opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible master: Offload network provisionment for AIO to openstack_hosts https://review.opendev.org/c/openstack/openstack-ansible/+/953570 | 06:37 |
---|---|---|
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible master: Offload kernel module management to openstack_hosts https://review.opendev.org/c/openstack/openstack-ansible/+/953685 | 06:38 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible master: Define losetup devices statically rather then dynamically https://review.opendev.org/c/openstack/openstack-ansible/+/953770 | 06:38 |
f0o | noonedeadpunk: sometimes you get so fixated on the high-tech solutions that you entirely forget the low-tech ones. I've already a spanned L2 because of distributed FIPs. I can just slop a /48 on that and expose that as a 2nd network. Sure it's not dualstack but honestly who cares. It's far less headaches than the bgp-shenanigans | 06:56 |
noonedeadpunk | well, if you are passing it to computes, and don't need any routers on it - then yeah | 06:59 |
noonedeadpunk | NDP still does work | 06:59 |
f0o | yeah that's where I'm at right now after drowning in overcomplicated diagrams and just moving the bottleneck from one OVN chassis to another | 07:00 |
noonedeadpunk | but I'd guess you need a different vl;an and then another port to VMs | 07:00 |
f0o | yeah | 07:00 |
f0o | vlans are free :D | 07:00 |
noonedeadpunk | and it could be tricky for sya octavia/magnum/trove | 07:00 |
f0o | octavia is my only concern | 07:00 |
f0o | but if I go with amphora driver instead of ovn it shouldnt care right? | 07:01 |
noonedeadpunk | I frankly never checked if you can have multiple VIP ports there | 07:01 |
noonedeadpunk | like technically - it should be possible, but if it's implemented or not - good question | 07:01 |
f0o | or maybe LBaaS just becomes a v4-only thing alltogether | 07:01 |
noonedeadpunk | or different LBs for v4 v6?:) | 07:02 |
f0o | yeah something like that | 07:02 |
noonedeadpunk | which is kinda waste of resources... but well | 07:02 |
f0o | idk better than the OVN GWChassis rabbithole | 07:02 |
f0o | will lab this a bit prior | 07:03 |
noonedeadpunk | frankly - I tend to agree here | 07:12 |
jrosser | ^ interested in the meaning here? | 07:13 |
noonedeadpunk | I'm not much fan of L3 setup as of today, si8mply due to it being overcomplex and very tricky to debug and understand | 07:13 |
jrosser | dedicated gw chassis == bad? | 07:13 |
noonedeadpunk | no, not really | 07:13 |
noonedeadpunk | but ovn-bgp-agent is not best thing out | 07:14 |
jrosser | this is all in my future so knowing what not to do is ++++ | 07:14 |
noonedeadpunk | or well. maybe too early and too late | 07:14 |
f0o | dedicated gw chassis is alright but it lacks active/active load sharing. Right now it's just sharded allocation. A single tenant can put a lot of stress on them if they start pushing packets a lot which will effect other tenants that happened to be scheduled on the same GW chassis. If OVN would allow ECMP then all chassis could be used in active/active fashion | 07:15 |
noonedeadpunk | just ovn-bgp-agent is really a set of hooks to make L2 oriented OVN deal with L3 | 07:15 |
jrosser | did anyone try ovs offload for a gw chassis | 07:16 |
noonedeadpunk | we can't do that due to ovn-bgp pretty much | 07:16 |
noonedeadpunk | as it all gets ejected into kernel networking right away | 07:17 |
f0o | I tried but apparently my NICs although supported by DPDK and OVS, wouldnt work so the whole thing just collapsed | 07:17 |
opendevreview | Jonathan Rosser proposed openstack/openstack-ansible-os_keystone master: Switch from wsgi script to wsgi module https://review.opendev.org/c/openstack/openstack-ansible-os_keystone/+/955268 | 07:53 |
opendevreview | Jonathan Rosser proposed openstack/openstack-ansible master: Bump SHAs for master https://review.opendev.org/c/openstack/openstack-ansible/+/955226 | 07:53 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible stable/2023.2: Bump SHAs for EOL-ing 2023.2 https://review.opendev.org/c/openstack/openstack-ansible/+/950893 | 07:55 |
