*** k_mouza has joined #openstack-kolla | 00:30 | |
*** e0ne has joined #openstack-kolla | 00:31 | |
*** k_mouza has quit IRC | 00:34 | |
*** e0ne has quit IRC | 00:35 | |
*** brinzhang has joined #openstack-kolla | 01:10 | |
*** maharg101 has joined #openstack-kolla | 01:24 | |
*** maharg101 has quit IRC | 01:29 | |
*** ricolin has joined #openstack-kolla | 01:29 | |
*** k_mouza has joined #openstack-kolla | 01:49 | |
*** k_mouza has quit IRC | 02:00 | |
*** ysirndjuro has left #openstack-kolla | 02:04 | |
*** e0ne has joined #openstack-kolla | 02:32 | |
*** e0ne has quit IRC | 02:37 | |
*** maharg101 has joined #openstack-kolla | 03:25 | |
*** maharg101 has quit IRC | 03:30 | |
*** skramaja has joined #openstack-kolla | 03:51 | |
*** k_mouza has joined #openstack-kolla | 04:00 | |
*** k_mouza has quit IRC | 04:04 | |
*** rohit02 has joined #openstack-kolla | 04:10 | |
*** k_mouza has joined #openstack-kolla | 04:13 | |
*** ricolin has quit IRC | 04:16 | |
*** k_mouza has quit IRC | 04:18 | |
*** e0ne has joined #openstack-kolla | 04:32 | |
*** jpward has quit IRC | 04:33 | |
*** vishalmanchanda has joined #openstack-kolla | 04:36 | |
*** e0ne has quit IRC | 04:37 | |
*** cah_link has joined #openstack-kolla | 05:06 | |
*** cah_link has quit IRC | 05:19 | |
*** maharg101 has joined #openstack-kolla | 05:26 | |
*** maharg101 has quit IRC | 05:31 | |
*** ricolin has joined #openstack-kolla | 06:29 | |
*** e0ne has joined #openstack-kolla | 06:33 | |
*** e0ne has quit IRC | 06:38 | |
*** cz3 has quit IRC | 06:48 | |
*** cz3 has joined #openstack-kolla | 06:49 | |
*** cah_link has joined #openstack-kolla | 06:53 | |
*** pvh_sa has joined #openstack-kolla | 06:55 | |
openstackgerrit | Pierre Riteau proposed openstack/kayobe stable/train: Add ipa_build_upper_constraints_file variable https://review.opendev.org/c/openstack/kayobe/+/775965 | 07:00 |
---|---|---|
openstackgerrit | Pierre Riteau proposed openstack/kayobe stable/train: Fix building CentOS 8 IPA images on stable/train https://review.opendev.org/c/openstack/kayobe/+/773944 | 07:02 |
openstackgerrit | Pierre Riteau proposed openstack/kayobe stable/train: Test building seed deployment images in the seed job (CentOS 8 only) https://review.opendev.org/c/openstack/kayobe/+/773853 | 07:07 |
*** pvh_sa has quit IRC | 07:10 | |
openstackgerrit | Pierre Riteau proposed openstack/kayobe stable/train: Test building seed deployment images in the seed job (CentOS 8 only) https://review.opendev.org/c/openstack/kayobe/+/773853 | 07:26 |
*** maharg101 has joined #openstack-kolla | 07:27 | |
*** k_mouza has joined #openstack-kolla | 07:29 | |
*** maharg101 has quit IRC | 07:32 | |
*** k_mouza has quit IRC | 07:34 | |
*** maharg101 has joined #openstack-kolla | 07:38 | |
*** heikkine has joined #openstack-kolla | 07:44 | |
*** luksky has joined #openstack-kolla | 07:57 | |
*** amoralej|off is now known as amoralej | 08:07 | |
*** ricolin has quit IRC | 08:08 | |
*** ricolin_ has joined #openstack-kolla | 08:12 | |
*** rpittau|afk is now known as rpittau | 08:12 | |
*** andrewbonney has joined #openstack-kolla | 08:13 | |
*** bengates has joined #openstack-kolla | 08:15 | |
*** ricolin_ is now known as ricolin | 08:17 | |
*** bengates has quit IRC | 08:19 | |
*** bengates has joined #openstack-kolla | 08:20 | |
mnasiadka | Morning | 08:23 |
mnasiadka | 2021-02-16 20:50:20.787 8 WARNING octavia.cmd.api [-] You are running the Octavia API wsgi application using simple_server. We do not recommend this outside of simple testing. We recommend you run the Octavia API wsgi with a more full function server such as gunicorn or uWSGI. | 08:23 |
mnasiadka | Huh | 08:23 |
*** bengates has quit IRC | 08:23 | |
*** bengates has joined #openstack-kolla | 08:25 | |
*** e0ne has joined #openstack-kolla | 08:34 | |
*** dougsz has joined #openstack-kolla | 08:38 | |
*** e0ne has quit IRC | 08:38 | |
*** bengates has quit IRC | 08:43 | |
*** bengates has joined #openstack-kolla | 08:44 | |
*** gfidente has joined #openstack-kolla | 08:44 | |
mgoddard | morning | 08:45 |
*** e0ne has joined #openstack-kolla | 08:45 | |
mgoddard | mnasiadka: yes I noticed that a while ago. Also means no backend TLS for octavia | 08:45 |
*** jbadiapa has joined #openstack-kolla | 08:46 | |
mnasiadka | mgoddard: seems that Octavia deploys properly in octavia-driver-agent change, I'll add some checks for creating an LB in test-ovn.sh today (and docs of course) | 08:46 |
