Tuesday, 2021-01-19

*** tosky has quit IRC00:02
*** maharg101 has joined #openstack-ansible00:15
*** maharg101 has quit IRC00:19
*** gshippey has quit IRC00:24
*** rh-jelabarre has quit IRC00:52
openstackgerritMerged openstack/openstack-ansible stable/train: Bump SHAs for stable/train  https://review.opendev.org/c/openstack/openstack-ansible/+/77114701:05
openstackgerritMerged openstack/openstack-ansible master: Restrict zun thread/process count for AIO deployments  https://review.opendev.org/c/openstack/openstack-ansible/+/77027401:49
*** maharg101 has joined #openstack-ansible02:15
*** maharg101 has quit IRC02:21
*** jhesketh_ has joined #openstack-ansible03:40
*** jhesketh has quit IRC03:41
*** jhesketh_ is now known as jhesketh03:43
*** maharg101 has joined #openstack-ansible04:17
*** maharg101 has quit IRC04:21
*** evrardjp has quit IRC05:33
*** evrardjp has joined #openstack-ansible05:33
*** partlycloudy has quit IRC06:08
*** partlycloudy has joined #openstack-ansible06:12
*** maharg101 has joined #openstack-ansible06:17
*** maharg101 has quit IRC06:22
*** pto has joined #openstack-ansible07:16
*** pto has quit IRC07:19
*** pto has joined #openstack-ansible07:19
*** macz_ has joined #openstack-ansible07:22
*** miloa has joined #openstack-ansible07:24
*** macz_ has quit IRC07:27
*** miloa has quit IRC07:31
*** miloa has joined #openstack-ansible07:31
*** MickyMan77 has joined #openstack-ansible07:59
*** rpittau|afk is now known as rpittau08:07
CeeMacadmin0: morning.  Did you get anywhere with fleio?  I've got billing systems on my list of things to look at08:13
*** andrewbonney has joined #openstack-ansible08:13
*** maharg101 has joined #openstack-ansible08:18
*** miloa has quit IRC08:22
*** maharg101 has quit IRC08:23
*** maharg101 has joined #openstack-ansible08:31
*** miloa has joined #openstack-ansible08:36
*** tosky has joined #openstack-ansible08:39
jrossermorning08:46
jrosserinteresting in the venv build log Skipping link: unsupported archive format: .04-x86_64: /var/www/repo/os-releases/22.0.0.0rc2.dev13/ubuntu-20.04-x86_64/08:52
taccomorning everyone.08:54
taccoshort question. Anyone knows if there are any bugs left if i have a LB/Proxy in place before the API-Services and LB is doing ssl-offloading but backend don't get it that we are using ssl and gives back a self URL for http instead? endpoints configured properly but some of the openstackSDK modules seems to use the selfurl like designate for listing all recordsets.08:56
taccoand yes the required x-forwarded-proto is set.08:56
jrossertacco: it is not unusal for there to be bugs in openstack services regarding endpoint handling08:59
jrosserit is quite inconsistent between services08:59
jrosserdo you have an example?09:03
taccoi've tested with designate recordset list in sdk. or in general if i curl to the endpoint it gives me a http link instead of https as self url.09:29
taccothis http://paste.openstack.org/show/801718/09:29
taccofor the part of the affected module/request in sdk i can give you a example later on.09:30
jrosserthose really are bugs that should be raised against sdk/designate i would think09:32
jrosserodyssey4me: have you tried to install rally with the new pip resolver?09:32
taccojrosser: ok will do so.09:36
taccobut the case that i call the api endpoind and it gives me back a self url with http instead of https is a general issue i gues.. but in only creates pain with the sdk on designate. not sure why this is the only place where the self url is used. :D09:37
taccothats why i tought it could be a general setup issue09:37
taccoand it was deployed by osa thats why i initialy asked here. if someone already had the same issue here is my place to ask :D09:38
