*** tosky has quit IRC | 00:28 | |
*** csmart has joined #openstack-ansible | 00:29 | |
*** prometheanfire has quit IRC | 00:44 | |
*** prometheanfire has joined #openstack-ansible | 00:45 | |
*** suryasingh has joined #openstack-ansible | 01:11 | |
*** karanveersingh56 has joined #openstack-ansible | 01:13 | |
*** MickyMan77 has quit IRC | 01:20 | |
*** cshen has quit IRC | 02:15 | |
*** karanveersingh56 has quit IRC | 03:01 | |
*** MickyMan77 has joined #openstack-ansible | 03:33 | |
*** MickyMan77 has quit IRC | 04:07 | |
*** MickyMan77 has joined #openstack-ansible | 04:40 | |
*** MickyMan77 has quit IRC | 05:06 | |
*** yasemind has joined #openstack-ansible | 05:11 | |
*** evrardjp has quit IRC | 05:33 | |
*** evrardjp has joined #openstack-ansible | 05:33 | |
*** NewJorg has quit IRC | 06:26 | |
*** NewJorg has joined #openstack-ansible | 06:33 | |
*** sshnaidm|off is now known as sshnaidm | 07:00 | |
*** sshnaidm is now known as sshnaidm|rover | 07:01 | |
noonedeadpunk | morning | 07:31 |
---|---|---|
pto | morning | 07:36 |
*** rpittau|afk is now known as rpittau | 07:57 | |
pto | I think there is still something wrong with federated identity in os_keystone i ussuri. Who can help to clarify if its a configuration issue or an actual bug? | 08:06 |
*** andrewbonney has joined #openstack-ansible | 08:16 | |
ebbex | mornin' | 08:23 |
*** cshen has joined #openstack-ansible | 08:25 | |
*** pto_ has joined #openstack-ansible | 08:53 | |
*** pto has quit IRC | 08:56 | |
pto_ | Anyone know when the SQL trigger idp_insert_read_only is dropped? | 09:04 |
*** pto_ is now known as pto | 09:05 | |
*** MickyMan77 has joined #openstack-ansible | 09:12 | |
*** fresta has joined #openstack-ansible | 09:18 | |
*** pto has quit IRC | 09:23 | |
*** pto has joined #openstack-ansible | 09:24 | |
noonedeadpunk | pto: I think #openstack-keystone folks are most competent here | 09:33 |
jrosser | morning | 10:23 |
openstackgerrit | Dmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible-os_swift master: Define condition for the first play host one time https://review.opendev.org/754428 | 10:26 |
noonedeadpunk | so, we're having ptg in 2.5 hours | 10:27 |
noonedeadpunk | we're having mitaka room https://www.openstack.org/ptg/rooms/mitaka | 10:36 |
jrosser | so we should unblock these lxc images then | 10:40 |
noonedeadpunk | I wasn't able to find what's wrong with centos | 10:42 |
noonedeadpunk | so we need to pick the chair... | 10:43 |
noonedeadpunk | ah 759229 ok) | 10:44 |
*** pto has quit IRC | 10:44 | |
*** pto has joined #openstack-ansible | 10:45 | |
noonedeadpunk | well, dib does exactly the same https://opendev.org/openstack/diskimage-builder/src/branch/master/diskimage_builder/elements/ubuntu/root.d/10-cache-ubuntu-tarball#L22 | 10:57 |
noonedeadpunk | except for centos they get qcow image o_O | 10:58 |
*** pto has quit IRC | 11:12 | |
*** pto has joined #openstack-ansible | 11:13 | |
openstackgerrit | Dmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible-rabbitmq_server master: Bump rabbitmq version https://review.opendev.org/759664 | 11:17 |
pto | noonedeadpunk: I tried multiple times in #openstack-keystone but the channel seems totally dead | 11:19 |
pto | noonedeadpunk: But i have isolated the issue to be a timing problem in the ansible play. commenting out part of the play, run the play and then commenting it in again, make it install successful | 11:20 |
jrosser | pto: my team are running openid federation here but we do not run into the same issue | 11:21 |
pto | jrosser: I have made a fresh install to two nodes, running the boiler plate example from tasks/default.yml and it breaks at Ensure external IDP - because the keystone tables have an trigger which rejects inserts. I cant quite figure out what makes migration trigger to be dropped. I think its the keystone-manage db_sync --contracts but its not always the case. | 11:23 |
