Re: Upgrade to v3.6.0, "oc adm migrate storage" return many errors like: Forbidden: pod updates may not change fields other than `containers[*].image` or `spec.activeDeadlineSeconds`

2017-08-22 Thread Stéphane Klein
201.95:5000/openshift/ta-s2i-php-prod@sha256:f6da85d9b0aada51f45f776d8c04941f7ada1fe0219776b5eb0ccb1bab20a3e3 imagePullPolicy: Always name: app ... 2017-08-22 11:35 GMT+02:00 Michal Fojtik : > Can you please post the YAML representation of the > 'test-secret-6-qz4ar' pod?

Upgrade to v3.6.0, "oc adm migrate storage" return many errors like: Forbidden: pod updates may not change fields other than `containers[*].image` or `spec.activeDeadlineSeconds`

2017-08-21 Thread Stéphane Klein
like: error: pods/test-secret-6-qz4ar -n issue-29059: Pod \"test-secret-6-qz4ar\" is invalid: spec: Forbidden: pod updates may not change fields other than `containers[*].image` or `spec.activeDeadlineSeconds` What is it? How can I fix it? Best regards, Stéphane -- Stéphane Klein

How do you manage your git repository when you use public Ansible recipes like Ceph-Ansible or OpenShift-Ansible?

2017-08-01 Thread Stéphane Klein
Hi, this is a message that I posted on Ansible Google Groups: https://groups.google.com/forum/#!topic/ansible-project/wfm_vmywwTU I use Ceph-Ansible (https://github.com/ceph/ceph-ansible) and OpenShift-Ansible (https://github.com/openshift/openshift-ansible) to install this stuffs on our servers.

Re: timeout expired waiting for volumes to attach/mount for pod

2017-07-17 Thread Stéphane Klein
2017-07-17 17:20 GMT+02:00 Andrew Lau : > I see this too. It only started happening after mixing 1.5 and 1.4 nodes. > Ok, thanks, we have also master 1.5.1 and nodes in 1.4 :( ___ users mailing list users@lists.openshift.redhat.com http://lists.openshif

Re: timeout expired waiting for volumes to attach/mount for pod

2017-07-17 Thread Stéphane Klein
2017-07-17 17:03 GMT+02:00 Stéphane Klein : > > > 2017-07-17 17:01 GMT+02:00 Hemant Kumar : > >> Did you use openshift-ansible? >> >> > Yes > We use ovs-multitenant ___ users mailing list u

Re: timeout expired waiting for volumes to attach/mount for pod

2017-07-17 Thread Stéphane Klein
2017-07-17 17:01 GMT+02:00 Hemant Kumar : > Is there anything in apiserver/controller logs? > You mean "journalctl -u origin-node" on node ? ___ users mailing list users@lists.openshift.redhat.com http://lists.openshift.redhat.com/openshiftmm/listinfo/u

Re: timeout expired waiting for volumes to attach/mount for pod

2017-07-17 Thread Stéphane Klein
2017-07-17 17:01 GMT+02:00 Hemant Kumar : > Did you use openshift-ansible? > > Yes ___ users mailing list users@lists.openshift.redhat.com http://lists.openshift.redhat.com/openshiftmm/listinfo/users

Re: timeout expired waiting for volumes to attach/mount for pod

2017-07-17 Thread Stéphane Klein
2017-07-17 15:39 GMT+02:00 Hemant Kumar : > Phillippe - I have never seen a properly configured openshift server to > timeout while mounting secrets. > We have this messages in log (it is the same cluster that Philippe) : ul 17 10:34:15 prod-node-rbx-2.example.com origin-node[65154]: E0717 10:3

[Resolved] Re: oc rsh or oc get pod -w disconnection after few minutes

2017-07-17 Thread Stéphane Klein
2017-07-14 13:06 GMT+02:00 Aleksandar Lazic : > > > We have achieved a lot of tests, and the connection is dropped somewhere > in Openshift, not by the firewall. > > As we don't have any proxy, except haproxy. > > We've seen https://docs.openshift.com/container-platform/3.3/ > install_config/route

Re: [Logging] searchguard configuration issue? ["warning", "elasticsearch"], "pid":1, "message":"Unable to revive connection: https://logging-es:9200/"}

2017-07-12 Thread Stéphane Klein
2017-07-12 15:41 GMT+02:00 Peter Portante : > > > On Wed, Jul 12, 2017 at 9:28 AM, Stéphane Klein < > cont...@stephane-klein.info> wrote: > >> >> 2017-07-12 15:20 GMT+02:00 Peter Portante : >> >>> This looks a lot like this BZ: https://bugzilla.r

Re: [Logging] searchguard configuration issue? ["warning", "elasticsearch"], "pid":1, "message":"Unable to revive connection: https://logging-es:9200/"}

2017-07-12 Thread Stéphane Klein
2017-07-12 15:20 GMT+02:00 Peter Portante : > This looks a lot like this BZ: https://bugzilla.redhat. > com/show_bug.cgi?id=1449378, "Timeout after 30SECONDS while retrieving > configuration" > > What version of Origin are you using? > > Logging image : origin-logging-elasticsearch:v1.5.0 $ oc ve

[Logging] searchguard configuration issue? ["warning", "elasticsearch"], "pid":1, "message":"Unable to revive connection: https://logging-es:9200/"}

2017-07-12 Thread Stéphane Klein
asticsearch server: $ oc rsh -c kibana logging-kibana-1-jblhl bash $ curl https://logging-es:9200/ --cacert /etc/kibana/keys/ca --key /etc/kibana/keys/key --cert /etc/kibana/keys/cert { "name" : "Adri Nital", "cluster_name" : "logging-es", "cluste

Re: [Logging] What component forward log entries to fluentd input service?

