Re: VPC ACLs SRC and DST

2018-07-18 Thread Andrija Panic
Hi Adam, unless something has changed in most recent version (doubt that) - no, you can only define one CIDR in each ACL rule, which, if creating egress/outbound rule is considered as destination IP/CIDR to which you alow/deny access from your VPC network, or if using ingress (inbound) rule, then

Re: add new ip range to zone

2018-07-18 Thread Andrija Panic
Bunch of Public IP ranges, again in same VLAN... (gateway is just an virtual inteface on physical router...all virtual interfaces in same vlan) On Wed, 18 Jul 2018 at 14:28, Nicolas Bouige wrote: > Hi Rafael, > > yes, we had the situation but both ranges of public IPs was already in the > same V

Re: Unable to upload volumes 4.11.0

2018-07-16 Thread Andrija Panic
HttpS links were not supported (at least up to 4.8 release - I have to always use plain HTTP). Cheers On Mon, Jul 16, 2018, 12:43 Paul Angus wrote: > Hi Adam, > Have you tried this with 4.11.1? > > > Kind regards, > > Paul Angus > > paul.an...@shapeblue.com > www.shapeblue.com > 53 Chandos Plac

Re: Unable to upload volumes 4.11.0

2018-07-13 Thread Andrija Panic
Hi Adam, can you try volume name without underscores ? Andrija On Fri, 13 Jul 2018 at 10:21, Adam Witwicki wrote: > Hello > > I cant seem to upload (add) a qcow2 volume via a URL, any ideas or other > methods? we really need to import other systems disks. > > I get this in the logs > > 2018-07

Re: Adding secondary IP to VM

2018-07-11 Thread Andrija Panic
ACS doesn't handle this in any way (except that it might reserve the IP, so it's not possible to add same IP to another VM/nic in same network). You need to manually configure secondary IP on the VM - this is at least in 4.8 release, and per my experience so far. Cheers. On Wed, 11 Jul 2018 at 1

Re: Is there a way to get back destroyed Virtual Router?

2018-07-11 Thread Andrija Panic
If this is advanced networking (VPC), then just restart VPC and it should bring up a new router. For me (4.8), restarting network actually never did anything (for whatever reason...). Cheers On Wed, Jul 11, 2018, 09:28 Boris Stoyanov wrote: > If you restart your network cloudstack will create a

Re: Importing Hyper-V to Cloudstack 4.11.0 UEFI and GPT

2018-07-10 Thread Andrija Panic
tion, we have lots of hyper-v GEN2 boxes we > need to import. > > I have found one bootloader on a CD that will boot the windows OS, but am > having a nightmare getting this installed on the first HDD > https://sourceforge.net/projects/cloverefiboot/ > > Thanks > > Ad

Re: ACS for Reseller

2018-07-10 Thread Andrija Panic
Just FYI, we are managing this via custom user Portal (portal does initial user provisioning as well as i.e. demo VPC etc, lots of possibilities from Portal side...) and it has account mapping from itself to ACS users, etc - this all done because we are public IaaS provided, so for billing/usage ne

Re: Cloudstack Collab Canada anyone?

2018-07-10 Thread Andrija Panic
looking forward! > > Boris Stoyanov > > > boris.stoya...@shapeblue.com > www.shapeblue.com > 53 Chandos Place, Covent Garden, London WC2N 4HSUK > @shapeblue > > > > > On 10 Jul 2018, at 10:29, Andrija Panic wrote: > > > > Hi all, > > > >

Cloudstack Collab Canada anyone?

2018-07-10 Thread Andrija Panic
Hi all, I was wondering who would be going to Apache CloudStack Collab conference of 2018 on September 24-26th, Montreal, Canada? I know it's still early, but if you know, we could (a bit later i.e. beginning of September) organise some beer sessions or so, after the official presentation hours a

Re: Broken guest vm consoles after upgrading to 4.11.1.0

2018-07-09 Thread Andrija Panic
strange... On Mon, 9 Jul 2018 at 23:35, Andrija Panic wrote: > HI Andrei, > > I will share my setup, ACS 4.8 though - we also had "similar" issue from > 4.5 going forward to 4.8 - there was some settings that needed to be on > (for whatever reason), hope th

Re: Broken guest vm consoles after upgrading to 4.11.1.0

2018-07-09 Thread Andrija Panic
HI Andrei, I will share my setup, ACS 4.8 though - we also had "similar" issue from 4.5 going forward to 4.8 - there was some settings that needed to be on (for whatever reason), hope this will help consoleproxy.url.domain *.consoleproxy.net (yes we did buy that one :D ) secstorage.ssl.cert.d