taccoanyway if you still think it is sdk/designate generic i can still ask in sdk/designate channels or bug-tracker09:39
jrosserthe haproxy on openstack-ansible terminates the ssl and hands the request off to designate09:49
jrosserthe reply content comes from designate, not the loadbalancer09:49
jrosserreally the sdk should probably be using the service catalog instead, that may be the root cause09:50
taccook i see. thanks. :) Yes would also prefer if it uses the baseURL from endpoint list09:56
taccothats what you create endpoints for.09:56
noonedeadpunko/09:57
taccohi there. :)09:57
*** miloa has quit IRC10:11
*** gshippey has joined #openstack-ansible10:23
*** miloa has joined #openstack-ansible10:34
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-os_rally master: Ensure that the rally venv build is self contained  https://review.opendev.org/c/openstack/openstack-ansible-os_rally/+/77142110:43
jrosser^ grrrrrr10:43
*** miloa has quit IRC11:10
*** macz_ has joined #openstack-ansible11:24
*** macz_ has quit IRC11:28
admin0CeeMac, fleio setup might complete today11:52
admin0its a 3rd party that one customer asked for to integrate11:52
*** SecOpsNinja has joined #openstack-ansible11:52
*** SecOpsNinja has quit IRC11:57
*** ThiagoCMC has quit IRC11:57
*** dpawlik has quit IRC11:57
*** logan- has quit IRC11:57
*** fresta has quit IRC11:57
*** ebbex has quit IRC11:57
*** fresta has joined #openstack-ansible11:58
*** maharg102 has joined #openstack-ansible11:58
*** ThiagoCMC has joined #openstack-ansible11:58
*** logan- has joined #openstack-ansible12:00
*** maharg101 has quit IRC12:00
*** luksky has joined #openstack-ansible12:03
admin0what could be the reason when sometimes all routers are in standby mode?12:04
*** miloa has joined #openstack-ansible12:04
*** SecOpsNinja4 has joined #openstack-ansible12:05
*** SecOpsNinja4 has quit IRC12:07
*** SecOpsNinja has joined #openstack-ansible12:10
*** SiavashSardari has joined #openstack-ansible12:11
SecOpsNinjahi everyone. in osad is there any way that i can configure haproxy to only start after keepalived (i have my openstack endpoint ips behind a vip that is managed by keepalived)?12:12
*** dpawlik has joined #openstack-ansible12:15
CeeMacSecOpsNinja: I'm sure I had some notes on that, i'll see if I can dig somethine out12:22
SecOpsNinjahhah thanks12:22
SecOpsNinjai could normalty edit systemd haproxy unit and add keepalive in after line but it doesn't seem that the current haproxy role allows that12:23
noonedeadpunkjrosser: looks pretty neat at the end of the day12:29
CeeMacSecOpsNinja: i think the issue I had, haproxy wouldn't start as keepalived hadn't started as there was an issue with the VIP IP not binding after a reboot.  I'll keep poking though.12:32
openstackgerritDmitriy Rabotyagov proposed openstack/openstack-ansible stable/ussuri: Add some protection from shadowing mount  https://review.opendev.org/c/openstack/openstack-ansible/+/77139912:34
SecOpsNinjamy problem is that when my haproxy starts it cant bind socket to the vip (keepalive havent configured yet in the host)12:34
CeeMacso similar, but different12:34
openstackgerritDmitriy Rabotyagov proposed openstack/openstack-ansible stable/train: Add some protection from shadowing mount  https://review.opendev.org/c/openstack/openstack-ansible/+/77140012:35
CeeMacis keepalived actually not starting in the right time or is it failing to start?12:35
CeeMaci thought it should always start before haproxy12:35
CeeMacadmin0: I'd be interested to hear how it went with fleio once you've got it up and running12:45
CeeMacadmin0: for the routers in standby mode are they deployed HA ?12:46
*** ebbex has joined #openstack-ansible12:48
openstackgerritMerged openstack/openstack-ansible-plugins master: Remove chroot connection from ssh plugin  https://review.opendev.org/c/openstack/openstack-ansible-plugins/+/73727312:55