2017-07-11 Thread Stéphane Klein
2017-07-11 15:00 GMT+02:00 Alex Wauck : > Last I checked (OpenShift Origin 1.2), fluentd was just slurping up the > log files produced by Docker. It can do that because the pods it runs in > have access to the host filesystem. > > On Tue, Jul 11, 2017 at 6:12 AM, Stéphane

[Logging] What component forward log entries to fluentd input service?

2017-07-11 Thread Stéphane Klein
-- Stéphane Klein blog: http://stephane-klein.info cv : http://cv.stephane-klein.info Twitter: http://twitter.com/klein_stephane ___ users mailing list users@lists.openshift.redhat.com http://lists.openshift.redhat.com/openshiftmm/listinfo/users

Re: Origin-Aggregated-Logging OPS generate 10Go ES data by day, 40000 hits by hours

2017-07-07 Thread Stéphane Klein
2017-07-07 15:51 GMT+02:00 Stéphane Klein : > 2017-07-07 14:26 GMT+02:00 Peter Portante : > >> > >> > 4 hits by hours! >> >> How are you determining 40,000 hits per hour? >> >> > I did a search

Re: Origin-Aggregated-Logging OPS generate 10Go ES data by day, 40000 hits by hours

2017-07-07 Thread Stéphane Klein
2017-07-07 14:26 GMT+02:00 Peter Portante : > > > > 4 hits by hours! > > How are you determining 40,000 hits per hour? > > I did a search in Kibana, last hour => 40,000 hits ___ users mailing list users@lists.openshift.redhat.com http://lists.openshi

Origin-Aggregated-Logging OPS generate 10Go ES data by day, 40000 hits by hours

2017-07-07 Thread Stéphane Klein
/sysconfig/docker:ro openshift/node:v1.4.1 ... 4 hits by hours! I don't understand why I have all this log record, it is usual? How can I fix it? Best regards, Stéphane -- Stéphane Klein blog: http://stephane-klein.info cv : http://cv.stephane-klein.info Twitter: http://twitter.com

Re: Error creating: pods "mysql-79-" is forbidden: failed quota: resource-quota: must specify limits.cpu, limits.memory, requests.cpu, requests.memory

2017-06-29 Thread Stéphane Klein
2017-06-29 16:33 GMT+02:00 Jessica Forrester : > It means the pod template in your DC doesn't set requests and limits for > the pods. If you are going to have a resourcequota restricting cpu and > memory then you either have to explicitly set requests/limits on all of > your pod templates OR > Y

Error creating: pods "mysql-79-" is forbidden: failed quota: resource-quota: must specify limits.cpu, limits.memory, requests.cpu, requests.memory

2017-06-29 Thread Stéphane Klein
uests.cpu,requests.memory » because I have specified this parameters. Where did I go wrong? Best regards, Stéphane -- Stéphane Klein blog: http://stephane-klein.info cv : http://cv.stephane-klein.info Twitter: http://twitter.com/klein_stephane ___

oc rsh or oc get pod -w disconnection after few minutes

2017-06-23 Thread Stéphane Klein
Hi, When I use: oc rsh mypod bash or oc get pod -w I lost connection after few minutes. It's not always the same duration. Why this disconnection? Where can I look to fix it? Best regards, Stéphane -- Stéphane Klein blog: http://stephane-klein.info cv : http://cv.stephane-klein

Can I configure a SCC to allow container to access to CephFS volume without SELinux attributes support?

2017-06-22 Thread Stéphane Klein
allowHostNetwork: true allowHostPID: true allowHostPorts: true allowPrivilegedContainer: true allowedCapabilities: null Best regards, Stéphane -- Stéphane Klein blog: http://stephane-klein.info cv : http://cv.stephane-klein.info Twitter: http://t

Re: CephFS => ls: cannot open directory /cephfs/: Permission denied

2017-06-22 Thread Stéphane Klein
CephFS appear to don't support SELinux labels ( http://tracker.ceph.com/issues/13231) then what can I do to allow container access to volume? 2017-06-21 17:52 GMT+02:00 Stéphane Klein : > > > 2017-06-21 16:25 GMT+02:00 Stéphane Klein : > >> I don't see where is my pe

Re: CephFS => ls: cannot open directory /cephfs/: Permission denied

2017-06-21 Thread Stéphane Klein
2017-06-21 16:25 GMT+02:00 Stéphane Klein : > I don't see where is my permission error. > Maybe it's this error: http://tracker.ceph.com/issues/13231 ? I have tried that: # setfattr -n security.selinux -v system_u:object_r:nfs_t:s0 /var/lib/origin/openshift.local.volumes/po

CephFS => ls: cannot open directory /cephfs/: Permission denied

2017-06-21 Thread Stéphane Klein
bd - secret allowHostDirVolumePlugin: false allowHostIPC: false allowHostNetwork: false allowHostPID: false allowHostPorts: false allowPrivilegedContainer: false allowedCapabilities: null I don't see where is my permission error. Best regards, Stéphane -- Stéphane Kl

Re: Is CephFS supported by OpenShift?

