OpenStack status
by Pádraig Brady
Hi,
It's been about 3 weeks since the last status update, so here's the latest:
https://fedoraproject.org/wiki/OpenStack_status_report_2012-06-15
Historical archives are here:
http://fedoraproject.org/wiki/OpenStack_status_reports
Cheers,
Pádraig.
(appended below for convenience)
= Distro news =
Fedora 17 was released on May 29th containing the [http://fedoraproject.org/wiki/Features/OpenStack_Essex OpenStack Essex "Feature"]
Chris Wright discusses [http://www.youtube.com/watch?v=dmWdYJTsKbM#t=166s OpenStack in the Fedora 17 release video].
== openstack-nova ==
Nova updates for Fedora 16, 17, EPEL 6 and rawhide, were released for
a security issue where [https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-2654 security groups fail to be set correctly]
Nova packages now enable libguestfs image inspection,
which allows injection to more complex guest images.
This is supported by libguestfs updates to the inspection functionality.
== openstack-keystone ==
Derek Higgins identified and fixed important keystone security issues:
* [https://bugzilla.redhat.com/show_bug.cgi?id=824945 Tokens remain valid after a user account is disabled]
* [https://bugzilla.redhat.com/show_bug.cgi?id=824939 Tokens remain valid following a password compromise and subsequent password change]
* [https://bugzilla.redhat.com/show_bug.cgi?id=828794 Once a token is created/distributed its expiry date can be circumvented]
Alan Pevec backported these to the essex release and updated the packages
== novnc ==
novnc packages were finalized to support VNC from a browser to guests through the dashboard.<br/>
There were tested successfully by CERN who shared [https://fedoraproject.org/wiki/Getting_started_with_OpenStack_EPEL#VNC_ac... setup and testing notes]
Yong Sheng Gong from IBM also documented [https://www.ibm.com/developerworks/mydeveloperworks/blogs/e93514d3-c4f0-4... OpenStack VNC setups]
== OpenStack Folsom in rawhide ==
Fedora Rawhide has been mostly updated to the Folsom milestone 1 OpenStack release:
* [http://pkgs.fedoraproject.org/gitweb/?p=openstack-keystone.git;a=commit;h... keystone]
* [http://pkgs.fedoraproject.org/gitweb/?p=openstack-glance.git;a=commit;h=2... glance]
* [http://pkgs.fedoraproject.org/gitweb/?p=openstack-nova.git;a=commit;h=8d4... nova]
* [http://pkgs.fedoraproject.org/gitweb/?p=python-django-horizon.git;a=commi... horizon]
* [http://pkgs.fedoraproject.org/gitweb/?p=python-novaclient.git;a=commit;h=... python-novaclient]
Also there was a [https://fedoraproject.org/wiki/Features/OpenStack_Folsom Fedora 18 Folsom Feature page] prepared, summarizing the tasks for Folsom support
= OpenStack upstream news =
== Bug triaging day ==
About 20 people on and off, many from the Fedora community,
participated in the upstream OpenStack bug triaging day,
which yielded some [http://fnords.wordpress.com/2012/06/08/bug-triage-day-results/ very beneficial results]
== Fedora/RHEL/Centos docs ==
Anne Gentle wrote and guided through review a significant update to the
[http://docs.openstack.org/trunk/openstack-compute/install/yum/content/ Fedora/RHEL/Centos specific information] in the upstream docs:
== LVM backed guest images ==
GridDynamics after a dedicated review process,
commited [https://github.com/openstack/nova/commit/e0540df support for LVM backed guest images].
This significantly improves performance in their testing,
over guest images run from a standard file system.
As part of this they refactored the guest image handling code,
making it much more maintainable.
== Red Hat upstream work ==
There is too much to track in detail the OpenStack upstream activity of Red Hat developers,
but here is a link showing the [http://goo.gl/aewXr last 3 weeks of Red Hat OpenStack upstream development]
= Misc =
== OpenStack + OpenShift presentation ==
A recent presentation on the synergies of [http://www.slideshare.net/fallenpegasus/openshift-openstack-fedora-awesome OpenStack and OpenShift] was made available.
== CERN's plans for OpenStack ==
Tim Bell from CERN (who use Red Hat flavored systems) has presented [http://cern.ch/go/NH9w plans for running OpenStack on 15K systems] (running 300K VMs) by 2015.
11 years, 9 months
Cloud SIG Meeting Minutes :: 2012-06-15
by Robyn Bergeron
Minutes:
http://meetbot.fedoraproject.org/fedora-meeting/2012-06-15/cloud_sig.2012...
