*** brinzhang0 has joined #openstack-kolla | 00:09 | |
*** brinzhang_ has quit IRC | 00:12 | |
*** markmcclain has quit IRC | 00:13 | |
*** markmcclain has joined #openstack-kolla | 00:15 | |
*** markmcclain has quit IRC | 00:24 | |
*** keper7 has quit IRC | 00:49 | |
*** brinzhang0 has quit IRC | 00:51 | |
*** zhanglong has joined #openstack-kolla | 00:52 | |
*** xinliang has joined #openstack-kolla | 00:54 | |
*** kevko has quit IRC | 01:13 | |
*** devfaz has quit IRC | 02:03 | |
*** devfaz has joined #openstack-kolla | 02:04 | |
*** rphillips_ has joined #openstack-kolla | 02:05 | |
*** zzzeek has quit IRC | 02:05 | |
*** mgoddard has quit IRC | 02:05 | |
*** weshay|ruck has quit IRC | 02:05 | |
*** timburke has quit IRC | 02:05 | |
*** weshay has joined #openstack-kolla | 02:06 | |
*** rphillips has quit IRC | 02:06 | |
*** benj_ has quit IRC | 02:06 | |
*** benj_ has joined #openstack-kolla | 02:07 | |
*** ricolin has quit IRC | 02:09 | |
*** dciabrin has quit IRC | 02:10 | |
*** dciabrin has joined #openstack-kolla | 02:10 | |
*** zzzeek has joined #openstack-kolla | 02:11 | |
*** timburke has joined #openstack-kolla | 02:11 | |
*** mgoddard has joined #openstack-kolla | 02:13 | |
*** ricolin has joined #openstack-kolla | 02:19 | |
*** dave-mccowan has quit IRC | 02:44 | |
*** jcmdln has quit IRC | 03:29 | |
*** vishalmanchanda has joined #openstack-kolla | 03:30 | |
*** suryasingh has joined #openstack-kolla | 03:51 | |
*** zhanglong has quit IRC | 04:07 | |
*** bengates has joined #openstack-kolla | 04:10 | |
*** bengates has quit IRC | 04:15 | |
*** xinliang has quit IRC | 04:28 | |
*** evrardjp has quit IRC | 04:33 | |
*** evrardjp has joined #openstack-kolla | 04:33 | |
*** skramaja has joined #openstack-kolla | 04:37 | |
*** abdysn has joined #openstack-kolla | 05:00 | |
*** zhanglong has joined #openstack-kolla | 05:17 | |
openstackgerrit | caoyuan proposed openstack/kolla-ansible stable/ussuri: Mount /etc/timezone based on host OS https://review.opendev.org/746017 | 05:19 |
---|---|---|
openstackgerrit | caoyuan proposed openstack/kolla-ansible stable/train: Mount /etc/timezone based on host OS https://review.opendev.org/746018 | 05:19 |
openstackgerrit | caoyuan proposed openstack/kolla-ansible master: Standardize use and construction of endpoint URLs https://review.opendev.org/652157 | 05:20 |
*** brinzhang has joined #openstack-kolla | 05:42 | |
*** cah_link has joined #openstack-kolla | 06:06 | |
*** dmellado has quit IRC | 06:11 | |
*** zijlboot has joined #openstack-kolla | 06:11 | |
*** zhanglong has quit IRC | 06:29 | |
*** dmellado has joined #openstack-kolla | 06:41 | |
*** patchbot has quit IRC | 06:41 | |
*** happyhemant has joined #openstack-kolla | 06:42 | |
oyrogerg | Back to chewing on OSA vs KA, I see that OSA recommend and include the use of https://docs.openstack.org/ansible-hardening - has that been discussed here before? | 06:52 |
*** patchbot has joined #openstack-kolla | 06:52 | |
*** xinliang has joined #openstack-kolla | 06:54 | |
yoctozepto | oyrogerg: it does not cover containerised services; we seem to have the hardening discussion from time to time but noone really picks it up to do something | 06:56 |
*** brinzhang_ has joined #openstack-kolla | 06:56 | |
*** jbadiapa has joined #openstack-kolla | 06:57 | |
oyrogerg | Ah right, so I guess they use it to harden hosts, not containers. Would it make sense to do the same for a KA deployment? | 06:58 |
oyrogerg | (Or maybe since they are using system containers they do it for them as well, but that's a side issue for this question.) | 06:59 |
yoctozepto | oyrogerg: I guess it would not hurt; nah, they speak openly it affects only the hosts | 06:59 |
*** brinzhang has quit IRC | 07:00 | |
yoctozepto | I don't know whether it would cause hiccups with docker or not; if you try, please let us know | 07:00 |
oyrogerg | Thanks, will do if we go that way. | 07:00 |
*** dmellado has quit IRC | 07:07 | |
*** bengates has joined #openstack-kolla | 07:10 | |
*** nikparasyr has joined #openstack-kolla | 07:15 | |
openstackgerrit | Radosław Piliszek proposed openstack/kolla-ansible master: Skip broken ansible-lint https://review.opendev.org/746847 | 07:20 |
openstackgerrit | Radosław Piliszek proposed openstack/kolla-ansible master: Fix tz handling for newly introduced services https://review.opendev.org/746791 | 07:21 |
openstackgerrit | Radosław Piliszek proposed openstack/kolla-ansible master: Standardize use and construction of endpoint URLs https://review.opendev.org/652157 | 07:22 |
