Wednesday, 2021-09-08

*** b3lab is now known as ierdem06:49
*** pto is now known as ptoft10:53
ptoftI need to upgrade from nautilus to octopus. Should I use the rolling upgrade playbook?10:58
spatelnoonedeadpunk did we release new 23.2.0 ? 13:36
noonedeadpunkspatel: we did 23.1.013:37
noonedeadpunknever had plans for 22.2.0 yet13:38
spateli am already running 23.1.0 in lab and waiting for 23.2.0 13:38
spatelwhen are we start working on Xena ? 13:38
noonedeadpunk23.1.0 has been released week ago... https://opendev.org/openstack/releases/commit/8fde3038fe82d8990daf9710ac1f03bb27c84ff913:39
jrosserspatel: the work on xena is continuous13:41
spatelnice!! 13:41
jrosserit kind of starts the moment the W branch is made, on master13:41
jrosserbut its obviously requiring effort to achieve things13:41
noonedeadpunkWe just didn't put a lot of efforts into it since I guess we have lack of time due to internal needs13:42
spatelassuming we won't see any more 23.x.x moving forward13:42
spatelI understand :)13:42
noonedeadpunkwell, I believe there would be bugfixes anyway13:42
jrosserspatel: there is a point release every ~2 weeks on all the supported stable branches13:42
noonedeadpunkand it will move forward at least because upstream version will be bumped13:42
spatelI am deploying OVN in production soon, currently running load-test 13:42
noonedeadpunkbtw I need to push bumps...13:42
noonedeadpunkjrosser: when you have time, can you check pls yestarday meeting?  https://meetings.opendev.org/meetings/openstack_ansible_meeting/2021/openstack_ansible_meeting.2021-09-07-15.02.log.html13:43
noonedeadpunkneed your opinion on that before doing smth stupid :p13:44
jrosserah ok yes will have a look13:45
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible master: Set galera to use TLS for connections by default  https://review.opendev.org/c/openstack/openstack-ansible/+/80788014:33
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible-galera_server master: Use ansible-role-pki to generate SSL certificates  https://review.opendev.org/c/openstack/openstack-ansible-galera_server/+/80771714:33
noonedeadpunkregarding ^ I have weird issue, when I provide ssl_ca in my.cnf for client, I get `SSL connection error: unable to get issuer certificate`15:14
noonedeadpunkwithout it ssl works like a charm15:14
noonedeadpunkany thoughts?15:15
noonedeadpunkAs I'd rather fix this then adjust connection string in each role https://opendev.org/openstack/openstack-ansible-os_glance/src/branch/master/templates/glance-api.conf.j2#L3915:16
*** tosky is now known as Guest670215:22
*** tosky_ is now known as tosky15:22
noonedeadpunkit feels like we missing some info in CA15:22
noonedeadpunklike authority_cert_issuer...15:25
noonedeadpunk`The keyIdentifier is composed of the 160-bit SHA-1 hash of the value of the BIT STRING subjectPublicKey (excluding the tag, length, and number of unused bits)` um....15:37
opendevreviewMerged openstack/openstack-ansible-os_neutron stable/wallaby: Set OVN jobs to voting  https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/80608417:57
jrossernoonedeadpunk: see https://mariadb.com/kb/en/securing-connections-for-client-and-server/#enabling-two-way-tls-for-mariadb-clients18:47
jrosserare you trying "one way" or "two way" TLS?18:47
-opendevstatus- NOTICE: The Gerrit service on review.opendev.org is going offline momentarily for a host migration and zuul upgrade, downtime should be only a few minutes.21:04

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!