Logs:
http://meetbot.fedoraproject.org/fedora-meeting/2012-06-15/cloud_sig.2012...
==========================
#fedora-meeting: Cloud SIG
==========================
Meeting started by rbergeron at 19:00:13 UTC. The full logs are
available at
http://meetbot.fedoraproject.org/fedora-meeting/2012-06-15/cloud_sig.2012...
.
Meeting summary
---------------
* Roll Call, yo! (rbergeron, 19:00:28)
* gholms, tdawson, mdomsch, jzb, mrunge (if you're here for cloud, if
not, Hi!) present (rbergeron, 19:03:05)
* Features! Who's got em (rbergeron, 19:04:36)
* Feature submission deadline is 2012-07-24; Feature Freeze is
2012-08-07 (rbergeron, 19:05:31)
* Euca will be shooting for F18 (rbergeron, 19:05:58)
* hoping for CS as well. (rbergeron, 19:07:14)
* LINK: https://fedoraproject.org/wiki/Features/OpenShift_Origin
(rbergeron, 19:09:10)
* rubygem-passenger review stalled on licensing questions (gholms,
19:10:11)
* but OSO is still optimistic about F18 :) which is good! (rbergeron,
19:12:42)
* russellb mentions that pbrady has said that he was going to start
work on a folsom feature page for F18 (rbergeron, 19:14:57)
* Cloud SIG FAD (rbergeron, 19:16:19)
* Cloud Interop FAD is the idea - taking things like openstack,
eucalyptus, etc. that are in or going to be in fedora, and then also
things like plans to have openshift in fedora (rbergeron, 19:26:05)
* and then combining the two (rbergeron, 19:26:17)
* LINK:
http://docs.fedoraproject.org/en-US/Fedora_Draft_Documentation/0.1/html/C...
(rbergeron, 19:49:10)
* Open Floor (rbergeron, 19:52:52)
Meeting ended at 19:57:55 UTC.
Action Items
------------
Action Items, by person
-----------------------
* **UNASSIGNED**
* (none)
People Present (lines said)
---------------------------
* rbergeron (157)
* gholms (61)
* tdawson (24)
* jzb (13)
* ke4qqq (7)
* agrimm (6)
* russellb (4)
* zodbot (4)
* jsmith (3)
* mrunge (2)
* mdomsch (1)
* apevec (1)
Generated by `MeetBot`_ 0.1.4
.. _`MeetBot`: http://wiki.debian.org/MeetBot
11 years, 9 months
Cloud SIG meeting today! 3pm US Eastern, 12pm US Pacific
by Robyn Bergeron
Howdy,
Cloud SIG meeting today. Woohoo!
Agenda:
* Feature-land - who's doing them, what's the plan for everyone for F18?
* Cloud FAD - discussion / brainstorming / scope
* Anything else interesting :)
When: 1900 UTC (3pm US Eastern, 12pm US Pacific)
Where: #fedora-meeting on irc.freenode.net
See you later,
-Robyn
11 years, 9 months
Cloud-init on SLC6
by Tomas Karasek
Hi,
we are testing cloud-init rpm from
http://pbrady.fedorapeople.org/cloud-init-el6/
on Scientific Linux CERN 6 (SLC6) which is I think a derivate of EL6.
We're getting
2012-06-15 14:32:39,061 - __init__.py[WARNING]: Traceback (most recent call last):
File "/usr/lib/python2.6/site-packages/cloudinit/CloudConfig/__init__.py", line 118, in run_cc_modules
cc.handle(name, run_args, freq=freq)
File "/usr/lib/python2.6/site-packages/cloudinit/CloudConfig/__init__.py", line 71, in handle
mod = __import__("cc_" + name.replace("-", "_"), globals())
ImportError: No module named cc_config
during startup from
"cloud-init-cfg config all" executed from /etc/init.d/cloud-config.
Shouldn't it be the other way around - "cloud-init-cfg all config"?
Are the iniscripts for the rpm in version control somewhere?
Cheers,
Tomas
11 years, 9 months
glance-registry/selinux policy problem
by Joe Breu
Hi All,
Running through a Fedora/OpenStack deployment in our lab and ran into the following selinux policy violation:
type=AVC msg=audit(1339706457.635:1431): avc: denied { name_connect } for pid=31822 comm="glance-registry" dest=3306 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:mysqld_port_t:s0 tclass=tcp_socket
I have the following installed:
openstack-glance-2012.1-4.fc17.noarch
python-glance-2012.1-4.fc17.noarch
selinux-policy-targeted-3.10.0-130.fc17.noarch
selinux-policy-3.10.0-130.fc17.noarch
---
Joseph Breu
Deployment Engineer
Rackspace Cloud Builders
210-312-3508
11 years, 9 months
Networking issue with OpenStack on Fedora 17
by Tómas Edwardsson
Hi
I've gone through the install according to http://fedoraproject.org/wiki/Getting_started_with_OpenStack_on_Fedora_17.
