert Vm rhel_Vsp-4.4.0.GA-53
...
2016-12-12 16:57:38,458 INFO  
[org.ovirt.engine.core.vdsbroker.vdsbroker.DeleteV2VJobVDSCommand] 
(DefaultQuartzScheduler8) [5237b44a] FINISH, DeleteV2VJobVDSCommand, log id: 
1a69f33d
2016-12-12 16:57:38,459 WARN  
[org.ovirt.engine.core.bll.lock.InMemoryLockManager] (DefaultQuartzScheduler8) 
[5237b44a] Trying to release exclusive lock which does not exist, lock key: 
'2a3d20f9-502a-4c60-8c14-371456cd4c99VM'
2016-12-12 16:57:38,459 INFO  
[org.ovirt.engine.core.bll.exportimport.ConvertOvaCommand] 
(DefaultQuartzScheduler8) [5237b44a] Lock freed to object 
'EngineLock:{exclusiveLocks='[2a3d20f9-502a-4c60-8c14-371456cd4c99=]', 
sharedLocks='null'}'
2016-12-12 16:57:38,463 ERROR 
[org.ovirt.engine.core.dal.dbbroker.auditloghandling.AuditLogDirector] 
(DefaultQuartzScheduler8) [5237b44a] Correlation ID: 3187db75, Call Stack: 
null, Custom Event ID: -1, Message: Failed to import Vm rhel_Vsp-4.4.0.GA-53 to 
Data Center Default, Cluster Default

What could be the problem?
___
Users mailing list
Users@ovirt.org
http://lists.phx.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] How to notify cluster nodes after "engine-config --set IPTablesConfigSiteCustom..." ?

2016-11-24 Thread aleksey . maksimov
Thank you Didi. 

The proposed method works.
I described my experience here:
https://blog.it-kb.ru/2016/11/24/extension-of-iptables-add-custom-rules-on-the-ovirt-4-0-hosts/

23.11.2016, 16:12, "Yedidyah Bar David" :
> On Wed, Nov 23, 2016 at 1:54 PM,  wrote:
>>  "As I wrote there, you can also do this manually"
>>
>>  How?
>
> I am not sure I understand the question.
>
> The same way you configure iptables on non-oVirt-hosts machines.
>
> If you mean "How to imitate the way the engine does this during
> host deploy", then I don't know - you can check engine sources
> for that. I am guessing that you can get the values of IPTablesConfig
> and IPTablesConfigSiteCustom with engine-config, replace inside the
> latter "@CUSTOM_RULES@" with the contents of the former, then copy
> the result to the host and load it with iptables-restore (and/or
> copy to /etc/sysconfig/iptables and restart iptables service).
>
>>  23.11.2016, 14:23, "Yedidyah Bar David" :
>>>  On Wed, Nov 23, 2016 at 12:51 PM,  wrote:
   Hi Didi!

   https://www.mail-archive.com/users@ovirt.org/msg37193.html

   "Move to maintenance and reinstall" to add the iptables rules ?

   Are you serious?

   There is no other way (without reinstalling the hosts) ?
>>>
>>>  AFAIK, using ovirt-host-deploy, no.
>>>
>>>  I am not aware of an engine API or vdsm verb to do this, but these are
>>>  not my main area of expertise.
>>>
>>>  As I wrote there, you can also do this manually.
>>>
>>>  The oVirt engine is not a replacement for configuration management
>>>  systems. If you have complex needs, might as well uncheck this
>>>  checkbox and use other means.
>>>
>>>  Best,
>>>
   23.11.2016, 13:07, "Yedidyah Bar David" :
>   On Wed, Nov 23, 2016 at 12:02 PM,  wrote:
>>    Hmm. I just rebooted the host, but the iptables rules have not been 
>> updated :(
>>
>>    On Engine server my custom iptables rules are visible:
>>
>>    # engine-config --get IPTablesConfigSiteCustom
>>
>>    IPTablesConfigSiteCustom:
>>    -A INPUT -p tcp --dport 2301 -j ACCEPT -m comment --comment 'HPE 
>> System Management Homepage'
>>    -A INPUT -p tcp --dport 2381 -j ACCEPT -m comment --comment 'HPE 
>> System Management Homepage (Secure port)'
>> version: general
>>
>>    How to update the configuration on the hosts ?
>>
>>    23.11.2016, 11:30, "aleksey.maksi...@it-kb.ru" 
>> :
>>>    Hello oVirt guru`s !
>>>
>>>    oVirt Engine Version: 4.0.5.5-1.el7.centos
>>>
>>>    I updated the configuration of the firewall on the Engine server 
>>> with "engine-config --set IPTablesConfigSiteCustom...".
>>>    How to notify cluster nodes (all virtualization hosts) about the 
>>> changes without reboot?
>
>   Please check the other thread here "[ovirt-users] Hook to add firewall
>   rules". Thanks.
>
>>    ___
>>    Users mailing list
>>    Users@ovirt.org
>>    http://lists.ovirt.org/mailman/listinfo/users
>
>   --
>   Didi
>>>
>>>  --
>>>  Didi
>
> --
> Didi
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] How to notify cluster nodes after "engine-config --set IPTablesConfigSiteCustom..." ?

2016-11-23 Thread aleksey . maksimov
"As I wrote there, you can also do this manually"

How?

23.11.2016, 14:23, "Yedidyah Bar David" :
> On Wed, Nov 23, 2016 at 12:51 PM,  wrote:
>>  Hi Didi!
>>
>>  https://www.mail-archive.com/users@ovirt.org/msg37193.html
>>
>>  "Move to maintenance and reinstall" to add the iptables rules ?
>>
>>  Are you serious?
>>
>>  There is no other way (without reinstalling the hosts) ?
>
> AFAIK, using ovirt-host-deploy, no.
>
> I am not aware of an engine API or vdsm verb to do this, but these are
> not my main area of expertise.
>
> As I wrote there, you can also do this manually.
>
> The oVirt engine is not a replacement for configuration management
> systems. If you have complex needs, might as well uncheck this
> checkbox and use other means.
>
> Best,
>
>>  23.11.2016, 13:07, "Yedidyah Bar David" :
>>>  On Wed, Nov 23, 2016 at 12:02 PM,  wrote:
   Hmm. I just rebooted the host, but the iptables rules have not been 
 updated :(

   On Engine server my custom iptables rules are visible:

   # engine-config --get IPTablesConfigSiteCustom

   IPTablesConfigSiteCustom:
   -A INPUT -p tcp --dport 2301 -j ACCEPT -m comment --comment 'HPE System 
 Management Homepage'
   -A INPUT -p tcp --dport 2381 -j ACCEPT -m comment --comment 'HPE System 
 Management Homepage (Secure port)'
    version: general

   How to update the configuration on the hosts ?

   23.11.2016, 11:30, "aleksey.maksi...@it-kb.ru" 
 :
>   Hello oVirt guru`s !
>
>   oVirt Engine Version: 4.0.5.5-1.el7.centos
>
>   I updated the configuration of the firewall on the Engine server with 
> "engine-config --set IPTablesConfigSiteCustom...".
>   How to notify cluster nodes (all virtualization hosts) about the 
> changes without reboot?
>>>
>>>  Please check the other thread here "[ovirt-users] Hook to add firewall
>>>  rules". Thanks.
>>>
   ___
   Users mailing list
   Users@ovirt.org
   http://lists.ovirt.org/mailman/listinfo/users
>>>
>>>  --
>>>  Didi
>
> --
> Didi
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] How to notify cluster nodes after "engine-config --set IPTablesConfigSiteCustom..." ?

2016-11-23 Thread aleksey . maksimov
Hi Didi!

https://www.mail-archive.com/users@ovirt.org/msg37193.html

"Move to maintenance and reinstall" to add the iptables rules ?

Are you serious?

There is no other way (without reinstalling the hosts) ?

23.11.2016, 13:07, "Yedidyah Bar David" :
> On Wed, Nov 23, 2016 at 12:02 PM,  wrote:
>>  Hmm. I just rebooted the host, but the iptables rules have not been updated 
>> :(
>>
>>  On Engine server my custom iptables rules are visible:
>>
>>  # engine-config --get IPTablesConfigSiteCustom
>>
>>  IPTablesConfigSiteCustom:
>>  -A INPUT -p tcp --dport 2301 -j ACCEPT -m comment --comment 'HPE System 
>> Management Homepage'
>>  -A INPUT -p tcp --dport 2381 -j ACCEPT -m comment --comment 'HPE System 
>> Management Homepage (Secure port)'
>>   version: general
>>
>>  How to update the configuration on the hosts ?
>>
>>  23.11.2016, 11:30, "aleksey.maksi...@it-kb.ru" :
>>>  Hello oVirt guru`s !
>>>
>>>  oVirt Engine Version: 4.0.5.5-1.el7.centos
>>>
>>>  I updated the configuration of the firewall on the Engine server with 
>>> "engine-config --set IPTablesConfigSiteCustom...".
>>>  How to notify cluster nodes (all virtualization hosts) about the changes 
>>> without reboot?
>
> Please check the other thread here "[ovirt-users] Hook to add firewall
> rules". Thanks.
>
>>  ___
>>  Users mailing list
>>  Users@ovirt.org
>>  http://lists.ovirt.org/mailman/listinfo/users
>
> --
> Didi
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] How to notify cluster nodes after "engine-config --set IPTablesConfigSiteCustom..." ?

2016-11-23 Thread aleksey . maksimov
Hmm. I just rebooted the host, but the iptables rules have not been updated :(

On Engine server my custom iptables rules are visible:

# engine-config --get IPTablesConfigSiteCustom

IPTablesConfigSiteCustom:
-A INPUT -p tcp --dport 2301 -j ACCEPT -m comment --comment 'HPE System 
Management Homepage'
-A INPUT -p tcp --dport 2381 -j ACCEPT -m comment --comment 'HPE System 
Management Homepage (Secure port)'
 version: general

How to update the configuration on the hosts ?

23.11.2016, 11:30, "aleksey.maksi...@it-kb.ru" :
> Hello oVirt guru`s !
>
> oVirt Engine Version: 4.0.5.5-1.el7.centos
>
> I updated the configuration of the firewall on the Engine server with 
> "engine-config --set IPTablesConfigSiteCustom...".
> How to notify cluster nodes (all virtualization hosts) about the changes 
> without reboot?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] oVirt 4.0 Reporting

2016-10-29 Thread aleksey . maksimov
Hello oVirt guru`s!

In the first half of 2016 was the following information: 
http://lists.ovirt.org/pipermail/users/2016-June/040549.html

Are there any news about the built-in oVirt 4.0 reporting mechanism?
Is there any chance that we will see reports in the oVirt web console?

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Active Directory domain authorization in oVirt Hosted Engine guest OS

2016-10-20 Thread aleksey . maksimov
Thank You for the advice, Karli

Problem solved here: 
https://lists.fedorahosted.org/archives/list/sssd-us...@lists.fedorahosted.org/thread/NDBFLJ774A2TUWC65CHRQ5XVL3DGVMQR/

Again sorry for offtopic

19.10.2016, 15:23, "Karli Sjöberg" :
> On Wed, 2016-10-19 at 13:48 +0300, aleksey.maksi...@it-kb.ru wrote:
>>  Hello oVirt guru`s!
>>
>>  I'm sorry for possible offtopic, but I do not know where to seek
>>  help.
>>
>>  I want to set up Active Directory domain authorization in oVirt
>>  Hosted Engine guest OS.
>>
>>  For this I use SSSD as described here:
>>  https://blog.it-kb.ru/2016/10/15/join-debian-gnu-linux-8-6-to-active-
>>  directory-domain-with-sssd-and-realmd-for-authentication-and-
>>  configure-ad-domain-security-group-authorization-for-sudo-and-ssh-
>>  with-putty-sso/
>
> I used this[*] that worked for me (at least on Ubuntu) yesterday.
> Adjust accordingly for CentOS.
>
> /K
>
> [*] https://help.ubuntu.com/lts/serverguide/sssd-ad.html
>
>>  I attached the computer to the domain using the realm utility.
>>  It looks nice.
>>
>>  [root@KOM-OVIRT1 ~]# realm list
>>  ad.holding.com
>>    type: kerberos
>>    realm-name: AD.HOLDING.COM
>>    domain-name: ad.holding.com
>>    configured: kerberos-member
>>    server-software: active-directory
>>    client-software: sssd
>>    required-package: oddjob
>>    required-package: oddjob-mkhomedir
>>    required-package: sssd
>>    required-package: adcli
>>    required-package: samba-common
>>    login-formats: %u...@ad.holding.com
>>    login-policy: allow-permitted-logins
>>    permitted-logins:
>>    permitted-groups: kom-srv-linux-adm...@ad.holding.com
>>
>>  However, getent does not return information about domain accounts:
>>
>>  [root@KOM-OVIRT1 ~]# getent passwd alek...@ad.holding.com
>>  [root@KOM-OVIRT1 ~]#
>>
>>  getent for local accounts work:
>>
>>  [root@KOM-OVIRT1 ~]# getent passwd root
>>  root:x:0:0:root:/root:/bin/bash
>>
>>  oVirt Hosted Engine guest OS has some tricky authorization settings?
>>  Can you help me?
>>  ___
>>  Users mailing list
>>  Users@ovirt.org
>>  http://lists.ovirt.org/mailman/listinfo/users
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] Active Directory domain authorization in oVirt Hosted Engine guest OS

2016-10-19 Thread aleksey . maksimov
Hello oVirt guru`s!

I'm sorry for possible offtopic, but I do not know where to seek help.

I want to set up Active Directory domain authorization in oVirt Hosted Engine 
guest OS.

For this I use SSSD as described here: 
https://blog.it-kb.ru/2016/10/15/join-debian-gnu-linux-8-6-to-active-directory-domain-with-sssd-and-realmd-for-authentication-and-configure-ad-domain-security-group-authorization-for-sudo-and-ssh-with-putty-sso/

I attached the computer to the domain using the realm utility.
It looks nice.

[root@KOM-OVIRT1 ~]# realm list
ad.holding.com
  type: kerberos
  realm-name: AD.HOLDING.COM
  domain-name: ad.holding.com
  configured: kerberos-member
  server-software: active-directory
  client-software: sssd
  required-package: oddjob
  required-package: oddjob-mkhomedir
  required-package: sssd
  required-package: adcli
  required-package: samba-common
  login-formats: %u...@ad.holding.com
  login-policy: allow-permitted-logins
  permitted-logins:
  permitted-groups: kom-srv-linux-adm...@ad.holding.com

However, getent does not return information about domain accounts:

[root@KOM-OVIRT1 ~]# getent passwd alek...@ad.holding.com
[root@KOM-OVIRT1 ~]# 

getent for local accounts work:

[root@KOM-OVIRT1 ~]# getent passwd root
root:x:0:0:root:/root:/bin/bash

oVirt Hosted Engine guest OS has some tricky authorization settings?
Can you help me?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] RE > Multiple export domains limit?

2016-10-07 Thread aleksey . maksimov
Hello oVirt guru`s!

http://lists.ovirt.org/pipermail/users/2015-November/036056.html

Is there a progress on this issue?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Correct recovery procedure of the oVirt Hosted Engine 4.0

2016-10-06 Thread aleksey . maksimov
Simone, thank you for your work.
We will wait for the updates.

06.10.2016, 09:55, "Simone Tiraboschi" :
> On Thu, Oct 6, 2016 at 7:32 AM,  wrote:
>> Hi Simone.
>> When can we expect a new version of the engine-backup with built-in cleaning 
>> helper?
>
> That bug is targeted to 4.1
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Correct recovery procedure of the oVirt Hosted Engine 4.0

2016-10-05 Thread aleksey . maksimov
Hi Simone. 
When can we expect a new version of the engine-backup with built-in cleaning 
helper?

05.10.2016, 13:52, "Simone Tiraboschi" :
> On Wed, Oct 5, 2016 at 12:40 PM,  wrote:
>> Ouch. It is beyond my understanding.
>>
>> Thus, it appears that described in the RHV4 guide 
>> (https://access.redhat.com/documentation/en/red-hat-virtualization/4.0/single/self-hosted-engine-guide/#sect-Restoring_SHE_bkup)
>>  recovery procedure in fact incomplete?
> Yes, you are right although this is a kind of special case since we are 
> moving/restoring to a different storage domain while you are not asked to 
> remove the old storage if you are restoring in place.
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Correct recovery procedure of the oVirt Hosted Engine 4.0

2016-10-05 Thread aleksey . maksimov
Ouch. It is beyond my understanding.

Thus, it appears that described in the RHV4 guide 
(https://access.redhat.com/documentation/en/red-hat-virtualization/4.0/single/self-hosted-engine-guide/#sect-Restoring_SHE_bkup)
 recovery procedure in fact incomplete?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Correct recovery procedure of the oVirt Hosted Engine 4.0

2016-10-05 Thread aleksey . maksimov
Weird. The RHV4 guides not contain the information that we need to clean the database from old storage domain before running the command engine-setup.What specific actions do we need?Eventually I want to get a full recovery plan at the moment for oVirt 4.0. 05.10.2016, 12:07, "Simone Tiraboschi" :  On Wed, Oct 5, 2016 at 10:30 AM,  wrote:Well.Then, in the case of conditions:1) the vm is not available anymore due to storage corruption2) an empty shared storage is available3) engine backup exists4) all VMs still running on the hosts in the clusterThe recovery plan will be like this (as I understand it):1) On all the hosts (if they are still available):# service ovirt-ha-broker stop# service ovirt-ha-agent stop# chkconfig --del ovirt-ha-broker# chkconfig --del ovirt-ha-agent2) On first host (if the original host is not available anymore, provision a new host from scratch and proceed on this new host):  2.1) # hosted-engine --deploy ◾use same fqdn you had previously in the HE VM. ◾point to the new shared storage ◾provide the same admin password you used in previous setup ◾install the OS on the vm I'd suggest to use the engine appliance also for this.You can just say No when it asks about automatically running engine-setup.   ◾confirm it has been installed on Hosted Engine VM:  a) Install the ovirt-engine rpms on the vm but don't run engine-setup:  # yum install http://resources.ovirt.org/pub/yum-repo/ovirt-release40.rpm  # yum install epel-release  # yum install ovirt-engine  b) Restore the backup:  # engine-backup --mode=restore --file=file_name --log=log_file_name --provision-db --provision-dwh-db --restore-permissions In order to let the engine auto-import the new hosted-engine storage domain, you have to remove the old one.The same for the engine VM. Unfortunately you cannot do that from the engine since they are somehow protected to avoid unintentional damages.The easiest way is to remove them from the DB before running engine-setup.I'm working on a helper utility to make it easiser:https://gerrit.ovirt.org/#/c/64966/I think I'll integrate it with engine-backup to simply do it with an additional CLI flag.    c) Run "engine-setup"   2.2) Open Administration Portal and remove the all old hosts used for Hosted Engine Right, we can also integrate this step in the HE cleaning helper. 2.3) Confirm that the engine has been installed (Return to the host and continue the hosted-engine deployment script by selecting option 1) and then finish the deploy.   2.4) In Administration Portal activate new host3) On all additional hosts run "hosted-engine --deploy". I strongly suggest to deploy them from the engine and not from CLI.CLI deploy support for additional HE host is deprecated an it will be removed in 4.1. Right?___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Correct recovery procedure of the oVirt Hosted Engine 4.0

2016-10-05 Thread aleksey . maksimov
Well.
Then, in the case of conditions:

1) the vm is not available anymore due to storage corruption
2) an empty shared storage is available
3) engine backup exists
4) all VMs still running on the hosts in the cluster


The recovery plan will be like this (as I understand it):


1) On all the hosts (if they are still available):

# service ovirt-ha-broker stop
# service ovirt-ha-agent stop
# chkconfig --del ovirt-ha-broker
# chkconfig --del ovirt-ha-agent


2) On first host (if the original host is not available anymore, provision a 
new host from scratch and proceed on this new host):

  2.1) # hosted-engine --deploy

 ◾use same fqdn you had previously in the HE VM.
 ◾point to the new shared storage
 ◾provide the same admin password you used in previous setup
 ◾install the OS on the vm
 ◾confirm it has been installed

 on Hosted Engine VM:

  a) Install the ovirt-engine rpms on the vm but don't run engine-setup:
  # yum install http://resources.ovirt.org/pub/yum-repo/ovirt-release40.rpm
  # yum install epel-release
  # yum install ovirt-engine
  b) Restore the backup:
  # engine-backup --mode=restore --file=file_name --log=log_file_name 
--provision-db --provision-dwh-db --restore-permissions
  c) Run "engine-setup"

   2.2) Open Administration Portal and remove the all old hosts used for Hosted 
Engine

   2.3) Confirm that the engine has been installed (Return to the host and 
continue the hosted-engine deployment script by selecting option 1) and then 
finish the deploy.

