Re: [Openstack] Liberty: (path|segment)_mtu values

2016-07-07 Thread Matt Kassawara
The effect of these options depends on your version of Liberty. Some patches fixing MTU implementation in Mitaka+ were backported to Liberty [1]. [1] https://review.openstack.org/#/c/305782/ On Mon, Jul 4, 2016 at 2:18 AM, Nicolas Bock wrote: > Hi, > > I am trying to understand the effect of th

Re: [Openstack] Openstack Mitaka - Neutron configuration

2016-06-03 Thread Matt Kassawara
You can use the management interface in the Linux bridge agent interface mappings, but using a single interface for management and instances with Linux bridge requires some additional configuration at the host level to prevent the Networking service from breaking management connectivity. Also, DHCP

Re: [Openstack] Whole sections of ml2_conf.ini being ignored?

2016-02-19 Thread Matt Kassawara
e virtual router (even from the > internet on its public port!) but cannot reach the running instance on > either IP (tried all the namespaces with ip netns exec... with both IPs but > nothing). But I will create a new thread here unless someone has a quick > answer. > On 19 Feb 2016 09:00,

Re: [Openstack] Whole sections of ml2_conf.ini being ignored?

2016-02-19 Thread Matt Kassawara
Looks like we (docs) never backported those fixes to the Liberty version of the guide. For some reason, the patch does not merge cleanly so I'm not sure when I'll get to it. On Thu, Feb 18, 2016 at 11:08 PM, Matt Kassawara wrote: > In Liberty, the L2 agent configuration moves from

Re: [Openstack] Whole sections of ml2_conf.ini being ignored?

2016-02-18 Thread Matt Kassawara
In Liberty, the L2 agent configuration moves from ml2_conf.ini to openvswitch_agent.ini for OVS and linuxbridge_agent.ini for Linux bridge. On Thu, Feb 18, 2016 at 10:51 PM, Mark Hayden wrote: > Hi, > > I have recently installed a small openstack setup using the Liberty > release (from Debian Si

Re: [Openstack] DVR and public IP consumption

2016-01-22 Thread Matt Kassawara
Do you need project/private networks? If so, do those networks need to route to provider/public networks? For a number of reasons, most of which seem to revolve around the concept of floating IP addresses and neutron routing performance/complexity issues, providers often attach VMs directly to prov

Re: [Openstack] Question about OpenStack Networking on Liberty

2016-01-20 Thread Matt Kassawara
See the DVR scenario in the networking guide [1]. [1] http://docs.openstack.org/liberty/networking-guide/scenario_dvr_ovs.html On Wed, Jan 20, 2016 at 2:39 AM, BYEONG-GI KIM wrote: > Hello. > > I've been learning OpenStack from Havana, and as far as I know the DVR > (Distributed Virtual Router)

Re: [Openstack] [neutron] User documentation for Neutron's Firewall-as-a-Service (FWaaS)?

2016-01-12 Thread Matt Kassawara
Not really... :/ On Tue, Jan 12, 2016 at 9:43 AM, Mike Spreitzer wrote: > Is there any user documentation for FWaaS besides > *http://docs.openstack.org/admin-guide-cloud/networking_introduction.html#firewall-as-a-service-fwaas-overview* >

Re: [Openstack] [openstack] Wrong descriptions for something

2016-01-07 Thread Matt Kassawara
Can you provide an example? On Thu, Jan 7, 2016 at 7:17 PM, Shinobu Kinjo wrote: > Hello, > > If there is any wrong explanation on > https://wiki.openstack.org/wiki/**something**, > what is usual procedure? > > Usually I don't mind but sometimes... > > Is there maintainers? > > Rgds, > Shinobu >

Re: [Openstack] Moving from Legacy with GRE to Provider with Linux bridge

2016-01-06 Thread Matt Kassawara
Could be a number of things. Did the deployment work with OVS + GRE before you moved to LB with provider networks? On Wed, Jan 6, 2016 at 11:36 AM, Tyler Couto wrote: > Hi all, > > I¹m moving openstack from legacy networking with GRE to provider > networking with linux bridge. I¹m new to Opensta

Re: [Openstack] Moving from vSphere to openstack

2015-12-15 Thread Matt Kassawara
I can speak to the networking bits... In OpenStack, DHCP doesn't imply inconsistent IP addresses. If you boot a VM without a specific IP address, it keeps the IP chosen for it until you destroy the VM. If you boot a VM with a specific (static) IP address, DHCP serves that IP to the VM. You can dis

Re: [Openstack] Liberty Dashboard Error: Unable to retrieve floating IP addresses and connect to Neutron.

