Earlier  
Posted Nick Remark
#openstack-nova - 2019-09-25
16:33:19 mriedem nope https://blueprints.launchpad.net/nova/+spec/hide-hypervisor-id-flavor-extra-spec was rocky
16:33:39 gregwork and there is no way to pass libvirt domain customizations
16:33:52 gregwork even kludgy ones :)
16:33:57 gregwork or even qemu execution lines
16:34:10 mriedem not through the compute api no
16:34:29 mriedem that's not really...cloud
16:35:29 artom Don't we have image props or something to make Windows happy?
16:35:54 mriedem artom: read scrollback
16:36:03 gregwork ever since they started planning to go to core based licensing instead of socket they have implemented some draconian things to prevent the potential for nested virtualization
16:36:11 openstackgerrit Merged openstack/nova master: docs: Scrub available quotas https://review.opendev.org/670125
16:36:31 gregwork especially since you can do performant nested virt with kvm on intel xeon e3-v4 processors using vmcs shadowing and device passthrough of network/storage
16:38:05 gregwork in our lab using those chips and passing through a virtual function off our nic to the L1 guest (hypervisor) we were only seeing a 5-10% difference in perf
16:38:10 gregwork it was really interesting
16:38:27 gregwork this is how hitachi does LPAR's on their x86_64 platform
16:39:04 gregwork hardware logical partitions which can run performant guests using intel xeon chips
16:39:17 gregwork anyhow it sucks i cant fiddle with this on queens
16:39:19 gregwork :/
16:40:51 mriedem i can't believe sean-k-mooney isn't around to chat about this
16:41:07 mriedem gregwork: well you could if you $$$ your vendor to backport a feature
16:43:32 artom mriedem, next time dinner first
16:47:00 mriedem dinner? you mean lunch?
16:47:05 mriedem what are you 80?
16:47:45 artom In my mind :(
16:53:35 mriedem stephenfin: i'm not sure we need this https://review.opendev.org/#/c/684781/ - it appears to already be fixed in master, though i guess we might want it just for backports
16:53:37 mriedem i left some notes inline
17:02:59 gmann mriedem: ohk. did you push the fix to tag tempest on pike gate ?
17:03:15 mriedem gmann: yup
17:03:41 gmann thanks. got it
17:09:17 openstackgerrit Matt Riedemann proposed openstack/nova master: Ignore sqla-migrate inspect.getargspec deprecation warnings on py36 https://review.opendev.org/684781
17:09:18 openstackgerrit Matt Riedemann proposed openstack/nova master: Ignore warning from sqlalchemy-migrate https://review.opendev.org/684772
17:09:18 openstackgerrit Matt Riedemann proposed openstack/nova master: tox: Use common 'command' definition for unit tests https://review.opendev.org/684774
17:09:19 openstackgerrit Matt Riedemann proposed openstack/nova master: tox: Stop overriding the 'install_command' https://review.opendev.org/684775
17:09:19 openstackgerrit Matt Riedemann proposed openstack/nova master: tests: Nuke OS_STDOUT_CAPTURE, OS_STDERR_CAPTURE https://review.opendev.org/684773
17:26:08 gregwork mriedem: what about sean-k-mooney ?
17:33:08 sean-k-mooney gregwork: mriedem sriov testing?
