openstackgerrit | James Kirsch proposed openstack/kolla-ansible master: Add support for LetsEncrypt-managed certs https://review.opendev.org/c/openstack/kolla-ansible/+/741340 | 00:39 |
---|---|---|
*** zhanglong has joined #openstack-kolla | 00:41 | |
*** schwicht has joined #openstack-kolla | 01:08 | |
*** rouk has quit IRC | 01:23 | |
*** LinPeiWen has joined #openstack-kolla | 02:06 | |
*** ivan_lin has quit IRC | 02:09 | |
*** LinPeiWen2 has joined #openstack-kolla | 02:19 | |
*** zhanglong has quit IRC | 02:48 | |
openstackgerrit | James Kirsch proposed openstack/kolla-ansible master: Add support for LetsEncrypt-managed certs https://review.opendev.org/c/openstack/kolla-ansible/+/741340 | 03:06 |
*** zhanglong has joined #openstack-kolla | 03:20 | |
*** zhanglong has quit IRC | 03:46 | |
*** skramaja has joined #openstack-kolla | 03:55 | |
*** vishalmanchanda has joined #openstack-kolla | 04:41 | |
*** zhanglong has joined #openstack-kolla | 05:36 | |
*** wuchunyang has joined #openstack-kolla | 05:36 | |
*** Luzi has joined #openstack-kolla | 05:40 | |
*** iniazi_ has joined #openstack-kolla | 06:25 | |
*** iniazi has quit IRC | 06:27 | |
mnasiadka | morning | 07:21 |
*** shyamb has joined #openstack-kolla | 07:22 | |
openstackgerrit | Michal Nasiadka proposed openstack/kayobe master: Bump max Ansible version to 2.10 https://review.opendev.org/c/openstack/kayobe/+/780898 | 07:25 |
*** shyamb has quit IRC | 07:28 | |
*** shyamb has joined #openstack-kolla | 07:29 | |
*** parallax has quit IRC | 07:29 | |
*** ohorecny2 has joined #openstack-kolla | 07:31 | |
*** zhanglong has quit IRC | 07:32 | |
*** schwicht has quit IRC | 07:39 | |
*** shyam89 has joined #openstack-kolla | 07:44 | |
*** ysirndjuro has quit IRC | 07:46 | |
*** shyamb has quit IRC | 07:47 | |
*** shyam89 has quit IRC | 07:49 | |
*** luksky has joined #openstack-kolla | 07:55 | |
hrw | morning | 07:59 |
hrw | ERROR nova.compute.manager [instance: 1529def5-4708-4436-b3e8-f2059e5ad435] TypeError: can't concat str to bytes | 08:00 |
hrw | getting closer to working openstack | 08:00 |
*** bengates has joined #openstack-kolla | 08:02 | |
*** bengates has quit IRC | 08:06 | |
*** bengates has joined #openstack-kolla | 08:06 | |
*** bengates has quit IRC | 08:07 | |
*** bengates has joined #openstack-kolla | 08:07 | |
mnasiadka | hrw: it's a never ending story ;) | 08:09 |
*** amoralej|off is now known as amoralej | 08:11 | |
*** andrewbonney has joined #openstack-kolla | 08:12 | |
*** bengates_ has joined #openstack-kolla | 08:15 | |
*** bengates has quit IRC | 08:18 | |
*** rpittau|afk is now known as rpittau | 08:19 | |
*** ricolin has quit IRC | 08:27 | |
hrw | yeah | 08:27 |
hrw | too bad that I found time for it so late in cycle | 08:28 |
*** ricolin has joined #openstack-kolla | 08:32 | |
*** ChenSa has joined #openstack-kolla | 08:38 | |
openstackgerrit | Mark Goddard proposed openstack/kayobe master: CI: use retries for control host bootstrap in seed VM jobs https://review.opendev.org/c/openstack/kayobe/+/782668 | 08:50 |
openstackgerrit | Merged openstack/kayobe master: CI: Fix IP address detection in baremetal compute test https://review.opendev.org/c/openstack/kayobe/+/782324 | 08:54 |
hrw | can someone remind me how to switch install to devmode? | 08:56 |
hrw | ok. found | 08:58 |
*** vishalmanchanda has quit IRC | 09:01 | |
mgoddard | morning | 09:03 |
hrw | mgoddard: https://review.opendev.org/c/openstack/kolla/+/782619 https://review.opendev.org/c/openstack/kolla/+/782247 https://review.opendev.org/c/openstack/kolla/+/782606 are vital to get Debian running | 09:03 |
hrw | mgoddard: and nova change we discuss on nova channel as cherry on top | 09:05 |
*** brinzhang has quit IRC | 09:07 | |
*** gfidente has joined #openstack-kolla | 09:08 | |
*** e0ne has joined #openstack-kolla | 09:19 | |
*** e0ne has quit IRC | 09:22 | |
*** e0ne has joined #openstack-kolla | 09:24 | |
*** e0ne has quit IRC | 09:24 | |
openstackgerrit | Marcin Juszkiewicz proposed openstack/kolla master: rabbitmq: bump Erlang requirements to v23 in Debian https://review.opendev.org/c/openstack/kolla/+/782247 | 09:28 |
hrw | mgoddard: commented on other ones | 09:28 |
*** brinzhang has joined #openstack-kolla | 09:30 | |
*** zhanglong has joined #openstack-kolla | 09:30 | |
mnasiadka | maybe it's a stupid idea - but shouldn't we have debian-source jobs as voting? | 09:34 |
hrw | mnasiadka: +2 in Xena | 09:39 |
hrw | now it is at: 2021-03-24 10:36:23.905 7 ERROR nova.compute.manager [instance: ef71de37-1a2b-4f60-9fb4-d5942ffe7fc4] libvirt.libvirtError: unable to open '/sys/fs/cgroup/machine/qemu-1-instance-00000002.libvirt-qemu/': No such file or directory | 09:40 |
*** shyamb has joined #openstack-kolla | 09:41 | |
*** vishalmanchanda has joined #openstack-kolla | 09:42 | |
*** parallax has joined #openstack-kolla | 09:52 | |
*** zhanglong has quit IRC | 09:53 | |
*** e0ne has joined #openstack-kolla | 09:56 | |
*** strigazi has joined #openstack-kolla | 09:58 | |
*** brinzhang_ has joined #openstack-kolla | 10:03 | |
*** brinzhang has quit IRC | 10:06 | |
*** e0ne has quit IRC | 10:09 | |
ChenSa | hi, did anyone try enabling ovs-dpdk on the latest release of kolla? | 10:10 |
openstackgerrit | Mark Goddard proposed openstack/kolla-ansible master: magnum: Add CA certificate configuration for internal TLS https://review.opendev.org/c/openstack/kolla-ansible/+/781062 | 10:13 |
openstackgerrit | Mark Goddard proposed openstack/kolla-ansible master: DNM: CI: Enable TLS in all jobs https://review.opendev.org/c/openstack/kolla-ansible/+/782387 | 10:17 |
openstackgerrit | Merged openstack/kolla-ansible master: prometheus: Collect metrics from rabbitmq https://review.opendev.org/c/openstack/kolla-ansible/+/628337 | 10:23 |
openstackgerrit | Mark Goddard proposed openstack/kayobe master: Ubuntu: AppArmor config for seed VM provisioning https://review.opendev.org/c/openstack/kayobe/+/782272 | 10:41 |
openstackgerrit | Mark Goddard proposed openstack/kayobe master: CI: Enable bare metal testing for Ubuntu https://review.opendev.org/c/openstack/kayobe/+/782273 | 10:42 |
*** shyamb has quit IRC | 10:46 | |
*** shyamb has joined #openstack-kolla | 10:55 | |
openstackgerrit | Mark Goddard proposed openstack/kayobe master: DNM: Test IPA build with Ansible 2.10 https://review.opendev.org/c/openstack/kayobe/+/782689 | 10:58 |
