[00:01] hey all. I have several websites hosting on my server (running apache) is there something I can use to monitor network traffic and cap the total network traffic over a specified period of time? [00:01] jasonmsp what u use for monitoring [00:02] nothing at the moment. I'm looking for a solution to monitor the traffic and cap it if they hit a certain threshold [00:03] but I'm looking to do that on a vhost basis. [00:03] hallyn: https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1023205 [00:03] Launchpad bug 1023205 in libvirt "libvirt_lxc crashed with SIGSEGV in random_r()" [Undecided,New] === Pupeno_W_ is now known as Pupeno_W === txwikinger2 is now known as txwikinger === wylde_ is now known as wylde === n0ts_off is now known as n0ts [00:40] pxe installing, I keep getting an error about a corrupt Packages file. I read some posts suggesting just gunzip it, but it didn't help. [00:50] ww/away gone === kermit1 is now known as kermit === cpg is now known as cpg|away === n0ts is now known as n0ts_off === th0mz_ is now known as th0mz === cpg|away is now known as cpg === cpg is now known as cpg|away === MoleMan is now known as MoleMan_ === cpg|away is now known as cpg === cpg is now known as cpg|away [03:10] Hello, can multiple virtual instances of Ubuntu Server access the same physical RAID array directly, or can this only be done by mounting samba shares of the physical host locally within each VM instance? [03:11] I can't stick around but if you have any info on this please let me know at public AT duvrazh (dot) net === Guest36151 is now known as exocaesar === cpg|away is now known as cpg [04:18] Any know any link on beefing up dhcpclient for a server. I run a private cloud with openstack and the instances sometime have a glitch and do not get a dhcp response. It then destroys the interface and I loose IP. === Aaton is now known as Aaton_off === n0ts_off is now known as n0ts === n0ts is now known as n0ts_off [05:38] Any fstab wizards out there? [05:47] Hello, I would need a little help with an autoupdate script [05:47] Any helping hands? === n0ts_off is now known as n0ts [05:57] resno: looks to me unraid is some file-level raid aka raid-3. it' also proprietary, or little used, full of buzzwords etc, so i think i'll stick to linux ;-) [05:59] <_Andrew> Hi guys, need some help, I'm following the answers posted about getting DNS working here.. http://askubuntu.com/questions/140688/upgraded-server-to-12-04-dns-no-longer-working [06:00] <_Andrew> But none of the answers are working [06:00] <_Andrew> This is for 12.04 [06:00] <_Andrew> Clean install === almaisan-away is now known as al-maisan === n0ts is now known as n0ts_off === n0ts_off is now known as n0ts [06:43] _Andrew: check /etc/resolv.conf [06:44] _Andrew: static ip or dhcp? [07:06] Nathan_S === ubuntu is now known as Nathan_S [07:46] fstab wizards.... remember "\040"= a directory space in fstab... [07:46] That had me stumped... [08:03] <_Andrew> RoyK, I have a static IP set and I have added nameservers to resolve.conf [08:04] <_Andrew> but still can't ping google.com or anything [08:05] <_Andrew> In fact the resolv.conf just gets wiped regardless of the config I changed in the link I gave eariler [08:09] zul, I think we should drop the openvswitch-datapath packages based on what upstream have suggested for quantal === n0ts is now known as n0ts_off === n0ts_off is now known as n0ts === n0ts is now known as n0ts_off === ubuntu is now known as Nathan_S [09:17] _Andrew: with static ip, you need to add the nameservers to /etc/network/interfaces - at the end of the eth0 block, add 'dns-nameservers x.x.x.x' and 'dns-search your.tld' [09:18] is there a way to run bash instead of sh in upstart scripts? === ninjak_ is now known as ninjak === Pupeno_W_ is now known as Pupeno_W === cpg is now known as cpg|away === al-maisan is now known as almaisan-away === matsubara is now known as matsubara-afk [11:41] zul, thoughts on openvswitch then? drop the datapath packages? [11:42] jamespage: still waking up but yes...i agree === almaisan-away is now known as al-maisan === al-maisan is now known as almaisan-away [11:50] could someone tell me why scponly has been removed from the repos and what I'm supposed to use instead? [11:51] feisar: "(From Debian) RoQA; RC buggy, unmaintained, replacement