Friday, 2018-11-02

guilhermesphello everyone! so I'm from openstack-ansible team :)00:02
guilhermespwell, as placement is not part of the nova than, we are going to create an openstack-ansible-os_placement role.00:02
guilhermespI'm following that guide to add the project to the openstack ci00:03
guilhermesphttps://docs.openstack.org/infra/manual/creators.html#add-the-project-to-the-master-projects-list00:03
guilhermespjust to confirm, that's the repo to add the project, isn't it? https://review.openstack.org/#/admin/projects/openstack-infra/project-config00:03
tonybclarkb: any chance you can +1 https://review.openstack.org/#/c/614887/00:04
clarkbtonyb: done00:05
tonybclarkb: Thanks00:06
clarkbguilhermesp: yes that is the repo to modify00:06
clarkbguilhermesp: our automation picks up changes to that repo then updates gerrit based on those changes00:06
guilhermespthanks clarkb ! I'm just trying to pick every information about the whole process :) Hopefully I can use another osa projects as a reference to kick of the placement role00:07
guilhermespyeah, seems straight forward as we have a bunch of osa projects, they all share the same acls00:12
*** hongbin has joined #openstack-infra00:17
*** ssbarnea has quit IRC00:25
openstackgerritTony Breeds proposed openstack-infra/irc-meetings master: add tc meetings  https://review.openstack.org/60868200:33
openstackgerritTony Breeds proposed openstack-infra/irc-meetings master: Use yaml2ical 0.9.0 to get monthly events  https://review.openstack.org/61489200:33
openstackgerritIan Wienand proposed openstack-infra/system-config master: [wip] test against ansible master  https://review.openstack.org/61489400:41
*** longkb has joined #openstack-infra00:44
openstackgerritIan Wienand proposed openstack-infra/system-config master: [wip] test against ansible master  https://review.openstack.org/61489400:49
openstackgerritIan Wienand proposed openstack-infra/system-config master: [wip] test against ansible master  https://review.openstack.org/61489400:56
openstackgerritGuilherme  Steinmuller Pimentel proposed openstack-infra/project-config master: Add os_placement role to OpenStack-Ansible  https://review.openstack.org/61489600:59
*** agopi|pto is now known as agopi|off01:11
openstackgerritIan Wienand proposed openstack-infra/system-config master: [wip] test against ansible master  https://review.openstack.org/61489401:12
*** zhangfei has joined #openstack-infra01:15
*** diablo_rojo has quit IRC01:16
openstackgerritIan Wienand proposed openstack-infra/system-config master: [wip] test against ansible master  https://review.openstack.org/61489401:30
openstackgerritGuilherme  Steinmuller Pimentel proposed openstack-infra/project-config master: Add os_placement role to OpenStack-Ansible  https://review.openstack.org/61489601:30
openstackgerritGuilherme  Steinmuller Pimentel proposed openstack-infra/project-config master: Add os_placement role to OpenStack-Ansible  https://review.openstack.org/61489601:32
*** hongbin has quit IRC01:32
openstackgerritIan Wienand proposed openstack-infra/system-config master: [wip] test against ansible master  https://review.openstack.org/61489402:00
*** hongbin has joined #openstack-infra02:12
*** carl_cai has joined #openstack-infra02:13
openstackgerritIan Wienand proposed openstack-infra/system-config master: [wip] test against ansible master  https://review.openstack.org/61489402:18
*** yamamoto has joined #openstack-infra02:31
openstackgerritIan Wienand proposed openstack-infra/system-config master: [wip] test against ansible master  https://review.openstack.org/61489402:33
*** xarses_ has joined #openstack-infra02:36
*** bobh has joined #openstack-infra02:37
*** jamesmcarthur has joined #openstack-infra02:43
openstackgerritIan Wienand proposed openstack-infra/system-config master: [wip] test against ansible master  https://review.openstack.org/61489402:43
*** jamesmcarthur has quit IRC02:44
*** jamesmcarthur has joined #openstack-infra02:45
*** mrsoul has joined #openstack-infra02:51
*** bobh has quit IRC02:57
openstackgerritTristan Cacqueray proposed openstack-infra/zuul master: web: uses queues uid to preserve state on change  https://review.openstack.org/61493302:59
*** bhavikdbavishi has joined #openstack-infra02:59
*** eernst has joined #openstack-infra03:01
*** eernst has quit IRC03:08
*** yamamoto has quit IRC03:09
*** yamamoto has joined #openstack-infra03:09
*** yamamoto has quit IRC03:09
tonybIn the past the irc-meetings-tox-ical job in irc-meetings just to copy generated html and iCal files ontp the logs server so we could check the thinsg looked about right.03:21
tonybWhat's the right way to do that again?  Is there a role I can add to the job?03:21
*** jamesmcarthur has quit IRC03:25
*** jamesmcarthur has joined #openstack-infra03:26
*** yamamoto has joined #openstack-infra03:30
*** jamesmcarthur has quit IRC03:39
*** ramishra has joined #openstack-infra03:50
openstackgerritIan Wienand proposed openstack-infra/system-config master: Pin bridge.o.o to ansible 2.7.0, add devel testing job  https://review.openstack.org/61489403:51
*** udesale has joined #openstack-infra03:56
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Configure opendev nameservers using ansible  https://review.openstack.org/61487003:56
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Move start_services to all.yaml  https://review.openstack.org/61495904:00
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Remove start_services  https://review.openstack.org/61496104:02
*** bhavikdbavishi1 has joined #openstack-infra04:07
*** david-lyle has joined #openstack-infra04:08
*** bhavikdbavishi has quit IRC04:09
*** dklyle has quit IRC04:09
*** bhavikdbavishi1 is now known as bhavikdbavishi04:09
*** auristor has quit IRC04:10
*** toabctl has quit IRC04:13
*** toabctl has joined #openstack-infra04:14
*** hongbin has quit IRC04:17
*** ykarel|away has joined #openstack-infra04:24
openstackgerritKim Bao Long proposed openstack-infra/ansible-role-puppet master: Update min tox version to 2.0  https://review.openstack.org/61497004:34
*** zhangfei has quit IRC04:47
*** ykarel|away is now known as ykarel04:47
*** janki has joined #openstack-infra04:48
*** zhangfei has joined #openstack-infra04:57
*** Keitaro has quit IRC05:03
*** carl_cai has quit IRC05:22
*** auristor has joined #openstack-infra05:26
*** threestrands has quit IRC05:40
*** kjackal has joined #openstack-infra05:45
*** quiquell|off is now known as quiquell06:07
*** ykarel is now known as ykarel|afk06:21
*** ramishra has quit IRC06:22
*** dpawlik has joined #openstack-infra06:26
*** dpawlik has quit IRC06:26
*** dpawlik has joined #openstack-infra06:27
*** apetrich has quit IRC06:27
*** ykarel|afk has quit IRC06:31
*** ykarel|afk has joined #openstack-infra06:31
openstackgerritKim Bao Long proposed openstack-infra/system-config master: Update the min version of tox to 2.0  https://review.openstack.org/61502306:40
*** annp has joined #openstack-infra06:43
*** apetrich has joined #openstack-infra06:43
*** udesale has quit IRC06:49
openstackgerritKim Bao Long proposed openstack-infra/storyboard-webclient master: Update the min version of tox to 2.0  https://review.openstack.org/61503506:49
*** ramishra has joined #openstack-infra06:53
openstackgerritVieri proposed openstack/os-performance-tools master: Update min tox version to 2.0  https://review.openstack.org/61504506:58
*** erlon has joined #openstack-infra07:14
*** gbutnaru has quit IRC07:15
*** pcaruana has joined #openstack-infra07:20
*** Douhet has quit IRC07:22
*** Douhet has joined #openstack-infra07:22
*** auristor has quit IRC07:24
*** Douhet has quit IRC07:33
*** ccamacho has joined #openstack-infra07:34
*** auristor has joined #openstack-infra07:35
*** Douhet has joined #openstack-infra07:37
*** lennyb has quit IRC07:39
*** lennyb has joined #openstack-infra07:40
*** armax has quit IRC07:43
*** ramishra has quit IRC07:46
*** ramishra has joined #openstack-infra07:53
*** kjackal has quit IRC07:55
*** coolsvap has joined #openstack-infra07:55
openstackgerritVieri proposed openstack-dev/specs-cookiecutter master: Update min tox version to 2.0  https://review.openstack.org/61508307:57
*** ykarel|afk is now known as ykarel08:11
*** slaweq has joined #openstack-infra08:17
*** bhavikdbavishi has quit IRC08:25
*** ralonsoh has joined #openstack-infra08:26
*** kjackal has joined #openstack-infra08:29
*** betherly has joined #openstack-infra08:30
openstackgerritMerged openstack/diskimage-builder master: Add systemd-containers functional tests  https://review.openstack.org/61405108:37
*** florianf|afk is now known as florianf08:40
*** bauzas is now known as bauwser08:52
*** jpich has joined #openstack-infra09:00
*** xek__ has joined #openstack-infra09:08
*** shrasool has joined #openstack-infra09:11
*** erlon has quit IRC09:13
*** ssbarnea has joined #openstack-infra09:15
*** ykarel_ has joined #openstack-infra09:20
*** ykarel has quit IRC09:23
*** derekh has joined #openstack-infra09:25
*** dpawlik has quit IRC09:28
*** ykarel_ is now known as ykarel09:31
*** ykarel_ has joined #openstack-infra09:34
*** ykarel_ has quit IRC09:35
*** ykarel has quit IRC09:36
quiquellGood morning09:41
quiquellDo we have a URL with the centos7 images we use at zuul ?09:41
*** zhangfei has quit IRC09:42
eumel8o/09:43
eumel8something is broken on the user-survey: https://www.openstack.org/user-survey/09:43
eumel8seems like database backend issue09:43
*** dtantsur|afk is now known as dtantsur09:48
*** e0ne has joined #openstack-infra09:51
*** udesale has joined #openstack-infra09:53
*** shrasool has quit IRC09:54
openstackgerritPavlo Shchelokovskyy proposed openstack/diskimage-builder master: Disable tgt service under systemd for ironic-agent  https://review.openstack.org/61511909:54
*** ykarel has joined #openstack-infra09:55
bauwserAJaeger: morning09:55
bauwserttx: morning too09:55
bauwserAJaeger: ttx: something got messed up with the website09:56
bauwserhttps://www.openstack.org/summit/berlin-2018/ gives me a weird "SilverStripe Framework requires a $databaseConfig defined."09:56
bauwserttx: AJaeger: previously, I got a connection refused so I suspect someone is looking at it anyway09:57
eumel8bauwser: had the same09:59
ttxyes confirmed. Will ping internally10:00
eumel8maybe frickler can help, or other from the EU team10:00
bauwserttx: ack, thanks10:01
bauwsercontext: it was for subscribing for the pub crawl event10:01
*** shrasool has joined #openstack-infra10:01
bauwsertl;dr : beer triggered monitoring system10:01
bauwsersubscribing to*10:01
ttxaffects all of www.openstack.org -- that's not run by the infra team10:02
bauwserttx: ack, gtk10:02
bauwser(oh btw. bauwser == bauzas on Fridays)10:02
ttxthanks for flagging it!10:02
bauwserttx: I was thinking code was hosted by infra?10:03
frickleryeah, nothing I can do about that site I fear, will need some foundation folks10:03
bauwserbut infra isn't, gotcha10:03
*** panda|off is now known as panda10:03
*** jamesmcarthur has joined #openstack-infra10:05
*** jamesmcarthur has quit IRC10:09
*** annp has quit IRC10:10
*** sshnaidm|off has quit IRC10:10
*** shrasool has quit IRC10:11
*** shrasool has joined #openstack-infra10:14
*** sshnaidm has joined #openstack-infra10:14
eumel8ok10:16
openstackgerritMerged openstack-infra/irc-meetings master: Use yaml2ical 0.9.0 to get monthly events  https://review.openstack.org/61489210:16
shrasoolthe website is also “SilverStripe Framework requires a $databaseConfig defined.”10:17
*** quiquell is now known as quiquell|brb10:17
*** sshnaidm is now known as sshnaidm|off10:24
*** yamamoto has quit IRC10:24
*** EmilienM is now known as EvilienM10:25
*** yamamoto has joined #openstack-infra10:28
*** owalsh_ is now known as owalsh10:30
*** alexchadin has joined #openstack-infra10:36
*** alexchadin has quit IRC10:37
*** alexchadin has joined #openstack-infra10:37
*** alexchadin has quit IRC10:37
*** alexchadin has joined #openstack-infra10:38
*** alexchadin has quit IRC10:38
*** alexchadin has joined #openstack-infra10:39
*** agopi|off has quit IRC10:39
*** alexchadin has quit IRC10:39
*** agopi|off has joined #openstack-infra10:39
*** udesale has quit IRC10:40
*** mgoddard has joined #openstack-infra10:41
mgoddardmorning, could someone add me to the tenks-core group in Gerrit?10:41