Re: Next CloudStack EU user group date

2018-07-09 Thread Andrija Panic
ANd Open Source Summit Europe in October 22-24th... On Mon, 9 Jul 2018 at 15:04, Rafael Weingärtner wrote: > Do not forget that we have CCC/ApacheCon in September 22-28. > > On Mon, Jul 9, 2018 at 10:01 AM, Sven Vogel wrote: > > > Hi Ivan, > > > > > > > > Early September or October? What do yo

Re: Importing Hyper-V to Cloudstack 4.11.0

2018-07-09 Thread Andrija Panic
wrote: > Andrija > > It looks like we cannot boot a GPT disk, this will be a huge pain, as most > of the systems we want to migrate are GPT > > Thanks > > Aadm > > -Original Message- > From: Andrija Panic > Sent: 06 July 2018 14:27 > To: users > Subj

Re: Importing Hyper-V to Cloudstack 4.11.0

2018-07-06 Thread Andrija Panic
O drivers. > I have also tried with NFS storage and get the same boot error. > > This process worked on 4.9, I notice there are more template options on > 4.11.0 do I need to do any thing different? > > Thanks > > Adam > > -Original Message- > From: Andrija Pan

Re: Importing Hyper-V to Cloudstack 4.11.0

2018-07-06 Thread Andrija Panic
Hi Adam, havent done that myslef (but helped some customers) - if you are running OS TYpe :"Windows XXX" - anything concrete version - this means no VirtIO drives are needed, since all IDE, so no drivers needed) If using "Windows PV" this means you need to have installed VirtIO drivers inside the

Re: Properly remove VMs in unconsistent states

2018-07-05 Thread Andrija Panic
Hi Natalia, perhaps not much of a help - but I usually try to reproduce "good" records - in your case by deploying a VM, then destroy it, wait for some time (expunge, cleanup, etc...i.e. wait 24h) and then get these "good" records and compare against other records that you want to change. This is

Re: Amount of virtual machines per host

2018-07-05 Thread Andrija Panic
Hi Dmitry, did you roll all 450 VMs from the same template (450 VMs, on single host ???) With KVM on local/shared storage, it works by initially moving/copying a template qcow2 image from Secondary Storage NFS, to Primary Storage (local or shared NFS...) and then protecting this image and making

Re: Cloud0 interface disappeared after reboot

2018-07-04 Thread Andrija Panic
oes anyone know what > process > >creates the cloud0 interface? This is really frustrating since > it's now > >happening on 2 hosts that I am running and I don't really know > where to > >look. > > > >On Tue, Ju

Re: Migrating workloads into CloudStack

2018-07-04 Thread Andrija Panic
We do it this way (as Dag mentioned) - but in general I would not advise DB hacks unless tested 100+ times - on next upgrade you might face issues while updating DB schema etc, though I do have a lot of experience with DB manipulation, (un)fortunately :) On Wed, 4 Jul 2018 at 11:29, Dag Sonstebo

Re: Cloud0 interface disappeared after reboot

2018-07-03 Thread Andrija Panic
I vaguely remember that cloud0 were lazy provisioned/started... did you start VR on that host, does it trigger cloud0 creation ? Cheers On Tue, 3 Jul 2018 at 16:34, Christoffer Pedersen wrote: > Hi all, > > Currently doing some POC'ing in a nested environment. Running the latest > 4.11.1 with U

Re: Open Summit CFP anyone ?

2018-06-29 Thread Andrija Panic
have submitted a proposal, perhaps someone else also from the community... Would be a good excuse to have a beer :) Cheers Andrija On Wed, 27 Jun 2018 at 16:43, Andrija Panic wrote: > Thx Giles, that's great. > > On Wed, Jun 27, 2018, 16:11 Giles Sirett > wrote: > >>

Re: CloudStack - KVM / Ceph Performance

2018-06-26 Thread Andrija Panic
dam > > -Original Message- > From: Andrija Panic > Sent: 26 June 2018 15:00 > To: users > Subject: Re: CloudStack - KVM / Ceph Performance > > ** This mail originated from OUTSIDE the Oakford corporate network. Treat > hyperlinks and attachments in this email wit

Re: CloudStack - KVM / Ceph Performance

2018-06-26 Thread Andrija Panic
You are obviously hitting some issues on Centos vs Ubuntu as KVM host, and can be due to difference in kernel, ceph (librbd), libvirt/qemu... But we have been using ceph (older, hammer release) with Ubuntu 14.04 and dont expect any miracle on single volume. BUT if you i.e. start Bitlocker drive en

Re: CloudStack - KVM / Ceph Performance

2018-06-26 Thread Andrija Panic
Rbd cache configured and active on KVM side ? What guest OS you test within - you get these last results from inside VM as I understand? Do you have ceph (client side on kVM hosts) version difference between centos and ubuntu host? Kernel upgrade on centos (to 4.x) makes any difference ? (Very eas

