opendevreview | Merged openstack/ansible-role-systemd_mount master: Allow to avoid mount names escaping https://review.opendev.org/c/openstack/ansible-role-systemd_mount/+/951889 | 00:20 |
---|---|---|
opendevreview | Merged openstack/openstack-ansible-openstack_openrc master: tox: Remove ineffective ignore_basepython_conflict and bump minimum version https://review.opendev.org/c/openstack/openstack-ansible-openstack_openrc/+/954735 | 06:02 |
opendevreview | Merged openstack/openstack-ansible-os_masakari master: tox: Remove ineffective ignore_basepython_conflict and bump minimum version https://review.opendev.org/c/openstack/openstack-ansible-os_masakari/+/954866 | 06:03 |
opendevreview | Merged openstack/openstack-ansible-plugins master: tox: Remove ineffective ignore_basepython_conflict and bump minimum version https://review.opendev.org/c/openstack/openstack-ansible-plugins/+/954740 | 06:05 |
opendevreview | Merged openstack/openstack-ansible-memcached_server master: tox: Remove ineffective ignore_basepython_conflict and bump minimum version https://review.opendev.org/c/openstack/openstack-ansible-memcached_server/+/954729 | 06:05 |
opendevreview | Merged openstack/openstack-ansible-lxc_container_create master: tox: Remove ineffective ignore_basepython_conflict and bump minimum version https://review.opendev.org/c/openstack/openstack-ansible-lxc_container_create/+/954731 | 06:07 |
opendevreview | Merged openstack/openstack-ansible-repo_server master: tox: Remove ineffective ignore_basepython_conflict and bump minimum version https://review.opendev.org/c/openstack/openstack-ansible-repo_server/+/954737 | 06:07 |
opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_neutron master: wip https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/955344 | 08:04 |
opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_neutron master: wip https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/955344 | 08:08 |
opendevreview | Takashi Kajinami proposed openstack/openstack-ansible-os_ceilometer master: Drop zake https://review.opendev.org/c/openstack/openstack-ansible-os_ceilometer/+/955351 | 09:30 |
opendevreview | Takashi Kajinami proposed openstack/openstack-ansible-os_ceilometer master: Drop removed options https://review.opendev.org/c/openstack/openstack-ansible-os_ceilometer/+/955352 | 09:35 |
opendevreview | Takashi Kajinami proposed openstack/openstack-ansible-os_aodh master: Drop unused [api] port https://review.opendev.org/c/openstack/openstack-ansible-os_aodh/+/955353 | 09:39 |
opendevreview | Merged openstack/ansible-hardening master: Replaced usage outdate egrep to grep https://review.opendev.org/c/openstack/ansible-hardening/+/955242 | 09:45 |
opendevreview | Merged openstack/ansible-hardening master: Use doc8 for documentation generation https://review.opendev.org/c/openstack/ansible-hardening/+/710284 | 09:45 |
opendevreview | Dmitriy Chubinidze proposed openstack/openstack-ansible-lxc_hosts master: Add nano and wget to the default package set for LXC hosts. https://review.opendev.org/c/openstack/openstack-ansible-lxc_hosts/+/955366 | 12:19 |
opendevreview | Dmitriy Chubinidze proposed openstack/openstack-ansible-lxc_hosts master: Add nano and wget to the default package set for LXC hosts. https://review.opendev.org/c/openstack/openstack-ansible-lxc_hosts/+/955366 | 12:26 |
gillesMo | Hello ! On the upgrade docs https://docs.openstack.org/openstack-ansible/2025.1/admin/upgrades/major-upgrades.html we still can see the 31.0.0.0rc1 Git Tag. We are ready to upgrade from 2023.1 to 2024.1, and then I want to go to 2025.1, but is OSA production ready for Epoxy ? | 13:06 |
jrosser | noonedeadpunk: damiandabrowski i only really just realised that the hashi vault PKI backend is keeping the private key in vault rather than signing a CSR, is that what we want? | 13:06 |
jrosser | it was probably a mistake to make the standalone backend not do that initially | 13:07 |
damiandabrowski | hmm, are you sure about that? I'm not an expert in this area, but from what I see, only private key to the intermediate CA is stored in vault | 13:10 |
damiandabrowski | but it's needed to sign service certs | 13:10 |
damiandabrowski | but private key for service certs shouldn't be stored in vault | 13:10 |
damiandabrowski | i just send you PM with credentials to openbao on my AIO test VM if you want to have a look what is actually stored there | 13:12 |
jrosser | https://developer.hashicorp.com/vault/api-docs/secret/pki#sample-response-2 | 13:12 |
damiandabrowski | yeah, you receive private key in API response, but it's not stored in Vault | 13:16 |
jrosser | that does not make much sense | 13:20 |
jrosser | isnt that the difference between the /issue/ and /sign/ api endpoints in vault | 13:21 |
damiandabrowski | the difference is: with issue you don't have to generate CSR and key on your own, you can just pass for example CN of your cert to the vault. | 13:26 |
damiandabrowski | all other parameters, like extended key usage, TTL etc. are controlled by the Vault's role. | 13:27 |
opendevreview | Damian DÄ…browski proposed openstack/ansible-role-pki master: Add hashi_vault backend https://review.opendev.org/c/openstack/ansible-role-pki/+/948881 | 14:38 |
damiandabrowski | jrosser: noonedeadpunk I think we're ready for another round of reviews https://review.opendev.org/q/topic:%22osa_hashi_vault%22 | 15:04 |
damiandabrowski | if we agree on variables defined in service roles, I can start patching service roles | 15:05 |
damiandabrowski | currently, only neutron is aligned with the most recent concept of using type and name for *_install_certificates | 15:07 |
damiandabrowski | https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/949420 | 15:07 |
jrosser | i left some comments | 15:22 |
damiandabrowski | thanks | 15:29 |
opendevreview | Merged openstack/ansible-role-systemd_mount master: Allow to define only overrides for mounts https://review.opendev.org/c/openstack/ansible-role-systemd_mount/+/951891 | 18:12 |
-opendevstatus- NOTICE: The Gerrit service on review.opendev.org will be offline briefly for a configuration and version update, but should return to service momentarily | 20:05 |
Generated by irclog2html.py 4.0.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!