   2.4) In Administration Portal activate new host


3) On all additional hosts run "hosted-engine --deploy".


Right?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] Correct recovery procedure of the oVirt Hosted Engine 4.0

2016-10-05 Thread aleksey . maksimov
Hello oVirt guru`s!


My Hosted Engine VM located on a dedicated LUN FC Storage.

I do daily data backups (on NFS share) with the command:

/usr/bin/engine-backup --mode=backup --scope=all --file=$BcpFileName.xz 
--log=$BcpFileName.log --archive-compressor=xz --files-compressor=None

However, I don't know what would be the correct procedure to recover, because 
in different manuals outline the various steps.

For example, there is information that I have to do configure postgresql (with 
password from file files/etc/ovirt-engine/engine.conf.d/10-setup-database.conf) 
before restoring (engine-backup --mode=restore):
https://www.ovirt.org/documentation/admin-guide/hosted-engine-backup-and-restore/

And at the same time, in another document, there are no such steps:
https://access.redhat.com/documentation/en/red-hat-virtualization/4.0/single/self-hosted-engine-guide/#sect-Restoring_SHE_bkup

What should be the correct procedure for the recovery of Hosted Engine 4.0 ?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] oVirt 4.0.4 and Active Directory Kerberos SSO for Administration/User Portal. Troubleshooting

2016-10-04 Thread aleksey . maksimov
Martin, thanks for the help. It works.

03.10.2016, 15:01, "Martin Perina" :
> ​Ahh, this is the issue. Above configuration is valid for oVirt 3.x, but in 
> 4.0 we have quite new OAuth base SSO, so you need to use following 
> configuration:
>
>  ^/ovirt-engine/sso/(interactive-login-negotiate|oauth/token-http-auth)|^/ovirt-engine/api>
>   
>     RewriteEngine on
>     RewriteCond %{LA-U:REMOTE_USER} ^(.*)$
>     RewriteRule ^(.*)$ - [L,NS,P,E=REMOTE_USER:%1]
>     RequestHeader set X-Remote-User %{REMOTE_USER}s
>     AuthType Kerberos
>     AuthName "Kerberos Login"
>     Krb5Keytab /etc/httpd/s-oVirt-Krb.keytab
>     KrbAuthRealms AD.HOLDING.COM
>     KrbMethodK5Passwd off
>     Require valid-user
>     ErrorDocument 401 " url=/ovirt-engine/sso/login-unauthorized\"/> href=\"/ovirt-engine/sso/login-unauthorized\">Here"
>   
> 
> ​
>
> ​Also as 4.0 is working on EL7 you may use mod_auth_gssapi/mod_session 
> instead of quite old mod_auth_krb. For mod_auth_gssapi/mod_sessions you need 
> to do following:
>
>   1. yum install mod_session mod_auth_gssapi
>   2. Use following Apache configuration ​
>
> ​ ^/ovirt-engine/sso/(interactive-login-negotiate|oauth/token-http-auth)|^/ovirt-engine/api>
>   
>     RewriteEngine on
>     RewriteCond %{LA-U:REMOTE_USER} ^(.*)$
>     RewriteRule ^(.*)$ - [L,NS,P,E=REMOTE_USER:%1]
>     RequestHeader set X-Remote-User %{REMOTE_USER}s
>
>     AuthType GSSAPI
>     AuthName "Kerberos Login"
>
>     # Modify to match installation
>     GssapiCredStore keytab:/etc/httpd/s-oVirt-Krb.keytab
>     GssapiUseSessions On
>     Session On
>     SessionCookieName ovirt_gssapi_session path=/private;httponly;secure;
>
>     Require valid-user
>     ErrorDocument 401 " url=/ovirt-engine/sso/login-unauthorized\"/> href=\"/ovirt-engine/sso/login-unauthorized\">Here"
>   
> ​
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Slow first opening web portal when the ovirt-engine.service is restarted

2016-10-03 Thread aleksey . maksimov
Thank you, Sandro

03.10.2016, 15:48, "Sandro Bonazzola" :

>> But now the question arises, in what cases can be a helpful 
>> ovirt-warmup.service 
>> (https://github.com/geertj/ravstack/blob/master/share/ovirt-warmup.service) ?
>
> No idea, I guess ravstack developer wanted to ensure ovirt-engine was 
> responding before continuing the boot sequence.
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Slow first opening web portal when the ovirt-engine.service is restarted

2016-10-03 Thread aleksey . maksimov
Wow. I have installed and enabled the service on Hosted Engine VM:

# yum -y install haveged
# service haveged start
# systemctl enable haveged.service
# service haveged status

Redirecting to /bin/systemctl status  haveged.service
● haveged.service - Entropy Daemon based on the HAVEGE algorithm
   Loaded: loaded (/usr/lib/systemd/system/haveged.service; enabled; vendor 
preset: disabled)
   Active: active (running) since Mon 2016-10-03 12:56:24 MSK; 2min 12s ago
 Docs: man:haveged(8)
   http://www.issihosts.com/haveged/
 Main PID: 5304 (haveged)
   CGroup: /system.slice/haveged.service
   └─5304 /usr/sbin/haveged -w 1024 -v 1 --Foreground

Oct 03 12:56:24 KOM-AD01-OVIRT1 systemd[1]: Started Entropy Daemon based on the 
HAVEGE algorithm.
Oct 03 12:56:24 KOM-AD01-OVIRT1 systemd[1]: Starting Entropy Daemon based on 
the HAVEGE algorithm...
Oct 03 12:56:24 KOM-AD01-OVIRT1 haveged[5304]: haveged: ver: 1.9.1; arch: x86; 
vend: GenuineIntel; build: (gcc 4.8.2 ITV); collect: 128K
Oct 03 12:56:24 KOM-AD01-OVIRT1 haveged[5304]: haveged: cpu: (L4 VC); data: 32K 
(L2 L4 V); inst: 32K (L2 L4 V); idx: 21/40; sz: 32709/60538
Oct 03 12:56:24 KOM-AD01-OVIRT1 haveged[5304]: haveged: tot tests(BA8): A:1/1 
B:1/1 continuous tests(B):  last entropy estimate 8.00013
Oct 03 12:56:24 KOM-AD01-OVIRT1 haveged[5304]: haveged: fills: 0, generated: 0


And now after restarting the ovirt-engine.service, first open the web portal 
pages is instantaneous!
It works.
Thank you.

But now the question arises, in what cases can be a helpful 
ovirt-warmup.service 
(https://github.com/geertj/ravstack/blob/master/share/ovirt-warmup.service) ?

03.10.2016, 12:32, "Sandro Bonazzola" :
> This looks like not enough entropy on the host / guest running ovirt-engine.
> If you're on Hosted Engine I suggest to install haveged (in EPEL repo) and 
> run it to ensure enough entropy is available for the VM.
> Adding Simone.
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Slow first opening web portal when the ovirt-engine.service is restarted

2016-10-03 Thread aleksey . maksimov
Any thoughts on this? 

I found the systemd service example for a warm start:
https://github.com/geertj/ravstack/blob/master/share/ovirt-warmup.service

This is a good solution?


03.10.2016, 09:35, "aleksey.maksi...@it-kb.ru" :
> Hello oVirt guru`s !
>
> oVirt Engine Version: 4.0.4.4-1.el7.centos
>
> After restarting the ovirt-engine.service, the web login page is available 
> after a few seconds. That's good.
> But when trying the first login, the portal web page open for 2-3 minutes
>
> All subsequent logins are fast.
>
> The question is: Why is the delay in the opening pages of the first call?
>
> Do I understand correctly that this feature of JBoss web application?
> Need some warming up of the web application?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] oVirt 4.0.4 and Active Directory Kerberos SSO for Administration/User Portal. Troubleshooting

2016-10-03 Thread aleksey . maksimov
Yes. Of course. Here are my configs.

=
# cat /etc/ovirt-engine/aaa/ovirt-sso.conf


RewriteEngine on
RewriteCond %{LA-U:REMOTE_USER} ^(.*)$
RewriteRule ^(.*)$ - [L,NS,P,E=REMOTE_USER:%1]
RequestHeader set X-Remote-User %{REMOTE_USER}s
AuthType Kerberos
AuthName "Kerberos Login"
Krb5Keytab /etc/httpd/s-oVirt-Krb.keytab
KrbAuthRealms AD.HOLDING.COM
#KrbMethodNegotiate on
#KrbMethodK5Passwd on
KrbMethodK5Passwd off
Require valid-user



# ls -la /etc/httpd/conf.d/ovirt-*

-rw-r--r--. 1 root root 33 Jul 26 16:42 
/etc/httpd/conf.d/ovirt-engine-root-redirect.conf
lrwxrwxrwx. 1 root root 36 Sep 30 00:06 /etc/httpd/conf.d/ovirt-sso.conf -> 
/etc/ovirt-engine/aaa/ovirt-sso.conf


=
# cat /etc/ovirt-engine/aaa/ad.holding.com.properties

include = 
vars.domain = ad.holding.com
pool.default.auth.simple.bindDN = s-oVirt-LS@${global:vars.domain}
pool.default.auth.simple.password = Passw0rd
pool.default.dc-resolve.enable = false
search.default.dc-resolve.enable = false
search.ad-resolve-upn.search-request.baseDN = DC=ad,DC=holding,DC=com
pool.default.serverset.type = failover
pool.default.serverset.failover.00.server = kom-dc01.${global:vars.domain}
pool.default.serverset.failover.01.server = kom-dc02.${global:vars.domain}
pool.default.serverset.failover.port = 636
pool.default.serverset.failover.domain = ${global:vars.domain}
pool.default.ssl.enable = true
pool.default.ssl.protocol = TLSv1.2
pool.default.ssl.truststore.file = ${local:_basedir}/${global:vars.domain}.jks
pool.default.ssl.truststore.password = changeit

=
# cat /etc/ovirt-engine/extensions.d/ad.holding.com-authz.properties

ovirt.engine.extension.name = ad.holding.com-authz
ovirt.engine.extension.bindings.method = jbossmodule
ovirt.engine.extension.binding.jbossmodule.module = 
org.ovirt.engine-extensions.aaa.ldap
ovirt.engine.extension.binding.jbossmodule.class = 
org.ovirt.engineextensions.aaa.ldap.AuthzExtension
ovirt.engine.extension.provides = org.ovirt.engine.api.extensions.aaa.Authz
config.profile.file.1 = ../aaa/ad.holding.com.properties

=
# cat /etc/ovirt-engine/extensions.d/ad.holding.com-http-authn.properties

ovirt.engine.extension.name = ad.holding.com-http-authn
ovirt.engine.extension.bindings.method = jbossmodule
ovirt.engine.extension.binding.jbossmodule.module = 
org.ovirt.engine-extensions.aaa.misc
ovirt.engine.extension.binding.jbossmodule.class = 
org.ovirt.engineextensions.aaa.misc.http.AuthnExtension
ovirt.engine.extension.provides = org.ovirt.engine.api.extensions.aaa.Authn
ovirt.engine.aaa.authn.profile.name = ad.holding.com-http
ovirt.engine.aaa.authn.authz.plugin = ad.holding.com-authz
ovirt.engine.aaa.authn.mapping.plugin = ad.holding.com-http-mapping
config.artifact.name = HEADER
config.artifact.arg = X-Remote-User

=
# cat /etc/ovirt-engine/extensions.d/ad.holding.com-http-mapping.properties

ovirt.engine.extension.name = ad.holding.com-http-mapping
ovirt.engine.extension.bindings.method = jbossmodule
ovirt.engine.extension.binding.jbossmodule.module = 
org.ovirt.engine-extensions.aaa.misc
ovirt.engine.extension.binding.jbossmodule.class = 
org.ovirt.engineextensions.aaa.misc.mapping.MappingExtension
ovirt.engine.extension.provides = org.ovirt.engine.api.extensions.aaa.Mapping
config.mapAuthRecord.type = regex
config.mapAuthRecord.regex.mustMatch = true
config.mapAuthRecord.regex.pattern = 
^(?.*?)(((?@)(?.*?)@.*)|(?@.*))$
config.mapAuthRecord.regex.replacement = ${user}${at}${suffix}${realm}


03.10.2016, 09:56, "Martin Perina" :

> ​Ahh, so kerberos SSO works fine for API, but not for portals. Could you 
> please share your Apache configuration with oVirt kerberos configuration? 
> Usually it's in /etc/ovirt-engine/aaa/ovirt-sso.conf
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] oVirt 4.0.4 and Active Directory Kerberos SSO for Administration/User Portal. Troubleshooting

2016-10-03 Thread aleksey . maksimov
 > network.negotiate-auth.delegation-uris = .ad.holding.com > network.negotiate-auth.trusted-uris = .ad.holding.com Yes. Configured The URL https://kom-ad01-ovirt1.ad.holding.com/ovirt-engine/api in IE and Firefox opens without problems and without password prompts But when opening links from start page... https://kom-ad01-ovirt1.ad.holding.com/ovirt-engine/userportal/?locale=en_UShttps://kom-ad01-ovirt1.ad.holding.com/ovirt-engine/webadmin/?locale=en_US ...opens a oVirt form prompting for credentials with a single profile "internal"  03.10.2016, 09:37, "Martin Perina" :  On Mon, Oct 3, 2016 at 8:18 AM,  wrote: Hello, Martin Before I wrote: Kerberos authentication FOR WINDOWS WEB SERVERS working successfully from Internet Explorer & Forefox.Kerberos authentication NOT working with oVirt Web-Portals. I expect that the users opening the oVirt web portal in the browser did not enter a password, and used instead of the transparent sign-on using Kerberos.It is impossible ?? ​It's possible and it's working fine when everything is properly set up. But please bear in mind kerberos SSO is one of the most complicated oVirt setup, but usually the error is on kerberos side (environment issues on the client). So, you are saying that using curl you are able to access API using kerberos ticket but when you try to access the same API from the browser it does not work, right?I don't use IE, but you need to set following options in "about:config" URL for Firefox to work properly with kerberos: network.negotiate-auth.delegation-uris = .ad.holding.com network.negotiate-auth.trusted-uris = .ad.holding.com If you have those options set, what exactly happen when you try to access ​https://kom-ad01-ovirt1.ad.holding.com/ovirt-engine/api​ ​in Firefox? Martin Perina​ 03.10.2016, 09:08, "Martin Perina" :Hi Aleksey,in your last email you wrote that everything works (at least that's my understanding, email pasted below). So what exactly doesn't work for you?RegardsMartin Perina> # kinit aleksey>> Password for alek...@ad.holding.com: ***>> # klist>> Ticket cache: KEYRING:persistent:0:krb_ccache_9W86VN9> Default principal: alek...@ad.holding.com>> Valid starting       Expires              Service principal> 09/30/2016 16:50:32  10/01/2016 02:50:32  krbtgt/ad.holding@ad.holding.com>         renew until 10/07/2016 16:50:29>>> # curl --negotiate -u : -X GET -H "Accept: application/xml" -k​​https://kom-ad01-ovirt1.ad.holding.com/ovirt-engine/api>> > >  ... output truncated ...> >> It Works.> The browsers are configured.> Kerberos authentication for Windows web servers working successfully from Internet Explorer & Forefox  On Mon, Oct 3, 2016 at 7:37 AM,  wrote: Up30.09.2016, 18:55, "aleksey.maksi...@it-kb.ru" :> Any other ideas?___Users mailing listUsers@ovirt.orghttp://lists.ovirt.org/mailman/listinfo/users___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] Slow first opening web portal when the ovirt-engine.service is restarted

2016-10-03 Thread aleksey . maksimov
Hello oVirt guru`s !

oVirt Engine Version: 4.0.4.4-1.el7.centos

After restarting the ovirt-engine.service, the web login page is available 
after a few seconds. That's good.
But when trying the first login, the portal web page open for 2-3 minutes

All subsequent logins are fast.

The question is: Why is the delay in the opening pages of the first call?

Do I understand correctly that this feature of JBoss web application?
Need some warming up of the web application?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] oVirt 4.0.4 and Active Directory Kerberos SSO for Administration/User Portal. Troubleshooting

2016-10-03 Thread aleksey . maksimov
 Hello, Martin Before I wrote: Kerberos authentication FOR WINDOWS WEB SERVERS working successfully from Internet Explorer & Forefox.Kerberos authentication NOT working with oVirt Web-Portals. I expect that the users opening the oVirt web portal in the browser did not enter a password, and used instead of the transparent sign-on using Kerberos.It is impossible ?? 03.10.2016, 09:08, "Martin Perina" :Hi Aleksey,in your last email you wrote that everything works (at least that's my understanding, email pasted below). So what exactly doesn't work for you?RegardsMartin Perina> # kinit aleksey>> Password for alek...@ad.holding.com: ***>> # klist>> Ticket cache: KEYRING:persistent:0:krb_ccache_9W86VN9> Default principal: alek...@ad.holding.com>> Valid starting       Expires              Service principal> 09/30/2016 16:50:32  10/01/2016 02:50:32  krbtgt/ad.holding@ad.holding.com>         renew until 10/07/2016 16:50:29>>> # curl --negotiate -u : -X GET -H "Accept: application/xml" -k https://kom-ad01-ovirt1.ad.holding.com/ovirt-engine/api>> > >  ... output truncated ...> >> It Works.> The browsers are configured.> Kerberos authentication for Windows web servers working successfully from Internet Explorer & Forefox  On Mon, Oct 3, 2016 at 7:37 AM,  wrote: Up30.09.2016, 18:55, "aleksey.maksi...@it-kb.ru" :> Any other ideas?___Users mailing listUsers@ovirt.orghttp://lists.ovirt.org/mailman/listinfo/users___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] oVirt 4.0.4 and Active Directory Kerberos SSO for Administration/User Portal. Troubleshooting

2016-10-02 Thread aleksey . maksimov

Up

30.09.2016, 18:55, "aleksey.maksi...@it-kb.ru" :
> Any other ideas?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] oVirt 4.0.4 and Active Directory Kerberos SSO for Administration/User Portal. Troubleshooting

2016-09-30 Thread aleksey . maksimov
Any other ideas?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] oVirt 4.0.4 and Active Directory Kerberos SSO for Administration/User Portal. Troubleshooting

2016-09-30 Thread aleksey . maksimov
# kinit aleksey

Password for alek...@ad.holding.com: ***

# klist

Ticket cache: KEYRING:persistent:0:krb_ccache_9W86VN9
Default principal: alek...@ad.holding.com

Valid starting   Expires  Service principal
09/30/2016 16:50:32  10/01/2016 02:50:32  krbtgt/ad.holding@ad.holding.com
renew until 10/07/2016 16:50:29


# curl --negotiate -u : -X GET -H "Accept: application/xml" -k 
https://kom-ad01-ovirt1.ad.holding.com/ovirt-engine/api



 ... output truncated ...