mgoddard | mnasiadka: wonderful | 08:47 |
*** bengates_ has joined #openstack-kolla | 08:48 | |
*** bengates has quit IRC | 08:51 | |
openstackgerrit | Pierre Riteau proposed openstack/kayobe stable/train: Test building seed deployment images in the seed job (CentOS 8 only) https://review.opendev.org/c/openstack/kayobe/+/773853 | 09:10 |
openstackgerrit | Mark Goddard proposed openstack/kolla-ansible stable/victoria: Update String type for Monasca ES template https://review.opendev.org/c/openstack/kolla-ansible/+/775908 | 09:18 |
openstackgerrit | Mark Goddard proposed openstack/kolla-ansible stable/ussuri: Update String type for Monasca ES template https://review.opendev.org/c/openstack/kolla-ansible/+/775909 | 09:18 |
*** jbadiapa has quit IRC | 09:29 | |
openstackgerrit | Pierre Riteau proposed openstack/kayobe stable/train: Test building seed deployment images in the seed job (CentOS 8 only) https://review.opendev.org/c/openstack/kayobe/+/773853 | 09:37 |
openstackgerrit | Mark Goddard proposed openstack/kolla master: CI: publish images with a master-weekly tag https://review.opendev.org/c/openstack/kolla/+/775995 | 09:40 |
openstackgerrit | Mark Goddard proposed openstack/kolla stable/train: Fix several issues (Train) https://review.opendev.org/c/openstack/kolla/+/774602 | 09:43 |
openstackgerrit | Mark Goddard proposed openstack/kolla-ansible stable/train: Update String type for Monasca ES template https://review.opendev.org/c/openstack/kolla-ansible/+/775910 | 09:44 |
*** rohit02 has quit IRC | 09:44 | |
*** k_mouza has joined #openstack-kolla | 09:51 | |
hrw | elo | 09:51 |
dardelean | Hi | 09:53 |
dardelean | Glance is not deployed in HA if it has a file backed storage, right? | 09:54 |
dardelean | even if I have 3 controllers | 09:54 |
*** rohit02 has joined #openstack-kolla | 10:06 | |
yoctozepto | dardelean: right | 10:19 |
yoctozepto | this can be overridden but will only cause misery :P | 10:20 |
dardelean | yoctozepto thanks, what about cinder-volume? I have it with ceph also but there is only one cinder-volume service in compute service list | 10:22 |
dardelean | does it have internal HA machanism? | 10:22 |
openstackgerrit | Merged openstack/kayobe master: Test building seed deployment images in the seed job https://review.opendev.org/c/openstack/kayobe/+/772751 | 10:45 |
*** e0ne has quit IRC | 10:53 | |
hrw | https://michael-prokop.at/blog/2021/02/16/how-to-properly-use-3rd-party-debian-repository-signing-keys-with-apt/ - I am considering changing how we are using apt keys | 11:03 |
*** e0ne has joined #openstack-kolla | 11:05 | |
dardelean | is there any docs on update (not upgrade) procedure? for example if I am on 9.1 and want to move to 9.3 | 11:13 |
openstackgerrit | Pierre Riteau proposed openstack/kayobe stable/train: Fix building CentOS 8 IPA images on stable/train https://review.opendev.org/c/openstack/kayobe/+/773944 | 11:19 |
openstackgerrit | Pierre Riteau proposed openstack/kayobe stable/train: Test building seed deployment images in the seed job (CentOS 8 only) https://review.opendev.org/c/openstack/kayobe/+/773853 | 11:20 |
*** kevko_ has joined #openstack-kolla | 11:37 | |
*** kevko__ has joined #openstack-kolla | 11:38 | |
*** kevko_ has quit IRC | 11:40 | |
yoctozepto | dardelean: it should be as simple as re-running the 'deploy' | 11:57 |
yoctozepto | just always read | 11:57 |
yoctozepto | 'upgrade notes' | 11:57 |
yoctozepto | even for minor releases | 11:57 |
dardelean | change the tag in globals and rerun deploy, got it, thnaks | 11:57 |
yoctozepto | dardelean: you should have more than one cinder-volume for HA | 11:57 |
yoctozepto | dardelean: there is no tag in globals for a minor release | 11:58 |
yoctozepto | oh | 11:58 |
yoctozepto | I know what you mean | 11:58 |
yoctozepto | you should not be using these versioned images | 11:58 |
yoctozepto | they are frozen at some point | 11:58 |
dardelean | hmmm, so you advise against changing the "openstack_tag" in globals are rerun deploy? | 11:59 |
dardelean | i have 9.1 atm set, would like to try 9.3 | 12:00 |
yoctozepto | dardelean: you should first update the kolla-ansible | 12:01 |
yoctozepto | and unset the openstack_tag at all | 12:01 |
yoctozepto | that will get you the latest images with latest ansible code | 12:01 |
dardelean | yoctozepto but still on the same train release, right? | 12:02 |