exists; Debian bug #650590" [11:51] Debian bug 650590 in ftp.debian.org "RM: scponly -- RoQA; RC buggy, unmaintained, replacement exists" [Important,Open] http://bugs.debian.org/650590 [11:52] https://launchpad.net/ubuntu/+source/scponly/+publishinghistory [11:52] good morning [11:53] jpds: thanks [11:56] zul, I'll stuff that in now then [11:57] jamespage: cool....i have to go figure out how to unbreak libvirt === almaisan-away is now known as al-maisan [12:04] how do i change openstack dashboard passwd ..password is lost by me [12:04] usign 12.04 [12:09] zul: does bug 1011627 need some love? [12:09] Launchpad bug 1011627 in six "[MIR] python-requests" [Undecided,Fix released] https://launchpad.net/bugs/1011627 [12:09] Daviey: yes i just havent gotten to it yet [12:10] cool [12:10] roaksoax: python-mailer needs dh2 transition ? [12:19] zul: I'm just going to disable the package in control for the time being [12:19] upstream might make it work again at some point in time [12:19] i.e. its a hack [12:20] jamespage: yeah i think 1.4.2 might be getting long in the tooth as well [12:20] zul, I think an update to 1.6.x with current snapshot from branch-1.6 might be a good idea [12:20] zul, I can do that at the same time if you like - have a test setup here already [12:21] jamespage: stick it in a ppa first before uploading it :) === th0mz_ is now known as th0mz [13:03] zul: hm, for some reason tftpd-hpa is not starting right here on boot. upstart thinks its running, but ps -ef | grep tftp shows nothing, and clients aren't connecting [13:04] when i sudo restart tftpd-hpa, then clients can connect and ps -ef | grep tftp shows it running [13:04] running what? [13:04] root 18298 1 0 08:02 ? 00:00:00 /usr/sbin/in.tftpd --listen --user tftp --address 0.0.0.0:69 --secure /var/lib/tftpboot [13:06] i see nothing in the upstart job that should cause that... [13:12] Daviey: checking... [13:12] Daviey: that' [13:12] Daviey: that's wird I thjought I had uploaded it already [13:22] roaksoax: heh [13:23] Daviey: done! [13:23] \o/ [13:23] Daviey: if you are doing AA work, could you also take care of python-tx-tftp please? [13:24] it's in the new queue [13:24] roaksoax: i accepted it earlier :) [13:24] Daviey: awesome then, thanks1` [13:24] Daviey: awesome then, thanks1 [13:24] err [13:24] ! [13:25] oh what [13:25] I reviewed it, but didn't accept it. [13:25] roaksoax: I wanted to question why you didn't use github? [13:26] roaksoax: There isn't a debian/watch file which will probably be needed for MIR btw [13:26] but happy to accept it. [13:27] Daviey: I didn't use github because I wanted to use the same approach as we did with cobbler on having it imported over launchpad, and for ease of packaging [13:27] roaksoax: ok, cool [13:27] Daviey: and can't really have a watch file when upstream doesn't provide tarballs, can we? [13:28] roaksoax: well.. you can.. it's just less fun. [13:28] probably not required for this example TBH [13:29] anyway, accepted :) [13:29] Daviey: I see, cause I couldn't find any examples of importing from a branch in debian/watch. But I agree it is pretty stationary code either way. [13:29] Daviey: and thanks! [13:35] RoyK: no unraid for you lol [13:35] jamespage: im sitting on libvirt 0.9.13 btw [13:36] zul, coolio - I think that gives us ceph authenticated block access [13:44] zul, breeding? [13:44] smb: ? [13:44] smb: exactly [13:45] Just imagined you sitting on the package keeping it warm. ;) [13:45] * smb wonders how zul speaks without being present... [13:47] I suggest you turn join/leave messages on ;) [13:48] well, duh, zul's a demi-god. of course he can speak without being present. === zyga is now known as zyga-food === zyga-food is now known as zyga === al-maisan is now known as almaisan-away [14:40] hallyn: i applied the random libvirt-lxc segfaulting patch to libvirt and still get the same thing [14:41] zul: drat. (i'm still waiting for mine to finish building) === Lcawte|Away is now known as Lcawte [14:42] hallyn: http://paste.ubuntu.com/1086274/ [14:42] * hallyn shakes his head - traffic to archives is painfully slow right now for me [14:45] hallyn: it just cant find veth [14:45] zul: are you sure you quilt push'd the patch? bc it's fixed here [14:46] mind you in ppa i had a test case failure for i386, something to do with initrd, but