It Works.
The browsers are configured.
Kerberos authentication for Windows web servers working successfully from 
Internet Explorer & Forefox

30.09.2016, 16:45, "Ondra Machacek" :
> '/etc/httpd/s-oVirt-Krb.keytab' is apache keytab, you can't try to test
> login with it. You should try something like `kinit myuser` and then
> curl. And be sure that 'myuser' has appropriate permissions in oVirt.
>
> Do you have properly setup your browser and enabled negotiation (for
> example for firefox [1])?
>
> [1]
> https://docs.fedoraproject.org/en-US/Fedora/11/html/Security_Guide/sect-Security_Guide-Single_Sign_on_SSO-Configuring_Firefox_to_use_Kerberos_for_SSO.html
>
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] oVirt 4.0.4 and Active Directory Kerberos SSO for Administration/User Portal. Troubleshooting

2016-09-30 Thread aleksey . maksimov
# kinit -V -k -t /etc/httpd/s-oVirt-Krb.keytab 
HTTP/kom-ad01-ovirt1.ad.holding.com

Using existing cache: persistent:0:0
Using principal: HTTP/kom-ad01-ovirt1.ad.holding@ad.holding.com
Using keytab: /etc/httpd/s-oVirt-Krb.keytab
Authenticated to Kerberos v5

# klist

Ticket cache: KEYRING:persistent:0:0
Default principal: HTTP/kom-ad01-ovirt1.ad.holding@ad.holding.com

Valid starting   Expires  Service principal
09/30/2016 16:28:02  10/01/2016 02:28:02  krbtgt/ad.holding@ad.holding.com
renew until 10/07/2016 16:28:02

# curl --negotiate -u : -X GET -H "Accept: application/xml" -k 
https://kom-ad01-ovirt1.ad.holding.com/ovirt-engine/api

ErrorUnauthorized

However, if I open this URL 
(https://kom-ad01-ovirt1.ad.holding.com/ovirt-engine/api) in browser it opens 
without errors and authorization requests


# tail -f  /var/log/httpd/ssl_error_log
# tail -f  /var/log/ovirt-engine/engine.log

In the logs nothing in that moment when I open the portal in the browser.

30.09.2016, 15:52, "Ondra Machacek" :

> So if you run kinit and then:
>
>   $ curl --negotiate -u : -X GET -H "Accept: application/xml" -k
> https://fqdn/ovirt-engine/api
>
> It's fine?
>
>>  Please tell me how to find the cause of the problem. What are the steps to 
>> troubleshooting to do?
>
> On oVirt engine check:
>
>   /var/log/httpd/ssl_error_log
>   /var/log/ovirt-engine/engine.log
>
> On AD check kerberos log.
>
>>  ___
>>  Users mailing list
>>  Users@ovirt.org
>>  http://lists.ovirt.org/mailman/listinfo/users
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] oVirt 4.0.4 and Active Directory Kerberos SSO for Administration/User Portal. Troubleshooting

2016-09-30 Thread aleksey . maksimov
Hello oVirt guru`s!

I set up oVirt integration with Active Directory LDAP according to the manual:
https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Virtualization/3.6/html/Administration_Guide/sect-Configuring_an_External_LDAP_Provider.html#Configuring_an_External_LDAP_Provider_ManualMethod

I created a profile integration with my domain. All is working well.

Now I'm trying to configure single sign-on for portals based on Kerberos.

All settings are performed according to the manual:
https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Virtualization/3.6/html/Administration_Guide/Configuring_LDAP_and_Kerberos_for_Single_Sign-on.html

Kerberos client tested and working. However, SSO is not working. 

Please tell me how to find the cause of the problem. What are the steps to 
troubleshooting to do?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] ovirt-engine-extension-aaa-ldap-setup > [ ERROR ] Invalid CA certificate: unknown error (_ssl.c:2988)

2016-09-28 Thread aleksey . maksimov
Yes. You're right. Thank you.

> "Please select method to obtain PEM encoded CA certificate"
>
> File means the PEM file not the jks file. The jks is created by
> aaa-ldap-setup.
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Time synchronization in guest OS for Hosted Engine VM (for Kerberos)

2016-09-28 Thread aleksey . maksimov
Robert, you're right. 
Thanks for clarifying.

28.09.2016, 15:10, "Robert Story" :
> On Tue, 27 Sep 2016 13:22:29 -0400 (EDT) Michal wrote:
> MS> > On 27 Sep 2016, at 19:12, aleksey.maksi...@it-kb.ru wrote:
> MS> >
> MS> > I'm afraid that in the future OS time may get out of sync because of 
> kvm-clock
> MS> > And as a result Kerberos may stop working
> MS> > I hope I explained clearly
> MS>
> MS> Sorry, not really. You said you set up ntpd/chrony correctly. So how can 
> the time get out of sync? Why do you think it can be because of kvmclock 
> anyway? Do you refer to some specific bug?
>
> I'd guess that it's a misunderstanding of what kvmclock is. Someone
> guessing based on the name might think that it keeps the vm time in sync
> with the host. Which might lead one to think it would conflict with ntp
> (two different things trying to manage time).
>
> If you know that kvmclock is essentially just a way to monitor the passage
> of time (tick-tock-tick-tock) using the host's timer, then it makes sense
> that you need also need ntp to tweak the current time to adjust for the
> minor drift inherit in any clock.
>
> Robert
>
> --
> Senior Software Engineer @ Parsons
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Time synchronization in guest OS for Hosted Engine VM (for Kerberos)

2016-09-27 Thread aleksey . maksimov
Thank you

27.09.2016, 20:38, "Michal Skrivanek" :
> kvmclock is the most accurate clock in Linux guests. Once you hit a bug we 
> can take a look at something, but until then I do not see a reason to modify 
> anything
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] ovirt-engine-extension-aaa-ldap-setup > [ ERROR ] Invalid CA certificate: unknown error (_ssl.c:2988)

2016-09-27 Thread aleksey . maksimov
Hello oVirt guru's!

I want to configure MS Active Directory authentication for oVirt web UI.

I configured an External LDAP Provider in accordance with the instructions:

Link #1) 
https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Virtualization/3.6/html/Administration_Guide/sect-Configuring_an_External_LDAP_Provider.html

Link #2) 
https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Virtualization/3.6/html/Administration_Guide/Setting_Up_SSL_or_TLS_Connections_between_the_Manager_and_an_LDAP_Server.html

For support LDAP over TLS I did file with all Root certificates 
(~/AD-LDAP-Files/myrootca_chain.pem).

Check file:

$ openssl verify -CAfile ~/AD-LDAP-Files/myrootca_chain.pem 
~/AD-LDAP-Files/ldapserver.pem
/root/AD-LDAP-Files/end.pem: OK

Then I create  JKS (Java Key Store) file (as described in Link #2):

# keytool -importcert -noprompt -trustcacerts -alias myrootcachain -file 
~/AD-LDAP-Files/myrootca_chain.pem -keystore /etc/ovirt-engine/aaa/myrootca.jks 
-storepass changeit
Certificate was added to keystore

Then I run ovirt-engine-extension-aaa-ldap-setup:

# ovirt-engine-extension-aaa-ldap-setup

[ INFO  ] Stage: Initializing
[ INFO  ] Stage: Environment setup
  Configuration files: 
['/etc/ovirt-engine-extension-aaa-ldap-setup.conf.d/10-packaging.conf']
  Log file: 
/tmp/ovirt-engine-extension-aaa-ldap-setup-20160927202843-npv8ru.log
  Version: otopi-1.5.2 (otopi-1.5.2-1.el7.centos)
[ INFO  ] Stage: Environment packages setup
[ INFO  ] Stage: Programs detection
[ INFO  ] Stage: Environment customization
  Welcome to LDAP extension configuration program
  Available LDAP implementations:
   1 - 389ds
   2 - 389ds RFC-2307 Schema
   3 - Active Directory
   4 - IPA
   5 - Novell eDirectory RFC-2307 Schema
   6 - OpenLDAP RFC-2307 Schema
   7 - OpenLDAP Standard Schema
   8 - Oracle Unified Directory RFC-2307 Schema
   9 - RFC-2307 Schema (Generic)
  10 - RHDS
  11 - RHDS RFC-2307 Schema
  12 - iPlanet
  Please select: 3
  Please enter Active Directory Forest name: holding.com
[ INFO  ] Resolving Global Catalog SRV record for holding.com
[ INFO  ] Resolving LDAP SRV record for holding.com
  NOTE:
  It is highly recommended to use secure protocol to access the LDAP 
server.
  Protocol startTLS is the standard recommended method to do so.
  Only in cases in which the startTLS is not supported, fallback to non 
standard ldaps protocol.
  Use plain for test environments only.
  Please select protocol to use (startTLS, ldaps, plain) [startTLS]:
  Please select method to obtain PEM encoded CA certificate (File, URL, 
Inline, System, Insecure): File
  File path: /etc/ovirt-engine/aaa/myrootca.jks
[ ERROR ] Invalid CA certificate: unknown error (_ssl.c:2988)
  Please select method to obtain PEM encoded CA certificate (File, URL, 
Inline, System, Insecure):
 

In the log /tmp/ovirt-engine-extension-aaa-ldap-setup-20160927202843-npv8ru.log:

...
2016-09-27 20:28:57 DEBUG otopi.plugins.otopi.dialog.human 
dialog.__logString:204 DIALOG:SEND Please select method to 
obtain PEM encoded CA certificate (File, URL, Inline, System, Insecure):
2016-09-27 20:29:01 DEBUG otopi.plugins.otopi.dialog.human 
dialog.__logString:204 DIALOG:RECEIVEFile
2016-09-27 20:29:01 DEBUG otopi.plugins.otopi.dialog.human 
human.queryString:145 query OVAAALDAP_LDAP_CACERT_FILE
2016-09-27 20:29:01 DEBUG otopi.plugins.otopi.dialog.human 
dialog.__logString:204 DIALOG:SEND File path:
2016-09-27 20:29:10 DEBUG otopi.plugins.otopi.dialog.human 
dialog.__logString:204 DIALOG:RECEIVE/etc/ovirt-engine/aaa/myrootca.jks
2016-09-27 20:29:10 ERROR 
otopi.plugins.ovirt_engine_extension_aaa_ldap.ldap.common 
common._customization_late:756 Invalid CA certificate: unknown error 
(_ssl.c:2988)
2016-09-27 20:29:10 DEBUG 
otopi.plugins.ovirt_engine_extension_aaa_ldap.ldap.common 
common._customization_late:757 Exception
Traceback (most recent call last):
  File 
"/usr/share/ovirt-engine-extension-aaa-ldap/setup/bin/../plugins/ovirt-engine-extension-aaa-ldap/ldap/common.py",
 line 748, in _customization_late
cacert, cacertfile, insecure = self._getCACert()
  File 
"/usr/share/ovirt-engine-extension-aaa-ldap/setup/bin/../plugins/ovirt-engine-extension-aaa-ldap/ldap/common.py",
 line 366, in _getCACert
error=e,
SoftRuntimeError: Invalid CA certificate: unknown error (_ssl.c:2988)

Tell me, please, what am I doing wrong.
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Time synchronization in guest OS for Hosted Engine VM (for Kerberos)

2016-09-27 Thread aleksey . maksimov
No. At the moment I have no sync-time errors. I'm just asking hypothetically

27.09.2016, 20:22, "Michal Skrivanek" :
>>  On 27 Sep 2016, at 19:12, aleksey.maksi...@it-kb.ru wrote:
>>
>>  I'm afraid that in the future OS time may get out of sync because of 
>> kvm-clock
>>  And as a result Kerberos may stop working
>>  I hope I explained clearly
>
> Sorry, not really. You said you set up ntpd/chrony correctly. So how can the 
> time get out of sync? Why do you think it can be because of kvmclock anyway? 
> Do you refer to some specific bug?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Time synchronization in guest OS for Hosted Engine VM (for Kerberos)

2016-09-27 Thread aleksey . maksimov
I'm afraid that in the future OS time may get out of sync because of kvm-clock
And as a result Kerberos may stop working
I hope I explained clearly

27.09.2016, 19:59, "Michal Skrivanek" :
>>  On 27 Sep 2016, at 18:57, aleksey.maksi...@it-kb.ru wrote:
>>
>>  Michal, please, read my first message.
>>  I have 3 times wrote that the NTP client works for me.
>>  The question is not that.
>>  The question is how to disable kvm-clock for a virtual machine?
>
> What leads you to think you have to do that? Why?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Time synchronization in guest OS for Hosted Engine VM (for Kerberos)

2016-09-27 Thread aleksey . maksimov
Michal, please, read my first message.
I have 3 times wrote that the NTP client works for me.
The question is not that.
The question is how to disable kvm-clock for a virtual machine? Do I have to do 
it at all? If you want, how to do it correctly?

My hypervisors OS - CentOS 7.2


27.09.2016, 19:39, "Michal Skrivanek" :
>>  On 27 Sep 2016, at 17:57, aleksey.maksi...@it-kb.ru wrote:
>>
>>  Yaniv, I do not understand how to do it.
>>  You can tell steps how to do it?
>>
>>  27.09.2016, 18:53, "Yaniv Dary" :
>>>  You can do that from the edit VM dialog.
>
> I don't think you can
>
> Aleksey,
> I don't understand what issue you have. Time is getting desynchronized? How 
> did you configure your ntp client? Does it behave the same on different 
> hypervisor? What is the hypervisor OS?
>
> Thanks,
> michal
>
>>  ___
>>  Users mailing list
>>  Users@ovirt.org
>>  http://lists.ovirt.org/mailman/listinfo/users
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Time synchronization in guest OS for Hosted Engine VM (for Kerberos)

2016-09-27 Thread aleksey . maksimov
Yaniv, I do not understand how to do it.
You can tell steps how to do it?

27.09.2016, 18:53, "Yaniv Dary" :
> You can do that from the edit VM dialog.
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Time synchronization in guest OS for Hosted Engine VM (for Kerberos)

2016-09-27 Thread aleksey . maksimov
I think that the NTP-client (chrony) in guest OS may conflict with the 
kvm-clock (vm guest OS time sync from vm-host). 
Do I need to turn off  kvm-clock in virtual machine properties? 
And how to do it?

What is not clear in my question?

27.09.2016, 18:24, "aleksey.maksi...@it-kb.ru" :
> I wrote that I had set up the NTP client. The question is not that..
>
> 27.09.2016, 17:56, "Yaniv Dary" :
>>  Why not use ntp?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Time synchronization in guest OS for Hosted Engine VM (for Kerberos)

2016-09-27 Thread aleksey . maksimov
I wrote that I had set up the NTP client. The question is not that..

27.09.2016, 17:56, "Yaniv Dary" :
> Why not use ntp?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Time synchronization in guest OS for Hosted Engine VM (for Kerberos)

2016-09-27 Thread aleksey . maksimov
No ideas?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Scheduling policy for oVirt cluster "vm_evenly_distributed"

2016-09-27 Thread aleksey . maksimov
Hi Artem. Today I updated oVirt to version 4.0.4.Now balancing "vm_evenly_distributed" works fine.Thank you for participating. 27.09.2016, 10:36, "Artyom Lukianov" :Can you please show the screenshot from the clusters->edit cluster-> scheduling policy and also specify what host is SPM? On Tue, Sep 27, 2016 at 10:09 AM,  wrote:These parameters can be seen in the screenshot in my first message27.09.2016, 09:51, "Artyom Lukianov" :> Please provide all policy parameters(HighVmCount, SpmVmGrace and MigrationThreshold)___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Scheduling policy for oVirt cluster "vm_evenly_distributed"

2016-09-27 Thread aleksey . maksimov
These parameters can be seen in the screenshot in my first message

27.09.2016, 09:51, "Artyom Lukianov" :
> Please provide all policy parameters(HighVmCount, SpmVmGrace and 
> MigrationThreshold)
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] How can I to add RAM to Hosted Engine VM?

2016-09-26 Thread aleksey . maksimov

Thank you all for the information. 
I made a small wiki article [for the Russian-speaking oVirt users]
https://wiki.it-kb.ru/ovirt/ovirt-kvm-how-to-add-ram-memory-to-hosted-engine-vm

25.09.2016, 09:15, "Doron Fediuck" <dfedi...@redhat.com>:
> The right way is simply to edit the hosted engine VM memory settings from the 
> admin UI.
> The file is not meant to be edited and may lead to issues in your setup.
>
> On Sat, Sep 24, 2016 at 7:57 PM, <aleksey.maksi...@it-kb.ru> wrote:
>> My HE VM stored on FC Storage
>>
>> 24.09.2016, 19:51, "Logan Kuhn" <log...@wolfram.com>:
>>> Sorry hit send too quickly.
>>>
>>> Move the shared storage version out of the way if you can. In my instance 
>>> it was just an NFS volume so it wasn't too hard to move it.
>>>
>>> Regards,
>>> Logan
>>>
>>> - On Sep 24, 2016, at 11:50 AM, Logan Kuhn log...@wolfram.com wrote:
>>>
>>> | I believe you can do it by editing this file:
>>> | /var/run/ovirt-hosted-engine-ha/vm.conf and then restarting the vm
>>> |
>>> | Regards,
>>> | Logan
>>> |
>>> | - On Sep 24, 2016, at 10:13 AM, aleksey maksimov 
>>> aleksey.maksi...@it-kb.ru
>>> | wrote:
>>> |
>>> || Hello oVirt guru`s !
>>> ||
>>> || How can I to add RAM to Hosted Engine VM?
>>> || Solution from "Fix: The recovery flow is:..." in
>>> || https://bugzilla.redhat.com/show_bug.cgi?id=1309572 not working.
>>> ||
>>> || oVirt Engine Version: 4.0.3-1.el7.centos
>>> || ___
>>> || Users mailing list
>>> || Users@ovirt.org
>>> | | http://lists.ovirt.org/mailman/listinfo/users
>> ___
>> Users mailing list
>> Users@ovirt.org
>> http://lists.ovirt.org/mailman/listinfo/users
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] Time synchronization in guest OS for Hosted Engine VM (for Kerberos)

2016-09-26 Thread aleksey . maksimov

Hello oVirt guru`s!

