noonedeadpunk | NeilHanlon: hm, are you sure about EL10? as I don't see build? https://koji.fedoraproject.org/koji/packageinfo?packageID=30906 | 05:59 |
---|---|---|
noonedeadpunk | should it be another request to build it? | 05:59 |
noonedeadpunk | I also wonder how this did work actually: https://opendev.org/openstack/ansible-role-systemd_networkd/src/branch/master/vars/redhat-9.yml#L34 | 06:01 |
-opendevstatus- NOTICE: the gerrit service (https://review.opendev.org) is currently down, please be patient while we work on restoring it | 07:33 | |
noonedeadpunk | I think it might be worth to write a doc around our pki role as well, so that we could replace this tripleO guide for instance: https://docs.openstack.org/project-deploy-guide/tripleo-docs/latest/features/tls-everywhere.html | 10:21 |
noonedeadpunk | which is referenced in https://docs.openstack.org/project-deploy-guide/tripleo-docs/latest/features/tls-everywhere.html | 10:22 |
frickler | that was the same URL twice? | 10:23 |
noonedeadpunk | oh, sorry | 10:23 |
noonedeadpunk | second meant to be https://docs.openstack.org/nova/latest/admin/secure-live-migration-with-qemu-native-tls.html | 10:23 |
noonedeadpunk | “TLS everywhere” link | 10:24 |
noonedeadpunk | as pki role is quite osa-agnostic and we use it internally as well. so it could be a fit for replacement which does not have havile dependence on deployment tooling | 10:25 |
noonedeadpunk | or just do openssl cli guide... | 10:25 |
frickler | maybe https://docs.openstack.org/security-guide/secure-communication.html would be a good generic location. but then I'm not sure how much refreshing that whole guide would be needing | 10:34 |
noonedeadpunk | oh, actually this might be a realy good one | 10:35 |
noonedeadpunk | I guess if add as a separate section, it might not need refactoring? | 10:36 |
frickler | that might work, yes | 10:37 |
darkhackernc | https://bugs.launchpad.net/openstack-ansible/+bug/2116934 | 11:12 |
noonedeadpunk | darkhackernc: not sure if that paste issuue or not, but you seems have an indent issue for manila_backends | 11:13 |
darkhackernc | noonedeadpunk, let me double check | 11:14 |
darkhackernc | yeah, you are right | 11:15 |
darkhackernc | changed, let me rerun | 11:15 |
darkhackernc | noonedeadpunk, thanks, deployment moved, breaking at other point | 11:26 |
-opendevstatus- NOTICE: the gerrit service (https://review.opendev.org) is back up. We believe the restoration is complete. If you notice any issues please report them in #opendev ASAP | 11:54 | |
darkhackernc | noonedeadpunk, https://bugs.launchpad.net/openstack-ansible/+bug/2116934 can you check, user is not creating and permission issue, manually setting up fixed the issue, | 12:00 |
darkhackernc | do we need to hardcode this as well like octavia? | 12:00 |
noonedeadpunk | not sure what do you mean under "this" | 12:42 |
opendevreview | Jonathan Rosser proposed openstack/ansible-role-pki master: Allow certificates to be installed by specifying them by name https://review.opendev.org/c/openstack/ansible-role-pki/+/954239 | 12:45 |
noonedeadpunk | #startmeeting openstack_ansible_meeting | 15:00 |
opendevmeet | Meeting started Tue Jul 15 15:00:45 2025 UTC and is due to finish in 60 minutes. The chair is noonedeadpunk. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:00 |
opendevmeet | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:00 |
opendevmeet | The meeting name has been set to 'openstack_ansible_meeting' | 15:00 |
noonedeadpunk | #topic rollcall | 15:00 |
noonedeadpunk | o/ hey there | 15:00 |
DavidGomez | o/ | 15:01 |
damiandabrowski | hi! | 15:04 |
noonedeadpunk | #topic office hours | 15:04 |
noonedeadpunk | so, I think the first thing I wanted to raise is review state overall - we have quite some things waiting for approval, including some bug fixes | 15:05 |
damiandabrowski | ack, I'll have a look | 15:05 |
jrosser | o/ hello | 15:06 |
jrosser | we really do need more activity on reviews all the time | 15:07 |
jrosser | as noonedeadpunk and i seem to make a lot of patches and do a lot of reviews we can't merge each others stuff alone | 15:07 |
noonedeadpunk | right | 15:08 |
noonedeadpunk | unless we change the project rules | 15:08 |