i'm going to have to hope that's a ppa-only problem bc nothing i changed should have caused that. [15:00] zul: (back in a bit, lemme know... it'd be very weird if it worked for me but not for you) [15:07] smoser, if i have a multi-part cloud-init user-data can i specify the order things get run? [15:07] what things? [15:08] smoser, for example can i have a couple scripts run , then cloud-config, then another script? [15:09] hm.. [15:09] you can accomplish what you want, yes. [15:11] depending on what you want, bootcmd may be sufficient [15:11] http://bazaar.launchpad.net/~cloud-init-dev/cloud-init/trunk/view/head:/doc/examples/cloud-config.txt [15:11] also see Cloud Boothook at https://help.ubuntu.com/community/CloudInit [15:18] smoser, ok, thanks ... what about multiple user-data scripts running at rc.local-like time? do they run in any particular order? such as alphabetical? [15:21] if you provide filenames, they run in run-parts order [15:21] C locale sorted order. [15:22] ok, thanks very much === n0ts_off is now known as n0ts === zyga_ is now known as zyga [15:44] hello, I am facing issue with ubuntu image desktop via PXE installation [15:45] I am using version 12.04 LTS [15:46] I am using DNSMASQ & atftpd for booting PXE [15:48] resno: no, I prefer the real stuff, either linux md or zfs, depending on application ;) [15:49] but once the system booting over the network, they read the preseed.cfg but issues with Packages file missed, I created that file, the 2nd issue say, continue without installing kernel ? .... really strange stuff ! [15:50] what is the best way to install ubuntu desktop 12.04 LTS over the LAN? [15:50] any suggestion ? [16:00] zul: exaclty what do you mean by 'missing veth'? can you show 'ls /sys/class/net'; 'ip link add type veth'; 'ls /sys/class/net' output? === matsubara-afk is now known as matsubara === n0ts is now known as n0ts_off [16:02] hallyn: gimme a sec rebooting [16:04] hallyn: well manually it works: http://paste.ubuntu.com/1086402/ [16:06] zul: can edit that domain, get rid of the 'target dev=veth0' and 'mac address=' lines, and see if that helps? [16:06] hallyn: sure [16:06] the 'target dev=veth0' *should* only be there while it's running, hopefully [16:06] note, i don't expect that to help, just want to verify [16:09] looks like the next few servers I'll be setting up at work, will be on centos, because ubuntu doesn't have ovirt :( [16:10] RoyK: if you do try oVirt on Ubuntu, i'd like to know how it goes. [16:10] is there any control panel which supports lighttpd? [16:10] hasdf: gnome-terminal is one, putty is another.. there are a few. [16:10] bug 337976 [16:10] Launchpad bug 337976 in ubuntu "[needs-packaging] Package Redhat's oVirt for use on Ubuntu" [Wishlist,Confirmed] https://launchpad.net/bugs/337976 [16:11] hallyn: no dice [16:11] now that's unrelated to the new 'ovirt' effort right? [16:11] Daviey: after browsing this http://www.ovirt.org/wiki/Ovirt_build_on_debian/ubuntu I don't think I can give my boss a good reason for choosing ubuntu for this system [16:12] hallyn: why? [16:13] hallyn: are there any new ovirt efforts ongoing in debuntu land? [16:13] RoyK: http://www.theregister.co.uk/2011/09/23/ovirt_red_hat/ [16:13] dannf: were you the one who knows a bit more about (the new) ovirt? [16:13] RoyK: we were more involved initially, but really decided to consecrate our effort on IaaS [16:13] Daviey, I mean control panels like webmin, cpanel etc [16:14] hallyn: both link to ovirt.org [16:14] hmm [16:14] hallyn: the fancy windows frontend isn't interesting [16:14] ok, i thought it had a new code base for some reason. parently not [16:14] the failover parts in ovirt *is* interesting [16:15] but then - perhaps I'll just setup KVM with shared storage on GFS2 and do some hacking - possibly more fun :D [16:17] zul: looks like 0.9.12-0ubuntu5 has built but not yet been published... come on... come on... [16:19] hallyn: im going to finish what im doing here then i can grab the source and build it myself :) [16:22] zul: the advantage of the archive is the -dbg packages :) [16:22] right nm then :) [16:22] * RoyK wonders if vbox can handle sharing disks.... [16:24] How do you disable upstart services? [16:25] !upstart [16:25] Upstart is meant to replace the old Sys V Init system with an event-driven init