I want to configure Kerberos authentication (via MS Active Directory) for the 
oVirt portal.
So I need to properly configure the time synchronization for my Hosted Engine 
VM.
I set up chronyd service in a HE VM for time synchronization from Active 
Directory domain controllers:

# cat /etc/chrony.conf | grep ^[^#\;]

server 10.1.0.9 iburst
server 10.1.6.8 iburst
stratumweight 0
driftfile /var/lib/chrony/drift
rtcsync
makestep 10 3
bindcmdaddress 127.0.0.1
keyfile /etc/chrony.keys
commandkey 1
generatecommandkey
noclientlog
logchange 0.5
logdir /var/log/chrony

# chronyc tracking

Reference ID: 10.1.0.9 (kom-dc01.holding.com)
Stratum : 4
Ref time (UTC)  : Mon Sep 26 17:40:16 2016
System time : 0.000437915 seconds slow of NTP time
Last offset : -0.000789918 seconds
RMS offset  : 0.001730987 seconds
Frequency   : 13.612 ppm slow
Residual freq   : -0.009 ppm
Skew: 0.166 ppm
Root delay  : 0.078126 seconds
Root dispersion : 0.126046 seconds
Update interval : 1031.9 seconds
Leap status : Normal

It looks workable.

But I think that the service may conflict with the kvm-clock

# cat /sys/devices/system/clocksource/clocksource0/current_clocksource

kvm-clock

# dmesg | grep -i clock

[0.00] kvm-clock: Using msrs 4b564d01 and 4b564d00
[0.00] kvm-clock: cpu 0, msr 2:3ff84001, primary cpu clock
[0.00] kvm-clock: using sched offset of 6567130420 cycles
[0.538339] kvm-clock: cpu 1, msr 2:3ff84041, secondary cpu clock
[0.571323] acpi PNP0A03:00: _OSC: OS supports [ASPM ClockPM Segments MSI]
[0.663452] Switching to clocksource kvm-clock
[1.065348] rtc_cmos 00:00: setting system clock to 2016-09-25 16:16:04 UTC 
(1474820164)
[1.988543] tsc: Refined TSC clocksource calibration: 3166.733 MHz
[   16.792347] Adjusting kvm-clock more than 11% (9437295 vs 9311354)

Do I need to turn off  kvm-clock in virtual machine properties? And how to do 
it?
Please explain the best practice.
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] Scheduling policy for oVirt cluster "vm_evenly_distributed"

2016-09-26 Thread aleksey . maksimov
Hello oVirt guru`s!

oVirt Engine Version: 4.0.3-1.el7.centos

I test load balancing (Scheduling policy for oVirt cluster) 
I created a copy of the policy "vm_evenly_distributed" (see 
My_vm_evenly_distributed.png)
The policy specified limit 2 VMs on the host.

I have a 4 host in oVirt cluster. On the first host are 5 virtual machines. 
Other hosts do not have the VM.

HOST1 - 5VM
HOST2 - 0VM
HOST3 - 0VM
HOST4 - 0VM

Now I apply the policy on a cluster and I expect that oVirt start to migrate 
VMs from first host to another, e.g.

HOST1 - 2 VM
HOST2 - 2 VM
HOST3 - 1 VM
HOST4 - 0 VM

But in fact, migration is performed only one virtual machine:

HOST1 - 4 VM
HOST2 - 1 VM
HOST3 - 0 VM
HOST4 - 0 VM

All hosts on the same hardware.
VMs not have Affinity Groups.
All VMs are HA-enabled and automigration-enabled

What am I doing wrong?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] How can I to add RAM to Hosted Engine VM?

2016-09-25 Thread aleksey . maksimov
Thank you, Roy. It works. Just do not understand why this information is not available in the online documentation. 25.09.2016, 09:14, "Roy Golan" <rgo...@redhat.com>:You need to edit the vm in the webui and increase the memory there. The next cold boot of the machine will load it with the new config. Do note that the engine has an interval which triggers the creation of the new vm.conf. The interval config item can be checked using ```engine-config -g OvfUpdateIntervalInMinutes``` the vm.conf under the host is now always and extraction of the configuration saved under your hosted_storage domain On 24 September 2016 at 19:57, <aleksey.maksi...@it-kb.ru> wrote:My HE VM stored on FC Storage24.09.2016, 19:51, "Logan Kuhn" <log...@wolfram.com>:> Sorry hit send too quickly.>> Move the shared storage version out of the way if you can. In my instance it was just an NFS volume so it wasn't too hard to move it.>> Regards,> Logan>> - On Sep 24, 2016, at 11:50 AM, Logan Kuhn log...@wolfram.com wrote:>> | I believe you can do it by editing this file:> | /var/run/ovirt-hosted-engine-ha/vm.conf and then restarting the vm> |> | Regards,> | Logan> |> | - On Sep 24, 2016, at 10:13 AM, aleksey maksimov aleksey.maksi...@it-kb.ru> | wrote:> |> || Hello oVirt guru`s !> ||> || How can I to add RAM to Hosted Engine VM?> || Solution from "Fix: The recovery flow is:..." in> || https://bugzilla.redhat.com/show_bug.cgi?id=1309572 not working.> ||> || oVirt Engine Version: 4.0.3-1.el7.centos> || ___> || Users mailing list> || Users@ovirt.org> | | http://lists.ovirt.org/mailman/listinfo/users___Users mailing listUsers@ovirt.orghttp://lists.ovirt.org/mailman/listinfo/users___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] How can I to add RAM to Hosted Engine VM?

2016-09-24 Thread aleksey . maksimov
My HE VM stored on FC Storage

24.09.2016, 19:51, "Logan Kuhn" <log...@wolfram.com>:
> Sorry hit send too quickly.
>
> Move the shared storage version out of the way if you can. In my instance it 
> was just an NFS volume so it wasn't too hard to move it.
>
> Regards,
> Logan
>
> - On Sep 24, 2016, at 11:50 AM, Logan Kuhn log...@wolfram.com wrote:
>
> | I believe you can do it by editing this file:
> | /var/run/ovirt-hosted-engine-ha/vm.conf and then restarting the vm
> |
> | Regards,
> | Logan
> |
> | - On Sep 24, 2016, at 10:13 AM, aleksey maksimov 
> aleksey.maksi...@it-kb.ru
> | wrote:
> |
> || Hello oVirt guru`s !
> ||
> || How can I to add RAM to Hosted Engine VM?
> || Solution from "Fix: The recovery flow is:..." in
> || https://bugzilla.redhat.com/show_bug.cgi?id=1309572 not working.
> ||
> || oVirt Engine Version: 4.0.3-1.el7.centos
> || ___
> || Users mailing list
> || Users@ovirt.org
> | | http://lists.ovirt.org/mailman/listinfo/users
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] DeprecationWarning: vdscli uses xmlrpc. since ovirt 3.6 xmlrpc is deprecated, please use vdsm.jsonrpcvdscli

2016-09-18 Thread aleksey . maksimov
https://bugzilla.redhat.com/show_bug.cgi?id=1377069

18.09.2016, 10:09, "Roy Golan" :
> On 18 September 2016 at 09:48,  wrote:
>> Thanks Roy
>>
>> But if I'm going to redirect the output of the hosted-engine command to 
>> /dev/null, I can not identify the possible problem of the command :(
>
> That's only stderror. You should still see the standard input and check for 
> $? value.  Not perfect but I think this can get you started. I must say I am 
> against this deprecation warning and I'll make an effort to find other ways 
> of doing that
>
>> It may be possible exclude DeprecationWarning from the code in next version 
>> 4.0.4 :) ?
>
> I know VDSM guys started working on that but its WIP. Can you please open a 
> bug for that and I'll make sure to put it on the right person?
>
>> 18.09.2016, 09:27, "Roy Golan" :
>>> Try to point stderr to /dev/null. For example this should work:
>>>
>>> ```bash
>>> vdsClient -s 0 list table 2> /dev/null
>>> ```
>>>
>>> On 18 September 2016 at 08:59,  wrote:
 Hello oVirt guru`s !

 Every time I call the commands:

 * hosted-engine --set-maintenance --mode=global
 * hosted-engine --set-maintenance --mode=none

 The message appears:

 /usr/lib/python2.7/site-packages/ovirt_hosted_engine_ha/lib/storage_backends.py:15:
  DeprecationWarning: vdscli uses xmlrpc. since ovirt 3.6 xmlrpc is 
 deprecated, please use vdsm.jsonrpcvdscli
   import vdsm.vdscli
 ...

 This message prevents tracking the status of execution of commands in my 
 scripts.

 How can I suppress this message?
 ___
 Users mailing list
 Users@ovirt.org
 http://lists.ovirt.org/mailman/listinfo/users
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] DeprecationWarning: vdscli uses xmlrpc. since ovirt 3.6 xmlrpc is deprecated, please use vdsm.jsonrpcvdscli

2016-09-18 Thread aleksey . maksimov
Thanks Roy


But if I'm going to redirect the output of the hosted-engine command to 
/dev/null, I can not identify the possible problem of the command :(

It may be possible exclude DeprecationWarning from the code in next version 
4.0.4 :) ?

18.09.2016, 09:27, "Roy Golan" :
> Try to point stderr to /dev/null. For example this should work:
>
> ```bash
> vdsClient -s 0 list table 2> /dev/null
> ```
>
> On 18 September 2016 at 08:59,  wrote:
>> Hello oVirt guru`s !
>>
>> Every time I call the commands:
>>
>> * hosted-engine --set-maintenance --mode=global
>> * hosted-engine --set-maintenance --mode=none
>>
>> The message appears:
>>
>> /usr/lib/python2.7/site-packages/ovirt_hosted_engine_ha/lib/storage_backends.py:15:
>>  DeprecationWarning: vdscli uses xmlrpc. since ovirt 3.6 xmlrpc is 
>> deprecated, please use vdsm.jsonrpcvdscli
>>   import vdsm.vdscli
>> ...
>>
>> This message prevents tracking the status of execution of commands in my 
>> scripts.
>>
>> How can I suppress this message?
>> ___
>> Users mailing list
>> Users@ovirt.org
>> http://lists.ovirt.org/mailman/listinfo/users
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] DeprecationWarning: vdscli uses xmlrpc. since ovirt 3.6 xmlrpc is deprecated, please use vdsm.jsonrpcvdscli

2016-09-17 Thread aleksey . maksimov
Hello oVirt guru`s !

Every time I call the commands:

* hosted-engine --set-maintenance --mode=global
* hosted-engine --set-maintenance --mode=none

The message appears:

/usr/lib/python2.7/site-packages/ovirt_hosted_engine_ha/lib/storage_backends.py:15:
 DeprecationWarning: vdscli uses xmlrpc. since ovirt 3.6 xmlrpc is deprecated, 
please use vdsm.jsonrpcvdscli
  import vdsm.vdscli
...

This message prevents tracking the status of execution of commands in my 
scripts.

How can I suppress this message?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] oVirt 4.0.3 (Hosted Engine) - High Availability VM not restart after auto-fencing of host.

2016-09-16 Thread aleksey . maksimov
"your VM would be killed uncleanly."

This is not a good idea, I think


16.09.2016, 17:14, "Michal Skrivanek" :
>>  On 16 Sep 2016, at 16:02, aleksey.maksi...@it-kb.ru wrote:
>>
>>  So, colleagues.
>>  I again tested the Fencing and now I think that my host-server power-button 
>> (physically or through ILO) sends a KILL-command to the host OS (and as a 
>> result to VM)
>
> thanks for confirmation, then it is indeed 
> https://bugzilla.redhat.com/show_bug.cgi?id=1341106
>
> I’m not sure if there is any good workaround. You can always 
> reconfigure(disable) ACPI in the guest, then HA logic would work ok but it 
> also means there is no graceful shutdown and your VM would be killed 
> uncleanly.
>
>>  This journald log in my guest OS when I press the power-button on the host:
>>
>>  ..
>>  Sep 16 16:19:27 KOM-AD01-PBX02 systemd[1]: Stopping ACPI event daemon...
>>  Sep 16 16:19:27 KOM-AD01-PBX02 systemd[1]: Stopping User Manager for UID 
>> 1000...
>>  Sep 16 16:19:27 KOM-AD01-PBX02 systemd[1]: Starting Unattended Upgrades 
>> Shutdown...
>>  Sep 16 16:19:27 KOM-AD01-PBX02 snapd[2583]: 2016/09/16 16:19:27.289063 
>> main.go:67: Exiting on terminated signal.
>>  Sep 16 16:19:27 KOM-AD01-PBX02 sshd[2940]: pam_unix(sshd:session): session 
>> closed for user user
>>  Sep 16 16:19:27 KOM-AD01-PBX02 su[3015]: pam_unix(su:session): session 
>> closed for user root
>>  Sep 16 16:19:27 KOM-AD01-PBX02 spice-vdagentd[2638]: vdagentd quiting, 
>> returning status 0
>>  Sep 16 16:19:27 KOM-AD01-PBX02 sudo[3014]: pam_unix(sudo:session): session 
>> closed for user root
>>  Sep 16 16:19:27 KOM-AD01-PBX02 /usr/lib/snapd/snapd[2583]: main.go:67: 
>> Exiting on terminated signal.
>>  Sep 16 16:19:27 KOM-AD01-PBX02 sshd[2812]: Received signal 15; terminating.
>>  ..
>>  Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Reached target Unmount All 
>> Filesystems.
>>  Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Stopped target Local File 
>> Systems (Pre).
>>  Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Stopping Monitoring of LVM2 
>> mirrors, snapshots etc. using dmeventd or progress polling...
>>  Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Stopped Remount Root and Kernel 
>> File Systems.
>>  Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Stopped Create Static Device 
>> Nodes in /dev.
>>  Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Reached target Shutdown.
>>  Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Reached target Final Step.
>>  Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Starting Reboot...
>>  Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Stopped Monitoring of LVM2 
>> mirrors, snapshots etc. using dmeventd or progress polling.
>>  Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Shutting down.
>>  Sep 16 16:19:28 KOM-AD01-PBX02 kernel: [drm:qxl_enc_commit [qxl]] *ERROR* 
>> head number too large or missing monitors config: c984a000, 
>> 0systemd-shutdown[1]: Sending SIGTERM to remaining processes...
>>  Sep 16 16:19:28 KOM-AD01-PBX02 systemd-journald[3342]: Journal stopped
>>  -- Reboot --
>>
>>  Perhaps this feature of HP ProLiant DL 360 G5. I dont know.
>>
>>  If I test the unavailability of a host other ways that everything is going 
>> well.
>>
>>  I described my experience testing Fencing on practical examples on my blog 
>> for everyone in Russian.
>>  
>> https://blog.it-kb.ru/2016/09/16/install-ovirt-4-0-part-4-about-ssh-soft-fencing-and-hard-fencing-over-hp-proliant-ilo2-power-managment-agent-and-test-of-high-availability/
>>
>>  Thank you all very much for your participation and support.
>>
>>  Michal, what kind of scenario are you talking about?
>>
>>  PS: Excuse me for my bad English :)
>>
>>  16.09.2016, 16:37, "Simone Tiraboschi" :
>>>  On Fri, Sep 16, 2016 at 3:34 PM, Michal Skrivanek 
>>>  wrote:
>  On 16 Sep 2016, at 15:31, aleksey.maksi...@it-kb.ru wrote:
>
>  Hi Simone.
>  Exactly.
>  Now I'll put the journald on the guest and try to understand how the 
> guest off.

  great. thanks

>  16.09.2016, 16:25, "Simone Tiraboschi" :
>>  On Fri, Sep 16, 2016 at 3:13 PM, Michal Skrivanek 
>>  wrote:
  On 16 Sep 2016, at 15:05, Gianluca Cecchi  
 wrote:

  On Fri, Sep 16, 2016 at 2:50 PM, Michal Skrivanek 
  wrote:
>  no, that’s not how HA works today. When you log into a guest and 
> issue “shutdown” we do not restart the VM under your hands. We can 
> argue how it should or may work, but this is the defined behavior 
> since the dawn of oVirt.
>
>>  ​AFAIK that's correct, we need to be able ​
>>  ​shutdown HA VM​
>>  ​
>>  ​ without being it immediately restarted on different host. We want 
>> to restart HA VM only if host, where HA VM is running, is 
>> 

Re: [ovirt-users] oVirt 4.0.3 (Hosted Engine) - High Availability VM not restart after auto-fencing of host.

2016-09-16 Thread aleksey . maksimov
Тested.

If I run 'shutdown -h now' on host with running HA VM (not HostedEngine VM)...

in oVirt web-console appears event:

Sep 16, 2016 5:13:18 PM VM KOM-AD01-PBX02 is down. Exit message: User shut down 
from within the guest

HA VM is turned off and will not start on another host.

This journald log from HA VM guest OS:

...
Sep 16 17:06:48 KOM-AD01-PBX02 python[2637]: [100B blob data]
Sep 16 17:06:53 KOM-AD01-PBX02 systemd-timesyncd[1739]: Timed out waiting for 
reply from 91.189.91.157:123 (ntp.ubuntu.com).
Sep 16 17:07:03 KOM-AD01-PBX02 systemd-timesyncd[1739]: Timed out waiting for 
reply from 91.189.89.199:123 (ntp.ubuntu.com).
Sep 16 17:07:13 KOM-AD01-PBX02 systemd-timesyncd[1739]: Timed out waiting for 
reply from 91.189.89.198:123 (ntp.ubuntu.com).
Sep 16 17:07:23 KOM-AD01-PBX02 systemd-timesyncd[1739]: Timed out waiting for 
reply from 91.189.94.4:123 (ntp.ubuntu.com).
Sep 16 17:08:48 KOM-AD01-PBX02 python[2637]: [90B blob data]
Sep 16 17:08:49 KOM-AD01-PBX02 python[2637]: [155B blob data]
Sep 16 17:08:49 KOM-AD01-PBX02 python[2637]: [100B blob data]
Sep 16 17:10:49 KOM-AD01-PBX02 python[2637]: [90B blob data]
Sep 16 17:10:50 KOM-AD01-PBX02 python[2637]: [155B blob data]
Sep 16 17:10:50 KOM-AD01-PBX02 python[2637]: [100B blob data]
-- Reboot --
...