2017-06-16 Thread Stéphane Klein
2017-06-16 16:04 GMT+02:00 Clayton Coleman : > If you configure it yourself it's in the code > In the code ? OpenShift Go source code or Ansible role source code? ___ users mailing list users@lists.openshift.redhat.com http://lists.openshift.redhat.com/

Re: Is CephFS supported by OpenShift?

2017-06-16 Thread Stéphane Klein
2017-06-16 16:04 GMT+02:00 Rahul Agarwal : > Its in the list. > > https://docs.openshift.org/latest/install_config/ > persistent_storage/persistent_storage_ceph_rbd.html#install- > config-persistent-storage-persistent-storage-ceph-rbd > > I speak about CephFS not Ceph Block Storage (rbd).

Is CephFS supported by OpenShift?

2017-06-16 Thread Stéphane Klein
Hi, I see that Kubernetes support CephFS: https://kubernetes.io/docs/concepts/storage/volumes/#cephfs Is CephFS supported by OpenShift? I don't see it here https://docs.openshift.org/latest/install_config/persistent_storage/index.html Best regards, Stéphane -- Stéphane Klein blog:

Can I exclude one project or one container to Origin-Aggregated-Logging system?

2017-05-30 Thread Stéphane Klein
HI, I just read origin-aggregated-logging <https://github.com/openshift/origin-aggregated-logging> documentation and I don't found if I can exclude one project or one container to logging system. Is it possible with a container labels? or other system? Best regards, Stéphane -- Sté

Re: Pods has connectivity to other pod and service only when I run an additional pod

2017-05-23 Thread Stéphane Klein
2017-05-23 15:32 GMT+02:00 Andrew Lau : > Philippe, I'm curious if you are running containerized? > > yes, containerized. ___ users mailing list users@lists.openshift.redhat.com http://lists.openshift.redhat.com/openshiftmm/listinfo/users

Re: Pods has connectivity to other pod and service only when I run an additional pod

2017-05-17 Thread Stéphane Klein
2017-05-12 17:13 GMT+02:00 Gilbert Roulot : > > My issue is that I cant access elasticsearch:9200 from the injector pod. > Nor can I access the other pod directly. BUT if I start a new pod in the > project, communications are fixed with the pod and the service until I exit > it. > > Same issue here

In OpenShift Ansible, what is the differences between roles/openshift_hosted_metrics and roles/openshift_metrics ?

2017-04-28 Thread Stéphane Klein
regards, Stéphane -- Stéphane Klein blog: http://stephane-klein.info cv : http://cv.stephane-klein.info Twitter: http://twitter.com/klein_stephane ___ users mailing list users@lists.openshift.redhat.com http://lists.openshift.redhat.com/openshiftmm/listinfo

Re: Why I can use insecureEdgeTerminationPolicy: Redirect when I have termination: reencrypt

2017-04-01 Thread Stéphane Klein
> > What version of OpenShift are you running? $ oc version oc v1.4.1+3f9807a kubernetes v1.4.0+776c994 features: Basic-Auth Server https://console.atomic-test-master-1.priv.tech-angels.net:443 openshift v1.4.1+3f9807a kubernetes v1.4.0+776c994 I have this message: The Route "console" is inval

Why I can use insecureEdgeTerminationPolicy: Redirect when I have termination: reencrypt

2017-03-31 Thread Stéphane Klein
Hi, why I can't use: insecureEdgeTerminationPolicy: Redirect where I have : termination: reencrypt Best regards, Stéphane -- Stéphane Klein blog: http://stephane-klein.info cv : http://cv.stephane-klein.info Twitter: http://twitter.com/klein_ste

Is it possible to use Helm package system with OpenShift?

2017-03-23 Thread Stéphane Klein
Hi, is it possible to use Helm (https://github.com/kubernetes/helm) package system with OpenShift? Maybe not default Kubernetes Helm Charts but some OpenShift Charts? Best regards, Stéphane -- Stéphane Klein blog: http://stephane-klein.info cv : http://cv.stephane-klein.info Twitter: http

Re: Error: MountVolume.SetUp failed for volume ... Error: MountVolume.SetUp failed for volume ... with: rbd: map failed exit status 1 ... -1 did not load config file, using default settings

2017-03-15 Thread Stéphane Klein
2017-03-15 18:22 GMT+01:00 Huamin Chen : > Which ceph release you are using, "rbd -v" ? > docker exec -it origin-node bash [root@atomic-test-node-1 origin]# rbd -v ceph version 0.94.5 (9764da52395923e0b32908d83a9f7304401fee43) ___ users mailing list use

Re: Error: MountVolume.SetUp failed for volume ... Error: MountVolume.SetUp failed for volume ... with: rbd: map failed exit status 1 ... -1 did not load config file, using default settings

2017-03-15 Thread Stéphane Klein
2017-03-15 14:48 GMT+01:00 Huamin Chen : > One mistake I saw from elsewhere is that the secret is not base64 encoded, > we made it explicit here > https://github.com/kubernetes/kubernetes/tree/master/ > examples/volumes/rbd#use-ceph-authentication-secret > > Yes, thanks, it was a bad Ceph Key in s

Re: Error: MountVolume.SetUp failed for volume ... Error: MountVolume.SetUp failed for volume ... with: rbd: map failed exit status 1 ... -1 did not load config file, using default settings

