opendevreview | Jonathan Rosser proposed openstack/openstack-ansible-ops master: Do not duplicate the in-repo example files inside the documentation https://review.opendev.org/c/openstack/openstack-ansible-ops/+/916870 | 08:47 |
---|---|---|
opendevreview | Merged openstack/openstack-ansible-os_neutron master: Add debian package libstrongswan-standard-plugins https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/916832 | 09:07 |
opendevreview | Jonathan Rosser proposed openstack/openstack-ansible-ops master: Do not duplicate the in-repo example files inside the documentation https://review.opendev.org/c/openstack/openstack-ansible-ops/+/916870 | 09:11 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible master: Add Tempest test for OVN Octavia driver https://review.opendev.org/c/openstack/openstack-ansible/+/916872 | 09:17 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_neutron stable/2023.2: Add debian package libstrongswan-standard-plugins https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/916765 | 09:17 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_neutron stable/2023.1: Add debian package libstrongswan-standard-plugins https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/916766 | 09:18 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible master: Add Tempest test for OVN Octavia driver https://review.opendev.org/c/openstack/openstack-ansible/+/916872 | 09:22 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_octavia master: Implement support for octavia-ovn-provider driver https://review.opendev.org/c/openstack/openstack-ansible-os_octavia/+/868462 | 09:24 |
opendevreview | Jonathan Rosser proposed openstack/openstack-ansible-ops master: Do not duplicate the in-repo example files inside the documentation https://review.opendev.org/c/openstack/openstack-ansible-ops/+/916870 | 09:39 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_keystone master: Add service policies defenition https://review.opendev.org/c/openstack/openstack-ansible-os_keystone/+/916874 | 09:42 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_keystone master: Add variable to globally control notifications enablement and disable RPC https://review.opendev.org/c/openstack/openstack-ansible-os_keystone/+/916878 | 09:47 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_keystone master: Implement variables to address oslo.messaging improvements https://review.opendev.org/c/openstack/openstack-ansible-os_keystone/+/916879 | 09:52 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_barbican master: Add service policies defenition https://review.opendev.org/c/openstack/openstack-ansible-os_barbican/+/916881 | 10:10 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_barbican master: Add variable to globally control notifications enablement https://review.opendev.org/c/openstack/openstack-ansible-os_barbican/+/916882 | 10:13 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_barbican master: Implement variables to address oslo.messaging improvements https://review.opendev.org/c/openstack/openstack-ansible-os_barbican/+/916884 | 10:17 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible master: Switch service repos to track 2024.1 https://review.opendev.org/c/openstack/openstack-ansible/+/914188 | 10:43 |
opendevreview | Jonathan Rosser proposed openstack/openstack-ansible-ops master: Do not duplicate the in-repo example files inside the documentation https://review.opendev.org/c/openstack/openstack-ansible-ops/+/916870 | 10:51 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_magnum master: Allow zuul job variables to be inserted into user_variables https://review.opendev.org/c/openstack/openstack-ansible-os_magnum/+/916647 | 11:48 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_sahara master: Preserve actual production playbook in examples https://review.opendev.org/c/openstack/openstack-ansible-os_sahara/+/916890 | 12:08 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_murano master: Preserve actual production playbook in examples https://review.opendev.org/c/openstack/openstack-ansible-os_murano/+/916891 | 12:11 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_senlin master: Preserve actual production playbook in examples https://review.opendev.org/c/openstack/openstack-ansible-os_senlin/+/916892 | 12:12 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible master: Move Murano/Senlin/Sahara to Inactive state https://review.opendev.org/c/openstack/openstack-ansible/+/916900 | 12:58 |
