Friday, 2023-01-27

opendevreviewOpenStack Proposal Bot proposed openstack/openstack-ansible master: Imported Translations from Zanata  https://review.opendev.org/c/openstack/openstack-ansible/+/87192903:24
*** akahat is now known as akahat|ruck07:01
*** akahat|ruck is now known as akahat|rover07:01
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible stable/yoga: Bump OSA for stable/yoga to cover CVE-2022-47951  https://review.opendev.org/c/openstack/openstack-ansible/+/87183408:32
moha7Do you update-upgrade hosts' operating systems? For example, if Ubuntu has been installed on controller&compute nodes, do you regularly run `apt update && apt -y upgrade`?09:33
noonedeadpunkI wouldn't run upgrade on compute hosts and net nodes without evacuating vms/namespaces from them09:59
kleiniI think, OSA configures through ansible-hardening role unattended upgrades in Ubuntu by default.10:07
moha7Ah, net nodes; I remembered a question (:10:11
moha7jamesdenton: Do you recommend separating network nodes in an OVN-based production env?10:11
noonedeadpunkkleini: oh, does it ? :D10:15
noonedeadpunkI'm not sure it's default?10:15
noonedeadpunkhttps://opendev.org/openstack/ansible-hardening/src/branch/master/defaults/main.yml#L31210:17
noonedeadpunkit's disabled by default, yeah10:17
moha7there's no more line for Ubuntu having `automatic_package_updates`in that link!10:20
moha7If you were going to employ someone to join to your OpenStack team, what would the questions you asked him? What about a 1-week project you asked for?10:22
noonedeadpunklol, we're trying to hire someone for last 2 years without good results - are you sure you want my advice? :D10:37
opendevreviewMerged openstack/openstack-ansible stable/zed: Bump OSA for stable/zed to cover CVE-2022-47951  https://review.opendev.org/c/openstack/openstack-ansible/+/87183010:51
opendevreviewMerged openstack/openstack-ansible master: Imported Translations from Zanata  https://review.opendev.org/c/openstack/openstack-ansible/+/87192910:51
moha7noonedeadpunk: ((=11:46
*** tosky_ is now known as tosky12:55
admin1i have hired a lot of people for openstack roles in the past .. look for their knowledge in openstack based on the role .. support or infra 13:20
admin1if support, how to handle customers and common tasks ( level 1/ 2 ) 13:20
admin1if infra, more on troubleshoting , how much they know in depth 13:21
admin1also some can be hired with no knowledge of openstack, but good knowlege on virtualization, storage, api, bits of programming etc 13:21
admin1at the end ( for me ) its a bunch of apis provided by microservices .. but if the person knows about kvm, iscsi, nfs , ovs etc , he can understand and do well .. at least, that has been my experience 13:22
noonedeadpunkIt's so hard to find proper linux engineer even these days...13:31
noonedeadpunkAs everyone are "devops"13:31
noonedeadpunkopenstack can be taught indeed quite fast if needed13:31
noonedeadpunkbut again then you would need to spent quite some time for learning and once they learn - they leave D13:33
mgariepyit's not easy to find ppl.13:40
noonedeadpunkwould be sweet to get reviews on https://review.opendev.org/q/topic:bump_osa+status:open13:56
jamesdentonmoha7 If you can swing pulling down provider networks to each compute, that's probably the way to go. Meaning, make the computes gateway chassis14:35
mgariepyhow far are you pushing for the CVE? are you waiting on the patches to merge then update down to V ? os U T S ?14:37
moha7Generally, is it a good idea to separate the net nodes? I checked the documentation of Red Hat, Ubuntu and others, except for one case about Mirantis, this isolation from controllers is not done anywhere else.14:37
admin1moha7, it depends on your network  domains and how you expect traffic .. if internal, you do not have to .. if you are doing public and expect ddos or probes or slow tcp that can affect other traffic  ( if sharing the same network card ) then you might want to isolate those domains 14:39
admin1if single bond or network card, and you are doing vxlan and vlan with mgmt, then vxlan ( east-west) can eat the bandwidth when users copy large files or do stuff - -which is totally beyond your control 14:39
admin1so you want to think about isolating that in the design14:39
jamesdentonfor a small-medium environment, having network+controller co-located is usually not a problem. But, if you find resource contention then you can consider breaking them out. It's really that simple14:41
jamesdentonthat goes for any of the services14:41
mgariepymedium is up to how many nodes ? 14:52
mgariepythe line is kinda blury14:53
noonedeadpunkI guess that depends on the throughput mostly?14:53
noonedeadpunkAnd well, if you allow external network conenction directly through VMs or oblige users to use floating ips14:54
mgariepyyeah14:55
mgariepydepending on the usecase it depend greatly , collect metric on everything and adjust for the future :)14:55
*** dviroel|out is now known as dviroel|ruck15:08
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible-os_neutron master: Generate OVN certs only for OVN plugin  https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/87202415:24
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible-os_neutron master: Generate OVN certs only for OVN scenario  https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/87202415:30
noonedeadpunkjamesdenton: if around, could you vote on https://review.opendev.org/q/topic:bump_osa+status:open ?16:45
jamesdentonack17:10
noonedeadpunkthanks!17:28
prometheanfireis there any facility to install a master version of horizon into an older release?  (I know we can override UC url, horizing install branch, and venv tag, but the repo container shows version conflicts in the constraints it's trying to install still)17:52
prometheanfireI feel like I'm missing something...17:52
jrosserprometheanfire: are you setting horizon_upper_constraints_url to something appropriate for master?18:07
prometheanfireya, I think I needed to set rebuild-wheels/venvs18:07
opendevreviewMerged openstack/openstack-ansible stable/xena: Bump OSA for stable/xena to cover CVE-2022-47951  https://review.opendev.org/c/openstack/openstack-ansible/+/87183919:24
noonedeadpunkI'm going to be mostly offline next week. So if somebody will have couple of minutes and spot that https://review.opendev.org/c/openstack/openstack-ansible/+/871834 is merged - would be great to update with it's SHA here https://review.opendev.org/c/openstack/releases/+/87128120:24
jamesdentonack20:26
admin1anyone played with skyline yet  ? or using it in prod instead of horizon 20:40
*** dviroel|ruck is now known as dviroel|ruck|afk20:53
spateladmin1 i am running in dev but not in prod20:54
admin1does it have everything to not miss horizon ? 20:54
spatelbecause that project is little slow.. to catch up with all requirements 20:54
admin1and only 1-2 devs from china 20:55
spatelDoes anyone know how cinder-backup works? 20:55
spatelIf i have cinder on ceph and cinder-backup on NFS or POSIX local filesystem, in that case how does data copy from ceph to NFS or POSIX filesystem?20:56
spatelHow data flow will look like? 20:56
spatelTrying to understand this flow but very confused - https://gorka.eguileor.com/inside-cinders-incremental-backup/21:01
spateldoes controller nodes come into path during backing up????21:05

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!