jrosser | sure, i've seen your description of this | 11:23 |
pto | jrosser: Commenting out the import_tasks: keystone_federation_sp_idp_setup.yml and then run the os-keystone-install.yml makes it succeed, then commenting it in again and run os-keystone-install.yml again works | 11:24 |
jrosser | do you add keystone federation to the fresh install or do you add the keystone_sp config afterwards? | 11:24 |
*** tosky has joined #openstack-ansible | 11:25 | |
pto | jrosser: yes. Fresh installed Ubuntu 20.04 from MAAS, and then a fresh bootstraped ussiri/stable checkout (21.1.0 is broken). user_variables.yml: http://paste.openstack.org/show/799373/ | 11:26 |
jrosser | have you tried initially installing without the keystone_sp, then re-running os_keystone to add the federation after the initial deploy? | 11:28 |
jrosser | pto: what do you find broken with 21.1.0? | 11:28 |
pto | jrosser: Ubuntu 20.04 support in keystone (/etc/ansible/roles/os_keystone/vars/ubuntu-20.04.yml) unless its has been merged recently. | 11:29 |
jrosser | oh yes, the libcurl thing | 11:30 |
pto | jrosser: I think the keystone_federation_sp_idp_setup.yml should be run after https://github.com/openstack/openstack-ansible/blob/47e5a90a7fcc78adc44bbd0803e0faabb56197b6/playbooks/os-keystone-install.yml#L135 - or the idp_insert_read_only trigger (https://docs.openstack.org/keystone/ussuri/_modules/keystone/common/sql/expand_repo/versions/012_expand_add_domain_id_to_idp.html) will be active and the Ensure Exte | 11:31 |
pto | rnal IDP fail | 11:31 |
openstackgerrit | Dmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible-os_senlin master: Updated from OpenStack Ansible Tests https://review.opendev.org/752892 | 11:46 |
openstackgerrit | Dmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible-os_zun master: Add placement client to zun config file https://review.opendev.org/741494 | 11:47 |
*** rfolco has joined #openstack-ansible | 11:50 | |
*** gshippey has joined #openstack-ansible | 11:50 | |
*** persia_ is now known as persia | 11:52 | |
*** pfsmorigo has joined #openstack-ansible | 12:17 | |
gillesMo | Hello. Upgrading to Ussuri, Aodh DB migration fails with "Row size too large". I already see WARNINGs concerning some sizes due to TABLE FORMAT TYPE (Compact instead of Dynamic or Compressed). Is ther a specific task outside playbooks to run ? | 12:19 |
* noonedeadpunk never run aodh.... | 12:20 | |
pto | jrosser: Any suggestions on how to fix this? Cloud/should the keystone_federation_sp_idp_setup.yml be moved to after the db migration has been done? | 12:20 |
*** gillesMo has quit IRC | 12:20 | |
*** gillesMo has joined #openstack-ansible | 12:21 | |
openstackgerrit | Merged openstack/openstack-ansible-os_ironic master: Add iPXE support to Ironic Conductor https://review.opendev.org/736336 | 12:36 |
noonedeadpunk | uh, for stein we have circular dependency... | 12:41 |
openstackgerrit | Dmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible-tests stable/stein: Pin virtualenv<20 for python2 functional tests https://review.opendev.org/759308 | 12:43 |
openstackgerrit | Dmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible-tests stable/stein: Pin virtualenv<20 for python2 functional tests https://review.opendev.org/759308 | 12:45 |
openstackgerrit | Dmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible-tests stable/stein: Return bionic jobs to voting https://review.opendev.org/759676 | 12:45 |
openstackgerrit | Dmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible-tests stable/rocky: Pin virtualenv<20 for python2 functional tests https://review.opendev.org/759677 | 12:49 |
jrosser | pto: you can't move the tasks like that | 12:49 |
