*** dviroel|out is now known as dviroel | 01:30 | |
*** dviroel is now known as dviroel|out | 02:02 | |
opendevreview | Takashi Kajinami proposed openstack/openstack-ansible-os_tempest master: Ensure heat_stack_owner role exists before assigning it https://review.opendev.org/c/openstack/openstack-ansible-os_tempest/+/831640 | 08:26 |
---|---|---|
opendevreview | Pranali Deore proposed openstack/openstack-ansible-os_tempest master: Add the glance-tempest-plugin https://review.opendev.org/c/openstack/openstack-ansible-os_tempest/+/831649 | 10:21 |
noonedeadpunk | mgariepy: I think we should merge https://review.opendev.org/c/openstack/openstack-ansible/+/831427 and then go to cherry-picks on W, X and master | 10:54 |
noonedeadpunk | So https://review.opendev.org/c/openstack/ansible-role-systemd_networkd/+/831603/ is not that required then | 10:56 |
noonedeadpunk | (but good to have anyway) | 10:56 |
*** dviroel|out is now known as dviroel | 11:15 | |
noonedeadpunk | cores, please let's review https://review.opendev.org/c/openstack/openstack-ansible/+/831427 and go in reverse order to master to fix upgrade jobs | 13:58 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_keystone master: Drop distributed_lock parameter https://review.opendev.org/c/openstack/openstack-ansible-os_keystone/+/831786 | 14:37 |
*** dviroel is now known as dviroel|lunch | 15:22 | |
mgariepy | hey. | 15:30 |
mgariepy | noonedeadpunk, for the systemd_networkd stuff i saw a failure that's why i did the patch | 15:35 |
noonedeadpunk | yeah, it would go away with adding utils collection | 15:39 |
mgariepy | when is the full path name of the filter needed and not needed ? i'm quite a bit confused lol | 15:39 |
mgariepy | https://zuul.opendev.org/t/openstack/build/dec257dcc56549eb91ef386fe2c7d98a/log/job-output.txt#4565 | 15:43 |
noonedeadpunk | so what basically happened - netcommon has dropped filter in favor of utils | 15:43 |
mgariepy | https://review.opendev.org/c/openstack/openstack-ansible/+/831525 | 15:43 |
noonedeadpunk | we pull in latest netcommon as it's dependency | 15:44 |
noonedeadpunk | but, for backport we'd rather set older version of netcommon | 15:44 |
noonedeadpunk | and for master - use utils | 15:44 |
noonedeadpunk | yes, upgrade fail, as to pass it - we need X, for X we need W, for W we need V... | 15:45 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible master: Add ansible.utils collectoin requirement https://review.opendev.org/c/openstack/openstack-ansible/+/831525 | 15:46 |
mgariepy | https://zuul.opendev.org/t/openstack/build/dec257dcc56549eb91ef386fe2c7d98a/log/job-output.txt#5499 | 15:48 |
mgariepy | for that check the utils collection was installed but the filter wasn't found by jinja | 15:48 |
noonedeadpunk | but it's upgrade job? | 15:48 |
mgariepy | ha. | 15:49 |
noonedeadpunk | which runs X-master upgrade | 15:49 |
mgariepy | lol ok | 15:49 |
noonedeadpunk | so for X we don't have that yet | 15:49 |
mgariepy | now i get it.. less confused than i was.. | 15:49 |
mgariepy | can we do depends on for upgrade job ? | 15:54 |
noonedeadpunk | nope | 16:27 |
noonedeadpunk | well, we can, but only on current branch | 16:27 |
noonedeadpunk | we can't on M-1 | 16:27 |
*** dviroel|lunch is now known as dviroel | 16:27 | |
opendevreview | Merged openstack/openstack-ansible stable/victoria: Bump ansible.netcommon version https://review.opendev.org/c/openstack/openstack-ansible/+/831427 | 16:29 |
mgariepy | w is rechecking ! | 16:35 |
*** dviroel__ is now known as dviroel | 16:56 | |
noonedeadpunk | awesome, thanks! | 17:07 |
jamesdenton | noonedeadpunk did you integrate Barbican w/ the Luna? | 17:31 |
noonedeadpunk | yup | 17:31 |
jamesdenton | cool cool. Working on nCipher at the moment, and a little lost. I might ping you :) | 17:32 |
noonedeadpunk | I tested only with pkcs#11 and vault actually | 17:33 |
jamesdenton | ok, i will be using the pkcs#11 driver too | 17:33 |