openstackgerrit | Radosław Piliszek proposed openstack/kolla-ansible master: Fix ownership and permissions of admin-openrc.sh https://review.opendev.org/745071 | 07:24 |
openstackgerrit | Radosław Piliszek proposed openstack/kolla-ansible master: Use iSCSI multipath for libvirt https://review.opendev.org/700910 | 07:24 |
openstackgerrit | Radosław Piliszek proposed openstack/kolla-ansible master: Add cinder auth config to nova-cell nova.conf.j2 https://review.opendev.org/746039 | 07:25 |
*** hjensas has joined #openstack-kolla | 07:27 | |
*** born2bake has joined #openstack-kolla | 07:33 | |
*** e0ne has joined #openstack-kolla | 07:51 | |
*** dmellado has joined #openstack-kolla | 07:53 | |
*** muhaha has joined #openstack-kolla | 07:56 | |
openstackgerrit | Merged openstack/kolla-ansible master: Skip broken ansible-lint https://review.opendev.org/746847 | 08:02 |
openstackgerrit | Radosław Piliszek proposed openstack/kolla-ansible stable/ussuri: Skip broken ansible-lint https://review.opendev.org/746852 | 08:02 |
openstackgerrit | Radosław Piliszek proposed openstack/kolla-ansible stable/ussuri: Mount /etc/timezone based on host OS https://review.opendev.org/746017 | 08:03 |
*** gfidente has joined #openstack-kolla | 08:05 | |
openstackgerrit | Radosław Piliszek proposed openstack/kolla-ansible master: Fix fernet bootstrap and key distribution - follow up https://review.opendev.org/707080 | 08:24 |
oklhost | `zxcvbm,./ m,./uiop[] | 08:29 |
oklhost | ups, sorry | 08:29 |
*** brtknr has quit IRC | 08:36 | |
*** brtknr has joined #openstack-kolla | 08:38 | |
yoctozepto | oklhost: thanks for the passw0rd | 08:42 |
*** brtknr has quit IRC | 08:42 | |
yoctozepto | :D | 08:42 |
oklhost | :D | 08:43 |
*** brtknr has joined #openstack-kolla | 08:43 | |
oklhost | keybord cleaning :P | 08:43 |
oklhost | keyboard* | 08:43 |
*** bengates has quit IRC | 08:43 | |
*** bengates has joined #openstack-kolla | 08:44 | |
*** bengates has quit IRC | 08:49 | |
*** gfidente has quit IRC | 08:59 | |
*** gfidente has joined #openstack-kolla | 08:59 | |
*** eliaswimmer has joined #openstack-kolla | 09:03 | |
*** ewimmer_ has quit IRC | 09:04 | |
*** k_mouza has joined #openstack-kolla | 09:14 | |
*** eliaswimmer has quit IRC | 09:28 | |
*** muhaha has quit IRC | 09:36 | |
*** bengates has joined #openstack-kolla | 09:36 | |
openstackgerrit | Zihao Wang proposed openstack/kolla-ansible master: Fix sysctl config not live until reboot https://review.opendev.org/746872 | 10:04 |
openstackgerrit | Zihao Wang proposed openstack/kolla-ansible master: Fix sysctl config not live until reboot https://review.opendev.org/746872 | 10:06 |
openstackgerrit | Merged openstack/kolla-ansible master: Standardize use and construction of endpoint URLs https://review.opendev.org/652157 | 10:28 |
*** xinliang has quit IRC | 10:29 | |
*** eliaswimmer has joined #openstack-kolla | 10:39 | |
*** stingrayza has joined #openstack-kolla | 10:48 | |
*** also_stingrayza has quit IRC | 10:49 | |
*** bengates has quit IRC | 11:02 | |
*** bengates has joined #openstack-kolla | 11:09 | |
*** bengates_ has joined #openstack-kolla | 11:12 | |
*** bengates has quit IRC | 11:12 | |
*** eliaswimmer has quit IRC | 11:18 | |
*** kevko has joined #openstack-kolla | 11:21 | |
*** kevko_ has joined #openstack-kolla | 11:23 | |
*** kevko has quit IRC | 11:23 | |
*** kevko_ has quit IRC | 11:26 | |
*** kevko has joined #openstack-kolla | 11:26 | |
*** k_mouza has quit IRC | 11:30 | |
openstackgerrit | Pierre Riteau proposed openstack/kayobe master: Skip broken ansible-lint https://review.opendev.org/746896 | 11:31 |
*** eliaswimmer has joined #openstack-kolla | 11:36 | |
*** wuchunyang has joined #openstack-kolla | 11:42 | |
JamesBenson | morning all, is there an easy way to deploy the certificates but keep the cluster up? | 11:43 |
*** gfidente has quit IRC | 12:07 | |
*** ewimmer_ has joined #openstack-kolla | 12:08 | |
*** gfidente has joined #openstack-kolla | 12:09 | |
*** ewimmer_ has quit IRC | 12:10 | |
*** ewimmer_ has joined #openstack-kolla | 12:10 | |
*** eliaswimmer has quit IRC | 12:11 | |
*** wuchunyang has quit IRC | 12:15 | |
openstackgerrit | Pierre Riteau proposed openstack/kayobe stable/ussuri: Skip broken ansible-lint https://review.opendev.org/746906 | 12:28 |
r3ap3r | JamesBenson: I've been wondering that as well. I intend on using Letsencrypt for my Stack but was also thinking I may be able to just "refresh" the certs during a normal "maintenance" window one of the four times a month I would be doing that? Won't know until I try I guess? | 12:28 |