*** wuchunyang has quit IRC | 10:59 | |
*** brinzhang0 has joined #openstack-kolla | 11:08 | |
*** brinzhang_ has quit IRC | 11:12 | |
openstackgerrit | Merged openstack/kolla-ansible stable/victoria: nova-cell: Stop printing ceph keys in output https://review.opendev.org/c/openstack/kolla-ansible/+/782118 | 11:19 |
*** ohorecny2 has quit IRC | 11:20 | |
openstackgerrit | Merged openstack/kolla-ansible stable/victoria: don't use the same CIDR in octavia_amp_network_cidr and init-run-once https://review.opendev.org/c/openstack/kolla-ansible/+/781199 | 11:25 |
openstackgerrit | Mark Goddard proposed openstack/kayobe master: CI: Enable bare metal testing for Ubuntu https://review.opendev.org/c/openstack/kayobe/+/782273 | 11:33 |
ChenSa | hi, did anyone try enabling ovs-dpdk on the latest release of kolla? | 11:36 |
mgoddard | ChenSa: I think wuchunyang uses it, but they are not here right now | 11:36 |
*** shyamb has quit IRC | 11:37 | |
*** shyamb has joined #openstack-kolla | 12:23 | |
openstackgerrit | Mark Goddard proposed openstack/kayobe stable/victoria: Support configuring docker_registry network_mode https://review.opendev.org/c/openstack/kayobe/+/782703 | 12:26 |
*** sean-k-mooney has joined #openstack-kolla | 12:43 | |
*** skramaja has quit IRC | 12:59 | |
*** LinPeiWen2 has quit IRC | 12:59 | |
*** shyamb has quit IRC | 13:02 | |
*** ChenSa has quit IRC | 13:07 | |
*** bengates_ has quit IRC | 13:09 | |
*** brinzhang0 has quit IRC | 13:09 | |
*** bengates has joined #openstack-kolla | 13:10 | |
*** amoralej is now known as amoralej|lunch | 13:12 | |
*** bengates has quit IRC | 13:13 | |
*** bengates has joined #openstack-kolla | 13:14 | |
*** e0ne has joined #openstack-kolla | 13:18 | |
*** devfaz has quit IRC | 13:21 | |
*** bengates has quit IRC | 13:22 | |
*** bengates has joined #openstack-kolla | 13:23 | |
*** devfaz has joined #openstack-kolla | 13:24 | |
*** ysirndjuro has joined #openstack-kolla | 13:37 | |
yoctozepto | wth with these rc -13 in CI | 13:48 |
yoctozepto | mnasiadka: cephadm failing on ubuntu often | 13:49 |
yoctozepto | 2021-03-24 09:46:14.086790 | primary | FileExistsError: [Errno 17] File exists: '/var/log/ceph/42e24910-8c85-11eb-8add-1bdc6ebc3286' | 13:49 |
kevko | mgoddard: do you have a time for quick look mariadb review ? | 14:01 |
mgoddard | kevko: if using haproxy, are multiple shards supported, and if so, what happens with shards other than the default? | 14:03 |
openstackgerrit | Mark Goddard proposed openstack/kayobe master: Import merge_configs and merge_yaml from Kolla Ansible https://review.opendev.org/c/openstack/kayobe/+/778994 | 14:04 |
openstackgerrit | Mark Goddard proposed openstack/kayobe master: WIP: Use merge_configs and merge_yaml to generate custom config https://review.opendev.org/c/openstack/kayobe/+/782749 | 14:04 |
kevko | mgoddard: yes, they are supported, but other shards has no haproxy VIP:3006, only deployed | 14:04 |
mgoddard | kevko: ok, thanks for clarifying behaviour | 14:04 |
kevko | mgoddard: I think this is how it should work ... | 14:04 |
kevko | mgoddard: if user want to proxy all shards, he just turn-on proxysql .. | 14:05 |
mgoddard | kevko: is there any special meaning to mariadb_default_database_shard_id when proxysql is usd? | 14:05 |
kevko | mgoddard: yes, from ID number , internal groups of proxysql is generated | 14:06 |
kevko | mgoddard: can't be undefined | 14:06 |
mgoddard | kevko: right, but the 'default' shard behaves the same as others? | 14:06 |
kevko | mgoddard: writer,backup_writer,reader,offline = id*10, id*10+1,etc.. | 14:06 |
mgoddard | i.e., it is only really 'special' when using haproxy? | 14:06 |
kevko | mgoddard: sorry, don't understand the question | 14:07 |
mgoddard | kevko: ok, in haproxy mode, the default shard is the one that gets load balanced | 14:07 |
kevko | mgoddard: yes | 14:08 |
mgoddard | in proxysql mode, it is just the same as any other shard, right? | 14:08 |
kevko | mgoddard: yes | 14:08 |
mgoddard | ok | 14:08 |
*** suff has joined #openstack-kolla | 14:08 | |
kevko | mgoddard: well, I've implemented your request to not create root_shard_{{ default_shard_id }} .. | 14:09 |
mgoddard | kevko: so I think that mariadb_default_database_shard_id is conflating two things | 14:09 |
mgoddard | 1. which type of load balancer am I using | 14:09 |
kevko | mgoddard: so you can login to mariadb default shard via proxysql by root user | 14:09 |
mgoddard | 2. which shard will be load balanced when using haproxy | 14:09 |
mgoddard | kevko: ok, all that sounds like more of an accident than a useful feature? :) | 14:10 |
mgoddard | s/all/although/ | 14:10 |
kevko | mgoddard: what ? why ? | 14:10 |
mgoddard | maybe I'm wrong. Why is it useful? | 14:10 |
kevko | mgoddard: what do you mean specifically ? | 14:11 |
kevko | mgoddard: like feature - that it is able to have several clusters behind proxysql ? | 14:11 |
mgoddard | sorry, I mean that root user can access the default shard | 14:11 |
*** amoralej|lunch is now known as amoralej | 14:12 | |
kevko | mgoddard: well, it's like it is now ...you *are* able to login via mysql -h VIP -u root -pSECRET also via haproxy | 14:12 |
kevko | *via haproxy | 14:12 |
mgoddard | kevko: WDYT to this: http://paste.openstack.org/show/803866/ | 14:13 |
kevko | but this is about proxysql templating only .. in mariadb refactor it is only about one thing -> If creating root_shard_ID or only root | 14:13 |
kevko | mgoddard: not needed I think -> you can set mariadb_default_database_shard in globals to 0 or to 1 or whatewer ... and in inventory just set this also to hosts .. | 14:15 |
kevko | mgoddard: and you have what you wanted .. | 14:15 |
mgoddard | kevko: perhaps this makes the intention clearer: http://paste.openstack.org/show/803867/ | 14:17 |
hrw | elo | 14:18 |
kevko | mgoddard: well, could be .. why not .. but i think it's quite cosmetic | 14:20 |
mgoddard | kevko: having only a single root user is not cosmetic | 14:21 |
kevko | mgoddard: ah, now I understand maybe ... | 14:21 |
kevko | mgoddard: on new deployments where you have proxysql turned off, shards can be deployed ..but will be deployed only with root user | 14:21 |
mgoddard | right | 14:21 |
kevko | mgoddard: if you switch to proxysql and reconfigure .. proxysql is configured first (order in site.yml) and in mariadb role which is running right after ..users are created extra | 14:22 |