dardelean | or whatever release I am on | 12:02 |
*** e0ne has quit IRC | 12:06 | |
openstackgerrit | Pierre Riteau proposed openstack/kayobe stable/train: Test building seed deployment images in the seed job (CentOS 8 only) https://review.opendev.org/c/openstack/kayobe/+/773853 | 12:11 |
*** k_mouza has quit IRC | 12:16 | |
*** k_mouza has joined #openstack-kolla | 12:17 | |
openstackgerrit | Pierre Riteau proposed openstack/kayobe stable/train: Fix building CentOS 8 IPA images on stable/train https://review.opendev.org/c/openstack/kayobe/+/773944 | 12:18 |
openstackgerrit | Pierre Riteau proposed openstack/kayobe stable/train: Test building seed deployment images in the seed job (CentOS 8 only) https://review.opendev.org/c/openstack/kayobe/+/773853 | 12:18 |
*** kevko__ has quit IRC | 12:26 | |
*** kevko has joined #openstack-kolla | 12:26 | |
openstackgerrit | Egon Rijpkema proposed openstack/kolla-ansible master: keep X-Forwarded-Proto of exterbal ssl termination. https://review.opendev.org/c/openstack/kolla-ansible/+/758361 | 12:31 |
kevko | hi, yoctozepto, mgoddard will you have a time to re-review my proxysql stack ? I think it's in good shape ..so can we review it again ... what is a blocker ? | 12:34 |
*** jbadiapa has joined #openstack-kolla | 12:49 | |
*** jbadiapa has quit IRC | 12:50 | |
*** jbadiapa has joined #openstack-kolla | 12:51 | |
openstackgerrit | Michal Nasiadka proposed openstack/kolla-ansible master: Add missing octavia-driver-agent https://review.opendev.org/c/openstack/kolla-ansible/+/761872 | 12:53 |
*** amoralej is now known as amoralej|lunch | 13:04 | |
kevko | yoctozepto, mgoddard : Here ? someone ? | 13:05 |
*** rohit02 has quit IRC | 13:06 | |
*** rohit02 has joined #openstack-kolla | 13:06 | |
*** e0ne has joined #openstack-kolla | 13:09 | |
*** skramaja has quit IRC | 13:34 | |
openstackgerrit | Doug Szumski proposed openstack/kolla-ansible master: Remove Monasca Log Transformer https://review.opendev.org/c/openstack/kolla-ansible/+/769900 | 13:35 |
openstackgerrit | Doug Szumski proposed openstack/kolla-ansible master: Disable Monasca Log Metrics service by default https://review.opendev.org/c/openstack/kolla-ansible/+/769901 | 13:35 |
openstackgerrit | Doug Szumski proposed openstack/kolla-ansible master: Support disabling Monasca alerting pipeline https://review.opendev.org/c/openstack/kolla-ansible/+/769902 | 13:35 |
mgoddard | kevko: I'll try to make time for it soon | 13:35 |
*** rohit02 has quit IRC | 13:55 | |
kevko | mgoddard: ok | 13:56 |
kevko | mgoddard: btw, we delivered proxysql with kolla last saturday to production :) and working nice | 13:57 |
*** amoralej|lunch is now known as amoralej | 14:00 | |
mgoddard | kevko: nice, congrats | 14:10 |
kevko | mgoddard: well, we were upgrading for 18 hours :D | 14:11 |
openstackgerrit | Pierre Riteau proposed openstack/kayobe stable/train: Fix copying Swift ring files https://review.opendev.org/c/openstack/kayobe/+/773900 | 14:12 |
*** e0ne has quit IRC | 14:28 | |
*** e0ne has joined #openstack-kolla | 14:29 | |
kevko | guys, could you help me with this http://paste.openstack.org/show/802736/ I just need to create a dict from this list of dicts ..but want to have key: value , so output_key : value -> this will be key , ouput_value: value -> this will be value | 14:31 |
kevko | and I don't mind the description | 14:32 |
yoctozepto | kevko: congrats, you truly are a hard worker! | 14:35 |
yoctozepto | dardelean: yes, the same | 14:36 |
yoctozepto | it is designed as no-touch-unless-you-have-to-and-know-what-you-are-doing thingy | 14:37 |
*** cyberkev has joined #openstack-kolla | 14:38 | |
cyberkev | Hello, I'm attempting a multinode deployment. Overcome a few hurdles (mostly ssh passphrase/sudo related) and now I'm at the point of doing kolla-ansible -i ./multinode prechecks | 14:40 |
cyberkev | The error I'm getting is:- Hostname has to resolve uniquely to the IP address of api_interface | 14:41 |
cyberkev | tried with and without it on 127.0.0.1 and its got it in hostfiles under hosts IP addresses on all 3 nodes | 14:41 |
cyberkev | any pointers ? I'm sure its something simple DNS related but cant put my finger on it | 14:41 |
kevko | yoctozepto: manual changes by client was hell ..but on the end it was successfull without downtime | 14:43 |