openstackgerrit | Pierre Riteau proposed openstack/kayobe stable/train: Skip broken ansible-lint https://review.opendev.org/746907 | 12:28 |
JamesBenson | r3ap3r: I was a new deploy, so I just decided to destroy and re-deploy. But please keep me posted ;-) | 12:29 |
r3ap3r | JamesBenson: will add it to my list. ;-D | 12:30 |
*** k_mouza has joined #openstack-kolla | 12:34 | |
*** muhaha has joined #openstack-kolla | 12:37 | |
*** dave-mccowan has joined #openstack-kolla | 12:38 | |
*** wuchunyang has joined #openstack-kolla | 12:39 | |
*** weshay is now known as weshay|interview | 12:47 | |
*** k_mouza has quit IRC | 12:59 | |
openstackgerrit | Merged openstack/kolla-ansible stable/train: Mount /etc/timezone based on host OS https://review.opendev.org/746018 | 13:04 |
*** k_mouza has joined #openstack-kolla | 13:05 | |
*** wuchunyang has quit IRC | 13:09 | |
*** weshay|interview is now known as weshay | 13:10 | |
r3ap3r | JamesBenson: I guess the other question to ask would be if you were just wanting the Horizon Dashboard to be accessed via HTTPS or are you also wanting to encrypt the API's as well? If you are leaning toward the former, probably no need to restart anything but maybe the Horizon container. Anything dealing with the API's, you probably want to do a "reboot" of the entire stack for something at that level. | 13:14 |
*** weshay is now known as weshay|ruck | 13:21 | |
*** priteau has joined #openstack-kolla | 13:31 | |
*** wuchunyang has joined #openstack-kolla | 13:36 | |
*** cah_link has quit IRC | 13:40 | |
openstackgerrit | wu.chunyang proposed openstack/kolla-ansible master: remove obsolete configurations https://review.opendev.org/746732 | 13:40 |
*** TrevorV has joined #openstack-kolla | 13:46 | |
*** bengates_ has quit IRC | 13:48 | |
*** bengates has joined #openstack-kolla | 13:50 | |
*** gfidente has quit IRC | 14:03 | |
*** KeithMnemonic has joined #openstack-kolla | 14:09 | |
*** gfidente has joined #openstack-kolla | 14:12 | |
*** abdysn has quit IRC | 14:15 | |
*** happyhemant has quit IRC | 14:22 | |
openstackgerrit | Merged openstack/kolla-ansible master: CI: enable Ansible SSH pipelining https://review.opendev.org/746019 | 14:38 |
*** nikparasyr has left #openstack-kolla | 14:46 | |
yoctozepto | kolla meeting in 10 minutes : mgoddard mnasiadka hrw egonzalez yoctozepto rafaelweingartne cosmicsound osmanlicilegi bbezak | 14:50 |
priteau | mgoddard and mnasiadka are both on holiday | 14:51 |
yoctozepto | priteau: yeah, sadly I know :-( the list is prerendered and we never modify it | 14:52 |
*** gfidente has quit IRC | 14:53 | |
yoctozepto | I guess you, priteau, and dougsz and jovial[m] should be on that list | 14:53 |
yoctozepto | guessing the Szumskis are not around either :-) | 14:53 |
hrw | morning | 14:55 |
*** chensa has joined #openstack-kolla | 14:58 | |
osmanlicilegi | morning | 14:59 |
*** jovial[m] has joined #openstack-kolla | 14:59 | |
chensa | did anyone manage to install ceph osb on a compute node? i cant make it work because ceph-ansible wants docker.io to be present and kolla needs docker-ce | 14:59 |
yoctozepto | chensa: you can configure ceph-ansible not to install it | 15:00 |
yoctozepto | anyhow, meeting time | 15:01 |
yoctozepto | #startmeeting kolla | 15:01 |
openstack | Meeting started Wed Aug 19 15:01:09 2020 UTC and is due to finish in 60 minutes. The chair is yoctozepto. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:01 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:01 |
*** openstack changes topic to " (Meeting topic: kolla)" | 15:01 | |
openstack | The meeting name has been set to 'kolla' | 15:01 |
yoctozepto | #topic rollcall | 15:01 |
*** openstack changes topic to "rollcall (Meeting topic: kolla)" | 15:01 | |
priteau | o/ | 15:01 |
yoctozepto | \o/ | 15:01 |
yoctozepto | roll in | 15:01 |
osmanlicilegi | o/ | 15:01 |
headphoneJames | o/ | 15:01 |
JamesBenson | o/ | 15:01 |
chensa | o/ | 15:01 |
jovial[m] | 0/ | 15:02 |
yoctozepto | guessing that's it :-) | 15:03 |
yoctozepto | #topic agenda | 15:03 |
*** openstack changes topic to "agenda (Meeting topic: kolla)" | 15:03 | |
yoctozepto | * Roll-call | 15:03 |
yoctozepto | * Announcements | 15:03 |
yoctozepto | ** Kolla Kall tomorrow (2020-08-20) | 15:03 |
yoctozepto | * Review action items from the last meeting | 15:03 |
yoctozepto | * CI status | 15:03 |
yoctozepto | * Victoria release planning (kayobe) | 15:03 |
yoctozepto | * Victoria release planning (kolla ansible) | 15:03 |
yoctozepto | * Victoria release planning (kolla) | 15:03 |