*** agopi|off has quit IRC10:43
*** stephenfin is now known as finucannot10:44
finucannotI'd love it if someone could finish reviewing https://review.openstack.org/#/q/topic:story/1130330+(status:open+OR+status:merged) so we could get it in a release. It's killing me downstream, where our bug reports naturally have a different number10:46
finucannotclarkb: Any progress on nominating new cores for git-review? ^_^10:47
*** quiquell|brb is now known as quiquell10:48
*** longkb has quit IRC10:50
*** shrasool has quit IRC10:59
*** electrofelix has joined #openstack-infra11:00
*** shrasool has joined #openstack-infra11:01
*** erlon has joined #openstack-infra11:06
fricklermgoddard: I cannot seem to find that group, do you have a reference to a patch that should have caused it to be created?11:08
mgoddardfrickler: it's a new project, added to project-config via https://review.openstack.org/#/c/600397/2. I can see the group in the gerrit group list but it currently has no members11:09
fricklerttx: do you have some feedback from the foundation regarding www or will we have to wait for US folks to be awake? I'm wondering whether we should push a status notice11:09
fricklermgoddard: ah, right, I shouldn't look for it under "My groups" ;) ... added you as a member11:12
mgoddardfrickler: heh, that caught me out first time around. Thanks11:12
*** shrasool has quit IRC11:13
*** shrasool has joined #openstack-infra11:16
*** alexchadin has joined #openstack-infra11:17
ttxfrickler: haven't got a response yet. We have a group in South America that is usually awake earlier but I suspect this is a holiday where they are11:18
ttxI don't think the infra team should put out a notice for an outage on a system they don't operate :)11:19
*** alexchadin has quit IRC11:22
*** lpetrut has joined #openstack-infra11:32
*** yamamoto has quit IRC11:33
eumel8ttx: it seems it's working again11:34
ttxlikely a lost connection to the DB instance11:35
*** yamamoto has joined #openstack-infra11:39
*** kjackal has quit IRC11:43
*** yamamoto has quit IRC11:48
openstackgerritVieri proposed openstack-infra/irc-meetings master: Update min tox version to 2.0  https://review.openstack.org/61513911:48
eumel8ttx: would be good to know how  we can report such kind of issues in the future without disturbing the infra team :)11:49
openstackgerritVieri proposed openstack-infra/os-loganalyze master: Update min tox version to 2.0  https://review.openstack.org/61514211:51
openstackgerritVieri proposed openstack-infra/openstackid master: Update min tox version to 2.0  https://review.openstack.org/61514311:52
openstackgerritVieri proposed openstack-infra/gear master: Update min tox version to 2.0  https://review.openstack.org/61514411:52
*** alexchadin has joined #openstack-infra11:53
openstackgerritVieri proposed openstack-infra/storyboard-webclient master: Update min tox version to 2.0  https://review.openstack.org/61514511:53
openstackgerritVieri proposed openstack-infra/germqtt master: Update min tox version to 2.0  https://review.openstack.org/61514611:54
openstackgerritVieri proposed openstack-infra/lpmqtt master: Update min tox version to 2.0  https://review.openstack.org/61514711:55
openstackgerritVieri proposed openstack-infra/zuul-base-jobs master: Update min tox version to 2.0  https://review.openstack.org/61514811:56
openstackgerritVieri proposed openstack-infra/python-storyboardclient master: Update min tox version to 2.0  https://review.openstack.org/61514911:56
openstackgerritVieri proposed openstack-infra/glean master: Update min tox version to 2.0  https://review.openstack.org/61515112:00
*** alexchadin has quit IRC12:00
openstackgerritVieri proposed openstack-infra/puppet-openstackci master: Update min tox version to 2.0  https://review.openstack.org/61515212:01
openstackgerritVieri proposed openstack-infra/ansible-role-puppet master: Update min tox version to 2.0  https://review.openstack.org/61515312:02
*** shrasool has quit IRC12:02
*** shrasool has joined #openstack-infra12:02
openstackgerritVieri proposed openstack-infra/infra-specs master: Update min tox version to 2.0  https://review.openstack.org/61515412:03
strigaziHello, I'm trying to encrypt a secret with tools/encrypt_secret.py from openstack-infra/zuul but I can't find the zuul server url. It is not zuul.openstack.org12:03
openstackgerritVieri proposed openstack-infra/system-config master: Update min tox version to 2.0  https://review.openstack.org/61515512:04
openstackgerritVieri proposed openstack-infra/project-config master: Update min tox version to 2.0  https://review.openstack.org/61515612:05
openstackgerritVieri proposed openstack-infra/subunit2sql master: Update min tox version to 2.0  https://review.openstack.org/61515712:06
*** zul has quit IRC12:06
openstackgerritVieri proposed openstack-infra/elastic-recheck master: Update min tox version to 2.0  https://review.openstack.org/61515812:06
eumel8strigazi: maybe ask in #zuul12:07
strigazieumel8: I was looking for #openstack-zuul thanks12:07
eumel8yeah, it's only #zuul :)12:08
openstackgerritVieri proposed openstack-infra/openstackid-resources master: Update min tox version to 2.0  https://review.openstack.org/61516012:09
*** pbourke has quit IRC12:10
*** pbourke has joined #openstack-infra12:10
*** kjackal has joined #openstack-infra12:10
openstackgerritVieri proposed openstack-infra/infra-manual master: Update min tox version to 2.0  https://review.openstack.org/61516112:10
strigaziI think it is an infra question, since I look for the openstack.org zuul deployment. Thanks anyway.12:11
openstackgerritVieri proposed openstack-infra/zuul-sphinx master: Update min tox version to 2.0  https://review.openstack.org/61516212:11
*** jcoufal has joined #openstack-infra12:12
openstackgerritVieri proposed openstack-infra/gerritlib master: Update min tox version to 2.0  https://review.openstack.org/61516312:13
*** lpetrut has quit IRC12:13
openstackgerritVieri proposed openstack-infra/zuul master: Update min tox version to 2.0  https://review.openstack.org/61516412:13
openstackgerritVieri proposed openstack-infra/openstack-zuul-roles master: Update min tox version to 2.0  https://review.openstack.org/61516512:14
openstackgerritVieri proposed openstack-infra/afsmon master: Update min tox version to 2.0  https://review.openstack.org/61516612:15
openstackgerritVieri proposed openstack-infra/reviewstats master: Update min tox version to 2.0  https://review.openstack.org/61516712:16
openstackgerritVieri proposed openstack-infra/openstack-zuul-jobs master: Update min tox version to 2.0  https://review.openstack.org/61516812:18
openstackgerritVieri proposed openstack-infra/devstack-gate master: Update min tox version to 2.0  https://review.openstack.org/61516912:19
openstackgerritVieri proposed openstack-infra/ciwatch master: Update min tox version to 2.0  https://review.openstack.org/61517012:20
openstackgerritVieri proposed openstack-infra/grafyaml master: Update min tox version to 2.0  https://review.openstack.org/61517112:20
openstackgerritVieri proposed openstack-infra/zuul-jobs master: Update min tox version to 2.0  https://review.openstack.org/61517212:22
fricklerdid I miss something or is this a new batch of uncoordinated mass patches?12:24
openstackgerritVieri proposed openstack-infra/log_processor master: Update min tox version to 2.0  https://review.openstack.org/61517312:24
openstackgerritIldiko Vancsa proposed openstack-infra/project-config master: Add StarlingX core groups  https://review.openstack.org/61517412:25
*** trown|outtypewww is now known as trown12:25
openstackgerritVieri proposed openstack-infra/yaml2ical master: Update min tox version to 2.0  https://review.openstack.org/61517512:26
openstackgerritGary Perkins proposed openstack-infra/system-config master: Add Arm64 CI cloud  https://review.openstack.org/60243612:26
openstackgerritVieri proposed openstack-infra/lodgeit master: Update min tox version to 2.0  https://review.openstack.org/61517612:27
openstackgerritIldiko Vancsa proposed openstack-infra/project-config master: Add StarlingX core groups  https://review.openstack.org/61517412:28
aspiersanyone interested in a better understanding of OpenStack's code review culture within Gerrit should check out this awesome talk which is finally online one year later! https://twitter.com/GerritReview/status/105831031238919782412:32
aspiersfungi, corvus, clarkb: ^^^12:33
*** jamesmcarthur has joined #openstack-infra12:34
fungiaspiers: awesome! how was the conference overall?12:34
aspiersit was really good, which is why I promoted this year's event within this community.12:35
fungioh, that was from last year's?12:35
aspiersyes12:35
aspiersjust got published a few minutes agoo12:35
fungii see that now in the quoted frame12:35
fungiquite the delay12:35
*** yamamoto has joined #openstack-infra12:36
aspiersenough that I got a personal apology as you can see :)12:36
*** zul has joined #openstack-infra12:36
*** jamesmcarthur has quit IRC12:39
*** quiquell is now known as quiquell|lunch12:43
fungiquiquell: https://nb01.openstack.org/images/ or if you want the arm64 images instead of amd64 then https://nb03.openstack.org/images/ (there's a self-signed https cert you'll have to okay to access those urls)12:44
*** jamesmcarthur has joined #openstack-infra12:45
*** yamamoto has quit IRC12:47
*** yamamoto has joined #openstack-infra12:49
fungimgoddard: i've added you to tenks-core and removed the ironic-core group from being included in it for now since it looks like it ended up not becoming an official ironic project after all12:51
*** kgiusti has joined #openstack-infra12:53
fungistrigazi: eumel8: yes, this is the appropriate channel to ask questions about zuul.openstack.org, we try not to burden #zuul with support questions from users of openstack's deployment of their software (though there is a lot of overlap of the same people on both channels)12:53
*** janki has quit IRC12:53
mgoddardfungi: I think it's still TBD but correct that it's not official yet. I'll wait for that to happen before adding ironic-core12:53
*** janki has joined #openstack-infra12:53
*** yamamoto has quit IRC12:56
fungistrigazi: the last time i used encrypt_secret.py i'm pretty certain i passed --url=https://zuul.openstack.org/ but maybe something has changed about that recently and we missed updating documentation... what does your command-line invocation look like?12:57
*** roman_g has joined #openstack-infra12:58
fungier, not --url= just as the first positional argument12:58
*** bobh has joined #openstack-infra12:59
*** quiquell|lunch is now known as quiquell13:00
*** jamesmcarthur has quit IRC13:04
*** boden has joined #openstack-infra13:07
*** yamamoto has joined #openstack-infra13:08
*** yamamoto has quit IRC13:08
*** yamamoto has joined #openstack-infra13:08
*** ykarel_ has joined #openstack-infra13:10
*** panda is now known as panda|lunch13:10
*** ykarel has quit IRC13:10
fricklerinfra-root: please review https://review.openstack.org/614545 so that creating venvs on bridge.o.o will work without fancy tricks13:12
*** yamamoto has quit IRC13:13
fricklerinfra-root: I'd also still like to discuss how to resolve access to the all-clouds.yaml. do we want to add all infra-roots to the admin group and change group ownership of /etc/openstack to that? (c.f. https://docs.openstack.org/infra/system-config/sysadmin.html#accessing-clouds)13:13
*** ccamacho has quit IRC13:14
*** shrasool has quit IRC13:14
Shrewsfungi: strigazi: tools/encrypt_secret.py --infile file_with_secret --tenant openstack https://zuul.openstack.org openstack/kolla13:14
Shrewswfm13:14
*** ccamacho has joined #openstack-infra13:14
fungiyeah, looks like it still uses the parameters i remember13:17