opendevreview | Ivan Anfimov proposed openstack/openstack-ansible master: Replaced usage outdate egrep to grep https://review.opendev.org/c/openstack/openstack-ansible/+/953740 | 08:43 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible master: Offload network provisionment for AIO to openstack_hosts https://review.opendev.org/c/openstack/openstack-ansible/+/953570 | 09:30 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible master: Provision AIO network interfaces conditionally https://review.opendev.org/c/openstack/openstack-ansible/+/953574 | 10:36 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-plugins master: Implement post openstack_hosts playbook https://review.opendev.org/c/openstack/openstack-ansible-plugins/+/955280 | 10:47 |
opendevreview | Jonathan Rosser proposed openstack/openstack-ansible-os_magnum master: Switch from wsgi script to wsgi module https://review.opendev.org/c/openstack/openstack-ansible-os_magnum/+/950509 | 12:30 |
opendevreview | Jonathan Rosser proposed openstack/openstack-ansible-os_ironic master: Add apparmor rules for ironic inspector https://review.opendev.org/c/openstack/openstack-ansible-os_ironic/+/951003 | 12:35 |
opendevreview | Ivan Anfimov proposed openstack/ansible-hardening master: Use doc8 for documentation generation https://review.opendev.org/c/openstack/ansible-hardening/+/710284 | 12:50 |
opendevreview | Jonathan Rosser proposed openstack/openstack-ansible-os_ironic master: Switch from wsgi script to wsgi module https://review.opendev.org/c/openstack/openstack-ansible-os_ironic/+/950508 | 12:52 |
opendevreview | Jonathan Rosser proposed openstack/openstack-ansible-os_ironic master: Switch from wsgi script to wsgi module https://review.opendev.org/c/openstack/openstack-ansible-os_ironic/+/950508 | 12:52 |
opendevreview | Ivan Anfimov proposed openstack/ansible-hardening master: Use doc8 for documentation generation https://review.opendev.org/c/openstack/ansible-hardening/+/710284 | 13:06 |
opendevreview | Ivan Anfimov proposed openstack/ansible-hardening master: Use doc8 for documentation generation https://review.opendev.org/c/openstack/ansible-hardening/+/710284 | 13:25 |
opendevreview | Ivan Anfimov proposed openstack/ansible-hardening master: Use doc8 for documentation generation https://review.opendev.org/c/openstack/ansible-hardening/+/710284 | 14:07 |
opendevreview | Ivan Anfimov proposed openstack/ansible-hardening master: Use doc8 for documentation generation https://review.opendev.org/c/openstack/ansible-hardening/+/710284 | 14:07 |
opendevreview | Jonathan Rosser proposed openstack/openstack-ansible-os_ironic master: Switch from wsgi script to wsgi module https://review.opendev.org/c/openstack/openstack-ansible-os_ironic/+/950508 | 16:21 |
opendevreview | Jonathan Rosser proposed openstack/openstack-ansible-os_magnum master: Switch from wsgi script to wsgi module https://review.opendev.org/c/openstack/openstack-ansible-os_magnum/+/950509 | 16:21 |
jrosser | this is going to be a blocker for getting the master sha bump in https://review.opendev.org/c/openstack/openstack-ansible-os_keystone/+/955268 | 16:23 |
jrosser | and looks like we lost the neutron-server service entirely somewhere https://zuul.opendev.org/t/openstack/build/ece7fae953cc44a580038ff54a8b6471/logs | 16:27 |
noonedeadpunk | I think they might have dropped it in favor of uwsgi | 16:46 |
noonedeadpunk | and we switched it back and forth: https://opendev.org/openstack/openstack-ansible-os_neutron/src/branch/master/defaults/main.yml#L196 | 16:47 |
noonedeadpunk | I think we might need to add some more services still to make uwsgi work | 16:47 |
opendevreview | Ivan Anfimov proposed openstack/ansible-hardening master: Use doc8 for documentation generation https://review.opendev.org/c/openstack/ansible-hardening/+/710284 | 16:49 |
opendevreview | Ivan Anfimov proposed openstack/ansible-hardening master: Use doc8 for documentation generation https://review.opendev.org/c/openstack/ansible-hardening/+/710284 | 16:51 |