noonedeadpunk | ah, then hopefully I can help if needed :) | 17:34 |
jamesdenton | i'm just missing some details on the nCipher side (using their hosted service vs on-prem) | 17:34 |
noonedeadpunk | I'd say basically you need client library. For luna it was pre-built driver and config file with token/auth stuff for their API | 17:35 |
noonedeadpunk | Should be same stuff actually for everybody else as well.. | 17:36 |
jamesdenton | i have the library installed and can talk to the HSM, but i'm missing the passphrase (since i/we don't manage the device) and can't generate hmac or mkek keys at the moment | 17:36 |
jamesdenton | i found the osa docs and assumed you wrote it, but also looking at upstream | 17:36 |
jamesdenton | just some holes to fill on my end | 17:36 |
jamesdenton | are you using HSM in production w/ Octavia? Cinder? | 17:37 |
noonedeadpunk | yup | 17:38 |
jamesdenton | Sweet. Like it? | 17:38 |
noonedeadpunk | well for Luna they have portal for hosted service | 17:38 |
jamesdenton | i'm sure its the same here, i just don't have access (we're navigating this blindly, together) | 17:38 |
jamesdenton | and by we i mean me and the vendor | 17:39 |
noonedeadpunk | well, there's a bug in octavia https://bugs.launchpad.net/keystone/+bug/1959674 | 17:39 |
johnsom | It's a bug in keystone... grin. Keystone 500's out | 17:40 |
noonedeadpunk | well, ok:) but touches only octavia :) | 17:41 |
noonedeadpunk | and for cinder things are a bit weird/slow. Also ephemeral encryption not implemented yet as well as glance encryption... so tons of gaps kind of | 17:41 |
johnsom | Yeah, that might be the case | 17:41 |
noonedeadpunk | object storage encryption also meh... | 17:41 |
jamesdenton | is that just in general? | 17:41 |
johnsom | Sadly I don't know the inner workings on the keystone side to figure out which one of the three possibilities are the right fix. | 17:42 |
jamesdenton | the use case for us is primary octavia at the moment. simple crypto may be fine, just trying to vet this for now | 17:43 |
noonedeadpunk | for us it was data encryption and octavia as nice bonus | 17:45 |
johnsom | jamesdenton Hi there. Let me know how nCipher goes for you. Most folks doing HSM like things with Octavia seem to be using Vault. | 17:46 |
jamesdenton | will do! | 17:46 |
noonedeadpunk | I wonder how they do it, considering barbican/vault integration was broken since T till X I believe | 17:48 |
noonedeadpunk | just castellan directly to vault? | 17:48 |
noonedeadpunk | but then there's no multi-tenancy so kind of same simple_crypto... | 17:49 |
johnsom | We do allow a pure Castellan option. I'm pretty sure at least a few use that | 17:49 |
johnsom | Right, it all goes into one bucket | 17:49 |
johnsom | We talked about how that could be fixed a few PTGs ago, but I don't know if it ever happened | 17:50 |
noonedeadpunk | for me sounds like overkill given what it provides but ok:) | 17:50 |
noonedeadpunk | and that you also need to have enterprise to at least unlock vault safely... | 17:50 |
noonedeadpunk | anyway | 17:50 |
mgariepy | woohoo W [ Status: Success ] :D | 18:55 |
mgariepy | anyone here can push this one ?https://review.opendev.org/c/openstack/openstack-ansible/+/831426 | 19:46 |
mgariepy | thanks jamesdenton | 19:59 |
*** dviroel is now known as dviroel|out | 21:37 | |
*** dviroel|out is now known as dviroel | 22:21 | |
opendevreview | Neil Hanlon proposed openstack/openstack-ansible master: Add support for running on Rocky Linux https://review.opendev.org/c/openstack/openstack-ansible/+/823573 | 23:49 |
opendevreview | Neil Hanlon proposed openstack/openstack-ansible master: Add support for running on Rocky Linux https://review.opendev.org/c/openstack/openstack-ansible/+/823573 | 23:52 |
opendevreview | Neil Hanlon proposed openstack/openstack-ansible master: Add support for running on Rocky Linux https://review.opendev.org/c/openstack/openstack-ansible/+/823573 | 23:59 |
Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!