openstackgerrit | Merged openstack/kayobe master: Fix "Wait for the ironic node to be inspected" task https://review.opendev.org/758202 | 00:13 |
---|---|---|
*** wuchunyang has joined #openstack-kolla | 01:00 | |
*** mrunge has quit IRC | 01:05 | |
*** wuchunyang has quit IRC | 01:10 | |
*** plootonyum has quit IRC | 01:13 | |
*** devfaz has quit IRC | 01:44 | |
*** wuchunyang has joined #openstack-kolla | 01:55 | |
*** wuchunyang has quit IRC | 02:05 | |
*** mrunge has joined #openstack-kolla | 02:17 | |
*** brinzhang has quit IRC | 02:31 | |
*** skramaja has joined #openstack-kolla | 03:03 | |
*** bsanjeewa has joined #openstack-kolla | 03:45 | |
*** LinPeiWen has quit IRC | 03:51 | |
*** LinPeiWen has joined #openstack-kolla | 03:57 | |
*** evrardjp has quit IRC | 04:33 | |
*** evrardjp has joined #openstack-kolla | 04:33 | |
*** gfidente has joined #openstack-kolla | 04:57 | |
*** williampiv has quit IRC | 05:04 | |
*** vishalmanchanda has joined #openstack-kolla | 05:39 | |
*** bsanjeewa has quit IRC | 05:44 | |
*** jbadiapa has joined #openstack-kolla | 05:46 | |
*** bsanjeewa has joined #openstack-kolla | 05:59 | |
*** cah_link has joined #openstack-kolla | 06:08 | |
yoctozepto | morning | 06:30 |
*** wuchunyang has joined #openstack-kolla | 06:30 | |
openstackgerrit | wu.chunyang proposed openstack/kolla master: Remove the unused coding style modules https://review.opendev.org/759189 | 06:30 |
*** devfaz has joined #openstack-kolla | 06:37 | |
*** bsanjeewa has quit IRC | 06:37 | |
*** rpittau|afk is now known as rpittau | 06:54 | |
mnasiadka | yoctozepto: say w00t? | 06:57 |
mnasiadka | yoctozepto: master? | 06:57 |
yoctozepto | mnasiadka: yeah | 06:57 |
mnasiadka | did neutron change something? | 06:57 |
yoctozepto | mnasiadka: I have no idea | 06:59 |
yoctozepto | mnasiadka: left it all to you :-) | 06:59 |
mnasiadka | I'll check that, but most probably tomorrow, today I have another crazy day | 06:59 |
openstackgerrit | Radosław Piliszek proposed openstack/kolla-ansible stable/ussuri: docs: Add link back to Train CentOS 8 migration page https://review.opendev.org/759193 | 07:05 |
*** bengates has joined #openstack-kolla | 07:06 | |
yoctozepto | mnasiadka: sure thing | 07:06 |
*** bsanjeewa has joined #openstack-kolla | 07:07 | |
*** bsanjeewa has quit IRC | 07:11 | |
*** e0ne has joined #openstack-kolla | 07:12 | |
openstackgerrit | Radosław Piliszek proposed openstack/kolla-ansible master: WIP: CI: Test MariaDB backup https://review.opendev.org/693332 | 07:16 |
*** devfaz has quit IRC | 07:17 | |
*** bsanjeewa has joined #openstack-kolla | 07:19 | |
*** muhaha has joined #openstack-kolla | 07:22 | |
*** gfidente is now known as gfidente|pto | 07:23 | |
muhaha | do i need to provision ceph if i wanna install allinone ? | 07:27 |
mgoddard | morning | 07:40 |
mgoddard | muhaha: no | 07:40 |
mnasiadka | morning | 07:43 |
*** grandfso has joined #openstack-kolla | 07:47 | |
wuchunyang | morning | 07:47 |
*** bengates has quit IRC | 07:48 | |
*** bengates has joined #openstack-kolla | 07:48 | |
muhaha | Are you recommending https://github.com/ceph/ceph-ansible as aditional deployment to multi node kolla ? | 07:50 |
*** gfidente|pto has quit IRC | 07:52 | |
wuchunyang | mgoddard should we take a little time to review octavia docs since patchsets were merged ? | 07:52 |
mnasiadka | If you're planning to deploy Ceph Nautilus - yes, if Ceph Octopus - rather use cephadm. | 07:53 |
mgoddard | wuchunyang: yes, just need some time :) | 07:53 |
