summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2018-10-19[swarm-mode] Remove --live-restore from Docker daemon optionsstable/ocataTobias Urdin
Ensure the --live-restore is not in the Docker daemon OPTIONS. Some images has this option by default which will cause the node not being able to perform it swarm init process. Change-Id: I287a5274143903fad5d4476e9d1640b26bdb46d4 Story: 2004095 Task: 27497 (cherry picked from commit 095b49e6f532f961854d8e0363e0f4aae01d189f) Notes (review): Code-Review+2: Spyros Trigazis <strigazi@gmail.com> Code-Review+1: Erik Olof Gunnar Andersson <eandersson@blizzard.com> Code-Review+1: Colin Gibbons <cgibbons@blizzard.com> Workflow+1: Spyros Trigazis <strigazi@gmail.com> Verified+2: Zuul Submitted-by: Zuul Submitted-at: Wed, 24 Oct 2018 21:26:07 +0000 Reviewed-on: https://review.openstack.org/611839 Project: openstack/magnum Branch: refs/heads/stable/ocata
2018-08-29import zuul job settings from project-configqingszhao
This is a mechanically generated patch to complete step 1 of moving the zuul job settings out of project-config and into each project repository. Because there will be a separate patch on each branch, the branch specifiers for branch-specific jobs have been removed. Because this patch is generated by a script, there may be some cosmetic changes to the layout of the YAML file(s) as the contents are normalized. See the python3-first goal document for details: https://governance.openstack.org/tc/goals/stein/python3-first.html Change-Id: I259cf2c1f6757a65c043ee45e01b260ac13be452 Story: #2002586 Task: #24308 Notes (review): Code-Review+1: Erik Olof Gunnar Andersson <eandersson@blizzard.com> Code-Review+1: Shu Muto <shu.mutow@gmail.com> Code-Review+2: yatin <ykarel@redhat.com> Workflow+1: Spyros Trigazis <strigazi@gmail.com> Verified+2: Zuul Submitted-by: Zuul Submitted-at: Fri, 31 Aug 2018 11:02:58 +0000 Reviewed-on: https://review.openstack.org/595467 Project: openstack/magnum Branch: refs/heads/stable/ocata
2018-04-25Stop using slave_scripts/install-distro-packages.shPaul Belanger
Migrate the legacy job to start using our bindep role from zuul-jobs. This will allow openstack-infra to delete slave_scripts/install-distro-packages.sh in the future. Change-Id: Ie3437d26fd6dfa884c86e18d69c1b1398d821dbe Signed-off-by: Paul Belanger <pabelanger@redhat.com> (cherry picked from commit 3d1ee579cb1af0272cae6c55b5cc455e3e1e6a37) Notes (review): Code-Review+2: Spyros Trigazis <strigazi@gmail.com> Workflow+1: Spyros Trigazis <strigazi@gmail.com> Verified+2: Zuul Submitted-by: Zuul Submitted-at: Wed, 02 May 2018 09:53:08 +0000 Reviewed-on: https://review.openstack.org/564297 Project: openstack/magnum Branch: refs/heads/stable/ocata
2018-01-28Zuul: Remove project nameJames E. Blair
Zuul no longer requires the project-name for in-repo configuration. Omitting it makes forking or renaming projects easier. Change-Id: I3ee0e9f148695ae089c732418f981503a29c1fbb Notes (review): Code-Review+2: yatin <ykarel@redhat.com> Code-Review+2: Spyros Trigazis (strigazi) <strigazi@gmail.com> Workflow+1: Spyros Trigazis (strigazi) <strigazi@gmail.com> Verified+2: Zuul Submitted-by: Zuul Submitted-at: Mon, 29 Jan 2018 19:33:17 +0000 Reviewed-on: https://review.openstack.org/538603 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-11-24Add required job definitionyatin
Job definition are also required to be added to stable branches. Change-Id: Iae381bee99301e9d3dc7342f0778851f2bd26faa Notes (review): Code-Review+2: Madhuri Kumari <madhuri.kumari@intel.com> Code-Review+2: Spyros Trigazis (strigazi) <strigazi@gmail.com> Workflow+1: Spyros Trigazis (strigazi) <strigazi@gmail.com> Verified+2: Zuul Submitted-by: Zuul Submitted-at: Fri, 24 Nov 2017 20:42:33 +0000 Reviewed-on: https://review.openstack.org/522821 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-10-26Add zuul v3 jobs in stable/ocatayatin