2015-11-29 Thread Matt Kassawara
If you're only using public/provider networks (no L3 agent), you probably came across this bug: https://bugs.launchpad.net/horizon/+bug/1515572 On Sat, Nov 28, 2015 at 11:31 PM, Aijun Wang wrote: > Hi all > After installation step by step on CentOS7 1503 by Installation > Guide - http://d

Re: [Openstack] How to connect instance directly to (additional) external network?

2015-11-21 Thread Matt Kassawara
See the provider networks scenario in the networking guide [1]. [1] http://docs.openstack.org/networking-guide/scenario_provider_ovs.html On Sat, Nov 21, 2015 at 4:27 PM, Amir Huskić wrote: > How to connect instance directly to external network using Neutron, ML2, > OVS? I have created addition

Re: [Openstack] Openstack Identity: could not create service endpoint

2015-11-12 Thread Matt Kassawara
Sure you're installing Liberty packages? On Thu, Nov 12, 2015 at 3:26 PM, Joerg Streckfuss wrote: > Dear list, > > i have tried to install the keystone service (liberty) on centos 7 > following the docs under: > > http://docs.openstack.org/liberty/install-guide-rdo/keystone-install.html > > When

Re: [Openstack] liberty's documentation

2015-11-03 Thread Matt Kassawara
At this point, a Debian version of the installation guide for Liberty seems unlikely, at least in the near future. However, Debian and Ubuntu are similar enough that you could probably determine the repository for OpenStack packages on Debian, disable Debconf, and follow the Ubuntu version of the i

Re: [Openstack] Documentaiton Status Openstack Liberty

2015-10-29 Thread Matt Kassawara
We haven't officially published the Liberty guide for RHEL/CentOS yet due to some timing issues with package availability during the development process. I recommend waiting for the Liberty documentation because it contains architectural changes that primarily make networking easier and more flexib

Re: [Openstack] [Neutron] DVR wiki

2015-10-22 Thread Matt Kassawara
You should see the networking guide, particularly the DVR scenario. http://docs.openstack.org/networking-guide/scenario_dvr_ovs.html On Thu, Oct 22, 2015 at 1:33 PM, Adam Lawson wrote: > https://wiki.openstack.org/wiki/Neutron/DVR_L2_Agent > > Is this wiki link up to date explaining neutron DVR

Re: [Openstack] Liberty address-scope

2015-10-20 Thread Matt Kassawara
> > > root@compute1:~# brctl show > bridge name bridge id STP enabled interfaces > brq432a531d-9d 8000.767a4a107f5e no > tap6c99f105-81 > vxlan-83 > ​# &

Re: [Openstack] Liberty address-scope

2015-10-20 Thread Matt Kassawara
I suspect that extension appeared in the list while updating the installation guide using pre-release packages. I don't see it in my lab environment with release packages. In any case, I don't think it is causing your problem. Can you elaborate on "router is not able to see the public network" and

Re: [Openstack] [Liberty] Option "driver = memcached" under [token] in keystone.conf triggers an error...

2015-10-18 Thread Matt Kassawara
for driver in the token section. AFAIK, there are some > issues with python-memcache library yet ( > https://bugs.launchpad.net/keystone/+bug/1462152/comments/6) > > Regards/Saludos > Victor Morales > > From: Matt Kassawara > Date: Sunday, October 18, 2015 at

Re: [Openstack] [Liberty] Option "driver = memcached" under [token] in keystone.conf triggers an error...

2015-10-18 Thread Matt Kassawara
The documentation says "driver = memcache" not "driver = memcached". On Sat, Oct 17, 2015 at 10:33 PM, Martinx - ジェームズ wrote: > On 18 October 2015 at 02:16, Martinx - ジェームズ > wrote: > > Guys, > > > > I'm trying to install Liberty on Ubuntu Trusty, I'm following the doc: > > > > > http://docs.op

Re: [Openstack] OpenStack "Liberty" is officially released !