yoctozepto | #topic announcements | 15:03 |
*** openstack changes topic to "announcements (Meeting topic: kolla)" | 15:03 | |
yoctozepto | #info Kolla Kall tomorrow (2020-08-20) | 15:04 |
yoctozepto | any others? | 15:04 |
yoctozepto | guess not! | 15:05 |
yoctozepto | #topic Review action items from the last meeting | 15:05 |
*** openstack changes topic to "Review action items from the last meeting (Meeting topic: kolla)" | 15:05 | |
yoctozepto | mgoddard to message openstack-discuss about focal & victoria upgrade | 15:05 |
openstackgerrit | Pierre Riteau proposed openstack/kayobe stable/stein: Skip broken ansible-lint https://review.opendev.org/746952 | 15:05 |
hrw | o\ | 15:05 |
yoctozepto | pretty sure he did not :-) | 15:05 |
yoctozepto | #action mgoddard to message openstack-discuss about focal & victoria upgrade | 15:05 |
yoctozepto | feels like stuck in the queue! | 15:05 |
yoctozepto | #topic CI status | 15:06 |
*** openstack changes topic to "CI status (Meeting topic: kolla)" | 15:06 | |
priteau | Kayobe is RED | 15:06 |
yoctozepto | last time new ansible | 15:06 |
yoctozepto | this time new ansible-lint :-) | 15:06 |
priteau | because of ansible-lint too | 15:06 |
yoctozepto | priteau: ack | 15:06 |
priteau | I shamelessly stole your fix | 15:07 |
yoctozepto | priteau: all branches? | 15:07 |
yoctozepto | priteau: I may forgive you | 15:07 |
priteau | I submitted all the way back to stein | 15:07 |
yoctozepto | ok | 15:07 |
priteau | ansible-lint is not in upper-constraints unfortunately | 15:07 |
yoctozepto | priteau: yeah :-( | 15:07 |
yoctozepto | we could pin it completely | 15:08 |
*** kberger_ has joined #openstack-kolla | 15:08 | |
yoctozepto | kolla-ansible master got fixed | 15:08 |
openstackgerrit | Pierre Riteau proposed openstack/kayobe stable/rocky: Skip broken ansible-lint https://review.opendev.org/746955 | 15:08 |
yoctozepto | ussuri blocked by a funny situation that we branched off ussuri during victoria cycle | 15:08 |
yoctozepto | and reqs-check for ussuri never checked its deps and now it got stuck due to yamllint not being ignored :-) | 15:09 |
yoctozepto | hopefully it's only yamllint... | 15:09 |
yoctozepto | anyhow, all fixes checking/gating | 15:09 |
yoctozepto | kolla master and ussuri green | 15:09 |
yoctozepto | older red; I guess mnasiadka won't be fixing that too soon :-) | 15:09 |
*** skramaja has quit IRC | 15:10 | |
*** KeithMnemonic has quit IRC | 15:10 | |
yoctozepto | hrw: care to massage train and older kolla branches to make them GREEN? (or any other volunteers for that matter) | 15:11 |
hrw | -ENOTIME a bit | 15:11 |
yoctozepto | hrw: ack, no problem | 15:11 |
yoctozepto | #topic Victoria release planning (kayobe) | 15:12 |
*** openstack changes topic to "Victoria release planning (kayobe) (Meeting topic: kolla)" | 15:12 | |
yoctozepto | priteau, jovial[m]: anything to discuss regarding kayobe? | 15:12 |
priteau | Nothing big going on at the moment. | 15:13 |
jovial[m] | nothing from me I'm afraid | 15:13 |
yoctozepto | sure, we are all waiting till the end of cycle :-) | 15:13 |
priteau | I could highlight a few patches that I submitted recently: | 15:14 |
priteau | https://review.opendev.org/#/c/746459/ | 15:14 |
patchbot | patch 746459 - kayobe - Add support for custom Aodh configuration - 1 patch set | 15:14 |
priteau | https://review.opendev.org/#/c/746465/ | 15:14 |
patchbot | patch 746465 - kayobe - Support setting ethtool options on network interfaces - 2 patch sets | 15:14 |
jovial[m] | exactly - it's the only way to work ;-) | 15:14 |
priteau | (no need to W+1 them yet, we need to fix CI first) | 15:14 |
priteau | But having another +2 would be nice | 15:14 |
yoctozepto | priteau: enjoy my +1s, changes look sane from far perspective | 15:16 |
yoctozepto | #topic Victoria release planning (kolla ansible) | 15:17 |
*** openstack changes topic to "Victoria release planning (kolla ansible) (Meeting topic: kolla)" | 15:17 | |
priteau | jovial[m]: I said no need to W+1 :P | 15:17 |
yoctozepto | anyone willing to discuss kolla-ansible? | 15:17 |
jovial[m] | too busy looking at your patch to see that :D | 15:17 |
yoctozepto | haha | 15:17 |
hrw | I was on holidays | 15:17 |
yoctozepto | guess not much about kolla-ansible without mgoddard and mnasiadka :-) | 15:19 |
yoctozepto | #topic Victoria release planning (kolla) | 15:19 |
*** openstack changes topic to "Victoria release planning (kolla) (Meeting topic: kolla)" | 15:19 | |
yoctozepto | and for kolla itself? | 15:19 |
hrw | no one looks at infra so nothing from my side | 15:20 |