Change-Id: Id2212fd5cb9caee538664308540c75b7bdaddbbb (cherry picked from commit 839884593e6f6dabaebe401b013465c836fefc84) Notes (review): Code-Review+2: Spyros Trigazis (strigazi) <strigazi@gmail.com> Code-Review+1: Rico Lin <rico.lin@easystack.cn> Workflow+1: Spyros Trigazis (strigazi) <strigazi@gmail.com> Verified+2: Zuul Submitted-by: Zuul Submitted-at: Thu, 02 Nov 2017 13:26:51 +0000 Reviewed-on: https://review.openstack.org/515367 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-09-14Update CoreDNS to 0114.1.4Spyros Trigazis
Update CoreDNS to version 011 which includes a fix [0] for kubernetes srv and update the Corefile appropriately [1]. [0] https://github.com/coredns/coredns/pull/823 [1] https://github.com/coredns/deployment/blob/master/kubernetes/coredns.yaml.sed#L12 Closes-Bug: #1717238 (Cherry-picked from 68d7b87a0bd506ed1ed9b1e24a9eda3ec568b0ef) Change-Id: Ibeaa01578874335ddb70ac178ff708c6b953f129 Notes (review): Code-Review+2: yatin <ykarel@redhat.com> Code-Review+2: Madhuri Kumari <madhuri.kumari@intel.com> Workflow+1: Madhuri Kumari <madhuri.kumari@intel.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Fri, 15 Sep 2017 06:42:30 +0000 Reviewed-on: https://review.openstack.org/504063 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-08-28Merge "Add CoreDNS deployment in kubernetes atomic" into stable/ocataJenkins
2017-08-22Add kube dashboard and remove kube uiyatinkarel
kube-ui [2] is deprecated and not actively maintained since long time. Instead kubernetes dashboard [1] has lot of features and is actively managed. With this patch kube-ui is removed and kubernetes dashboard is added and enabled in k8s cluster by default. The kubernetes dashboard is enabled by default. To disable it, set the label 'kube_dashboard_enabled' to False Reference: [1] https://github.com/kubernetes/dashboard [2] https://github.com/kubernetes/kube-ui (cherry-pick from 44d102a65efa934ed7867673775163e7f67482eb) Change-Id: Ib4a6fcd08606dea70aae5b018c5e3c2dedcd2c6e Notes (review): Code-Review+2: Spyros Trigazis (strigazi) <strigazi@gmail.com> Code-Review+2: yatin <ykarel@redhat.com> Workflow+1: yatin <ykarel@redhat.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Tue, 22 Aug 2017 08:50:32 +0000 Reviewed-on: https://review.openstack.org/496064 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-08-17Don't poll heat if no stack existsMark Goddard
Cluster objects are created asynchronously from their underlying heat stacks, meaning that the periodic update can sometimes end up trying to poll a cluster's heat stack before the stack has been created. This change checks whether the stack_id is None and skips polling heat if so. This has the side effect of resolving bug 1682058, since we don't try to use a trust and trustee that do not exist. Change-Id: I73f039659250f1d5b69b23141835c4602c8e019a Closes-Bug: #1682058 (cherry picked from commit 88a6e3bab5f4af92ea4700580af05f5c20ab64f6) Notes (review): Code-Review+2: yatin <ykarel@redhat.com> Code-Review+1: Mark Goddard <mark@stackhpc.com> Code-Review+2: Madhuri Kumari <madhuri.kumari@intel.com> Workflow+1: Madhuri Kumari <madhuri.kumari@intel.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Sun, 20 Aug 2017 17:18:55 +0000 Reviewed-on: https://review.openstack.org/494688 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-08-01Merge "Copy cluster nodes logs always whether tests pass or fail" into ↵Jenkins
stable/ocata
2017-07-28Add CoreDNS deployment in kubernetes atomicRicardo Rocha