kevko | yoctozepto: can u advise me with above paste.openstack.org please ? | 14:44 |
*** Mareo has joined #openstack-kolla | 14:47 | |
*** zzzeek has quit IRC | 14:49 | |
*** zzzeek has joined #openstack-kolla | 14:50 | |
mgoddard | mgoddard mnasiadka hrw egonzalez yoctozepto rafaelweingartne cosmicsound osmanlicilegi bbezak parallax Fl1nt | 14:50 |
mgoddard | ^ meeting in 10 | 14:50 |
hrw | shit. right | 14:52 |
hrw | sorry, terrible day today | 14:52 |
hrw | will attend | 14:52 |
*** rafaelweingartne has joined #openstack-kolla | 14:54 | |
*** brinzhang has quit IRC | 14:55 | |
*** brinzhang has joined #openstack-kolla | 14:55 | |
*** brinzhang has quit IRC | 14:57 | |
*** brinzhang has joined #openstack-kolla | 14:58 | |
mgoddard | #startmeeting kolla | 15:00 |
openstack | Meeting started Wed Feb 17 15:00:32 2021 UTC and is due to finish in 60 minutes. The chair is mgoddard. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:00 |
*** openstack changes topic to " (Meeting topic: kolla)" | 15:00 | |
openstack | The meeting name has been set to 'kolla' | 15:00 |
mgoddard | #topic rollcall | 15:00 |
*** openstack changes topic to "rollcall (Meeting topic: kolla)" | 15:00 | |
yoctozepto | \o/ | 15:00 |
mgoddard | \o | 15:00 |
rafaelweingartne | \o | 15:00 |
risson | \o | 15:01 |
hrw | /o\ | 15:02 |
hrw | /ō\ even | 15:03 |
mgoddard | #topic agenda | 15:03 |
*** openstack changes topic to "agenda (Meeting topic: kolla)" | 15:03 | |
mgoddard | * Roll-call | 15:03 |
mgoddard | * Announcements | 15:03 |
mgoddard | * Review action items from the last meeting | 15:03 |
mgoddard | * CI status | 15:03 |
mgoddard | * Review requests | 15:04 |
mgoddard | * Keystone federation & HAProxy session stickiness https://review.opendev.org/c/openstack/kolla-ansible/+/695432/56/ansible/roles/keystone/defaults/main.yml | 15:04 |
mgoddard | * Dockerhub pull limits: publish weekly master images? https://review.opendev.org/c/openstack/kolla/+/775995 | 15:04 |
mgoddard | * Wallaby release planning | 15:04 |
mgoddard | #topic announcements | 15:04 |
*** openstack changes topic to "announcements (Meeting topic: kolla)" | 15:04 | |
mgoddard | None from me | 15:04 |
mgoddard | #topic Review action items from the last meeting | 15:05 |
*** openstack changes topic to "Review action items from the last meeting (Meeting topic: kolla)" | 15:05 | |
mgoddard | mgoddard fix bifrost on Train | 15:06 |
mgoddard | Fixing bifrost itself proved tricky, but there is a part of the bifrost fix that we can apply via config | 15:06 |
mgoddard | I added the fix to https://review.opendev.org/c/openstack/kolla/+/774602, which seems to have worked | 15:07 |
mgoddard | but now there are other issues | 15:07 |
mgoddard | something to do with the elasticsearch 5.x repo | 15:07 |
mgoddard | I'm wondering if it's a mirror sync issue | 15:07 |
yoctozepto | yeah, it fails randomly | 15:07 |
yoctozepto | but weirdly | 15:07 |
mgoddard | fails every time | 15:08 |
mgoddard | on ubuntu source | 15:08 |
yoctozepto | hmm, but that ubuntu binary built | 15:08 |
yoctozepto | something fishy I would say | 15:08 |
mgoddard | yes | 15:08 |
mgoddard | retry tomorrow | 15:08 |
yoctozepto | let's leave it be for today | 15:08 |
yoctozepto | yes | 15:08 |
mgoddard | #topic CI status | 15:09 |
*** openstack changes topic to "CI status (Meeting topic: kolla)" | 15:09 | |
mgoddard | Generally looks better | 15:10 |
mgoddard | kolla failing in Train & earlier due to aforementioned issues | 15:10 |
mgoddard | #topic Review requests | 15:11 |
*** openstack changes topic to "Review requests (Meeting topic: kolla)" | 15:11 | |
mgoddard | Does anyone have a patch they would like to be reviewed? | 15:11 |
risson | Yep! https://review.opendev.org/c/openstack/kolla-ansible/+/772886 | 15:11 |
risson | It has been discussed here before between you and Mr_Freezeex | 15:12 |
hrw | https://review.opendev.org/c/openstack/kolla/+/772841 from me (centos 8 stream) | 15:12 |
kevko | yeah, https://review.opendev.org/q/hashtag:%22proxysql%22+(status:open%20OR%20status:merged) :) | 15:12 |
kevko | :D | 15:12 |
hrw | kevko: could you look at https://review.opendev.org/c/openstack/kolla/+/772479 one? | 15:13 |
kevko | will | 15:14 |
mgoddard | risson: I've added review priority +1 label to the patch | 15:15 |
risson | thanks! | 15:15 |
mgoddard | added RP+1 to those | 15:16 |
mgoddard | Anyone else? | 15:16 |
mgoddard | I'm going to request the same as last week, | 15:17 |