fungiit's possible https://docs.openstack.org/infra/manual/zuulv3.html#secret-variables would benefit from a sample invocation for our deployment which indicates the need for --tenant=openstack13:18
fungimy guess is that strigazi didn't pass that option13:18
Shrewswell, that works for me w/o --tenant too13:21
Shrewsmy guess is strigazi is using "kolla" and not "openstack/kolla" for the project13:22
Shrewswhich results in a 40413:22
Shrewsadmittedly confusing13:22
fungioh, likely so13:22
*** janki has quit IRC13:27
*** mriedem has joined #openstack-infra13:28
*** efried is now known as fried_rice13:35
openstackgerritGuilherme  Steinmuller Pimentel proposed openstack-infra/project-config master: Add os_placement role to OpenStack-Ansible  https://review.openstack.org/61489613:40
*** d0ugal has quit IRC13:40
*** lpetrut has joined #openstack-infra13:42
openstackgerritAndreas Jaeger proposed openstack-infra/infra-manual master: Give encryption example  https://review.openstack.org/61518913:44
AJaegerfungi, Shrews, strigazi , is this ok? ^13:44
*** panda|lunch is now known as panda13:48
*** eharney has joined #openstack-infra13:50
*** ykarel_ is now known as ykarel13:53
*** xarses_ has quit IRC13:54
*** jamesmcarthur has joined #openstack-infra13:55
fungifrickler: regarding access to all-clouds.yaml, i was advocating for similarly granting admin group access to the ansible inventory so we could launch servers without sudo. there seemed to be a fair amount of opposition to that for some reason, and consensus was that we should just run all commands on bridge.o.o with sudo or from a root shell13:56
openstackgerritGuilherme  Steinmuller Pimentel proposed openstack-infra/project-config master: Add os_placement role to OpenStack-Ansible  https://review.openstack.org/61489613:56
openstackgerritMonty Taylor proposed openstack-infra/system-config master: Configure adns1.opendev.org via ansible  https://review.openstack.org/61464813:57
openstackgerritMonty Taylor proposed openstack-infra/system-config master: Configure opendev nameservers using ansible  https://review.openstack.org/61487013:57
fungifrickler: those advocating for avoiding explicit unix group management on the server seemed to feel a lot more passionate about it than i did, so i dropped it13:57
mordredcorvus, clarkb, fungi: ^^ updated to take in to account logan- review comment13:57
fungimordred: thanks! i was about to +2 and suggest a followup, but that works13:58
*** tdasilva has joined #openstack-infra13:58
fungifwiw i agree with logan- we've seen that same exact issue elsewhere though in this particular case the servers we're initially deploying to have working global ipv6 addresses so it isn't a blocker13:58
mordredyah13:59
fungi(and i can't imagine us ever wanting to have v4-only nameservers anyway)13:59
mordredI figure we're waiting for people to awaken anyway - so wasn't too much of a thing13:59
*** yamamoto has joined #openstack-infra13:59
fricklerfungi: hmm, o.k., but I really don't like advocating to run sudo in combination with osc from a private venv. not sure how to best amend the docs, then14:03
*** armax has joined #openstack-infra14:06
fungifrickler: yeah, it's not my first choice either. maybe if we get consensus on setting group ownership of all-clouds.yaml we can come to a similar consensus on reversing the decision about the ansible inventory cache14:07
mordredfungi, fungi: I'd be in support of group management14:07
fungiit's less of a security measure to me and more avoiding gratuitous use of sudo which could lead to accidents14:07
fungiif i don't prefix commands with `sudo` then the files on the server i can accidentally remove or overwrite are extremely limited14:08
fricklerI agree. o.k., let me try to come up with a patch for that14:09
fungiyou might want to avoid making that group "admin" though. it was a particular hot-button group name which is why it got removed in the first place if memory serves14:10
fungiubuntu used to grant sudo access to members of the admin group, but deprecated it in favor of the sudo group, so to some that seems to mean we shouldn't have a group named admin14:11
*** rfolco is now known as rfolco|off14:11
guilhermesphello all!  AJaeger :) could you review these please https://review.openstack.org/#/c/615187/2 https://review.openstack.org/#/c/614896/514:13
*** dansmith is now known as SteelyDan14:13
fricklerfungi: actually I've been thinking about just re-using the sudo group instead of creating/setting up another one that would just duplicate membership there.14:16
fricklerthough for some reason we keep the default ubuntu account a member of that, maybe we need to drop that?14:17
fricklerI could not find any code that touches/updates /etc/openstack, would it be o.k. to just change the group for that manually once?14:18
mordredfrickler, fungi: maybe in our base.yaml playbook we should remove the ubuntu user14:18
gary_perkinsHi! I've redeployed our Arm cloud and fixed the outstanding issues: https://review.openstack.org/#/c/602436 Can I PM you new credentials, ianw? Would appreciate if people can review when they get a dull moment :)14:19
fungimordred: is that an artifact of using cloud-provided images?14:19
mordredfrickler: it's in playbooks/roles/configure-openstacksdk/tasks/main.yaml14:19
mordredfungi: yes14:19
mordredfungi: it's the user that has blanket sudo access - because somehow that's better than allowing remote root logins14:20
*** shrasool has joined #openstack-infra14:20
fungigary_perkins: ianw is in au so likely already wound down for the day. i'm happy to get the updated credentials if you can get them to me14:20
gary_perkinsfungi: Thanks :)14:21
mordredfrickler: and, in fact, you could likely just change the default for openstacksdk_config_group in playbooks/roles/configure-openstacksdk/defaults/main.yaml14:21
openstackgerritMerged openstack-infra/system-config master: Make the pip3 role really install something  https://review.openstack.org/61454514:21
fungimordred: yeah, i've always found that absurd as well. it's basically to shut up orange book obsessives who insist "root" logins must be disabled for a secure system14:21
mordredfungi: YOU MUST FOLLOW THE ARBITRARY RULES TO BE GOOD14:21
fricklermordred: hmm, I was thinking only to override it for bridge.yaml, since the role seems to be used for nodepool deployments, too14:22
mordredfrickler: ah - fair14:22
mordredfrickler: well, luckily we're already even passing parameters to that role in playbooks/base.yaml14:23
*** lpetrut has quit IRC14:26
openstackgerritMatt Riedemann proposed openstack-infra/elastic-recheck master: Adjust query for bug 1800472  https://review.openstack.org/61519414:27
openstackbug 1800472 in OpenStack Compute (nova) "nova.tests.functional.test_server_group.ServerGroupTestV264.test_boot_servers_with_affinity_no_valid_host intermittently failing with "OpenStackApiNotFoundException: Item not found"" [Medium,Triaged] https://launchpad.net/bugs/180047214:27
*** d0ugal has joined #openstack-infra14:27
openstackgerritMonty Taylor proposed openstack-infra/nodepool master: Consume rate limiting task manager from openstacksdk  https://review.openstack.org/61216914:27
corvusfungi, frickler, mordred: i'm not *opposed* to group management, i'm just not in favor of it.  that sort of thing is always complex and takes a lot of time and maintenance for almost no gain on a server where every action is effectively a root action.  i was hoping to save us a bunch of time.14:28
*** lpetrut has joined #openstack-infra14:30
openstackgerritJens Harbott (frickler) proposed openstack-infra/system-config master: Fix access to clouds on bridge  https://review.openstack.org/61519714:32
fricklercorvus: fungi: mordred: that does look simple enough to me ^^14:32
openstackgerritAndrey Nikitin proposed openstack-infra/jeepyb master: Make use of Gerrit CLI to retrieve group UUID  https://review.openstack.org/28484314:33
corvusfrickler: oh, yeah, i was thinking in context of the previous discussion where running ansible without sudo was contemplated.14:34
fungicorvus: yeah, but also running openstackclient without sudo14:34
corvusfrickler: i think read access to to clouds.yaml is a great idea.  that will let us do server lists, etc, easily.  we won't be able to launch new nodes or run ansible though..14:34
fricklercorvus: that would possibly be a second step, indeed, but I'd be fine with the first one for now14:35
corvusfrickler: the second step is where several more things on the filesystem need to be group-writeable -- and stay group-writable even though automatic processes are maintaining them.14:36
*** ccamacho has quit IRC14:36
openstackgerritMerged openstack-infra/git-review master: Remove auto-branch name  https://review.openstack.org/61057314:37
*** lpetrut has quit IRC14:37
fricklercorvus: yeah, that would be tricky14:38
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Configure opendev nameservers using ansible  https://review.openstack.org/61487014:39
*** quiquell is now known as quiquell|off14:45
*** ccamacho has joined #openstack-infra14:53
*** coolsvap has quit IRC14:54
openstackgerritMerged openstack-infra/infra-manual master: Give encryption example  https://review.openstack.org/61518914:57
fricklerwow, canonical is getting quite fancy it seems ... cosmic ... disco ... ;)14:58
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Move start_services to all.yaml  https://review.openstack.org/61495914:58
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Remove start_services  https://review.openstack.org/61496114:59
* fungi turns on the mirror ball and starts to groove14:59
*** diablo_rojo has joined #openstack-infra15:02
*** xek has joined #openstack-infra15:05
fungimordred: i'm a bit confused by the seemingly arbitrary use of globbing and explicit lists of nearly-identical hostnames in 602385. is there some reason i'm overlooking or is that just an opportunity for cleanup in the future?15:05
*** xek__ has quit IRC15:06
strigaziShrews: fungi AJaeger this works: ./tools/encrypt_secret.py --tenant=openstack https://zuul.openstack.org/ openstack/<myproject> --infile <file> ; Thank you ; I was trying like this ./tools/encrypt_secret.py https://zuul.openstack.org <myproject>15:06
strigaziShrews: fungi AJaeger And I was getting http://paste.openstack.org/show/734047/15:07
*** ssbarnea has quit IRC15:08
*** ssbarnea has joined #openstack-infra15:10
fungistrigazi: yeah, in this case the confusion is that openstack/ is actually part of the name of the project15:11
fungie.g., openstack/kolla is a project name as far as zuul (and gerrit, and storyboard and whatever else) is concerned15:12
fungikolla by itself is not15:12
fungijust like openstack-infra/bindep or openstack-dev/pbr are project names15:13
Shrewsgit.openstack.org/openstack/kolla would also be valid15:13
*** chandankumar is now known as chkumar|off15:14
*** munimeha1 has joined #openstack-infra15:14
mordredfungi: I think it's just an opportunity for cleanup in the future15:16
fungiokay, just wanted to be sure i understood the change. the lack of consistency made me worry there was something i was overlooking. thanks!15:16
strigaziShrews: fungi this works too "curl https://zuul.openstack.org/api/key/openstack/kolla.pub"15:16
strigaziShrews: fungi thanks again for your time15:17
mordredfungi: I tnik it was some combination of me getting bored with typing - and also not being sure which of the approaches (globs vs lists) we liked better15:17
openstackgerritMerged openstack-infra/elastic-recheck master: Adjust query for bug 1800472  https://review.openstack.org/61519415:18
openstackbug 1800472 in OpenStack Compute (nova) "nova.tests.functional.test_server_group.ServerGroupTestV264.test_boot_servers_with_affinity_no_valid_host intermittently failing with "OpenStackApiNotFoundException: Item not found"" [Medium,Triaged] https://launchpad.net/bugs/180047215:18
fungimordred: great--this way we get to try both! ;)15:18