Re: Current cloudstack prebuilt images wrong VR address

2018-06-25 Thread Andrija Panic
Well, thank you Daan for these great credits, but it's actually Nux who owns this templates afaik. :) Cheers, Andrija On Mon, Jun 25, 2018, 15:34 Ivan Kudryavtsev wrote: > Yes, Daan. > > The problem is with template, not with ACS. My English is so-so, but I > meant that) > > And I use a Basic z

Re: advanced networking with public IPs direct to VMs

2018-06-05 Thread Andrija Panic
Zone-wide NFS storage ? in this case the SQL returns no results (cluster_id field in table is NULL) On 5 June 2018 at 17:16, Jon Marshall wrote: > No problem. > > > I am leaving work now but will test first thing tomorrow and get back to > you. > > > I definitely have NFS storage as far as I can

Re: FW: [poll] cloudstack exam

2018-06-05 Thread Andrija Panic
pan and they tell me that > nobodys > > used it ! > > > > > > > > Kind regards > > Giles > > > > giles.sir...@shapeblue.com > > www.shapeblue.com > > 53 Chandos Place, Covent Garden, London WC2N 4HSUK > > @shapeblue > > >

Re: 答复: How to run Oracle 11g RAC on an instance of CloudStack

2018-05-28 Thread Andrija Panic
Yes, as we already mentioned - you can do KVM with shared disks - but not via CloudStack, simply CloudStack doesn't provide a way to configure shared disks between VMs... Best On 28 May 2018 at 15:40, li li wrote: > @Andrija Panic<mailto:andrija.pa...@gmail.com> > > > &g

Re: How to run Oracle 11g RAC on an instance of CloudStack

2018-05-28 Thread Andrija Panic
> on shared storage to several instances. Ideally, two iscsi instances backed > with drbd volumes and iscsi multipath. > > пн, 28 мая 2018 г., 19:30 Rafael Weingärtner >: > > > What do you mean by shared disks? Multiple VMs accessing the same data > > disk? > > >

Re: How to run Oracle 11g RAC on an instance of CloudStack

2018-05-28 Thread Andrija Panic
Hi there, not sure if shared disks are supported in CloudStack. At least for KVM, I'm pretty sure this is not possible, not sure about Xen/Vmware. Andrija On 28 May 2018 at 11:41, li li wrote: > Hi All >I need to run Oracle 11g RAC on a VM (shared disk required); does > anyone know how

Re: KVM Problem by deploying VPC

2018-05-25 Thread Andrija Panic
udbr0 > iface cloudbr0 inet static > address 10.253.250.230 > gateway 10.253.250.1 > netmask 255.255.255.0 > dns-nameservers 8.8.8.8 8.8.4.4 > bridge_ports bond0 > bridge_fd 5 > bridge_stp off > bridge_maxwait 1 > > Now i moved back to centos7 and have another probl

Re: SOLVED: KVM Problem by deploying VPC

2018-05-25 Thread Andrija Panic
> > bond-mode active-backup > > bond-miimon 100 > > bond-slaves none > > > > auto cloudbr0 > > iface cloudbr0 inet static > > address 10.253.250.230 > > gateway 10.253.250.1 > > netmask 255.255.255.0 > > dns-

Re: KVM Problem by deploying VPC

2018-05-23 Thread Andrija Panic
ion found. Opening a new one > 2018-05-23 12:59:54,856 DEBUG [kvm.resource.LibvirtConnection] > (agentRequest-Handler-4:null) (logid:ef8b353e) Successfully connected to > libvirt at: lxc:/// > 2018-05-23 12:59:54,857 DEBUG [kvm.resource.LibvirtConnection] > (agent

Re: KVM Problem by deploying VPC

2018-05-21 Thread Andrija Panic
NetworkManager ? I though it was advised to not run it... On 18 May 2018 at 16:11, Simon Weller wrote: > Ben, > > > Can you put the KVM agent in debug mode and post the logs? > > > sed -i 's/INFO/DEBUG/g' /etc/cloudstack/agent/log4j-cloud.xml > > > Then restart the agent. > > > - Si > > > __

Re: FW: [poll] cloudstack exam

2018-05-16 Thread Andrija Panic
> www.shapeblue.com > 53 Chandos Place, Covent Garden, London WC2N 4HSUK > @shapeblue > > > > > -Original Message- > From: Andrija Panic > Sent: 01 May 2018 10:04 > To: users > Cc: dev > Subject: Re: [poll] cloudstack exam > > Hi Giles

Re: related to CLOUDSTACK-10310 Fix KVM reboot on storage issue need workaround

2018-05-15 Thread Andrija Panic
Hi, we are on 4.8 version, but make sure to just comment one line in the script on the AGENTs. /usr/share/cloudstack-common/scripts/vm/hypervisor/kvm/kvmheartbeat.sh #echo b > /proc/sysrq-trigger and optionally restart agents (should NOT be needed, but doesn't hurt anyway). This works for us.

