Using generate_service_certificate and undercloud_public_vip in undercloud.conf breaks nova
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Compute (nova) |
Incomplete
|
Undecided
|
Unassigned | ||
Newton |
Incomplete
|
Undecided
|
Unassigned | ||
tripleo |
Invalid
|
Medium
|
Unassigned | ||
python-rfc3986 (Ubuntu) |
Fix Released
|
Medium
|
Unassigned | ||
Xenial |
Fix Released
|
Medium
|
Unassigned | ||
Yakkety |
Fix Released
|
Medium
|
Unassigned | ||
Zesty |
Fix Released
|
Medium
|
Unassigned |
Bug Description
Enabling SSL on the Undercloud using generate_
2016-10-11 22:28:27.327 66082 CRITICAL nova [req-b5f37af3-
2016-10-11 22:28:27.327 66082 ERROR nova Traceback (most recent call last):
2016-10-11 22:28:27.327 66082 ERROR nova File "/usr/bin/
2016-10-11 22:28:27.327 66082 ERROR nova sys.exit(main())
2016-10-11 22:28:27.327 66082 ERROR nova File "/usr/lib/
2016-10-11 22:28:27.327 66082 ERROR nova service.wait()
2016-10-11 22:28:27.327 66082 ERROR nova File "/usr/lib/
2016-10-11 22:28:27.327 66082 ERROR nova _launcher.wait()
2016-10-11 22:28:27.327 66082 ERROR nova File "/usr/lib/
2016-10-11 22:28:27.327 66082 ERROR nova status, signo = self._wait_
2016-10-11 22:28:27.327 66082 ERROR nova File "/usr/lib/
2016-10-11 22:28:27.327 66082 ERROR nova self.conf.
2016-10-11 22:28:27.327 66082 ERROR nova File "/usr/lib/
2016-10-11 22:28:27.327 66082 ERROR nova _sanitize(opt, getattr(group_attr, opt_name)))
2016-10-11 22:28:27.327 66082 ERROR nova File "/usr/lib/
2016-10-11 22:28:27.327 66082 ERROR nova return self._conf.
2016-10-11 22:28:27.327 66082 ERROR nova File "/usr/lib/
2016-10-11 22:28:27.327 66082 ERROR nova value = self._do_get(name, group, namespace)
2016-10-11 22:28:27.327 66082 ERROR nova File "/usr/lib/
2016-10-11 22:28:27.327 66082 ERROR nova % (opt.name, str(ve)))
2016-10-11 22:28:27.327 66082 ERROR nova ConfigFileValue
2016-10-11 22:28:27.327 66082 ERROR nova
I believe the failure happens inside the [neutron] section of /etc/nova/
This does not look related to the scheme (https) being used as the result of enabling SSL because doing a one-off test with the openstack-
Another one-off test substituting an IP address instead of a FQDN inside of nova.conf with the openstack-
Changed in tripleo: | |
milestone: | none → ocata-1 |
importance: | Undecided → Medium |
status: | New → Triaged |
Changed in nova (Ubuntu Yakkety): | |
status: | New → Incomplete |
status: | Incomplete → Triaged |
Changed in nova (Ubuntu Zesty): | |
status: | New → Triaged |
importance: | Undecided → Medium |
Changed in tripleo: | |
milestone: | ocata-1 → ocata-2 |
Changed in tripleo: | |
milestone: | ocata-2 → ocata-3 |
Additional information:
This may be caused by the combination of enabling SSL (generate_ service_ certificate= true) and using an FQDN for the Undercloud Public VIP (undercloud_ public_ vip=rdo- ci-fx2- 06-s5.v103. rdoci.lab. eng.rdu. redhat. com) in undercloud.conf.