jrosser | they are all inside the os_keystone role and the db migrations are finalised in the playbook | 12:49 |
*** sshnaidm|rover has quit IRC | 12:50 | |
pto | jrosser: I am aware of that. Any suggestion on how to fix the issue then? | 12:51 |
pto | Rerun the role with a special flag? | 12:51 |
jrosser | imho this is an issue to do with the keystone db migrations, though i've not looked in any detail | 12:52 |
jrosser | like i suggested earlier you could do an initial deployment without federation then add it in afterwards with a second run of os_keystone | 12:52 |
jrosser | it is unfortunate that no-one is helping in the keystone irc channel | 12:53 |
dmsimard | jrosser, noonedeadpunk: just checking in, have you noticed playbooks getting stuck due to ara since friday ? | 12:59 |
noonedeadpunk | I'm not | 12:59 |
noonedeadpunk | seems pretty green | 12:59 |
dmsimard | great, thanks | 12:59 |
*** sshnaidm has joined #openstack-ansible | 12:59 | |
*** rh-jelabarre has joined #openstack-ansible | 13:00 | |
*** sshnaidm is now known as sshnaidm|rover | 13:00 | |
* noonedeadpunk feels a bit lonely | 13:00 | |
jamesden_ | hi | 13:05 |
*** jamesden_ is now known as jamesdenton | 13:05 | |
jamesdenton | noonedeadpunk is there a schedule for ptg? | 13:15 |
noonedeadpunk | it's right now) | 13:16 |
noonedeadpunk | https://www.openstack.org/ptg/rooms/mitaka | 13:17 |
jamesdenton | thank you | 13:17 |
pto | Is the file /etc/keystone/sso_callback_template.html supposed to be installed? | 13:21 |
*** dave-mccowan has joined #openstack-ansible | 13:22 | |
spotz | noonedeadpunk: I'll be there as soon as my meeting is over. Do we have an etherpad? | 13:25 |
noonedeadpunk | sure it's https://etherpad.opendev.org/p/osa-wallaby-ptg | 13:25 |
spotz | Thanks | 13:25 |
openstackgerrit | James Denton proposed openstack/openstack-ansible-os_tempest master: WIP - Allow deployer to skip default resource creation https://review.opendev.org/733892 | 13:29 |
openstackgerrit | James Denton proposed openstack/openstack-ansible-os_tempest master: WIP - Allow deployer to skip default resource creation https://review.opendev.org/733892 | 13:29 |
openstackgerrit | James Denton proposed openstack/openstack-ansible master: WIP - Create OSA-specific tempest resources https://review.opendev.org/733894 | 13:30 |
openstackgerrit | James Denton proposed openstack/openstack-ansible-os_tempest master: Allow deployer to skip default resource creation https://review.opendev.org/733892 | 13:30 |
openstackgerrit | James Denton proposed openstack/openstack-ansible master: Create OSA-specific tempest resources https://review.opendev.org/733894 | 13:30 |
gshippey | @pto, have a look at https://github.com/openstack/openstack-ansible-os_keystone/blob/2b125eca319271b9ad8fc700f5b5aba00dc09037/defaults/main.yml#L501, on your deploy host you need to create your sso_callback_template and set keystone_sso_callback_file_path to it. This is the example keystone give https://github.com/openstack/keystone/blob/master/etc/sso_callback_template.html - you can use that/modify/make | 13:30 |
gshippey | your own | 13:30 |
pto | gshippey: But the shouldnt it default if its not defined? | 13:33 |
*** spatel has joined #openstack-ansible | 13:39 | |
*** nurdie has joined #openstack-ansible | 13:40 | |
gshippey | https://github.com/openstack/openstack-ansible-os_keystone/commit/62d9f9c10d18fcf9e6a6b5b4039a1f3b54137c03 - this is the most recent relevant commit, might be possible to default it to the file in the keystone venv | 13:49 |
*** d34dh0r53 has joined #openstack-ansible | 13:51 | |
openstackgerrit | Dmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible-os_tempest master: Added tempest ironic resources setup. https://review.opendev.org/720705 | 14:04 |
