|
Posted
about 17 hours
ago
by
Julian Pistorius
Overview
Fixes Show unified limits when creating a server #1120 (closed).
feat(limits): constrain multi-create by unified limits
feat(limits): log custom resource config problems on first load
feat(quotas): granular detail on how compute quota is
... [More]
exceeded
feat(quotas): evaluate resize quotas based on resource delta <- Previously, instance quotas used a full instead of difference requirement.
feat(limits): evaluate resource limits per server flavour
feat(limits): add flavour spec alias to identify custom resource requirements
refactor: using string equalsCaseInsensitive helper
feat(limits): show quota usage above flavour picker on create & resize server
feat(limits): show limit exceeded warnings on flavour picker
How to Test
Background
Similar to !1125 (merged), it helps to work on a Jetstream2 project in a region with custom resource limits (like CCR190024_IU).
Ask an admin to set a project limit for a custom resource.
openstack limit create \
--service nova \
--project [Less]
|
|
Posted
about 17 hours
ago
by
Kyle Tee
Overview
Fixes Show unified limits when creating a server #1120 (closed).
feat(limits): constrain multi-create by unified limits
feat(limits): log custom resource config problems on first load
feat(quotas): granular detail on how compute quota is
... [More]
exceeded
feat(quotas): evaluate resize quotas based on resource delta <- Previously, instance quotas used a full instead of difference requirement.
feat(limits): evaluate resource limits per server flavour
feat(limits): add flavour spec alias to identify custom resource requirements
refactor: using string equalsCaseInsensitive helper
feat(limits): show quota usage above flavour picker on create & resize server
feat(limits): show limit exceeded warnings on flavour picker
How to Test
Background
Similar to !1125 (merged), it helps to work on a Jetstream2 project in a region with custom resource limits (like CCR190024_IU).
Ask an admin to set a project limit for a custom resource.
openstack limit create \
--service nova \
--project [Less]
|
|
Posted
about 17 hours
ago
by
Kyle Tee
Overview
Fixes Show unified limits when creating a server #1120 (closed).
feat(limits): constrain multi-create by unified limits
feat(limits): log custom resource config problems on first load
feat(quotas): granular detail on how compute quota is
... [More]
exceeded
feat(quotas): evaluate resize quotas based on resource delta <- Previously, instance quotas used a full instead of difference requirement.
feat(limits): evaluate resource limits per server flavour
feat(limits): add flavour spec alias to identify custom resource requirements
refactor: using string equalsCaseInsensitive helper
feat(limits): show quota usage above flavour picker on create & resize server
feat(limits): show limit exceeded warnings on flavour picker
How to Test
Background
Similar to !1125 (merged), it helps to work on a Jetstream2 project in a region with custom resource limits (like CCR190024_IU).
Ask an admin to set a project limit for a custom resource.
openstack limit create \
--service nova \
--project [Less]
|
|
Posted
about 17 hours
ago
by
Kyle Tee
Overview
Fixes: Improve Upload SSH Public Key form validation #1082.
e7e102cc feat: indicate whether ssh public key value looks valid
4b0e885e feat: validate ssh public key name character set
710902fa fix: emitting raw json errors from server
... [More]
create <- This is an item discovered during testing.
ff38319e fix: public key type nist naming
Also addresses a issue where server create request errors would log their json output. This is worth closing because it could include sensitive data for other failure modes.
How to Test
Create server error json message.
Open two tabs,
From the create instance page, select an ssh key to attach to the new instance.
From the ssh keys page, delete the key you selected.
Submit your create server request.
Expect a failure, but without raw json in the message.
Create ssh key
From the create ssh public key page:
Enter a name with invalid characters. Apostrophes, full stops, anything exotic should do.
Expect an invalid name form error.
Enter a body which is clearly not a public key.
Expect a warning.
Enter a private key.
Expect an error.
Enter a valid public key.
Expect some positive feedback from the form, probably identifying your key type.
Screenshots
Create server error logging fix
Before
After
Create ssh key
Invalid inputs
Warnings
Valid inputs
[Less]
|
|
Posted
about 17 hours
ago
by
Kyle Tee
Problem/Opportunity Statement
Unified limits for custom resources should be available when creating new instances so that users can understand their availability when picking flavours and to prevent surprise if resource limits would prevent an
... [More]
instance from being provisioned.
What would success / a fix look like?
Taken from parent issue #1110 (closed):
When creating a new instance, a user should only be able to select flavors that fit within their project's limits and usage. For example, if a project has a A100 limit of 4, and is currently using 3 out of 4 of this resource, they should only be able to select g3.xl (A100:1), but not g3.2xl (A100:2) or g3.4xl (A100:4). The other options should either be unselectable or not show up in the list at all.