Re: Cloudstack compatiblity Windows 2016 Server

2018-05-14 Thread Andrija Panic
+1 for KVM - just make sure to have vmware tools / drivers installed properly (virtio for KVM) On 14 May 2018 at 19:19, Simon Weller wrote: > On KVM, selecting the "Windows PV" OS type will work fine with Windows > Server 2016. Might be worth trying on vmware. > > > _

Re: Anyone using LB to solve Console Proxy DNS..

2018-05-11 Thread Andrija Panic
obviously other options out there as well – pfSense springs to > mind: https://www.howtoforge.com/how-to-use-pfsense-to-load- > balance-your-web-servers > > > Regards, > Dag Sonstebo > Cloud Architect > ShapeBlue > > On 10/05/2018, 23:21, "Andrija Panic"

Re: Anyone using LB to solve Console Proxy DNS..

2018-05-10 Thread Andrija Panic
ses actually host a CPVM. > > Regards, > Dag Sonstebo > Cloud Architect > ShapeBlue > > On 10/05/2018, 22:48, "Andrija Panic" wrote: > > Hi Rohit, > > thx a lot for sharing that - here, if I understand correctly, you > relly on > the static IP (r

Re: Anyone using LB to solve Console Proxy DNS..

2018-05-10 Thread Andrija Panic
proxies to the CPVM IP. In 4.11 there is also a new > option to dedicate a public IP (range) to systemvms in a way could be > useful to fix public IP - dns mapping. > > > For this to work, on 4.11 I made this change: > > https://github.com/apache/cloudstack/commit/392f62dae0f

Anyone using LB to solve Console Proxy DNS..

2018-05-05 Thread Andrija Panic
Hi, instead of using DNS A records in form x-y-w-z.domain.com --> x.y.w.zz, there is another way as stated in CWIKI to fix an IP/A record in DNS that will point to single public IP of the LB, and this LB should do loadbalancing across all public IPs that could be potentially assigned to CPVM... or

Re: [poll] cloudstack exam

2018-05-01 Thread Andrija Panic
Hi Giles, FYI, discount code is no more valid: Discount validation failed. Exam: ACCEL-100, May 8 at 11:30 AM - This discount cannot be used with appointments scheduled after 31 Oct 2016. Cheers, Andrija On Mon, Nov 30, 2015, 19:44 Stephan Seitz < s.se...@secretresearchfacility.com> wro

Re: Question about instance volumes

2018-04-23 Thread Andrija Panic
> > Also why would the golden image be deleted by the Cloudstack scavenger? I > have an Instance failing to boot because it's backing file was deleted by > the scavenger. > > Thanks, > > On Mon, Apr 23, 2018 at 4:43 AM, Andrija Panic > wrote: > > > As Ivan

Re: Question about instance volumes

2018-04-23 Thread Andrija Panic
As Ivan explained, when there is brand new template used, ACS will copy it from Secondary Storage to Primary Storage, this image will become "parent" / backing / gold image, and is locked as Read Only. Any new VM will have it's volume "linked" as child image to this parent image. This is done to 1

Re: KVM HostHA

2018-03-14 Thread Andrija Panic
nd Fences the faulty one. > > Hope that explains your case. > > Boris. > > > boris.stoya...@shapeblue.com > www.shapeblue.com > 53 Chandos Place, Covent Garden, London WC2N 4HSUK > @shapeblue > > > > > On 14 Mar 2018, at 13:53, Andrija Panic wrote

Re: KVM HostHA

2018-03-14 Thread Andrija Panic
Hi Paul, sorry to bump in the middle of the thread, but just curious about the idea behing host-HA and why it behaves the way you exlained above: Would it be more sense (or not?), that when MGMT detects agents is unreachable or host unreachable (or after unsuccessful i.e. agent restart, etc...,t

Re: Migrate system VMs volumes to new storage

2018-03-13 Thread Andrija Panic
dures and confirm that it works fine! >> Now I have to dismiss the storage server and I'm wondering if you just >> put it in maintenance mode forever or if there's another way to delete it. >> >> Thanks >> >> Il 15/02/2018 18:03, Andrija Panic ha

Re: Storage Migration VPC ACS 4.5.2

2018-03-09 Thread Andrija Panic
retor de Negócios e Inovação > >> Cloud Architect > >> +55(45) 9911.60094 +55(45) 3326-4568 > >> fel...@brascloud.com.br www.brascloud.com.br > >> <https://www.facebook.com/felipesecure> <https://www.instagram.com/ > >> felipesecure/> <h