2017-03-15 Thread Stéphane Klein
2017-03-13 18:07 GMT+01:00 Huamin Chen : > "rbd: sysfs write failed > rbd: map failed: (1) Operation not permitted" > > These messages indicate a permission issue. Do your ceph user and keyring > have permission to map the rbd image? > > I use OpenShift Containerized instance. In "origin-node" D

Re: Error: MountVolume.SetUp failed for volume ... Error: MountVolume.SetUp failed for volume ... with: rbd: map failed exit status 1 ... -1 did not load config file, using default settings

2017-03-13 Thread Stéphane Klein
Nobody have this error with OpenShift 1.4.1? 2017-02-27 21:21 GMT+01:00 Stéphane Klein : > Hi, > > after OpenShift upgrade from 1.3.3 to 1.4.1, I have this error message: > > Feb 27 21:01:39 atomic-test-node-2.priv.example.com origin-node[21301]: > E0227 21:01

Error: MountVolume.SetUp failed for volume ... Error: MountVolume.SetUp failed for volume ... with: rbd: map failed exit status 1 ... -1 did not load config file, using default settings

2017-02-27 Thread Stéphane Klein
Hi, after OpenShift upgrade from 1.3.3 to 1.4.1, I have this error message: Feb 27 21:01:39 atomic-test-node-2.priv.example.com origin-node[21301]: E0227 21:01:39.446984 21368 nestedpendingoperations.go:253] Operation for "\"kubernetes.io/rbd/6ef0738f-fd0d-11e6-818d-005056b17dcc-pv-ceph-image5\

Log message error on all nodes: encountered error refreshing thin pool watcher: error performing thin_ls on metadata device /dev/mapper/cah-docker--pool_tmeta: Error running command `thin_ls --no-head

2017-02-27 Thread Stéphane Klein
Hi, I have many many lines with this error message in nodes logs: Feb 27 17:51:13 atomic-test-node-1.priv.tech-angels.net origin-node[24165]: E0227 17:51:13.183150 24451 thin_pool_watcher.go:72] encountered error refreshing thin pool watcher: error performing thin_ls on metadata device /dev/map

Can I create a new scc with chroot capability?

2017-01-30 Thread Stéphane Klein
ies is dropped now? Can I create a new scc with chroot capability? Best regards, Stéphane -- Stéphane Klein blog: http://stephane-klein.info cv : http://cv.stephane-klein.info Twitter: http://twitter.com/klein_stephane ___ users mailing list users@lists.op

Re: How can I scale up the number of etcd host ?

2017-01-13 Thread Stéphane Klein
2017-01-10 20:17 GMT+01:00 Scott Dodson : > openshift-ansible doesn't currently provide this, there's an issue > requesting it https://github.com/openshift/openshift-ansible/issues/1772 > which links to a blog post describing how to do it, though I've not > validated that myself. The only hard par

One command to check if all etcd serverd are up and if all masters are connected to this etcd nodes?

2017-01-13 Thread Stéphane Klein
tcd-2.priv.example.com:2379 - https://etcd-3.priv.example.com:2379 ``` Check if this configuration is valid on all OpenShift masters. Something like `oc get nodes`. I try `oc status` but I haven't information about etcd configure. Best regards, Stéphane -- Stéphane Klein blog: http:

Re: How can I scale up the number of etcd host ?

2017-01-13 Thread Stéphane Klein
2017-01-12 17:12 GMT+01:00 Alex Wauck : > Are you using the built-in OpenShift etcd on that one node, or are you > using real etcd? > I use registry.access.redhat.com/rhel7/etc standard docker OpenShift image. Best regards, Stéphane ___ users mailing l

Re: How can I scale up the number of etcd host ?

2017-01-10 Thread Stéphane Klein
2017-01-10 20:17 GMT+01:00 Scott Dodson : > openshift-ansible doesn't currently provide this, there's an issue > requesting it https://github.com/openshift/openshift-ansible/issues/1772 > which links to a blog post describing how to do it, though I've not > validated that myself. Thanks. > I'm

How can I scale up the number of etcd host ?

2017-01-10 Thread Stéphane Klein
/openshift-ansible/blob/c65c07f4238b23ee0e4c72746927d587517518ce/playbooks/byo/openshift-node/scaleup.yml This is what I going to do: * add new etcd host in [etcd] section in my inventory file * launch this two scaleup playbooks This is the good method ? Best regards, Stéphane -- Stéphane Klein

Re: In Ansible, what oo_ meaning? for instance in oo_masters, is it meaning Openshift Origin?

2016-12-28 Thread Stéphane Klein
https://docs.ansible.com/ansible/dev_guide/developing_ > plugins.html#lookup-plugins > > On Mon, Dec 26, 2016 at 11:38 AM, Stéphane Klein > wrote: > > Hi, > > > > I have a simple question: what the oo_ is meaning example here > > https://github.com/openshift/opensh

Re: I'm connected on Atomic Registry web UI but I have this message: « Server has closed the connection »

2016-12-27 Thread Stéphane Klein
HTTP 301 response on https://registry-console-test.example.com/cockpit/socket and the target redirection is the same: " https://registry-console-test.example.com/cockpit/socket"; I don't understand why I have this redirection. Best regards, Stéphane 2016-12-27 21:14 GMT+01:00 St

I'm connected on Atomic Registry web UI but I have this message: « Server has closed the connection »

2016-12-27 Thread Stéphane Klein
min: timed out * I'm connected on Atomic Registry web UI but I have this message: « Server has closed the connection » Where can be my error? I don't found registry-console debug mode. Best regards, Stéphane -- Stéphane Klein blog: http://stephane-klein.info cv : http:

In Ansible, what oo_ meaning? for instance in oo_masters, is it meaning Openshift Origin?