*** jbadiapa has joined #openstack-ansible12:56
admin0CeeMac, routers are deployed in ha13:03
*** macz_ has joined #openstack-ansible13:25
CeeMacadmin0: could there have been a blip in networking that would affect vrrp health?13:29
*** macz_ has quit IRC13:29
admin0i am retrying13:29
openstackgerritJonathan Rosser proposed openstack/openstack-ansible master: Update pip/setuptools/wheel to latest version  https://review.opendev.org/c/openstack/openstack-ansible/+/77028413:30
*** jamesgibo has joined #openstack-ansible14:11
*** spatel has joined #openstack-ansible14:13
odyssey4mejrosser - I've not tried installing rally with the new pip resolver... why do you ask?14:31
jrosserodyssey4me: i was WTF about rally for a good time this morning, and ended up with this https://review.opendev.org/c/openstack/openstack-ansible-os_rally/+/77142114:31
odyssey4mejrosser ah yeah, that old crusty nightmare... your conclusions are the same as mine - let rally be in its own sandbox14:32
*** dave-mccowan has quit IRC14:38
jrossernoonedeadpunk: we should probably wait for https://zuul.openstack.org/status#770284......14:41
*** pto has quit IRC14:42
noonedeadpunkit's totally failed atm14:44
noonedeadpunk`No matching distribution found for setuptools` whaaat14:44
jrosserit's the utility container install, suspect i've not looked at that yet14:45
jrossergot an AIO here and just running it now14:45
jrosser770284 is a depends-on all of the other role patches and needs to include all the necessary fixes for the integrated repo14:45
openstackgerritMerged openstack/openstack-ansible stable/victoria: Add some protection from shadowing mount  https://review.opendev.org/c/openstack/openstack-ansible/+/77120514:47
*** SiavashSardari has quit IRC14:59
openstackgerritArtom Lifshitz proposed openstack/openstack-ansible-os_tempest master: Add whitebox-tempest-plugin support  https://review.opendev.org/c/openstack/openstack-ansible-os_tempest/+/77147215:00
*** macz_ has joined #openstack-ansible15:01
jrossernoonedeadpunk: what do you make of this? http://paste.openstack.org/show/801736/15:03
*** chandankumar is now known as raukadah15:08
openstackgerritDaniel Meloy proposed openstack/openstack-ansible-os_nova master: Add Virtual GPU Config to nova.conf template  https://review.opendev.org/c/openstack/openstack-ansible-os_nova/+/76811715:09
jrosseroh it's this https://github.com/openstack/requirements/commit/097e2110b0548890309c548b2117647965c24fe7#diff-449046f51430a028478d668e3d3150c5b8f80e1a2682f1df9fd264dd6a42681aR58215:13
*** SiavashSardari has joined #openstack-ansible15:14
openstackgerritJonathan Rosser proposed openstack/openstack-ansible master: Update pip/setuptools/wheel to latest version  https://review.opendev.org/c/openstack/openstack-ansible/+/77028415:15
jrossercan i get another review on this https://review.opendev.org/c/openstack/openstack-ansible-rsyslog_client/+/77073115:27
openstackgerritJonathan Rosser proposed openstack/ansible-hardening master: Fix linter errors  https://review.opendev.org/c/openstack/ansible-hardening/+/77148115:35
*** sshnaidm|ruck is now known as sshnaidm|afk15:37
mgariepygerrit is more responsive this morning.15:43
*** klamath_atx has joined #openstack-ansible15:45
*** spatel has quit IRC15:55
*** klamath_atx has quit IRC16:01
*** sshnaidm|afk is now known as sshnaidm|ruck16:03
noonedeadpunk#startmeeting openstack_ansible_meeting16:05
openstackMeeting started Tue Jan 19 16:05:32 2021 UTC and is due to finish in 60 minutes.  The chair is noonedeadpunk. Information about MeetBot at http://wiki.debian.org/MeetBot.16:05
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.16:05
