Bug 1403794

Summary: keystone can't connect on network isolation
Product: Red Hat OpenStack Reporter: Edu Alcaniz <ealcaniz>
Component: openstack-keystoneAssignee: John Dennis <jdennis>
Status: CLOSED WONTFIX QA Contact: nlevinki <nlevinki>
Severity: high Docs Contact:
Priority: high    
Version: 8.0 (Liberty)CC: ayoung, dhill, ealcaniz, eglynn, gekis, jdanjou, jdennis, jruzicka, mschuppe, nkinder, pablo.iranzo, panbalag, pbarta, pkilambi, srevivo
Target Milestone: asyncKeywords: ZStream
Target Release: 8.0 (Liberty)   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-03-20 19:40:00 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description Edu Alcaniz 2016-12-12 11:36:53 UTC
Description of problem:
We configured the ceilometer servers to query to internal URL but appear to connect to the externalURL. In the Logs we saw the line "ConnectionRefused: Unable to establish connection to https://server1/v2.0/tokens" that is the URL of the keystone external endpoint.
The memory of the servers grow until the openstack-ceilometer-api service die.

Version-Release number of selected component (if applicable):

No OSPd is used. only manual configuration.

How reproducible:


Steps to Reproduce:
1.
2.
3.

Actual results:
Customer can't connect with ceilometer with network isolation. 

Expected results:

Connect to Ceilometer with network isolation.
Additional info:

Comment 2 Edu Alcaniz 2016-12-12 11:39:40 UTC
KCS referred before (https://access.redhat.com/solutions/2750251), connection to the external (public_endpoint) IP being result of this. There is information that removing public_endpoint didn't resolve the issue

Comment 20 Julien Danjou 2017-01-24 10:24:01 UTC
So this really looks like 

When talking to Keystone on http://10.0.0.10:5000 it replies with a URL https://172.16.18.25:5000 in its header and body. Which really looks like bug https://bugzilla.redhat.com/show_bug.cgi?id=1311165

I'm reassigning to Keystone.