- Aug 19, 2020
-
-
Rafael Weingärtner authored
The goal for this push request is to normalize the construction and use of internal, external, and admin URLs. While extending Kolla-ansible to enable a more flexible method to manage external URLs, we noticed that the same URL was constructed multiple times in different parts of the code. This can make it difficult for people that want to work with these URLs and create inconsistencies in a large code base with time. Therefore, we are proposing here the use of "single Kolla-ansible variable" per endpoint URL, which facilitates for people that are interested in overriding/extending these URLs. As an example, we extended Kolla-ansible to facilitate the "override" of public (external) URLs with the following standard "<component/serviceName>.<companyBaseUrl>". Therefore, the "NAT/redirect" in the SSL termination system (HAproxy, HTTPD or some other) is done via the service name, and not by the port. This allows operators to easily and automatically create more friendly URL names. To develop this feature, we first applied this patch that we are sending now to the community. We did that to reduce the surface of changes in Kolla-ansible. Another example is the integration of Kolla-ansible and Consul, which we also implemented internally, and also requires URLs changes. Therefore, this PR is essential to reduce code duplicity, and to facility users/developers to work/customize the services URLs. Change-Id: I73d483e01476e779a5155b2e18dd5ea25f514e93 Signed-off-by:
Rafael Weingärtner <rafael@apache.org>
-
- Aug 17, 2020
-
-
Bartosz Bezak authored
Change-Id: If90c2dfd32c8bc50671f6dd38e5a82b434c07151 Depends-On: https://review.opendev.org/#/c/720338
-
chenxing authored
The "kolla_internal_address" variable is not documented or defined anywhere. When "kolla_internal_vip_address" is undefined, the error message is about "kolla_internal_address", which will confuse operators. This change deprecates "kolla_internal_address", and adds a default value for "kolla_internal_vip_address" when "kolla_internal_address" is undefined. Change-Id: I09694b38420ea67896bb8cf4ffd7ce6f131af10e Closes-Bug: #1864206
-
- Aug 15, 2020
-
-
James Kirsch authored
This patch introduces an optional backend encryption for the Nova API service. When used in conjunction with enabling TLS for service API endpoints, network communcation will be encrypted end to end, from client through HAProxy to the Nova service. Change-Id: I48e1540b973016079d5686b328e82239dcffacfd Partially-Implements: blueprint add-ssl-internal-network
-
- Aug 13, 2020
-
-
Bharat Kunwar authored
Change-Id: I173669bdf92b1f2ea98907ba16808ca3c914944c
-
James Kirsch authored
This patch introduces a global keep alive timeout value for services that leverage httpd + wsgi to handle http/https requests. The default value is one minute. Change-Id: Icf7cb0baf86b428a60a7e9bbed642999711865cd Partially-Implements: blueprint add-ssl-internal-network
-
- Aug 12, 2020
-
-
Radosław Piliszek authored
This fix was premature as it completely ignores the previously-respected umask. Let's discuss a proper fix and revert this one since CI is fixed elsewhere [1]. [1] https://review.opendev.org/743502 This reverts commit 87efdce2. Change-Id: If38adbf124e793574a21ae986f9ee146d587f820
-
- Aug 11, 2020
-
-
Radosław Piliszek authored
Ansible changed the default mode for files, even in stable releases. [1] This change restores the previous default (with the common umask). [1] https://github.com/ansible/ansible/pull/70221 Change-Id: I0f81214b4f95fe8a378844745ebc77f3c43027ab Closes-Bug: #1891145
-
Marcin Juszkiewicz authored
There is a time once every 2 years when ubuntu team releases new LTS release. And then UCA joins with binary packages for current OpenStack development cycle. It is this time for Ubuntu 20.04 'focal'. Includes CI fix to pass: [CI] Temporarily block new Ansible The proper fix [1] needs fixing older branches before newer. This one allows to fix CI first, in the usual order. To revert after [1] gets merged in all relevant branches. [1] https://review.opendev.org/745648 Old-Change-Id: Ifbd37d8addd4322773118e2e9d46494741a8ae66 Related-Bug: #1891145 Depends-on: https://review.opendev.org/#/c/738994/ Change-Id: Ib8b70ee40ec2d19509cc84c0f530612f81907721 Co-Authored-By:
Radosław Piliszek <radoslaw.piliszek@gmail.com>
-
- Aug 10, 2020
-
-
Mark Goddard authored