*** openstack changes topic to " (Meeting topic: openstack_ansible_meeting)"16:05
openstackThe meeting name has been set to 'openstack_ansible_meeting'16:05
noonedeadpunkwe have smth to discuss I guess this week, so I'd suggest to moe bug triaghe to the end if we have time for it16:06
noonedeadpunk#topic office hours16:06
*** openstack changes topic to "office hours (Meeting topic: openstack_ansible_meeting)"16:06
jrosserhello16:06
mgariepyhello.16:06
noonedeadpunkso you had awesome progress with new pip resolver16:06
jrosseryeah, i was expecting tons of horrid stuff but it's not been so bad16:07
noonedeadpunkI think now we stuck with really weird thing16:07
noonedeadpunk(ie setupttols missing)?16:07
jrosseri think i figured that, unfortunatley setuptools is in u-c, and we also have it in global-requirement-pins16:07
jrosserso if they dont exactly match you have a constraint of setuptools==X simultaneous with setuptools==Y which isnt possible16:08
noonedeadpunkand moreover virtualenv is also pinned16:09
jrosserso thats kind of the remaining thing to figure out, if we still want to keep complete control of the setuptools version in the openstack-ansible repo16:09
jrosseri was considering extending the repo server role to retrieve the u-c URL and create a filtered version with these things removed16:09
noonedeadpunkso now requirements does not have prescedence over constraints? (I guess it was the case previously)16:10
noonedeadpunkthen we can kind of drop tempest as well...16:10
jrosserit's possible that having one thing constrained twice now behaves differently16:10
jrosseri'm not sure that this is true any more https://github.com/openstack/openstack-ansible/blob/master/global-requirement-pins.txt#L1-L416:11
noonedeadpunkseems that it's not since it does not override u-c anymore :(16:12
noonedeadpunkwhich is really bad imo16:12
jrosserso i think we should look at maintaining a file on the repo server which as an adjusted version of u-c16:15
noonedeadpunkyeah you're right http://paste.openstack.org/show/801739/16:15
jrosseryes i think thats why my patch was total fail before because of that mismatch16:16
noonedeadpunkso it should filter out stuff that is in the defined list + what we have in global-requirement-pins.txt right?16:16
jrosseryeah, sounds about right16:17
jrosserwe have to do it this way as u-c is passed directly into pip as a URL16:17
noonedeadpunkAnd it's the change to python_venv_build I guess16:17
jrosserthe alternative is to create a variable which is a filtered version u-c as a list16:18
jrosserbut thats a very wide ranging change16:18
noonedeadpunkI'd rather download and store it I guess. However, another tricky thing is not to download it each time16:18
noonedeadpunkSo we might need to get uri like you did with tempest, filter things out, and save to file afterwards16:19
noonedeadpunkor having some temp file that will be common across each role run....16:19
noonedeadpunkuh16:19
jrosserneed to have a look at how the variables are at the moment16:21
noonedeadpunkwell, at least that sounds like smth that can be done...16:21
jrosserthe roles use requirements_git_url16:21
noonedeadpunkok, anyway souds like some plan:)16:21
jrossersure, i'll take a look, feels like this is nearly done tbh16:21
noonedeadpunkyeah, it does :)16:22
noonedeadpunkok, another thing. Changing policies to yaml. Change is pretty straightforward actually. But not sure about upgrade path16:22
noonedeadpunkI think the best way is to make old policy.json absent at the same place where we will be placing ploicy.yaml16:23
noonedeadpunkbut that would mean we need to do cleanup in every single role afterwards16:23
noonedeadpunkand having them dropped at some pre-stage (like in upgrade-utilities) is kind of too early I guess. And I'm not 100% sure, but are policies pre-loaded or read from disk with each request and do not require service restart?16:25