model. For more information please see: http://upstart.ubuntu.com/ [16:26] RoyK: it sounds like you're doing something interesting. might be fun to post goals to ubuntu-server and get some more ideas. For instance i think SpamapS has some experience with all the cluster/cloud-fs's [16:27] hallyn: will do - just need to discuss it a bit at work first [16:27] cool [16:27] but I guess we'll start off with two pizzaboxes and a shared piece of disk on the SAN [16:30] Pupeno_W: natty and later, do 'echo manual >> /etc/init/$jobname.override' [16:30] SpamapS: interesting. Thanks :) [16:31] SpamapS: do you have much experience with shared filesystems like GFS or OCFS? [16:37] RoyK: yes, my experience with both was to give up and buy a NetApp [16:38] how did that make things better? [16:38] RoyK: they are very old-world.. very fussy, and IMO, SAN shared FS's are a money and time sink [16:38] tried v2 of them as well? [16:39] RoyK: the NetApp always worked.. even tho we had to find all the flock()'s and turn them into fcntl locks.. that was nothing compared to trying to tune GFS [16:39] no this was maybe 8 years ago [16:39] a few things have happened since then ;) [16:40] RoyK: in fact the netapp was eventually replaced by a couple of commodity servers running Linux NFS once we made our code behave and realized we didn't even need the netapp. [16:40] RoyK: this was with *billions* of file operations per hour [16:41] SpamapS: so a mere million IOPS? pretty fancy hardware, then ;) [16:42] RoyK: 20 disks in RAID5+0 on a nice external HP RAID (I forget the number.. something-1000) [16:43] but probably not a million IOPS [16:43] RoyK: the key was to have 1GB of battery backed cache [16:43] RoyK: I did not say IOPS too.. file operations... not everything made it to disk :) [16:44] well, I'll do some testing with vbox to see what happens :D [16:44] and tomorrow with some 1U machines struggling to use the same SAN LUN [16:44] * RoyK likes that sort of fun [16:45] zul: looking one more time at http://paste.ubuntu.com/1086274/, the missing eth0 looks to still be because the libvirt-lxc driver segfaulted before it created the veth pair. then the libvirt monitor which is supposed to do brctl addif br100 veth0 fails [16:45] zul: what does /var/log/libvirt/lxc/instance-00000001.log show? [16:45] RoyK: Anyway, I've never had a workload which wanted a real SAN.. so perhaps your use case is different. I prefer to encapsulate everything in its own cost pool rather than have a big storage monster. ;) [16:45] funny thing is, we already have an ESX setup, but it's drawing too much from the budget, so I've been asked to help setup something with KVM to offload whatever not needing that redundancy ESX can give us [16:47] hallyn: i turned on more verbose debugging: http://paste.ubuntu.com/1086475/ [16:48] royk, ya, esx is nice, but alittle overkill unless you want some kind of ha [16:50] I *do* want to do some kind of HA [16:50] for instance, I want to move VMs around if they're in the way [16:50] that's not HA, but perhaps poor-man's-HA [16:54] hallyn: doesnt seem to be published yet :*( [16:54] zul: all right fine build locally ((*&%(*$&%) [16:55] dont worry ill build the debug packages as well [17:06] patdk-wk: I misread that - we need HA for pretty much, but we don't need ESX-grade HA for everything, and ESX is rather expensive, so we want a small KVM setup to offload the ESX with the not-so-important-VMs, but even there, we want shared storage, I recommended NFS, but he didn't listen, so we'll try GFS2 [17:09] basically, you just want normal esx HA, but not FT [17:10] vmotion, restart on host failure, but not 100% uptime requirement [17:10] I don't know if we use FT [17:10] I just started in this job :) [17:10] heh [17:11] and for what I can understand, there's no current plan of abandoning ESX altogether, but to offload it with KVM for the less important stuff [17:12] heh, I hope they are using other good features of esx for something then [17:13] so do I [17:13] but then, those features only really come into play with really demanding vm's [17:13] so maybe that is the goal [17:13] hallyn: well it seems to work, but the domain seems to crash http://paste.ubuntu.com/1086519/ (note: that this is with a precise image) [17:14] IIRC FT VMs are rather heavy, so perhaps they want to offload the cluster with taking out the smaller, less important ones to KVM [17:14] I'm getting ready to setup my first few FT vm's here [17:14] what sort of network are you using? 