Re: Cannot change service offering

2018-03-08 Thread Andrija Panic
Hi Natalia, what is the current setup of your Compute Offerings - can you post some details. Do you have same type of storage (shared vs local) and tags defined for current and any new offering (to which you want to change) ? Cheers On 8 March 2018 at 15:55, Natalia Costas Lago wrote: > > Hi,

Re: Storage Migration VPC ACS 4.5.2

2018-03-08 Thread Andrija Panic
Hi Felipe, I did not understand the question - what are you trying to achieve exactly ? Cheers On 8 March 2018 at 16:21, Felipe Rossi wrote: > Hello Guys, > > I need Verify what process for storage migration of VPC on ACS 4.5.2 > > I try migrate VR but not work. > > > > Att / Regards > > > > F

Re: KVM HostHA

2018-03-07 Thread Andrija Panic
Hi Victor, zero experience here with 4.11 in general, but what are you expecting to happen ? you powered off a host, so nothing for IPMI driver to do - host is down already, no host HA actions are expected afaik. I guess you might have have wanted to i.e. unplug NIC (cause network issues on MGMT

Re: Change VPC CIDR - and some Mailing List issues

2018-03-07 Thread Andrija Panic
root@r-5015-VM:~# grep -ir "10.128.0.0/18" /etc/ ### this is VPC CIDR /etc/iptables/router_rules.v4:-A INPUT -s 10.128.64.0/18 -d 10.128.0.0/18 -j MARK --set-xmark 0x524/0x /etc/iptables/router_rules.v4:-A FORWARD -s 10.128.64.0/18 -d 10.128.0.0/18 -j MARK --set-xmark 0x524/0x /etc

Re: Cloud (Infrastructure reselling) = VPC ?

2018-03-05 Thread Andrija Panic
Doman architecture setup: Domain: /PARTNER1/client1/ Domain: /PARTNER1/client2/... Domain: /PARTNER2/client1/ Domain: /PARTNER2/client2/ ... partner=reseler, while you keep to be provider of IaaS for your reselers... This all above is if you leave the "selling" to you "partners" In each PART

Re: VPC DNS server DHCP options settings

2018-03-05 Thread Andrija Panic
Hi Eric, not sure this is possible actually, except that you can override DNS settings (windows at least I know for sure) in the TCP/IP dialog properties. Cheers On 3 March 2018 at 14:56, Eric Neumann wrote: > Hi All, > > How can a CloudStack tenant set their preferred DNS servers in the VPC’s

Re: Question: Domain filed on the SSL upload form

2018-03-01 Thread Andrija Panic
the > global parameter you are good to go. > > On Thu, Mar 1, 2018 at 10:49 AM, Andrija Panic > wrote: > > > anyone ? > > > > On 27 February 2018 at 14:32, Andrija Panic > > wrote: > > > > > Hi all, > > > > > > I got confused

Re: Question: Domain filed on the SSL upload form

2018-03-01 Thread Andrija Panic
anyone ? On 27 February 2018 at 14:32, Andrija Panic wrote: > Hi all, > > I got confused about the domain fields/API parameter that is used when > uploading new SSL, to be used on CPVM and SSVM copy process (this is > domain_suffix in cloud.keystore table) > > Due to so

Question: Domain filed on the SSL upload form

2018-02-27 Thread Andrija Panic
Hi all, I got confused about the domain fields/API parameter that is used when uploading new SSL, to be used on CPVM and SSVM copy process (this is domain_suffix in cloud.keystore table) Due to some automation, I came across the following scenarios, which WORKS FINE, but I'm confused as how and w

Re: change primary storage scope

2018-02-22 Thread Andrija Panic
Hi Piotr, as far as I know, it's not possible to change in in the normal/official way, but you can actually change it via DB (test on DEV first and makes sure to run some tests, deploy VMs, do some live migrations etc...) UPDATE cloud.storage_pool SET pod_id=1, cluster_id=1, scope='CLUSTER' WHERE

Re: VR routing issues in Advanced Mode

2018-02-21 Thread Andrija Panic
Hi Andrei, you dont have typo in your input, right ? if I read this correctly, the case that don't work for you is as following: VR1 ( XXX.XXX.XXX.10/26) --> Guest1 Network / VM 10.1.1.100/24 VR2 ( XXX.XXX.XXX.20/26)-- Guest1 Network / VM 10.1.1.200/24 Is this correct ? If so, it's normal t

Re: AW: KVM with shared storage

2018-02-20 Thread Andrija Panic
ivers. Do you know any other customers/users of CS who are looking for > it > > too? > > > > Mit freundlichen Grüßen / With kind regards, > > > > Swen > > > > -Ursprüngliche Nachricht- > > Von: Andrija Panic [mailto:andrija.pa...@gmail.com] &g