*** strattao has joined #openstack-ansible | 14:12 | |
openstackgerrit | James Denton proposed openstack/openstack-ansible-os_neutron master: Implement uWSGI for neutron-api https://review.opendev.org/486156 | 14:23 |
*** macz_ has joined #openstack-ansible | 14:24 | |
openstackgerrit | Merged openstack/openstack-ansible-os_tempest master: Re-adding redhat-7.yml distro var https://review.opendev.org/758823 | 14:46 |
*** cshen has quit IRC | 15:00 | |
*** gyee has joined #openstack-ansible | 15:04 | |
noonedeadpunk | dmsimard: are you around | 15:32 |
dmsimard | I am | 15:32 |
noonedeadpunk | can you join us on https://www.openstack.org/ptg/rooms/mitaka ?:) | 15:33 |
dmsimard | uh oh, what did I break this time | 15:33 |
noonedeadpunk | no, nothing:) | 15:33 |
noonedeadpunk | just discussing ara for osa deployers | 15:33 |
dmsimard | joining in a sec | 15:33 |
dmsimard | it's because of the browser | 15:38 |
dmsimard | lemme install the app | 15:38 |
noonedeadpunk | ah.... | 15:38 |
noonedeadpunk | sorry:( | 15:38 |
*** munimeha1 has joined #openstack-ansible | 15:40 | |
gillesMo | During Train upgrade, the relase notes says that the placement API is moved from nova to a specific contener. But my inventory continues to have an entry for nova_api_plaement, and so haproxy is configured with a frontend/backend for it... | 15:49 |
* prometheanfire wonders if there's a timeline for victoria greenfield and/or upgrade (from ussuri) | 15:57 | |
* dmsimard uninstalls zoom app | 15:58 | |
prometheanfire | lol | 16:01 |
openstackgerrit | James Denton proposed openstack/ansible-role-systemd_networkd master: Add GPG Key for EPEL8 Repo https://review.opendev.org/759145 | 16:03 |
prometheanfire | oh, didn't know there was a networkd role now | 16:04 |
*** yolanda has quit IRC | 16:06 | |
jamesdenton | congrats! you are now moderator of networkd role | 16:06 |
mgariepy | lol | 16:22 |
prometheanfire | lol | 16:24 |
prometheanfire | sounds about right | 16:24 |
prometheanfire | I do push it at work though | 16:24 |
openstackgerrit | Merged openstack/openstack-ansible-os_senlin master: Use the utility host for db setup tasks https://review.opendev.org/756039 | 16:34 |
*** MickyMan77 has quit IRC | 16:44 | |
*** MickyMan77 has joined #openstack-ansible | 16:45 | |
*** MickyMan77 has quit IRC | 16:54 | |
*** rpittau is now known as rpittau|afk | 17:09 | |
*** tosky has quit IRC | 17:17 | |
*** MickyMan77 has joined #openstack-ansible | 17:27 | |
*** ThiagoCMC has joined #openstack-ansible | 17:29 | |
*** cshen has joined #openstack-ansible | 17:34 | |
*** MickyMan77 has quit IRC | 17:35 | |
*** recyclehero has quit IRC | 17:59 | |
*** recyclehero has joined #openstack-ansible | 18:10 | |
*** munimeha1 has quit IRC | 18:12 | |
*** cshen has quit IRC | 18:14 | |
*** cshen has joined #openstack-ansible | 18:27 | |
openstackgerrit | Merged openstack/openstack-ansible-os_senlin master: Updated from OpenStack Ansible Tests https://review.opendev.org/752892 | 18:31 |
*** MickyMan77 has joined #openstack-ansible | 18:31 | |
*** cshen has quit IRC | 18:45 | |
*** andrewbonney has quit IRC | 18:51 | |
*** recyclehero has quit IRC | 18:52 | |
*** cshen has joined #openstack-ansible | 18:53 | |
*** recyclehero has joined #openstack-ansible | 18:58 | |
*** MickyMan77 has quit IRC | 19:06 | |
*** recyclehero has quit IRC | 19:53 | |
openstackgerrit | James Denton proposed openstack/ansible-role-systemd_networkd master: Add GPG Key for EPEL8 Repo https://review.opendev.org/759145 | 19:53 |
*** spatel has quit IRC | 19:57 | |
*** MickyMan77 has joined #openstack-ansible | 20:02 | |
jrosser | jamesdenton: the neutron uwsgi patch looks close, they all fail similarly | 20:19 |
jrosser | https://zuul.opendev.org/t/openstack/build/f04fac2bc188470596e2e6552063854e/log/logs/host/neutron-l3-agent.service.journal-15-41-46.log.txt#69 | 20:20 |