10G or IB? [17:15] right now, 1g :( [17:15] the FT vm's might have to wait till the 10g upgrade [17:15] not good for FT, or so I've heard [17:15] ya [17:15] zul: ok lemme try a precise container. (gonna take awhile to create, archives NOT treating me well) [17:15] hallyn: ok lemme try with a quantal container [17:15] patdk-wk: perhaps better use IB, might even be cheaper, and for the memory transfer, probably better than 10GE [17:16] really wish I could use my 8g fc's for it [17:16] they can't use IB though :( [17:16] their systems can't handle it [17:16] ok [17:16] zul: that's libvirtd.log right? do you have a instance-00000x.log you can pb? [17:16] hallyn: thats the instance-00000x.log [17:16] hm [17:16] just use a dedicated FC setup, then - the memory traffic is *heavy* [17:17] zul: in what way does it crash? does the whole domain disappear? or does it hang and you can't login? [17:17] whole domain disapears [17:17] plausible [17:18] sigh, i hope i dno't have to weed through the other libvirt-lxc commits t o pick the 'important' ones [17:18] patdk-wk: but - why is it their systems can't handle IB? [17:18] their blades/chassis can't [17:18] it could do IB or FC [17:18] ah [17:18] ic [17:18] but they build everything on fc [17:19] but they can do 10Ge? [17:19] zul: might be worth switching to 0.9.13 + the init_random patch [17:19] hallyn: agreed [17:20] ya, the blades already support 10g, just the blade switch needs to be swapped [17:20] i thought the init_random patch already made it in [17:20] patdk-wk: if they have dual port, use a dedicated network for the memory part [17:20] and thus, a dedicated switch [17:20] they currently have 2 10g and 2 1g nic's per blade [17:20] 4 switchs [17:20] or at least a vlan if the switch can handle that [17:20] could do 4 10g ports [17:21] zul: can't have, you said yo uhad the same failure with 0.9.13 right? [17:21] hallyn: yeah but i might be on crack now...anyways ill double check, play around with it and upload it on friday [17:21] ya, if they give me 4x 10g, I'll be dedicated 1 or 2 of those ports for bulk data moves [17:21] that is - any switch can handle vlans, but I meant "if the switch can handle both the ordinary traffic and that memory traffic" [17:21] zul: wait, what, upload what on friday? [17:22] libvirt 0.9.13 [17:22] my container should be half debootstrapped... [17:22] ok [17:22] i have it already packaged, just need to add one more patch other than the init-random patch [17:41] jamespage, ivoks: merged open-iscsi from Debian, our delta is really quite minimal now so it should help keeping on top of the bugs === fenris_ is now known as Guest10826 [17:41] (took a couple of days to get it done as it was last merged back in Jaunty) === Guest10826 is now known as ejat [17:45] stgraber: jaunty?? [17:45] anyone have linux-crashdump / apport working on 10.04? we're trying to gather information on these '200ish days' failures which are affecting our prod infra.. [17:45] when i install linux-crashdump, i see that apport fails to start [17:45] doesn't really say much in log, some boilerplate in daemon.log [17:45] which i can paste bin in a sec :) [17:47] When you're installing via kickstart, which packages can you safely select for installation? I tried vim-nox, but it's failing on it. [17:48] * bitmonk thinks ubu+kickstart makes about as much sense as apt on rhel [17:49] just an opinion, of course, but you should take a look at fai. === cpg|away is now known as cpg [17:50] * bitmonk is an idiot, enabled=0 in /etc/default/apport of course [17:50] bitmonk: fai is more than I need. and from what I've read, with what I'm doing, kickstart and preseed should be almost identical. Hell, one requires the other. [17:51] RoyK: yeah, nobody really looked after open-iscsi for quite a few years :) [17:51] strange thing is that it works... [17:51] hopefully also after this upgrade ;) [17:51] kinda, I had to add pretty ugly hacks back in 11.10 for it to still let you boot [17:56] stgraber: What are people using for iscsi instead then? [17:56] kyle__: they are using open-iscsi, that's the scary part ;) [17:56] I mean, it works fine as