2016-12-26 Thread Stéphane Klein
Hi, I have a simple question: what the oo_ is meaning example here https://github.com/openshift/openshift-ansible/blob/master/playbooks/common/openshift-cluster/evaluate_groups.yml#L44 ? Is it meaning Openshift Origin? Best regards, Stéphane -- Stéphane Klein blog: http://stephane-klein.info

Re: Error: error communicating with registry: Get https://registry.example.com/healthz: x509: certificate signed by unknown authority

2016-11-28 Thread Stéphane Klein
rts/AddTrustExternalCARoot.crt 2016-11-28 14:24 GMT+01:00 Skarbek, John : > > On November 28, 2016 at 08:19:21, Stéphane Klein ( > cont...@stephane-klein.info) wrote: > > Hi, > > I can execute with success this command on my desktop host: > > oc adm --token=`oc -n defa

Error: error communicating with registry: Get https://registry.example.com/healthz: x509: certificate signed by unknown authority

2016-11-28 Thread Stéphane Klein
the same error. Where is my mistake ? Best regards, Stéphane -- Stéphane Klein blog: http://stephane-klein.info cv : http://cv.stephane-klein.info Twitter: http://twitter.com/klein_stephane ___ users mailing list users@lists.openshift.redhat.com http

Re: I try to connect to my custom route to registry-console and I have this error « The request is missing a required parameter, includes an invalid parameter value, includes a parameter more than onc

2016-11-28 Thread Stéphane Klein
cal - https://registry-console.example.com secret: $ oc apply -f foobar.yaml Best regards, Stéphane 2016-11-28 9:15 GMT+01:00 Stéphane Klein : > $ oc get oauthclient > NAME SECRET > WWW-CHALLENGE REDIRECT URIS &g

Re: I try to connect to my custom route to registry-console and I have this error « The request is missing a required parameter, includes an invalid parameter value, includes a parameter more than onc

2016-11-28 Thread Stéphane Klein
> > Cheers, > > Luis > > On 11/25/2016 10:18 AM, Stéphane Klein wrote: > > Hi, > > In OpenShift 1.3.1, I have configured this route: > > * https://registry-console.example.com => registry-console > > When I try to connect to https://registry

I try to connect to my custom route to registry-console and I have this error « The request is missing a required parameter, includes an invalid parameter value, includes a parameter more than once, o

2016-11-25 Thread Stéphane Klein
ter.local / https://registry-console.example.com/ I have appended https://registry-console.example.com/ to corsAllowedOrigins field in /etc/origin/master/master-config.yaml config file. Where is my error? I have forgotten something? Best regards, Stéphane -- Stéphane Klein blog: http://stepha

Re: OpenShift use Github issue and Trello, why not use a service like https://waffle.io/ to avoid using two systems and create confusion ?

2016-11-17 Thread Stéphane Klein
2016-11-16 15:28 GMT+01:00 John Lamb : > What confusion? > Where are feature requests and bug reports? In hidden Trello or in Github issues? ___ users mailing list users@lists.openshift.redhat.com http://lists.openshift.redhat.com/openshiftmm/listinfo/u

Re: s2i build on OSX => fatal error: unexpected signal during runtime execution

2016-11-17 Thread Stéphane Klein
Done: https://github.com/openshift/source-to-image/issues/639 2016-11-17 15:23 GMT+01:00 Ben Parees : > please open an issue on github. > > On Thu, Nov 17, 2016 at 9:08 AM, Stéphane Klein < > cont...@stephane-klein.info> wrote: > >> I have this error: >> &

s2i build on OSX => fatal error: unexpected signal during runtime execution

2016-11-17 Thread Stéphane Klein
Descriptors: 16 Goroutines: 29 System Time: 2016-11-17T14:06:42.466914005Z EventsListeners: 1 No Proxy: *.local, 169.254/16 Registry: https://index.docker.io/v1/ WARNING: No kernel memory limit support Insecure Registries: 127.0.0.0/8 -- Stéphane Klein blog: http://stephane-klein.info cv : http

Re: Error from server: User "system:serviceaccount:default:pruner" cannot list all images in the cluster

2016-11-17 Thread Stéphane Klein
: dial tcp 172.30.154.75:5000: i/o timeout 2016-11-16 17:54 GMT+01:00 Jordan Liggitt : > When granting the cluster role, the username for the service account is > not "pruner", it is "system:serviceaccount:default:pruner" > > On Nov 16, 2016, at 11:29 AM, Stéphane Kle

Error from server: User "system:serviceaccount:default:pruner" cannot list all images in the cluster

2016-11-16 Thread Stéphane Klein
nt ? Best regards, Stéphane -- Stéphane Klein blog: http://stephane-klein.info cv : http://cv.stephane-klein.info Twitter: http://twitter.com/klein_stephane ___ users mailing list users@lists.openshift.redhat.com http://lists.openshift.redhat.com/o

Re: How can I put logstash config files in ConfigMap ?

2016-11-16 Thread Stéphane Klein
2016-10-27 15:08 GMT+02:00 Luke Meyer : > The underscores are the problem. Can you convert them to hyphens? > > Yes ! It's that, it works with OpenShift 1.3.1 and hyphens instead underscores. ___ users mailing list users@lists.openshift.redhat.com http:/

OpenShift use Github issue and Trello, why not use a service like https://waffle.io/ to avoid using two systems and create confusion ?

