Bug 1403794 - keystone can't connect on network isolation
Summary: keystone can't connect on network isolation
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-keystone
Version: 8.0 (Liberty)
Hardware: x86_64
OS: Linux
high
high
Target Milestone: async
: 8.0 (Liberty)
Assignee: John Dennis
QA Contact: nlevinki
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-12-12 11:36 UTC by Edu Alcaniz
Modified: 2020-04-15 14:58 UTC (History)
15 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2017-03-20 19:40:00 UTC
Target Upstream Version:


Attachments (Terms of Use)

Description Edu Alcaniz 2016-12-12 11:36:53 UTC
Description of problem:
We configured the ceilometer servers to query to internal URL but appear to connect to the externalURL. In the Logs we saw the line "ConnectionRefused: Unable to establish connection to https://server1/v2.0/tokens" that is the URL of the keystone external endpoint.
The memory of the servers grow until the openstack-ceilometer-api service die.

Version-Release number of selected component (if applicable):

No OSPd is used. only manual configuration.

How reproducible:


Steps to Reproduce:
1.
2.
3.

Actual results:
Customer can't connect with ceilometer with network isolation. 

Expected results:

Connect to Ceilometer with network isolation.
Additional info:

Comment 2 Edu Alcaniz 2016-12-12 11:39:40 UTC
KCS referred before (https://access.redhat.com/solutions/2750251), connection to the external (public_endpoint) IP being result of this. There is information that removing public_endpoint didn't resolve the issue

Comment 20 Julien Danjou 2017-01-24 10:24:01 UTC
So this really looks like 

When talking to Keystone on http://10.0.0.10:5000 it replies with a URL https://172.16.18.25:5000 in its header and body. Which really looks like bug https://bugzilla.redhat.com/show_bug.cgi?id=1311165

I'm reassigning to Keystone.


Note You need to log in before you can comment on or make changes to this bug.