Enable internal cluster DNS by deploying CoreDNS in the kube-system namespace. It covers dns queries for both the cluster and external, acting as a proxy with a cache layer in front. Version of CoreDNS hard-coded to 007, image taken from dockerhub. Related-Bug: #1692449 Change-Id: I0a9703b531fe872416dcd79fa7d4d27c1ea61586 (cherry picked from commit 7c35c8fe40ec2b012696965e225d2b2d6ea0f6b1) Notes (review): Code-Review+2: Spyros Trigazis (strigazi) <strigazi@gmail.com> Code-Review+2: Madhuri Kumari <madhuri.kumari@intel.com> Workflow+1: Madhuri Kumari <madhuri.kumari@intel.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Mon, 28 Aug 2017 09:49:49 +0000 Reviewed-on: https://review.openstack.org/488577 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-07-26[k8s-fedora-atomic] fix multimaster clusterArchiFleKs
Same fix as CoreOS for Fedora which enable multimaster with TLS and ETCD Load balancer. Closes-Bug: #1679724 Change-Id: I45b62a20f0a89ebd1494ad61021384fc7a416e8e (cherry picked from commit 6ea4a7872d646e6def8c3a38c9e2182b7a23225a) Notes (review): Code-Review+2: Spyros Trigazis (strigazi) <strigazi@gmail.com> Workflow+1: Spyros Trigazis (strigazi) <strigazi@gmail.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Thu, 27 Jul 2017 08:09:27 +0000 Reviewed-on: https://review.openstack.org/487425 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-07-26Copy cluster nodes logs always whether tests pass or failyatin
- Use addOnCleanup instead of addOnException. This will make copy logs to run whether tests pass or fail. - Also try to copy logs if setupClass Fails. Change-Id: I76b135ade4c1ed4987f9bcbe1d5ded09ad57deb9 Notes (review): Code-Review+2: yatin <ykarel@redhat.com> Workflow+1: Spyros Trigazis (strigazi) <strigazi@gmail.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Tue, 01 Aug 2017 12:16:40 +0000 Reviewed-on: https://review.openstack.org/487404 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-07-25Use kubernetes service name in cert requestMathieu Velten
In kubernetes with atomic we have a set of certificates that we use in three places: 1. etcd 2. kubernetes apiserver 3. kubernetes service accounts In order to make service accounts work we need to set the common name properly in the certificates. Partial-Bug: #1705694 Change-Id: I04ed3bba938f0d5f340e2141be94058c38c2ed2b (cherry picked from commit a7ab475cd0917ffdeb1dd5ffa5a8a9a38f907b78) Notes (review): Code-Review+2: Spyros Trigazis (strigazi) <strigazi@gmail.com> Code-Review+2: yatin <ykarel@redhat.com> Workflow+1: yatin <ykarel@redhat.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Tue, 25 Jul 2017 18:23:34 +0000 Reviewed-on: https://review.openstack.org/486949 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-07-24Set k8s apiserver preferred address type argVijendar Komalla
Currently not able to run kubectl exec/logs commands with a k8s cluster created on devstack. This is due to the fact that apiserver is not able to resolve the worker node by hostname. This change fixes the issue by passing --kubelet-preferred-address-types argument to apiserver. Change-Id: I9d328626723d11372a6d912fae4edd33b8f01277 Closes-Bug: #1668337 (cherry picked from commit 396439f703aea8598a07adac6b562c714fa19113) Notes (review): Code-Review+2: Spyros Trigazis (strigazi) <strigazi@gmail.com> Code-Review+2: yatin <ykarel@redhat.com> Workflow+1: yatin <ykarel@redhat.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Mon, 24 Jul 2017 17:28:13 +0000 Reviewed-on: https://review.openstack.org/486634 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-07-19Add Kubernetes API Service IP to x509 certificates4.1.3ArchiFleKs
