| Posted | Nick | Remark | |
|---|---|---|---|
| #openstack-nova - 2019-11-06 | |||
| 21:02:28 | mriedem | i've got a recording on youtube that does that with a floating ip | |
| 21:02:29 | sean-k-mooney | devstack will auto run the local.sh if present | |
| 21:02:36 | efried | openstack server reboot | |
| 21:02:36 | efried | openstack security group rule create --ingress --protocol tcp --remote-ip 0.0.0.0/0 $group for all three groups | |
| 21:02:36 | efried | openstack subnet set --dhcp public-subnet | |
| 21:02:36 | efried | I did | |
| 21:02:47 | efried | mriedem: yes, that's what I'm trying to do. | |
| 21:02:50 | sean-k-mooney | yep that should be enough | |
| 21:02:58 | mriedem | heh, it's been like 3 days :) | |
| 21:02:58 | mriedem | sec | |
| 21:03:39 | mriedem | efried: it's a bit old, but this shows setting up a guest in devstack with a floating ip to ssh into it https://www.youtube.com/watch?v=hZg6wqxdEHk | |
| 21:03:58 | sean-k-mooney | ... my clean vm failed because i forget to mount /opt on a cinder volume and ran out of space :( | |
| 21:04:25 | efried | thanks mriedem, will try that on my other devstack | |
| 21:04:42 | efried | ssh: connect to host 2001:db8::109 port 22: No route to host | |
| 21:04:42 | efried | stack@nucle:/opt/stack/devstack$ openstack server ssh --private -l cirros test1 | |
| 21:04:42 | efried | sean-k-mooney: | |
| 21:04:54 | sean-k-mooney | add -4 | |
| 21:04:59 | mriedem | start about 3 minutes in | |
| 21:05:04 | mriedem | ignore all of the volume multiattach stuff | |
| 21:05:06 | sean-k-mooney | unless you have routable ipv6 | |
| 21:05:27 | sean-k-mooney | if you do you need to change teh --remote-ip to allow ipv6 trafic | |
| 21:05:56 | sean-k-mooney | efried: you cans also just use ssh directly if you know the ip | |
| 21:06:06 | efried | ah, but I can ssh to the IP... yes | |
| 21:06:22 | efried | I don't think I can ipv6 at all | |
| 21:06:49 | ioni | g like lxd/openvz | |
| 21:06:49 | ioni | hello guys, i'm using openstack in production and also sadly still use openvz and i plan to move away from it in the near future. is there a project that i can use with openstack to orchestrate containers like openvz. lxd seems the same but nova-lxd is not maintained anymore and everything that i can find related to openstack and containers is mostly related to docker and kubernets but not somethin | |
| 21:07:01 | efried | adding -4 also made the openstack command work | |
| 21:07:11 | sean-k-mooney | efried: the firewall is blocking all ipv6 into the vm by default | |
| 21:07:19 | mriedem | ioni: zun | |
| 21:07:31 | efried | sokay, I'm pretty sure ipv6 is never going to catch on anyway. I'll just use v4 | |
| 21:07:34 | efried | thanks for the help, again. | |
| 21:08:09 | sean-k-mooney | haha i spend like a full weekend getting it working at home like a month ago | |
| 21:08:48 | sean-k-mooney | i dont have native ipv6 at home so had to set up tunneling and then route it into openstack so that my vms get public ipv6 adresses | |
| 21:08:55 | mriedem | "how do i ssh into a guest in devstack" <3 days later> "wait, you don't need ipv6 with numa and dpdk? oh, well then..." | |
| 21:09:35 | sean-k-mooney | :) | |
| 21:09:47 | sean-k-mooney | mriedem: actully regarding multi attach | |
| 21:09:51 | mriedem | stop | |
| 21:09:56 | sean-k-mooney | what file system do you use? | |
| 21:10:08 | mriedem | in this demo? | |
| 21:10:12 | sean-k-mooney | in general | |
| 21:10:18 | mriedem | i don't | |
| 21:10:22 | sean-k-mooney | i dont think we mention it in the docs | |
| 21:10:24 | sean-k-mooney | ok | |
| 21:10:33 | mriedem | multiattach docs are mostly in cinder | |
| 21:10:47 | sean-k-mooney | ah o should read those at some point | |
| 21:11:04 | mriedem | https://docs.openstack.org/cinder/latest/admin/blockstorage-volume-multiattach.html | |
| 21:11:07 | mriedem | doesn't really go into details either | |
| 21:11:15 | ioni | mriedem, zun seems that it uses docker and is not something that i can replace openvz with | |
| 21:11:29 | sean-k-mooney | i was thinking of using it for k8s on openstack but it seamed complicated | |
| 21:11:30 | mriedem | efried: so about 9 minutes into that demo i'm creating a floating ip for the port attached to the server | |
| 21:13:00 | mriedem | might be useful if i just wrote this up into devstack docs | |
| 21:13:27 | sean-k-mooney | mriedem: i think there used to be an exersie that coverd it | |
| 21:13:36 | sean-k-mooney | but i cant find it | |
| 21:14:00 | mriedem | ioni: nova isn't really big on containers, it's basically vms and a front end for ironic baremetal, | |