Before shutting down in the log no termination procedures.
It looks like a rough poweroff the VM

16.09.2016, 17:08, "Simone Tiraboschi" :
> On Fri, Sep 16, 2016 at 4:02 PM,  wrote:
>> So, colleagues.
>> I again tested the Fencing and now I think that my host-server power-button 
>> (physically or through ILO) sends a KILL-command to the host OS (and as a 
>> result to VM)
>> This journald log in my guest OS when I press the power-button on the host:
>>
>> ...
>> Sep 16 16:19:27 KOM-AD01-PBX02 systemd[1]: Stopping ACPI event daemon...
>> Sep 16 16:19:27 KOM-AD01-PBX02 systemd[1]: Stopping User Manager for UID 
>> 1000...
>> Sep 16 16:19:27 KOM-AD01-PBX02 systemd[1]: Starting Unattended Upgrades 
>> Shutdown...
>> Sep 16 16:19:27 KOM-AD01-PBX02 snapd[2583]: 2016/09/16 16:19:27.289063 
>> main.go:67: Exiting on terminated signal.
>> Sep 16 16:19:27 KOM-AD01-PBX02 sshd[2940]: pam_unix(sshd:session): session 
>> closed for user user
>> Sep 16 16:19:27 KOM-AD01-PBX02 su[3015]: pam_unix(su:session): session 
>> closed for user root
>> Sep 16 16:19:27 KOM-AD01-PBX02 spice-vdagentd[2638]: vdagentd quiting, 
>> returning status 0
>> Sep 16 16:19:27 KOM-AD01-PBX02 sudo[3014]: pam_unix(sudo:session): session 
>> closed for user root
>> Sep 16 16:19:27 KOM-AD01-PBX02 /usr/lib/snapd/snapd[2583]: main.go:67: 
>> Exiting on terminated signal.
>> Sep 16 16:19:27 KOM-AD01-PBX02 sshd[2812]: Received signal 15; terminating.
>> ...
>> Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Reached target Unmount All 
>> Filesystems.
>> Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Stopped target Local File Systems 
>> (Pre).
>> Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Stopping Monitoring of LVM2 
>> mirrors, snapshots etc. using dmeventd or progress polling...
>> Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Stopped Remount Root and Kernel 
>> File Systems.
>> Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Stopped Create Static Device 
>> Nodes in /dev.
>> Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Reached target Shutdown.
>> Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Reached target Final Step.
>> Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Starting Reboot...
>> Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Stopped Monitoring of LVM2 
>> mirrors, snapshots etc. using dmeventd or progress polling.
>> Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Shutting down.
>> Sep 16 16:19:28 KOM-AD01-PBX02 kernel: [drm:qxl_enc_commit [qxl]] *ERROR* 
>> head number too large or missing monitors config: c984a000, 
>> 0systemd-shutdown[1]: Sending SIGTERM to remaining processes...
>> Sep 16 16:19:28 KOM-AD01-PBX02 systemd-journald[3342]: Journal stopped
>> -- Reboot --
>>
>> Perhaps this feature of HP ProLiant DL 360 G5. I dont know.
>>
>> If I test the unavailability of a host other ways that everything is going 
>> well.
>>
>> I described my experience testing Fencing on practical examples on my blog 
>> for everyone in Russian.
>> https://blog.it-kb.ru/2016/09/16/install-ovirt-4-0-part-4-about-ssh-soft-fencing-and-hard-fencing-over-hp-proliant-ilo2-power-managment-agent-and-test-of-high-availability/
>>
>> Thank you all very much for your participation and support.
>>
>> Michal, what kind of scenario are you talking about?
>
> Basically what you just did,
> the question is what happens when you run 'shutdown -h now' (or press the 
> physical button if configured to trigger a soft shutdown); is it going to 
> propagate somehow the shutdown action to the VMs or to brutally kill them?
>
> In the first case the VMs will not restart regardless of their HA flags.
>
>> PS: Excuse me for my bad English :)
>>
>> 16.09.2016, 16:37, "Simone Tiraboschi" 

Re: [ovirt-users] oVirt 4.0.3 (Hosted Engine) - High Availability VM not restart after auto-fencing of host.

2016-09-16 Thread aleksey . maksimov
So, colleagues. 
I again tested the Fencing and now I think that my host-server power-button 
(physically or through ILO) sends a KILL-command to the host OS (and as a 
result to VM)
This journald log in my guest OS when I press the power-button on the host:

...
Sep 16 16:19:27 KOM-AD01-PBX02 systemd[1]: Stopping ACPI event daemon...
Sep 16 16:19:27 KOM-AD01-PBX02 systemd[1]: Stopping User Manager for UID 1000...
Sep 16 16:19:27 KOM-AD01-PBX02 systemd[1]: Starting Unattended Upgrades 
Shutdown...
Sep 16 16:19:27 KOM-AD01-PBX02 snapd[2583]: 2016/09/16 16:19:27.289063 
main.go:67: Exiting on terminated signal.
Sep 16 16:19:27 KOM-AD01-PBX02 sshd[2940]: pam_unix(sshd:session): session 
closed for user user
Sep 16 16:19:27 KOM-AD01-PBX02 su[3015]: pam_unix(su:session): session closed 
for user root
Sep 16 16:19:27 KOM-AD01-PBX02 spice-vdagentd[2638]: vdagentd quiting, 
returning status 0
Sep 16 16:19:27 KOM-AD01-PBX02 sudo[3014]: pam_unix(sudo:session): session 
closed for user root
Sep 16 16:19:27 KOM-AD01-PBX02 /usr/lib/snapd/snapd[2583]: main.go:67: Exiting 
on terminated signal.
Sep 16 16:19:27 KOM-AD01-PBX02 sshd[2812]: Received signal 15; terminating.
...
Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Reached target Unmount All 
Filesystems.
Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Stopped target Local File Systems 
(Pre).
Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Stopping Monitoring of LVM2 mirrors, 
snapshots etc. using dmeventd or progress polling...
Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Stopped Remount Root and Kernel File 
Systems.
Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Stopped Create Static Device Nodes 
in /dev.
Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Reached target Shutdown.
Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Reached target Final Step.
Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Starting Reboot...
Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Stopped Monitoring of LVM2 mirrors, 
snapshots etc. using dmeventd or progress polling.
Sep 16 16:19:28 KOM-AD01-PBX02 systemd[1]: Shutting down.
Sep 16 16:19:28 KOM-AD01-PBX02 kernel: [drm:qxl_enc_commit [qxl]] *ERROR* head 
number too large or missing monitors config: c984a000, 
0systemd-shutdown[1]: Sending SIGTERM to remaining processes...
Sep 16 16:19:28 KOM-AD01-PBX02 systemd-journald[3342]: Journal stopped
-- Reboot --

Perhaps this feature of HP ProLiant DL 360 G5. I dont know.

If I test the unavailability of a host other ways that everything is going well.

I described my experience testing Fencing on practical examples on my blog for 
everyone in Russian.
https://blog.it-kb.ru/2016/09/16/install-ovirt-4-0-part-4-about-ssh-soft-fencing-and-hard-fencing-over-hp-proliant-ilo2-power-managment-agent-and-test-of-high-availability/


Thank you all very much for your participation and support.

Michal, what kind of scenario are you talking about?


PS: Excuse me for my bad English :)


16.09.2016, 16:37, "Simone Tiraboschi" :
> On Fri, Sep 16, 2016 at 3:34 PM, Michal Skrivanek 
>  wrote:
>>> On 16 Sep 2016, at 15:31, aleksey.maksi...@it-kb.ru wrote:
>>>
>>> Hi Simone.
>>> Exactly.
>>> Now I'll put the journald on the guest and try to understand how the guest 
>>> off.
>>
>> great. thanks
>>
>>> 16.09.2016, 16:25, "Simone Tiraboschi" :
 On Fri, Sep 16, 2016 at 3:13 PM, Michal Skrivanek 
  wrote:
>> On 16 Sep 2016, at 15:05, Gianluca Cecchi  
>> wrote:
>>
>> On Fri, Sep 16, 2016 at 2:50 PM, Michal Skrivanek 
>>  wrote:
>>> no, that’s not how HA works today. When you log into a guest and issue 
>>> “shutdown” we do not restart the VM under your hands. We can argue how 
>>> it should or may work, but this is the defined behavior since the dawn 
>>> of oVirt.
>>>
 ​AFAIK that's correct, we need to be able ​
 ​shutdown HA VM​
 ​
 ​ without being it immediately restarted on different host. We want to 
 restart HA VM only if host, where HA VM is running, is non-responsive.
>>>
>>> we try to restart it in all other cases other than user initiated 
>>> shutdown, e.g. a QEMU process crash on an otherwise-healthy host
>> Hi, just another question in case HA is not configured at all.
>
> by “HA configured” I expect you’re referring to the “Highly Available” 
> checkbox in Edit VM dialog.
>
>> If I run the "shutdown -h now" command on an host where some VMs are 
>> running, what is the expected behavior?
>> Clean VM shutdown (with or without timeout in case it doesn't complete?) 
>> or crash of their related QEMU processes?
>
> expectation is that you won’t do that. That’s why there is the 
> Maintenance host state.
> But if you do that regardless, with VMs running, all the processes will 
> be terminated in a regular system way, i.e. all 

Re: [ovirt-users] oVirt 4.0.3 (Hosted Engine) - High Availability VM not restart after auto-fencing of host.

2016-09-16 Thread aleksey . maksimov
Hi Simone.Exactly.Now I'll put the journald on the guest and try to understand how the guest off. 16.09.2016, 16:25, "Simone Tiraboschi" :  On Fri, Sep 16, 2016 at 3:13 PM, Michal Skrivanek  wrote: On 16 Sep 2016, at 15:05, Gianluca Cecchi  wrote: On Fri, Sep 16, 2016 at 2:50 PM, Michal Skrivanek  wrote: no, that’s not how HA works today. When you log into a guest and issue “shutdown” we do not restart the VM under your hands. We can argue how it should or may work, but this is the defined behavior since the dawn of oVirt.  ​AFAIK that's correct, we need to be able ​​shutdown HA VM​​​ without being it immediately restarted on different host. We want to restart HA VM only if host, where HA VM is running, is non-responsive. we try to restart it in all other cases other than user initiated shutdown, e.g. a QEMU process crash on an otherwise-healthy host Hi, just another question in case HA is not configured at all. by “HA configured” I expect you’re referring to the “Highly Available” checkbox in Edit VM dialog. If I run the "shutdown -h now" command on an host where some VMs are running, what is the expected behavior?Clean VM shutdown (with or without timeout in case it doesn't complete?) or crash of their related QEMU processes? expectation is that you won’t do that. That’s why there is the Maintenance host state.But if you do that regardless, with VMs running, all the processes will be terminated in a regular system way, i.e. all QEMU processes get SIGTERM. From the perspective of each guest this is not a clean shutdown and it would just get killed   Aleksey is reporting that he started a shutdown on his host by power management and the VM processes didn't get roughly killed but smoothly shut down and so they didn't restarted regardless of their HA flag and so this thread.   Thanks,michal Thanks,Gianluca___Users mailing listUsers@ovirt.orghttp://lists.ovirt.org/mailman/listinfo/users___Users mailing listUsers@ovirt.orghttp://lists.ovirt.org/mailman/listinfo/users ___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] oVirt 4.0.3 (Hosted Engine) - High Availability VM not restart after auto-fencing of host.

2016-09-16 Thread aleksey . maksimov
There are more ideas?

15.09.2016, 14:40, "aleksey.maksi...@it-kb.ru" :
> Martin, I physically turned off the server through the iLO2. See screenshots.
> I did not touch Virtual Machine (KOM-AD01-PBX02) at the same time.
> The virtual machine has been turned on at the time when the host shut down.
>
> 15.09.2016, 14:27, "Martin Perina" :
>>  Hi,
>>
>>  I found out this in the log:
>>
>>  2016-09-15 12:02:04,661 INFO  
>> [org.ovirt.engine.core.vdsbroker.monitoring.VmAnalyzer] 
>> (ForkJoinPool-1-worker-6) [] VM 
>> '660bafca-e9c3-4191-99b4-295ff8553488'(KOM-AD01-PBX02) moved from 'Up' --> 
>> 'Down'
>>  2016-09-15 12:02:04,788 INFO  
>> [org.ovirt.engine.core.dal.dbbroker.auditloghandling.AuditLogDirector] 
>> (ForkJoinPool-1-worker-6) [] Correlation ID: null, Call Stack: null, Custom 
>> Event ID: -1, Message: VM KOM-AD01-PBX02 is down. Exit message: User shut 
>> down from within the guest
>>
>>  If I'm not mistaken, this means that VM was properly shutted down from 
>> within itself and in that case it's not restarted automatically. So I'm 
>> curious what actions have you made to make host KOM-AD01-VM31 non-responsive?
>>
>>  If you want to test fencing properly, then I suggest you to either block 
>> connection between host and engine on host side and forcibly stop ovirtmgmt 
>> network interface on host and watch fencing is applied.
>>
>>  Martin
>>
>>  On Thu, Sep 15, 2016 at 1:16 PM,  wrote:
>>>  engine.log for this period.
>>>
>>>  15.09.2016, 14:01, "Martin Perina" :
  On Thu, Sep 15, 2016 at 12:47 PM,  wrote:
>  Hi Martin.
>  I have a stupid question. Use Watchdog device mandatory to automatically 
> start a virtual machine in host Fencing process?

  ​AFAIK it's not, but I'm not na expert, adding Arik.

  You need correct power management setup for the hosts and VM has to be 
 marked as highly available​ for sure.

>  15.09.2016, 13:43, "Martin Perina" :
>>  Hi,
>>
>>  could you please share whole engine.log?
>>
>>  Thanks
>>
>>  Martin Perina
>>
>>  On Thu, Sep 15, 2016 at 12:01 PM,  wrote:
>>>  Hello oVirt guru`s !
>>>
>>>  I have oVirt Hosted Engine 4.0.3-1.el7.centos on two CentOS 7.2 hosts 
>>> (HP ProLiant DL 360 G5) connected to shared FC SAN Storage.
>>>
>>>  1. I configured Power Management for the Hosts (successfully added 
>>> Fencing Agent for iLO2 from my hosts)
>>>
>>>  2. I created new VM (KOM-AD01-PBX02) and installed Guest OS (Ubuntu 
>>> Server 16.04 LTS) and oVirt Guest Agent
>>>  (As described herein 
>>> https://blog.it-kb.ru/2016/09/14/install-ovirt-4-0-part-2-about-data-center-iso-domain-logical-network-vlan-vm-settings-console-guest-agent-live-migration/)
>>>     In VM settings on "High Availability" I turned on the option 
>>> "Highly Available" and change "Priority" to "High"
>>>
>>>  3. Now I'm trying to check Hard-Fencing and power off my first host 
>>> (KOM-AD01-VM31) from his iLO (KOM-AD01-ILO31).
>>>
>>>  Fencing successfully works and server is automatically turned on, but 
>>> my HA VM not started on second host (KOM-AD01-VM32).
>>>
>>>  These events I see in the oVirt web console:
>>>
>>>  Sep 15, 2016 12:08:13 PM        Host KOM-AD01-VM31 power management 
>>> was verified successfully.
>>>  Sep 15, 2016 12:08:13 PM        Status of host KOM-AD01-VM31 was set 
>>> to Up.
>>>  Sep 15, 2016 12:08:05 PM        Executing power management status on 
>>> Host KOM-AD01-VM31 using Proxy Host KOM-AD01-VM32 and Fence Agent 
>>> ilo:KOM-AD01-ILO31.holding.com.
>>>  Sep 15, 2016 12:05:48 PM        Host KOM-AD01-VM31 is rebooting.
>>>  Sep 15, 2016 12:05:48 PM        Host KOM-AD01-VM31 was started by 
>>> SYSTEM.
>>>  Sep 15, 2016 12:05:48 PM        Power management start of Host 
>>> KOM-AD01-VM31 succeeded.
>>>  Sep 15, 2016 12:05:41 PM        Executing power management status on 
>>> Host KOM-AD01-VM31 using Proxy Host KOM-AD01-VM32 and Fence Agent 
>>> ilo:KOM-AD01-ILO31.holding.com.
>>>  Sep 15, 2016 12:05:19 PM        Executing power management start on 
>>> Host KOM-AD01-VM31 using Proxy Host KOM-AD01-VM32 and Fence Agent 
>>> ilo:KOM-AD01-ILO31.holding.com.
>>>  Sep 15, 2016 12:05:19 PM        Power management start of Host 
>>> KOM-AD01-VM31 initiated.
>>>  Sep 15, 2016 12:05:19 PM        Auto fence for host KOM-AD01-VM31 was 
>>> started.
>>>  Sep 15, 2016 12:05:11 PM        Executing power management status on 
>>> Host KOM-AD01-VM31 using Proxy Host KOM-AD01-VM32 and Fence Agent 
>>> ilo:KOM-AD01-ILO31.holding.com.
>>>  Sep 15, 2016 12:05:04 PM        Executing power management status on 
>>> Host KOM-AD01-VM31 using 

Re: [ovirt-users] oVirt 4.0.3 (Hosted Engine) - High Availability VM not restart after auto-fencing of host.

2016-09-15 Thread aleksey . maksimov
Martin, I physically turned off the server through the iLO2. See screenshots.
I did not touch Virtual Machine (KOM-AD01-PBX02) at the same time.
The virtual machine has been turned on at the time when the host shut down.