mgoddard | there are also a few places where the code tries to infer whether it is using haproxy or proxysql. Having mariadb_loadbalancer can make those conditions nice and explicit | 14:22 |
kevko | ^^ am i right ? | 14:23 |
kevko | this was your point .. | 14:23 |
mgoddard | kevko: I don't think that was my point :) | 14:24 |
mgoddard | kevko: my point was that if we have haproxy with multiple shards, all shards should use the root user | 14:25 |
kevko | mgoddard: yes | 14:25 |
kevko | mgoddard: but if you reconfigure ..you will have root_shard_ID | 14:26 |
mgoddard | but this is what the code looks like now: | 14:26 |
mgoddard | mariadb_shard_database_user: "{% if mariadb_shard_id == mariadb_default_database_shard_id %}{{ database_user }}{% else %}root_{{ mariadb_shard_name }}{% endif %}" | 14:26 |
kevko | yeah, you are right .. | 14:26 |
mgoddard | so only the default shard uses root | 14:26 |
kevko | now it creates root for default ..and others with root_shard_ID | 14:27 |
mgoddard | right | 14:27 |
kevko | mgoddard: understand, | 14:27 |
kevko | mgoddard: ok, that's small change ..can edit | 14:27 |
kevko | mgoddard: something else ? :P | 14:29 |
mgoddard | just looking at mariadb_default_database_shard_hosts | 14:30 |
kevko | variable where hosts from default shard is stored .. | 14:31 |
kevko | it is used in internal_haproxy_members | 14:31 |
mgoddard | that part always seems tricky | 14:31 |
mgoddard | does it need to be in group_vars/all? | 14:32 |
kevko | yes, unfortunatelly yes | 14:32 |
kevko | it's because you can run kolla-ansible ..... -t mariadb | 14:32 |
kevko | or -t loadbalancer | 14:32 |
mgoddard | shouldn't be an issue | 14:33 |
kevko | really ? | 14:33 |
mgoddard | site.yml includes mariadb role, loadbalancer.yml | 14:33 |
mgoddard | so it gets the mariadb defaults | 14:33 |
mgoddard | then loadbalancer.yml imports haproxy-config | 14:33 |
mgoddard | the fiddly part is that hostvars does not contain role default variables, unless they have been overridden by inventory or globals.yml | 14:34 |
kevko | mgoddard: i've tested and i really had to place it in globals (before i was doing dirty set_fact if you remember ..this is nicer) | 14:36 |
*** suff has quit IRC | 14:36 | |
mgoddard | kevko: ok | 14:39 |
*** Luzi has quit IRC | 14:43 | |
*** bengates has quit IRC | 14:46 | |
*** bengates has joined #openstack-kolla | 14:47 | |
mgoddard | mgoddard mnasiadka hrw egonzalez yoctozepto rafaelweingartne cosmicsound osmanlicilegi bbezak parallax Fl1nt | 14:51 |
mgoddard | ^ meeting in 10 | 14:51 |
yoctozepto | ok | 14:51 |
*** rafaelweingartne has joined #openstack-kolla | 14:51 | |
hrw | ay | 14:57 |
kevko | \o/ | 14:59 |
mgoddard | #startmeeting kolla | 15:00 |
openstack | Meeting started Wed Mar 24 15:00:19 2021 UTC and is due to finish in 60 minutes. The chair is mgoddard. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:00 |
*** openstack changes topic to " (Meeting topic: kolla)" | 15:00 | |
openstack | The meeting name has been set to 'kolla' | 15:00 |
mgoddard | #topic rollcall | 15:00 |
*** openstack changes topic to "rollcall (Meeting topic: kolla)" | 15:00 | |
*** rafaelweingartne has quit IRC | 15:00 | |
hrw | ]°[ | 15:00 |
osmanlicilegi | o/ | 15:00 |
headphoneJames | o/ | 15:01 |
mgoddard | \o\ |o| /o/ | 15:01 |
parallax | \o | 15:01 |
yoctozepto | o_ | 15:01 |
mgoddard | #topic agenda | 15:02 |
*** openstack changes topic to "agenda (Meeting topic: kolla)" | 15:02 | |
mgoddard | * Roll-call | 15:03 |
mgoddard | * Announcements | 15:03 |
mgoddard | ** PTG 19th - 23rd April, registration open | https://april2021-ptg.eventbrite.com | https://www.openstack.org/ptg/ | 15:03 |
mgoddard | * Review action items from the last meeting | 15:03 |
mgoddard | * CI status | 15:03 |
mgoddard | * Review requests | 15:03 |
mgoddard | * PTG team signup http://lists.openstack.org/pipermail/openstack-discuss/2021-March/020915.html | 15:03 |
mgoddard | * Quay.io | 15:03 |
mgoddard | * Wallaby release planning | 15:03 |
mgoddard | #topic announcements | 15:03 |
*** openstack changes topic to "announcements (Meeting topic: kolla)" | 15:03 | |
mgoddard | #info PTG 19th - 23rd April, registration open | 15:03 |
mgoddard | #link https://april2021-ptg.eventbrite.com | 15:03 |
mgoddard | #link https://www.openstack.org/ptg/ | 15:03 |
mgoddard | #link https://etherpad.opendev.org/p/kolla-xena-ptg | 15:04 |
mgoddard | Please add your name to ^ if you plan to attend | 15:04 |
mgoddard | We will discuss PTG more later | 15:04 |
*** jovial[m] has joined #openstack-kolla | 15:04 | |
mgoddard | #info Kolla feature freeze next week | 15:05 |
mgoddard | Any other announcements? | 15:05 |
mgoddard | #topic Review action items from the last meeting | 15:06 |
*** openstack changes topic to "Review action items from the last meeting (Meeting topic: kolla)" | 15:06 | |
mgoddard | yoctozepto try out quay.io | 15:06 |
mgoddard | he most certainly did | 15:06 |
mgoddard | will discuss later | 15:06 |
mgoddard | #topic CI status | 15:06 |
*** openstack changes topic to "CI status (Meeting topic: kolla)" | 15:06 | |
* hrw | 15:07 | |
mgoddard | lots of nice notes on debian issues, thanks hrw | 15:07 |
hrw | and we need all of them merged | 15:07 |
*** wuchunyang has joined #openstack-kolla | 15:08 | |
mgoddard | this one makes x86 zuul pass: https://review.opendev.org/c/openstack/kolla/+/782606 | 15:09 |
hrw | then would love to get some help on checking do things work | 15:09 |
yoctozepto | I've added a note on rc -13 | 15:09 |
hrw | mgoddard: so s/-1/+2/ ;D | 15:10 |
yoctozepto | +23 | 15:11 |
yoctozepto | oops | 15:11 |
hrw | I would need to check Debian in victoria, ussuri, train | 15:11 |
mgoddard | yoctozepto: how often is ubuntu cephadm failing | 15:12 |
yoctozepto | quite often but not 100% I think | 15:12 |
yoctozepto | let's see the recent runs | 15:12 |
yoctozepto | https://zuul.openstack.org/builds?job_name=kolla-ansible-ubuntu-source-cephadm&branch=master | 15:13 |
yoctozepto | seems not horribly often | 15:13 |
yoctozepto | or perhaps it was not always ubuntu | 15:13 |
yoctozepto | let me see | 15:13 |
yoctozepto | yup, bingo | 15:14 |
yoctozepto | it just I recognised ubuntu as happening more often | 15:14 |
yoctozepto | could be | 15:14 |
yoctozepto | but it's on both | 15:14 |
mgoddard | ok, sounds like more investigation needed | 15:15 |
yoctozepto | I wonder if it's not rc -13 in disguise | 15:15 |