fungistrigazi: glad it's working for you15:19
openstackgerritJames E. Blair proposed openstack-infra/zuul master: Merger: automatically add new hosts to the known_hosts file  https://review.openstack.org/60845315:19
arxcruzmtreinish: hey around? I'm getting some weird tempest results, hope you can help me, at some point all scenarios are being executed in one single worker while the other workers are idle15:20
arxcruzmtreinish: http://logs.openstack.org/33/615133/2/check/tripleo-ci-centos-7-standalone/9ac46cc/logs/stackviz/#/testrepository.subunit/timeline15:20
openstackgerritJames E. Blair proposed openstack-infra/zuul master: WIP: support foreign required-projects  https://review.openstack.org/61314315:22
fungistrigazi: would https://review.openstack.org/615189 have helped avoid your confusion at all?15:24
*** dave-mccowan has joined #openstack-infra15:26
*** gyee has joined #openstack-infra15:26
*** ramishra has quit IRC15:29
clarkbfinucannot: I'm sending email now to formalize the "lets keep git-review stable" and what that means (corvus had a great one liner for that). So look out for email shortly15:30
finucannotclarkb: Yup, got that and agreed. FWIW, I'm for _removing_ extraneous features (auto-configuration of topics) where possible15:34
*** Swami has joined #openstack-infra15:34
clarkbmordred: fungi  we should watch bridge.o.o closely when https://review.openstack.org/#/c/602385/ merges15:35
fungiclarkb: i agree. we have testing there, but as we saw with things like misapplication of firewall rules having changes to how hostnames get mapped can result in some surprising problems15:36
*** eharney has quit IRC15:36
openstackgerritAndreas Jaeger proposed openstack-infra/project-config master: Move operations-guide translations to project-config  https://review.openstack.org/61522215:39
mordredclarkb: I've opened a root shell on bridge, just in case15:39
fungiclarkb: http://cacti.openstack.org/cacti/graph.php?action=view&local_graph_id=115&rra_id=all is making me think there's been some automated process hammering the etherpad server since ~2018-10-16/17 and someone just turned it off around 22:15z15:39
clarkbfungi: https://review.openstack.org/#/c/614883/ sort of15:40
clarkbfungi: I think ^ was the culprit all along (with the broken web server config)15:40
clarkbfungi: basically all our browsers had to poll etherpad and that created sadness15:40
fungiaha!15:41
clarkbfungi: it wasn't until I had asserted "we use websockets" to TheJulia that I realized I can actually check that using browser debugging tools and then saw the websocket urls were 400ing and we were doing many requests wthat had transport=poll in them that it hit me15:41
fungiyikes15:41
fungii had already checked out by then, i think15:41
clarkbI manually applied that change before it merged since I had TheJulia around helping test things15:42
clarkband that seemed to make it happy at that point. Good to see cacti seems to agree15:42
clarkbmordred: great. I'm still booting my morning but assume I'm actually here in the next half hour or so15:44
clarkbfungi: thank you for helping gary_perkins15:45
openstackgerritMerged openstack-infra/system-config master: Add yamlgroup inventory plugin  https://review.openstack.org/60238515:46
*** AJaeger has quit IRC15:46
mordredclarkb: yes. I am here15:46
openstackgerritMerged openstack-infra/system-config master: Add unittest for yamlgroup inventory plugin  https://review.openstack.org/61469415:47
*** AJaeger has joined #openstack-infra15:48
*** xek_ has joined #openstack-infra15:48
*** eharney has joined #openstack-infra15:51
*** xek has quit IRC15:51
fungiclarkb: yeah, no problem. i'm only just starting on resetting the passwords and getting them into our usual list15:51
openstackgerritMerged openstack-infra/system-config master: Remove puppet config for opendev nameservers  https://review.openstack.org/61486915:54
clarkblooks like gra1 is happy again15:57
*** jaosorior has quit IRC15:58
*** bnemec is now known as beekneemech16:00
*** yamamoto has quit IRC16:03
*** yamamoto has joined #openstack-infra16:05
*** yamamoto has quit IRC16:05
*** yamamoto has joined #openstack-infra16:05
clarkbI need to start putting together the infra project update talk as well as an onboarding session. For the project update I think big changes have been the ansiblification and work to use containers. We've also added a new arm64 region and are in the process of adding a third. On the zuul side of things we have been (helpful I hope) beta testers. We've also onboarded new top level projects (starlingx16:07
clarkband airship)16:07
clarkbany other big ticket items I'm forgetting that should be called out?16:07
mordredclarkb: I think that's about it16:08
clarkbfor onboarding in particular I was thinking about changing tactics a bit and targetting top level projects in partciular. I need to see what I can learn about how is attending and who can go to the onboarding session but more 1:1 type time with interested individuals might be helpful?16:10
clarkbdtroyer: ^ do you have any sense for whether or not that could be useful for starlingx in berlin?16:10
*** yamamoto has quit IRC16:10
fungiinteresting... etherpad is working on a new default theme for the next release https://github.com/ether/etherpad-lite/issues/344116:10
fungiclarkb: opendev is a big ticket item16:11
clarkbfungi: ya, though I think it is still a bit in the air as far as how much we will be talking about it? maybe we should just go for it at this point16:11
clarkblsell has feedback on my email too so hopefully we can get that and the message/faq sorted soonish16:12
fungieven though we're really just getting started on the implementation of the changes it implies, it's probably worth calling out16:12
fungigiven people are already talking about it and using the name whether we want them to or not, so not at least mentioning it could seem a bit weird16:13
*** AJaeger_ has joined #openstack-infra16:13
clarkbfair point16:13
AJaeger_clarkb: you can also point out that with the python3-first goal, most of the jobs migrated from central place to in-repo.16:14
mordredclarkb: like user onboarding rather than trying to onboard new admins?16:14
fungioh, yep that's a fairly big change16:14
AJaeger_clarkb: you could give a summary on what is placed in-repo - and what in the central repo.16:15
*** imacdonn has quit IRC16:15
*** AJaeger has quit IRC16:15
*** imacdonn has joined #openstack-infra16:15
clarkbmordred: ya16:16
clarkbAJaeger_: ++ thanks16:16
corvusfungi: if you zoom in, the document gets wider16:16
fungiinteresting16:17
*** pcaruana has quit IRC16:17
funginot sure i like that much better, but at least you can zoom it so the editing space is as wide as the window16:18
corvusfungi: so basically, it's a fixed number of characters wide, as compared to the current system which lets you change size and line length independently.16:18
fungii'll miss being able to alter the display size of the text independently of the width of the editing box16:18
fungiyes, that16:18
clarkbit looks more google docs16:18
dtroyerclarkb: that would be useful, there will be a small number of stx devs in Berlin that don't have much, if any, OpenStack background.16:18
fungiclarkb: yes, i don't consider that a plus16:19
dtroyerand some of that do could probably make sure we are up-to-date :)16:19
AJaeger_dtroyer: could you review https://review.openstack.org/615174 , please?16:19
*** AJaeger_ is now known as AJaeger16:20
fungiAJaeger_: if we resume work on https://review.openstack.org/578557 would you still expect the same set of jobs to be kept in project-config?16:20
dtroyerAJaeger_: sure… I'm getting a slow start today, didn't realize ildiko had that up already16:20
fungiAJaeger: once that's no longer a necessary workaround for matching tag-triggered jobs against specific branches?16:20
AJaegerfungi: I think in that case we can move publish-to-pypi etc. in-repo16:20
AJaegerfungi: agreed.16:21
fungigot it. wasn't sure if there were additional reasons for centralizing some of those16:21
AJaegerfungi: other reason was that release team had no way to query that proper release jobs are set up16:21
AJaegerfungi: zuul is working on an API - once that is in, the publish-to-pypi jobs can move ...16:22
AJaeger(and it needs a change to release tools - it might be that this change is already done)16:22
AJaegerfungi, I suggest to rename publish-to-pypi-python3 to publish-to-pypi - I don't think we need both jobs and tmplates. dhellmann, do you agree?16:23
AJaegerfungi: so, I would do that first before we move these in-repo16:23
clarkbdtroyer: ok let me try to formalize this a bit more but if I get an etherpad together maybe you can circulate that with stx folks and I'll reach out to airhsip and kata et al too16:23
dtroyerclarkb: that sounds good, will do16:24
mordredclarkb: the yamlgroup update on bridge did not go well - we missed a sequence somewhere16:25
clarkbmordred: ok, did it just fail to run at all?16:25
mordredclarkb: basically, the new groups.yaml file got put down before the new ansible.cfg telling ansible to load the yamlgroup plugin16:25
mordredyeah - totally faile to run - looking to see how much is in place16:25
mordredclarkb: OH - duh16:27
mordredclarkb: so - the issue is that we serve our inventory files directly from /opt/system-config/inventory/groups.yaml16:28
mordredso when system-config got updated by the git pull, the new groups.yaml content was immediately in place16:28
mordredbut ansible had not yet run to update ansible.cfg or copy the plugin in to place16:29
mordredclarkb: do you think we should revert the yamlgroup patch and re-add it in a sequence that will run - or just fix in place for now and learn for next time?16:29
clarkbmordred: probably fix in place?16:30
clarkbthat seems less error prone16:30
mordredyeah. and this isn't a thing we do very often16:30
*** fried_rice is now known as fried_rolls16:30
fungiseems like an okay fix to me for now16:31
mordredok. I copied the yamlgroup.py and ansible.cfg files into place by hand16:32
mordredyou know - for the future - we could change the execution of the bridge.yaml playbook to use its own ansible.cfg that doesn't load the dynamic inventory at all16:33
*** shrasool has quit IRC16:33
*** e0ne has quit IRC16:33
openstackgerritAndreas Jaeger proposed openstack-infra/project-config master: Use python3 for release  https://review.openstack.org/61523616:34
mordredAJaeger: your commit message doesn't seem to match the content of the patch16:36
openstackgerritAndreas Jaeger proposed openstack-infra/openstack-zuul-jobs master: Sync publish-to-pypi templates  https://review.openstack.org/61523716:38
AJaegermordred: let me expand the commit message...16:38
openstackgerritAndreas Jaeger proposed openstack-infra/project-config master: Use python3 for release  https://review.openstack.org/61523616:39
AJaegermordred: updated ^16:39
AJaegerconfig-core, could you review https://review.openstack.org/615222 and https://review.openstack.org/615174 , please16:41
openstackgerritAndreas Jaeger proposed openstack-infra/project-config master: Use publish-to-pypi everywhere  https://review.openstack.org/61523916:43
openstackgerritAndreas Jaeger proposed openstack-infra/openstack-zuul-jobs master: Remove publish-to-pypi-python3  https://review.openstack.org/61524116:44
openstackgerritAndreas Jaeger proposed openstack-infra/project-config master: Use publish-to-pypi everywhere  https://review.openstack.org/61523916:46
openstackgerritAndreas Jaeger proposed openstack-infra/project-config master: Remove python3 release jobs  https://review.openstack.org/61524216:46
openstackgerritAndreas Jaeger proposed openstack-infra/openstack-zuul-jobs master: Remove publish-to-pypi-python3  https://review.openstack.org/61524116:46
AJaegermordred, dhellmann, smcginnis, could you review the stack starting at https://review.openstack.org/615236, please? This is a bit back and forth between the two repos...16:47
smcginnisSure, I'll take a look.16:47