I had to make the changes from the Getting Started manual to change from using kvm to qemu. I also had to disable SELinux because of glance issues (see previous e-mail). Third change I had to make was updating nova.conf with "scheduler_default_filters=AllHostsFilter", looks from some googling that this is needed for running qemu.
Now I was able to boot the f16-jeos image with the following command:
nova boot myserver --flavor 2 --key_name mykey --image $(glance index | grep f16-jeos | awk '{print $1}')
It is running and looks good:
[tommi@stack ~]$ nova list
+--------------------------------------+----------+--------+------------------+
| ID | Name | Status | Networks |
+--------------------------------------+----------+--------+------------------+
| d1e99d0e-d19a-4cfe-b300-a113b7ff5e64 | myserver | ACTIVE | demonet=10.0.0.2 |
+--------------------------------------+----------+--------+------------------+
But I am unable to ping it. tshark shows the following output:
[root@stack ~]# tshark -i any host 10.0.0.2
Running as user "root" and group "root". This could be dangerous.
Capturing on Pseudo-device that captures on all interfaces
0.000000 fe:16:3e:40:2d:5f -> ARP 44 Who has 10.0.0.2? Tell 10.0.0.1
0.000018 fe:16:3e:40:2d:5f -> ARP 44 Who has 10.0.0.2? Tell 10.0.0.1
1.001195 fe:16:3e:40:2d:5f -> ARP 44 Who has 10.0.0.2? Tell 10.0.0.1
1.001220 fe:16:3e:40:2d:5f -> ARP 44 Who has 10.0.0.2? Tell 10.0.0.1
2.003167 fe:16:3e:40:2d:5f -> ARP 44 Who has 10.0.0.2? Tell 10.0.0.1
2.003201 fe:16:3e:40:2d:5f -> ARP 44 Who has 10.0.0.2? Tell 10.0.0.1
I'm not sure if the bridge is correctly setup:
[root@stack ~]# brctl show
bridge name bridge id STP enabled interfaces
demonetbr0 8000.fe163e402d5f no vnet0
virbr0 8000.000000000000 yes
Any pointers?
---
Tommi
11 years, 9 months
Openstack on Fedora 17 - glance
by Tómas Edwardsson
Hi
I just registered to the mailing list so I can't reply directly to the emails that have been sent recently.
I had the same issue Michael reported with "glance index" and was able to fix it with running:
sudo setenforce 0
sudo systemctl restart openstack-glance-api.service
sudo systemctl restart openstack-glance-api.service
My Fedora 17 is fully yum updated.
Denials from the audit.log, has one AVC for nova_cert as well:
type=AVC msg=audit(1339505968.994:557): avc: denied { read } for pid=15519 comm="sh" name="passwd" dev="dm-1" ino=2624014 scontext=system_u:system_r:glance_api_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file
type=AVC msg=audit(1339505969.032:558): avc: denied { read } for pid=15521 comm="sh" name="passwd" dev="dm-1" ino=2624014 scontext=system_u:system_r:glance_api_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file
type=AVC msg=audit(1339505969.069:559): avc: denied { execute } for pid=15523 comm="glance-registry" name="bash" dev="dm-1" ino=1704915 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:shell_exec_t:s0 tclass=file
type=AVC msg=audit(1339505969.089:560): avc: denied { execute } for pid=15524 comm="glance-registry" name="bash" dev="dm-1" ino=1704915 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:shell_exec_t:s0 tclass=file
type=AVC msg=audit(1339505969.104:561): avc: denied { execute } for pid=15525 comm="glance-registry" name="bash" dev="dm-1" ino=1704915 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:shell_exec_t:s0 tclass=file
type=AVC msg=audit(1339505969.115:562): avc: denied { execute } for pid=15526 comm="glance-registry" name="bash" dev="dm-1" ino=1704915 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:shell_exec_t:s0 tclass=file
type=AVC msg=audit(1339506279.402:713): avc: denied { create } for pid=15607 comm="nova-cert" scontext=system_u:system_r:nova_cert_t:s0 tcontext=system_u:system_r:nova_cert_t:s0 tclass=netlink_route_socket
type=AVC msg=audit(1339506601.713:880): avc: denied { read } for pid=16556 comm="sh" name="passwd" dev="dm-1" ino=2624014 scontext=system_u:system_r:glance_api_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file
type=AVC msg=audit(1339506601.735:881): avc: denied { read } for pid=16558 comm="sh" name="passwd" dev="dm-1" ino=2624014 scontext=system_u:system_r:glance_api_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file