By default, API service with service account is accessible from inside the cluster at the address 10.254.0.1. This IP should be added to SANS when generating the certs. Fixes-bug: #1660811 Change-Id: I214b4296bea55bb0c4015165c56fbd8ca3cebd39 (cherry picked from commit 288bb34fe311041a911bba9d43dfb75176ee43cd) Notes (review): Code-Review+2: Spyros Trigazis (strigazi) <strigazi@gmail.com> Code-Review+2: yatin <ykarel@redhat.com> Workflow+1: yatin <ykarel@redhat.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Thu, 20 Jul 2017 18:17:29 +0000 Reviewed-on: https://review.openstack.org/485370 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-06-28Merge "Checkout stable/ocata branches when installing via devstack" into ↵Jenkins
stable/ocata
2017-06-16Checkout stable/ocata branches when installing via devstackyatin
Change-Id: Icc1b9c93ebbdffd99511ed82b560c0496bd6bdba Notes (review): Code-Review+2: Madhuri Kumari <madhuri.kumari@intel.com> Code-Review+2: Spyros Trigazis (strigazi) <strigazi@gmail.com> Workflow+1: Spyros Trigazis (strigazi) <strigazi@gmail.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Wed, 28 Jun 2017 10:46:15 +0000 Reviewed-on: https://review.openstack.org/472550 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-06-16Use lowercase keys for swarm waitcondition signalMark Goddard
The heat waitcondition signal API accepts status, reason, data and id fields in a JSON object supplied as POST data. Missing fields will be filled with defaults. Previously, the swarm script fragments used a capitalised form of these keys (Status, Reason, Data, Id) which was not being recognised by heat. This caused failures to not be reported. This change uses the correct lowercase names for these fields and also fixes some quoting and incorrect use of UUIDs provided as the id field. Change-Id: I9bfe36e5dd956280eaa42d1c3f1620c4ec27bc0c Closes-Bug: #1504059 Notes (review): Code-Review+2: Spyros Trigazis (strigazi) <strigazi@gmail.com> Code-Review+2: yatin <ykarel@redhat.com> Workflow+1: yatin <ykarel@redhat.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Sat, 17 Jun 2017 21:07:57 +0000 Reviewed-on: https://review.openstack.org/474972 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-06-15Pass a mutable target to oslo policy enforcerMark Goddard
Magnum API previously passed magnum.objects.cluster.Cluster objects as the target argument to magnum.common.policy.enforce(). However, enforce() expects target to be a mutable mapping, as it adds an entry for trustee_domain_id which is used by the magnum policy.json. This causes cluster detailed GET requests to fail with the following message: AttributeError: 'Cluster' object has no attribute 'trustee_domain_id' This change uses the as_dict() method of the magnum RPC objects to provide a mutable mapping to the policy enforcer. Change-Id: I54b136243afff9e0fadae3be4b36cad1679e5721 Closes-Bug: #1689797 (cherry picked from commit f1326626b94778dfd03e1ca76e61cbecb10495aa) Notes (review): Code-Review+2: Adrian Otto <aotto@aotto.com> Code-Review+2: yatin <ykarel@redhat.com> Workflow+1: yatin <ykarel@redhat.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Fri, 16 Jun 2017 04:01:21 +0000 Reviewed-on: https://review.openstack.org/474502 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-06-07Remove reliance on osprofiler configuration section4.1.2Corey O'Brien
Change-Id: I5b06afc0da936c1def04375e9990a20b5d53c3e2 Closes-Bug: 1667417 Depends-On: Ia2881f5c6b84993850f2642c7a7f240ce6ad3f73 Notes (review): Code-Review+2: Spyros Trigazis (strigazi) <strigazi@gmail.com> Code-Review+2: Adrian Otto <aotto@aotto.com> Workflow+1: Adrian Otto <aotto@aotto.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Wed, 07 Jun 2017 14:40:31 +0000 Reviewed-on: https://review.openstack.org/454812 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-05-25Fix rexray systemd unitMathieu Velten