hrw | and no one started tier stuff | 15:20 |
yoctozepto | yeah, lack of time, low priority, always something more urgent to deal with | 15:20 |
yoctozepto | the big little issues | 15:20 |
yoctozepto | (and I don't mean endianess) | 15:21 |
hrw | yoctozepto: do not mention big.little | 15:21 |
yoctozepto | xD | 15:21 |
yoctozepto | I felt late it might be hrw-triggering | 15:21 |
hrw | good side: disallowed in servers ;D | 15:22 |
yoctozepto | hrw, in Polish: duże problemiki :-) | 15:22 |
yoctozepto | sad that English does not use proper diminutives | 15:22 |
yoctozepto | anyhow, not much to discuss | 15:22 |
yoctozepto | #topic Open discussion | 15:22 |
*** openstack changes topic to "Open discussion (Meeting topic: kolla)" | 15:22 | |
headphoneJames | I started considering how to integrate let's encrypt into openstack. | 15:23 |
headphoneJames | It doesn't seem trivial, and maybe warrants its own separate meeting | 15:23 |
chensa | i've got some bugs that happend to me with centos and rhel distributions if its relevant now | 15:24 |
yoctozepto | headphoneJames: we could use tomorrow's Kall; but without mgoddard and mnasiadka I would have to proxy the thoughts to them :-) | 15:24 |
hrw | I think that we need to train some new cores | 15:24 |
yoctozepto | headphoneJames: yeah, it's not trivial | 15:24 |
yoctozepto | headphoneJames: anyway, how do you imagine it? | 15:24 |
yoctozepto | I can tell you my expectation | 15:24 |
yoctozepto | at least manual refresh of certs via commands | 15:25 |
yoctozepto | which could be run from some simple cron | 15:25 |
yoctozepto | premium version that refreshes by itself | 15:25 |
yoctozepto | but for that we need some reload machinery | 15:25 |
hrw | once you have a way to replace them automation will be easy | 15:25 |
yoctozepto | we seem to be approaching this topic from another angle as well (the reload thingy) | 15:25 |
wuchunyang | hi , the octavia bp really really need to review | 15:26 |
yoctozepto | chensa: it's relevant, please speak up; our launchpad also always welcomes bug reports :-) | 15:26 |
hrw | headphoneJames: do you have a way to replace certificates with new files? | 15:26 |
hrw | headphoneJames: 1. do a way to replace certificates 2. create a way to refresh LE certs 3. automate LE refresh 4. use 1st step after 3rd one | 15:27 |
headphoneJames | Not yet to all | 15:27 |
chensa | in centOS 8 I had a bug that kolla-toolbox did not install and it affected mariaDB by not configuring the db users | 15:27 |
hrw | headphoneJames: if Henry comes from MoneyCorp and they have own SSL certs then he would use 1st to refresh certs with his own ones | 15:27 |
chensa | couldn't find any fix | 15:27 |
hrw | headphoneJames: at same time Bob will use LE | 15:28 |
yoctozepto | chensa: odd, this is the most basic and the most well tested part of kolla-ansible :-) | 15:28 |
headphoneJames | My impression is that the ansible host will need to redistribute certificates and inform containers to pick up fanook certificates | 15:28 |
yoctozepto | chensa: was it ussuri release with ussuri kolla-ansible run from centos 8 against centos 8? | 15:28 |
yoctozepto | chensa: did you report that to launchpad? it's best documented well | 15:28 |
hrw | headphoneJames: so small steps | 15:29 |
*** brinzhang0 has joined #openstack-kolla | 15:29 | |
*** gfidente has joined #openstack-kolla | 15:29 | |
yoctozepto | headphoneJames: the brutal way is to keep doing restarts but that's normally not so feasible | 15:29 |
yoctozepto | we need reloads also for regular refreshes | 15:29 |
chensa | I don't know the protocols i'm very new to kolla (2 weeks) so i didn't report anything | 15:29 |
yoctozepto | chensa: ok, no problem; the gates to bug reporting machine are here: https://bugs.launchpad.net/kolla-ansible | 15:30 |
headphoneJames | In the scenario that ansible distribute certificates, also indicates that that certbot would run on the ansible host | 15:31 |
yoctozepto | hrw, priteau, jovial[m]: would you be joining tomorrow's Kall? we could use it to review kolla/kolla-ansible bugs - the more, the merrier (as you might recognise the symptoms) | 15:31 |
yoctozepto | wuchunyang: still in my queue | 15:31 |
*** brinzhang_ has quit IRC | 15:32 | |
wuchunyang | yoctozepto thanks | 15:32 |
yoctozepto | wuchunyang: I am not knowledgeable about octavia so it gets postponed pretty much every time, hence the delay, I am really sorry about that | 15:32 |
priteau | yoctozepto: if not too busy I'll join | 15:32 |
hrw | yoctozepto: ok | 15:32 |