mgoddard | https://review.opendev.org/c/openstack/kolla-ansible/+/695432 | 15:17 |
mgoddard | keystone federation | 15:17 |
mgoddard | on that topic... | 15:18 |
mgoddard | #topic Keystone federation & HAProxy session stickiness | 15:18 |
*** openstack changes topic to "Keystone federation & HAProxy session stickiness (Meeting topic: kolla)" | 15:18 | |
mgoddard | #link https://review.opendev.org/c/openstack/kolla-ansible/+/695432/56/ansible/roles/keystone/defaults/main.yml | 15:18 |
mgoddard | rafaelweingartne: hi | 15:18 |
rafaelweingartne | Hello | 15:19 |
risson | We applied that patch on our deployment and we needed the balance source option for session stickiness as explained by Pedro in his comment | 15:20 |
mgoddard | We have one main point of contention in the keystone federation patch: session stickiness | 15:20 |
mgoddard | the aim here is to talk it out | 15:20 |
*** k_mouza has quit IRC | 15:20 | |
mgoddard | argh, Fl1nt isn't here | 15:20 |
rafaelweingartne | Exactly, we explained a few times for different people, and probably when Flint asked the same, we just jumped over the question. | 15:20 |
yoctozepto | I saw the explanation, I am buying it | 15:21 |
mgoddard | I would say that he's done quite a good job of explaining himself now, and I haven't seen a decent response yet, although maybe I missed it | 15:21 |
rafaelweingartne | A few days ago flint explicitly showed what he wanted to address there, which is the "sticky session mode" that is being used, and not the use of the sticky session per se | 15:21 |
risson | yes, sticky sessions should be achieved based on the user's cookies, not with `balance source` | 15:22 |
mgoddard | right, I think we're in agreement that stickiness is required | 15:22 |
risson | I'm not sure if HAProxy permits that though | 15:22 |
rafaelweingartne | We do not actually mind changing that, if that had been said, we would have done it. | 15:22 |
rafaelweingartne | risson: we also do not know that | 15:22 |
rafaelweingartne | we started experimenting with some options, we normally only use source, because it is easier :) | 15:22 |
rafaelweingartne | to avoid more problems, what alternatives to source would you guys prefer? | 15:23 |
mgoddard | Fl1nt made a comment on PS57: https://review.opendev.org/c/openstack/kolla-ansible/+/695432/56 | 15:24 |
rafaelweingartne | custom cookie based sticky session? Session ID? a configurable load balancing mode (least connection/round-robin)? | 15:24 |
risson | there's an rdp-cookie option that can be passed to `balance`, not sure if it is what we're looking for | 15:24 |
rafaelweingartne | yes, that seems to be the implementation Flint prefers | 15:25 |
mgoddard | It would be better to use roundrobin or leastconn with a session cookie, that would let HAProxy to appropriately let you contact the correct backend if the node you were connecting from died or if the lease of your client expired. | 15:25 |
mgoddard | Additionally, there is an optional extra option that can be used to be more deterministic on the way HAproxy is handling the backend chosen for your session which is: hash-type that can be set to many options such as consistent / map-based / sdbm, etc (see haproxy doc about that). | 15:25 |
mgoddard | We use consistent on our side but that could be something up to the operators to choose. | 15:25 |
mgoddard | quoting Fl1nt there | 15:25 |
rafaelweingartne | yes | 15:25 |
mgoddard | TBH, balance source is what we use for horizon, so it's not going to be making things any worse | 15:26 |
rafaelweingartne | actually, it does not make any difference | 15:26 |
yoctozepto | ^ exactly mgoddard | 15:26 |
rafaelweingartne | you know, the sticky session is only needed during the authentication phase to validate the token generated by the IdP | 15:26 |
risson | what was the argument against balance source again? | 15:26 |
yoctozepto | exactly, it should be either short enough to be irrelevant | 15:26 |
rafaelweingartne | that is the moment we need the sticky session, after that, it does not make much difference | 15:26 |
yoctozepto | or slow enough that it needs fixing anyhow elsewhere | 15:26 |
openstackgerrit | Arthur Outhenin-Chalandre proposed openstack/kolla-ansible master: Add `kolla_externally_managed_cert` option https://review.opendev.org/c/openstack/kolla-ansible/+/772886 | 15:27 |