Re: downloading iso to secondary storage

2018-02-20 Thread Andrija Panic
Hi Swastik, last issue (enter = reboot) = you are using Firefox ? there is some combo cobination, where you will very easily restart VR (into unusable state), so don't use firefox (or make sure to understand what happens, but effectively something will put focus on the ctrl + alt +del BUTTON and o

Re: KVM with shared storage

2018-02-19 Thread Andrija Panic
>From my (production) experience from few years ago, even GFS2 as a clustered file system was S unstable, and lead to locks, causing the share to become unresponsive 100%, and then you go and fix the things any way you can (and this was with only 3 nodes !!! accessing the share with LIGHT

Re: Migrate system VMs volumes to new storage

2018-02-15 Thread Andrija Panic
recreating the VM in the old storage. I also tried to > change the order of appearance of the system offerings list but the result > does not change. > > I thought about intervening in the database but I do not like it as a > solution. > > Any idea? > > > > > Il

Re: VPC ACLs and Loadbalancer

2018-02-15 Thread Andrija Panic
Well :) that is a good question - desired by who :) ACLs are applied on routined traffic (i.e. traffic between networks), so here its simply not aplicable - you connect to LOCAL port/service on VR (imagine port 22 as in mine example, but otherwise default rules are all DENY, so you can't access ha

Re: VPC ACLs and Loadbalancer

2018-02-13 Thread Andrija Panic
Hi S, so I have reproduced same behavior on ACS 4.8.x and from what I can see this is EXPECTED for following reason: root@r-4997-VM:~# iptables-save | grep "\-j ACL" -A PREROUTING -s 10.10.10.0/24 ! -d 10.10.10.1/32 -i eth2 -m state --state NEW -j ACL_OUTBOUND_eth2 -A FORWARD -d 10.10.

Re: SystemVM not starting after updating console SSL cert

2018-02-07 Thread Andrija Panic
Hi Amit, you should be able to login to host and check logs as Dan said. On the other hand, I see there is arround 30sec before agent is connected and the time it receives the kill command - so this should be enough for you to do one line ssh/scp command that will rsync/scp/copy logs from inside

Re: Migrate system VMs volumes to new storage

2018-02-07 Thread Andrija Panic
ally (my experience). Not sure if this helps. On 6 February 2018 at 16:26, Ugo Vasi wrote: > Hi Andrija, > do I have to eliminate other system offers that do not have storage tag > before destroy the SVM? > > > Il 02/02/2018 17:32, Andrija Panic ha scritto: > >> I

Re: host KVM unable to find cloudbr0

2018-02-05 Thread Andrija Panic
Hi Nicolas, what does your zone networking look like ? For every network you setup in the Zone (are you using advanced zones, vlan isolation method ???) you need to specify "KVM traffic label" - this actually tells ACS what parent interface to look for... Cheers On 5 February 2018 at 18:12, Nico

Re: Migrate system VMs volumes to new storage

2018-02-02 Thread Andrija Panic
If you can afford using (Storage) Tags, then you can do it that way also. we have 3 different storages (had) and all 3 were having at some time different TAGs - you edit existing System Offering for the CPVM, SSVM, VR (and/or Compute and Data disk offerings) i.e. //Service Offerings -> System Of

Re: AW: AW: AW: KVM storage cluster

2018-02-02 Thread Andrija Panic
max, so > > ScaleIO can do 210.000 IOPS (read) at its best. fio shows around 140.000 > > IOPS (read) max. ScaleIO GUI shows me around 45.000 IOPS (read/write > > combined) per SSD. > > > > Do you have a different fio command I can run? > > > > Mit freundlichen Gr

Re: Failing to enable SSL/HTTPS on console proxy vm

2018-02-02 Thread Andrija Panic
You need to put all certificates in the chain in the GUI dialog, in 4.8 this is supported in GUI, made easy (god forgive doing the same work in 4.5 :) I don't remember ATM, but I believe also restarting MGMT was required or advises, since it build up the ssl/trust chan (of whaever...) so make sure

Re: Time-out when creating a template from a snapshot

2018-02-02 Thread Andrija Panic
are no messages about the database in the log-file and ACS thinks > that the operation has been finished successfully. > > I'm pretty sure that haproxy was a half of a problem, but the second half > is somewhere inside of the SSVM. > > On Thu, Feb 01, 2018 at 09:17:51PM +

Re: AW: AW: KVM storage cluster

2018-02-02 Thread Andrija Panic
Brüseke - proIO GmbH" < > > s.brues...@proio.com> написал: > > > > I am also testing with ScaleIO on CentOS7 with KVM. With a 3 node cluster > > with each node has 2x 2TB SSD (Samsung PM1663a) I get 250.000 IOPS when > > doing a fio test (random 4k). &g