Also when creating an instance, in the "How Many Instances?" field the user should not be able select an amount more than what their project's limit and usage supports.
Ideally the reason for why they cannot select a certain flavor or launch more than X number of instances should be clear to the user with the specific resource that is preventing them.
[Less]
|
|
Posted
about 17 hours
ago
by
Kyle Tee
Problem/Opportunity Statement
Openstack switched from from legacy quotas to Unified Limits a few years ago and Jetstream2 is following suite. Part of this switch enables putting limits on specific custom resources, such as GPUs. Jetstream2 plans
... [More]
to implement these limits for GPU resources soon.
These custom resources are as follows:
Resource Name
Associated Flavor(s)
Properties Alias
CUSTOM_A100X_10C
g3.medium
A100X_10C
CUSTOM_A100X_20C
g3.large
A100X_20C
CUSTOM_PCI_10DE_20B0
g3.*xl
A100
CUSTOM_PCI_10DE_26B9
g4.*
L40
CUSTOM_PCI_10DE_2330
g5.*
H100
The properties.pci_passthrough:alias field in the flavor details tells you what resource that flavor is associated with and how many of that resource the flavor consumes. For example, g3.2xl consumes 2 A100s, so it's value in this field is A100:2. The table above then tells us that the "Resource Name" associated with this property is CUSTOM_PCI_10DE_20B0
$ os flavor show g3.2xl -c properties -f json
{
"properties": {
"aggregate_instance_extra_specs:multigpu": "true",
"pci_passthrough:alias": "A100:2"
}
}
See references below for a discussion on the default limits as well as a more high-level discussion on the switch to Unified Limits on Jetstream2.
NOTE these are only the defaults; these can be altered on a per-project basis. Also we plan to set the limits associated with g3.medium and g3.large flavors to -1, or unlimited, so these won't need to be accounted for.
What would success / a fix look like?
When creating a new instance, a user should only be able to select flavors that fit within their project's limits and usage. For example, if a project has a A100 limit of 4, and is currently using 3 out of 4 of this resource, they should only be able to select g3.xl (A100:1), but not g3.2xl (A100:2) or g3.4xl (A100:4). The other options should either be unselectable or not show up in the list at all.
Also when creating an instance, in the "How Many Instances?" field the user should not be able select an amount more than what their project's limit and usage supports.
Ideally the reason for why they cannot select a certain flavor or launch more than X number of instances should be clear to the user with the specific resource that is preventing them.
Relevant non-unlimited (A100, L40S, and H100) limits and usage should be displayed under the instances, cores, and RAM limits already present on the instances page:
Reference
Parent issue tracking progress on Jetstream2 side: jetstream-cloud/jetstream2/project-management#342 (closed)
Discussion about default limits: jetstream-cloud/jetstream2/project-management#250 (comment 3272008388)
Openstack documentation on API routes for unified limits: https://docs.openstack.org/api-ref/identity/v3/#unified-limits
[Less]
|
|
Posted
about 17 hours
ago
by
Zach Graber
The latest commit addresses an issue with the ordering of the vncpasswd setup. This step (actually present upstream for other distros) runs before any VNC server packages are installed, so it wrongfully assumes that the vncpasswd binary is already present on the instance image.
|
|
Posted
3 days
ago
by
Kyle Tee
Overview
Fixes Show unified limits when creating a server #1120.
feat(limits): constrain multi-create by unified limits
feat(limits): log custom resource config problems on first load
feat(quotas): granular detail on how compute quota is exceeded
... [More]
feat(quotas): evaluate resize quotas based on resource delta <- Previously, instance quotas used a full instead of difference requirement.
feat(limits): evaluate resource limits per server flavour
feat(limits): add flavour spec alias to identify custom resource requirements
refactor: using string equalsCaseInsensitive helper
feat(limits): show quota usage above flavour picker on create & resize server
feat(limits): show limit exceeded warnings on flavour picker
How to Test
Background
Similar to !1125 (merged), it helps to work on a Jetstream2 project in a region with custom resource limits (like CCR190024_IU).
Ask an admin to set a project limit for a custom resource.
openstack limit create \
--service nova \
--project [Less]
|
|
Posted
3 days
ago
by
Kyle Tee
🙌 That's amazing, thanks for all those updates @JulianGonzalezR!
|
|
Posted
3 days
ago
by
Kyle Tee
Kyle Tee
(c10f6853)
at
28 Sep 15:08
Merge branch 'feature/create-server-unified-limits' into 'master'
... and
15 more commits
|