/srv/irclogs.ubuntu.com/2017/12/21/#ubuntu-server.txt

=== ShaRose_ is now known as ShaRose
cpaelzergood morning06:34
lordievaderGood morning07:01
jamespagecpaelzer: good morning10:03
jamespagecpaelzer: need some help with https://bugs.launchpad.net/cloud-archive/+bug/173958510:03
ubottuLaunchpad bug 1739585 in Ubuntu Cloud Archive "L2 guest failed to boot under nested KVM: entry failed, hardware error 0x0" [Undecided,New]10:03
cpaelzerhi jamespage10:03
cpaelzerlet me read10:03
jamespagecpaelzer: ta10:03
cpaelzerjamespage: you know the nested story is "it works great most of the time until it doesn't" :-)10:04
jamespagecpaelzer: yup10:04
cpaelzerso this is one :-)10:04
jamespagecpaelzer: unfortunately we kinda rely on this for testing10:04
jamespagecpaelzer: I guess I could switch back to using userspace qemu10:04
cpaelzersure I know the CI things behind this10:04
cpaelzerwhich isn't 100% reliable either10:05
cpaelzerjamespage: you could think next time you buy HW to buy AMD which is said to be slightly more stable at nested10:05
cpaelzerlike 99.99 vs 99.9 %10:05
jamespagelol10:05
cpaelzerbut none in the 5-9s or more10:05
cpaelzerjamespage: to confirm - this is Host "xenial (4.4) + queens stack" running zesty (or X-HWE) 4.10 KVM guests and in said KVM guests running 4.10 again10:08
jamespagecpaelzer: base cloud is 4.4 with ocata10:08
cpaelzerok10:08
jamespagecpaelzer: test cloud is xenial (4.4 or 4.10) with queens stack10:08
jamespagefrom bionic basically10:08
cpaelzeryep10:08
cpaelzerok10:08
cpaelzerthx10:08
cpaelzerjamespage: also I wonder about "specific hosts" in the bug - what makes them "specific"10:09
cpaelzerjust a few of your systems but those always failing?10:09
jamespagecpaelzer: I think they are the newer hardware ones10:09
jamespagecpaelzer: yeah confirmed - flemming is ~12 months old, caipora is 6 years old10:14
cpaelzerjamespage: is flemming the failing one and is it >=Haswell thne?10:14
jamespageyes10:14
jamespageits a "Intel(R) Xeon(R) CPU E5-2650 v4"10:15
cpaelzerjamespage: IIRC openstack will make model a host-passthrough or host-model right?10:20
cpaelzerjamespage: I dumped some background, comparison data from my system and a few requests to the bug10:36
jamespagecpaelzer: ta10:36
cpaelzerjamespage: I hope based on this we can spot a difference that is a tunable you might be able to change10:36
cpaelzerbut no guarantees10:36
cpaelzerthis is just setting up the scanners based on how this issue showed up a few years ago10:37
jamespagecpaelzer: http://paste.ubuntu.com/26226375/ thats in the vm10:41
jamespagehttp://paste.ubuntu.com/26226377/ is the host10:41
jamespageso infact its a broadwell, not a haswell10:41
jamespageso I think that's host-model rather than host-passthrough10:42
cpaelzerjamespage: (me reading)11:07
jamespagecpaelzer: attached stuff11:07
cpaelzerthx11:07
jamespagecpaelzer: the last two are odd - one is from an OK host the other from a failing one11:07
jamespagethe OK host as an AMD cpu definition11:08
jamespagebut its not AMD?11:08
cpaelzerG4 AMD ?11:08
cpaelzerwut11:08
jamespageyeah11:09
jamespagethat's what I said11:09
cpaelzerjamespage: I'm picke dup for lunch, back later11:10
cpaelzerjamespage: how much can you tune the cpu definitions?11:10
cpaelzerfor testing would you be fine dropping all these host-* things?11:11
cpaelzera "normal"  defautl cpu might do11:11
cpaelzerback later11:11
jamespagecpaelzer: ack - tbh this is not a priority right now - need to figure it out but its nearly christmas :-)11:15
jamespagecpaelzer: tbh I'm a bit baffled - libvirt and qemu are identitical to pike, where I've not seen this issue11:17
jamespageI guess its possible non of my hypervisors landed on a newer hardware machine11:17
jamespagecoreycb: good and bad news11:19
jamespagegood news is I have a oct profile that will configure a queens v3 cloud and tempest configuration11:20
jamespagebad news - https://bugs.launchpad.net/cloud-archive/+bug/173958511:20
ubottuLaunchpad bug 1739585 in Ubuntu Cloud Archive "L2 guest failed to boot under nested KVM: entry failed, hardware error 0x0" [Undecided,Incomplete]11:20
jamespageI found a bug!11:20
jamespage\o/11:20
=== nitemare is now known as t_robotham
cpaelzerhmm12:05
cpaelzerback with you and reading jamespage12:05
cpaelzerjamespage: I can't reproduce, maybe all my chips are just too old12:20
cpaelzerjamespage: I tried to add all the custom cpu magic, but that isn't (as expected) compatible with the cpus I have12:20
cpaelzerand with a smaller set it doesn't trigger12:20
cpaelzerjamespage: I updated the bug but wanted to ask how much you have control over what cpu definition openstack adds in these cases?12:21
=== Dmitrii-Sh is now known as Dmitrii-Sh-PTO