2015-10-16 Thread Matt Kassawara
Ubuntu has not published Liberty release packages to the cloud archive repository (for 14.04) and RDO has not provided a permanent location for any Liberty packages yet. On Fri, Oct 16, 2015 at 12:04 PM, Martinx - ジェームズ wrote: > Amazing times!!! Thanks you guys! > > It is already included in Ubu

Re: [Openstack] 'NoneType' object has no attribute 'service_catalog' with openstack command

2015-10-16 Thread Matt Kassawara
Ubuntu has not published official packages for Liberty, so your installation is probably using RC1 pre-release packages. Also, I cannot reproduce your issue on any of my labs that I use to develop the installation guide. Did you forget to unset the OS_TOKEN OS_URL environment variables? On Fri, Oc

Re: [Openstack] [Openstack-operators] [Neutron][Linuxbridge] Problem with configuring linux bridge agent with vxlan networks

2015-10-02 Thread Matt Kassawara
Did you review the scenarios in the networking guide [1]? [1] http://docs.openstack.org/networking-guide/deploy.html On Fri, Oct 2, 2015 at 2:41 PM, Sławek Kapłoński wrote: > Hello, > > I'm trying to configure small openstack infra (one network node, 2 > compute nodes) with linux bridge and vxl

Re: [Openstack] Neutron add external interface to external router?

2015-09-02 Thread Matt Kassawara
Using the Linux bridge agent? If so, take a look at the scenario [1] in the networking guide. [1] http://docs.openstack.org/networking-guide/scenario_legacy_lb.html On Wed, Sep 2, 2015 at 5:22 AM, Mohammed Naser wrote: > Sorry for brief reply, I'm on mobile > > external_network_bridge is suppos

Re: [Openstack] HA for Network node

2015-08-12 Thread Matt Kassawara
Icehouse is EOL. On Wed, Aug 12, 2015 at 10:54 AM, Hoài Nam wrote: > Thanks Matt Kassaware for reply my question. I am using release Icehouse, > but Icehouse don’t have support configuration HA for L3-agent L > > > > *From:* Matt Kassawara [mailto:mkassaw...@gmail.com] > *

Re: [Openstack] HA for Network node

2015-08-12 Thread Matt Kassawara
http://docs.openstack.org/networking-guide/deploy.html On Wed, Aug 12, 2015 at 9:46 AM, Hoài Nam wrote: > Hi everyone. My name is Nam. I am having a problem with Network node, now > i want to HA for Network node, when i have read ebook of OpenStack about > > using pacemaker but I haven't cleanl

Re: [Openstack] qg port in br-int

2015-06-17 Thread Matt Kassawara
A few releases ago, neutron only supported one external network per L3 agent. However, it currently supports multiple external networks if you set a blank value for the external_network_bridge option. On Wed, Jun 17, 2015 at 4:22 AM, Andreas Scheuring < scheu...@linux.vnet.ibm.com> wrote: > Yes,

Re: [Openstack] Openstack Kilo Fresh install on Centos7 Create Keystone Service Error

2015-05-26 Thread Matt Kassawara
tallation as I am following the documentation so not really sure where >> it is going wrong. >> >> >> >> Thanks >> >> >> >> Darren >> >> >> >> *From:* Mehdi BADAOUI [mailto:mehdiu...@gmail.com] >> *Sent:* 26 May 2015 15:58 >

Re: [Openstack] Openstack Kilo Fresh install on Centos7 Create Keystone Service Error

2015-05-26 Thread Matt Kassawara
A 404 indicates that Apache is probably listening on ports 5000 and 35357. Can you check with the 'ss -lntp' command to verify both ports? Also, can you check the WSGI configuration (wsgi-keystone.conf) again and the files that you copy into the /var/www/cgi-bin/keystone directory? On Tue, May 26,

Re: [Openstack] keystone service endpoint creation failing on RHEL7

2015-05-25 Thread Matt Kassawara
installation guide, > http://docs.openstack.org/kilo/install-guide/install/yum/content/keystone-install.html, > and if the 'usermod -a -G keystone apache' is for what you mentioned, yes, > I did. > > Am I missing something? > > > 2015-05-26 10:32 GMT+09:00 Matt K

Re: [Openstack] keystone service endpoint creation failing on RHEL7

2015-05-25 Thread Matt Kassawara
Starting the keystone service simply enables Eventlet, a library deprecated in Kilo in favor of the Apache HTTP server. I'd call it a workaround rather than a valid solution. Did you try adding the group to the WSGI configuration? On Mon, May 25, 2015 at 8:04 PM, BYEONG-GI KIM wrote: > Hello. >