noonedeadpunk | which would be better to avoid | 15:08 |
noonedeadpunk | but I'm getting tempted from time to time to be frank | 15:08 |
jrosser | andrew will be back in ~1 week | 15:09 |
noonedeadpunk | ┌(° ͜ʖ͡°)┘ | 15:09 |
noonedeadpunk | ok, then I'll manage my temptation :) | 15:10 |
noonedeadpunk | I see some work has started on adding Debian 13 job? | 15:10 |
noonedeadpunk | though we have an issue in hardening module | 15:10 |
noonedeadpunk | and python 13 compatability | 15:10 |
noonedeadpunk | 3.14=3 ofc, sorry | 15:12 |
noonedeadpunk | * 3.13 | 15:12 |
jrosser | i have it in a vm here | 15:13 |
jrosser | there is a super strange pip error in the patch i pushed that i dont understqand | 15:13 |
jrosser | and i dont get locally | 15:13 |
noonedeadpunk | also, it seems that C10S at least nodesets are around | 15:15 |
noonedeadpunk | so probably we should check on adding CI for it as well | 15:15 |
noonedeadpunk | at least from what I see in kolla recent patches: https://review.opendev.org/c/openstack/kolla/+/950392/78/.zuul.d/centos.yaml | 15:15 |
noonedeadpunk | (I was searching for rocky10 though in gerrit) | 15:15 |
noonedeadpunk | I think that LXC was built for EPEL testing at least | 15:16 |
noonedeadpunk | https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-87f14463e7 | 15:16 |
noonedeadpunk | interestingly, it seems that EL is gonna have more modern LXC then Noble does | 15:17 |
noonedeadpunk | jrosser: what lxc is shipped in debian - did you checked? | 15:17 |
noonedeadpunk | or can you if have VM handy :) | 15:18 |
jrosser | yeah one moment | 15:18 |
jrosser | carry on whist i look :) | 15:18 |
noonedeadpunk | sure | 15:18 |
noonedeadpunk | Do we have any updates or smth to discuss on PKI topic? | 15:19 |
noonedeadpunk | damiandabrowski: ? | 15:19 |
damiandabrowski | I'm working on the things we agreed on and testing them on my AIO | 15:20 |
jrosser | i have left the os_glance change as an example for where we might start the vault stuff | 15:20 |
damiandabrowski | so nothing to discuss, until I push updates to my patches :D | 15:20 |
damiandabrowski | https://review.opendev.org/c/openstack/openstack-ansible-os_glance/+/954269 | 15:21 |
damiandabrowski | yeah I saw, thanks a lot | 15:21 |
noonedeadpunk | ok, cool, then no obvious blockers so far at least :) | 15:22 |
noonedeadpunk | and this is pki-side patch, I assume | 15:22 |
jrosser | debian 13 lxc `Installed: 1:6.0.4-4+b1` | 15:23 |
noonedeadpunk | btw, just today I was thinking if we should add some better documentation around the role with real-life examples, like generating certs for libvirt/nova, if to use it as a standalone role | 15:23 |
noonedeadpunk | ok, so it's the same with what C10S and EL10 gonna have | 15:23 |
noonedeadpunk | just noble seems to be still on 5 | 15:24 |
noonedeadpunk | so I was a bit curious how badly 6 gonna break | 15:24 |
jrosser | as far as lxc goes it did just work (+/- a few bugfixes i pushed) on trixie | 15:24 |
jrosser | but those are our bugs in ansible code | 15:24 |
noonedeadpunk | right | 15:25 |
noonedeadpunk | Should we be mergning https://review.opendev.org/c/openstack/openstack-ansible-plugins/+/954976 now? | 15:26 |
noonedeadpunk | As it's more of - get all patches out vs start merging things regardless | 15:27 |
noonedeadpunk | don't have anything against any approach, just checking how you wanna handle that | 15:29 |
jrosser | it might not hurt, we can merge that even if trixie is experimental/broken | 15:29 |
NeilHanlon | bleh, sorry.. distracted today | 15:30 |
noonedeadpunk | I kinda wonder, if we might actually do a list of OS as a variable.... | 15:30 |
noonedeadpunk | so that to be able to override in AIO/CI, but not allow in actual deployments | 15:31 |
NeilHanlon | regarding systemd-extras for el10: yes we should request it if not there. I'd asked about el9 specifically to the group and sorta assumed it was there for 10, too.. I can file that request quickly on my laptop | 15:31 |
NeilHanlon | regarding how the includepkgs: systemd-networkd from EPEL worked/works, it's because the package is "provided" by the systemd-extras, so it's addressable in it's own right. similar to how normally the `systemd` package provides all it's subcomponents | 15:32 |