15.09.2016, 14:27, "Martin Perina" :
> Hi,
>
> I found out this in the log:
>
> 2016-09-15 12:02:04,661 INFO  
> [org.ovirt.engine.core.vdsbroker.monitoring.VmAnalyzer] 
> (ForkJoinPool-1-worker-6) [] VM 
> '660bafca-e9c3-4191-99b4-295ff8553488'(KOM-AD01-PBX02) moved from 'Up' --> 
> 'Down'
> 2016-09-15 12:02:04,788 INFO  
> [org.ovirt.engine.core.dal.dbbroker.auditloghandling.AuditLogDirector] 
> (ForkJoinPool-1-worker-6) [] Correlation ID: null, Call Stack: null, Custom 
> Event ID: -1, Message: VM KOM-AD01-PBX02 is down. Exit message: User shut 
> down from within the guest
>
> If I'm not mistaken, this means that VM was properly shutted down from within 
> itself and in that case it's not restarted automatically. So I'm curious what 
> actions have you made to make host KOM-AD01-VM31 non-responsive?
>
> If you want to test fencing properly, then I suggest you to either block 
> connection between host and engine on host side and forcibly stop ovirtmgmt 
> network interface on host and watch fencing is applied.
>
> Martin
>
> On Thu, Sep 15, 2016 at 1:16 PM,  wrote:
>> engine.log for this period.
>>
>> 15.09.2016, 14:01, "Martin Perina" :
>>> On Thu, Sep 15, 2016 at 12:47 PM,  wrote:
 Hi Martin.
 I have a stupid question. Use Watchdog device mandatory to automatically 
 start a virtual machine in host Fencing process?
>>>
>>> ​AFAIK it's not, but I'm not na expert, adding Arik.
>>>
>>> You need correct power management setup for the hosts and VM has to be 
>>> marked as highly available​ for sure.
>>>
 15.09.2016, 13:43, "Martin Perina" :
> Hi,
>
> could you please share whole engine.log?
>
> Thanks
>
> Martin Perina
>
> On Thu, Sep 15, 2016 at 12:01 PM,  wrote:
>> Hello oVirt guru`s !
>>
>> I have oVirt Hosted Engine 4.0.3-1.el7.centos on two CentOS 7.2 hosts 
>> (HP ProLiant DL 360 G5) connected to shared FC SAN Storage.
>>
>> 1. I configured Power Management for the Hosts (successfully added 
>> Fencing Agent for iLO2 from my hosts)
>>
>> 2. I created new VM (KOM-AD01-PBX02) and installed Guest OS (Ubuntu 
>> Server 16.04 LTS) and oVirt Guest Agent
>> (As described herein 
>> https://blog.it-kb.ru/2016/09/14/install-ovirt-4-0-part-2-about-data-center-iso-domain-logical-network-vlan-vm-settings-console-guest-agent-live-migration/)
>>    In VM settings on "High Availability" I turned on the option "Highly 
>> Available" and change "Priority" to "High"
>>
>> 3. Now I'm trying to check Hard-Fencing and power off my first host 
>> (KOM-AD01-VM31) from his iLO (KOM-AD01-ILO31).
>>
>> Fencing successfully works and server is automatically turned on, but my 
>> HA VM not started on second host (KOM-AD01-VM32).
>>
>> These events I see in the oVirt web console:
>>
>> Sep 15, 2016 12:08:13 PM        Host KOM-AD01-VM31 power management was 
>> verified successfully.
>> Sep 15, 2016 12:08:13 PM        Status of host KOM-AD01-VM31 was set to 
>> Up.
>> Sep 15, 2016 12:08:05 PM        Executing power management status on 
>> Host KOM-AD01-VM31 using Proxy Host KOM-AD01-VM32 and Fence Agent 
>> ilo:KOM-AD01-ILO31.holding.com.
>> Sep 15, 2016 12:05:48 PM        Host KOM-AD01-VM31 is rebooting.
>> Sep 15, 2016 12:05:48 PM        Host KOM-AD01-VM31 was started by SYSTEM.
>> Sep 15, 2016 12:05:48 PM        Power management start of Host 
>> KOM-AD01-VM31 succeeded.
>> Sep 15, 2016 12:05:41 PM        Executing power management status on 
>> Host KOM-AD01-VM31 using Proxy Host KOM-AD01-VM32 and Fence Agent 
>> ilo:KOM-AD01-ILO31.holding.com.
>> Sep 15, 2016 12:05:19 PM        Executing power management start on Host 
>> KOM-AD01-VM31 using Proxy Host KOM-AD01-VM32 and Fence Agent 
>> ilo:KOM-AD01-ILO31.holding.com.
>> Sep 15, 2016 12:05:19 PM        Power management start of Host 
>> KOM-AD01-VM31 initiated.
>> Sep 15, 2016 12:05:19 PM        Auto fence for host KOM-AD01-VM31 was 
>> started.
>> Sep 15, 2016 12:05:11 PM        Executing power management status on 
>> Host KOM-AD01-VM31 using Proxy Host KOM-AD01-VM32 and Fence Agent 
>> ilo:KOM-AD01-ILO31.holding.com.
>> Sep 15, 2016 12:05:04 PM        Executing power management status on 
>> Host KOM-AD01-VM31 using Proxy Host KOM-AD01-VM32 and Fence Agent 
>> ilo:KOM-AD01-ILO31.holding.com.
>> Sep 15, 2016 12:05:04 PM        Host KOM-AD01-VM31 is non responsive.
>> Sep 15, 2016 12:02:32 PM        Host KOM-AD01-VM31 is not responding. It 
>> will stay in 

Re: [ovirt-users] oVirt 4.0.3 (Hosted Engine) - High Availability VM not restart after auto-fencing of host.

2016-09-15 Thread aleksey . maksimov
Hi Martin.I have a stupid question. Use Watchdog device mandatory to automatically start a virtual machine in host Fencing process? 15.09.2016, 13:43, "Martin Perina" :Hi, could you please share whole engine.log? Thanks Martin Perina  On Thu, Sep 15, 2016 at 12:01 PM,  wrote:Hello oVirt guru`s !I have oVirt Hosted Engine 4.0.3-1.el7.centos on two CentOS 7.2 hosts (HP ProLiant DL 360 G5) connected to shared FC SAN Storage.1. I configured Power Management for the Hosts (successfully added Fencing Agent for iLO2 from my hosts)2. I created new VM (KOM-AD01-PBX02) and installed Guest OS (Ubuntu Server 16.04 LTS) and oVirt Guest Agent(As described herein https://blog.it-kb.ru/2016/09/14/install-ovirt-4-0-part-2-about-data-center-iso-domain-logical-network-vlan-vm-settings-console-guest-agent-live-migration/)   In VM settings on "High Availability" I turned on the option "Highly Available" and change "Priority" to "High"3. Now I'm trying to check Hard-Fencing and power off my first host (KOM-AD01-VM31) from his iLO (KOM-AD01-ILO31).Fencing successfully works and server is automatically turned on, but my HA VM not started on second host (KOM-AD01-VM32).These events I see in the oVirt web console:Sep 15, 2016 12:08:13 PM        Host KOM-AD01-VM31 power management was verified successfully.Sep 15, 2016 12:08:13 PM        Status of host KOM-AD01-VM31 was set to Up.Sep 15, 2016 12:08:05 PM        Executing power management status on Host KOM-AD01-VM31 using Proxy Host KOM-AD01-VM32 and Fence Agent ilo:KOM-AD01-ILO31.holding.com.Sep 15, 2016 12:05:48 PM        Host KOM-AD01-VM31 is rebooting.Sep 15, 2016 12:05:48 PM        Host KOM-AD01-VM31 was started by SYSTEM.Sep 15, 2016 12:05:48 PM        Power management start of Host KOM-AD01-VM31 succeeded.Sep 15, 2016 12:05:41 PM        Executing power management status on Host KOM-AD01-VM31 using Proxy Host KOM-AD01-VM32 and Fence Agent ilo:KOM-AD01-ILO31.holding.com.Sep 15, 2016 12:05:19 PM        Executing power management start on Host KOM-AD01-VM31 using Proxy Host KOM-AD01-VM32 and Fence Agent ilo:KOM-AD01-ILO31.holding.com.Sep 15, 2016 12:05:19 PM        Power management start of Host KOM-AD01-VM31 initiated.Sep 15, 2016 12:05:19 PM        Auto fence for host KOM-AD01-VM31 was started.Sep 15, 2016 12:05:11 PM        Executing power management status on Host KOM-AD01-VM31 using Proxy Host KOM-AD01-VM32 and Fence Agent ilo:KOM-AD01-ILO31.holding.com.Sep 15, 2016 12:05:04 PM        Executing power management status on Host KOM-AD01-VM31 using Proxy Host KOM-AD01-VM32 and Fence Agent ilo:KOM-AD01-ILO31.holding.com.Sep 15, 2016 12:05:04 PM        Host KOM-AD01-VM31 is non responsive.Sep 15, 2016 12:02:32 PM        Host KOM-AD01-VM31 is not responding. It will stay in Connecting state for a grace period of 60 seconds and after that an attempt to fence the host will be issued.Sep 15, 2016 12:02:32 PM        VDSM KOM-AD01-VM31 command failed: Heartbeat exeededSep 15, 2016 12:02:04 PM        VM KOM-AD01-PBX02 is down. Exit message: User shut down from within the guestWhat am I doing wrong? Why HA VM not start on a second host?___Users mailing listUsers@ovirt.orghttp://lists.ovirt.org/mailman/listinfo/users___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] oVirt 4.0.3 (Hosted Engine) - High Availability VM not restart after auto-fencing of host.

2016-09-15 Thread aleksey . maksimov
Hello oVirt guru`s !

I have oVirt Hosted Engine 4.0.3-1.el7.centos on two CentOS 7.2 hosts (HP 
ProLiant DL 360 G5) connected to shared FC SAN Storage.

1. I configured Power Management for the Hosts (successfully added Fencing 
Agent for iLO2 from my hosts)

2. I created new VM (KOM-AD01-PBX02) and installed Guest OS (Ubuntu Server 
16.04 LTS) and oVirt Guest Agent 
(As described herein 
https://blog.it-kb.ru/2016/09/14/install-ovirt-4-0-part-2-about-data-center-iso-domain-logical-network-vlan-vm-settings-console-guest-agent-live-migration/)
   In VM settings on "High Availability" I turned on the option "Highly 
Available" and change "Priority" to "High"

3. Now I'm trying to check Hard-Fencing and power off my first host 
(KOM-AD01-VM31) from his iLO (KOM-AD01-ILO31).

Fencing successfully works and server is automatically turned on, but my HA VM 
not started on second host (KOM-AD01-VM32).

These events I see in the oVirt web console:

Sep 15, 2016 12:08:13 PMHost KOM-AD01-VM31 power management was 
verified successfully.
Sep 15, 2016 12:08:13 PMStatus of host KOM-AD01-VM31 was set to Up.
Sep 15, 2016 12:08:05 PMExecuting power management status on Host 
KOM-AD01-VM31 using Proxy Host KOM-AD01-VM32 and Fence Agent 
ilo:KOM-AD01-ILO31.holding.com.
Sep 15, 2016 12:05:48 PMHost KOM-AD01-VM31 is rebooting.
Sep 15, 2016 12:05:48 PMHost KOM-AD01-VM31 was started by SYSTEM.
Sep 15, 2016 12:05:48 PMPower management start of Host KOM-AD01-VM31 
succeeded.
Sep 15, 2016 12:05:41 PMExecuting power management status on Host 
KOM-AD01-VM31 using Proxy Host KOM-AD01-VM32 and Fence Agent 
ilo:KOM-AD01-ILO31.holding.com.
Sep 15, 2016 12:05:19 PMExecuting power management start on Host 
KOM-AD01-VM31 using Proxy Host KOM-AD01-VM32 and Fence Agent 
ilo:KOM-AD01-ILO31.holding.com.
Sep 15, 2016 12:05:19 PMPower management start of Host KOM-AD01-VM31 
initiated.
Sep 15, 2016 12:05:19 PMAuto fence for host KOM-AD01-VM31 was started.
Sep 15, 2016 12:05:11 PMExecuting power management status on Host 
KOM-AD01-VM31 using Proxy Host KOM-AD01-VM32 and Fence Agent 
ilo:KOM-AD01-ILO31.holding.com.
Sep 15, 2016 12:05:04 PMExecuting power management status on Host 
KOM-AD01-VM31 using Proxy Host KOM-AD01-VM32 and Fence Agent 
ilo:KOM-AD01-ILO31.holding.com.
Sep 15, 2016 12:05:04 PMHost KOM-AD01-VM31 is non responsive.
Sep 15, 2016 12:02:32 PMHost KOM-AD01-VM31 is not responding. It will 
stay in Connecting state for a grace period of 60 seconds and after that an 
attempt to fence the host will be issued.
Sep 15, 2016 12:02:32 PMVDSM KOM-AD01-VM31 command failed: Heartbeat 
exeeded
Sep 15, 2016 12:02:04 PMVM KOM-AD01-PBX02 is down. Exit message: User 
shut down from within the guest


What am I doing wrong? Why HA VM not start on a second host?
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Failed to check for available updates on host * with message 'Command returned failure code 1 during SSH session 'root@*

2016-09-14 Thread aleksey . maksimov
 Problem solved.The cause of the problem was really in the fact that there was no global proxy settings in yum.confThank you all! 14.09.2016, 13:24, "aleksey.maksi...@it-kb.ru" :Hmm..I'll try.How can I call the forced update checking process for oVirt, as well as it happens every night ? 14.09.2016, 13:05, "Gianluca Cecchi" :On Wed, Sep 14, 2016 at 10:40 AM,  wrote:Yesterday I installed the all updates to hosts and Hosted Engine (and now I have oVirt Engine Version: 4.0.3-1.el7.centos)But the problem still persists.==>>> Is this happening consistently or randomly?Consistently. every night.==>>> Do you have any proxy server defined?Yes. I add to end of ~/.bash_profile (for root) three lines:export https_proxy=http://s-MY01-Linux-Upd:passw...@kom-ad01-gwclu.holding.com:3128/export http_proxy=http://s-MY01-Linux-Upd:passw...@kom-ad01-gwclu.holding.com:3128/export ftp_proxy=http://s-MY01-Linux-Upd:passw...@kom-ad01-gwclu.holding.com:3128/  Why not using global proxy config in yum.conf?https://wiki.centos.org/TipsAndTricks/YumAndRPM#head-ea1fc5d78f578114f4843e57627ebae9cc4fcb5a eventually changing permissions of yum.conf if passowrd is to be kept secret (it seems that by default is 644) ___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Failed to check for available updates on host * with message 'Command returned failure code 1 during SSH session 'root@*

2016-09-14 Thread aleksey . maksimov
Hmm..I'll try.How can I call the forced update checking process for oVirt, as well as it happens every night ? 14.09.2016, 13:05, "Gianluca Cecchi" :On Wed, Sep 14, 2016 at 10:40 AM,  wrote:Yesterday I installed the all updates to hosts and Hosted Engine (and now I have oVirt Engine Version: 4.0.3-1.el7.centos)But the problem still persists.==>>> Is this happening consistently or randomly?Consistently. every night.==>>> Do you have any proxy server defined?Yes. I add to end of ~/.bash_profile (for root) three lines:export https_proxy=http://s-MY01-Linux-Upd:passw...@kom-ad01-gwclu.holding.com:3128/export http_proxy=http://s-MY01-Linux-Upd:passw...@kom-ad01-gwclu.holding.com:3128/export ftp_proxy=http://s-MY01-Linux-Upd:passw...@kom-ad01-gwclu.holding.com:3128/  Why not using global proxy config in yum.conf?https://wiki.centos.org/TipsAndTricks/YumAndRPM#head-ea1fc5d78f578114f4843e57627ebae9cc4fcb5a eventually changing permissions of yum.conf if passowrd is to be kept secret (it seems that by default is 644) ___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Failed to check for available updates on host * with message 'Command returned failure code 1 during SSH session 'root@*

2016-09-14 Thread aleksey . maksimov
Yesterday I installed the all updates to hosts and Hosted Engine (and now I 
have oVirt Engine Version: 4.0.3-1.el7.centos)
But the problem still persists.

==>>> Is this happening consistently or randomly?

Consistently. every night.

==>>> Do you have any proxy server defined?

Yes. I add to end of ~/.bash_profile (for root) three lines:

export 
https_proxy=http://s-MY01-Linux-Upd:passw...@kom-ad01-gwclu.holding.com:3128/
export 
http_proxy=http://s-MY01-Linux-Upd:passw...@kom-ad01-gwclu.holding.com:3128/
export 
ftp_proxy=http://s-MY01-Linux-Upd:passw...@kom-ad01-gwclu.holding.com:3128/

==>>> anything special in yum.conf?

In yum.conf I changed just one parameter (installonly_limit)
Other parameters - default

# cat /etc/yum.conf | grep -v '^$\|^\s*\#'

[main]
cachedir=/var/cache/yum/$basearch/$releasever
keepcache=0
debuglevel=2
logfile=/var/log/yum.log
exactarch=1
obsoletes=1
gpgcheck=1
plugins=1
installonly_limit=3
bugtracker_url=http://bugs.centos.org/set_project.php?project_id=23=http://bugs.centos.org/bug_report_page.php?category=yum
distroverpkg=centos-release

==>>> Perhaps you should try 'yum clean all', but it makes no sense since 
'update' worked for you.

I already tried "yum clean". Ineffectually

==>>> Is NetworkManager operational? Does it help if you disable it?

NetworkManager already off:

# service NetworkManager status

Redirecting to /bin/systemctl status  NetworkManager.service
● NetworkManager.service - Network Manager
   Loaded: loaded (/usr/lib/systemd/system/NetworkManager.service; disabled; 
vendor preset: enabled)
   Active: inactive (dead)

14.09.2016, 11:21, "Edward Haas" :
> On Wed, Sep 14, 2016 at 8:21 AM,  wrote:
>> Hi oVirt guru`s!
>>
>> # getent ahosts mirrorlist.centos.org
>>
>> 216.176.179.218 STREAM mirrorlist.centos.org
>> 216.176.179.218 DGRAM
>> 216.176.179.218 RAW
>> 67.219.148.138  STREAM
>> 67.219.148.138  DGRAM
>> 67.219.148.138  RAW
>> 85.236.43.108   STREAM
>> 85.236.43.108   DGRAM
>> 85.236.43.108   RAW
>> 212.69.166.138  STREAM
>> 212.69.166.138  DGRAM
>> 212.69.166.138  RAW
>>
>> # ip addr | grep inet6
>>
>> (no output)
>
> This is indeed very strange.
> Is this happening consistently or randomly?
> Do you have any proxy server defined? anything special in yum.conf?
> Perhaps you should try 'yum clean all', but it makes no sense since 'update' 
> worked for you.
>
> Is NetworkManager operational? Does it help if you disable it?
>
>> 13.09.2016, 21:58, "Edward Haas" :
>>> On Tue, Sep 13, 2016 at 12:55 PM, Martin Perina  wrote:
 On Tue, Sep 13, 2016 at 10:59 AM,  wrote:
> nslookup resolves names on the engine and hosts without ipv6 address:
>
> # nslookup mirrorlist.centos.org
>
> Server:         10.1.0.10
> Address:        10.1.0.10#53
>
> Non-authoritative answer:
> Name:   mirrorlist.centos.org
> Address: 67.219.148.138
> Name:   mirrorlist.centos.org
> Address: 85.236.43.108
> Name:   mirrorlist.centos.org
> Address: 212.69.166.138
> Name:   mirrorlist.centos.org
> Address: 216.176.179.218
>
> Why oVirt updates checking process trying to use ipv6 ?
>
> 13.09.2016, 08:26, "aleksey.maksi...@it-kb.ru" 
> :
>> Yesterday I changed the settings the host to:
>>
>> net.ipv6.conf.all.disable_ipv6 = 1
>> net.ipv6.conf.default.disable_ipv6 = 1
>>
>> I deleted the last two lines in /etc/sysctl.conf and rebooted host.
>>
>> Tonight - problem repeated:
>>
>> 2016-09-13 01:11:13 ERROR otopi.context context._executeMethod:151 
>> Failed to execute stage 'Environment packages setup': Cannot find a 
>> valid baseurl for repo: base/7/x86_64
>> 2016-09-13 01:11:13 DEBUG otopi.transaction transaction.abort:119 
>> aborting 'Yum Transaction'
>> 2016-09-13 01:11:13 INFO otopi.plugins.otopi.packagers.yumpackager 
>> yumpackager.info:80 Yum Performing yum transaction rollback
>> Could not retrieve mirrorlist 
>> http://mirrorlist.centos.org/?release=7=x86_64=os=stock 
>> error was
>> 14: curl#7 - "Failed to connect to 2604:1580:fe02:2::10: Network is 
>> unreachable"
>>
>> Why so?