wuchunyang | mgoddard thanks. and could you help review a comment ? just a comment. https://review.opendev.org/#/c/755589/14/ansible/roles/octavia/defaults/main.yml | 07:57 |
patchbot | patch 755589 - kolla-ansible - octavia: support tenant management network - 14 patch sets | 07:57 |
*** bsanjeewa has quit IRC | 08:00 | |
hrw | mornig | 08:08 |
mgoddard | mnasiadka: do we have a bug for the keystone-startup issue? | 08:10 |
mgoddard | https://bugs.launchpad.net/kolla-ansible/+bug/1895723 | 08:11 |
openstack | Launchpad bug 1895723 in kolla-ansible ussuri "Keystone is restarting due to stale primary key" [High,Fix committed] - Assigned to Radosław Piliszek (yoctozepto) | 08:11 |
*** nikparasyr has joined #openstack-kolla | 08:12 | |
openstackgerrit | Merged openstack/kolla-ansible master: Fix fernet cron path on Ubuntu/Debian https://review.opendev.org/757076 | 08:13 |
openstackgerrit | Merged openstack/kolla-ansible stable/ussuri: docs: Add link back to Train CentOS 8 migration page https://review.opendev.org/759193 | 08:13 |
*** gfidente has joined #openstack-kolla | 08:16 | |
*** gfidente is now known as gfidente|pto | 08:17 | |
*** dardelean has joined #openstack-kolla | 08:20 | |
openstackgerrit | Mark Goddard proposed openstack/kolla-ansible master: Fix keystone-startup.sh - remove Fernet key age check https://review.opendev.org/759210 | 08:26 |
*** bsanjeewa has joined #openstack-kolla | 08:27 | |
mgoddard | mnasiadka, priteau, yoctozepto: ^ | 08:27 |
mnasiadka | mgoddard: nope, only some on rotation related things. | 08:27 |
mgoddard | mnasiadka: I found it. See https://review.opendev.org/759210 | 08:29 |
patchbot | patch 759210 - kolla-ansible - Fix keystone-startup.sh - remove Fernet key age check - 1 patch set | 08:30 |
mnasiadka | yeah, already +2 ;) | 08:30 |
mgoddard | nice | 08:31 |
*** bsanjeewa has quit IRC | 08:35 | |
openstackgerrit | Mark Goddard proposed openstack/kolla-ansible master: Fix permission denied during Fernet key rotation https://review.opendev.org/759215 | 08:35 |
openstackgerrit | Mark Goddard proposed openstack/kolla-ansible stable/ussuri: Fix fernet cron path on Ubuntu/Debian https://review.opendev.org/759217 | 08:36 |
openstackgerrit | Mark Goddard proposed openstack/kolla-ansible stable/train: Fix fernet cron path on Ubuntu/Debian https://review.opendev.org/759218 | 08:37 |
openstackgerrit | Mark Goddard proposed openstack/kolla-ansible stable/stein: Fix fernet cron path on Ubuntu/Debian https://review.opendev.org/759219 | 08:37 |
mnasiadka | the perm denied - I have never seen that, but it might happen | 08:37 |
mgoddard | mnasiadka: I saw it in https://review.opendev.org/#/c/746153 | 08:47 |
patchbot | patch 746153 - kolla-ansible - WIP: keystone fernet follow up follow up - 7 patch sets | 08:47 |
hrw | so what do we do with elasticsearch-curator? | 08:50 |
*** skramaja_ has joined #openstack-kolla | 08:55 | |
*** skramaja has quit IRC | 08:56 | |
openstackgerrit | Mark Goddard proposed openstack/kolla-ansible master: WIP: Fix keystone cron generator https://review.opendev.org/758797 | 08:58 |
hrw | INFO:kolla.common.utils.elasticsearch-curator: Downloading https://files.pythonhosted.org/packages/34/78/787a52834656f7f5dab6d709e38876c4d2604f0e1a16d17937d00330b0c5/elasticsearch-curator-5.8.1.tar.gz (225kB) | 09:00 |
hrw | that file is served on wet wire... | 09:01 |
mgoddard | hrw: if I install boto3 separately, it works | 09:13 |
mgoddard | hmm, actually it seems to always work now | 09:14 |