*** ykarel is now known as ykarel|away16:48
AJaegersmcginnis: I mainly need feedback on whether using the python3 variant is fine for *all* repos.16:48
AJaegerThe essence of the change is "mv publish-to-pypi-python3 publish-to-pypi", so making publish-to-pypi using the set up of publish-to-pypi-python3 - and then removing publish-to-pypi-python316:49
smcginnisI think it was needed for transition to make sure everything was working right under python3, but now that we've established that fact, I don't see any reason why we can't just use one updated job everywhere.16:49
AJaegeragreed16:50
smcginnisAJaeger: That first one says it's changing release-openstack-python, but looks like it is only adding test-release-openstack. Was that missed, or refactored after the commit message was written to break things up?16:51
* AJaeger checks16:52
smcginnisAJaeger: I don't see release-openstack-python being updated anywhere to have release_python: python3.16:52
AJaegersmcginnis: indeed - thanks16:52
* AJaeger fixes16:53
*** zul has quit IRC16:53
openstackgerritAndreas Jaeger proposed openstack-infra/openstack-zuul-jobs master: Sync publish-to-pypi templates  https://review.openstack.org/61523716:55
openstackgerritAndreas Jaeger proposed openstack-infra/openstack-zuul-jobs master: Remove publish-to-pypi-python3  https://review.openstack.org/61524116:55
openstackgerritAndreas Jaeger proposed openstack-infra/project-config master: Use python3 for release  https://review.openstack.org/61523616:55
openstackgerritAndreas Jaeger proposed openstack-infra/project-config master: Use publish-to-pypi everywhere  https://review.openstack.org/61523916:55
openstackgerritAndreas Jaeger proposed openstack-infra/project-config master: Remove python3 release jobs  https://review.openstack.org/61524216:55
AJaegersmcginnis: updated and rebased16:56
AJaegerthanks, smcginnis16:56
openstackgerritMerged openstack-infra/irc-meetings master: add tc meetings  https://review.openstack.org/60868216:58
*** yamamoto has joined #openstack-infra16:59
*** Swami has quit IRC17:01
*** yamamoto has quit IRC17:07
*** ykarel_ has joined #openstack-infra17:10
openstackgerritMerged openstack-infra/project-config master: Add os_placement role to OpenStack-Ansible  https://review.openstack.org/61489617:11
finucannotmordred: Would you do me the honor? https://review.openstack.org/#/c/610988/17:12
clarkbis etherpad unresponsive for anyone else?17:13
clarkbI can hit it via ssh and apache and nodejs are running17:13
clarkbbut firefox says it cannot connect17:13
*** ykarel|away has quit IRC17:13
clarkbaha17:13
clarkbwe broke iptables17:13
clarkbmordred: ^ is this group fallout17:13
clarkbya I see the bug17:14
mwhahahabreaking stuff on a friday :( i assume :8080 mirror failures are related?17:16
fungimwhahaha: what are you doing working on a friday? sheesh! ;)17:16
mwhahahai know right?17:16
clarkbmwhahaha: maybe?17:16
mwhahahano one else does17:16
fungiand no, i don't think we knew about mirror problems yet, so thanks!17:17
clarkbcan someone else look at the mirrors I'm sorting out etherpad17:17
fungiyeah, i'm looking now17:17
fungiyep, we're blocking 8080 with the iptables rules on the mirror servers17:17
funginow to figure out why17:18
clarkbfungi: likely the groups change17:18
fungiright, that much i'm almost sure of, just looking to figure out what it did wrong17:19
*** dtantsur is now known as dtantsur|afk17:19
fungiplaybooks/group_vars/mirror.yaml has 80, 8080, 8081 and 8082 i its iptables_extra_public_tcp_ports list17:20
fungiguessing these hosts didn't match the host pattern for the mirror group17:20
openstackgerritClark Boylan proposed openstack-infra/system-config master: Update etherpad group membership  https://review.openstack.org/61525017:20
clarkbfungi: that is a good guess ^ essentially the same problem with etherpad17:21
*** trown is now known as trown|lunch17:21
fungiyeah, i was just pulling it up to see what you fixed ;)17:21
clarkbinfra-root ^ can we get reviews on that please17:21
fungiare these globs or regular expressions?17:21
clarkbfungi: globs17:21
fungiso so why didn't that match?17:22
fungiif they're globs then what you patched would just be a subset of what was there, right?17:22
*** jpich has quit IRC17:22
clarkbfungi: not under the webservers group17:23
fungioh!17:23
clarkbfungi: and the webservers group is what writes out the port 80 and 443 iptables rules17:23
fungiyep, i didn't look far enough down17:23
clarkbthe first change in the diff is to rpevent etherpad-dev from using etherpad's cert and database17:23
clarkb(I'm going to try not to think about what that would break if it happened)17:23
clarkb(I actually think we still have hostvars in place which take precedence over the group vars so don't think that would've actually happened)17:24
clarkbmwhahaha: have a specific example? I'm reading our groups and the mirrors look right to me17:25
mwhahahahttp://logs.openstack.org/02/610102/19/check/tripleo-ci-centos-7-containers-multinode-pike/2e37e64/job-output.txt.gz#_2018-11-02_17_00_08_47638417:25
mwhahahait's failing at the end, if i curl it it's giving me a No route to host17:25
mwhahahawhich i assume is iptables reject17:25
mwhahahai noticed it in vexxhost and there was aa different failure in inap17:26
mwhahahaso i don't think it's regions pecific17:26
fungiclarkb: here's the openstack-INPUT chain from the limestone mirror for example: http://paste.openstack.org/show/734048/17:26
clarkbya its definitely not allowing 808017:26
mwhahahaand it just started17:26
fungiwe have duplicate rules for 22/tcp (strangely) as well as rules for 80/tcp and 443/tcp but not 8080,8081,808217:27
fungiit's like it didn't actually apply the mirror group17:27
*** ccamacho has quit IRC17:27
clarkbfungi: ya17:28
fungiwe have mirror[0-9]*.*.*.openstack.org in the webservers group17:28
fungiwhich i think explains the 80/443 rules17:28
*** shrasool has joined #openstack-infra17:28
clarkband specific names in the mirror group17:28
fungimordred: ^ extra eyes would be helpful here, we're breaking a *lot* of ci jobs right now17:29
fungii confirmed the limestone entry in the mirror group, for example, matches the hostname17:29
clarkbfnmatch.fnmatch('mirror01.bhs1.ovh.openstack.org', 'mirror01.bhs1.ovh.openstack.org') returns True which is what I think the yamlgroup inventory plugin will run17:29
fungiwe could try switching to the glob used for applying afs-client and webserver to them17:30
clarkbya17:30
*** mriedem has quit IRC17:30
clarkbI'd like to udnerstand that though to better understand what else might be broken17:31
fungii concur17:31
clarkbthe zookeeper group for example has all of its iptables rules and is also explicitly listed17:31
fungiif i `sudo ansible --list-hosts mirror` i get a list of the mirror servers i expect too17:33
fungi[WARNING]: Unable to parse /etc/ansible/hosts/emergency.yaml as an inventory17:33
fungisource17:33
fungii do see that17:33
clarkbuh17:33
clarkbI'm guessing that means we are going to try and run stuff on disabled hosts?17:34
fungiand /etc/ansible/hosts/emergency.yaml is indeed an empty file17:34
fungier, nonexistent file17:34
fungibut /etc/ansible/hosts/emergency is still there17:34
fungiso it didn't get renamed17:35
*** mriedem has joined #openstack-infra17:35
clarkbah ok if we read the old emergency file then maybe we are ok17:35
*** ralonsoh has quit IRC17:35
clarkbfungi: can you try a /opt/system-config/tools/kick.sh mirror01.bhs1.ovh.openstack.org17:35
clarkbthat might give us more insight into why it isn't applying the rules despite being in the right group17:35
fungiyeah, `sudo ansible --list-hosts disabled` does still show the stuff from the old file at least17:35
*** panda is now known as panda|off17:36
fungirunning in a root screen session now17:36
fungino errors from the iptables playbook tasks17:37
clarkband yet no port 8080 rule17:37
clarkbfungi: also maybe we should disable teh ansible puppet cron until we understand this?17:39
fungii don't know what that buys us at this point since whatever it was going to do it's already done17:39
clarkbzuul-executor group also defines iptables rules in playbooks/group_vars. These rules are applied to ze01. This group is also defined by listing all of the nodes17:41
clarkbI'm stumped on what makes the mirror nodes different17:42
clarkbmaybe the asnible cache stuff will tell us17:42
clarkb"name": "mirror01.bhs1.ovh.openstack.org", looks correct to me17:44
fungiis /etc/puppet/hieradata/production/group_vars still where the group vars files are written out on the servers now?17:47
clarkbfungi: no, /etc/ansible/hosts/group_vars is the location17:48
clarkboh sorry ^ is the source. the path you have is the right destiation17:48
fungiyeah, there's no /etc/ansible on the servers17:48
fungithinking we should probably roll back that stack of changes if we can't find a smoking gun shortly17:50
clarkbagreed. I'm not really getting anywhere trying to debug this mirror group listing17:51
fungihere's an extra bit of crazy for you...17:51
clarkball of the ansible data looks as I expect it and if you feed that to fnmatch you get a match which should put the hsots in the mirror group which should apply the 8080 port firewall rules17:52
fungi/etc/iptables/rules has the old rules in it. not a symlink to /etc/iptables/rules.v4 (which has the new rules)17:52
fungiit's definitely not copying the group_vars/mirror.yaml to the server17:53
fungibut ansible itself says the servers are members of the mirror group17:53
fungithough it's also not putting the webservers.yaml in there yet we're getting webserver ports opened17:54
clarkbfungi: I don't think group_vars/mirror.yaml is a valid hieradata file17:54
clarkbfungi: we only copy the private data that way17:54
fungiahh17:54
clarkbso new theory it is in the group properly but we are misapplying the files?17:54
fungias in not applying the group_vars file for the mirror group in particular?17:55
clarkbor applying it wrong? rules.v4 is the file we write and it looks like we did update it on bhs117:55
openstackgerritJens Harbott (frickler) proposed openstack-infra/system-config master: Fix access to clouds on bridge  https://review.openstack.org/61519717:55
clarkboh v4 lacks the 8080 rule, now I understand17:56
fungiyeah, i think /etc/iptables/rules became a transitional symlink between precise and trusty and we could just delete that file off our servers at this point17:57
fungii don't think it's the problem17:57
openstackgerritDoug Hellmann proposed openstack-infra/yaml2ical master: update the versions of python 3 claimed  https://review.openstack.org/61526617:57
openstackgerritDoug Hellmann proposed openstack-infra/yaml2ical master: add base class for recurrence  https://review.openstack.org/61526717:57
openstackgerritDoug Hellmann proposed openstack-infra/yaml2ical master: add day_specifier to recurrence  https://review.openstack.org/61526817:57
fungiansible is updating /etc/iptables/rules.v4 (and .v6) and that's what iptables-persistent is applying17:57
clarkbya17:58
fungiis it possible ansible is overriding iptables_extra_public_tcp_ports from mirror with the one from webservers rather than merging them?17:59
clarkbfungi: ya that is what I'm wondering, we combine things as part of the all group17:59
clarkbmy current hunch is that that combination is what fails17:59
clarkbpossibly due to what you describe17:59
fungiif it's going alphabetically, then zuul is overriding webservers for the executors you were looking at18:00
clarkbya though exectuors don't run a webserver ?18:00
fungioh, right18:00
fungithe zuul-scheduler group respecifies 80 and 443 in its iptables_extra_public_tcp_ports list18:01
clarkbwebservers: inventory_hostname is match('(grafana\d*|health\d*|graphite\d*|groups\d*|groups-dev\d*|eavesdrop\d*|paste\d*|ethercalc\d+|etherpad\d*|etherpad-dev\d*|files\d*|refstack\d*|static\d*|status\d*|survey\d+|nodepool|nl\d+|nb\d+|zm\d+|ask|ask-staging|translate.*|codesearch\d*|cacti\d+|wiki.*|storyboard.*|openstackid-dev|planet\d*)\.openstack\.org|openstackid.org') is the old webservers list18:01