* remove existing rexray containers in ExecStartPre * set volume tag to rshared * fix indentation Closes-Bug: #1686421 Change-Id: I71ffd708baac0403dae7d8f38a073240c44e0434 (cherry picked from commit ad94578a2f5d3dd7fb6bad57cc7c741227ed5c30) Notes (review): Code-Review+2: Spyros Trigazis (strigazi) <strigazi@gmail.com> Code-Review+2: yatin <ykarel@redhat.com> Workflow+1: yatin <ykarel@redhat.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Thu, 25 May 2017 14:42:50 +0000 Reviewed-on: https://review.openstack.org/467901 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-05-24Merge "Enable custom keystone endpoint_type in templates" into stable/ocataJenkins
2017-05-22Enable custom keystone endpoint_type in templatesKevin Lefevre
Allow to specify a custom AUTH_URL for the templates in case instances cannot reach internalURL which is the case in mose deployment. A new variable in trust section: trustee_keystone_interface which default to public is introduced. Change-Id: I2a908c0752387e4ff4ad2b0fdf0c1025a73ce806 Closes-Bug: #1643197 Notes (review): Code-Review+2: Spyros Trigazis (strigazi) <strigazi@gmail.com> Code-Review+2: yatin <ykarel@redhat.com> Workflow+1: yatin <ykarel@redhat.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Wed, 24 May 2017 13:43:42 +0000 Reviewed-on: https://review.openstack.org/463601 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-05-18Use 'virt_type=kvm' in devstack vm if supportedyatin
If the devstack vm supports nested virtualization we should use it. This can done using by setting: DEVSTACK_GATE_LIBVIRT_TYPE=kvm. This will increase the performance in gate jobs. Change-Id: I2439de036dfec2ada3c92c2d4b71c73b5f41a518 (cherry picked from commit 34efcdfcafad3108e54fd4351a414f3a74e1ef6f) Notes (review): Code-Review+2: Spyros Trigazis (strigazi) <strigazi@gmail.com> Workflow+1: Spyros Trigazis (strigazi) <strigazi@gmail.com> Code-Review+1: ShangXiao <shangxiaobj@inspur.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Fri, 19 May 2017 08:21:38 +0000 Reviewed-on: https://review.openstack.org/465796 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-05-15Fix keystone auth_uri and auth_urlyatin
Post [1] we cannot use auth_uri/auth_url containing :5000, :35357. Update keystone auth_uri and auth_url in magnum.conf to connect with keystone using /identity/v3 and /identity_admin/v3. [1] https://review.openstack.org/#/c/456344/ Change-Id: I5d69e7454cf8a5e8c92ff23b6c932184d82e8a98 devstack: Allow access to ports 80 and 443 So far, we were allowing access to port 5000 for keystone. When devstack siwtched to uwsgi we couldn't access keystone anymore. Co-Authored-By: Spyros Trigazis <strigazi@gmail.com> Change-Id: I4d3d482889fd9f6119ceec81757abac9d1251a97 (cherry picked from commit 530d225fcd154eef89e3fc2189898e23a7bc9e14) Notes (review): Code-Review+2: Adrian Otto <aotto@aotto.com> Code-Review+2: Spyros Trigazis (strigazi) <strigazi@gmail.com> Workflow+1: Spyros Trigazis (strigazi) <strigazi@gmail.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Mon, 15 May 2017 20:38:46 +0000 Reviewed-on: https://review.openstack.org/464328 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-05-12Pass 'client', 'message' param to AuthorizationFailure Exceptionyatinkarel
Change-Id: Ia3f39a0362259429f4d2d995e94073a993ae48a7 Closes-Bug: #1666790 (cherry picked from commit 44b83d3b142e84b14c5fda3ede76e6210a22b422) Notes (review): Code-Review+2: yatin <ykarel@redhat.com> Code-Review+2: Eli Qiao <qiaoliyong@gmail.com> Workflow+1: Eli Qiao <qiaoliyong@gmail.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Mon, 15 May 2017 06:54:36 +0000 Reviewed-on: https://review.openstack.org/464187 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-05-09Fix usage of the trustee user in K8S Cinder pluginMathieu Velten