2016-11-16 Thread Stéphane Klein
Hi, I see that you use Github issue and Trello to manage OpenShift issue, example: https://github.com/openshift/origin/issues/7018 Why not use a service like https://waffle.io/ to avoid using two systems and create confusion ? Best regards, Stéphane -- Stéphane Klein blog: http://stephane

Re: Why Metrics and Logging use Deployer container?

2016-11-15 Thread Stéphane Klein
2016-11-15 16:00 GMT+01:00 Matt Wringe : > > Is there any features we are missing that you are needing to make changes > for? > > https://github.com/openshift/origin-metrics/issues/262 https://github.com/openshift/origin-metrics/issues/263 ___ users mail

Why Metrics and Logging use Deployer container?

2016-11-15 Thread Stéphane Klein
book * fix my errors and restart to step 2 Why this complexity? Best regards, Stéphane -- Stéphane Klein blog: http://stephane-klein.info cv : http://cv.stephane-klein.info Twitter: http://twitter.com/klein_stephane ___ users mailing

Re: Error: valueFrom fieldRef resource => ...env[5].valueFrom.fieldRef.fieldPath: Required value

2016-11-08 Thread Stéphane Klein
2016-11-08 16:43 GMT+01:00 Marko Lukša : > Your version of oc is too old. Your file works for me, when I use 1.3.0+, > but I get the same error as you when using 1.2.0. > Thanks ! I've created this issue: https://github.com/openshift/origin/issues/11836 « Suggestion: append in `oc` a warning mes

Re: Error: valueFrom fieldRef resource => ...env[5].valueFrom.fieldRef.fieldPath: Required value

2016-11-08 Thread Stéphane Klein
s.memory - name: CPU_LIMIT valueFrom: resourceFieldRef: resource: limits.cpu divisor: 1m complete file: https://gist.github.com/harobed/fc24a7766dbcf2d9e61f42dd8a968a6c 2016-11-08 16:14 GMT+01:00 Stéphane Klein : > https://gist.github.

Re: Error: valueFrom fieldRef resource => ...env[5].valueFrom.fieldRef.fieldPath: Required value

2016-11-08 Thread Stéphane Klein
https://gist.github.com/harobed/fc24a7766dbcf2d9e61f42dd8a968a6c 2016-11-08 16:03 GMT+01:00 Avesh Agarwal : > > > On Tue, Nov 8, 2016 at 8:50 AM, Stéphane Klein < > cont...@stephane-klein.info> wrote: > >> >> >> 2016-11-08 13:43 GMT+01:00 Avesh Agarwal :

Re: Error: valueFrom fieldRef resource => ...env[5].valueFrom.fieldRef.fieldPath: Required value

2016-11-08 Thread Stéphane Klein
2016-11-08 13:43 GMT+01:00 Avesh Agarwal : > > > On Tue, Nov 8, 2016 at 5:44 AM, Stéphane Klein < > cont...@stephane-klein.info> wrote: > >> Hi, >> >> I've this ReplicationController: >> >> apiVersion: v1 >> kind: List >> metadat

Re: Error: valueFrom fieldRef resource => ...env[5].valueFrom.fieldRef.fieldPath: Required value

2016-11-08 Thread Stéphane Klein
Same error here: http://lists.openshift.redhat.com/openshift-archives/users/2016-October/msg00082.html 2016-11-08 12:00 GMT+01:00 Stéphane Klein : > With resourceFieldRef like here https://github.com/openshift/ > origin-metrics/blob/master/deployer/templates/hawkular- > cassa

Re: Error: valueFrom fieldRef resource => ...env[5].valueFrom.fieldRef.fieldPath: Required value

2016-11-08 Thread Stéphane Klein
.valueFrom: Invalid value: "": may not have more than one field specified at a time, spec.template.spec.containers[0].env[6].valueFrom: Invalid value: "": may not have more than one field specified at a time] 2016-11-08 11:44 GMT+01:00 Stéphane Klein : > Hi, > > I'v

Error: valueFrom fieldRef resource => ...env[5].valueFrom.fieldRef.fieldPath: Required value

2016-11-08 Thread Stéphane Klein
ound no example with valueFrom + resource in OpenShift documentation. Best regards, Stéphane -- Stéphane Klein blog: http://stephane-klein.info cv : http://cv.stephane-klein.info Twitter: http://twitter.com/klein_stephane ___ users mailing list users@lists.

Re: default node selectors

2016-11-07 Thread Stéphane Klein
o select ssd. > > ___ > users mailing list > users@lists.openshift.redhat.com > http://lists.openshift.redhat.com/openshiftmm/listinfo/users > > -- Stéphane Klein blog: http://stephane-klein.info cv : http://cv.stephane-klein

Re: How to use SCC and HostPath ?

2016-11-03 Thread Stéphane Klein
2016-11-03 15:03 GMT+01:00 Stéphane Klein : > > > 2016-11-03 14:56 GMT+01:00 Clayton Coleman : > >> That RC is creating pods under service account cassandra. So you need to >> give "cassandra" access to privileged >> >> >

Re: How to use SCC and HostPath ?

2016-11-03 Thread Stéphane Klein
2016-11-03 15:03 GMT+01:00 Stéphane Klein : > > > 2016-11-03 14:56 GMT+01:00 Clayton Coleman : > >> That RC is creating pods under service account cassandra. So you need to >> give "cassandra" access to privileged >> >> >

Re: How to use SCC and HostPath ?