chensa | yoctozepto second bug was when I tried deploying openstack on rhel 8.2 ansible reports ansible_distribution variable as RedHat and not RHEL which breaks deployment | 15:32 |
chensa | its only FYI i'll report them to launchpad | 15:33 |
yoctozepto | if there is anyone around familiar with octavia, then please take a look at wuchunyang's set of patches: https://review.opendev.org/#/q/project:openstack/kolla-ansible+topic:bp/implement-automatic-deploy-of-octavia | 15:33 |
wuchunyang | i have updated octavia docs, https://review.opendev.org/#/c/746409/ , you can refer to this docs | 15:33 |
patchbot | patch 746409 - kolla-ansible - update octavia doc - 3 patch sets | 15:33 |
yoctozepto | chensa: that could be a real issue - we don't test against rhel because it's not freely available | 15:34 |
johnsom | I can also raise this at the Octavia meeting later this morning so Octavia folks can also help review. | 15:34 |
yoctozepto | johnsom: thanks, that would be awesome! | 15:35 |
yoctozepto | wuchunyang: ^^ | 15:35 |
wuchunyang | johnsom thanks | 15:36 |
yoctozepto | the goal is to make kolla-ansible really deploy ready-to-use octavia rather than just throwing basic config and containers around :-) | 15:36 |
johnsom | On the agenda. Thank you for the work! | 15:36 |
yoctozepto | yes, thanks wuchunyang for making this happen | 15:36 |
hrw | chensa: and we check for RHEL? | 15:36 |
hrw | chensa: then send a patch | 15:36 |
yoctozepto | hrw: we do have some RHEL conditionals | 15:37 |
JamesBenson | side note: before meeting I asked exactly about the certs, so def. +1 on getting this integrated | 15:37 |
yoctozepto | hrw: there were some users running centos7 containers on rhel7 | 15:37 |
chensa | hrw sorry I am very new, what does it mean to send a patch? | 15:37 |
hrw | chensa: git clone, do a change, test it, git commit changed-file;git review | 15:38 |
yoctozepto | chensa: please get acquainted with https://docs.openstack.org/kolla-ansible/latest/contributor/index.html | 15:38 |
hrw | o! better | 15:38 |
yoctozepto | it explains some of the things we already said and draws the whole picture linking to other relevant docs | 15:39 |
JamesBenson | I've found a bug also with enable_cinder: "yes" & enable_cinder_backend_*: "no" | 15:39 |
yoctozepto | if anything is unclear, then please reach out to us | 15:39 |
JamesBenson | the prechecks will fail stating it needs a backend | 15:39 |
JamesBenson | this is on centos distro | 15:39 |
hrw | chensa: you mean RHEL in ansible/roles/prechecks/vars/main.yml file? | 15:39 |
yoctozepto | JamesBenson: ah, yeah; it prevents doing a out-of-kolla backend config as a sole one | 15:40 |
*** bengates has quit IRC | 15:40 | |
JamesBenson | yeah | 15:40 |
yoctozepto | JamesBenson: it might have been reported; please report to launchpad if not | 15:40 |
yoctozepto | JamesBenson: or ping in the current one | 15:40 |
JamesBenson | I'll double check, I didn't see it earlier when I check | 15:40 |
openstackgerrit | Michal Arbet proposed openstack/kolla-ansible master: Fix kolla-ansible not reflect environment changed https://review.opendev.org/746965 | 15:40 |
openstackgerrit | Pierre Riteau proposed openstack/kolla-ansible master: Add workaround for keystonemiddleware/neutron memcached issue https://review.opendev.org/746966 | 15:41 |
headphoneJames | regarding certs / letsencrypt - perhaps first step is simply just developing a certificate distribution command that is separate from deploy. Deal with lets encrypt second | 15:41 |
yoctozepto | JamesBenson: it might have been told me on irc, I have weird memory | 15:41 |
hrw | headphoneJames: yes. | 15:41 |
hrw | headphoneJames: look at Henry usecase I gave before | 15:41 |
yoctozepto | hrw: that totally makes sense | 15:41 |
JamesBenson | headphoneJames: totally agree | 15:41 |
chensa | @hrw yes, but I think they changed it only for the latest versions of RHEL.. might need to accept both | 15:41 |
yoctozepto | totally totally | 15:41 |
hrw | chensa: sure | 15:42 |
hrw | chensa: at sme time it is trivial enough change for new contributor to learn how stuff works | 15:42 |
JamesBenson | regarding certs: will there have to be a usecase for when the certs are pulled into the images as well? "kolla_copy_ca_into_containers" | 15:42 |
yoctozepto | chensa, hrw: I guess it could be ansible that changed things; or it was just broken and rhel users just brute-patched it for themselves | 15:43 |
yoctozepto | :-) | 15:43 |
JamesBenson | yoctozepto: I think I might have mentioned it earlier too, I've been a bit scattered as of late, juggling a ton atm. | 15:43 |