jrosseri'm not sure, but i think gmann can probably give us good advice here16:26
noonedeadpunkyeah...16:29
noonedeadpunkAnother thing was our SSL topic16:31
noonedeadpunkI think we should at least create a repo for that and I wanted to ask about proper name for it:)16:32
noonedeadpunkshould we use smth like ansible-role-ssl or openstack-ansible-ssl?16:33
noonedeadpunkI kind of don't have really good ideas about how it should be called...16:34
jrosserhmm yes, naming is always hard16:35
jrosserthere was also service tokens, is that something we need to get done?16:35
jrosserthis sort of thing https://docs.openstack.org/cinder/latest/configuration/block-storage/service-token.html16:35
noonedeadpunkhm... I think I started doing smth related a while ago...16:40
noonedeadpunkbut what we should reflect for sure is healthapi endpoints16:40
noonedeadpunk*healthcheck16:40
noonedeadpunkBut not sure if the're here for all services...16:41
noonedeadpunkkeystone_authtoken.service_token_roles_required <- that one16:45
noonedeadpunkI guess that's kind of related things?16:46
jrosseryes16:46
noonedeadpunkI'm pretty sure I was patching it somewhere, but can't recall...16:46
noonedeadpunkok, octavia, zun and masakari are patched at least...16:47
*** jamesdenton has quit IRC16:49
*** jamesdenton has joined #openstack-ansible16:49
noonedeadpunkhealthcheck is this https://docs.openstack.org/keystone/latest/admin/health-check-middleware.html16:51
noonedeadpunkand it should be pretty simple to adjust16:51
noonedeadpunkjust need to be sure about what services have implemented that16:52
*** macz_ has quit IRC16:52
noonedeadpunkbtw, have you read about Venus?16:52
*** macz_ has joined #openstack-ansible16:52
noonedeadpunkwhich is new log management service16:52
jrosseri saw some stuff on the ML but not looked too much, though it did look very interesting16:54
openstackgerritJonathan Rosser proposed openstack/ansible-hardening master: Fix linter errors  https://review.opendev.org/c/openstack/ansible-hardening/+/77148116:57
jrossernoonedeadpunk: any thoughts on the many many patches like this https://review.opendev.org/c/openstack/ansible-role-python_venv_build/+/76868916:58
jrosserdo we abandon them?16:58
noonedeadpunkI clean forgot to take care about them...16:58
* noonedeadpunk writes down on top of todo list16:59
noonedeadpunkYes, I think we should abandon them and I should go to release team and ask how we should stop publishing renos for each repo....16:59
noonedeadpunk#endmeeting17:00
*** openstack changes topic to "Launchpad: https://launchpad.net/openstack-ansible || Weekly Meetings: https://wiki.openstack.org/wiki/Meetings/openstack-ansible || Review Dashboard: http://bit.ly/osa-review-board-v3"17:00
openstackMeeting ended Tue Jan 19 17:00:27 2021 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)17:00
openstackMinutes:        http://eavesdrop.openstack.org/meetings/openstack_ansible_meeting/2021/openstack_ansible_meeting.2021-01-19-16.05.html17:00
openstackMinutes (text): http://eavesdrop.openstack.org/meetings/openstack_ansible_meeting/2021/openstack_ansible_meeting.2021-01-19-16.05.txt17:00
openstackLog:            http://eavesdrop.openstack.org/meetings/openstack_ansible_meeting/2021/openstack_ansible_meeting.2021-01-19-16.05.log.html17:00
*** sshnaidm|ruck is now known as sshnaidm|afk17:11
SiavashSardariI have question regarding policy files. is the json format deprecated in OpenStack services? I was working on policies last month and my understanding from oslo policy docs is that they just added yaml format so people can have comments in policy definitions.17:12