long as you don't use it for your root device [17:57] if you use it for your root device, it'll still work but if anything happens on the server, you're pretty much dead [17:57] Ooh I see. I don't know why you'd use iscsi for your root device without an HBA to be honest. [17:57] as there's a bug preventing iscsid from starting [17:57] some people apparently are doing that ;) [17:57] I suppose it would be pretty easy to setup a pxeboot to do it... Ugh. [17:58] the new version I just uploaded fixes that bug on top of a lot of others and reduces the delta so much that merging changes from Debian should just be a matter of minutes [17:58] stgraber: Most of the root device is really file-level stuff, so NFS would probably outpreform iscsi (software not hba) anyway. [17:58] yeah, that's how I've been testing it, PXE setup + iscsi server [17:58] * kyle__ nods [17:59] I never liked iscsi to be honnest, if you're into serious storage, just go with a SAN+fiber-channel, sure it's more expensive but it's MUCH faster and usually more reliable [18:00] has anyone buit dns servers with content filtering? [18:00] I'm doing iscsi for diskless workstations [18:00] like it over other models [18:00] i need something similar to opendns but..well not opendns [18:00] grendal: I'm sure lots of people do, but I tend to do filtering at a proxy level. What are you trying to do? [18:00] Ahh. [18:01] patdk-wk: Which OS? How's it preforming? [18:01] for me? no one has complained, or even noticed [18:01] right now, the iscsi server has 4 1g nic's, and workstations just have 1g nic [18:01] got a situation where i have a lot of individual boxes..over 6000 actually. cant send all their traffic to one server or a cluster even.. need to just block dns requests [18:01] stgraber: I can see it's advantages for some things, especially if you need lots of connectivity, and speed isn't the aim. But for anything I've ever done a well tuned NFS server beats it. Just what I've done though. [18:02] using OI comstar for iscsi target [18:02] patdk-wk: What OS is on the clients? Linux? BSD? windos? [18:02] mixture [18:02] mythbuntu at home :) [18:03] patdk-wk: And they're all fine with it? Neat. [18:03] here at work, win7 [18:03] have 8 of those win7 machines here [18:03] well, doing iscsi boot [18:04] the idea is, these machines are more for temp employee/workstations [18:04] grendal:Ah ok. If you want to do it in DNS, I'm pretty sure there are howtos. Or you could make a firewall rule on the server in question, and deny all traffic that not from where you want. [18:04] so iscsi makes it easy to snapback changes to redeploy [18:04] patdk-wk: cool. [18:05] also, having the whole disk image able to fit in ram, on the iscsi server, helps make it pretty snappy [18:05] Heh. That's almost cheating. [18:05] hallyn: new libvirt at http://people.canonical.com/~chucks === Aaton_off is now known as Aaton [18:54] Hi. How to get ubuntu 12.04 settings when installed from minimal netinstall? Things like visible boot process, motd? [19:00] punjab? heh? [19:01] patdk-wk: When you install from server iso, there are this little differences [19:01] yes [19:01] I just don't see the point [19:01] the graphical stuff just gets in the way if you have issues [19:02] or even to let you know what is slowing down the boot [19:02] Yes a want this, but i install from minimal netinstall === fenris is now known as Guest42115 [19:02] I only install from minimal [19:03] that's what i most often do [19:03] now in taskel you can then select 'ubuntu server image' iirc. not sure if that ends up same. [19:05] * patdk-wk did his first redhat minimal instal this week, that was a total pain, been too long since I last did one [19:06] When you login on clean minimal install, then login motd is different. In server minimal install have info about running procesess and system load [19:08] clean minimal install? [19:08] yes. Only ssh selected [19:09] I'm confused by your two different minimal installs [19:09] I only know of one [19:10] One from oficiall ubuntu server iso another from minimal iso: https://help.ubuntu.com/community/Installation/MinimalCD/ [19:12] ya, would have to compare the preseed files on those two different images [19:12] I always use the server iso these days, since it's easy to mount iso in vm [19:12] used to pxe