hrw | JamesBenson: I think it depends on how many certs you plan to have. | 15:43 |
yoctozepto | JamesBenson: welcome in the club | 15:43 |
hrw | some systems will want 1 cert for horizon frontend and other for infra. some may want cert per service? | 15:44 |
hrw | some will just use one for everything including frontend | 15:44 |
hrw | just to have TLS on connections | 15:44 |
JamesBenson | hrw: Plan for everything, that's my saying... | 15:44 |
hrw | plan for simple. implement. plan bigger. implement | 15:45 |
hrw | How to eat an elephant? | 15:45 |
yoctozepto | plan for planning... oh wait | 15:45 |
hrw | Piece by piece. | 15:45 |
headphoneJames | Would there have to be a mapping file to indicate where certs should be distributed? Could it be done by directory? Is it just a new config property per service? | 15:45 |
yoctozepto | headphoneJames: would the current deploy approach be bad? just focused on getting certs though | 15:46 |
*** patchbot has quit IRC | 15:47 | |
JamesBenson | Could the certs just be in a directory like on the deploy node /kolla/certificates and have the containers pull them in on start? | 15:47 |
JamesBenson | then it could just be a simple restart the container? | 15:47 |
*** patchbot has joined #openstack-kolla | 15:47 | |
yoctozepto | (and reload in the future) | 15:47 |
openstackgerrit | Doug Szumski proposed openstack/kolla-ansible master: Add workaround for keystonemiddleware/neutron memcached issue https://review.opendev.org/746966 | 15:47 |
headphoneJames | Just pull all certs over to each service? | 15:47 |
hrw | "docker run -v/etc/kolla/certs:/etc/kolla/certs nova-compute" | 15:48 |
hrw | headphoneJames: what is already implemented? | 15:48 |
JamesBenson | yeah, distribute certs to folder on nodes, then issue the command above from hrw | 15:48 |
*** dougsz has joined #openstack-kolla | 15:49 | |
headphoneJames | currently, we search for a cert and copy it modifying the name | 15:49 |
JamesBenson | maybe 2 certs folders, one for previous to roll back if issues, and another for current | 15:49 |
headphoneJames | https://www.irccloud.com/pastebin/kdUOL362/ | 15:49 |
JamesBenson | Also with my deploy yesterday/today I noticed that if certs are there, they wont overwrite. | 15:50 |
headphoneJames | ansible/roles/service-cert-copy/tasks/main.yml | 15:50 |
JamesBenson | And that certs are deleted upon destroy. | 15:50 |
yoctozepto | I guess the discussion stalled with that sad news :-) | 15:55 |
openstackgerrit | Pierre Riteau proposed openstack/kolla-ansible master: Add workaround for keystonemiddleware/neutron memcached issue https://review.opendev.org/746966 | 15:55 |
yoctozepto | thank you all for participating; and remember about the Kolla Kall tomorrow: same time, different place: https://wiki.openstack.org/wiki/Meetings/Kolla/Kall | 15:56 |
yoctozepto | #endmeeting | 15:56 |
*** openstack changes topic to "Vote on Victoria priorities https://bit.ly/2ActPtx | IRC meetings on Wednesdays @ 15:00 UTC - agenda @ https://goo.gl/OXB0DL | Whiteboard: https://bit.ly/2MM7mWF | IRC channel is *LOGGED* @ http://goo.gl/3mzZ7b" | 15:56 | |
openstack | Meeting ended Wed Aug 19 15:56:11 2020 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:56 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/kolla/2020/kolla.2020-08-19-15.01.html | 15:56 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/kolla/2020/kolla.2020-08-19-15.01.txt | 15:56 |
openstack | Log: http://eavesdrop.openstack.org/meetings/kolla/2020/kolla.2020-08-19-15.01.log.html | 15:56 |
headphoneJames | yoctozepto: thanks | 15:56 |
openstackgerrit | Pierre Riteau proposed openstack/kolla-ansible master: Add workaround for keystonemiddleware/neutron memcached issue https://review.opendev.org/746966 | 15:56 |
hrw | tensorflow works ;d | 15:57 |
openstackgerrit | zhoulinhui proposed openstack/kayobe master: Remove XenAPI integration https://review.opendev.org/746971 | 16:00 |
*** muhaha has quit IRC | 16:09 | |
*** keper7 has joined #openstack-kolla | 16:09 | |
openstackgerrit | wu.chunyang proposed openstack/kolla-ansible master: remove obsolete configurations https://review.opendev.org/746732 | 16:12 |
*** gfidente is now known as gfidente|afk | 16:18 | |
*** zijlboot has quit IRC | 16:20 | |
*** wuchunyang has quit IRC | 16:22 | |
*** gfidente|afk has quit IRC | 16:23 | |
*** gfidente has joined #openstack-kolla | 16:25 | |
*** _Cyclone_ has joined #openstack-kolla | 16:34 | |
*** dougsz has quit IRC | 16:36 | |
openstackgerrit | Merged openstack/kolla-ansible master: Fix ownership and permissions of admin-openrc.sh https://review.opendev.org/745071 | 16:46 |