| 21:14:24 | mriedem | nova-lxd is a thing out of tree as you know, openvz is in who knows what kind of maintenance state, and then there is libvirt+lxc which is also - who really knows if it works very well right now | |
| 21:15:22 | mriedem | of course with cirros you can just login with a password | |
| 21:15:25 | efried | sean-k-mooney: presumably I could have done all that dhcp and security group nonsense before creating the vm | |
| 21:15:41 | sean-k-mooney | efried: yes and you only have to do it once | |
| 21:15:54 | sean-k-mooney | efried: also i normally do it all via horizon as its faster | |
| 21:15:54 | efried | k, writing myself a cheat sheet | |
| 21:16:10 | efried | ew, gui | |
| 21:16:21 | sean-k-mooney | the cli is faster for most things but security groups are a pain on the cli | |
| 21:16:46 | efried | cheat sheet line for that: | |
| 21:16:47 | efried | openstack security group list -f value -c ID | xargs -n1 openstack security group rule create --ingress --protocol tcp --remote-ip 0.0.0.0/0 | |
| 21:17:02 | sean-k-mooney | efried: anyway as i said once you have the command you need to run. just put them in a file called local.sh and it will be run at the right time | |
| 21:17:44 | sean-k-mooney | oh is in the default local.sh in samples/local.sh | |
| 21:17:53 | sean-k-mooney | just copy that up one directory | |
| 21:18:48 | efried | hm, I thought I did all the right things on my other setup, but I'm still getting no route to host. | |
| 21:18:55 | efried | aaand gotta run get a kid | |
| 21:21:26 | melwitt | ioni: I see mention of openvz in the original proposal for the magnum project https://specs.openstack.org/openstack/magnum-specs/specs/pre-ocata/implemented/containers-service.html but I don't know if it supports it today | |
| 21:23:28 | sean-k-mooney | melwitt: ioni magnum is a different usage model | |
| 21:23:45 | sean-k-mooney | nova libvirt/lxc woudl be the closest | |
| 21:24:02 | melwitt | oh ok | |
| 21:24:10 | ioni | i just want to stop using openvz and migrate the current containers to something orchestrated by openstack with good support | |
| 21:24:28 | ioni | nova-lxd was something i could use but that was dropped recently by canonical | |
| 21:24:46 | sean-k-mooney | ioni: well there isnt really a good path forward if you also want the nova api | |
| 21:25:04 | sean-k-mooney | zun will work with docker style container but not system contianers | |
| 21:25:09 | sean-k-mooney | as far as i know | |
| 21:25:21 | ioni | right, that is want i found as well | |
| 21:25:32 | sean-k-mooney | nova libvirt wiht lxc could work but it does not have good support a the momemnt | |
| 21:25:51 | sean-k-mooney | if there was a lot of interest in it it would not take that much to get it working well again | |
| 21:26:26 | ioni | everybody told me that lxc support is not that great and was too scared to try it | |
| 21:26:48 | sean-k-mooney | its not but its not that far form being ok | |
| 21:27:31 | sean-k-mooney | the openvz driver is proably the best supproted fo all the nova conatiner drivers at the moment | |
| 21:27:43 | sean-k-mooney | it has not reaaly been a focus of nova of late | |
| 21:29:17 | openstackgerrit | Merged openstack/python-novaclient master: doc: Fix supported version descriptions https://review.opendev.org/693097 | |
| 21:29:29 | mriedem | i'm guessing the openvz 3rd party ci is still busted | |
| 21:30:33 | sean-k-mooney | was that the ci that had a hardcoded patch that is now in conclict because we fixed the bug | |
| 21:30:43 | mriedem | yes | |
| 21:31:17 | mriedem | looks like it doesn't even report anymore | |
| 21:31:26 | sean-k-mooney | ya i was just going to say that | |
| 21:31:32 | sean-k-mooney | i have not seen it in a while | |
| 21:31:43 | ioni | sean-k-mooney, alright thanks. i'll take a look at openvz 7 and nova | |
| 21:32:18 | sean-k-mooney | ioni: if you need contianer i would not bet on that long term | |
| 21:33:42 | ioni | sean-k-mooney, indeed, i mostly think that i'll do a container to full kvm migration, but that really sucks | |
| 21:34:39 | openstackgerrit | Matt Riedemann proposed openstack/nova master: Use ListOfUUIDField from oslo.versionedobjects https://review.opendev.org/693258 | |
| 21:34:49 | sean-k-mooney | if you are interested in system contaienr there are afew other like donnyd who also share that interest | |
| 21:35:47 | sean-k-mooney | so we could try and fix/test libvit lxc upstream but its currntly on lifesupprot/hobbyist support | |
| 21:36:20 | sean-k-mooney | kvm will have less desitiny but its deffently the best tested solution | |
| 21:37:41 | sean-k-mooney | night all o/ | |