boot install everything [19:14] I dont expect difference, so i install from minimal.iso... Now i must configure this things manually [19:15] Something like ubuntu-server package with server settings will be fine [19:18] hallyn: so i almost have libvirt-lxc working again on quantal, i supect i need to backport one more patch [19:19] which? [19:19] http://libvirt.org/git/?p=libvirt.git;a=commit;h=60687546705bab38bd5245713601b717b9b16c9d [19:20] oh, yeah [19:20] though i still maintain they start all right for me [19:21] on 0.9.13? === jdstrand_ is now known as jdstrand [19:42] zul: no on 0.9.12-0ubuntu5 [20:02] anyone can help me plz? [20:02] !ask [20:02] Please don't ask to ask a question, simply ask the question (all on ONE line and in the channel, so that others can read and follow it easily). If anyone knows the answer they will most likely reply. :-) See also !patience [20:03] I am working on PXE installation for Ubuntu 12.04 [20:03] and I faced this error "The installer cannot find a suitable kernel package to install" [20:03] any advices ? [20:04] hellp! [20:04] hello! [20:04] S0ME1: Where is your installer getting it's deb files from? [20:05] genii-around: from my own mirror [20:05] I just rsync the CD file under my web server [20:05] file=files [20:06] S0ME1: So you've added some option to your dhcpd.conf like next-server ? [20:06] genii-around: I am using DNSMASQ [20:06] Hm [20:06] managing TFTP & DNS & DHCP [20:07] S0ME1: What is the tftp line on your server which is loading the kernel? [20:07] genii-around: if install the ubuntu server using CD manual, it is working well but over the network I got this error ""The installer cannot find a suitable kernel package to install"" [20:08] genii-around: what do you mean please ? [20:08] Hm [20:09] S0ME1: So right now when you boot the remote machine, it starts to load it's first part but then stalls during boot? [20:10] it is working [20:10] S0ME1: What do you have in /var/lib/tftpboot/ ? [20:12] eg: What are the contents of your pxelinux.cfg file [20:14] work requires me, returning shortly [20:14] genii-around: juts to boot via my pressed and [20:23] S0ME1: In your /etc/dnsmasq.conf what do you have for tftp-root value? And then, wherever that directory is, do you have a netboot kernel in there? [20:50] What's the rational for putting ntpdate as the default on ubuntu server instead of ntpd? [21:23] hallyn, qemu-kvm installation fails if you dont have a kernel module for kvm available. [21:23] (as the service tries to modprobe and fails) [21:23] FATAL: Module kvm_amd not found. [21:24] i do not believe that was the case recently [21:24] in q? [21:26] smoser: you get that in quantal, not precise, right? [21:26] quantal [21:26] i dunno, debian maintainer wasn't happy with my q package anyway, perhaps i should redo all of it [21:27] smoser: thanks i'll fix it [21:27] smoser: tbh i don't understand why it sometimes isn't available. don't all our kernels ship it? [21:28] -virtual kernel does not have it. [21:28] and someone's custom kernel might not have had it [21:28] smoser: in precise it will also fail if not installed, fwiw [21:28] hallyn, for some reason i dont think tha tis the case [21:28] smoser: i agree i've never seen it happen, but looking at the upstart job, it *should* [21:28] i'm basically walking through some notes i had done on p [21:29] my point being i worry something else may be wrong [21:29] and i dont have any recollection of it failing ther [21:29] but it is possible my notes are just bad [21:29] clearly easy enough to test by launching an instance [21:29] no, i don't recall it ever failing in a cloud image in p [21:30] smoser: what would you suggest, do 'modprobe || true' or just 'modprobe || {stop; exit 0'}' ? [21:31] hallyn, i guess || true [21:32] modprobe -b kvm_intel "$KVM_NESTED" [21:32] that seems evil [21:32] the right way to do that i would think would be to modify modprobe.d [21:33] smoser: fwiw the reason i ignored this before is that we have an upstart job for loading the kernel module, so if loading kernel module fails, it seemed the upstart job should fail [21:36] smoser: 'options kvm_intel nested=1', and invite the user to change that if they like? [21:37] well, yeah, thats what i was saying. doesn't that seem like the more common place to do that? [21:37] ie, if