yoctozepto | perhaps the block storage is unreliable or something | 15:15 |
yoctozepto | I think it would make sense to decrease the amount of retries | 15:16 |
openstackgerrit | Pierre Riteau proposed openstack/kayobe master: [DNM] Set environment for testing https://review.opendev.org/c/openstack/kayobe/+/773411 | 15:16 |
yoctozepto | especially for non-voting jobs | 15:16 |
yoctozepto | as we sometimes wait for several runs | 15:16 |
yoctozepto | wonder what happens there | 15:16 |
mgoddard | I don't think we're going to solve this here. Let's move on | 15:16 |
mgoddard | #topic Review requests | 15:17 |
*** openstack changes topic to "Review requests (Meeting topic: kolla)" | 15:17 | |
mgoddard | You know the drill. One review per person | 15:17 |
yoctozepto | I will be back on masakari | 15:17 |
yoctozepto | nothing new today :-( | 15:17 |
hrw | I do not have one. Debian needs 3 ;D | 15:18 |
hrw | found one: https://review.opendev.org/c/openstack/kolla/+/782386 - ussuri backport | 15:18 |
mgoddard | I will choose https://review.opendev.org/c/openstack/kolla-ansible/+/781062 | 15:19 |
hrw | as we still use Ussuri and want upgrade to newer qemu to test SVE guests | 15:19 |
mnasiadka | yoctozepto: https://review.opendev.org/c/openstack/kolla-ansible/+/761872 - that one is for you ;) | 15:19 |
headphoneJames | I have some Questions about test case requirements for Let's Encrypt | 15:19 |
headphoneJames | https://review.opendev.org/c/openstack/kolla-ansible/+/741340 | 15:20 |
mgoddard | headphoneJames: go for it | 15:20 |
headphoneJames | Currently, I use "pebble" to create the TLS certificate. Then I distribute that TLS certificate to all haproxy | 15:21 |
yoctozepto | mnasiadka: why me? | 15:21 |
mnasiadka | yoctozepto: well, find another active core in k-a that does not work in StackHPC :) | 15:22 |
yoctozepto | mnasiadka: wuchunyang | 15:22 |
mnasiadka | is he on the meeting? nope | 15:22 |
headphoneJames | The certificate is not valid, because pebble is a testing product. Therefore, all subsequent requests to the OpenStack deployment would need to ignore the insecure certificate. | 15:23 |
yoctozepto | mnasiadka: ok | 15:23 |
mgoddard | headphoneJames: why isn't it valid? is there no CA certificate available for it? | 15:23 |
headphoneJames | Since I don't have access to the certificate authority for the certificate generated by pebble, I added a boolean to allow for insecure curl method executions to get around this for now. | 15:23 |
headphoneJames | The valid CA cert is generated by pebble -I have not determined a way to pull that certificate out of pebble / docker volume distribute it to the executor that's running the test | 15:25 |
headphoneJames | Note, when I run this with let's encrypt proper (not functional test with pebble), the certificate generated is valid and trusted | 15:26 |
*** rafaelweingartne has joined #openstack-kolla | 15:27 | |
headphoneJames | My first question is just validating the logs for certbot (That a certificate was properly generated) and that the certificate is distributed to all HAProxy enough for a test case? | 15:28 |
yoctozepto | we should be able to get the CA cert from pebble | 15:28 |
yoctozepto | mnasiadka: y no healthchecks? | 15:28 |
wuchunyang | yes | 15:28 |
mnasiadka | yoctozepto: where? | 15:28 |
yoctozepto | mnasiadka: left a comment | 15:29 |
mgoddard | headphoneJames: there's not much point in running a full test suite with insecure mode. We need to either do a more targeted test of the letsencrypt code, or somehow get hold of the CA cert | 15:29 |
yoctozepto | mnasiadka: on ovn-octavia | 15:29 |
*** stand has joined #openstack-kolla | 15:29 | |
mgoddard | headphoneJames: e.g. using something like the openssl suite to grab the cert from haproxy and check that it has come from pebble | 15:30 |
mnasiadka | yoctozepto: actually we can disable distributed FIP, but where do we communicate what CI does nowadays? :D | 15:30 |
yoctozepto | mnasiadka: what about the commit message for the starters? :P | 15:30 |
mnasiadka | commit message sounds good :) | 15:31 |
mnasiadka | will update | 15:31 |
yoctozepto | let's do the distr fip | 15:31 |
headphoneJames | mgoddard: the openssl suite approach would be doable if that feels acceptable | 15:31 |
yoctozepto | sounds fancier | 15:31 |
yoctozepto | and get those healthchecks in | 15:31 |
mgoddard | headphoneJames: that would be better than nothing | 15:32 |
mgoddard | and probably necessary in any case to verify that the cert has been rotated | 15:33 |
mgoddard | I think we've derailed a bit | 15:33 |
mgoddard | Let's move on | 15:33 |
mgoddard | #topic PTG team signup | 15:33 |
*** openstack changes topic to "PTG team signup (Meeting topic: kolla)" | 15:33 | |
mgoddard | #link http://lists.openstack.org/pipermail/openstack-discuss/2021-March/020915.html | 15:34 |
mgoddard | Tomorrow is the deadline to choose time slots | 15:34 |
mgoddard | I didn't get any responses regarding using earlier slots | 15:34 |
mgoddard | so I propose we stick to the usual plan | 15:34 |
mgoddard | 13:00-17:00 UTC on Monday and Tuesday for Kolla and Kolla Ansible | 15:35 |
mgoddard | 13:00-15:00 on Wednesday for Kayobe | 15:35 |
mgoddard | #vote | 15:35 |
hrw | +1 | 15:35 |
wuchunyang | 13:00-17:00 UTC is good for me | 15:35 |
yoctozepto | +1 | 15:36 |
mnasiadka | +1 | 15:36 |
mgoddard | done | 15:37 |
mgoddard | please add your names to https://etherpad.opendev.org/p/kolla-xena-ptg | 15:37 |
mgoddard | please also add discussion topics! | 15:38 |
hrw | * deprecate 'base' image | 15:38 |
hrw | ops, wrong window | 15:38 |
yoctozepto | let's deprecate something :-) | 15:39 |
mgoddard | deprecate yoctozepto | 15:40 |
yoctozepto | :-( | 15:40 |
hrw | mgoddard: you want to be PTL for rest of your life? | 15:41 |
mgoddard | of course | 15:41 |
hrw | +1 | 15:41 |
yoctozepto | <3 | 15:41 |
hrw | uf. nova change which makes Debian work just got +w ;D | 15:41 |
hrw | or rather s/work/fail in known place/ | 15:42 |
yoctozepto | good enuff | 15:42 |
mgoddard | #topic Quay.io | 15:42 |
*** openstack changes topic to "Quay.io (Meeting topic: kolla)" | 15:42 | |
mgoddard | yoctozepto has started a nice PoC of using Quay.io in CI | 15:43 |
mgoddard | #link https://review.opendev.org/c/openstack/kolla/+/781130 | 15:43 |
mgoddard | #link https://review.opendev.org/c/openstack/kolla-ansible/+/781546 | 15:43 |