jamespagecpaelzer: I can tweak what the L2 hypervisors do, but not really the L1's13:44
cpaelzerhmm13:45
cpaelzerfor now that is the best I could recommend to try13:45
cpaelzertoo bad you can't normalize L1's13:45
cpaelzeras there will be the HW dependent part13:46
cpaelzerlikely L2 only carries things forward13:46
cpaelzerbut it looks broken enough that even only tweaking L2 might help13:46
jamespagecpaelzer: actually I'm not sure this is not a longstanding issue15:12
jamespagecpaelzer: I just think I tripped ont he same problem with a xenial/pike test15:12
jamespageyes indded i have15:13
cpaelzerok15:14
cpaelzerso less of a regression than we thougth15:14
cpaelzerbut still an issue that stalls/stops your tests15:14
cpaelzerany luck with trying to convince openstack not to try to define the custom cpu?15:14
ToAruShiroiNekoI am trying to follow https://www.ostechnix.com/install-and-configure-dns-server-ubuntu-16-04-lts/17:07
ToAruShiroiNekoI am a bit confused17:08
UssatMy first question would be, why do you want to run a DNS server ?17:11
ToAruShiroiNekoMy hostname provider does not provide dns as well17:19
ToAruShiroiNekoIt was quite shocking so I am trying to learn how to do this thing.17:19
ToAruShiroiNekobasically all the DNS server will do is to resolve two websites and its relevant subdomains17:20
rbasakThat tutorial doesn't really do what you want.17:24
rbasakAll the right pieces are there, but you need to understand which bits you want. It might be easier to find a more suited tutorial.17:25
ToAruShiroiNekoyes, it seems to be creating a local dns server17:25
rbasakYeah. For a LAN, with reverse DNS, and with the local machine configured to use its own service.17:26
rbasakNone of those things are relevant for an Internet DNS server to host a properly delegated name.17:26
rbasakIt's usually an error to point anything directly to a master DNS server, too.17:26
ToAruShiroiNekoright so do you have a tutorial or keyword in mind for me?17:27
ToAruShiroiNekoI am uncertain what I should seek :/17:27
metastableIt may be more helpful to find a DNS hosting service than to try to roll your own, as a misconfigured public-facing DNS server can be exploited to leverage attacks on others.17:29
rbasakDepnds on the goal.17:31
rbasakAs a learning experience, it's fine :)17:31
rbasakA misconfigured anything on the the Internet can be exploited.17:32
metastableA misconfigured DNS server especially so. Saying that it's as bad as anything else is a false equivalence.17:32
rbasakInstalling bind in Ubuntu should be safe on its default.17:33
rbasakAnd so should simply adding a zone.17:33
rbasakWhich I believe is all that is needed here.17:33
rbasakIf it is not safe by default, please file a security bug, and I'll be happy to look at it urgently.17:34
rbasakFollowing unsafe third party instructions (such as enabling forwarding) is not safe.17:35
sdezielToAruShiroiNeko: part 2 of the tutorial you referenced touches on how to setup a master server, that's probably a good starting point17:35
rbasakBut then that's sort of a tautology.17:35
rbasaksdeziel, ToAruShiroiNeko: it does, but it also conflates that with adding a reverse zone and pointing the server to its own master DNS server. The first is not necessary, and the second would be a misconfiguration in this case.17:36
UssatRunning a public facing DNS server correctly is not trivial, I would find a hosting service that will do it17:38
sdezielrbasak: ToAruShiroiNeko: yeah, I don't know why they are putting it as dns-nameservers in /etc/network/interfaces. It wouldn't work if only part 2 is followed17:39
UssatI would seriousely consider finding a service to do this17:39
Ussata mis-confgured public facing dns server is a huger target17:39
Ussathuge17:39
ToAruShiroiNekoAre there free providers for this where I can simply register a domain?17:41
ToAruShiroiNekoin the past I have only used godaddy17:41
UssatI dont know about free, but most are inexpensive17:41
metastableCloudFlare will host your DNS for free. You just need to change the nameservers at the domain's current registrar.17:41
Ussatthere ya go17:41
ToAruShiroiNekoI can do that, sure17:41
metastableDNS updates are also VERY, VERY quick. Seconds, in most cases.17:42
ToAruShiroiNekoyes but my goal was to run this for two domains only and forward everything else to a known one, if I can out source this for free, I will love to do that17:42
metastableCloudFlare will do what you want.17:43
ToAruShiroiNekoyup, creating and account etc17:43
metastableNote that CloudFlare does a lot more than just DNS, but I don't use any of those features.17:45
=== _ruben_ is now known as _ruben
=== Neo3 is now known as Neo1

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!