type=AVC msg=audit(1339506605.178:889): avc: denied { execute } for pid=16565 comm="glance-registry" name="bash" dev="dm-1" ino=1704915 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:shell_exec_t:s0 tclass=file
type=AVC msg=audit(1339506605.187:890): avc: denied { execute } for pid=16566 comm="glance-registry" name="bash" dev="dm-1" ino=1704915 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:shell_exec_t:s0 tclass=file
type=AVC msg=audit(1339506605.193:891): avc: denied { execute } for pid=16567 comm="glance-registry" name="bash" dev="dm-1" ino=1704915 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:shell_exec_t:s0 tclass=file
type=AVC msg=audit(1339506605.200:892): avc: denied { execute } for pid=16568 comm="glance-registry" name="bash" dev="dm-1" ino=1704915 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:shell_exec_t:s0 tclass=file
type=AVC msg=audit(1339506608.636:893): avc: denied { name_connect } for pid=16564 comm="glance-registry" dest=35357 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:ephemeral_port_t:s0 tclass=tcp_socket
type=AVC msg=audit(1339506617.091:894): avc: denied { name_connect } for pid=16564 comm="glance-registry" dest=35357 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:ephemeral_port_t:s0 tclass=tcp_socket
type=AVC msg=audit(1339506626.883:895): avc: denied { name_connect } for pid=16564 comm="glance-registry" dest=35357 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:ephemeral_port_t:s0 tclass=tcp_socket
type=AVC msg=audit(1339506657.957:906): avc: denied { name_connect } for pid=16564 comm="glance-registry" dest=35357 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:ephemeral_port_t:s0 tclass=tcp_socket
type=AVC msg=audit(1339506695.931:907): avc: denied { name_connect } for pid=16564 comm="glance-registry" dest=35357 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:ephemeral_port_t:s0 tclass=tcp_socket
type=AVC msg=audit(1339506721.340:908): avc: denied { name_connect } for pid=16564 comm="glance-registry" dest=35357 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:ephemeral_port_t:s0 tclass=tcp_socket
type=AVC msg=audit(1339506778.794:909): avc: denied { name_connect } for pid=16564 comm="glance-registry" dest=35357 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:ephemeral_port_t:s0 tclass=tcp_socket
type=AVC msg=audit(1339506866.469:910): avc: denied { name_connect } for pid=16564 comm="glance-registry" dest=35357 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:ephemeral_port_t:s0 tclass=tcp_socket
type=AVC msg=audit(1339508296.813:911): avc: denied { name_connect } for pid=16564 comm="glance-registry" dest=35357 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:ephemeral_port_t:s0 tclass=tcp_socket
type=AVC msg=audit(1339508311.498:912): avc: denied { name_connect } for pid=16564 comm="glance-registry" dest=35357 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:ephemeral_port_t:s0 tclass=tcp_socket
type=AVC msg=audit(1339508344.815:914): avc: denied { name_connect } for pid=16564 comm="glance-registry" dest=35357 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:ephemeral_port_t:s0 tclass=tcp_socket
type=AVC msg=audit(1339508350.803:922): avc: denied { execute } for pid=18118 comm="glance-registry" name="bash" dev="dm-1" ino=1704915 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:shell_exec_t:s0 tclass=file
type=AVC msg=audit(1339508350.803:922): avc: denied { read open } for pid=18118 comm="glance-registry" name="bash" dev="dm-1" ino=1704915 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:shell_exec_t:s0 tclass=file
type=AVC msg=audit(1339508350.803:922): avc: denied { execute_no_trans } for pid=18118 comm="glance-registry" path="/usr/bin/bash" dev="dm-1" ino=1704915 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:shell_exec_t:s0 tclass=file
type=AVC msg=audit(1339508350.811:923): avc: denied { getattr } for pid=18118 comm="sh" path="/usr/bin/bash" dev="dm-1" ino=1704915 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:shell_exec_t:s0 tclass=file
type=AVC msg=audit(1339508350.812:924): avc: denied { read } for pid=18118 comm="sh" name="passwd" dev="dm-1" ino=2624014 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file
type=AVC msg=audit(1339508350.812:924): avc: denied { open } for pid=18118 comm="sh" name="passwd" dev="dm-1" ino=2624014 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file