 ​Didi, any idea why otopi (or python underneath, not sure) is using IPv6​ 
 addresses when IPv6 is disabled on the host?
>>>
>>> Could you please resolve it with "getent ahosts " ?
>>> Please add the output from "ip addr", if you see there an IPv6 address, 
>>> something is enabling the ipv6 on that iface.
>>>
>>
>> 12.09.2016, 17:34, "Martin Perina" :
>>> On Mon, Sep 12, 2016 at 3:34 PM,  wrote:
 My /etc/sysctl.conf is:

 net.ipv6.conf.all.disable_ipv6 = 1
 net.ipv6.conf.default.disable_ipv6 = 1
 net.ipv6.conf.lo.disable_ipv6 = 0
 net.ipv6.conf.ovirtmgmt.disable_ipv6 

Re: [ovirt-users] Failed to check for available updates on host * with message 'Command returned failure code 1 during SSH session 'root@*

2016-09-13 Thread aleksey . maksimov
IPv6 disabled in my ifcfg files # cat /etc/sysconfig/network-scripts/ifcfg-ovirtmgmt | grep IPV6 IPV6INIT=no And running the command "yum update" manually operates successfully.  13.09.2016, 22:25, "Gianluca Cecchi" :On Tue, Sep 13, 2016 at 10:59 AM,  wrote:nslookup resolves names on the engine and hosts without ipv6 address:# nslookup mirrorlist.centos.orgServer:         10.1.0.10Address:        10.1.0.10#53Non-authoritative answer:Name:   mirrorlist.centos.orgAddress: 67.219.148.138Name:   mirrorlist.centos.orgAddress: 85.236.43.108Name:   mirrorlist.centos.orgAddress: 212.69.166.138Name:   mirrorlist.centos.orgAddress: 216.176.179.218Why oVirt updates checking process trying to use ipv6 ?   I had a similar problem some days ago with a CentOS 7 system, but it was general and unrelated to ovirt itself.If I remember correctly the problem was that originally it was configured by anaconda with NetworkManager and ipv6 and yum worked well.Then I stopped and disabled NetworkManager service (the "network" service is already enabled by default, so no action for it)  but I didn't remove all the IPV6 entries inside the anaconda-configured ifcfg-eno16780032 file in my /etc/sysconfig/network-scripts directoryI also created a /etc/sysctl.d/noipv6.conf file with:net.ipv6.conf.all.disable_ipv6 = 1net.ipv6.conf.default.disable_ipv6 = 1 But I got the ipv6 problem when trying in general to run "yum update"After wiping ipv6 entries in ifcfg-xxx file all went well.Could it be that in some ifcfg-* files you still have any reference to ipv6? Also, I had to run systemctl restart network HIH,Gianluca ___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Failed to check for available updates on host * with message 'Command returned failure code 1 during SSH session 'root@*

2016-09-13 Thread aleksey . maksimov
Hi oVirt guru`s! # getent ahosts mirrorlist.centos.org 216.176.179.218 STREAM mirrorlist.centos.org216.176.179.218 DGRAM216.176.179.218 RAW67.219.148.138  STREAM67.219.148.138  DGRAM67.219.148.138  RAW85.236.43.108   STREAM85.236.43.108   DGRAM85.236.43.108   RAW212.69.166.138  STREAM212.69.166.138  DGRAM212.69.166.138  RAW # ip addr | grep inet6 (no output)  13.09.2016, 21:58, "Edward Haas" :  On Tue, Sep 13, 2016 at 12:55 PM, Martin Perina  wrote:  On Tue, Sep 13, 2016 at 10:59 AM,  wrote:nslookup resolves names on the engine and hosts without ipv6 address:# nslookup mirrorlist.centos.orgServer:         10.1.0.10Address:        10.1.0.10#53Non-authoritative answer:Name:   mirrorlist.centos.orgAddress: 67.219.148.138Name:   mirrorlist.centos.orgAddress: 85.236.43.108Name:   mirrorlist.centos.orgAddress: 212.69.166.138Name:   mirrorlist.centos.orgAddress: 216.176.179.218Why oVirt updates checking process trying to use ipv6 ?13.09.2016, 08:26, "aleksey.maksi...@it-kb.ru" :> Yesterday I changed the settings the host to:>> net.ipv6.conf.all.disable_ipv6 = 1> net.ipv6.conf.default.disable_ipv6 = 1>> I deleted the last two lines in /etc/sysctl.conf and rebooted host.>> Tonight - problem repeated:>> 2016-09-13 01:11:13 ERROR otopi.context context._executeMethod:151 Failed to execute stage 'Environment packages setup': Cannot find a valid baseurl for repo: base/7/x86_64> 2016-09-13 01:11:13 DEBUG otopi.transaction transaction.abort:119 aborting 'Yum Transaction'> 2016-09-13 01:11:13 INFO otopi.plugins.otopi.packagers.yumpackager yumpackager.info:80 Yum Performing yum transaction rollback> Could not retrieve mirrorlist http://mirrorlist.centos.org/?release=7=x86_64=os=stock error was> 14: curl#7 - "Failed to connect to 2604:1580:fe02:2::10: Network is unreachable">> Why so? ​Didi, any idea why otopi (or python underneath, not sure) is using IPv6​ addresses when IPv6 is disabled on the host? Could you please resolve it with "getent ahosts " ?Please add the output from "ip addr", if you see there an IPv6 address, something is enabling the ipv6 on that iface.  >> 12.09.2016, 17:34, "Martin Perina" :>> On Mon, Sep 12, 2016 at 3:34 PM,  wrote:>>> My /etc/sysctl.conf is:>> net.ipv6.conf.all.disable_ipv6 = 1>>> net.ipv6.conf.default.disable_ipv6 = 1>>> net.ipv6.conf.lo.disable_ipv6 = 0>>> net.ipv6.conf.ovirtmgmt.disable_ipv6 = 0 ​I'm not networking expert, but last two lines means that you have IPv6 enabled on loopback and ovirtmgmt network interfaces (but disabled on all others). So you shouldn't be surprised to get IPv6 address from DNS resolver if ovirtmgmt supports IPv6. Dan/Edward, am I right?>> ​>>> Last two lines was added for http://lists.ovirt.org/pipermail/users/2016-July/041443.html>> My configuration file is bad ??>> 12.09.2016, 16:22, "Martin Perina" : On Mon, Sep 12, 2016 at 2:49 PM,  wrote:> Ok. I found log-file /var/log/ovirt-engine/host-deploy/ovirt-host-mgmt-20160912020013-kom-ad01-vm31.holding.com-null.log with this:>> ...> 2016-09-12 02:00:13 ERROR otopi.plugins.otopi.packagers.yumpackager yumpackager.error:85 Yum Cannot queue package iproute: Cannot find a valid baseurl for repo: base/7/x86_64> 2016-09-12 02:00:13 DEBUG otopi.context context._executeMethod:142 method exception> Traceback (most recent call last):>   File "/tmp/ovirt-B4lcSm14u9/pythonlib/otopi/context.py", line 132, in _executeMethod>     method['method']()>   File "/tmp/ovirt-B4lcSm14u9/otopi-plugins/otopi/network/hostname.py", line 54, in _internal_packages>     self.packager.install(packages=('iproute',))>   File "/tmp/ovirt-B4lcSm14u9/otopi-plugins/otopi/packagers/yumpackager.py", line 295, in install>     ignoreErrors=ignoreErrors>   File "/tmp/ovirt-B4lcSm14u9/pythonlib/otopi/miniyum.py", line 851, in install>     **kwargs>   File "/tmp/ovirt-B4lcSm14u9/pythonlib/otopi/miniyum.py", line 495, in _queue>     provides = self._queryProvides(packages=(package,))>   File "/tmp/ovirt-B4lcSm14u9/pythonlib/otopi/miniyum.py", line 433, in _queryProvides>     for po in self._yb.searchPackageProvides(args=packages):>   File "/usr/lib/python2.7/site-packages/yum/__init__.py", line 3429, in searchPackageProvides>     where = self.returnPackagesByDep(arg)>   File "/usr/lib/python2.7/site-packages/yum/__init__.py", line 4255, in returnPackagesByDep>     return self.pkgSack.searchProvides(depstring)>   File "/usr/lib/python2.7/site-packages/yum/__init__.py", line 1079, in >     pkgSack = property(fget=lambda self: self._getSacks(),>   File "/usr/lib/python2.7/site-packages/yum/__init__.py", line 784, in _getSacks>     self.repos.populateSack(which=repos)>   File "/usr/lib/python2.7/site-packages/yum/repos.py", line 344, in 

Re: [ovirt-users] Failed to check for available updates on host * with message 'Command returned failure code 1 during SSH session 'root@*

2016-09-13 Thread aleksey . maksimov
nslookup resolves names on the engine and hosts without ipv6 address:

# nslookup mirrorlist.centos.org

Server: 10.1.0.10
Address:10.1.0.10#53

Non-authoritative answer:
Name:   mirrorlist.centos.org
Address: 67.219.148.138
Name:   mirrorlist.centos.org
Address: 85.236.43.108
Name:   mirrorlist.centos.org
Address: 212.69.166.138
Name:   mirrorlist.centos.org
Address: 216.176.179.218

Why oVirt updates checking process trying to use ipv6 ?


13.09.2016, 08:26, "aleksey.maksi...@it-kb.ru" :
> Yesterday I changed the settings the host to:
>
> net.ipv6.conf.all.disable_ipv6 = 1
> net.ipv6.conf.default.disable_ipv6 = 1
>
> I deleted the last two lines in /etc/sysctl.conf and rebooted host.
>
> Tonight - problem repeated:
>
> 2016-09-13 01:11:13 ERROR otopi.context context._executeMethod:151 Failed to 
> execute stage 'Environment packages setup': Cannot find a valid baseurl for 
> repo: base/7/x86_64
> 2016-09-13 01:11:13 DEBUG otopi.transaction transaction.abort:119 aborting 
> 'Yum Transaction'
> 2016-09-13 01:11:13 INFO otopi.plugins.otopi.packagers.yumpackager 
> yumpackager.info:80 Yum Performing yum transaction rollback
> Could not retrieve mirrorlist 
> http://mirrorlist.centos.org/?release=7=x86_64=os=stock error 
> was
> 14: curl#7 - "Failed to connect to 2604:1580:fe02:2::10: Network is 
> unreachable"
>
> Why so?
>
> 12.09.2016, 17:34, "Martin Perina" :
>> On Mon, Sep 12, 2016 at 3:34 PM,  wrote:
>>> My /etc/sysctl.conf is:
>>>
>>> net.ipv6.conf.all.disable_ipv6 = 1
>>> net.ipv6.conf.default.disable_ipv6 = 1
>>> net.ipv6.conf.lo.disable_ipv6 = 0
>>> net.ipv6.conf.ovirtmgmt.disable_ipv6 = 0
>>
>> ​I'm not networking expert, but last two lines means that you have IPv6 
>> enabled on loopback and ovirtmgmt network interfaces (but disabled on all 
>> others). So you shouldn't be surprised to get IPv6 address from DNS resolver 
>> if ovirtmgmt supports IPv6. Dan/Edward, am I right?
>> ​
>>> Last two lines was added for 
>>> http://lists.ovirt.org/pipermail/users/2016-July/041443.html
>>>
>>> My configuration file is bad ??
>>>
>>> 12.09.2016, 16:22, "Martin Perina" :
 On Mon, Sep 12, 2016 at 2:49 PM,  wrote:
> Ok. I found log-file 
> /var/log/ovirt-engine/host-deploy/ovirt-host-mgmt-20160912020013-kom-ad01-vm31.holding.com-null.log
>  with this:
>
> ...
> 2016-09-12 02:00:13 ERROR otopi.plugins.otopi.packagers.yumpackager 
> yumpackager.error:85 Yum Cannot queue package iproute: Cannot find a 
> valid baseurl for repo: base/7/x86_64
> 2016-09-12 02:00:13 DEBUG otopi.context context._executeMethod:142 method 
> exception
> Traceback (most recent call last):
>   File "/tmp/ovirt-B4lcSm14u9/pythonlib/otopi/context.py", line 132, in 
> _executeMethod
>     method['method']()
>   File "/tmp/ovirt-B4lcSm14u9/otopi-plugins/otopi/network/hostname.py", 
> line 54, in _internal_packages
>     self.packager.install(packages=('iproute',))
>   File 
> "/tmp/ovirt-B4lcSm14u9/otopi-plugins/otopi/packagers/yumpackager.py", 
> line 295, in install
>     ignoreErrors=ignoreErrors
>   File "/tmp/ovirt-B4lcSm14u9/pythonlib/otopi/miniyum.py", line 851, in 
> install
>     **kwargs
>   File "/tmp/ovirt-B4lcSm14u9/pythonlib/otopi/miniyum.py", line 495, in 
> _queue
>     provides = self._queryProvides(packages=(package,))
>   File "/tmp/ovirt-B4lcSm14u9/pythonlib/otopi/miniyum.py", line 433, in 
> _queryProvides
>     for po in self._yb.searchPackageProvides(args=packages):
>   File "/usr/lib/python2.7/site-packages/yum/__init__.py", line 3429, in 
> searchPackageProvides
>     where = self.returnPackagesByDep(arg)
>   File "/usr/lib/python2.7/site-packages/yum/__init__.py", line 4255, in 
> returnPackagesByDep
>     return self.pkgSack.searchProvides(depstring)
>   File "/usr/lib/python2.7/site-packages/yum/__init__.py", line 1079, in 
> 
>     pkgSack = property(fget=lambda self: self._getSacks(),
>   File "/usr/lib/python2.7/site-packages/yum/__init__.py", line 784, in 
> _getSacks
>     self.repos.populateSack(which=repos)
>   File "/usr/lib/python2.7/site-packages/yum/repos.py", line 344, in 
> populateSack
>     self.doSetup()
>   File "/usr/lib/python2.7/site-packages/yum/repos.py", line 158, in 
> doSetup
>     self.ayum.plugins.run('postreposetup')
>   File "/usr/lib/python2.7/site-packages/yum/plugins.py", line 188, in run
>     func(conduitcls(self, self.base, conf, **kwargs))
>   File "/usr/lib/yum-plugins/fastestmirror.py", line 197, in 
> postreposetup_hook
>     if downgrade_ftp and _len_non_ftp(repo.urls) == 1:
>   File "/usr/lib/python2.7/site-packages/yum/yumRepo.py", line 871, in 
> 
>     urls = property(fget=lambda self: self._geturls(),
>   

Re: [ovirt-users] Failed to check for available updates on host * with message 'Command returned failure code 1 during SSH session 'root@*

2016-09-12 Thread aleksey . maksimov
Yesterday I changed the settings the host to: net.ipv6.conf.all.disable_ipv6 = 1net.ipv6.conf.default.disable_ipv6 = 1 I deleted the last two lines in /etc/sysctl.conf and rebooted host. Tonight - problem repeated: 2016-09-13 01:11:13 ERROR otopi.context context._executeMethod:151 Failed to execute stage 'Environment packages setup': Cannot find a valid baseurl for repo: base/7/x86_642016-09-13 01:11:13 DEBUG otopi.transaction transaction.abort:119 aborting 'Yum Transaction'2016-09-13 01:11:13 INFO otopi.plugins.otopi.packagers.yumpackager yumpackager.info:80 Yum Performing yum transaction rollbackCould not retrieve mirrorlist http://mirrorlist.centos.org/?release=7=x86_64=os=stock error was14: curl#7 - "Failed to connect to 2604:1580:fe02:2::10: Network is unreachable" Why so?  12.09.2016, 17:34, "Martin Perina" :  On Mon, Sep 12, 2016 at 3:34 PM,  wrote:My /etc/sysctl.conf is: net.ipv6.conf.all.disable_ipv6 = 1net.ipv6.conf.default.disable_ipv6 = 1net.ipv6.conf.lo.disable_ipv6 = 0net.ipv6.conf.ovirtmgmt.disable_ipv6 = 0 ​I'm not networking expert, but last two lines means that you have IPv6 enabled on loopback and ovirtmgmt network interfaces (but disabled on all others). So you shouldn't be surprised to get IPv6 address from DNS resolver if ovirtmgmt supports IPv6. Dan/Edward, am I right?​ Last two lines was added for http://lists.ovirt.org/pipermail/users/2016-July/041443.html My configuration file is bad ??  12.09.2016, 16:22, "Martin Perina" :  On Mon, Sep 12, 2016 at 2:49 PM,  wrote:Ok. I found log-file /var/log/ovirt-engine/host-deploy/ovirt-host-mgmt-20160912020013-kom-ad01-vm31.holding.com-null.log with this:...2016-09-12 02:00:13 ERROR otopi.plugins.otopi.packagers.yumpackager yumpackager.error:85 Yum Cannot queue package iproute: Cannot find a valid baseurl for repo: base/7/x86_642016-09-12 02:00:13 DEBUG otopi.context context._executeMethod:142 method exceptionTraceback (most recent call last):  File "/tmp/ovirt-B4lcSm14u9/pythonlib/otopi/context.py", line 132, in _executeMethod    method['method']()  File "/tmp/ovirt-B4lcSm14u9/otopi-plugins/otopi/network/hostname.py", line 54, in _internal_packages    self.packager.install(packages=('iproute',))  File "/tmp/ovirt-B4lcSm14u9/otopi-plugins/otopi/packagers/yumpackager.py", line 295, in install    ignoreErrors=ignoreErrors  File "/tmp/ovirt-B4lcSm14u9/pythonlib/otopi/miniyum.py", line 851, in install    **kwargs  File "/tmp/ovirt-B4lcSm14u9/pythonlib/otopi/miniyum.py", line 495, in _queue    provides = self._queryProvides(packages=(package,))  File "/tmp/ovirt-B4lcSm14u9/pythonlib/otopi/miniyum.py", line 433, in _queryProvides    for po in self._yb.searchPackageProvides(args=packages):  File "/usr/lib/python2.7/site-packages/yum/__init__.py", line 3429, in searchPackageProvides    where = self.returnPackagesByDep(arg)  File "/usr/lib/python2.7/site-packages/yum/__init__.py", line 4255, in returnPackagesByDep    return self.pkgSack.searchProvides(depstring)  File "/usr/lib/python2.7/site-packages/yum/__init__.py", line 1079, in     pkgSack = property(fget=lambda self: self._getSacks(),  File "/usr/lib/python2.7/site-packages/yum/__init__.py", line 784, in _getSacks    self.repos.populateSack(which=repos)  File "/usr/lib/python2.7/site-packages/yum/repos.py", line 344, in populateSack    self.doSetup()  File "/usr/lib/python2.7/site-packages/yum/repos.py", line 158, in doSetup    self.ayum.plugins.run('postreposetup')  File "/usr/lib/python2.7/site-packages/yum/plugins.py", line 188, in run    func(conduitcls(self, self.base, conf, **kwargs))  File "/usr/lib/yum-plugins/fastestmirror.py", line 197, in postreposetup_hook    if downgrade_ftp and _len_non_ftp(repo.urls) == 1:  File "/usr/lib/python2.7/site-packages/yum/yumRepo.py", line 871, in     urls = property(fget=lambda self: self._geturls(),  File "/usr/lib/python2.7/site-packages/yum/yumRepo.py", line 868, in _geturls    self._baseurlSetup()  File "/usr/lib/python2.7/site-packages/yum/yumRepo.py", line 834, in _baseurlSetup    self.check()  File "/usr/lib/python2.7/site-packages/yum/yumRepo.py", line 554, in check    'Cannot find a valid baseurl for repo: %s' % self.ui_idRepoError: Cannot find a valid baseurl for repo: base/7/x86_642016-09-12 02:00:13 ERROR otopi.context context._executeMethod:151 Failed to execute stage 'Environment packages setup': Cannot find a valid baseurl for repo: base/7/x86_642016-09-12 02:00:13 DEBUG otopi.transaction transaction.abort:119 aborting 'Yum Transaction'2016-09-12 02:00:13 INFO otopi.plugins.otopi.packagers.yumpackager yumpackager.info:80 Yum Performing yum transaction rollbackCould not retrieve mirrorlist http://mirrorlist.centos.org/?release=7=x86_64=os=stock error was14: curl#7 - "Failed to connect to 2604:1580:fe02:2::10: Network is unreachable"Loaded plugins: fastestmirror2016-09-12 02:00:13 DEBUG otopi.context context.dumpEnvironment:760 ENVIRONMENT DUMP - 

