Wednesday, 2021-12-22

*** gmann_afk is now known as gmann00:35
noonedeadpunkspatel: well, it's epel design to start from scratch for each release. And depends only on package maintainers if and when package will appear on EPEL02:42
noonedeadpunkSo eventually package might be maintained, released for el6,el7,el8 and all new fedoras, but it doesn't mean that it will be for el9, despite for fedonra34 it's there02:43
noonedeadpunkBut I'm not sure it means we should bring in mess to ubuntu as well because of that :D02:43
*** ianw is now known as ianw_pto07:55
noonedeadpunk24.0.0 has finally landed!08:45
noonedeadpunkwell, that was wrong section for release note https://docs.openstack.org/releasenotes/openstack-ansible/xena.html#security-issues08:49
noonedeadpunkbecause it's feature, not issue...08:51
noonedeadpunkI wonder if we can change that now...08:51
damiandabrowski[m]good job guys!09:20
jrosser_“OVN-related endpoints will be completely removed in the Z release” in the release notes, should that actually be Y?09:20
noonedeadpunkwell, depends on how long we want to carry legacy :)09:36
noonedeadpunkhuh, ansible 2.12 failed on centos with lxc just on tempest execution...10:11
noonedeadpunk`ModuleNotFoundError: No module named 'libvirtmod'`10:12
noonedeadpunkin compute...10:12
jrosser_that would need this to work out as expected https://github.com/openstack/openstack-ansible-os_nova/search?q=nova_compute_kvm_packages_to_symlink10:17
jrosser_i wonder if the libvirt python bindings are specific to the python version10:17
jrosser_we are also very specific on the version here https://github.com/openstack/openstack-ansible-os_nova/blob/master/vars/redhat.yml#L7710:20
noonedeadpunkI bet they are, as well as ceph ones as well10:33
noonedeadpunkI'm surprised about lxc though10:35
noonedeadpunkbut I think we're trying to run 3.8 only for deploy now, it's just aio that results in compute using 3.8 as well.10:36
noonedeadpunk(but we likely should run 3.8 everywhere)10:38
admin1\o/ .. will be testing 24.0.0 on lab . 10:55
jrosser_noonedeadpunk: maybe we do the wrong thing for now with setting the system default python to 3.8 on centos11:05
jrosser_perhaps leaving that as default, and making a different workaround for ensuring ansible-runtime is 3.8 would be better11:06
jrosser_particuarly as i think that some people use infra1 as the deploy host so thats going to go kind of broken for them if we need to keep the services on 3.611:06
noonedeadpunkjrosser_: oh, well, I just saw Yoga without that patch https://review.opendev.org/c/openstack/governance/+/820195/3/reference/runtimes/yoga.rst11:08
noonedeadpunkso I kind of thought that 3.6 is not supported for Y11:08
noonedeadpunkso yes, I agree that we should jsut use it for runtime11:09
noonedeadpunkbut I'd say that replacing virtualenv with venv might be still good idea?11:10
jrosser_worth checking the ML about 3.6, I have a feeling that the RH people realised they backed themselves into a corner11:13
jrosser_yes I think we should drop the use of virtualenv11:14
noonedeadpunkJust briefly checked and yeah, they resulted in that patch11:15
jrosser_now that the python release cadence is >> faster than RHEL this is going to be interesting to see how they deal with that in the future11:15
noonedeadpunkbut I kind of dunno what they were expecting... 11:15
noonedeadpunkMight be stream concept would help them....11:16
noonedeadpunkto be fair - ubuntu does not bringing in modules as well while adding new python versions timely11:17
noonedeadpunkit's just releasing faster then python goes to eol:)11:17
noonedeadpunkwow, we still do have suse in bootstrap-ansible...11:19
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible master: Use the python venv module to build the ansible runtime venv  https://review.opendev.org/c/openstack/openstack-ansible/+/82227311:20
noonedeadpunkdoh, we haven't merged https://review.opendev.org/c/openstack/openstack-ansible/+/78255711:21
*** dviroel|afk is now known as dviroel11:24
*** sshnaidm|afk is now known as sshnaidm11:26
jrosser_it needs a fix, removed an extra 'fi' in the most recent PS11:27
noonedeadpunkyeah, saw that...11:27
jrosser_and likley a fairly big rebase in light of the other patches to remove OS11:27
noonedeadpunk(just saw that)11:27
noonedeadpunkI kind of thought it's merged for X11:28
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible master: Use python3.8 for CentOS 8  https://review.opendev.org/c/openstack/openstack-ansible/+/82226011:39
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible master: [WIP] Update ansible-core to 2.12.1  https://review.opendev.org/c/openstack/openstack-ansible/+/82206311:39
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible master: [WIP] Update ansible-core to 2.12.1  https://review.opendev.org/c/openstack/openstack-ansible/+/82206311:39
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible master: Remove references to unsupported operating systems  https://review.opendev.org/c/openstack/openstack-ansible/+/78255711:47
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible master: Use python3.8 for CentOS 8  https://review.opendev.org/c/openstack/openstack-ansible/+/82226011:53
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible master: [WIP] Update ansible-core to 2.12.1  https://review.opendev.org/c/openstack/openstack-ansible/+/82206311:53
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible master: Remove references to unsupported operating systems  https://review.opendev.org/c/openstack/openstack-ansible/+/78255711:55