something else modprobed this, they wouldnt get your settings [21:39] sure [21:39] just need to learn the debian packaging way to install a modprobe.d file [21:39] (will have to wait until next week) [21:50] dpkg-reconfigure mdadm offers you the choice of booting with a degraded raid, or not. But it doesn't seem to be putting bootdegraded=true into the grub config. Where's the "right" place to put that manually? /boot/grub/grub.cfg is auto-generated durring updates, right? [21:51] kyle__: /etc/default/grub [21:55] Thank you. [21:56] kyle__: you're welcome :) and dont't forget to run sudo update-grub afterwards [21:56] guntbert: This was getting really frustrating I'll tell ya. [21:57] Now to check to see if that's a known bug. === Lcawte is now known as Lcawte|Away [22:19] Yea, new bug. === n0ts_off is now known as n0ts [22:39] Hello! [22:40] I have a ubuntu server (12.04) with 2 nics, 1 nic is wan, the other is lan, how can i turn ssh off for the wan? (eth0) [22:44] hilarie: You mean have the ssh server only running on the lan for people to ssh in, or you mean to prevent people from ssh-ing out to the internet at large? [22:44] Prevent inbound SSH traffic, I.E. I think I want to close port 22 on the wan? I am not sure, I don't want anyone to be able to SSH the server from wan [22:49] hilarie: You can set in sshd_config to only listen on whatever IP only ( so the lan one only ) ... i think is the ListenAddress variable [22:49] genii-around, Thank you! [22:50] If traffic is going through a router already, probably not really a concern unless that machine has an IP directly on the internet, or is in the DMZ, or port 22 is forwarded [22:50] hilarie: np [22:51] genii-around, it isn't protected by a NAT [22:51] its Modem----->server----->wifi router-----> other stuff [22:52] hilarie: Ah, then yeah [22:53] would rather block the WAN then have to play around with disabling the p/w [22:53] ( if server is doing the ISP auth ) [22:53] The ISP multicast for IPTV destroys the wifi router [22:57] genii-around, this looks like the command [22:57] ListenAddress host|IPv4_addr:port [22:57] stgraber: bzr+ssh://bazaar.launchpad.net/~serge-hallyn/ubuntu/quantal/lxc/lxc-api-getconfig/ is working for me [22:57] stgraber: give it a spin [22:57] do I include the | ? [22:58] hilarie: Yes. So you can also put there some non-standard port too if you liked on the same line [22:58] so ListenAddress host|LANIP:22 ? [22:58] hilarie: If no port specified then 22 is assumed [22:58] genii-around, Your a gentleman and a scholar, thank you! [22:59] hilarie: Well, one of those two anyhow! ... don't forget to restart sshd after of course... [22:59] thats the sudo /etc/init.d/ssh restart [22:59] right? [22:59] stgraber: all right, never mind. i have some fine-tuning to do [22:59] hilarie: I can't remember if upstart job or no for that yet [23:00] ( might be sudo start sshd ...instead) [23:00] Yeah, everytime I do /etc/init.d/ stuff, it yells at me about an upstart job, what is that? [23:01] hilarie: init.d/contents are linear-loading type startup scripts... init/scripts are those for upstart which loads what it can in parallel [23:02] hilarie: The old way is being migrated, etc [23:02] I think I get it... if it yells at me about it, you can just go sudo start *stuff* [23:02] hilarie: Well, /etc/init.d/name stop first.... but yeah [23:02] without the /etc/init.d/*stuff* *start/restart/stop* [23:03] hilarie: If the app only has old one in /etc/init.d/ you can still go through upstart with sudo service old-name start [23:03] Port 22 is closed on MyIP :) [23:07] From a security standpoint, its not a big deal that the BIND9 has port 53 open on my WAN port right? [23:08] hilarie: Not sure there, but every closed port helps [23:09] It's the only open one on WAN :) [23:10] hilarie: If you're extremely worried about attacks there, you could even compartmentalize port 53 into a virtual machine that can't compromise anything else [23:10] I was just reading about bind9, and its so simple, and well devoloped, there are no known vulnerabilities [23:12] hilarie: If you search for bind9 and exploits I'm sure there's probably a few [23:12] Bleh, your right! [23:25] All ports closed or Stealth! === n0ts is now known as n0ts_off === n0ts_off is now known as n0ts === cpg is now known as cpg|away