type=AVC msg=audit(1339508350.812:925): avc: denied { getattr } for pid=18118 comm="sh" path="/etc/passwd" dev="dm-1" ino=2624014 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file
type=AVC msg=audit(1339508350.815:926): avc: denied { execute } for pid=18119 comm="sh" name="ldconfig" dev="dm-1" ino=1704887 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:ldconfig_exec_t:s0 tclass=file
type=AVC msg=audit(1339508350.815:926): avc: denied { read open } for pid=18119 comm="sh" name="ldconfig" dev="dm-1" ino=1704887 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:ldconfig_exec_t:s0 tclass=file
type=AVC msg=audit(1339508350.815:926): avc: denied { execute_no_trans } for pid=18119 comm="sh" path="/usr/sbin/ldconfig" dev="dm-1" ino=1704887 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:ldconfig_exec_t:s0 tclass=file
type=AVC msg=audit(1339508355.898:927): avc: denied { name_connect } for pid=18117 comm="glance-registry" dest=35357 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:ephemeral_port_t:s0 tclass=tcp_socket
type=AVC msg=audit(1339508420.705:932): avc: denied { name_connect } for pid=16555 comm="glance-api" dest=80 scontext=system_u:system_r:glance_api_t:s0 tcontext=system_u:object_r:http_port_t:s0 tclass=tcp_socket
type=AVC msg=audit(1339509237.883:1033): avc: denied { name_connect } for pid=18117 comm="glance-registry" dest=35357 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:ephemeral_port_t:s0 tclass=tcp_socket
type=AVC msg=audit(1339509446.913:1094): avc: denied { name_connect } for pid=18117 comm="glance-registry" dest=35357 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:ephemeral_port_t:s0 tclass=tcp_socket
type=AVC msg=audit(1339509649.087:1228): avc: denied { name_connect } for pid=18117 comm="glance-registry" dest=35357 scontext=system_u:system_r:glance_registry_t:s0 tcontext=system_u:object_r:ephemeral_port_t:s0 tclass=tcp_socket
Run through "audit2allow -Mmyopenstack":
module myopenstack 1.0;
require {
type ldconfig_exec_t;
type glance_registry_t;
type passwd_file_t;
type glance_api_t;
type shell_exec_t;
type ephemeral_port_t;
type http_port_t;
type nova_cert_t;
class tcp_socket name_connect;
class file { execute read open getattr execute_no_trans };
class netlink_route_socket create;
}
#============= glance_api_t ==============
allow glance_api_t http_port_t:tcp_socket name_connect;
allow glance_api_t passwd_file_t:file read;
#============= glance_registry_t ==============
allow glance_registry_t ephemeral_port_t:tcp_socket name_connect;
allow glance_registry_t ldconfig_exec_t:file { read execute open execute_no_trans };
allow glance_registry_t passwd_file_t:file { read getattr open };
allow glance_registry_t shell_exec_t:file { read execute open getattr execute_no_trans };
#============= nova_cert_t ==============
allow nova_cert_t self:netlink_route_socket create;
---
Tomas Edwardsson
11 years, 9 months
Re: Openstack on Fedora 17
by Michael Adeyeye
On 06/08/2012 09:24 PM, Pádraig Brady wrote:
> On 06/08/2012 08:11 PM, Michael Adeyeye wrote:
>> I have error installing openstack on fedora 17. I can't run glance index. please see http://fpaste.org/JJYL/
> Hmm. Did the glance services start correctly?
>
> Is the output Ok from:
>
> for svc in api registry; do
> systemctl status openstack-glance-$svc.service
> done
Yes, it is, see http://fpaste.org/ADLn/
>
> There might be something informative in /var/log/glance/*.log
api.log - http://fpaste.org/MBYh/
registry.log - http://fpaste.org/cY97/; I can see some errors here. But
I can connect using glance as username and password via the terminal. I
don't why glance-registry is throwing an error here.
>
> There have been selinux updates recently which you may not have.
> Could you try after doing:
>
> yum install selinux-policy
>
> Or if that doesn't work, to eliminate selinux temporarily
>
> setenforce 0
I just did this; and glance index gives no response.
>
> I also notice errors from the openstack-db --init commands:
> ERROR 1396 (HY000) at line 2: Operation CREATE USER failed for 'glance'@'localhost'
> I've not seen that before, so I'll need to look into that at least.
the username glance already exist in the DB; that's why it prompted the
error.
>
> cheers,
> Pádraig.
11 years, 9 months