yoctozepto | thanks, I've pushed all master and victoria images there | 15:43 |
mgoddard | #link https://review.opendev.org/c/openstack/kolla/+/781899 | 15:43 |
yoctozepto | except for centos binary which was failing at the time | 15:43 |
yoctozepto | but it's no biggie | 15:44 |
mgoddard | so I think we have two things to discuss | 15:44 |
mgoddard | 1. any concerns | 15:44 |
mgoddard | 2. plan | 15:44 |
mgoddard | yoctozepto: any concerns? | 15:44 |
yoctozepto | ~> https://review.opendev.org/q/topic:%22quay.io%22+projects:openstack/kolla | 15:44 |
yoctozepto | there is one limitation | 15:44 |
yoctozepto | in that new repositories get pushed as private | 15:45 |
yoctozepto | quay.io is "actively investigating" how to improve this | 15:45 |
yoctozepto | I have a script that fixes it for all repos | 15:45 |
yoctozepto | but it has to be run with human user credentials | 15:45 |
yoctozepto | otoh, we don't create new images that often | 15:46 |
yoctozepto | and quay.io might fix it sooner or later | 15:46 |
yoctozepto | other than that, I am quite happy with it | 15:46 |
yoctozepto | (not to mention having total control over it now) | 15:46 |
yoctozepto | (though I can share) | 15:46 |
yoctozepto | as for the plan | 15:47 |
yoctozepto | I would consider adding daily quay.io publishing jobs | 15:47 |
yoctozepto | leaving dockerhub ones in place to run their weekly sacred dance | 15:47 |
yoctozepto | then switching kolla-ansible to test from quay.io | 15:47 |
yoctozepto | we can run back to dockerhub if it proves worse | 15:48 |
yoctozepto | ;p | 15:48 |
mgoddard | so we would keep publishing to dockerhub for the time being | 15:48 |
mgoddard | it probably makes sense | 15:48 |
mgoddard | less disruption to users | 15:49 |
mgoddard | no need to clean up | 15:49 |
mgoddard | although we would have no way to test the images | 15:49 |
mgoddard | perhaps a weekly test pipeline | 15:49 |
hrw | mgoddard: we build weekly and publish to dockerhub and quay.io in same job? | 15:49 |
mgoddard | yoctozepto suggests publishing to quay.io daily | 15:50 |
yoctozepto | yes, quay.io more often | 15:50 |
yoctozepto | to get on track like we had it before ;p | 15:50 |
hrw | daily job on mon-sat to quay, weekly on sun to quay,docker? | 15:50 |
mgoddard | it would probably be simpler to just have separate publishing jobs | 15:51 |
hrw | sure | 15:51 |
openstackgerrit | Radosław Piliszek proposed openstack/kolla-ansible master: [CI] Drop the workaround in Masakari client calls https://review.opendev.org/c/openstack/kolla-ansible/+/777182 | 15:51 |
mgoddard | although potentially we could more easily test and promote to dockerhub | 15:51 |
yoctozepto | well, we can publish to dockerhub daily | 15:52 |
yoctozepto | it was not publishing that was broken | 15:52 |
yoctozepto | it was pulls | 15:52 |
yoctozepto | (and is) | 15:52 |
mgoddard | I think weekly is fine | 15:52 |
yoctozepto | "is enough" | 15:52 |
hrw | is both | 15:52 |
mgoddard | and doesn't double our CI load | 15:53 |
*** markmcclain has joined #openstack-kolla | 15:53 | |
yoctozepto | well, we can publish from the same jobs | 15:53 |
hrw | we may write in docs "please use quay" and keep dockerhub as source for those who still use it | 15:53 |
yoctozepto | but I guess we could timeout | 15:53 |
yoctozepto | and not know what to blame | 15:53 |
openstackgerrit | Pierre Riteau proposed openstack/kayobe master: [DNM] Set environment for testing https://review.opendev.org/c/openstack/kayobe/+/773411 | 15:53 |
yoctozepto | hrw: yes | 15:53 |
yoctozepto | for the time being | 15:53 |
yoctozepto | let's see | 15:53 |
mgoddard | so we have a rough plan | 15:53 |
yoctozepto | I will enact it | 15:54 |
yoctozepto | will make me happy | 15:54 |
hrw | we can also deprecate dockerhub in Xena and do quay only in Yeti | 15:54 |
mgoddard | wonderful | 15:54 |
mgoddard | what about account credentials for quay.io | 15:54 |
mgoddard | currently I don't think any of us have credentials for dockerub | 15:54 |
mgoddard | which you might argue is a security feature | 15:55 |
yoctozepto | I can give you admin access | 15:55 |
yoctozepto | as you are PTL | 15:55 |
mgoddard | that's the opposite of what I'm suggesting :) | 15:55 |
yoctozepto | and I'm just a humble CI servant :D | 15:55 |
yoctozepto | oh, someone has to have them | 15:55 |
yoctozepto | someone from the previous team generated them for dockerhub | 15:56 |
mgoddard | if any person has credentials, it would allow them to compromise the images | 15:56 |
yoctozepto | they did not appear magically | 15:56 |
yoctozepto | mind you | 15:56 |
yoctozepto | it all boils down to trust | 15:57 |
mgoddard | indeed | 15:57 |
yoctozepto | I can't give you a better answer | 15:57 |
yoctozepto | I trust myself | 15:57 |
yoctozepto | I trust the PTL | 15:57 |
mgoddard | but quite a lot of effort goes into trust in zuul | 15:57 |
mgoddard | this could effectively side step that | 15:57 |
yoctozepto | we can perhaps write something down who is moderating the images | 15:57 |
yoctozepto | zuul has it encrypted | 15:58 |
yoctozepto | as it always had | 15:58 |
hrw | I think that opendev infra should have it somewhere | 15:58 |
yoctozepto | and we trust it a lot | 15:58 |
yoctozepto | as well as all its admins | 15:58 |
hrw | in case of bus incident happening with yoctozepto and mgoddard | 15:58 |
yoctozepto | yeah, they can decryp the secrets | 15:58 |
mgoddard | potentially, a zuul job could rotate the password, encrypt it, and print the encrypted result | 15:58 |
mgoddard | for example | 15:58 |
mgoddard | then no human would have the password | 15:59 |
hrw | I know that I do not want to know it | 15:59 |
mgoddard | but infra could access it | 15:59 |
yoctozepto | I would worry about that thing getting broken in the middle | 15:59 |
yoctozepto | new password and it being nowhere | 15:59 |
mgoddard | it's possible | 16:00 |
mgoddard | we'd probably need a safety access account until we know it works | 16:00 |
mgoddard | anyway, we're out of time | 16:00 |
* hrw out | 16:00 | |
yoctozepto | thanks mgoddard | 16:00 |
mgoddard | I think this is a concern though, and we shouldn't assume anything about what happened with dockerhub | 16:00 |
mgoddard | perhaps we should put something on openstack-dicuss | 16:00 |
yoctozepto | yes, please do; sometimes we get really nice insight | 16:01 |
mgoddard | #action mgoddard email openstack-discuss about quay.io credentials | 16:01 |