Re: kvm live volume migration

2018-02-02 Thread Andrija Panic
he virsh migrate command if need be. > = = = > > In the simplest tests this works – destination VM remains online and has > storage in new location – but it’s not persistent – sometimes the > destination VM ends up in a paused state, and I’m working on how to get > around this. I als

Re: KVM storage cluster

2018-02-01 Thread Andrija Panic
a bit late, but: - for any IO heavy (medium even...) workload, try to avoid CEPH, no offence, simply it takes lot of $$$ to make CEPH perform in random IO worlds (imagine RHEL and vendors provide only refernce architecutre with SEQUNATIAL benchmark workload, not random) - not to mention a huge lis

Re: Intel meltdown/spectre kvm upgrade results

2018-02-01 Thread Andrija Panic
Thx Ivan for sharing, no reboot issues because of problematic Intel microcode ? This is just Meltdown fix for now, and btw congrats on courage to do so this early (since no final solution yet). FYI, CentOS/RHEL has already patched everyhing (kernel and qemu/libvirt) but we are also on Ubuntu..

Re: External DNS

2018-02-01 Thread Andrija Panic
in our VMs in reslolv.conf we have internal IP address of VR as first nameserver, then the public ones... ( use.external.dns set to false on Zone level - zone level settings) On 1 February 2018 at 21:16, wrote: > Hello, > > we are using advanced networking > > > > Andrij

Re: kvm live volume migration

2018-02-01 Thread Andrija Panic
Actually, we have this feature (we call this internally online-storage-migration) to migrate volume from CEPH/NFS to SolidFire (thanks to Mike Tutkowski) There is libvirt mechanism, where basically you start another PAUSED VM on another host (same name and same XML file, except the storage volume

Re: External DNS

2018-02-01 Thread Andrija Panic
Hi, you didn't write what kind of networking you have, are VMs supposed to use VR (advanced networking) for DNS (as deafult) or not. In zone settings, we have set public DNS to google's also, and some internal ones. SSVM and CPVM are assinged both 2 internal, and then 2 external servers (in that

Re: Time-out when creating a template from a snapshot

2018-02-01 Thread Andrija Panic
Vladimir, the original error seems as MySQL timeout for sure (I assume because of HAPROXY in the middle), and we also had this setup originally (MGMT server using HAPROXY on top of galera nodes...) but this has confirmed to be issue, no matter what we changed on HAproxy or Mysql, and at that time

Re: Circumventing VXLAN MTU issues

2017-12-21 Thread Andrija Panic
@devs any plan to implement VXLAN as isolation for also Private Gateway functionality ? On 21 December 2017 at 15:28, Andrija Panic wrote: > while there, here is another one (just below that one) :) which I learned > the very hard way, after 2 years in production (when clients s

Re: Circumventing VXLAN MTU issues

2017-12-21 Thread Andrija Panic
! wrote: > Thanks Andrija, well done, I have indeed read your document. > Using MTU 9000 solved my problem. :) > > Lucian > > -- > Sent from the Delta quadrant using Borg technology! > > Nux! > www.nux.ro > > - Original Message - > > From: &quo

Re: Circumventing VXLAN MTU issues

2017-12-21 Thread Andrija Panic
Hi Nux, there is one rare contributions from my side :D to the ACS (documentation, 2.5 years ago) - check it here: http://docs.cloudstack.apache.org/en/latest/networking/vxlan.html#important-note-on-mtu-size We are using it extensively, feel free to ask anything if needed. Cheers On 20 November

Re: HTTPS LB and x-forwarded-for

2017-11-09 Thread Andrija Panic
t; On Mon, Nov 6, 2017 at 7:10 AM, Nux! wrote: > > > > > Thanks Andrija, > > > > > > LB outside of the VR sounds like a good idea. An appliance based on, > say > > > cloud-init + ansible and so on could do the trick; alas it'd need to be > > > outsi

Re: Bandwith limit on guests

2017-11-02 Thread Andrija Panic
During your experiment, you can always confirm what speeds are set on each VNET/NIC of the VM - this below, is 1Gbps limit (multiple 131072 by 8KB = 1Gbps) root@X:~# virsh domiflist i-2-5-VM Interface Type Source Model MAC -

Re: HTTPS LB and x-forwarded-for

2017-11-02 Thread Andrija Panic
We used to make some special stuff for one of the clients, where all LB configuration work is done from outside of the ACS, i.e. python script to feed/configure VR - install latest haproxy 1.5.x for transparent proxy, since client insisted on SSL termination done on backend web SSL servers Not

RE: Help/Advice needed - some traffic don't reach VNET / VM

2017-10-09 Thread Andrija Panic
re. Please see if the public IP pool assigned to guest VMs > by CS is somehow overlapping with any IPs which are assigned to physical > /virtual machines somewhere. > > Kind regards, > > Imran > > -----Original Message- > From: Andrija Panic [mailto:andrija.pa...@gma