Re: [Openstack] keystone service endpoint creation failing on RHEL7

2015-05-25 Thread Matt Kassawara
At least on RH, try adding group=keystone to the WSGIDaemonProcess option. On Mon, May 25, 2015 at 05:53 wrote: > > > There's definitely something weird going on now we're trying SLES and > getting the same error. > > > > This is the keystone-error.log (apache) > > > > 2015-05-25 05:36:00.029

Re: [Openstack] keystone service endpoint creation failing on RHEL7

2015-05-24 Thread Matt Kassawara
What do you mean... tasks you've yet to get to? The patch addresses configuration prior to adding anything to the keystone database. On Sun, May 24, 2015 at 10:07 AM, Antonio Messina wrote: > Are you sure it's not a mysql error? Check permission for user keystone > from localhost, you might need

Re: [Openstack] keystone service endpoint creation failing on RHEL7

2015-05-23 Thread Matt Kassawara
ot;Access denied for user 'keystone'@'localhost' > (using password: YES)") None None > > In keystone.conf the hostname is set to "controller", not localhost. (and > changing it makes no diff) > > Thanks, > > Mike. > > > > On 23/0

Re: [Openstack] keystone service endpoint creation failing on RHEL7

2015-05-22 Thread Matt Kassawara
Yep, that patch should fix it. In particular, adding the group 'keystone' to the WSGI configuration bits. On Fri, May 22, 2015 at 9:59 PM, Steve Gordon wrote: > - Original Message - > > From: mich...@tropyx.com > > To: openstack@lists.openstack.org > > > > Hi List, > > > > We're trying t

Re: [Openstack] keystone service endpoint creation failing on RHEL7

2015-05-22 Thread Matt Kassawara
Robson, In this particular case, I believe the WSGI bits can't read the keystone configuration file and assume default values. On Fri, May 22, 2015 at 11:15 PM, Robson Ramos Barreto < robson.rbarr...@gmail.com> wrote: > Hi Michael, > > Did you check the grant to keystone user on database and are

Re: [Openstack] OpenStack Kilo RC1 for Ubuntu 14.04 LTS and Ubuntu 15.04.

2015-04-21 Thread Matt Kassawara
Thiago, The upstream installation guide deploys a minimal operational environment (with first-time users in mind) rather than a production environment. The installation guide covers several distributions and attempts to minimize content duplication by finding common ground for all of them. As such

Re: [Openstack] nova.conf (on Ubuntu 14.04) and documentation differing.

2015-01-27 Thread Matt Kassawara
Packages should include at least the upstream example configuration file(s). For some reason, Ubuntu continues to package a very minimal nova.conf file. Please file a bug under the Ubuntu nova package [1] rather than the documentation. [1] https://bugs.launchpad.net/ubuntu/+source/nova On Tue, Ja

Re: [Openstack] [juno][DVR]

2015-01-02 Thread Matt Kassawara
You might find this content useful... https://github.com/ionosphere80/openstack-networking-guide/blob/master/scenario-dvr/scenario-dvr.md The upcoming networking guide on docs.openstack.org (not available yet) will include this content plus content for other recent neutron features such as L3 HA.

Re: [Openstack] Glance timeout error

2014-11-07 Thread Matt Kassawara
Glance shouldn't use the message queue unless you're using ceilometer. The default configuration file might enable it, but it won't work without configuring additional options. In glance-api.conf, configure 'notification_driver = noop' to disable it. On Fri, Nov 7, 2014 at 9:16 AM, varun bhatnagar

Re: [Openstack] neutron error on upgrading from icehouse to juno

2014-10-19 Thread Matt Kassawara
The 'stamp' option sets the DB version so the upgrade process knows where to start and the 'upgrade' option actually upgrades the DB[1]. You probably want to re-stamp the DB as 'icehouse' and then upgrade to 'juno'. [1] https://github.com/openstack/neutron/blob/master/neutron/db/migration/README

Re: [Openstack] [Nova] Seeking clarification of 'auth_uri' configuration key

2014-10-18 Thread Matt Kassawara
The identity_uri option replaces auth_host/port/protocol in Juno. On Fri, Oct 17, 2014 at 9:13 AM, Lars Kellogg-Stedman wrote: > I'd like to resurrect the following thread from January: > > (http://lists.openstack.org/pipermail/openstack/2014-January/004968.html) > > > > ...and to pile on, ano

Re: [Openstack] [Openstack-docs] [OPENSTACK][TROVE] Modify to the manual installation guide