mgoddard | #endmeeting | 16:01 |
*** openstack changes topic to "IRC meetings on Wednesdays @ 15:00 UTC - agenda @ https://goo.gl/OXB0DL | Whiteboard: https://bit.ly/2MM7mWF | IRC channel is *LOGGED* @ http://goo.gl/3mzZ7b" | 16:01 | |
openstack | Meeting ended Wed Mar 24 16:01:44 2021 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 16:01 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/kolla/2021/kolla.2021-03-24-15.00.html | 16:01 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/kolla/2021/kolla.2021-03-24-15.00.txt | 16:01 |
openstack | Log: http://eavesdrop.openstack.org/meetings/kolla/2021/kolla.2021-03-24-15.00.log.html | 16:01 |
rafaelweingartne | Hey guys, I was waiting for the open questions/discussions moment :) | 16:02 |
rafaelweingartne | can I ask you guys something? | 16:02 |
rafaelweingartne | We have been experiencing some slowness when executing/using Kolla-ansible. We notice that the "Gather facts" tasks is running slow due to the high number of interfaces in the compute nodes | 16:02 |
rafaelweingartne | have you guys experienced something similar? | 16:03 |
rafaelweingartne | Internally, we added "filter: "ansible_[!qt]*"" here: https://github.com/openstack/kolla-ansible/blob/cdffc4845f8b4e642f3e896870fbef338310efa4/ansible/gather-facts.yml#L34 | 16:03 |
rafaelweingartne | And we would like to check if you guys are also experiencing the same, before opening the patch upstream | 16:04 |
mgoddard | rafaelweingartne: sounds like something outside of kolla ansible | 16:04 |
wuchunyang | yes, we have the similar issue. | 16:04 |
wuchunyang | https://etherpad.opendev.org/p/kolla-wallaby-ptg line: 554 | 16:05 |
rafaelweingartne | wuchunyang: I see | 16:05 |
rafaelweingartne | exactly that | 16:05 |
wuchunyang | actually, filter key just filters the results. ansible still gather the facts. | 16:06 |
*** bengates has quit IRC | 16:06 | |
rafaelweingartne | yes, but then it is just once, and the huge number of entries there do not slow the rest of the process | 16:06 |
*** bengates has joined #openstack-kolla | 16:07 | |
wuchunyang | have you try to use ansible cache ? | 16:07 |
kevko | what about fact caching ? it should fix (except first run) | 16:07 |
rafaelweingartne | by just applying the filter, the run time changed from 0:18:23.854 to 0:02:27.429 | 16:07 |
rafaelweingartne | kevko: we have not tried to use caching. | 16:08 |
rafaelweingartne | I will check this as well then, before creating a patch | 16:08 |
kevko | i'm also curious ..because when we are upgrading through kolla ..we are waiting also 30 minutes for facts :( | 16:08 |
rafaelweingartne | yes, and that was starting to bother us, specially now with bigger and bigger setups | 16:09 |
rafaelweingartne | thanks for the hint guys | 16:09 |
rafaelweingartne | I will check the caching, and then I will propose something for Kolla-ansible | 16:10 |
wuchunyang | hope you can fix this . | 16:11 |
*** rafaelweingartne has quit IRC | 16:12 | |
*** wuchunyang has left #openstack-kolla | 16:12 | |
mnasiadka | I saw that some time ago: https://github.com/ansible/ansible/issues/73654 | 16:14 |
priteau | I also saw slowdowns due to large number of interfaces on Neutron nodes with many networks/routers. Fact caching helps | 16:30 |
mnasiadka | yoctozepto: about healthcheck, it seems octavia driver agent communicates with octavia-api using a socket, we have healthcheck_socket but it requires lsof - which is not installed - are we happy with installing lsof in base? :D | 16:31 |
yoctozepto | mnasiadka: makes sense | 16:32 |
mnasiadka | yoctozepto: so I'll followup with another two changes for lsof in Kolla and octavia-driver-agent healthcheck - does that sound ok? (I'll only update the commit message in this change) | 16:33 |
yoctozepto | mnasiadka: fine by me since you may want to backport this one, no? | 16:34 |
mnasiadka | yoctozepto: well, it would be nice, but all in all it's a feature :) | 16:34 |
mnasiadka | (although it was a bug that we didn't have octavia-driver-agent) :) | 16:34 |
yoctozepto | mnasiadka: yeah, I would go with backporting | 16:35 |
yoctozepto | anyhow, I've added octavia to ovn in https://etherpad.opendev.org/p/KollaAnsibleScenarios | 16:36 |
mnasiadka | thanks | 16:37 |
mnasiadka | updated commit message | 16:37 |
openstackgerrit | Pierre Riteau proposed openstack/kayobe master: [DNM] Set environment for testing https://review.opendev.org/c/openstack/kayobe/+/773411 | 16:37 |
openstackgerrit | Michal Nasiadka proposed openstack/kolla-ansible master: Add missing octavia-driver-agent https://review.opendev.org/c/openstack/kolla-ansible/+/761872 | 16:38 |
openstackgerrit | Michal Nasiadka proposed openstack/kolla master: base: Add lsof for healthcheck_socket https://review.opendev.org/c/openstack/kolla/+/782815 | 16:40 |
openstackgerrit | Pierre Riteau proposed openstack/kayobe master: [DNM] Set environment for testing https://review.opendev.org/c/openstack/kayobe/+/773411 | 16:56 |
*** samcat116 has joined #openstack-kolla | 17:11 | |
*** rpittau is now known as rpittau|afk | 17:24 | |
openstackgerrit | Merged openstack/kayobe master: Add Ironic enabled_bios_interfaces and default_bios_interface settings https://review.opendev.org/c/openstack/kayobe/+/781620 | 17:25 |
dardelean | Hello. Are there plans to support CentOS Stream? Or what is the approach for the future of CentOS in Kolla, if discussed. Thanks | 17:29 |
*** suff has joined #openstack-kolla | 17:35 | |
*** jonaspaulo has joined #openstack-kolla | 17:36 | |
dardelean | or rocky linux | 17:40 |
openstackgerrit | Pierre Riteau proposed openstack/kayobe master: [DNM] Set environment for testing https://review.opendev.org/c/openstack/kayobe/+/773411 | 17:42 |
*** gfidente is now known as gfidente|af | 17:46 | |
*** gfidente|af is now known as gfidente|afk | 17:46 | |
*** ysirndjuro has quit IRC | 17:49 | |
openstackgerrit | Pierre Riteau proposed openstack/kayobe master: [DNM] Set environment for testing https://review.opendev.org/c/openstack/kayobe/+/773411 | 18:01 |
*** bengates_ has joined #openstack-kolla | 18:08 | |
*** amoralej is now known as amoralej|off | 18:10 | |
mgoddard | dardelean: Wallaby will be based on CentOS stream | 18:11 |
*** bengates has quit IRC | 18:11 | |
*** andrewbonney has quit IRC | 18:12 | |
mgoddard | dardelean: rocky linux tbd | 18:12 |