yoctozepto | but the problem is obviously that 'balance source' stays with us forever | 15:27 |
yoctozepto | in that token verifications | 15:27 |
yoctozepto | still hit it | 15:27 |
mgoddard | very old blog with info on using haproxy to insert cookies: https://www.haproxy.com/blog/load-balancing-affinity-persistence-sticky-sessions-what-you-need-to-know/#session-cookie-setup-by-the-load-balancer | 15:28 |
risson | damn, review priority has been removed from https://review.opendev.org/c/openstack/kolla-ansible/+/772886 | 15:28 |
yoctozepto | risson: it's baaaack | 15:29 |
rafaelweingartne | if the node that initiated the authentication dies, the user will get an error when presenting this token to other mod-OIDC instances | 15:29 |
risson | yes, but they can just try again and it'll work, right? | 15:30 |
risson | the proper way of fixing this would not be using apache2 for authentication, but keystone doing it and storing its state in its db | 15:30 |
mgoddard | how about this for a path forward: | 15:31 |
rafaelweingartne | yes, | 15:31 |
rafaelweingartne | but source-balance would do the same | 15:31 |
mgoddard | keep the current patch with balance source, enabled only with federation | 15:31 |
rafaelweingartne | it validates if the node is up, before sending it to the backend | 15:32 |
mgoddard | consider switching to another method for horizon and keystone together, as a follow up | 15:32 |
rafaelweingartne | the only difference between sticky session with source-balance and the others is the "more optimal" balance of load between nodes | 15:33 |
rafaelweingartne | considering that we could have one IP (NAT) with many different users | 15:33 |
mgoddard | right | 15:34 |
mgoddard | with a central service such as keystone that is something worth considering | 15:34 |
*** shyamb has joined #openstack-kolla | 15:34 | |
mgoddard | thoughts on my suggestion? | 15:34 |
risson | I think that going with balance source is a good idea for now | 15:35 |
yoctozepto | mgoddard: love it | 15:35 |
mgoddard | wonderful | 15:36 |
*** shyam89 has joined #openstack-kolla | 15:36 | |
rafaelweingartne | I like your suggestion | 15:36 |
mgoddard | let's aim to get it merged before the next meeting | 15:36 |
rafaelweingartne | because we have not extensively tested this with other balance methods | 15:36 |
risson | ^ this | 15:36 |
mgoddard | and rafaelweingartne and Pedro can stop pulling their hair out :) | 15:37 |
rafaelweingartne | :) | 15:37 |
rafaelweingartne | we do understand that the patch is huge. I also hate it | 15:37 |
rafaelweingartne | but, it was the first load of code to handle federation in Kolla-ansible | 15:37 |
mnasiadka | so next time make smaller patches :) | 15:37 |
mgoddard | I've seen bigger ;) | 15:37 |
rafaelweingartne | the improvements will be much easier | 15:37 |
mnasiadka | around haproxy balance source - that's a bit non-ideal solution, but I guess we can live with it for a while. | 15:38 |
mgoddard | I think the main obstacle is the subject matter, rather than the size of the code | 15:38 |
yoctozepto | I'll re-review this week | 15:38 |
mgoddard | anyways, we have some level of agreement, let's move on | 15:38 |
yoctozepto | but I expect to merge it | 15:38 |
mgoddard | thanks for joining rafaelweingartne | 15:38 |
mgoddard | #topic Dockerhub pull limits: publish weekly master images? | 15:39 |
*** openstack changes topic to "Dockerhub pull limits: publish weekly master images? (Meeting topic: kolla)" | 15:39 | |
mgoddard | #link https://review.opendev.org/c/openstack/kolla/+/775995 | 15:39 |
yoctozepto | y not | 15:39 |
rafaelweingartne | awesome thanks guys | 15:39 |
mgoddard | priteau and I were discussing the pull limit issue | 15:39 |
yoctozepto | it sucks | 15:40 |
mgoddard | what if we publish master images weekly and daily? | 15:40 |
mgoddard | some projects could use the weekly images in CI | 15:41 |
mgoddard | e.g. kayobe | 15:41 |
mgoddard | possibly kolla-ansible | 15:41 |
mgoddard | how often would we get hit by broken images, or blocked by images being out of date? | 15:42 |
priteau | Hard to say. I suppose if we get blocked we could override CI to use daily. | 15:42 |
mgoddard | right | 15:43 |
yoctozepto | I think we need to add ourselves the ability to publish on demand | 15:43 |
mgoddard | well, maybe for broken images | 15:43 |
yoctozepto | we can publish on specific commits we merge | 15:43 |