hrw | mgoddard: where? | 09:15 |
mgoddard | locally | 09:15 |
hrw | ah | 09:15 |
hrw | ERROR:kolla.common.utils.elasticsearch-curator:Error'd with the following message | 09:15 |
*** jaicaa has quit IRC | 09:22 | |
*** jaicaa has joined #openstack-kolla | 09:23 | |
*** jonaspaulo has joined #openstack-kolla | 09:34 | |
mnasiadka | mgoddard: what is interesting for me - Ubuntu seems to have never rotated fernet, and nobody came back before introducing ''check stale key feature'' that keystone is not working at all? | 09:38 |
mgoddard | mnasiadka: as priteau said yesterday, keystone will continue to work with old keys. Tokens expire, keys do not | 09:39 |
mnasiadka | so why do we rotate at all? | 09:39 |
mgoddard | mnasiadka: so they would have to look at the keys to check they are old | 09:39 |
priteau | mnasiadka: it's a security thing? | 09:39 |
mgoddard | so that if a key is compromised it is only temporary | 09:39 |
hrw | INFO:kolla.common.utils.elasticsearch-curator:Successfully tagged kolla/centos-source-elasticsearch-curator:10.1.0 | 09:40 |
mnasiadka | priteau: how long does it take for a normal person without thousands of servers to break a key? | 09:40 |
mnasiadka | AES256 if I remember correctly? | 09:40 |
mgoddard | more likely they will find a key | 09:40 |
priteau | It may be more about people getting access to system than brute force cracking | 09:40 |
mnasiadka | so then we should rotate every hour :) | 09:41 |
mnasiadka | or give a command to rotate the keys in case of a leak | 09:41 |
priteau | The keystone docs use 6 hours hours (although that's just an example) | 09:41 |
openstackgerrit | Marcin Juszkiewicz proposed openstack/kolla master: elasticsearch-curator: install boto before curator https://review.opendev.org/759233 | 09:42 |
hrw | git commit message could get improvements if someone has any suggestions | 09:42 |
*** k_mouza has joined #openstack-kolla | 09:44 | |
*** wuchunyang has quit IRC | 10:19 | |
*** bengates has quit IRC | 10:28 | |
*** bengates has joined #openstack-kolla | 10:30 | |
*** devfaz has joined #openstack-kolla | 10:38 | |
mnasiadka | hrw: well, probably a bug and a reno, if we would be strictly following the rules ;) | 11:07 |
*** kevko has joined #openstack-kolla | 11:12 | |
*** jonaspaulo has quit IRC | 11:13 | |
openstackgerrit | Michal Arbet proposed openstack/kolla-ansible master: Use native fluent-logger instead of tail - Fluent central_logging https://review.opendev.org/755775 | 11:23 |
kevko | mgoddard: is it ok now with native_fluentd_logger added ? ^^^ | 11:24 |
mgoddard | kevko: sorry, I don't have time for Wallaby patches currently | 11:25 |
mgoddard | kevko: would you like to discuss it at the PTG? | 11:26 |
mgoddard | I've added it to the agenda | 11:28 |
mgoddard | https://etherpad.opendev.org/p/kolla-wallaby-ptg | 11:28 |
kevko | yeah, sure , but how it works ? :) ..discuss on irc ? Or ? | 11:30 |
mgoddard | kevko: it's a video call over 2 days next week. Details in the etherpad | 11:32 |
mgoddard | Add your name if you're interested in attending | 11:32 |
mgoddard | even if you don't want to join the whole session, make a note that you want to be pinged for specific topics | 11:32 |
kevko | mgoddard: ok, i'm not sure if my english is good enough when I am speaking live :( .. but I can try it :/ | 11:34 |
mgoddard | kevko: it's fine, most will be non-native speakers | 11:34 |
kevko | ok, can I describe what is going on in my patch widely to that etherpad doc ? | 11:35 |