jrosserSiavashSardari: on the master branch of openstack there is a "community goal" to migrate from json to yaml policy17:13
jrosserthat is in progress now, and you'll find updates relating to that on the openstack-discuss mailing list17:14
*** spatel has joined #openstack-ansible17:15
SiavashSardariperfect, I didn't know that.17:15
SiavashSardariI'll be happy if I can help with the migration process17:16
openstackgerritJonathan Rosser proposed openstack/openstack-ansible master: Update pip/setuptools/wheel to latest version  https://review.opendev.org/c/openstack/openstack-ansible/+/77028417:22
jrosserSiavashSardari: ultimately all of the openstack-ansible service roles will need patching for this, if you are interested in helping out those would be good patches to attempt if you would like to get involved17:25
jrosseri think that we are still thinking about the best approach as it must address new deployments and also handle upgrades where there is existing json policy17:26
SiavashSardariOK then i will do a little digging on that and try to upload a patch for keystone role to have your inputs17:28
jrossernoonedeadpunk: html wierdness on your ML post http://lists.openstack.org/pipermail/openstack-discuss/2021-January/019907.html17:29
openstackgerritMerged openstack/openstack-ansible-rsyslog_client master: Update role for Ubuntu Focal and Centos-8  https://review.opendev.org/c/openstack/openstack-ansible-rsyslog_client/+/77073117:41
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-rsyslog_client stable/victoria: Update role for Ubuntu Focal and Centos-8  https://review.opendev.org/c/openstack/openstack-ansible-rsyslog_client/+/77140917:43
*** miloa has quit IRC17:43
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-rsyslog_client stable/ussuri: Update role for Ubuntu Focal and Centos-8  https://review.opendev.org/c/openstack/openstack-ansible-rsyslog_client/+/77141017:43
*** d34dh0r53 has quit IRC17:47
*** d34dh0r53 has joined #openstack-ansible17:50
noonedeadpunkdamn it17:50
noonedeadpunkuh, composer got updated and it seems I don't know how to send in plain text now...17:55
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-tests master: Run linters job on a focal node instead of bionic  https://review.opendev.org/c/openstack/openstack-ansible-tests/+/77149817:57
*** maharg102 has quit IRC18:01
*** gyee has joined #openstack-ansible18:16
*** pcaruana has quit IRC18:37
*** rpittau is now known as rpittau|afk18:41
*** pcaruana has joined #openstack-ansible18:48
*** pcaruana has quit IRC19:08
*** SiavashSardari has quit IRC19:22
*** SecOpsNinja has left #openstack-ansible19:27
openstackgerritMerged openstack/openstack-ansible-os_horizon master: Add missing 'horizon-config' tag  https://review.opendev.org/c/openstack/openstack-ansible-os_horizon/+/77126219:41
*** andrewbonney has quit IRC19:42
openstackgerritMerged openstack/openstack-ansible-os_neutron master: Allow overriding firewall_driver for ovs  https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/76852219:58
*** Jeffrey4l has quit IRC20:04
*** openstackgerrit has quit IRC20:12
*** Jeffrey4l has joined #openstack-ansible20:13
*** lemko3 has joined #openstack-ansible20:16
*** lemko has quit IRC20:16
*** lemko3 is now known as lemko20:16
*** poopcat has joined #openstack-ansible20:26
*** Jeffrey4l has quit IRC20:50
*** Jeffrey4l has joined #openstack-ansible20:51
*** poopcat has quit IRC21:09
*** poopcat has joined #openstack-ansible21:11
*** priteau has quit IRC21:35
*** gshippey has quit IRC22:07
*** jamesgibo has quit IRC22:14
*** mgariepy has quit IRC22:31
*** spatel has quit IRC22:31
*** mgariepy has joined #openstack-ansible22:34
*** klamath_atx has joined #openstack-ansible23:05
*** luksky has quit IRC23:36

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!