Previously we mounted /etc/timezone if the kolla_base_distro is debian or ubuntu. This would fail prechecks if debian or ubuntu images were deployed on CentOS. While this is not a supported combination, for correctness we should fix the condition to reference the host OS rather than the container OS, since that is where the /etc/timezone file is located. Change-Id: Ifc252ae793e6974356fcdca810b373f362d24ba5 Closes-Bug: #1882553
-
likui authored
Add trove-guestagent.conf templates for trove-guestagent service. Default the Guest Agent config file to be injected during instance creation. Change-Id: Id0750b84fef8e19658b27f8ae16a857e1394216e
-
- Aug 07, 2020
-
-
Mark Goddard authored
This patch is a continuation of I6a174468bd91d214c08477b93c88032a45c137be for the nova-cell role, which was missed. The Castellan (Barbican client) has different parameters to control the used CA file. This patch uses them. Moreover, this aligns Barbican with other services by defaulting its client config to the internal endpoint. See also [1]. [1] https://bugs.launchpad.net/castellan/+bug/1876102 Closes-Bug: #1886615 Change-Id: I056f3eebcf87bcbaaf89fdd0dc1f46d143db7785
-
- Aug 06, 2020
-
-
nikparasyr authored
Glance role copies glance-image-import.conf when enabled to allow configuration of glance interoperable image import. Property protection can be enabled and file is copied. Change-Id: I5106675da5228a5d7e630871f0882269603e6571 Closesl-Bug: #1889272 Signed-off-by:
nikparasyr <nik.parasyr@protonmail.com>
-
Marcin Juszkiewicz authored
Change-Id: I59a15186bbe931efd8d99a990a3ceafbd264e1df
-
Kien Nguyen authored
Change-Id: Ib08544a265fe1e0d599a6243cb9d38ed9a7769e1
-
- Aug 04, 2020
-
-
Radosław Piliszek authored
These two roles were missing 'stop' and 'deploy-containers', respectively. Change-Id: Iaf434be9baf1973323bb177fad799aea39210fba
-
- Aug 03, 2020
-
-
Mark Goddard authored
Some plays were not applied to all groups referenced by the services they deploy. In most cases this works fine, but if the default inventory is modified this may cause problems where containers are not deployed to hosts in the missing groups, if they are not a member of other groups that the play is targeted to. This change syncs up the play hosts for all services. Closes-Bug: #1889387 Change-Id: I6b92d8e53a29b06a065e0611840140d09c8a6695
-
- Jul 30, 2020
-
-
Radosław Piliszek authored
Masakari was introduced parallelly to deploy-containers action and so we missed to add this functionality to it. Change-Id: Ibef198d20d481bc92b38af786cdf0292b246bb12 Closes-Bug: #1889611
-
Nick Jones authored
With an incorrectly named section, whatever's defined in here is actually ignored which can result in unexpected behaviour. Closes-Bug: 1889455 Change-Id: Ib2e2b53e9a3c0e62a2e997881c0cd1f92acfb39c Signed-off-by:
Nick Jones <nick@dischord.org>
-
- Jul 29, 2020
-
-
likui authored
Option "network_label_regex" from group "DEFAULT" is deprecated for removal. Change-Id: I8aab2ca322159e61e4cbe9a5b30825a71a991e7e
-
- Jul 28, 2020
-
-
Radosław Piliszek authored
If not running containerised chrony, we need to check that host has its own means of system clock synchronization. Change-Id: I31b3e9ed625d63a4bf82c674593522268c20ec4c Partial-Bug: #1885689
-
Mark Goddard authored
Including tasks has a performance penalty when compared with importing tasks. If the include has a condition associated with it, then the overhead of the include may be lower than the overhead of skipping all imported tasks. In the case of the check-containers.yml include, the included file only has a single task, so the overhead of skipping this task will not be greater than the overhead of the task import. It therefore makes sense to switch to use import_tasks there. Partially-Implements: blueprint performance-improvements Change-Id: I65d911670649960708b9f6a4c110d1a7df1ad8f7
-
- Jul 27, 2020
-
-
Radosław Piliszek authored
Modern Ansible handles this just fine. Change-Id: Iea4d0499b92e2449ef8bc01651af6d3548ceab20
-
Radosław Piliszek authored
These are noop after Hyper-V support was removed. Change-Id: Ib451b154893e5cedc366aed83c35f48d92c7ab82
-
Justinas Balciunas authored
This change disables services in the Prometheus openstack-exporter if they are not enabled in the deployment. Such behaviour allows to avoid warnings and errors in the log files and keep the log file contents clean and informative. Change-Id: I4dcac976620a5f451e3d273183199aefe400994a
-
Christian Berendt authored
Change-Id: I2e22ec47f644de2f1509a0111c9e1fffe8da0a1a
-
Dincer Celik authored