17:34:02 gregwork sean-k-mooney: hi, no actually trying to fool a windows instance on openstack into not thinking it is a guest. either modifying the domain in libvirt or possibly passing args to qemu-kvm
17:34:08 gregwork i have a working libvirt domain that does what i need
17:34:17 gregwork trying to figure out how to do this with nova/kvm
17:34:27 sean-k-mooney i tested doing nested sriov like 3 weeks ago and it does work if you enable a vIOMMU in the l1 guest and use q35 chipset but you need to play with the pci layout to fix the iommu groups
17:34:30 sean-k-mooney oh
17:34:32 sean-k-mooney ok
17:34:44 sean-k-mooney i think we fixed that
17:34:55 sean-k-mooney so you can enable hypervior hideing
17:34:56 gregwork yeah the nested virt works great if you have a chip that can do vmcs shadowing, and do passthrough devices for the L1 guest
17:35:10 gregwork if you dont pass through network/storage it will suck real bad for the L2 guests
17:35:23 gregwork at least then you remove 1 layer of nested virt (storage/network)
17:35:27 sean-k-mooney and we not hardcode a fake vendor id in the hyperv secotion so it thinks its running on a phyical host
17:35:45 gregwork part of it is disabling the hypervisor cpu flag in the guest
17:35:49 gregwork the other is the vendor string thing
17:36:07 sean-k-mooney yes if you set teh image property i think it does both
17:36:42 sean-k-mooney gregwork: have you tried setting img_hide_hypervisor_id
17:36:47 sean-k-mooney in the image to yes
17:37:05 gregwork do you know if a certain hat wearing vendor backported that to their queens release
17:37:26 sean-k-mooney i could check
17:37:35 sean-k-mooney but not off the top of my head
17:37:51 sean-k-mooney the image property woudl not be backportable due to object changes
17:38:03 sean-k-mooney but i belive you can also contol the behavior via the flavor
17:38:14 sean-k-mooney the flavor extra spec would be backportable
17:38:21 sean-k-mooney downstream
17:40:34 sean-k-mooney it looks like the kvm supprot is ther for linux guests
17:40:44 sean-k-mooney which means the image property should be there
17:41:13 sean-k-mooney but the support for windows guest has not been backported
17:41:38 sean-k-mooney http://paste.openstack.org/show/779253/
17:41:54 sean-k-mooney gregwork: ^ that is the downstream code for generating the elements
17:49:49 sean-k-mooney gregwork: assuming you or one of your customers are a customer of said company have you filed a Bugzilla ro case to request the feature backport.
17:50:13 gregwork im initially trying to figure out if this was a thing accomplished another way
17:50:30 mriedem sean-k-mooney: if you're around i think we're waiting on an ack from you for https://review.opendev.org/#/c/683437/
17:50:32 sean-k-mooney gregwork: im not committing to it being granted but in principal i belive this would be a minimal risk
17:51:24 sean-k-mooney mriedem: strictly speaking its my birthday and im off but yes im waiting for windows updates to install so if have a few minutes
17:51:40 gregwork sean-k-mooney: happy bday sean :)
17:51:59 sean-k-mooney thanks you :)
17:52:18 gregwork i think i spoke to you here a few years about getting dpdk working with mellanox cards
17:52:21 gregwork your nic is familiar
17:52:27 gregwork *nick
17:52:43 sean-k-mooney yes we have spoken before
17:52:57 sean-k-mooney an ya i used to work with dpdk alot
17:53:08 sean-k-mooney im hopeing to get a dpdk gate job running soon
17:53:34 gregwork are you still with intel
17:53:57 sean-k-mooney no i moved to redhat about 14 months ago
17:54:14 sean-k-mooney hence why i was able to check the OSP downstream code
17:54:24 gregwork oh i just figured you were more in the know
17:54:46 gregwork that link you posted, was that for osp 15 ?
17:55:01 sean-k-mooney no it was osp 13 which is queens
17:55:40 sean-k-mooney so queens has support for hideing the hypervior signature for linux guest
17:55:53 gregwork not not the required bits for a windows guest
17:55:55 sean-k-mooney all its missing is the hyperv vendor signiture bit
17:55:58 gregwork *but
17:56:27 sean-k-mooney so a backport of the fix would just be the xml generation change the rest of the code is alreay in place
17:57:29 sean-k-mooney gregwork mriedem can correct me if im wrong but i think we fixed windwos guest in stien so 15 should have the support.
17:57:53 gregwork we are doing a prod rollout so the business decision was to stick with LTS releases
17:58:04 gregwork so 14 and 15 dont exist as options for us sadly
17:58:18 mriedem sean-k-mooney: train https://review.opendev.org/#/c/579897/
17:58:25 sean-k-mooney unfortunetly you are not the only customer with that view
17:59:02 sean-k-mooney oh so it was. it felt recent but i did not think it was train
17:59:42 sean-k-mooney mriedem: we ended up treating this as a bug. is it a candiate for upstream backport? generally i would assume not but it does not hurt to ask
17:59:54 gregwork im debating trying to patch this myself and splice it in /var/lib/config-data/puppet-generated/nova_libvirt and see if i can get the hyperv processor bits to die
18:00:12 gregwork then maybe circle back with an rfe
18:04:33 mriedem sean-k-mooney: exhibit A https://review.opendev.org/#/c/663616/
18:05:09 mriedem either way the hide_hypervisor_id stuff upstream was in rocky so gregwork doesn't have it anyway
18:05:32 mriedem unless you guys in rhosp are going to backport a feature

Earlier   Later