mgoddard | yes | 11:35 |
mgoddard | osmanlicilegi: do you want to discuss kolla-ceph at the PTG? | 11:36 |
kevko | ok, i will leave notes then .. thank you | 11:36 |
kevko | kolla-ceph ? is this some new project ? | 11:36 |
mnasiadka | we removed it some time ago. | 11:38 |
mgoddard | kevko: kolla used to deploy ceph. It's about where to go if you are using that functionality | 11:38 |
*** k_mouza_ has joined #openstack-kolla | 11:43 | |
*** k_mouza has quit IRC | 11:43 | |
*** k_mouza has joined #openstack-kolla | 11:44 | |
*** k_mouza_ has quit IRC | 11:47 | |
kevko | mgoddard: well I know that kolla-ansible used to deploy ceph until train (removed) .. but i think it was good step to remove it from kolla-ansible as there is ceph-ansible | 11:49 |
yoctozepto | mnasiadka: https://review.opendev.org/759217 slapped w+1 too early; please add CR+2 :-) | 11:49 |
patchbot | patch 759217 - kolla-ansible (stable/ussuri) - Fix fernet cron path on Ubuntu/Debian - 1 patch set | 11:49 |
yoctozepto | kevko: and now cephadm | 11:49 |
kevko | yoctozepto: is it better to use cephadm ? anf if .. why ? | 11:49 |
yoctozepto | well, the kolla-ceph topic was brought many times since | 11:49 |
yoctozepto | kevko: it's the so-called future :-) | 11:50 |
mgoddard | yoctozepto, hrw, mnasiadka, osmanlicilegi, Fl1nt, headphoneJames, bbezak: updated PTG schedule | 11:50 |
mgoddard | https://etherpad.opendev.org/p/kolla-wallaby-ptg | 11:50 |
mgoddard | begin the last minute addition of topics :) | 11:50 |
kevko | yoctozepto: I'm OK with ceph-ansible ..as it is ansible :) | 11:52 |
yoctozepto | kevko: well, they might drop its support anytime | 11:53 |
yoctozepto | kevko: anyhow, cephadm should be pretty easy to use once you have your cluster properly deployed with ceph-ansible anyway | 11:53 |
yoctozepto | so, uhm, nothing to worry about :-) | 11:53 |
kevko | yoctozepto: btw, i was trying to upgrade from stein to ussuri with kolla-ansible ...i had few small issues ...but what i am curious about what you said about keystone-fernet ... | 11:55 |
yoctozepto | kevko: have you skipped train? ;O | 11:55 |
kevko | yoctozepto: yes | 11:55 |
kevko | well, i was trying if it is ok to upgrade ..because we are going to upgrade on client's site .. | 11:55 |
kevko | but I probably hit a bug ..because i had stale fernet token ..is your patch fixing it ? | 11:56 |
yoctozepto | kevko: we have lots of fernet fixes, yes | 11:56 |
yoctozepto | kevko: turned out to have many funky issues | 11:56 |
yoctozepto | we believe we have very few actual ubuntu users and our users seem to not use their clusters on Sundays :D | 11:57 |
kevko | yoctozepto: i've seen this in docker logs -> http://paste.openstack.org/show/799274/ | 11:58 |
kevko | yoctozepto: and both keystones were restarting | 11:58 |
yoctozepto | kevko: yeah, because we added detection of this bad state... | 11:58 |
yoctozepto | well, ubuntu AND debian | 11:58 |
yoctozepto | let's say most times I say ubuntu I mean debian as well | 11:59 |
yoctozepto | because they share most of the distro-based issues | 11:59 |
kevko | yeah, i know | 11:59 |
yoctozepto | being the other distro family we support | 11:59 |
kevko | but I can see big progress in debian/ubuntu support in kolla{-ansible} | 12:00 |
kevko | from stein ,maybe rocky | 12:00 |
yoctozepto | yeah, there was indeed | 12:00 |
yoctozepto | while I don't use ubuntu for openstack and sometimes make jokes about deprecating its support, I advocate our support for both major distro families | 12:01 |