Docker is manipulating iptables rules by default to provide network isolation, and this might cause problems if the host already has an iptables-based firewall. This change introduces docker_disable_default_iptables_rules to disable the iptables manipulation by putting "iptables: false" [1] to daemon.json For better defaults, this feature will be enabled by default in Victoria. [1] https://docs.docker.com/network/iptables/ Closes-Bug: #1849275 Change-Id: I165199fc98fb98f227f2a20284e1bab03ef65b5b
-
Doug Szumski authored
This fixes an issue where multiple Grafana instances would race to bootstrap the Grafana DB. The following changes are made: - Only start additional Grafana instances after the DB has been configured. - During upgrade, don't allow old instances to run with an upgraded DB schema. Change-Id: I3e0e077ba6a6f43667df042eb593107418a06c39 Closes-Bug: #1888681
-
Doug Szumski authored
This ensures that when using automatic Kafka topic creation, with more than one node in the Kafka cluster, all partitions in the topic are automatically replicated. When a single node goes down in a >=3 node cluster, these topics will continue to accept writes providing there are at least two insync replicas. In a two node cluster, no failures are tolerated. In a three node cluster, only a single node failure is tolerated. In a larger cluster the configuration may need manual tuning. This configuration follows advice given here: [1] https://docs.cloudera.com/documentation/kafka/1-2-x/topics/kafka_ha.html#xd_583c10bfdbd326ba-590cb1d1-149e9ca9886--6fec__section_d2t_ff2_lq Closes-Bug: #1888522 Change-Id: I7d38c6ccb22061aa88d9ac6e2e25c3e095fdb8c3
-
Michal Nasiadka authored
fluentd logs currently to stdout, which is known to produce big docker logs in /var/lib/docker. This change makes fluentd to log to /var/log/kolla/fluentd. Closes-Bug: #1888852 Change-Id: I8fe0e54cb764a26d26c6196cef68aadc6fd57b90
-
- Jul 24, 2020
-
-
Mark Goddard authored
This reverts commit 8fc86893. It appears that it is still necessary to wait for ironic to be up, otherwise inspector may fail to start: The baremetal service for 192.0.2.10:None exists but does not have any supported versions. Change-Id: Ibc8314c91113618ce9e92b8933a63eba3cf3bbe1
-
- Jul 23, 2020
-
-
wu.chunyang authored
octavia deploy failed due to mount a empyt directroy into container Change-Id: Ifd95126da59f649b02ab39c0b209df4750bdcfce
-
Mark Goddard authored
From Ussuri, if CA certificates are copied into /etc/kolla/certificates/ca/, these should be copied into all containers. This is not being done for masakari currently. Additionally, we are not setting the [DEFAULT] nova_ca_certificates_file option in masakari.conf. This depends on masakari bug 1873736 being fixed to work. This change fixes these issues. Change-Id: I9a3633f58e5eb734fa32edc03a3022a500761bbb Closes-Bug: #1888655
-
- Jul 22, 2020
-
-
Pierre Riteau authored
Some CloudKitty API responses include a Location header using http instead of https. Seen with `openstack rating module enable hashmap`. Change-Id: I11158bbfd2006e3574e165b6afc9c223b018d4bc Closes-Bug: #1888544
-
likui authored
global file glance_backend_file parameters not take effect Closes-Bug: #1888501 Change-Id: I3afd117633a84d342effb6baadf16fa42c16776c
-
- Jul 21, 2020
-
-
Pierre Riteau authored
A "@type copy" statement is already present at the beginning of each match element, so extra "type copy" are not needed. They are causing the following warnings in fluentd logs: [warn]: parameter 'type' in <match syslog.local0.**> [warn]: parameter 'type' in <match syslog.local1.**> This commit also harmonizes indentation of the Monasca config block. Change-Id: I779c2b942d007acbdd43d999f2fc0cdc131d431f Related-Bug: #1885873
-
Pierre Riteau authored
Change-Id: Ia134a518b63bb59cfad631cc488181f5245160e6
-
wu.chunyang authored
we should clone freezer code before run bootstray, otherwise, the directory /opt/stack/freezer which is empty will mount into freezer_api container. Closes-Bug: #1888242 Change-Id: I7c22dd380fd5b1dff7b421109c4ae37bab11834a
-
likui authored
Option "trove_auth_url/os_region_name" from group "DEFAULT" is deprecated. Use option "auth_url/region_name" from group service_credentials Change-Id: I15d6891582c92c7fc813f280a2b47ebaaca77eba
-
- Jul 17, 2020
-
-
Radosław Piliszek authored
This makes use of udev rules to make it smarter and override host-level packages settings. Additionally, this masks Ubuntu-only service that is another pain point in terms of /dev/kvm permissions. Fingers crossed for no further surprises. Change-Id: I61235b51e2e1325b8a9b4f85bf634f663c7ec3cc Closes-bug: #1681461
-