NeilHanlon | also hi :) o/ | 15:32 |
noonedeadpunk | aha, ok, makes sense then | 15:32 |
noonedeadpunk | but I kinda wonder from standpoint of ecosystem... Why would epel need having it, if it's in SIG? | 15:33 |
noonedeadpunk | Or SIGs are only CentOS oriented? | 15:33 |
noonedeadpunk | and EPEL is also EL? | 15:33 |
NeilHanlon | well the Hyperscale SIG itself is only focused on centos stream | 15:33 |
NeilHanlon | so they wouldn't "allow" a build for systemd atop RHEL (and friends) in that SIG | 15:33 |
noonedeadpunk | I just kinda a little bit confused about versions provided by these | 15:33 |
NeilHanlon | so it'd have to be another SIG like cloud or nfv | 15:34 |
noonedeadpunk | aha, ok | 15:34 |
NeilHanlon | or, a rocky sig. or epel | 15:34 |
NeilHanlon | cause epel is against RHEL build roots, not Stream ones | 15:34 |
noonedeadpunk | so like epel shouldn't say smth like - go and use hyperscale sig now? | 15:34 |
NeilHanlon | no cause EPEL is maintaining compatibility with RHEL, not Stream | 15:35 |
noonedeadpunk | ok, then I think having a request to build networkd for el10 would be really nice | 15:35 |
NeilHanlon | 👍i'm gonna put in the request | 15:35 |
noonedeadpunk | amazing, thanks! | 15:35 |
NeilHanlon | looks like there's already one in: https://bugzilla.redhat.com/show_bug.cgi?id=2303892 | 15:36 |
NeilHanlon | i'll poke rsc about it | 15:36 |
noonedeadpunk | yeah, it didn't go too far :( | 15:36 |
noonedeadpunk | lxc in it's turn should be around anytime I guess | 15:38 |
noonedeadpunk | mariadb has builders for both rocky and c10s, but they did not build packages yet... | 15:39 |
noonedeadpunk | and I wouldn't exepct any until next minor version is out | 15:39 |
NeilHanlon | yep i need to test the lxc packages and give them some karma so they will move thru faster | 15:40 |
noonedeadpunk | so next mariadb release is planned on July 24th if my eyes don't fail me | 15:41 |
NeilHanlon | i believe ya | 15:42 |
noonedeadpunk | so I think once we solve CI/LXC/MariaDB we can tell about EL10 support also on Epoxy | 15:43 |
noonedeadpunk | but will see :) | 15:43 |
noonedeadpunk | and systemd ofc | 15:43 |
noonedeadpunk | so 4 things | 15:43 |
noonedeadpunk | I will try to poke at CI sometime this week | 15:44 |
NeilHanlon | sweet :) | 15:45 |
NeilHanlon | i'm gonna work on ceph this week... promise | 15:45 |
noonedeadpunk | even lxc is probably not a blocker, as we getting it from your corp | 15:45 |
noonedeadpunk | *copr | 15:45 |
noonedeadpunk | ok, great then :) | 15:46 |
noonedeadpunk | there's also one topic about magnum and capi drivers which was raised yesterday | 15:47 |
noonedeadpunk | as there's really good chance to get compatability with azimuth driver quite easy | 15:47 |
noonedeadpunk | though some minor changes, except capo>=0.12, to collection which produces control cluster would be needed | 15:48 |
noonedeadpunk | will try to check on that during these weekeends | 15:49 |
noonedeadpunk | and then - we can move out capi parts from ops repo | 15:49 |
noonedeadpunk | as I think magnum was gonna drop heat driver this cycle | 15:49 |
noonedeadpunk | so we should be right in time :) | 15:51 |
NeilHanlon | wonderful :D | 15:53 |
noonedeadpunk | anything else we wanna discuss? | 15:54 |
NeilHanlon | nothing from me i don't think | 15:54 |
jrosser | no, i dont think so | 15:56 |
noonedeadpunk | ok, then thanks everyone for taking time and for your contributions :) | 15:56 |
noonedeadpunk | #endmeeting | 15:56 |
opendevmeet | Meeting ended Tue Jul 15 15:56:36 2025 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:56 |
opendevmeet | Minutes: https://meetings.opendev.org/meetings/openstack_ansible_meeting/2025/openstack_ansible_meeting.2025-07-15-15.00.html | 15:56 |
opendevmeet | Minutes (text): https://meetings.opendev.org/meetings/openstack_ansible_meeting/2025/openstack_ansible_meeting.2025-07-15-15.00.txt | 15:56 |
opendevmeet | Log: https://meetings.opendev.org/meetings/openstack_ansible_meeting/2025/openstack_ansible_meeting.2025-07-15-15.00.log.html | 15:56 |
Generated by irclog2html.py 4.0.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!