clarkbI think you are right. webservers is meant to be mutually exclusive to any other iptables modifications18:02
clarkbmirrors were not listed in ^ previously18:02
*** derekh has quit IRC18:02
fungipatch on the way18:02
clarkbI believe the fix is to remove mirrors from webservers18:02
clarkband ya mirror lists port 80 too so doesn't need to be in webservers18:03
clarkbfungi: you should probably put your change under mine as we need working mirrors to test my change?18:03
openstackgerritDoug Hellmann proposed openstack-infra/irc-meetings master: use python 3 to build the site  https://review.openstack.org/61526918:04
openstackgerritDoug Hellmann proposed openstack-infra/irc-meetings master: add day_specifier from recurrence  https://review.openstack.org/61527018:04
clarkboh its only the non standard ports that are affected18:04
openstackgerritJeremy Stanley proposed openstack-infra/system-config master: Remove mirrors from the webservers group  https://review.openstack.org/61527118:04
clarkbso no need to rebase18:04
fungiwe should likely force merge those both18:04
clarkbalso how does this look #status notice OpenStack infra's mirror nodes stopped accepting connections on ports 8080, 8081, and 8082. We will notify when this is fixed and jobs can be rechecked if they failed to communicate with a mirror on these ports.18:05
fungilgtm18:06
fungior we could use status alert18:06
fungiand then status ok18:06
AJaegerdhellmann: could you review https://review.openstack.org/615236 , please?18:06
dhellmannAJaeger : looking18:06
clarkbfungi: I've approved your fix. I agree you should probably force merge or direct enqueue to the gate18:06
fungiclarkb: i've emergency approved yours as well18:06
AJaegerthanks, dhellmann. Backscroll has some more details...18:06
corvusi've +2d both after double checking against the original yamlgroup change18:07
fungii'll bypass gating for both and then we can rerun against the mirror servers ahead of schedule18:07
dhellmannAJaeger : why not just delete the old one and rename the new one? I'll read scrollback18:07
fungithanks corvus!18:07
AJaegerdhellmann: we cannot - as long as a job is used, zuul does not allow to remove it...18:07
clarkb#status notice OpenStack infra's mirror nodes stopped accepting connections on ports 8080, 8081, and 8082. We will notify when this is fixed and jobs can be rechecked if they failed to communicate with a mirror on these ports.18:07
openstackstatusclarkb: sending notice18:07
AJaegerdhellmann: I hope I didn't complicate things...18:07
dhellmannAJaeger : ok, that's probably why I just added the new one in the first place18:08
*** betherly has quit IRC18:08
AJaegerdhellmann: part was also to test that it didn't break anything18:08
clarkbfungi: the steps for running that on bridge will be to update /opt/system-config to the merged state then kick.sh. I'm happy to help with that18:08
dhellmannI only updated the official projects, and didn't include any infra projects IIRC18:08
-openstackstatus- NOTICE: OpenStack infra's mirror nodes stopped accepting connections on ports 8080, 8081, and 8082. We will notify when this is fixed and jobs can be rechecked if they failed to communicate with a mirror on these ports.18:09
AJaegerdhellmann: I know - the end result of that series is that publish-to-pypi-python3 gets renamed to publish-to-pypi and all repos use it.18:09
dhellmannyeah, I'm still reading18:09
dhellmannI think this is probably ok, but I wasn't sure of that when we started18:10
*** abishop has joined #openstack-infra18:10
openstackstatusclarkb: finished sending notice18:11
openstackgerritMerged openstack-infra/system-config master: Remove mirrors from the webservers group  https://review.openstack.org/61527118:11
clarkbafter lunch I'm thinking I'll go back through the conversion and possibly propose more simplifications. Like we shouldn't need to explicitly list all of the mirrors that way (whcih will add an additional step for anyone replacing mirrors)18:11
openstackgerritMerged openstack-infra/system-config master: Update etherpad group membership  https://review.openstack.org/61525018:12
dhellmannAJaeger : wow, zuul left a lot of repeated comments on https://review.openstack.org/#/c/615241/318:12
clarkbcorvus: related to ^ any idea why zuul mergers are a web server?18:13
clarkbcorvus: hold over from zuulv2 maybe?18:13
AJaegerdhellmann: yeah - it does not do speculatoin if project-config is involved ;( So, will need a couple of rechecks...18:13
fungiclarkb: i've reset master to origin/master so the new commits are there18:13
fungican i pass kick.sh a group name?18:14
clarkbfungi: agreed on git being up to date18:14
clarkbfungi: I think so? I've done it as foo1:foo2:foo3 before18:14
corvusclarkb: probably so; feel free to drop18:14
*** florianf is now known as florianf|afk18:14
fungitrying with `/opt/system-config/tools/kick.sh mirror`18:14
clarkbfungi: I expect that will also work18:14
clarkbif it does can you do etherpad-dev and etherpad after?18:14
fungigladly!18:15
dhellmannAJaeger : other than needing that patch to the releases repo, the changes all look good18:15
fungiclarkb: corvus: yeah, looks like it's doing the hosts we wanted18:15
openstackgerritRyan Beisner proposed openstack-infra/project-config master: Retire the unmaintained PLUMgrid Charms projects  https://review.openstack.org/61527318:15
AJaegerdhellmann: thanks, will work on the releases changes now...18:16
clarkbfungi: I've not seen bhs1 update yet18:17
clarkbI guess with many more nodes to process it may take longer for any one of them to finish18:17
fungiyep18:18
fungiit hasn't gotten to the iptables tasks yet18:19
mriedemi assume etherpad being down is a known issue?18:21
fungimriedem: yeah, we'll have it back up in just a sec18:21
fungigrowing pains :/18:21
mriedemcool18:21
fungiclarkb: i've started a kick.sh run for etherpad-dev:etherpad in a second screen window18:22
fungiso that we won't have to wait for the mirror servers to finish18:23
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Configure opendev nameservers using ansible  https://review.openstack.org/61487018:23
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Move start_services to all.yaml  https://review.openstack.org/61495918:23
clarkbfungi: thanks18:23
*** jamesmcarthur has quit IRC18:23
mordredclarkb: just got back from grabbing a sandwich - looks like I missed the fun18:23
mriedemthar she blar18:24
*** electrofelix has quit IRC18:24
clarkbfungi: still no port 8080 on bhs1 mirror18:25
fungiit's still going18:26
*** shrasool has quit IRC18:27
fungimordred: if you get a moment, might be a good idea to re-audit the yamlgroup inventory plugin change to make sure we didn't inadvertently add any other hosts to groups they weren't in previously18:27
mordred++18:27
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Configure adns1.opendev.org via ansible  https://review.openstack.org/61464818:27
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Configure opendev nameservers using ansible  https://review.openstack.org/61487018:27
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Move start_services to all.yaml  https://review.openstack.org/61495918:27
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Reload nameservers when config changes  https://review.openstack.org/61527818:27
*** pcaruana has joined #openstack-infra18:27
corvusum. hrm.  that sort of looks like a git-review rebase gone awry.18:27
mordredcorvus: did you catch that I updated https://review.openstack.org/614648 with logan's review included?18:28
corvusmordred: yes, i've been building on top of it18:28
mordredkk. then I don't know what git-review did :)18:28
corvusi am just surprised to see the adns1 change updated.18:28
clarkbmordred: I think the next thing we need to look at is how disabled vs emergency vs emergency.yaml is working18:28
clarkbmordred: because well fungi reports it may not be working 100% as expected.18:28
corvusi believe its rebase was aborted and it left my tree in the rebased state rather than resetting to the previous state18:29
clarkbmordred: 17:33:44*           fungi | [WARNING]: Unable to parse /etc/ansible/hosts/emergency.yaml as an inventory18:29
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Configure opendev nameservers using ansible  https://review.openstack.org/61487018:29
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Move start_services to all.yaml  https://review.openstack.org/61495918:29
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Reload nameservers when config changes  https://review.openstack.org/61527818:29
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Configure opendev nameservers using ansible  https://review.openstack.org/61487018:30
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Move start_services to all.yaml  https://review.openstack.org/61495918:30
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Reload nameservers when config changes  https://review.openstack.org/61527818:30
corvusugh18:30
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Configure adns1.opendev.org server via ansible  https://review.openstack.org/61464818:31
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Configure opendev nameservers using ansible  https://review.openstack.org/61487018:31
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Move start_services to all.yaml  https://review.openstack.org/61495918:31
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Reload nameservers when config changes  https://review.openstack.org/61527818:31
corvusokay, that should be back to the way it was, with the addition of a word in the commit message.  we'll never get back the lost testing time though :(18:32
*** trown|lunch is now known as trown18:33
corvusgit-review had its rebase aborted because the cwd was created in a patch involved in the rebase18:33
clarkbfungi: bhs1 looks correct now18:33
corvusthat could probably be improved (if it hasn't already been in a later version than what i'm running) by cding out of the cwd when performing the rebase18:33
*** e0ne has joined #openstack-infra18:34
corvusoh, nope still wrong.  one more revision.18:34
fungicorvus: i concur, a story about that would be awesome. also, git-review ought to refuse to push commits while a rebase is in progress (not finalized)?18:34
openstackgerritClark Boylan proposed openstack-infra/system-config master: Cleanup zuul-mergers in groups.yaml  https://review.openstack.org/61527918:34
openstackgerritClark Boylan proposed openstack-infra/system-config master: Cleanup zuul-executors in groups.yaml  https://review.openstack.org/61528018:34
openstackgerritClark Boylan proposed openstack-infra/system-config master: Simpligy logstash nodes in groups.yaml  https://review.openstack.org/61528118:35
openstackgerritClark Boylan proposed openstack-infra/system-config master: Simplify mirror node listings in groups.yaml  https://review.openstack.org/61528218:35
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Configure opendev nameservers using ansible  https://review.openstack.org/61487018:35
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Move start_services to all.yaml  https://review.openstack.org/61495918:35
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Reload nameservers when config changes  https://review.openstack.org/61527818:35
mordredfungi: I actually frequently git review halfway up a stack18:35
mordredon purpose18:35
mordredbut I'm weird18:35
clarkbI'm breaking up those cleanups by logical groups of services so that it is easier for us to monitor them and be happy with their running state as the changes go in18:36
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Configure adns1.opendev.org server via ansible  https://review.openstack.org/61464818:36
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Configure opendev nameservers using ansible  https://review.openstack.org/61487018:36