*** gfidente has quit IRC | 16:48 | |
*** chensa has quit IRC | 17:02 | |
*** k_mouza has quit IRC | 17:05 | |
*** gfidente has joined #openstack-kolla | 17:13 | |
*** k_mouza has joined #openstack-kolla | 17:15 | |
*** k_mouza has quit IRC | 17:20 | |
*** e0ne has quit IRC | 17:44 | |
yankcrime | anyone hit any problems with the upgrade to libvirt that's package as part of ussuri images? | 17:47 |
*** brinzhang_ has joined #openstack-kolla | 17:47 | |
yankcrime | "Failed to start libvirt guest: libvirt.libvirtError: Requested operation is not valid: format of backing image '/var/lib/nova/instances/_base/c3395c4245b7573c83342d68a0d0ea675b7a1722' of image '/var/lib/nova/instances/947df0d3-5aab-456d-a200-63b055934a43/disk' was not specified in the image metadata" | 17:48 |
yankcrime | https://bugs.launchpad.net/nova/+bug/1864020 looks like a fix for new images, if i'm reading it correctly | 17:49 |
openstack | Launchpad bug 1864020 in OpenStack Compute (nova) "libvirt.libvirtError: Requested operation is not valid: format of backing image %s of image %s was not specified in the image metadata (See https://libvirt.org/kbase/backing_chains.html for troubleshooting)" [Undecided,Fix committed] - Assigned to Lee Yarwood (lyarwood) | 17:49 |
*** brinzhang0 has quit IRC | 17:51 | |
*** k_mouza has joined #openstack-kolla | 17:54 | |
*** k_mouza has quit IRC | 17:59 | |
*** k_mouza has joined #openstack-kolla | 18:08 | |
*** ladrua has joined #openstack-kolla | 18:11 | |
*** k_mouza has quit IRC | 18:14 | |
*** gfidente has quit IRC | 18:21 | |
*** k_mouza has joined #openstack-kolla | 18:23 | |
*** k_mouza has quit IRC | 18:26 | |
openstackgerrit | Michal Arbet proposed openstack/kolla-ansible master: Fix kolla-ansible not reflect environment changed https://review.opendev.org/746965 | 18:31 |
yankcrime | yeah looks like this is a problem for anyone that's updated to ussuri and is using an image with libvirt 6.0 | 18:36 |
yankcrime | if you have an instance that was created a pre-train and it's been stopped and then started again for the first time under ussuri, users aren't going to be able to boot their instance | 18:36 |
*** k_mouza has joined #openstack-kolla | 18:40 | |
*** k_mouza has quit IRC | 18:40 | |
openstackgerrit | Radosław Piliszek proposed openstack/kolla-ansible stable/ussuri: Fix ownership and permissions of admin-openrc.sh https://review.opendev.org/747016 | 18:43 |
openstackgerrit | Radosław Piliszek proposed openstack/kolla-ansible stable/ussuri: Fix ownership and permissions of admin-openrc.sh https://review.opendev.org/747016 | 18:43 |
openstackgerrit | Radosław Piliszek proposed openstack/kolla-ansible stable/ussuri: CI: enable Ansible SSH pipelining https://review.opendev.org/747017 | 18:43 |
openstackgerrit | Radosław Piliszek proposed openstack/kolla-ansible stable/ussuri: CI: enable Ansible SSH pipelining https://review.opendev.org/747017 | 18:43 |
openstackgerrit | Radosław Piliszek proposed openstack/kolla-ansible stable/train: CI: enable Ansible SSH pipelining https://review.opendev.org/747021 | 18:43 |
openstackgerrit | Pedro Henrique Pereira Martins proposed openstack/kolla-ansible master: Add support to OpenID Connect Authentication flow https://review.opendev.org/695432 | 18:44 |
*** vishalmanchanda has quit IRC | 18:49 | |
*** kevko has quit IRC | 18:50 | |
*** priteau has quit IRC | 19:44 | |
openstackgerrit | James Kirsch proposed openstack/kolla master: Enable mod_wsgi in Ironic API and Inspector container https://review.opendev.org/742776 | 20:03 |
*** wathoom has joined #openstack-kolla | 20:50 | |
*** klippo has quit IRC | 20:54 | |
*** dmsimard7 has joined #openstack-kolla | 21:14 | |
*** dmsimard has quit IRC | 21:15 | |
*** dmsimard7 is now known as dmsimard | 21:15 | |
*** hjensas has quit IRC | 21:18 | |
*** rphillips_ has quit IRC | 22:24 | |
*** rphillips has joined #openstack-kolla | 22:27 | |
*** TrevorV has quit IRC | 22:31 | |
*** born2bake has quit IRC | 22:49 | |
openstackgerrit | James Kirsch proposed openstack/kolla master: Enable mod_wsgi in Ironic API and Inspector container https://review.opendev.org/742776 | 23:11 |
JamesBenson | I'm consistently getting this error "ERROR! The requested handler 'Restart swift-api container' was not found in either the main handlers list nor in the listening handlers list" under "service-cert-copy : swift | Copying over extra CA certificates" | 23:18 |
*** suryasingh has quit IRC | 23:37 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!