noonedeadpunk | I'm really not sure about if I'm doing right thing here ^ | 12:58 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible master: Move Murano/Senlin/Sahara to Inactive state https://review.opendev.org/c/openstack/openstack-ansible/+/916900 | 12:59 |
opendevreview | Jonathan Rosser proposed openstack/openstack-ansible-ops master: Do not duplicate the in-repo example files inside the documentation https://review.opendev.org/c/openstack/openstack-ansible-ops/+/916870 | 13:07 |
spatel | Hey! folks.. any idea what is going on here | 13:22 |
spatel | # openstack coe cluster config dev2 | 13:22 |
spatel | Policy doesn't allow certificate:get to be performed (HTTP 403) (Request-ID: req-7445ef3c-52a3-4911-97f6-1fb25d9fac1f) | 13:22 |
noonedeadpunk | spatel: what are you using for auth? | 13:23 |
noonedeadpunk | passowrd/application credentials? | 13:23 |
spatel | I have LDAP for username | 13:24 |
spatel | FreeIPA | 13:24 |
spatel | I am not using app creds | 13:24 |
noonedeadpunk | does the user has `reader` role then? | 13:24 |
spatel | My keystone talk to freeIPA ldap and I have assigned user to reader role.. | 13:25 |
noonedeadpunk | as I think this is provided by LDAP as well... | 13:25 |
spatel | openstack role add --user spatel --user-domain eng --project eng reader | 13:25 |
noonedeadpunk | huh. and can you do that this way with ldap? | 13:26 |
spatel | LDAP is only for username/password (all roles etc still handle by SQL ) | 13:26 |
noonedeadpunk | as I thought roles for user also provided from ldap | 13:26 |
noonedeadpunk | I frankly never did that specific setup | 13:26 |
noonedeadpunk | though I though that with ldap there's no local users created? | 13:27 |
noonedeadpunk | or they are on first login as well? | 13:27 |
spatel | Yes LDAP can fully integrate with keystone but I didn't configure that way.. LDAP only handling auth (just validate password) | 13:28 |
spatel | authorization should be handle by SQL | 13:28 |
spatel | This is what I have - https://satishdotpatel.github.io/openstack-ldap-integration/ | 13:29 |
noonedeadpunk | aha | 13:29 |
spatel | [identity] | 13:29 |
spatel | driver = ldap | 13:29 |
spatel | Assignment handle by SQL | 13:29 |
spatel | loadbalancer_memeber roles works that means keystone properly looking for roles mapping | 13:31 |
noonedeadpunk | yeah, ok, fair | 13:31 |
noonedeadpunk | well, `member` by default should imply `reader` anyway.... | 13:32 |
noonedeadpunk | but I don't really have good obvious ideas otherwise. | 13:33 |
spatel | Let me try to create local account outside LDAP and see how does it behave.. | 13:33 |
andrewbonney | noonedeadpunk: I think jrosser_ mentioned our oslo.messaging fun yesterday. If you get chance to look I have some patches in https://review.opendev.org/q/topic:%22osa/rmq-policy%22 for pre-quorum-queue deployments | 13:56 |
noonedeadpunk | andrewbonney: so basically it also means that deployments without HA queues are even more broken? | 13:59 |
andrewbonney | At present if you don't use HA queues for reply queues, but have a multi-node RMQ cluster then failover causes big issues from 2023.1 onwards | 14:00 |
noonedeadpunk | yeah | 14:04 |
noonedeadpunk | but probably even bigger if you don't use HA queues at all? | 14:04 |
andrewbonney | Yes absolutely, assuming a multi-node RMQ | 14:10 |
jrosser_ | we figured at the scale we run at here, moving the reply queues to also be HA was acheiveable and would make upgrades much less full of surprise failures | 14:30 |
jrosser_ | however - that might not be the case if you don't have capacity in your rabbitmq to acommodate moving the reply queues to be ha | 14:31 |
noonedeadpunk | yeah, fair | 14:35 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-openstack_hosts master: Update OpenStack Release to Caracal https://review.opendev.org/c/openstack/openstack-ansible-openstack_hosts/+/916917 | 14:43 |
noonedeadpunk | ThiagoCMC: we may see how distro install works soonish with this ^ :) | 14:43 |
opendevreview | Stuart Grace proposed openstack/openstack-ansible-ops master: Clarifications to mcapi_vexxhost README https://review.opendev.org/c/openstack/openstack-ansible-ops/+/916817 | 15:32 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-ops master: Do not duplicate the in-repo example files inside the documentation https://review.opendev.org/c/openstack/openstack-ansible-ops/+/916870 | 15:43 |