openstackgerrit | James Kirsch proposed openstack/kolla-ansible master: Add support for LetsEncrypt-managed certs https://review.opendev.org/c/openstack/kolla-ansible/+/741340 | 18:13 |
openstackgerrit | Merged openstack/kolla-ansible master: Remove Monasca Log Transformer https://review.opendev.org/c/openstack/kolla-ansible/+/769900 | 18:21 |
kevko | mgoddard: still here ? | 18:25 |
kevko | mgoddard: i can't add conditional what you advised .. | 18:25 |
kevko | mgoddard: in mariadb role review i don't have variable enable_proxysql yes | 18:25 |
kevko | yet | 18:25 |
yoctozepto | kevko: how so? it should be global | 18:26 |
kevko | yoctozepto: well, yes, but i have it in follow-up patch | 18:26 |
yoctozepto | uh-oh | 18:27 |
yoctozepto | that explains it | 18:27 |
yoctozepto | need mgoddard around | 18:27 |
kevko | yoctozepto: what i can do is to add this conditional to follow-up patch for proxysql .. | 18:27 |
yoctozepto | sounds sensible | 18:28 |
openstackgerrit | Merged openstack/kolla-ansible master: Disable Monasca Log Metrics service by default https://review.opendev.org/c/openstack/kolla-ansible/+/769901 | 18:32 |
openstackgerrit | Radosław Piliszek proposed openstack/kolla master: Deprecate chrony https://review.opendev.org/c/openstack/kolla/+/782840 | 18:36 |
openstackgerrit | Merged openstack/kolla-ansible master: Support disabling Monasca alerting pipeline https://review.opendev.org/c/openstack/kolla-ansible/+/769902 | 19:03 |
openstackgerrit | Merged openstack/kolla-ansible master: Support bypassing Monasca Log API for control plane logs https://review.opendev.org/c/openstack/kolla-ansible/+/776219 | 19:03 |
openstackgerrit | Merged openstack/kolla-ansible master: Follow up fixes for Monasca docs and formatting https://review.opendev.org/c/openstack/kolla-ansible/+/778191 | 19:04 |
*** dking has joined #openstack-kolla | 19:07 | |
*** suff has quit IRC | 19:10 | |
openstackgerrit | Merged openstack/kolla-ansible master: Add missing octavia-driver-agent https://review.opendev.org/c/openstack/kolla-ansible/+/761872 | 19:12 |
sean-k-mooney | yoctozepto: fyi i was trying to do stable victoria all in one yesterady and deploying without haproxy is broken again | 19:14 |
yoctozepto | sean-k-mooney: ooh, could be as we are not testing this particular scenario | 19:15 |
yoctozepto | sean-k-mooney: care to report? (and maybe fix too? :-) ) | 19:15 |
sean-k-mooney | it keeps trying to connect to the vip address | 19:15 |
sean-k-mooney | which you know wont exist | 19:15 |
sean-k-mooney | for example https://github.com/openstack/kolla-ansible/blob/stable/victoria/ansible/roles/mariadb/tasks/wait_for_loadbalancer.yml | 19:16 |
sean-k-mooney | is always run https://github.com/openstack/kolla-ansible/blob/5e638b757bdda9fbddf0fe0be5d76caa3419af74/ansible/roles/mariadb/tasks/register.yml#L2 | 19:17 |
yoctozepto | oh, that would be my bad | 19:17 |
sean-k-mooney | https://github.com/openstack/kolla-ansible/commit/03cd7eb3563788ca1ffd7b19130f18614887a546 | 19:18 |
sean-k-mooney | that added it | 19:18 |
yoctozepto | we should probably add, at least non-voting, this very minimal deployment | 19:18 |
yoctozepto | ooh, glad not me | 19:18 |
sean-k-mooney | i tought we used to use this in the gate at one point | 19:18 |
sean-k-mooney | there are other issues | 19:18 |
sean-k-mooney | i added a when enable_haprozy | bool | 19:18 |
yoctozepto | yeah, but then haproxy was more common still | 19:19 |
sean-k-mooney | to skpi it but it will fail a little latere then | 19:19 |
sean-k-mooney | here https://github.com/openstack/kolla-ansible/blob/5e638b757bdda9fbddf0fe0be5d76caa3419af74/ansible/roles/mariadb/tasks/check.yml#L2 | 19:20 |
sean-k-mooney | which is invoked here https://github.com/openstack/kolla-ansible/blob/3411b9e4201e619613cef427d228cf00f310a144/ansible/roles/mariadb/tasks/deploy.yml#L13-L14 | 19:21 |
yoctozepto | I am dropping this duplication at some point | 19:24 |
yoctozepto | I remember that part | 19:24 |
yoctozepto | probably for wallaby though | 19:24 |
yoctozepto | or not merged yet | 19:24 |
yoctozepto | but yeah, the point is this is not haproxy-less-friendly | 19:24 |
yoctozepto | so to speak | 19:25 |
yoctozepto | that said, any particular reason you don't want haproxy? | 19:25 |
* yoctozepto selling the working version | 19:25 | |
sean-k-mooney | oh this was a test deployment on openstack and i just didint feel like creating a neutron port to resreve an ip for it so i disabled it as a workaround last night | 19:26 |
sean-k-mooney | and then found it was broken again | 19:26 |
sean-k-mooney | this is about the 5 time its been broken it happens every cople of releases | 19:27 |
sean-k-mooney | so im use to just using ha proxy | 19:27 |
sean-k-mooney | we still document haproxy less deployment for ip constratined envrioments so either we shoudl fix it or drop support offcally and update the doc | 19:28 |
sean-k-mooney | https://github.com/openstack/kolla-ansible/blob/3411b9e4201e619613cef427d228cf00f310a144/doc/source/admin/advanced-configuration.rst#ip-address-constrained-environments | 19:29 |
sean-k-mooney | yoctozepto: this is just the env i was setting out to test if i could expose the service with different dns subdomains instead of ports | 19:30 |
yoctozepto | sure thing! | 19:30 |
yoctozepto | makes sense you would want it like that | 19:31 |
yoctozepto | it could also prove more beneficial for those who develop the services using kolla | 19:31 |
sean-k-mooney | well i normally use ha proxy even for singel node but it was 3 am so thought this would be quicker | 19:31 |
sean-k-mooney | truned out not to be in the end | 19:31 |
yoctozepto | yeah, but in some envs it really does not make sense to find that vip address | 19:32 |
sean-k-mooney | yep | 19:32 |
yoctozepto | well, you can always spin it up on some loopback | 19:32 |
yoctozepto | but still | 19:32 |
yoctozepto | :D | 19:32 |
yoctozepto | I guess we add one job for that | 19:32 |
yoctozepto | no need to test all distros | 19:32 |
sean-k-mooney | ya i could have chossen a 127.0.x.y address | 19:32 |
sean-k-mooney | i would proably jsut add it to one of the existing jobs | 19:33 |
*** zijlboot has quit IRC | 19:33 | |
sean-k-mooney | or make it a supper shrot one | 19:33 |
sean-k-mooney | that just install the db | 19:33 |
*** zijlboot has joined #openstack-kolla | 19:33 | |
yoctozepto | and keystone ;d | 19:34 |
