To access Designate/Zone/DNS endpoints, an api call needs to contact Keystone on a cloudcontrol for discovery, then Designate on a cloudservices node. Designate on the cloudservices node will, in turn, validate the token via Keystone back on the cloudcontrol nodes.
Something in that journey is a bit broken. Anytime I try a designate call on cloudcontrol2001-dev (behind cloudlb) I get:
root@cloudcontrol2001-dev:/var/log# openstack zone list --os-cloud novaadmin Failed to contact the endpoint at https://openstack.codfw1dev.wikimediacloud.org:29001 for discovery. Fallback to using that endpoint as the base url. Unknown
When I run the same command on cloudcontrol200[45]-dev, it works sometimes and times out sometimes:
root@cloudcontrol2004-dev:~# openstack zone list --os-cloud novaadmin root@cloudcontrol2005-dev:~# openstack zone list --os-cloud novaadmin timeout