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Move start_services to all.yaml  https://review.openstack.org/61495918:36
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Reload nameservers when config changes  https://review.openstack.org/61527818:36
*** ykarel_ is now known as ykarel18:37
openstackgerritClark Boylan proposed openstack-infra/system-config master: Simplify nodepool groups.yaml membership  https://review.openstack.org/61528418:38
fungiclarkb: judging from file timestamps, i'm guessing the mirrors were rejecting traffic to those ports between ~17:00-18:30z18:38
AJaegerclarkb, fungi, mordred, once you're done with firefighting and have time for a review I would appreciate if you could look at my stack starting at  https://review.openstack.org/615236 - it copies the content of the newish publish-to-pypi-python3 to publish-to-pypi - and then removes publish-to-pypi-python3. We really don't need both.18:38
clarkbfungi: ya it was 16:50 somethign when the rules.v4 file was written on bhs1 before18:38
openstackgerritDoug Hellmann proposed openstack-infra/yaml2ical master: add base class for recurrence  https://review.openstack.org/61526718:39
openstackgerritDoug Hellmann proposed openstack-infra/yaml2ical master: add day_specifier to recurrence  https://review.openstack.org/61526818:39
fungiclarkb: 16:58 is what i saw18:39
fungiaccording to my shell buffer18:39
clarkbfungi: same here18:40
fungiand you confirmed it corrected at 18:3318:40
mordredclarkb: I love Simpligigation18:40
fungiokay, the mirror ansible run finally completed18:40
fungijust moments ago now18:40
*** zul has joined #openstack-infra18:41
fungithe etherpad kicks are also done18:41
openstackgerritClark Boylan proposed openstack-infra/system-config master: Simplify zookeeper groups.yaml membership  https://review.openstack.org/61528818:41
mordredfungi: woot18:42
clarkbfungi: mordred that leaves us mostly with cleanup and simplification and the emergency file situation?18:42
fungii thnik so18:42
clarkbfwiw I'm going to do a few more simplification changes then go find lunch18:42
*** shrasool has joined #openstack-infra18:42
mordredclarkb, fungi: what's the emergency file situtation?18:43
openstackgerritClark Boylan proposed openstack-infra/system-config master: Simplify git backend server groups.yaml membership  https://review.openstack.org/61529018:43
clarkbmordred: 17:33:44*           fungi | [WARNING]: Unable to parse /etc/ansible/hosts/emergency.yaml as an inventory18:43
fungimordred: ansible is looking for the emergency disable file with a .yaml extension and not finding it18:43
mordredahhh. yeah. kk. patch coming18:44
fungiit also seems to be finding (and using) the one without the .yaml suffix for the moment18:44
fungiso i don't think we ran against anything we had expressly disabled, at least18:44
mordredfungi: ok. I made an emergency.yaml that's got the content from the original emergency file18:46
openstackgerritClark Boylan proposed openstack-infra/system-config master: Simplify elasticsearch cluster groups.yaml membership  https://review.openstack.org/61529318:46
*** fried_rolls is now known as fried_rice18:46
*** jamesmcarthur has joined #openstack-infra18:47
fungiyeah, i figured that was all that was required18:48
mordredfungi: I'm going to move the old file out of the way and run 'ansible disabled --list-hosts' just to make sure18:49
mordredfungi: looks like a sane list18:49
* clarkb finds food18:50
clarkboh before I do that. fungi you think we are good to send a ntoice that jobs can be recheckedn ow?18:51
openstackgerritAndreas Jaeger proposed openstack-infra/openstack-zuul-jobs master: Remove publish-to-pypi-python3  https://review.openstack.org/61524118:51
mordredfungi: hah. all of the hosts in the emergency file are in the main disabled list18:51
mordredfungi: I'm going to remove them from emergency18:51
clarkbhow about #status notice The firewall situation with ports 8080, 8081, and 8082 on mirror nodes has been resolved. You can recheck jobs that have failed to communicate to the mirrors on those ports now.18:51
mordred++18:52
clarkbmwhahaha: ^ fyi18:52
mwhahahagracias18:52
clarkb#status notice The firewall situation with ports 8080, 8081, and 8082 on mirror nodes has been resolved. You can recheck jobs that have failed to communicate to the mirrors on those ports now.18:52
openstackstatusclarkb: sending notice18:52
*** EvilienM is now known as EmilienM18:53
fungiclarkb: yeah, we're all clear i think18:53
fungisorry, just trying to figure out these new cloud accounts18:53
fungii'm getting "The request you have made requires authentication." from openstackclient18:53
corvusfungi: for which cloud(s)?18:53
-openstackstatus- NOTICE: The firewall situation with ports 8080, 8081, and 8082 on mirror nodes has been resolved. You can recheck jobs that have failed to communicate to the mirrors on those ports now.18:54
fungicorvus: new credentials gary_perkins provided me earlier today18:54
fungimore arm resources i think18:54
clarkbya this is the arm arm cloud aiui18:55
fungi"armci"18:55
*** ykarel is now known as ykarel|away18:55
fungihosted in a packethost facility in japan18:55
openstackstatusclarkb: finished sending notice18:56
fungiooh, progress. i was missing the project_domain_name and user_domain_name18:57
mordredthose are important for keystone v318:58
funginow i just need to work out the self-signed cert18:58
fungimordred: well, to be more specific, i had them set to "default" but there's an actual non-default domain for them18:58
mordredyou should be able to provide a ca bundle - I think we do that for one of the other clouds already18:58
fungiyup18:58
mordredfungi: ah - yes - it's even MORE important if there is an actual domain :)18:58
fungii'm copying that now, i just need to grab the cert via openssl s_client18:59
corvusmordred: clarkb has a few more groups.yaml changes if you want to +3 those too18:59
corvusmordred: 615288 and children18:59
*** ykarel|away has quit IRC19:01
fungimordred: oh! this might be a keystone catalog problem actually?19:02
fungithe cert is letsencrypt signed19:02
fungigetting this from osc:19:02
fungiSSL exception connecting to https://136.144.53.18:8774/v2.1/63ff25c687f3458cbf98a53936ca9bbf/servers/detail: HTTPSConnectionPool(host='136.144.53.18', port=8774): Max retries exceeded with url: /v2.1/63ff25c687f3458cbf98a53936ca9bbf/servers/detail (Caused by SSLError(CertificateError("hostname '136.144.53.18' doesn't match 'arm64ci.cloud'",),))19:03
mordredfungi: yah. looks like that catalog is listing ips19:03
mordredfungi: is this in a clouds.yaml on bridge? or just locally?19:03
fungimordred: in ~fungi/armci.yaml on bridge.o.o19:04
*** bobh has quit IRC19:04
fungii was trying to get it working well enough with the temporary passwords so i could use the keystone api to set some new passwords before recording them in our usual places19:04
mordredfungi: import openstack ; c=openstack.connect(cloud='foo') ; c.pprint(c.service_catalog)19:04
mordredis a nice way to look at the catalog19:05
*** e0ne has quit IRC19:05
mordredfungi: and yes - they are returning ips not hostnames in their catalog19:06
fungii suppose that's fairly trivially configurable?19:07
fungiit looks like it's the same ip address that the cn resolves to in dns19:07
mordredfungi: it's data entries in the keystone database19:07
*** pcaruana has quit IRC19:08
mordredso they either need to delete and re-add all of the services in via the api - or do an sql query to update things19:08
*** jamesmcarthur has quit IRC19:08
fungigot it19:08
fungithanks!19:08
mordredsure nuff - for now, you can work around by adding "insecure: true"19:08
mordredwhich will completely ignore all of the security provided by ssl19:09
clarkbit will still ssl right? just verify nothing?19:10
clarkbfyi logstash.o.o is not going to currently manage indexing jobs beacuse the firewall is broken there. But one of my approved cleanups to the inventory groups.yaml file should fix that(just pointing it out if anyone notices)19:12
mordredclarkb: yes, that's right19:13
corvusclarkb: test failures are coming back on the groups cleanup patches19:14
clarkbcorvus: bah19:14
clarkblet me look19:14
fungithanks mordred, i'll pass the catalog info along to gary_perkins19:14
clarkbcorvus: its a side effect of our fix for mirrors. I'll rebase the fix for that under my stack19:14
*** betherly has joined #openstack-infra19:16
corvusclarkb: it looks like the unit test for the groups has test fixtures which more or less assert the current state19:16
*** gtmanfred has quit IRC19:17
clarkbcorvus: ya the issue is results.yaml in the test-fixtures dir wants mirror02.something in webservers group which we took the mirrors out of19:17
clarkbI'm rerunning tox.ini locally to make sure that is the only fix that is needed19:17
corvusclarkb: what's with the groups.yaml fixture?19:17
clarkbcorvus: that is a symlink to our actual groups.yaml file19:18
clarkbcorvus: I think its in the test-fixtures dir for ease of finding the path to it relative to the test script19:18
corvusoh... that's an interesting choice :)19:18
corvusok then yeah, i agree this should be a straightforward fix19:18
fungifigures bypassing ci on changes would wedge our tests ;)19:19
fungi_every_time_19:19
corvusfungi: it has *never* failed to do so :)19:19
corvusi'm going to get a sandwich19:19
fungithat sounds like a capital idea19:19
*** gtmanfred has joined #openstack-infra19:20
openstackgerritClark Boylan proposed openstack-infra/system-config master: Cleanup zuul-mergers in groups.yaml  https://review.openstack.org/61527919:20
openstackgerritClark Boylan proposed openstack-infra/system-config master: Cleanup zuul-executors in groups.yaml  https://review.openstack.org/61528019:20
openstackgerritClark Boylan proposed openstack-infra/system-config master: Simpligy logstash nodes in groups.yaml  https://review.openstack.org/61528119:20
openstackgerritClark Boylan proposed openstack-infra/system-config master: Simplify mirror node listings in groups.yaml  https://review.openstack.org/61528219:20
openstackgerritClark Boylan proposed openstack-infra/system-config master: Simplify nodepool groups.yaml membership  https://review.openstack.org/61528419:20
openstackgerritClark Boylan proposed openstack-infra/system-config master: Simplify zookeeper groups.yaml membership  https://review.openstack.org/61528819:20
openstackgerritClark Boylan proposed openstack-infra/system-config master: Simplify git backend server groups.yaml membership  https://review.openstack.org/61529019:20
openstackgerritClark Boylan proposed openstack-infra/system-config master: Simplify elasticsearch cluster groups.yaml membership  https://review.openstack.org/61529319:20
openstackgerritClark Boylan proposed openstack-infra/system-config master: Remove mirrors from webservers in groups test  https://review.openstack.org/61530019:20
clarkbI think ^ fixes it19:20
fungimordred: thanks again, the insecure: true option does indeed seem to have worked around it for me in the meantime19:20
*** betherly has quit IRC19:21
clarkbfungi: isn't it great how universal that law of testing is?19:22
*** apetrich has quit IRC19:24
*** eharney has quit IRC19:24
*** bobh has joined #openstack-infra19:25
*** shrasool has quit IRC19:27
*** jamesmcarthur has joined #openstack-infra19:28
fungiyeah, i continue to be amazed by it. even something as simple as a one-line change19:28
*** shrasool has joined #openstack-infra19:32
*** lpetrut has joined #openstack-infra19:34
*** finucannot is now known as stephenfin19:35
*** jistr has quit IRC19:35
*** jistr has joined #openstack-infra19:37
*** apetrich has joined #openstack-infra19:38
*** shrasool has quit IRC19:41
clarkbits looking like that fix for the test will fix things19:42
AJaegergreat!19:44
*** betherly has joined #openstack-infra19:46
clarkbAJaeger: question about the openstack python release thing. Are we using that anywhere for infra. I am not sure all of our things are python3 safe yet (gerritbot for example)19:50