yoctozepto | and hrw has done a lot of work on debuntu and aarch64 side | 12:01 |
*** k_mouza_ has joined #openstack-kolla | 12:07 | |
*** k_mouza has quit IRC | 12:10 | |
yoctozepto | mgoddard: https://review.opendev.org/693332 weird; it looks as if it hanged | 12:13 |
patchbot | patch 693332 - kolla-ansible - WIP: CI: Test MariaDB backup - 3 patch sets | 12:13 |
*** k_mouza has joined #openstack-kolla | 12:13 | |
*** gfidente|pto is now known as gfidente | 12:15 | |
*** k_mouza_ has quit IRC | 12:17 | |
ebbex | How can I limit my controller, hypervisor and seed to only have an interface on provision_oc_net? (i have a route to the "oob_oc_net" from provisioning net, and the default seems to want interfaces on both.) | 12:19 |
*** muhaha has quit IRC | 12:24 | |
openstackgerrit | Radosław Piliszek proposed openstack/kolla-ansible master: [tox] Optimise docs actions https://review.opendev.org/759253 | 12:28 |
*** k_mouza has quit IRC | 12:29 | |
*** k_mouza has joined #openstack-kolla | 12:29 | |
openstackgerrit | Radosław Piliszek proposed openstack/kolla-ansible master: [docs] Add templates and examples of renos https://review.opendev.org/759254 | 12:29 |
yoctozepto | mgoddard, mnasiadka: ^ if you like the above, I will propose for kolla too (and please appropriate for kayobe :-) ) | 12:30 |
openstackgerrit | Merged openstack/kolla-ansible stable/stein: Fix fernet cron path on Ubuntu/Debian https://review.opendev.org/759219 | 12:49 |
*** wuchunyang has joined #openstack-kolla | 12:54 | |
kevko | guys, i would like to ask what is your opinion to write some common role to copy files ... | 12:58 |
kevko | i mean, there are several copying tasks in every role which is copying for example policy files .. | 12:59 |
hrw | kevko: common as 'macro in macros.j2'? | 12:59 |
hrw | kevko: if it has sense and covers distros | 13:00 |
kevko | but user (as us) want to sometimes change paste-ini file ..or copy some another files .. | 13:00 |
yoctozepto | kevko: that's kinda the goal to create a k-a framework | 13:00 |
kevko | and every time we are changing locally kolla-ansible to do everytime the same | 13:01 |
kevko | check if exist some file in /etc/kolla/config/service/file ... if yes copy to node ..and if defined ..render config.json | 13:01 |
* hrw -> food | 13:01 | |
kevko | so, now we are copying policy files, some kafka certs, paste ini files, and something more .. | 13:02 |
kevko | every time we are merging these changes to kolla-ansible locally | 13:02 |
kevko | so i was wondering what is your opinion to have one role (or whatewer iplementation it will be) ... just import in tasks/config.yml and role will find every custom config ..whatewer it is ..render config.json ..copy to node .. | 13:04 |
kevko | now it is several "entries" in config json (paste,policy, whatewer) ...in tasks/config ..and when merging (especially config.json) ..sometimes it is confusing for me :) ..so this approach will be very nice for me ..but i thing it is not bad idea globally | 13:06 |
mgoddard | kevko: it's a nice idea. It would be quite a lot of work to do it for every service for all config. But if we create a general role we can increase usage of it as we go | 13:22 |
mgoddard | kevko: if done well it could improve performance, by reducing the number of tasks | 13:22 |
mgoddard | probably at the expense of complexity | 13:22 |
kevko | ok, i will implement something to future :) when I will have some time :) | 13:23 |