2016-11-03 Thread Stéphane Klein
2016-11-03 14:56 GMT+01:00 Clayton Coleman : > That RC is creating pods under service account cassandra. So you need to > give "cassandra" access to privileged > > Yes ! it's here: https://gist.github.com/harobed/76dc697e1658afd934c107aadc4f09a6#file-replicationcontrollers-yaml-L87 Thanks! I do

Re: How to use SCC and HostPath ?

2016-11-03 Thread Stéphane Klein
2016-11-03 14:55 GMT+01:00 Slava Semushin : > I suspect that it can be caused by wrong indentation. Could you try to > reduce the indentation of the volumes: block by 2 spaces? Here? https://gist.github.com/harobed/76dc697e1658afd934c107aadc4f09a6#file-replicationcontrollers-yaml-L93 It's alrea

How to use SCC and HostPath ?

2016-11-03 Thread Stéphane Klein
alue: "hostPath": hostPath volumes are not allowed to be used] Why ? I set policy on bad user ? Is it this bug? https://github.com/openshift/origin/issues/11153 Best regards, Stéphane -- Stéphane Klein blog: http://stephane-klein.info cv : http://cv.stephane-klein.info Tw

Re: containters with host volumes from controllers

2016-11-03 Thread Stéphane Klein
>> >>>>> >> >>>>> On Tue, May 17, 2016 at 11:44 AM, Alan Jones >> >>>>> wrote: >> >>>>> > I have several containers that we run using K8 that require host >> >>>>> > volume >> >>>>>

How can I put logstash config files in ConfigMap ?

2016-10-25 Thread Stéphane Klein
configMap For the moment I use PersistentVolume to store this configuration files but I think that it isn't the better choice. Best regards, Stéphane -- Stéphane Klein blog: http://stephane-klein.info cv : http://cv.stephane-klein.info Twitter: http://twitter.com/klein_ste

Re: Why I don't have debug information in DockerRegistry logs?

2016-10-24 Thread Stéphane Klein
2016-10-23 18:23 GMT+02:00 Skarbek, John : > In my opinion, I don’t believe this is an auth issue. > Yes! It is SSL issue. ___ users mailing list users@lists.openshift.redhat.com http://lists.openshift.redhat.com/openshiftmm/listinfo/users

Re: Why I don't have debug information in DockerRegistry logs?

2016-10-23 Thread Stéphane Klein
I see some debug message here https://github.com/openshift/origin/blob/master/pkg/dockerregistry/server/token.go#L60 Why I didn't see it in container logs ? 2016-10-23 11:41 GMT+02:00 Stéphane Klein : > Hi, > > I've some auth issue with my OpenShift DockerRegistry: > &

Why I don't have debug information in DockerRegistry logs?

2016-10-23 Thread Stéphane Klein
ot; 10.1.3.1 - - [23/Oct/2016:09:39:25 +] "GET /healthz HTTP/1.1" 200 0 "" "Go-http-client/1.1" But I've this in DockerRegistry config file: $ cat /config.yml version: 0.1 log: level: debug http: addr: :5000 storage: cache: layerinfo: inmemory

Re: Managing OpenShift Configuration with Puppet/Ansible… what are your best practices?

2016-10-13 Thread Stéphane Klein
2016-10-12 17:41 GMT+02:00 Alex Wauck : > we do the actual OpenShift installation using openshift-ansible (which > Rich Megginson mentioned) > Thanks but my subject isn't about OpenShift cluster installation and upgrade. Best regards, Stéphane ___ user

Re: Managing OpenShift Configuration with Puppet/Ansible… what are your best practices?

2016-10-13 Thread Stéphane Klein
2016-10-12 17:10 GMT+02:00 Rich Megginson : > On 10/12/2016 03:15 AM, Stéphane Klein wrote: >> >> * are there some Ansible or Puppet tools for OpenShift (I found nothing)? >> > > https://github.com/openshift/openshift-ansible I know and I use that, it's only

Managing OpenShift Configuration with Puppet/Ansible… what are your best practices?

2016-10-12 Thread Stéphane Klein
for OpenShift (I found nothing)? Best regards, Stéphane -- Stéphane Klein blog: http://stephane-klein.info cv : http://cv.stephane-klein.info Twitter: http://twitter.com/klein_stephane ___ users mailing list users@lists.openshift.redhat.com http

Re: All my image stream are bad docker registry IP, where is my mistake ?

2016-06-24 Thread Stéphane Klein
2016-06-23 18:51 GMT+02:00 Clayton Coleman : > The IP is cached by the master when you install the registry. If you > delete the service, you'll need to restart your masters. > Thanks, now it's working. ___ users mailing list users@lists.openshift.redh

Re: What is the consequence if I switch from ovs-subnet to ovs-multitenant on production cluster ?

2016-06-24 Thread Stéphane Klein
k // DevOps Engineer >> >> *E X O S I T E* >> *www.exosite.com <http://www.exosite.com/>* >> >> Making Machines More Human. >> >> > > > -- > > Alex Wauck // DevOps Engineer > > *E X O S I T E* > *www.exosite.com <http://www.exo

Re: All my image stream are bad docker registry IP, where is my mistake ?