Closes-Bug: #1672667 Change-Id: I702818777ea4664ecd560c4b7a02431c86988e17 Notes (review): Code-Review+2: Spyros Trigazis <strigazi@gmail.com> Code-Review+1: Kevin Lefevre <lefevre.kevin@gmail.com> Code-Review+2: Ton Ngo <ton@us.ibm.com> Workflow+1: Ton Ngo <ton@us.ibm.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Wed, 10 May 2017 04:28:08 +0000 Reviewed-on: https://review.openstack.org/456501 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-05-05Merge "Add net creating in install-guide" into stable/ocataJenkins
2017-05-05Merge "Set clustertemplate:publish to admin only" into stable/ocataJenkins
2017-05-04Set clustertemplate:publish to admin onlyRicardo Rocha
Set the clustertemplate:publish policy to be admin only by default - currently it is admin_or_user, which means any openstack user can create a public cluster template. Update tests for bay model and cluster template, splitting tests requiring admin credentials into a separate class. Change-Id: I0bfb57c569863f1ecf7d697cd5ac161a9a710432 Closes-Bug: #1687887 (cherry picked from commit 12052b1253782655397a26b1c50a0a2b7b539eaa) Notes (review): Code-Review+2: yatin <ykarel@redhat.com> Code-Review+2: Spyros Trigazis <strigazi@gmail.com> Workflow+1: Spyros Trigazis <strigazi@gmail.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Fri, 05 May 2017 08:34:03 +0000 Reviewed-on: https://review.openstack.org/462728 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-05-02Add net creating in install-guidecoldmoment
The launch-instance.rst has no instruction for external net creating. Change-Id: I31b2e9092d936ceeb2e7e4f6b17cc5fc392677d0 Notes (review): Code-Review+2: Madhuri Kumari <madhuri.kumari@intel.com> Code-Review+2: Spyros Trigazis <strigazi@gmail.com> Workflow+1: Spyros Trigazis <strigazi@gmail.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Fri, 05 May 2017 08:34:10 +0000 Reviewed-on: https://review.openstack.org/461655 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-05-01Fix config type of copy_logs from string to BooleanChandan Kumar
* As per the default value of copy_logs is Boolean but config type is defined as string, It needs to be fixed other wise tempest init will throw warning. Change-Id: I9abf0c989e707b879c160d4df14546dd87c16f95 Closes-Bug: #1685797 (cherry picked from commit 32b468f7e11b674c36256e30f23e5fd317f5bfe8) Notes (review): Code-Review+2: yatin <ykarel@redhat.com> Code-Review+2: Madhuri Kumari <madhuri.kumari@intel.com> Workflow+1: Madhuri Kumari <madhuri.kumari@intel.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Thu, 04 May 2017 13:28:51 +0000 Reviewed-on: https://review.openstack.org/461430 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-04-12Update Fedora images4.1.1Spyros Trigazis
New release of Fedora Atomic [1]. The new release of Fedora Ironic includes the same packages. Main changes: Kubernetes 1.5.3 etcd 3.1.3 Plus several fixes and version bumps. Add :Z when mounting certs in the swarm containers to set selinux labels properly. [1] http://www.projectatomic.io/blog/2017/03/fedora_atomic_mar28/ (cherry picked from 706371f380f52f96e920f50595b0632bf59b2ef7) Change-Id: Ia2881f5c6b84993850f2642c7a7f240ce6ad3f73 Closes-Bug: #1677664 Notes (review): Code-Review+2: yatin <ykarel@redhat.com> Code-Review+1: Corey O'Brien <coreypobrien@gmail.com> Code-Review+2: Ton Ngo <ton@us.ibm.com> Workflow+1: Ton Ngo <ton@us.ibm.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Tue, 25 Apr 2017 19:55:58 +0000 Reviewed-on: https://review.openstack.org/452102 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-04-05Install client in install guide instructionsColleen Murphy