mgoddard | kevko: well, let's discuss it before jumping in | 13:26 |
mgoddard | (at the PTG) | 13:27 |
kevko | mgoddard: ok | 13:27 |
mgoddard | please add the topic | 13:27 |
mgoddard | yoctozepto: mariabackup hang in CI, sounds familiar | 13:27 |
yoctozepto | mgoddard: ok | 13:39 |
*** cah_link has quit IRC | 13:39 | |
*** TrevorV has joined #openstack-kolla | 13:40 | |
openstackgerrit | Merged openstack/kolla-ansible stable/train: Fix fernet cron path on Ubuntu/Debian https://review.opendev.org/759218 | 13:49 |
*** k_mouza has quit IRC | 14:01 | |
*** k_mouza has joined #openstack-kolla | 14:07 | |
openstackgerrit | Merged openstack/kolla-ansible stable/ussuri: Fix fernet cron path on Ubuntu/Debian https://review.opendev.org/759217 | 14:22 |
*** kevko has quit IRC | 14:23 | |
*** grandfso has quit IRC | 14:24 | |
mnasiadka | yoctozepto: what about supplying a predefined template for bug at least? I mean a template you can use with "reno new bla-bla --from-template bug-template.yaml"? | 14:44 |
yoctozepto | mnasiadka: hmm, does reno do that? did not know | 14:45 |
mnasiadka | yoctozepto: it seems it does, just checked in the docs | 14:46 |
yoctozepto | mnasiadka: oh, great; that would make it even better | 14:47 |
yoctozepto | mnasiadka: it could be made a part of tox | 14:47 |
*** skramaja_ has quit IRC | 14:50 | |
*** nikparasyr has left #openstack-kolla | 15:07 | |
mgoddard | CI unblocker: https://review.opendev.org/#/c/759233/ | 15:08 |
patchbot | patch 759233 - kolla - elasticsearch-curator: install boto before curator - 1 patch set | 15:08 |
*** also_stingrayza has joined #openstack-kolla | 15:12 | |
*** e0ne has quit IRC | 15:14 | |
*** stingrayza has quit IRC | 15:15 | |
*** muhaha has joined #openstack-kolla | 15:23 | |
*** williampiv has joined #openstack-kolla | 15:34 | |
*** bengates has quit IRC | 15:43 | |
*** bengates has joined #openstack-kolla | 15:44 | |
*** wuchunyang has quit IRC | 15:47 | |
*** bengates has quit IRC | 15:48 | |
*** rpittau is now known as rpittau|afk | 15:57 | |
*** iniazi has quit IRC | 15:58 | |
*** k_mouza has quit IRC | 16:06 | |
*** k_mouza_ has joined #openstack-kolla | 16:06 | |
*** k_mouza_ has quit IRC | 16:10 | |
*** muhaha has quit IRC | 17:06 | |
*** bsanjeewa has joined #openstack-kolla | 17:07 | |
*** born2bake has joined #openstack-kolla | 17:18 | |
*** kevko has joined #openstack-kolla | 17:19 | |
*** bsanjeewa has quit IRC | 17:24 | |
*** gfidente is now known as gfidente|afk | 17:28 | |
*** vishalmanchanda has quit IRC | 17:39 | |
*** jonaspaulo has joined #openstack-kolla | 17:42 | |
*** jonaspaulo has quit IRC | 17:48 | |
*** jonaspaulo has joined #openstack-kolla | 17:50 | |
*** ricolin has quit IRC | 17:54 | |
*** jonaspaulo has quit IRC | 18:10 | |
*** KurtB has quit IRC | 18:35 | |
*** e0ne has joined #openstack-kolla | 18:59 | |
*** kevko has quit IRC | 19:06 | |
*** kevko has joined #openstack-kolla | 19:11 | |
*** dardelean has quit IRC | 19:28 | |
*** e0ne has quit IRC | 19:53 | |
*** TrevorV has quit IRC | 20:38 | |
*** primeministerp has quit IRC | 20:50 | |
*** kwazar has joined #openstack-kolla | 21:15 | |
*** born2bake has quit IRC | 21:54 | |
*** bsanjeewa has joined #openstack-kolla | 22:18 | |
*** bsanjeewa has quit IRC | 22:23 | |
*** iniazi has joined #openstack-kolla | 23:02 | |
*** benj_ has quit IRC | 23:21 | |
*** benj_ has joined #openstack-kolla | 23:26 | |
*** williampiv has quit IRC | 23:38 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!