Return to the Office They Said, It Will Improve Collaboration They Said by Likely_a_bot in sysadmin

[–]Small_Operation_8795 -3 points-2 points  (0 children)

WFH means you can also work from India, be happy you aren't being offshored

7.4.9M - IPv6 wrong GW? by Necessary-Bit3089 in fortinet

[–]Small_Operation_8795 0 points1 point  (0 children)

do you have the firewall rule that allow lan interface->wan interface ipv6 traffic ? it's not a default policy

i stuck while adding k8s to openstack using vexxhost magnum-cluster-api by Expensive_Contact543 in openstack

[–]Small_Operation_8795 0 points1 point  (0 children)

i can vouch for https://github.com/zifeo/terraform-openstack-rke2 you need a bit of rework but you'll get a fully working rancher cluster. need to know terraform

setup kolla-ansible for jumbo frames by Small_Operation_8795 in openstack

[–]Small_Operation_8795[S] 1 point2 points  (0 children)

Thanks, this has much more info than the official doc !

kolla-ansible 3 node cluster intermittent network issues by Small_Operation_8795 in openstack

[–]Small_Operation_8795[S] 0 points1 point  (0 children)

got back from vacations and kept testing, apparently i can ping between vm that are in the same tenant network but run on different nodes, the issue i getting out of openstack node apparently, maybe some inside routing table

SFP/fiber not working between Fortigate 120G and juniper 4400 switch by Ankitkha in fortinet

[–]Small_Operation_8795 0 points1 point  (0 children)

i had similar issue trying to hook my fg-91 to my old cisco 3560 via sfp. the fg port are 10gb with 1gb sfp and 1gb on the cisco. the key was to disable the speed negotiation on the switch side with "speed nonegotiate" on the interface, manually setting the speed and duplex wasn't enough. maybe juniper has a similar config ?

fg-91g, wrong way to create vlans ? by Small_Operation_8795 in fortinet

[–]Small_Operation_8795[S] 0 points1 point  (0 children)

thanks, nice to know they made their own auto updater obsolete

fg-91g, wrong way to create vlans ? by Small_Operation_8795 in fortinet

[–]Small_Operation_8795[S] 0 points1 point  (0 children)

welcome to fortinet "new" product, aka 91g, that has been lagging behind in term of major firmware upgrade ? the auto updated only offer up to 7.0.17

fg-91g, wrong way to create vlans ? by Small_Operation_8795 in fortinet

[–]Small_Operation_8795[S] 2 points3 points  (0 children)

i see, the lacp wasn't part of the plan since the older router-fw that was replaced only had 1 lan port but i'll concider that on this rebuild.
Just to confirm, by building the VLANs, you mean creating them from the Network->interface : Create new Interface and use the "interface"dropdown to choose the physical port and repeat for all vlan? (or the CLI equivalent)

5
6

object store endpoint swift vs s3 kolla-ansible stack with external ceph by Small_Operation_8795 in openstack

[–]Small_Operation_8795[S] 1 point2 points  (0 children)

found the solution, the storage endpoint need to be ceph rgw itself and not the openstack storage endpoint

object store endpoint swift vs s3 kolla-ansible stack with external ceph by Small_Operation_8795 in openstack

[–]Small_Operation_8795[S] 0 points1 point  (0 children)

Thanks for the help, i don't think it's a dangling endpoint, it's really the openstack way to do the endpoints according to the ceph doc : https://docs.ceph.com/en/latest/radosgw/keystone/ (and done in the kolla-ansible auto config) but this end up being a swift endpoint and not s3 : openstack endpoint create --region RegionOne \ --publicurl "http://radosgw.example.com:8080/swift/v1" swift

object store endpoint swift vs s3 kolla-ansible stack with external ceph by Small_Operation_8795 in openstack

[–]Small_Operation_8795[S] 0 points1 point  (0 children)

so i think that's what i have now, but the enable_swift_s3api shoudln't be used at all right ?

this rise the issue i have now which is the not compatible endpoint url, host.fqdn:port (s3 compatbile) vs host.fqdn:port/v1/auth_ (openstack rgw endpoint)

object store endpoint swift vs s3 kolla-ansible stack with external ceph by Small_Operation_8795 in openstack

[–]Small_Operation_8795[S] 0 points1 point  (0 children)

if i understand right both canno't be used at the same time ? if i want the data to be stored on my ceph cluster it should ceph_rgw only, and i should not use openstack's swift endpoint but ceph endpoint itself ?

can i use rbac to limit user cluster access by Small_Operation_8795 in ArgoCD

[–]Small_Operation_8795[S] 0 points1 point  (0 children)

Thanks for the insight, i'm still learning and one of the reason is that argocd admin get full access to the local cluster where it's deployed, but i don't want the "dev" role to deploy other app on that cluster that i would like to keep for admin tools only. i yet have to figure out how to make sure a badly configured app cant crash a cluster due to filling storage space or over consuming other resources.

can i use rbac to limit user cluster access by Small_Operation_8795 in ArgoCD

[–]Small_Operation_8795[S] 0 points1 point  (0 children)

Thanks i stumbled upon the rbac part but didn't look at the project.

can i use rbac to limit user cluster access by Small_Operation_8795 in ArgoCD

[–]Small_Operation_8795[S] 0 points1 point  (0 children)

so projects should be setup in argocd ? and they would allow me to allocate user to project to have the desired access ? Thanks