opendevreview | Damian Dąbrowski proposed openstack/ansible-role-pki master: Rename pki_method variable to pki_default_backend https://review.opendev.org/c/openstack/ansible-role-pki/+/948877 | 17:07 |
opendevreview | Damian Dąbrowski proposed openstack/ansible-role-pki master: Rename pki_method variable to pki_default_backend https://review.opendev.org/c/openstack/ansible-role-pki/+/948877 | 17:07 |
opendevreview | Damian Dąbrowski proposed openstack/openstack-ansible-openstack_hosts master: Pass required vars when installing CA certs https://review.opendev.org/c/openstack/openstack-ansible-openstack_hosts/+/948884 | 17:12 |
opendevreview | Damian Dąbrowski proposed openstack/openstack-ansible-openstack_hosts master: Pass pki_authorities var when installing CA certs https://review.opendev.org/c/openstack/openstack-ansible-openstack_hosts/+/948884 | 17:13 |
jrosser | I still find this default backend var a bit wrong | 17:17 |
jrosser | that name might be more correct for a user when the backend is not overridden per cert | 17:18 |
opendevreview | Damian Dąbrowski proposed openstack/ansible-role-pki master: Add hashi_vault backend https://review.opendev.org/c/openstack/ansible-role-pki/+/948881 | 17:18 |
jrosser | but it’s much more wrong inside the role because it might not actually be the “default” backend if it’s overridden | 17:18 |
jrosser | idk why we don’t just call it pki_backend then it’s in defaults/ and the semantics/purpose are clear | 17:23 |
damiandabrowski | i really don't mind, i can change it | 17:29 |
damiandabrowski | when i thought about it, it was just confusing to call it pki_backend and let users put it into user_variables.yml for example | 17:30 |
damiandabrowski | while the subset of the certificates may use different backend | 17:30 |
opendevreview | Damian Dąbrowski proposed openstack/ansible-role-pki master: Rename pki_method variable to pki_backend https://review.opendev.org/c/openstack/ansible-role-pki/+/948877 | 17:31 |
opendevreview | Damian Dąbrowski proposed openstack/ansible-role-pki master: Rename pki_method variable to pki_backend https://review.opendev.org/c/openstack/ansible-role-pki/+/948877 | 17:36 |
opendevreview | Damian Dąbrowski proposed openstack/ansible-role-pki master: Rename pki_method variable to pki_backend https://review.opendev.org/c/openstack/ansible-role-pki/+/948877 | 17:38 |
opendevreview | Damian Dąbrowski proposed openstack/ansible-role-pki master: Rename pki_method variable to pki_backend https://review.opendev.org/c/openstack/ansible-role-pki/+/948877 | 17:39 |
opendevreview | Merged openstack/ansible-role-pki master: Add python3-setuptools for redhat-10 based distros. https://review.opendev.org/c/openstack/ansible-role-pki/+/954213 | 19:58 |
opendevreview | Ivan Anfimov proposed openstack/ansible-role-pki stable/2025.1: Add python3-setuptools for redhat-10 based distros. https://review.opendev.org/c/openstack/ansible-role-pki/+/955318 | 20:02 |
opendevreview | Merged openstack/ansible-role-pki master: Generate ca_bundle during cert creation for standalone backend https://review.opendev.org/c/openstack/ansible-role-pki/+/954628 | 20:07 |
opendevreview | Ivan Anfimov proposed openstack/ansible-hardening master: Use doc8 for documentation generation https://review.opendev.org/c/openstack/ansible-hardening/+/710284 | 20:08 |
opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-plugins master: Move provider_networks module into os_neutron https://review.opendev.org/c/openstack/openstack-ansible-plugins/+/658130 | 20:21 |
opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-galera_server master: Cannot set fs attributes on a non-existent symlink target https://review.opendev.org/c/openstack/openstack-ansible-galera_server/+/953203 | 20:28 |
opendevreview | Damian Dąbrowski proposed openstack/ansible-role-pki master: Separate backend-specific logic to improve extensibility https://review.opendev.org/c/openstack/ansible-role-pki/+/948878 | 20:51 |