The python-magnumclient package is not automatically installed with the other magnum packages, and it is needed later in the "Verify operation" and "Launch an instance" sections of the install guide, so this patch adds it to the package installation instructions. Change-Id: I12e1fd587f5327ee5404596b1d8b92dc5f770a93 (cherry picked from commit 7a356f5c9ef21466abb386e10bd2282f521ba2be) Notes (review): Code-Review+2: Spyros Trigazis <strigazi@gmail.com> Code-Review+2: Eli Qiao <qiaoliyong@gmail.com> Workflow+1: Eli Qiao <qiaoliyong@gmail.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Thu, 06 Apr 2017 01:09:44 +0000 Reviewed-on: https://review.openstack.org/453545 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-03-29Add reno for cluster_user_trust optionSpyros Trigazis
Add release notes for the new configuration parameter cluster_user_trust which was introduced in the fix for CVE-2016-7404. (cherry picked from commit 4d4e98157ecf9b880ef409f2256eca2d0466f40b) Change-Id: Ia59bd3ec543f6e9b53ddb4c107d6a44d198eb9d7 Related-Bug: #1620536 Notes (review): Code-Review+1: Vijendar Komalla <vijendar.komalla@rackspace.com> Code-Review+2: yatin <yatin.karel@nectechnologies.in> Code-Review+2: Madhuri Kumari <madhuri.kumari@intel.com> Workflow+1: Madhuri Kumari <madhuri.kumari@intel.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Thu, 30 Mar 2017 11:50:27 +0000 Reviewed-on: https://review.openstack.org/450697 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-03-10Pass 'context' to create_client_files methodyatinkarel
Change-Id: Ib45dbd4e48f840edf9497aa98ca87e0ffd89e17f Closes-Bug: #1670306 Notes (review): Code-Review+2: Eli Qiao <qiaoliyong@gmail.com> Code-Review+2: Ton Ngo <ton@us.ibm.com> Code-Review+1: Vijendar Komalla <vijendar.komalla@rackspace.com> Workflow+1: yatin <yatin.karel@nectechnologies.in> Code-Review+2: Spyros Trigazis <strigazi@gmail.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Thu, 16 Mar 2017 14:30:52 +0000 Reviewed-on: https://review.openstack.org/444149 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-02-27Merge "Pin images for ocata" into stable/ocataJenkins
2017-02-27Pin images for ocataSpyros Trigazis
Ping images in documentation and CI tests in specific version for the ocata branch. Change-Id: Ifc13e210c1dd6225e9534340356bed3c5beee0e7 Notes (review): Code-Review+1: Yan Zhiwei <yan.zhiwei1@zte.com.cn> Code-Review+2: yatin <yatin.karel@nectechnologies.in> Code-Review+2: Adrian Otto <adrian.otto@rackspace.com> Workflow+1: Adrian Otto <adrian.otto@rackspace.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Mon, 27 Feb 2017 19:43:47 +0000 Reviewed-on: https://review.openstack.org/438279 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-02-26Missing root-ca-file parameter for proper service account supportMathieu Velten
Change-Id: I8d581b1fbffdb4b8bc64457da6faae6d45dfc594 Closes-Bug: 1666599 Notes (review): Code-Review+2: yatin <yatin.karel@nectechnologies.in> Code-Review+2: Spyros Trigazis <strigazi@gmail.com> Workflow+1: Spyros Trigazis <strigazi@gmail.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Mon, 27 Feb 2017 10:31:12 +0000 Reviewed-on: https://review.openstack.org/436559 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-02-24Fix mesos gateSpyros Trigazis
Use DEVSTACK_LOCAL_CONFIG istead of localrc to pass MAGNUM_IMAGE_URL. Change-Id: I5b18ff84b532483c166fc92bf4c84e4e7dbd23bb Notes (review): Code-Review+2: yatin <yatin.karel@nectechnologies.in> Workflow+1: yatin <yatin.karel@nectechnologies.in> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Sat, 25 Feb 2017 06:24:44 +0000 Reviewed-on: https://review.openstack.org/438019 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-02-22Fix CVE-2016-7404Johannes Grassler