*** betherly has quit IRC19:50
clarkbwhat do you know its got the python3 job on it now19:51
clarkbso maybe it does and if it doesn't I guess we fix that later19:51
AJaegerI can test on gerritbot...19:51
clarkbAJaeger: I +2'd since we've already transitioned the jobs to python3. If we really need to you can do the inverse and add a pytho2n specific template later19:52
AJaegerYes, we use publish-to-pypi in many places - but the job is very simple, it's just "python3 setup.py sdist bdist_wheel "19:52
clarkb(I do think having defaults be python3 then explicitly opt into python2 instead of what we've doing is best)19:52
AJaegerclarkb: yeah, that is one option...19:52
openstackgerritAndreas Jaeger proposed openstack-infra/gerritbot master: DNM: Testing publish-to-pypi-python3  https://review.openstack.org/61530419:55
AJaegerclarkb: gerritbot test ^19:55
AJaegerclarkb's stack passes - any infra-root to +2 the bottom of it? https://review.openstack.org/#/c/615300/19:58
*** kgiusti has left #openstack-infra19:59
AJaegerclarkb: https://review.openstack.org/615304 is passing20:03
clarkbAJaeger: cool so probably a non issue then20:03
corvusmordred: 615288 and children can use a +320:06
*** jamesmcarthur has quit IRC20:07
AJaegercorvus, mordred first 615300 needs a +3...20:08
*** eharney has joined #openstack-infra20:15
AJaegermordred: children are 615290 and 615293 - if you like to merge full stack...20:16
mordredAJaeger: done20:18
AJaegerthanks20:19
AJaegermordred: what do you think of the stack starting at https://review.openstack.org/#/c/615236/ ? You looked earlier at it, now it should be ready...20:20
AJaegerthanks, mordred20:22
mordred\o/20:22
AJaegerclarkb, mordred, want to review the rest of the stack as well, please? https://review.openstack.org/#/q/topic:publish-pypi+(status:open+OR+status:merged) - I'll recheck once bits are merged...20:22
clarkbAJaeger: https://review.openstack.org/#/c/615237/2 probably deserves email when it merges20:26
AJaegerclarkb: I'll send one now...20:26
*** Swami has joined #openstack-infra20:27
*** jamesmcarthur has joined #openstack-infra20:28
openstackgerritMerged openstack-infra/project-config master: Use python3 for release  https://review.openstack.org/61523620:33
clarkbok where was I? project update slide brainstorming20:33
openstackgerritMerged openstack-infra/system-config master: Remove mirrors from webservers in groups test  https://review.openstack.org/61530020:33
*** lpetrut has quit IRC20:35
*** betherly has joined #openstack-infra20:35
openstackgerritMerged openstack-infra/system-config master: Cleanup zuul-mergers in groups.yaml  https://review.openstack.org/61527920:36
openstackgerritMerged openstack-infra/system-config master: Cleanup zuul-executors in groups.yaml  https://review.openstack.org/61528020:38
openstackgerritMerged openstack-infra/system-config master: Simpligy logstash nodes in groups.yaml  https://review.openstack.org/61528120:38
openstackgerritMerged openstack-infra/system-config master: Simplify mirror node listings in groups.yaml  https://review.openstack.org/61528220:40
openstackgerritMerged openstack-infra/system-config master: Simplify nodepool groups.yaml membership  https://review.openstack.org/61528420:40
*** betherly has quit IRC20:40
openstackgerritMerged openstack-infra/system-config master: Simplify zookeeper groups.yaml membership  https://review.openstack.org/61528820:43
openstackgerritMerged openstack-infra/system-config master: Simplify git backend server groups.yaml membership  https://review.openstack.org/61529020:43
openstackgerritMerged openstack-infra/system-config master: Simplify elasticsearch cluster groups.yaml membership  https://review.openstack.org/61529320:43
AJaeger\o/20:44
*** eharney has quit IRC20:46
AJaegermordred: could you review https://review.openstack.org/615237  and https://review.openstack.org/615239 as well, please?20:47
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Configure adns1.opendev.org server via ansible  https://review.openstack.org/61464820:50
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Configure opendev nameservers using ansible  https://review.openstack.org/61487020:50
fungigonna go grab some dinner, back later20:55
*** bobh has quit IRC20:59
*** abishop has quit IRC21:02
mordredAJaeger: done21:03
*** bobh has joined #openstack-infra21:03
AJaegerthanks, mordred  - can you review pbrx as well, please? https://review.openstack.org/61529621:03
*** jamesmcarthur has quit IRC21:04
mordredall done21:04
*** yamamoto has joined #openstack-infra21:05
*** jamesmcarthur has joined #openstack-infra21:05
AJaegerthanks21:05
*** jamesmcarthur has quit IRC21:08
*** bobh has quit IRC21:09
*** yamamoto has quit IRC21:09
openstackgerritMerged openstack-infra/openstack-zuul-jobs master: Sync publish-to-pypi templates  https://review.openstack.org/61523721:09
*** jamesmcarthur has joined #openstack-infra21:13
corvusmordred, clarkb, fungi: the opendev nameserver changes https://review.openstack.org/614648 and https://review.openstack.org/614870 pass tests now; i'd appreciate a +3 and we should be able to get those in production next week21:15
clarkbcorvus: great I'll take a look shortly21:18
*** shrasool has joined #openstack-infra21:23
openstackgerritMerged openstack-infra/project-config master: Use publish-to-pypi everywhere  https://review.openstack.org/61523921:25
openstackgerritAndreas Jaeger proposed openstack-infra/infra-manual master: Fix link to publish-to-pypi  https://review.openstack.org/61532921:29
openstackgerritJames E. Blair proposed openstack-infra/zuul master: DNM: extra debugging  https://review.openstack.org/61533021:30
AJaegerclarkb, mordred, fungi, small update for the publish-to-pypi change for infra-manual in https://review.openstack.org/61532921:31
clarkblooks like logstash.o.o is working again21:31
*** dave-mccowan has quit IRC21:35
clarkbcorvus: https://review.openstack.org/#/c/614648/11..16/playbooks/roles/master-nameserver/tasks/main.yaml you stopped checking if the service should be started or not, but the test remains in place to check if the service is started. Does bind9 start automatically when the package is installed?21:35
*** betherly has joined #openstack-infra21:37
*** jamesmcarthur has quit IRC21:38
*** rlandy has quit IRC21:41
*** betherly has quit IRC21:41
*** jamesmcarthur has joined #openstack-infra21:42
corvusclarkb: yes, they both do, so i simplified21:42
corvusclarkb: with nsd, we needed to write the config before installing the package anyway (because it starts on install), so i figured we could just rely on that for now.21:43
corvus(the default config for nsd breaks for us because it listens on 0.0.0.0)21:43
clarkbya I got to nsd and realized that must be what is happening21:43
clarkbfungi: re etherpad, maybe we want to redeploy it without the hwe kernel after the summit? I worry about changing much on it now that we've appeared to get it stable and happy21:44
*** jamesmcarthur has quit IRC21:47
*** jamesmcarthur has joined #openstack-infra21:48
*** boden has quit IRC21:51
*** jamesmcarthur has quit IRC21:52
*** jamesmcarthur has joined #openstack-infra22:06
*** munimeha1 has quit IRC22:06
*** jamesmcarthur has quit IRC22:10
openstackgerritJames E. Blair proposed openstack-infra/zuul master: DNM: extra debugging  https://review.openstack.org/61533022:19
*** rossella_s has quit IRC22:21
fungiclarkb: yeah, i haven't seen evidence that the hwe kernel made any observable difference in performance there22:22
*** shrasool has quit IRC22:24
fungiclarkb: we *can* also just swap back to the non-hwe kernel and reboot. no need to redeploy22:25
fungiboth are installed and available22:25
clarkbya the kernel tends to be pretty good about forward and backward compatibility22:26
fungithey're parallel packages, it's not as if there's any overlap22:26
*** shrasool has joined #openstack-infra22:27
clarkbmostly I think its happy now so don't want to keep changing it this close to summit :)22:28
*** shrasool has quit IRC22:28
fungik22:28
corvuspfft.  summit isn't until november.22:30
clarkbcorvus: don't look at a calendar22:30
clarkbI looked this morning and got scared. I need to put head down and get slides/talk/forum stuff done next week22:30
fungitime is an illusion22:32
corvuslunchtime doubly so22:32
fungii continue to use "missing, presumed fed" as my lunchtime /away message22:33
clarkbalso for people not in Oregon Tuesday probably involves physically going to a polling station. I get to drop my ballot off tonight22:33
fungiclarkb: north carolina hasn't officially announced that they burn early voting ballots in a big pile yet, so i cast mine a couple weeks ago22:34
corvusmine weighs like 10 pounds22:34
fungiwas encouraged to discover that sometime in the past few months nc also decided to completely get rid of electronic voting machines in favor of good old-fashioned paper ballots and a pen22:35
clarkbfungi: oh nice. In oregon we get a paper ballot with scantron bubbles you fill in then send back in the mail (or if you are like me wait too long for USPS to deliver it on time so have to drop it off in a collection box)22:35
corvusfungi: that is good and surprising news22:35
logan-fungi: in texas we use electronic voting machines that autocorrect your ballot for you22:35
clarkblogan-: the computers know best22:36
fungii suppose the scantrons could still get hacked, but that seems like it would take a much more concerted effort22:36
corvusfungi: and you can always recount scantrons manually22:36
clarkbwashington has the best voting process I've run into yet. Its like Oregon's in most ways except that your ballot counts if post marked on election day22:36
clarkbthis does mean it usually takes washington a few extra days to certify results though22:37
corvus(or run them through different scantrons)22:37
fungicorvus: well, someone can anyway. those people can also be hacked of course22:37
corvusfungi: i think you just came up with an election-themed slasher movie22:37
fungior a new season of ghost in the shell22:37
clarkbthe other thing Oregon did recentlyish was automagic voter registration through the dmv22:38
clarkbI wonder what that will do for turnout22:39
fungiour dmv gives you the option to register to vote when you get/renew your license (and update your registration if you file an address change for your driver's license). is oregon going further? opt-out?22:40
clarkbfungi: ya opt out22:40
clarkbbrainstorming of berlin infra onboarding https://etherpad.openstack.org/p/openstack-infra-berlin-onboarding22:41
clarkbdtroyer: ^ happy for feedback on what you think would be valuable for starlingx22:41
*** erlon has quit IRC22:43
*** bobh has joined #openstack-infra22:44
*** jamesmcarthur has joined #openstack-infra22:47
*** bobh has quit IRC22:50
*** jamesmcarthur has quit IRC22:51
*** jcoufal has quit IRC22:54
*** ianychoi has quit IRC23:02
*** owalsh has quit IRC23:16
*** owalsh has joined #openstack-infra23:17
*** shardy_ has quit IRC23:18
*** shardy has quit IRC23:18
*** mriedem has quit IRC23:18
*** shrasool has joined #openstack-infra23:19
*** roman_g has quit IRC23:23
openstackgerritJames E. Blair proposed openstack-infra/zuul master: WIP: Set relative priority of node requests  https://review.openstack.org/61535623:24
openstackgerritJames E. Blair proposed openstack-infra/zuul master: Merger: automatically add new hosts to the known_hosts file  https://review.openstack.org/60845323:30
*** jtomasek has quit IRC23:31
*** betherly has joined #openstack-infra23:39
*** markvoelker has joined #openstack-infra23:41
openstackgerritMerged openstack-infra/system-config master: Configure adns1.opendev.org server via ansible  https://review.openstack.org/61464823:41
*** dhill_ has quit IRC23:43
*** betherly has quit IRC23:43
*** Swami has quit IRC23:44
*** markvoelker has quit IRC23:46
*** gyee has quit IRC23:48
*** ianychoi has joined #openstack-infra23:55

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!