jamesdenton | not bad for a 3 yr old patch | 20:21 |
jamesdenton | :D | 20:21 |
jamesdenton | i guess the service isn't starting | 20:22 |
*** MickyMan77 has quit IRC | 20:36 | |
*** tosky has joined #openstack-ansible | 20:43 | |
*** mmercer has quit IRC | 20:45 | |
*** melwitt has quit IRC | 20:45 | |
*** mmercer has joined #openstack-ansible | 20:45 | |
spotz | jrosser jamesdenton - Because I was in and out today did we cover the gerrit incident at all today? | 20:54 |
jamesdenton | i don't recall anything about it | 20:59 |
*** MickyMan77 has joined #openstack-ansible | 21:03 | |
*** cshen has quit IRC | 21:10 | |
jamesdenton | repo cloning in this aio... could've walked to starbucks and back and it still wouldn't be done | 21:10 |
*** cshen has joined #openstack-ansible | 21:10 | |
*** MickyMan77 has quit IRC | 21:11 | |
spotz | jamesdenton: ooh Starbucks.... I need to run down to SA in a few hadn't made it to the barn yet and it's gotten cold! Need to put a blanky on the pony! | 21:11 |
jamesdenton | where are you at? | 21:12 |
spotz | NB | 21:12 |
*** jralbert has joined #openstack-ansible | 21:13 | |
jralbert | Is it expected/intended that OSA applies the ansible-hardening role to metal hosts only, and not to containers? | 21:14 |
jamesdenton | the notes seem to imply only physical hosts | 21:21 |
jamesdenton | https://docs.openstack.org/openstack-ansible/latest/user/security/hardening.html | 21:21 |
jralbert | I'm curious about that. It seems to me that at least things like sshd hardening should be applied to every OSA-managed system, physical or container. I was surprised to discover the containers running default sshd configs | 21:25 |
jamesdenton | not sure what the thinking was there | 21:27 |
*** spatel has joined #openstack-ansible | 21:30 | |
jralbert | Do you think it would be appropriate to raise a bug on this? | 21:32 |
jamesdenton | wouldn't hurt. the channel is more lively in the AM, UTC | 21:36 |
spotz | jamesdenton: was it a major thing? | 21:43 |
*** spatel has quit IRC | 21:45 | |
jamesdenton | i know Major was a big contributor. Not sure who maintains it these days | 21:50 |
spotz | That I don't know, he just did a lot of the hardening I remember from reviewing them | 21:51 |
openstackgerrit | James Denton proposed openstack/ansible-role-systemd_networkd master: Add GPG Key for EPEL8 Repo https://review.opendev.org/759145 | 21:56 |
jralbert | Is that role not maintained anymore? | 21:59 |
*** aedc has joined #openstack-ansible | 22:15 | |
*** aedc has quit IRC | 22:15 | |
*** aedc has joined #openstack-ansible | 22:15 | |
*** cshen has quit IRC | 22:32 | |
jrosser | jralbert: it’s probably more accurate to say that no one has contributed updates to the ansible-hardening role for a while | 22:42 |
jrosser | the CI is kept functional though, so in that sense the role is maintained | 22:43 |
jrosser | jamesdenton: I have a patch to parallelise the git clone, was discussed earlier | 22:44 |
jrosser | would be interested to see if that works for you | 22:45 |
*** aedc has quit IRC | 23:05 | |
*** aedc has joined #openstack-ansible | 23:09 | |
*** gshippey has quit IRC | 23:10 | |
jamesdenton | jrosser please share when you have the chance. i do seem to recall this being discussed this morning, maybe? | 23:15 |
jrosser | jamesdenton: https://review.opendev.org/#/c/588372/ | 23:16 |
jrosser | really wants to be in an ansible collection nowadays | 23:16 |
jamesdenton | thank you. | 23:17 |
jamesdenton | it's late! | 23:17 |
jrosser | it is! | 23:18 |
*** cshen has joined #openstack-ansible | 23:28 | |
*** tosky has quit IRC | 23:28 | |
*** cshen has quit IRC | 23:33 | |
*** rh-jelabarre has quit IRC | 23:48 | |
*** jralbert has quit IRC | 23:56 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!