opendevreviewJames Gibson proposed openstack/openstack-ansible-os_nova master: Disable TLS on VNC by default  https://review.opendev.org/c/openstack/openstack-ansible-os_nova/+/82266312:03
opendevreviewJames Gibson proposed openstack/openstack-ansible master: Update notes on how to enable TLS for VNC  https://review.opendev.org/c/openstack/openstack-ansible/+/82269012:14
opendevreviewJames Gibson proposed openstack/openstack-ansible master: Update notes on how to enable TLS for VNC  https://review.opendev.org/c/openstack/openstack-ansible/+/82269012:15
kleiniReading W release notes: Do I need a migration in a running deployment from iptables_hybrid to openvswitch  for neutron_firewall_driver?12:30
noonedeadpunkJamesGibo: am I right that if you upgrade with nova_qemu_vnc_tls enabled, you won't be able to run openstack console url get?12:30
noonedeadpunkor at least console wont work?12:30
kleiniTrying to answer my own question: As the firewall driver is only configured on neutron agent nodes, switching the driver should at least be possible when taking that node out of production.13:23
JamesGibonoonedeadpunk: You won't be able to access existing VM's until they are either migrated or rebooted, console access to new VMs will work 13:42
noonedeadpunkso it's not that vms are really broken, and there're 2 solutions for that13:42
noonedeadpunkeither to disble tls or restart VM if you want to go safe13:43
noonedeadpunkSo I'd actually vote to leave it enabled by default13:43
JamesGiboYeah, the VM's will be running fine, its just you can't use the VNC server13:44
noonedeadpunkand live migration I guess should work as well?13:44
JamesGiboOk, should I leave enabled and just add an release note issue to the xena branch?13:45
noonedeadpunkyeah, I'd say to do that tbh13:45
JamesGiboYeah that is not affected 13:45
noonedeadpunkjrosser_: wdyt?13:45
jrosser_seems reasonable, the release note can say what to do to disable vnc tls if it's important to anyone, i guess some things can't migrate (sriov, gpu...)13:47
jamesdentonkleini switching from iptables_hybrid to openvswitch firewall driver is doable in production, but you will have to script out veth/bridge/vif stuff14:09
jamesdentonand possibly stop/start or hard reboot instances to get the xml where it needs to be 14:10
kleinijamesdenton: thanks. so I will stick to evacuating a host before switching the firewall driver for it14:16
jamesdentonare you currently doing that now?14:17
kleininope, I am still planing my upgrade to W14:18
admin1what could be some good reasons to switch from iptables -> ovs firewall ? 14:21
opendevreviewJames Gibson proposed openstack/openstack-ansible-os_nova stable/xena: Add release note issue for no console access when TLS for VNC enabled  https://review.opendev.org/c/openstack/openstack-ansible-os_nova/+/82271314:23
opendevreviewJames Gibson proposed openstack/openstack-ansible master: Update notes on how to enable TLS for VNC  https://review.opendev.org/c/openstack/openstack-ansible/+/82269014:29
noonedeadpunkwow, that is good actually https://review.opendev.org/c/openstack/openstack-ansible/+/82206314:45
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible master: Update ansible-core to 2.12.1  https://review.opendev.org/c/openstack/openstack-ansible/+/82206314:48
opendevreviewJonathan Rosser proposed openstack/openstack-ansible master: Update ansible-core to 2.12.1  https://review.opendev.org/c/openstack/openstack-ansible/+/82206314:52
*** dviroel is now known as dviroel|lunch15:41
noonedeadpunkSo, we stuck atm with zun https://review.opendev.org/c/openstack/openstack-ansible-os_zun/+/82067915:51
noonedeadpunkhm...15:51
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible-os_zun master: [DNM]  https://review.opendev.org/c/openstack/openstack-ansible-os_zun/+/82272815:54
*** dviroel|lunch is now known as dviroel16:39
noonedeadpunkdamn, we're blocked with adjutant....16:42
noonedeadpunkwe probably should filter django there....16:48
noonedeadpunkoh damn... and we should backport neutron filtering to xena I believe16:48
noonedeadpunkah. no, we fixed that in master as well16:53
jrosser_adjutant looks like a bug? the django version in u-c is outside the range in their requirements16:54
noonedeadpunkyeah16:54
noonedeadpunkI doubt they will fllow that tbh16:54
noonedeadpunk*follow16:54
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible-os_adjutant master: Filter out Django version  https://review.opendev.org/c/openstack/openstack-ansible-os_adjutant/+/82274516:58
kleiniadmin1: release notes for W promise increasing scalability and performance with security groups as flows in OVS17:17
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible-os_adjutant master: Remove static parameter for import  https://review.opendev.org/c/openstack/openstack-ansible-os_adjutant/+/82225618:06
*** dviroel is now known as dviroel|afk19:31
admin1jamesdenton, if i read one of your books online on packt subscription, do you get paid  for it ? 22:16
admin1i already have your signed book, but if you do get paid, i can click and read it there :) 22:16
jamesdentongood question... probably22:34
jamesdentonin a few years i can buy a coffee :D22:35
admin1:D 22:46
admin1next time i meet you, coffee on  me then .. 22:46
jamesdentonsounds good :)22:48
jamesdentonhopefully the book is still useful, sorta long in the tooth, as they say22:48

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!