Re: [ovirt-users] Failed to check for available updates on host * with message 'Command returned failure code 1 during SSH session 'root@*

2016-09-12 Thread aleksey . maksimov
My /etc/sysctl.conf is: net.ipv6.conf.all.disable_ipv6 = 1net.ipv6.conf.default.disable_ipv6 = 1net.ipv6.conf.lo.disable_ipv6 = 0net.ipv6.conf.ovirtmgmt.disable_ipv6 = 0 Last two lines was added for http://lists.ovirt.org/pipermail/users/2016-July/041443.html My configuration file is bad ??  12.09.2016, 16:22, "Martin Perina" :  On Mon, Sep 12, 2016 at 2:49 PM,  wrote:Ok. I found log-file /var/log/ovirt-engine/host-deploy/ovirt-host-mgmt-20160912020013-kom-ad01-vm31.holding.com-null.log with this:...2016-09-12 02:00:13 ERROR otopi.plugins.otopi.packagers.yumpackager yumpackager.error:85 Yum Cannot queue package iproute: Cannot find a valid baseurl for repo: base/7/x86_642016-09-12 02:00:13 DEBUG otopi.context context._executeMethod:142 method exceptionTraceback (most recent call last):  File "/tmp/ovirt-B4lcSm14u9/pythonlib/otopi/context.py", line 132, in _executeMethod    method['method']()  File "/tmp/ovirt-B4lcSm14u9/otopi-plugins/otopi/network/hostname.py", line 54, in _internal_packages    self.packager.install(packages=('iproute',))  File "/tmp/ovirt-B4lcSm14u9/otopi-plugins/otopi/packagers/yumpackager.py", line 295, in install    ignoreErrors=ignoreErrors  File "/tmp/ovirt-B4lcSm14u9/pythonlib/otopi/miniyum.py", line 851, in install    **kwargs  File "/tmp/ovirt-B4lcSm14u9/pythonlib/otopi/miniyum.py", line 495, in _queue    provides = self._queryProvides(packages=(package,))  File "/tmp/ovirt-B4lcSm14u9/pythonlib/otopi/miniyum.py", line 433, in _queryProvides    for po in self._yb.searchPackageProvides(args=packages):  File "/usr/lib/python2.7/site-packages/yum/__init__.py", line 3429, in searchPackageProvides    where = self.returnPackagesByDep(arg)  File "/usr/lib/python2.7/site-packages/yum/__init__.py", line 4255, in returnPackagesByDep    return self.pkgSack.searchProvides(depstring)  File "/usr/lib/python2.7/site-packages/yum/__init__.py", line 1079, in     pkgSack = property(fget=lambda self: self._getSacks(),  File "/usr/lib/python2.7/site-packages/yum/__init__.py", line 784, in _getSacks    self.repos.populateSack(which=repos)  File "/usr/lib/python2.7/site-packages/yum/repos.py", line 344, in populateSack    self.doSetup()  File "/usr/lib/python2.7/site-packages/yum/repos.py", line 158, in doSetup    self.ayum.plugins.run('postreposetup')  File "/usr/lib/python2.7/site-packages/yum/plugins.py", line 188, in run    func(conduitcls(self, self.base, conf, **kwargs))  File "/usr/lib/yum-plugins/fastestmirror.py", line 197, in postreposetup_hook    if downgrade_ftp and _len_non_ftp(repo.urls) == 1:  File "/usr/lib/python2.7/site-packages/yum/yumRepo.py", line 871, in     urls = property(fget=lambda self: self._geturls(),  File "/usr/lib/python2.7/site-packages/yum/yumRepo.py", line 868, in _geturls    self._baseurlSetup()  File "/usr/lib/python2.7/site-packages/yum/yumRepo.py", line 834, in _baseurlSetup    self.check()  File "/usr/lib/python2.7/site-packages/yum/yumRepo.py", line 554, in check    'Cannot find a valid baseurl for repo: %s' % self.ui_idRepoError: Cannot find a valid baseurl for repo: base/7/x86_642016-09-12 02:00:13 ERROR otopi.context context._executeMethod:151 Failed to execute stage 'Environment packages setup': Cannot find a valid baseurl for repo: base/7/x86_642016-09-12 02:00:13 DEBUG otopi.transaction transaction.abort:119 aborting 'Yum Transaction'2016-09-12 02:00:13 INFO otopi.plugins.otopi.packagers.yumpackager yumpackager.info:80 Yum Performing yum transaction rollbackCould not retrieve mirrorlist http://mirrorlist.centos.org/?release=7=x86_64=os=stock error was14: curl#7 - "Failed to connect to 2604:1580:fe02:2::10: Network is unreachable"Loaded plugins: fastestmirror2016-09-12 02:00:13 DEBUG otopi.context context.dumpEnvironment:760 ENVIRONMENT DUMP - BEGIN2016-09-12 02:00:13 DEBUG otopi.context context.dumpEnvironment:770 ENV BASE/error=bool:'True'2016-09-12 02:00:13 DEBUG otopi.context context.dumpEnvironment:770 ENV BASE/exceptionInfo=list:'[(, RepoError(), 7002252f80>)]'2016-09-12 02:00:13 DEBUG otopi.context context.dumpEnvironment:774 ENVIRONMENT DUMP - END...He's trying to use ipv6 connection ??But, I have not ipv6 networks and my hosts/engine used only ipv4 settings. ​Hmm, it seems to me that you don't have IPv6 disabled properly, as your DNS resolver returns you IPv6 addresses. Please take a look at:https://wiki.centos.org/FAQ/CentOS7#head-8984faf811faccca74c7bcdd74de7467f2fcd8ee​ 12.09.2016, 15:45, "Martin Perina" :>> ​2016-09-12 02:00:13,388 INFO [org.ovirt.engine.core.bll.hostdeploy.VdsDeployBase] (VdsDeploy) [] Retrieving installation logs to: '/var/log/ovirt-engine/host-deploy/ovirt-host-mgmt-20160912020013-kom-ad01-vm31.holding.com-null.l$>> This is most probably the log file where details of the issue can be found>> On Mon, Sep 12, 2016 at 2:35 PM, Yedidyah Bar David  wrote:>> On Mon, Sep 12, 2016 at 3:08 PM,   wrote:>> Excuse me. I do 

Re: [ovirt-users] Failed to check for available updates on host * with message 'Command returned failure code 1 during SSH session 'root@*

2016-09-12 Thread aleksey . maksimov
Ok. I found log-file 
/var/log/ovirt-engine/host-deploy/ovirt-host-mgmt-20160912020013-kom-ad01-vm31.holding.com-null.log
 with this:

...
2016-09-12 02:00:13 ERROR otopi.plugins.otopi.packagers.yumpackager 
yumpackager.error:85 Yum Cannot queue package iproute: Cannot find a valid 
baseurl for repo: base/7/x86_64
2016-09-12 02:00:13 DEBUG otopi.context context._executeMethod:142 method 
exception
Traceback (most recent call last):
  File "/tmp/ovirt-B4lcSm14u9/pythonlib/otopi/context.py", line 132, in 
_executeMethod
    method['method']()
  File "/tmp/ovirt-B4lcSm14u9/otopi-plugins/otopi/network/hostname.py", line 
54, in _internal_packages
    self.packager.install(packages=('iproute',))
  File "/tmp/ovirt-B4lcSm14u9/otopi-plugins/otopi/packagers/yumpackager.py", 
line 295, in install
    ignoreErrors=ignoreErrors
  File "/tmp/ovirt-B4lcSm14u9/pythonlib/otopi/miniyum.py", line 851, in install
    **kwargs
  File "/tmp/ovirt-B4lcSm14u9/pythonlib/otopi/miniyum.py", line 495, in _queue
    provides = self._queryProvides(packages=(package,))
  File "/tmp/ovirt-B4lcSm14u9/pythonlib/otopi/miniyum.py", line 433, in 
_queryProvides
    for po in self._yb.searchPackageProvides(args=packages):
  File "/usr/lib/python2.7/site-packages/yum/__init__.py", line 3429, in 
searchPackageProvides
    where = self.returnPackagesByDep(arg)
  File "/usr/lib/python2.7/site-packages/yum/__init__.py", line 4255, in 
returnPackagesByDep
    return self.pkgSack.searchProvides(depstring)
  File "/usr/lib/python2.7/site-packages/yum/__init__.py", line 1079, in 

    pkgSack = property(fget=lambda self: self._getSacks(),
  File "/usr/lib/python2.7/site-packages/yum/__init__.py", line 784, in 
_getSacks
    self.repos.populateSack(which=repos)
  File "/usr/lib/python2.7/site-packages/yum/repos.py", line 344, in 
populateSack
    self.doSetup()
  File "/usr/lib/python2.7/site-packages/yum/repos.py", line 158, in doSetup
    self.ayum.plugins.run('postreposetup')
  File "/usr/lib/python2.7/site-packages/yum/plugins.py", line 188, in run
    func(conduitcls(self, self.base, conf, **kwargs))
  File "/usr/lib/yum-plugins/fastestmirror.py", line 197, in postreposetup_hook
    if downgrade_ftp and _len_non_ftp(repo.urls) == 1:
  File "/usr/lib/python2.7/site-packages/yum/yumRepo.py", line 871, in 
    urls = property(fget=lambda self: self._geturls(),
  File "/usr/lib/python2.7/site-packages/yum/yumRepo.py", line 868, in _geturls
    self._baseurlSetup()
  File "/usr/lib/python2.7/site-packages/yum/yumRepo.py", line 834, in 
_baseurlSetup
    self.check()
  File "/usr/lib/python2.7/site-packages/yum/yumRepo.py", line 554, in check
    'Cannot find a valid baseurl for repo: %s' % self.ui_id
RepoError: Cannot find a valid baseurl for repo: base/7/x86_64
2016-09-12 02:00:13 ERROR otopi.context context._executeMethod:151 Failed to 
execute stage 'Environment packages setup': Cannot find a valid baseurl for 
repo: base/7/x86_64
2016-09-12 02:00:13 DEBUG otopi.transaction transaction.abort:119 aborting 'Yum 
Transaction'
2016-09-12 02:00:13 INFO otopi.plugins.otopi.packagers.yumpackager 
yumpackager.info:80 Yum Performing yum transaction rollback
Could not retrieve mirrorlist 
http://mirrorlist.centos.org/?release=7=x86_64=os=stock error 
was
14: curl#7 - "Failed to connect to 2604:1580:fe02:2::10: Network is unreachable"
Loaded plugins: fastestmirror
2016-09-12 02:00:13 DEBUG otopi.context context.dumpEnvironment:760 ENVIRONMENT 
DUMP - BEGIN
2016-09-12 02:00:13 DEBUG otopi.context context.dumpEnvironment:770 ENV 
BASE/error=bool:'True'
2016-09-12 02:00:13 DEBUG otopi.context context.dumpEnvironment:770 ENV 
BASE/exceptionInfo=list:'[(, RepoError(), 
)]'
2016-09-12 02:00:13 DEBUG otopi.context context.dumpEnvironment:774 ENVIRONMENT 
DUMP - END
...

He's trying to use ipv6 connection ??
But, I have not ipv6 networks and my hosts/engine used only ipv4 settings.

12.09.2016, 15:45, "Martin Perina" :
>> ​2016-09-12 02:00:13,388 INFO 
>> [org.ovirt.engine.core.bll.hostdeploy.VdsDeployBase] (VdsDeploy) [] 
>> Retrieving installation logs to: 
>> '/var/log/ovirt-engine/host-deploy/ovirt-host-mgmt-20160912020013-kom-ad01-vm31.holding.com-null.l$
>
> This is most probably the log file where details of the issue can be found
>
> On Mon, Sep 12, 2016 at 2:35 PM, Yedidyah Bar David  wrote:
>> On Mon, Sep 12, 2016 at 3:08 PM,   wrote:
>>>
>>> Excuse me. I do not understand. What I should do?
>>> The directory /var/log/ovirt-engine/host-deploy many different log files
>>
>> Please check the one from a time where you see this error.
>>
>> Every run of host-deploy creates its own log file.
>>
>> Best,
>>
>>>
>>> 12.09.2016, 14:59, "Yedidyah Bar David" :
 On Mon, Sep 12, 2016 at 11:17 AM,  wrote:
>  # yum install iproute
>
>  Loaded plugins: fastestmirror
>  Loading mirror speeds from cached hostfile
>   * base: mirror.awanti.com

Re: [ovirt-users] Failed to check for available updates on host * with message 'Command returned failure code 1 during SSH session 'root@*

2016-09-12 Thread aleksey . maksimov

Excuse me. I do not understand. What I should do?
The directory /var/log/ovirt-engine/host-deploy many different log files

12.09.2016, 14:59, "Yedidyah Bar David" :
> On Mon, Sep 12, 2016 at 11:17 AM,  wrote:
>>  # yum install iproute
>>
>>  Loaded plugins: fastestmirror
>>  Loading mirror speeds from cached hostfile
>>   * base: mirror.awanti.com
>>   * elrepo: dfw.mirror.rackspace.com
>>   * epel: epel.besthosting.ua
>>   * extras: centos-mirror.rbc.ru
>>   * ovirt-4.0: ftp.nluug.nl
>>   * ovirt-4.0-epel: epel.besthosting.ua
>>   * updates: centos-mirror.rbc.ru
>>  Package iproute-3.10.0-54.el7_2.1.x86_64 already installed and latest 
>> version
>>  Nothing to do
>>
>>  # ls -la /etc/yum.repos.d/
>>
>>  total 76
>>  drwxr-xr-x. 2 root root 4096 Jul 26 14:08 .
>>  drwxr-xr-x. 102 root root 12288 Sep 12 11:00 ..
>>  -rw-r--r--. 1 root root 1664 Dec 9 2015 CentOS-Base.repo
>>  -rw-r--r--. 1 root root 1309 Dec 9 2015 CentOS-CR.repo
>>  -rw-r--r--. 1 root root 649 Dec 9 2015 CentOS-Debuginfo.repo
>>  -rw-r--r--. 1 root root 290 Dec 9 2015 CentOS-fasttrack.repo
>>  -rw-r--r--. 1 root root 630 Dec 9 2015 CentOS-Media.repo
>>  -rw-r--r--. 1 root root 1331 Dec 9 2015 CentOS-Sources.repo
>>  -rw-r--r--. 1 root root 1952 Dec 9 2015 CentOS-Vault.repo
>>  -rw-r--r--. 1 root root 2150 May 21 2014 elrepo.repo
>>  -rw-r--r--. 1 root root 957 Jun 3 16:52 epel.repo
>>  -rw-r--r--. 1 root root 1056 Jun 3 16:52 epel-testing.repo
>>  -rw-r--r--. 1 root root 383 Jul 21 10:44 HP-MCP.repo
>>  -rw-r--r--. 1 root root 446 Jul 21 10:45 HP-SPP-2014-06.repo
>>  -rw-r--r--. 1 root root 417 Jul 21 10:44 HP-SPP-Current.repo
>>  -rw-r--r--. 1 root root 1678 Jul 26 14:08 ovirt-4.0-dependencies.repo
>>  -rw-r--r--. 1 root root 289 Jul 26 14:08 ovirt-4.0.repo
>>
>>  Which repo file you are interested in?
>
> The one(s) that has in it '[base]'. Also, you might find more
> details in the host-deploy log, in /var/log/ovirt-engine/host-deploy .
>
>>  12.09.2016, 11:14, "Yedidyah Bar David" :
>>>  On Mon, Sep 12, 2016 at 10:59 AM,  wrote:
   Hi, Martin.

   The command is executed successfully:

   Updated:
 vdsm.x86_64 0:4.18.12-1.el7 vdsm-cli.noarch 0:4.18.12-1.el7
   Dependency Updated:
 vdsm-api.noarch 0:4.18.12-1.el7 vdsm-hook-vmfex-dev.noarch 
 0:4.18.12-1.el7 vdsm-infra.noarch 0:4.18.12-1.el7
 vdsm-jsonrpc.noarch 0:4.18.12-1.el7 vdsm-python.noarch 0:4.18.12-1.el7 
 vdsm-xmlrpc.noarch 0:4.18.12-1.el7
 vdsm-yajsonrpc.noarch 0:4.18.12-1.el7
   Complete!

   12.09.2016, 10:47, "Martin Perina" :
>   Hi Aleksey,
>
>   the error message is raised by Host upgrade manager (more info at [1]) 
> which checks for available package upgrades on the host.
>
>   It seems that you have somehow corrupted repository configuration of 
> the host 'kom-ad01-vm31.holding.com':
>
>   2016-09-12 02:00:13,300 ERROR 
> [org.ovirt.engine.core.bll.hostdeploy.VdsDeployBase] (VdsDeploy) [] Yum 
> Cannot queue package iproute: Cannot find a valid baseurl for repo: 
> base/7/x86_64
>   2016-09-12 02:00:13,304 ERROR 
> [org.ovirt.engine.core.bll.hostdeploy.VdsDeployBase] (VdsDeploy) [] 
> Failed to execute stage 'Environment packages setup': Cannot find a valid 
> baseurl for repo: base/7/x86_64
>
>   Could you please verify that you are able to successfully execute 
> following commands on the host?
>
> yum check-update
> yum update vdsm vdsm-cli
>>>
>>>  Can you please try also:
>>>
>>>  yum install iproute
>>>
>>>  And also share your /etc/yum.repos.d/* ?
>>>
>>>  Thanks.
>>>
>   Thanks
>
>   Martin Perina
>
>   [1] 
> http://www.ovirt.org/develop/release-management/features/engine/upgrademanager/
>
>   On Mon, Sep 12, 2016 at 9:20 AM,  wrote:
>>   Hello oVirt guru`s!
>>
>>   oVirt Engine Version: 4.0.1.1-1.el7.centos
>>
>>   Every day there is a message in web UI for one of my two hosts:
>>
>>   "Failed to check for available updates on host KOM-AD01-VM31 with 
>> message 'Command returned failure code 1 during SSH session 'root@
>>
>>   kom-ad01-vm31.holding.com''.
>>
>>   In /var/log/ovirt-engine/engine.log at this time:
>>
>>   ...
>>   2016-09-12 01:59:45,045 INFO 
>> [org.ovirt.engine.core.bll.hostdeploy.VdsDeployBase] (VdsDeploy) [] 
>> Stage: Initializing
>>   2016-09-12 01:59:45,055 INFO 
>> [org.ovirt.engine.core.bll.hostdeploy.VdsDeployBase] (VdsDeploy) [] 
>> Stage: Environment setup
>>   2016-09-12 01:59:45,070 INFO 
>> [org.ovirt.engine.core.bll.hostdeploy.VdsDeployBase] (VdsDeploy) [] 
>> Stage: Environment packages setup
>>
>>   2016-09-12 02:00:13,300 ERROR 
>> [org.ovirt.engine.core.bll.hostdeploy.VdsDeployBase] 

  1   2   >