2014-03-08 Thread Matt Kassawara
Yes, we need to add a chapter for Trove to the installation guide. On Sat, Mar 8, 2014 at 11:29 AM, Andreas Jaeger wrote: > On 03/08/2014 02:59 PM, Giuseppe Galeota wrote: > >>>2014-03-07 19:58 GMT+01:00 Michael Basnight > >: > > > > >>Giuseppe Galeota >

Re: [Openstack] Seeking clarification of 'auth_uri' configuration key

2014-01-14 Thread Matt Kassawara
Original Message - > > From: "Matt Kassawara" > > To: openstack@lists.openstack.org > > Sent: Tuesday, January 14, 2014 2:12:47 PM > > Subject: [Openstack] Seeking clarification of 'auth_uri' configuration > key > > > > Hi,

[Openstack] Seeking clarification of 'auth_uri' configuration key

2014-01-14 Thread Matt Kassawara
Hi, When authenticating via Keystone, most services seem to require configuring the 'auth_uri' key to prevent the following warning: WARNING keystoneclient.middleware.auth_token [-] Configuring auth_uri to point to the public identity endpoint is required; clients may not be able to authenticate

Re: [Openstack] Monitoring OpenStack platform

2014-01-03 Thread Matt Kassawara
Zenoss offers a module for OpenStack... http://wiki.zenoss.org/ZenPack:OpenStack_Cloud_Monitor On Fri, Jan 3, 2014 at 10:08 AM, Kaushal Shriyan wrote: > Hi, > > Are there monitoring tools to monitor OpenStack platform for example KVM > Hypervisor and the guest hosts? > > Regards, > > Kaushal >

[Openstack] Dedicated network node and neutron-server daemon

2014-01-02 Thread Matt Kassawara
I am following the "official" installation guide to build two separate lab environments using Havana with Neutron, each with a three-node configuration: controller, network, and compute. One environment runs on Ubuntu 12.04 LTS and the other on Scientific Linux 6.4. In both environments, the netw

Re: [Openstack] neutron install guide wording question

2013-12-23 Thread Matt Kassawara
You don't need a three-node architecture (controller, network, and compute) to deploy the Networking/Neutron service, but it seems to work best with the installation guide and also simplifies debugging. On Mon, Dec 23, 2013 at 5:07 PM, August Simonelli wrote: > Hi all, > > I’m currently going t

Re: [Openstack] Security group rules not propagating to instances

2013-12-15 Thread Matt Kassawara
e21971d1b2c27', 'provider:network_type': u'gre', 'router:external': False, 'shared': False, 'id': u'c095696e-6b0e-488f-bfdd-c81121137814', 'provider:segmentation_id': 2L} On Sun, Dec 15, 2013 at 6:13 AM, 郭龙仓 wrote: > Have

Re: [Openstack] Security group rules not propagating to instances

2013-12-13 Thread Matt Kassawara
Hmm, that looks more like a nova-net issue than a neutron issue. On Fri, Dec 13, 2013 at 6:07 PM, John Smith wrote: > On Sat, Dec 14, 2013 at 1:45 AM, Matt Kassawara > wrote: > > Hmm... anyone else experienced this problem? > > > Dont know. Is it anything

Re: [Openstack] Security group rules not propagating to instances

2013-12-13 Thread Matt Kassawara
Hmm... anyone else experienced this problem? On Fri, Dec 6, 2013 at 1:05 PM, Matt Kassawara wrote: > I installed Havana with Neutron on Scientific Linux 6.4 using the official > installation guide. I added the following rules to the default security > group to enable inbound ping a

Re: [Openstack] OpenStack networking and disks...

2013-12-10 Thread Matt Kassawara
This document was helpful for me... http://openstack.redhat.com/Networking_in_too_much_detail On Tue, Dec 10, 2013 at 12:36 PM, Gonzalo Aguilar Delgado < gagui...@aguilardelgado.com> wrote: > Hi Scott > > I have OVS. I did took a look to this document some time ago, the problem > is that right

[Openstack] Security group rules not propagating to instances

2013-12-06 Thread Matt Kassawara
I installed Havana with Neutron on Scientific Linux 6.4 using the official installation guide. I added the following rules to the default security group to enable inbound ping and secure shell access to my instances with floating IPs: nova secgroup-add-rule default icmp -1 -1 0.0.0.0/0 nova secgr