2016-06-23 Thread Stéphane Klein
Yes, many time already. 2016-06-23 18:37 GMT+02:00 Clayton Coleman : > Did you delete and recreate your docker registry? > > On Thu, Jun 23, 2016 at 12:34 PM, Stéphane Klein < > cont...@stephane-klein.info> wrote: > >> Hi, >> >> I've have this confi

All my image stream are bad docker registry IP, where is my mistake ?

2016-06-23 Thread Stéphane Klein
Hi, I've have this configuration: ``` -bash-4.2# oc status In project default on server https://... svc/docker-registry - 172.30.75.178:5000 dc/docker-registry deploys docker.io/openshift/origin-docker-registry:v1.2.0 deployment #1 deployed about an hour ago - 1 pod ``` I've this images

Re: define openshift origin version (stable 1.2.0) for Ansible install

2016-06-22 Thread Stéphane Klein
sues on this version of OpenShift. We've deployed in > a team several times and are pretty confident with the setup and it was > always working fine for us. But now this last weird versions seem really > bad for us. > > ___ > users

Re: All my ipfailover pods are in "Entering MASTER STATE", it's not fair ?

2016-06-22 Thread Stéphane Klein
2016-06-22 2:17 GMT+02:00 Ram Ranganathan : > Couldn't figure out if you have a problem or not (or it was just a > question) from the email thread. > > It's an observation and I don't know if it's normal and I ask the question. Sorry if my mail is unclear. > What does "ip addr show" on all the

Re: All my ipfailover pods are in "Entering MASTER STATE", it's not fair ?

2016-06-20 Thread Stéphane Klein
think it's normal to have many Master instances. 2016-06-20 9:35 GMT+02:00 Stéphane Klein : > I would like to say "It's a problem, it's abnormal ?" > > 2016-06-17 16:26 GMT+02:00 Stéphane Klein : > >> Hi, >> >> I've: >> >&g

Re: All my ipfailover pods are in "Entering MASTER STATE", it's not fair ?

2016-06-20 Thread Stéphane Klein
I would like to say "It's a problem, it's abnormal ?" 2016-06-17 16:26 GMT+02:00 Stéphane Klein : > Hi, > > I've: > > * one cluster with 2 nodes > * ipfailover replicas=2 > > I execute: > > * oc logs ipfailover-rbx-1-bh3kn > https://gis

All my ipfailover pods are in "Entering MASTER STATE", it's not fair ?

2016-06-17 Thread Stéphane Klein
Hi, I've: * one cluster with 2 nodes * ipfailover replicas=2 I execute: * oc logs ipfailover-rbx-1-bh3kn https://gist.github.com/harobed/2ab152ed98f95285d549cbc7af3a#file-oc-logs-ipfailover-rbx-1-bh3kn * oc logs ipfailover-rbx-1-mmp36 https://gist.github.com/harobed/2ab152ed98f95285d549

Re: I try to append role to user but it's not visible with oc policy who-can, why ?

2016-06-15 Thread Stéphane Klein
n get pods`). I think it's only listing the users who can do any > verb (*) on any resource (*). > > On Wed, Jun 15, 2016 at 11:57 AM, Stéphane Klein < > cont...@stephane-klein.info> wrote: > >> Hi, >> >> I try to append role to user: >> >> ``` >

I try to append role to user but it's not visible with oc policy who-can, why ?

2016-06-15 Thread Stéphane Klein
stand why user1 isn't in who-can user list ? Where is my mistake ? Best regards, Stéphane -- Stéphane Klein blog: http://stephane-klein.info cv : http://cv.stephane-klein.info Twitter: http://twitter.com/klein_stephane ___ users mailing

What is the consequence if I switch from ovs-subnet to ovs-multitenant on production cluster ?

2016-06-14 Thread Stéphane Klein
Hi, I've made a mistake: I've installed my OpenShift cluster with ovs-subnet but I want to use ovs-multitenant. What is the consequence if I execute the switch on production server ? I simply need to restart all node after configuration update ? Best regards, Stéphane ___

Re: Error: « kubernetesMasterConfig: Invalid value: null: either kubernetesMasterConfig or masterClients.externalKubernetesKubeConfig must have a value »

2016-05-31 Thread Stéphane Klein
Well, it was my mistake: ``` ubernetesMasterConfig: ``` => ``` kubernetesMasterConfig: ``` in /etc/origin/master/master-config.yaml :( 2016-05-31 10:29 GMT+02:00 Stéphane Klein : > Hi, > > my origin-master container work perfectly until yesterday, now when I > start it,

Re: In cluster with 2 regions, do I need to deploy one "oadm router…" by region ?

2016-05-31 Thread Stéphane Klein
ft-ansible/blob/4b734695abf9ca112c9ad3be33f03fcd1a1e7abf/roles/openshift_facts/library/openshift_facts.py#L1676 > > > On 31 May 2016, at 10:23, Stéphane Klein > wrote: > > > > 2016-05-31 8:29 GMT+02:00 Vincent Behar : > > > > Instead of creating a second DC for the router, I would fix the &

Error: « kubernetesMasterConfig: Invalid value: null: either kubernetesMasterConfig or masterClients.externalKubernetesKubeConfig must have a value »

2016-05-31 Thread Stéphane Klein
Hi, my origin-master container work perfectly until yesterday, now when I start it, I've this error: May 31 10:21:36 prod-master-1.priv.tech-angels.net docker[27197]: Invalid MasterConfig /etc/origin/master/master-config.yaml May 31 10:21:36 prod-master-1.priv.tech-angels.net docker[27197]: kuber

  1   2   >