Re: Help/Advice needed - some traffic don't reach VNET / VM

2017-10-09 Thread Andrija Panic
t; Dag Sonstebo > Cloud Architect > ShapeBlue > S: +44 20 3603 0540 | dag.sonst...@shapeblue.com | > http://www.shapeblue.com <http://www.shapeblue.com/> | Twitter:@ShapeBlue > <https://twitter.com/#!/shapeblue> > > > On 09/10/2017, 21:52, "Andrija Panic&

Help/Advice needed - some traffic don't reach VNET / VM

2017-10-09 Thread Andrija Panic
Hi guys, we have occasional but serious problem, that starts happening as it seems randomly (i.e. NOT under high load) - not ACS related afaik, purely KVM, but feedback is really welcomed. - VM is reachable in general from everywhere, but not reachable from specific IP address ?! - VM is NOT und

Re: Advise on multiple PODs network design

2017-10-04 Thread Andrija Panic
Anyone? I know I'm trying to squeeze some free paid consulting here :), but trying to understand if PODs makes sense in this situation Thx On 2 October 2017 at 10:21, Andrija Panic wrote: > Hi guys, > > Sorry for long post below... > > I was wondering if someone could

Re: Multi secondary storage use in one cluster

2017-10-02 Thread Andrija Panic
just 2 months late... but please make sure to read the documentation - Any "public" stuff (public ISO, public template, etc) will go to BOTH SS storages... (if you upload if from URL - URL is used as the source to download template/iso to this one Secondary Storage) Private stuff (someone's priva

Re: KVM evaluation

2017-10-02 Thread Andrija Panic
Hi, we have Advanced zone, purely KVM, for last 3-5 years... no major KVM related problems really. - You preferably want qemu 2.5+/libvirt 1.3+ - i.e. Ubuntu 16.04 natively (ACS4.9+), or Ubuntu 14.04 with OpenStack repo that provides these binaries) - simply because of auto-convergence, otherwi

Re: one question network survey

2017-10-02 Thread Andrija Panic
Hi Daan, we have dedicated VLAN interface on all KVM hosts (bond0.XXX) which is used as VTEP for our VxLANs - we are ACS advanced networking, 4.8, were used also 4.5 previously). MLAG configured from NIC1/NIC2 (bond0) to 2xTOR switches... pure (no OVS) KVM/Ubuntu 14.04. On the host side, we had t

Re: A solution for snapshots stuck in Allocated/BackingUp states

2017-10-02 Thread Andrija Panic
May I suggest another permanent fix (sounds like a joke, but I'm actually serious) - move away from Primary Storage whose behavior is to copy snapshoted data to Secondary Storage - to the Primary Storage that doesn't copy content to Secondary Storage -i.e. SolidFire :) Imagine having 500GB disk cu

Re: Quick 1 Question Survey

2017-10-02 Thread Andrija Panic
Cloud1/2: Cloudstack Management = Ubuntu 14.04 (on top of Centos6 KVM :D ) KVM= Ubuntu 14.04 Best On 25 September 2017 at 13:52, Dag Sonstebo wrote: > CloudStack Management = ACS 4.9 on CentOS 7.3 > HV = VMware vSphere 6.5 > > Regards, > Dag Sonstebo > Cloud Architect > ShapeBlue > > On 25/09/

Re: [Site-to-Site IPSEC Slow]

2017-10-02 Thread Andrija Panic
Hi Gian, can you please try same test with iperf ? I would check remote side (Openswap Debian), since these are bad numbers, and we never hit similar issue with ACS 4.5 and ACS 4.8 (not yet using 4.9) FYI, between 2 VPC sites (S-2-S VPN), I was able to get 340 Mbps out of 1Gbps internet connecti

Re: Cluster anti-affinity

2017-10-02 Thread Andrija Panic
We are using "User-dispersing" deployment algorithm in Compute Offerings, which should place VM (but doesn't guaranties... = I guess same as with anti-afinity rules) on different hosts. Not sure if this takes cluster into consideration though., For cluster anti-afinity - for i.e. 10 VMs, that

Advise on multiple PODs network design

2017-10-02 Thread Andrija Panic
Hi guys, Sorry for long post below... I was wondering if someone could bring some light for me for multiple PODs networking design (L2 vs L3) - idea is to make smaller L2 broadcast domains (any other reason?) We might decide to transition from current single pod, single cluster (single zone) to

Re: Advice on converting zone-wide to cluster-wide storage

2017-10-02 Thread Andrija Panic
ool, enter the applicable value for pod_id (this > should be null when being used as zone-wide storage and an integer when > being used as cluster-scoped storage). >• In cloud.storage_pool, enter the applicable value for cluster_id > (this should be null when being used as zone-wide

<    5   6   7   8   9   10   11   12   13   14   >