opendevreview | Damian Dąbrowski proposed openstack/ansible-role-pki master: Change the format of 'san' parameter in `pki_certificates` variable https://review.opendev.org/c/openstack/ansible-role-pki/+/948879 | 20:52 |
opendevreview | Damian Dąbrowski proposed openstack/ansible-role-pki master: Change the format of 'san' parameter in `pki_certificates` variable https://review.opendev.org/c/openstack/ansible-role-pki/+/948879 | 20:52 |
opendevreview | Damian Dąbrowski proposed openstack/ansible-role-pki master: Change the format of 'san' parameter in `pki_certificates` variable https://review.opendev.org/c/openstack/ansible-role-pki/+/948879 | 20:56 |
opendevreview | Damian Dąbrowski proposed openstack/ansible-role-pki master: Rename pki_method variable to pki_backend https://review.opendev.org/c/openstack/ansible-role-pki/+/948877 | 20:58 |
opendevreview | Damian Dąbrowski proposed openstack/ansible-role-pki master: Separate backend-specific logic to improve extensibility https://review.opendev.org/c/openstack/ansible-role-pki/+/948878 | 20:59 |
opendevreview | Damian Dąbrowski proposed openstack/ansible-role-pki master: Change the format of 'san' parameter in `pki_certificates` variable https://review.opendev.org/c/openstack/ansible-role-pki/+/948879 | 21:01 |
opendevreview | Damian Dąbrowski proposed openstack/ansible-role-pki master: Use ttl instead of not_after in pki_authorities https://review.opendev.org/c/openstack/ansible-role-pki/+/948880 | 21:01 |
opendevreview | Damian Dąbrowski proposed openstack/ansible-role-pki master: Use ttl instead of not_after in pki_authorities https://review.opendev.org/c/openstack/ansible-role-pki/+/948880 | 21:01 |
opendevreview | Damian Dąbrowski proposed openstack/ansible-role-pki master: Use ttl instead of not_after in pki_authorities https://review.opendev.org/c/openstack/ansible-role-pki/+/948880 | 21:02 |
opendevreview | Damian Dąbrowski proposed openstack/ansible-role-pki master: Add hashi_vault backend https://review.opendev.org/c/openstack/ansible-role-pki/+/948881 | 21:30 |
opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-plugins master: Move provider_networks module into os_neutron https://review.opendev.org/c/openstack/openstack-ansible-plugins/+/658130 | 21:36 |
opendevreview | Damian Dąbrowski proposed openstack/openstack-ansible master: Add support for hashi_vault PKI backend https://review.opendev.org/c/openstack/openstack-ansible/+/948888 | 21:38 |
opendevreview | Damian Dąbrowski proposed openstack/openstack-ansible master: Enable openbao jobs https://review.opendev.org/c/openstack/openstack-ansible/+/948889 | 21:38 |
opendevreview | Damian Dąbrowski proposed openstack/openstack-ansible master: Enable openbao jobs https://review.opendev.org/c/openstack/openstack-ansible/+/948889 | 21:39 |
opendevreview | Damian Dąbrowski proposed openstack/openstack-ansible-os_neutron master: Add hashi_vault pki backend support https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/949420 | 22:25 |
opendevreview | Damian Dąbrowski proposed openstack/ansible-role-pki master: Separate backend-specific logic to improve extensibility https://review.opendev.org/c/openstack/ansible-role-pki/+/948878 | 22:31 |
opendevreview | Damian Dąbrowski proposed openstack/ansible-role-pki master: Change the format of 'san' parameter in `pki_certificates` variable https://review.opendev.org/c/openstack/ansible-role-pki/+/948879 | 22:31 |
opendevreview | Damian Dąbrowski proposed openstack/ansible-role-pki master: Use ttl instead of not_after in pki_authorities https://review.opendev.org/c/openstack/ansible-role-pki/+/948880 | 22:32 |
opendevreview | Damian Dąbrowski proposed openstack/ansible-role-pki master: Add hashi_vault backend https://review.opendev.org/c/openstack/ansible-role-pki/+/948881 | 22:32 |
opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-plugins master: Move provider_networks module into os_neutron https://review.opendev.org/c/openstack/openstack-ansible-plugins/+/658130 | 23:09 |
Generated by irclog2html.py 4.0.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!