This commit addresses multiple potential vulnerabilities in Magnum. It makes the following changes: * Permissions for /etc/sysconfig/heat-params inside Magnum created instances are tightened to 0600 (used to be 0755). * Certificate retrieval is modified to work without the need for a Keystone trust. * The cluster's Keystone trust id is only passed into instances for clusters where that is actually needed. This prevents the trustee user from consuming the trust in cases where it is not needed. * The configuration setting trust/cluster_user_trust (False by default) is introduced. It needs to be explicitely enabled by the cloud operator to allow clusters that need the trust_id to be passed into instances to work. Without this setting, attempts to create such clusters will fail. Please note, that none of these changes apply to existing clusters. They will have to be deleted and rebuilt to benefit from these changes. (cherry picked from commit e93d82e8b3bc19211efd54edc17aebdca50670c1) Change-Id: I643d408cde0d6e30812cf6429fb7118184793400 Notes (review): Code-Review+2: Spyros Trigazis <strigazi@gmail.com> Code-Review+2: Adrian Otto <adrian.otto@rackspace.com> Workflow+1: Adrian Otto <adrian.otto@rackspace.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Wed, 22 Feb 2017 20:58:24 +0000 Reviewed-on: https://review.openstack.org/437051 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-02-17Update UPPER_CONSTRAINTS_FILE for stable/ocataOpenStack Release Bot
Change-Id: I124670a3f141b7fd691f111d71d57467a6f82909 Notes (review): Code-Review+2: Spyros Trigazis <strigazi@gmail.com> Workflow+1: Spyros Trigazis <strigazi@gmail.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Sun, 19 Feb 2017 18:44:50 +0000 Reviewed-on: https://review.openstack.org/435592 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-02-17Update .gitreview for stable/ocataOpenStack Release Bot
Change-Id: Ieccd4ae695760f0b7f09c6c628fa577767e8ecaa Notes (review): Code-Review+2: Spyros Trigazis <strigazi@gmail.com> Workflow+1: Spyros Trigazis <strigazi@gmail.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Sun, 19 Feb 2017 18:44:32 +0000 Reviewed-on: https://review.openstack.org/435591 Project: openstack/magnum Branch: refs/heads/stable/ocata
2017-02-16Fix some typos4.1.0yuhui_inspur
Change-Id: Ic68dcbb8c2d850b3b42c73db8774637068c94645 Notes (review): Code-Review+2: yatin <yatin.karel@nectechnologies.in> Code-Review+2: Madhuri Kumari <madhuri.kumari@intel.com> Workflow+1: Madhuri Kumari <madhuri.kumari@intel.com> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Thu, 16 Feb 2017 14:16:48 +0000 Reviewed-on: https://review.openstack.org/434722 Project: openstack/magnum Branch: refs/heads/master
2017-02-15Fix for cluster-update rollback issueVijendar Komalla
Currently cluster-update is rolling back in case of update failure irrespective of whether the rollback flag set to True or False. This change fixes the issue by setting the right parameter type in cluster patch method. Change-Id: I6c28c583e7e3b98622634ac2381513b442eb57b6 Closes-Bug: #1664781 Notes (review): Code-Review+2: Adrian Otto <adrian.otto@rackspace.com> Code-Review+2: yatin <yatin.karel@nectechnologies.in> Workflow+1: yatin <yatin.karel@nectechnologies.in> Verified+2: Jenkins Submitted-by: Jenkins Submitted-at: Thu, 16 Feb 2017 05:19:42 +0000 Reviewed-on: https://review.openstack.org/434403 Project: openstack/magnum Branch: refs/heads/master
2017-02-15Merge "Add keypair to api-ref cluster create"Jenkins
2017-02-15Merge "Support magnum-api multiple process workers"Jenkins
2017-02-15Merge "Remove support for py34"Jenkins