yoctozepto | fugly but worky | 15:43 |
mgoddard | probably not just for a feature that depends on images | 15:43 |
mgoddard | or we could publish twice-weekly | 15:43 |
mgoddard | that could be a better compromise | 15:44 |
yoctozepto | that's getting overly complicated | 15:44 |
mgoddard | not really | 15:44 |
yoctozepto | Sunday feels better | 15:44 |
mnasiadka | or we could build on every deployment, how long is the build? | 15:44 |
mnasiadka | (on master only) | 15:44 |
mgoddard | it just feels wrong | 15:44 |
yoctozepto | feels wrong | 15:44 |
mnasiadka | I think often we are dependent on something failing in the image | 15:44 |
yoctozepto | but might make CI saner | 15:44 |
mnasiadka | and then we're stuck for a week? | 15:44 |
yoctozepto | we don't build all the images | 15:45 |
yoctozepto | but indeed it might quite a bit of extra work | 15:45 |
mgoddard | well, like yoctozepto said we'd need an override | 15:45 |
yoctozepto | yeah, we can practice the override | 15:45 |
yoctozepto | empty commits with metadata are pretty cheap | 15:45 |
yoctozepto | we can publish from other pipelines than periodic | 15:46 |
yoctozepto | just not check | 15:46 |
yoctozepto | as it runs untrusted code | 15:46 |
mgoddard | which pipeline would be appropriate? | 15:46 |
yoctozepto | on that note, remember W+1 makes the change trusted | 15:46 |
mgoddard | gate? | 15:46 |
yoctozepto | nope, it should be after gating | 15:46 |
yoctozepto | either post or promote | 15:47 |
yoctozepto | but we should really keep the images built in gate | 15:47 |
yoctozepto | for publishing later | 15:47 |
yoctozepto | gate is technically fine but we all know we can end up overpublishing :-) | 15:47 |
openstackgerrit | Doug Szumski proposed openstack/kolla-ansible master: Support bypassing Monasca Log API for control plane logs https://review.opendev.org/c/openstack/kolla-ansible/+/776219 | 15:48 |
mgoddard | alternatively we have a nightly publish job that is a noop unless: | 15:48 |
mnasiadka | well, can we publish master to quay.io or github? will it work better? | 15:48 |
mgoddard | * it is a one of the selected publishing days | 15:48 |
yoctozepto | mnasiadka: yeah, we could test that as well | 15:49 |
yoctozepto | lots of ideas; need triage :-) | 15:49 |
mgoddard | * or we modify zuul config to override | 15:49 |
mnasiadka | yoctozepto: I just don't like those zuul dances, because it seems like a lot of work with random success :) | 15:49 |
yoctozepto | mnasiadka: i feel you | 15:50 |
hrw | what is wrong with each-day publish? do we mirror images on CI? | 15:50 |
mgoddard | hrw: new images -> invalidated registry caches -> docker pull -> pull request limit | 15:50 |
mgoddard | hrw: we now do weekly publishing on stables, and it has helped a lot | 15:51 |
hrw | can we publish daily to some opendev infra registry? | 15:51 |
hrw | and then use them on CI? | 15:51 |
mgoddard | we have discussed all these solutions before | 15:52 |
mgoddard | the problem is, I don't see anyone putting in time to implement them | 15:52 |
mnasiadka | hrw: and that solution is nice, but requires somebody to work with infra to get this implemented | 15:52 |
mgoddard | so this topic was aiming to be another stop-gap measure | 15:52 |
yoctozepto | yeah | 15:52 |
hrw | k | 15:52 |
mgoddard | we can very easily reduce our publishing frequency | 15:53 |
yoctozepto | so let's do it | 15:53 |
mgoddard | although it does come with gotchas | 15:53 |
mgoddard | as discussed :) | 15:53 |
yoctozepto | and cry* when we get blocked | 15:53 |
yoctozepto | * discuss | 15:53 |
yoctozepto | better than continuous rechecks | 15:54 |
yoctozepto | and now gimme open discussion | 15:54 |
mgoddard | #topic open discussion | 15:54 |
*** openstack changes topic to "open discussion (Meeting topic: kolla)" | 15:54 | |
yoctozepto | hrw: I like https://michael-prokop.at/blog/2021/02/16/how-to-properly-use-3rd-party-debian-repository-signing-keys-with-apt/ | 15:54 |
yoctozepto | it is essentially what we have in centos | 15:54 |
yoctozepto | and I was wondering once if we could have the same for debuntu | 15:55 |
yoctozepto | so I'm all in | 15:55 |
hrw | yoctozepto: I looked closer into it and can have it for Debian. Ubuntu uses 3 keys directly from keyserver so gnupg still needed | 15:55 |
yoctozepto | perhaps we can override that as well | 15:55 |
yoctozepto | but a mixed solution is fine for now | 15:55 |