ThiagoCMC | noonedeadpunk, Wheee!!! :-D | 16:07 |
jrosser_ | i think there is new RDO for caracal as well if we want to move those jobs over | 16:16 |
noonedeadpunk | yeah | 16:22 |
noonedeadpunk | that's exactly what https://review.opendev.org/c/openstack/openstack-ansible-openstack_hosts/+/916917 does | 16:22 |
ThiagoCMC | BTW, it seems OSA will skip Ceph 18, right? Since Caracal repos brings Ceph 19 already. Still with Ceph Ansible `stable-7.0`, BTW... | 16:30 |
ThiagoCMC | =P | 16:30 |
jrosser_ | ThiagoCMC: we have talked about this :) We need to bump OSA caracal to use ceph 18 | 16:43 |
jrosser_ | i was hoping you were going to make a patch for it | 16:43 |
ThiagoCMC | Yep, I know. Just confirming... =P | 16:44 |
jrosser_ | if ceph 19 is in the UCA repos we need to make sure we still pay attention to the apt pinning | 16:44 |
ThiagoCMC | I'm really busy with lots of personal issues going on right now (condo owner is selling the place and kicked me out, so I have to figure this out now, just to begin the issues lol)... :-( | 16:45 |
ThiagoCMC | And yes, Ceph 19 is in UCA for Caracal. | 16:45 |
jrosser_ | if it is difficult i can change the ceph version | 16:46 |
ThiagoCMC | I REALLY want to contribute! But I might need a couple of weeks to sort things out on my side... :-/ | 16:47 |
jrosser_ | switching the ceph version really is just a couple of lines to change, i'll try to take a look at it tomorrow | 16:51 |
spatel | noonedeadpunk I found the problem :) | 16:56 |
spatel | I forgot to set following in keystone.conf | 16:56 |
spatel | [assignment] | 16:56 |
spatel | driver = sql | 16:56 |
noonedeadpunk | yeah, that would explain it :D | 17:05 |
noonedeadpunk | I even clean forgot about ceph bump on ptg :( | 17:06 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-rabbitmq_server master: Add rabbitmq distro install support for EL https://review.opendev.org/c/openstack/openstack-ansible-rabbitmq_server/+/916936 | 17:17 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-rabbitmq_server master: Add distro infra jobs https://review.opendev.org/c/openstack/openstack-ansible-rabbitmq_server/+/914692 | 17:17 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-rabbitmq_server master: Do not pin packages nor install gpgs for distro method https://review.opendev.org/c/openstack/openstack-ansible-rabbitmq_server/+/916938 | 17:22 |
jrosser_ | there is a stack of ops repo docs changes if anyone can look https://review.opendev.org/c/openstack/openstack-ansible-ops/+/916650 | 17:37 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible master: Respect is_management_address for provider_networks https://review.opendev.org/c/openstack/openstack-ansible/+/915195 | 17:40 |
mgariepy | hmm.. https://www.reuters.com/markets/deals/ibm-nearing-buyout-deal-hashicorp-wsj-reports-2024-04-23/ | 19:08 |
jrosser_ | mgariepy: there’s a fork I think already | 19:09 |
jrosser_ | openbao it’s called | 19:11 |
mgariepy | still. | 19:11 |
mgariepy | they will ruin everything :( | 19:11 |
opendevreview | Merged openstack/openstack-ansible-os_skyline master: Add EL distro support and ssl configuration for DB connection https://review.opendev.org/c/openstack/openstack-ansible-os_skyline/+/912370 | 19:15 |
jrosser_ | that’s a fork of vault, I mean | 19:15 |
jrosser_ | and for fun, take a look at who is contributing most to that repo recently….. | 19:15 |
mgariepy | hmm fun | 19:18 |
mgariepy | incus have a new deploy tool | 19:19 |
mgariepy | simple ansible playbook ;) | 19:19 |
opendevreview | Merged openstack/openstack-ansible-os_skyline master: Support large uploads via Skyline https://review.opendev.org/c/openstack/openstack-ansible-os_skyline/+/914149 | 19:23 |
opendevreview | Merged openstack/openstack-ansible-os_nova stable/2023.2: Ensure TLS is enabled properly for cell0 mapping DB connection https://review.opendev.org/c/openstack/openstack-ansible-os_nova/+/916453 | 19:28 |
opendevreview | Merged openstack/openstack-ansible-rabbitmq_server master: Remove RabbitMQ restart when changing policy https://review.opendev.org/c/openstack/openstack-ansible-rabbitmq_server/+/916041 | 19:37 |
Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!