yoctozepto | do it everywhere it's simple | 15:56 |
hrw | yoctozepto: https://paste.centos.org/view/e526b842 is start of cleanup | 15:56 |
yoctozepto | ++ | 15:56 |
yoctozepto | let it continue | 15:56 |
openstackgerrit | Mark Goddard proposed openstack/kolla master: CI: publish images on a weekly basis https://review.opendev.org/c/openstack/kolla/+/776221 | 15:58 |
* hrw out | 16:01 | |
mgoddard | all done for this week | 16:01 |
mgoddard | thanks | 16:01 |
yoctozepto | thanks | 16:01 |
mgoddard | #endmeeting | 16:01 |
*** openstack changes topic to "IRC meetings on Wednesdays @ 15:00 UTC - agenda @ https://goo.gl/OXB0DL | Whiteboard: https://bit.ly/2MM7mWF | IRC channel is *LOGGED* @ http://goo.gl/3mzZ7b" | 16:01 | |
openstack | Meeting ended Wed Feb 17 16:01:22 2021 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 16:01 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/kolla/2021/kolla.2021-02-17-15.00.html | 16:01 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/kolla/2021/kolla.2021-02-17-15.00.txt | 16:01 |
openstack | Log: http://eavesdrop.openstack.org/meetings/kolla/2021/kolla.2021-02-17-15.00.log.html | 16:01 |
openstackgerrit | Doug Szumski proposed openstack/kolla-ansible master: Configure Monasca Grafana user roles https://review.opendev.org/c/openstack/kolla-ansible/+/667671 | 16:03 |
*** rafaelweingartne has quit IRC | 16:04 | |
*** k_mouza has joined #openstack-kolla | 16:14 | |
*** shyam89 has quit IRC | 16:19 | |
*** shyamb has quit IRC | 16:19 | |
*** alpha2385 has quit IRC | 16:24 | |
*** amoralej is now known as amoralej|off | 17:17 | |
openstackgerrit | Merged openstack/kolla-ansible stable/ussuri: Update String type for Monasca ES template https://review.opendev.org/c/openstack/kolla-ansible/+/775909 | 17:31 |
openstackgerrit | Merged openstack/kolla-ansible master: Lint and fix renos https://review.opendev.org/c/openstack/kolla-ansible/+/759370 | 17:31 |
*** dougsz has quit IRC | 17:32 | |
*** bengates_ has quit IRC | 17:37 | |
*** rpittau is now known as rpittau|afk | 17:41 | |
*** rohit02 has joined #openstack-kolla | 17:52 | |
*** gfidente is now known as gfidente|afk | 18:03 | |
*** k_mouza has quit IRC | 18:14 | |
*** bengates has joined #openstack-kolla | 18:15 | |
*** maharg101 has quit IRC | 18:16 | |
*** bengates has quit IRC | 18:19 | |
*** jonaspaulo has joined #openstack-kolla | 18:29 | |
*** andrewbonney has quit IRC | 18:33 | |
*** rohit02 has quit IRC | 18:33 | |
*** jonaspaulo has quit IRC | 18:37 | |
openstackgerrit | Ana Peric proposed openstack/kolla-ansible master: Avoid errors in apparmor chrony profile removal in Debian https://review.opendev.org/c/openstack/kolla-ansible/+/776252 | 18:38 |
openstackgerrit | Ana Peric proposed openstack/kolla-ansible master: Avoid errors in apparmor chrony profile removal in Debian https://review.opendev.org/c/openstack/kolla-ansible/+/776252 | 18:42 |
*** e0ne has quit IRC | 18:46 | |
*** jonaspaulo has joined #openstack-kolla | 18:51 | |
openstackgerrit | Ana Peric proposed openstack/kolla-ansible master: Avoid errors in apparmor chrony profile removal in Debian https://review.opendev.org/c/openstack/kolla-ansible/+/776252 | 18:52 |
openstackgerrit | Ana Peric proposed openstack/kolla-ansible master: chronyd crash loop if Debian server is rebooted https://review.opendev.org/c/openstack/kolla-ansible/+/776256 | 19:11 |
*** e0ne has joined #openstack-kolla | 19:48 | |
*** cah_link has quit IRC | 19:49 | |
*** luksky has quit IRC | 19:51 | |
*** luksky has joined #openstack-kolla | 19:52 | |
openstackgerrit | Merged openstack/kolla-ansible stable/victoria: Update String type for Monasca ES template https://review.opendev.org/c/openstack/kolla-ansible/+/775908 | 20:04 |
*** maharg101 has joined #openstack-kolla | 20:12 | |
*** jonaspaulo has quit IRC | 20:14 | |
*** maharg101 has quit IRC | 20:17 | |
*** alpha23 has joined #openstack-kolla | 20:28 | |
*** kevko has quit IRC | 21:07 | |
*** e0ne has quit IRC | 21:24 | |
*** vishalmanchanda has quit IRC | 21:37 | |
dmsimard | o/ heads up: ansible==3.0.0 releasing tomorrow | 21:44 |
*** gmann is now known as gmann_afk | 21:51 | |
*** alpha23 has quit IRC | 22:01 | |
*** cyberkev has quit IRC | 23:01 | |
*** alpha23 has joined #openstack-kolla | 23:22 | |
*** gmann_afk is now known as gmann | 23:22 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!