*** samcat116 has quit IRC | 19:37 | |
sean-k-mooney | i mean you praobly want to enable the core services really | 19:39 |
sean-k-mooney | that not much longer but ya one job should be more then enough | 19:40 |
sean-k-mooney | documenting the use fo a 127 address could be valid for singel node too as an alterinive to disabling haproxy | 19:40 |
sean-k-mooney | part of the issue is proably cause by https://github.com/openstack/kolla-ansible/commit/026f5cc48a37422cc9ba4b1a277fd8aea73a3e03#diff-792522c538794367129103be0ba66a30d71e4f609ea24bd1d47e7bc9add7ae00 | 19:41 |
sean-k-mooney | yoctozepto: have ye drop support for deploying mariadb without galara by the way | 19:42 |
sean-k-mooney | that used to be one of the big thing that change when you did single node in the past | 19:42 |
*** livelace has joined #openstack-kolla | 19:43 | |
openstackgerrit | Michal Arbet proposed openstack/kolla-ansible master: Refactor mariadb to support shards https://review.opendev.org/c/openstack/kolla-ansible/+/766952 | 19:43 |
openstackgerrit | Michal Arbet proposed openstack/kolla-ansible master: Rename role haproxy to loadbalancer https://review.opendev.org/c/openstack/kolla-ansible/+/770618 | 19:44 |
openstackgerrit | Michal Arbet proposed openstack/kolla-ansible master: Add proxysql support for database https://review.opendev.org/c/openstack/kolla-ansible/+/770215 | 19:44 |
openstackgerrit | Michal Arbet proposed openstack/kolla-ansible master: Edit services roles to support database sharding https://review.opendev.org/c/openstack/kolla-ansible/+/770216 | 19:44 |
openstackgerrit | Michal Arbet proposed openstack/kolla-ansible master: [CI] Test ProxySQL with shards in the nova cells scenario https://review.opendev.org/c/openstack/kolla-ansible/+/770621 | 19:44 |
openstackgerrit | Michal Arbet proposed openstack/kolla-ansible master: Add mariadb arbitrator to mariadb role https://review.opendev.org/c/openstack/kolla-ansible/+/780811 | 19:44 |
openstackgerrit | Michal Arbet proposed openstack/kolla-ansible master: [CI] Test Mariadb-Arbitrator with shards in the nova cells scenario https://review.opendev.org/c/openstack/kolla-ansible/+/780970 | 19:44 |
sean-k-mooney | ah i see this is been reqorked a lot a the moment | 19:44 |
*** e0ne has quit IRC | 19:51 | |
sean-k-mooney | that might be the issue alhtough i dont have time to confirm not but if we are configuring glarea even for single node perhaps it never fully starts | 19:55 |
sean-k-mooney | oh chrony is being remvoed? is that not the replacemnt for ntpd? | 19:58 |
sean-k-mooney | has it been replaced again | 19:58 |
sean-k-mooney | personlly i would be sad to see it go as i prefer havign kolla manage that in a contaienr instead of using the distos default way but i guess i can see why you might remvoe it | 20:01 |
sean-k-mooney | same is true for things like multipathd | 20:02 |
sean-k-mooney | i much prefer having as little as possible running on the host out side of a container beyond docker | 20:02 |
yoctozepto | sean-k-mooney: one-node galera is fine, should not require haproxy | 20:05 |
yoctozepto | yeah, I like this approach too | 20:05 |
yoctozepto | but ntp is too basic nowadays, like ssh | 20:05 |
sean-k-mooney | well isnt ntp dperecated | 20:06 |
yoctozepto | and we are fighting distros ways | 20:06 |
yoctozepto | I mean ntp as any provider | 20:06 |
sean-k-mooney | at least on the rhel side they wanted to move it to chorny at openpoint | 20:06 |
yoctozepto | not the ntpd | 20:06 |
sean-k-mooney | and likely systmed will take it over | 20:06 |
yoctozepto | yeah, that's what is happening on debuntu now | 20:07 |
sean-k-mooney | ya i think ntpd was depcreated in rhel7 and replace with chrony in rhel 8 and i assume systemd will just do it in rhle9 | 20:07 |
sean-k-mooney | so not really that concerend with removing it | 20:07 |
yoctozepto | indeed | 20:07 |
sean-k-mooney | just like to install as little as posibel on the hosts | 20:07 |
yoctozepto | me too | 20:08 |
*** also_stingrayza has joined #openstack-kolla | 20:10 | |
sean-k-mooney | i havent really been following kolla dev fro a while has anything related to podman come up lately | 20:10 |
*** stingrayza has quit IRC | 20:10 | |
*** bengates_ has quit IRC | 20:11 | |
sean-k-mooney | personally im fine using docker but on the topic of less stuff running on the host not haveing a deamon has some advantages althgouh i still prefer docker since it just works | 20:11 |
sean-k-mooney | getting podmand to work on anything that is not fedroa based and with out sudo is a pain. | 20:12 |
*** samcat116 has joined #openstack-kolla | 20:33 | |
openstackgerrit | James Kirsch proposed openstack/kolla-ansible master: Add support for LetsEncrypt-managed certs https://review.opendev.org/c/openstack/kolla-ansible/+/741340 | 20:50 |
yoctozepto | sean-k-mooney: no progress that I know of; pity that Canonical is kinda entrenched with Snapd and Red Hat analogously with Podman; and suse leaving openstack and going 100% kubernetes | 21:02 |
*** jonaspaulo has quit IRC | 21:02 | |
*** livelace has quit IRC | 21:03 | |
sean-k-mooney | well snapd and podman do very different things | 21:07 |
sean-k-mooney | snapd is more like flatpack | 21:07 |
sean-k-mooney | but with a deamon | 21:07 |
sean-k-mooney | canonoical provide docker via snapd as a way to install it now | 21:07 |
sean-k-mooney | adn for ubunut core i think that is the only way to install it | 21:08 |
sean-k-mooney | sicne that has an imuntable root file system | 21:08 |
sean-k-mooney | i only use podman if its preinstalled | 21:08 |
yoctozepto | sean-k-mooney: yup, they are two quite different things (but one could obviously do openstack in either) but I mean the adoption model - it does not want to go beyond the parent company distro | 21:17 |
yoctozepto | anyhow, time to bed now for me | 21:18 |
yoctozepto | take care | 21:18 |
*** samcat116 has quit IRC | 21:34 | |
*** kevko has quit IRC | 21:37 | |
openstackgerrit | James Kirsch proposed openstack/kolla-ansible master: Add support for LetsEncrypt-managed certs https://review.opendev.org/c/openstack/kolla-ansible/+/741340 | 22:12 |
*** kevko has joined #openstack-kolla | 22:36 | |
*** vishalmanchanda has quit IRC | 22:41 | |
*** kevko has quit IRC | 23:00 | |
*** stand has quit IRC | 23:20 | |
*** Underknowledge has quit IRC | 23:40 | |
*** Underknowledge has joined #openstack-kolla | 23:51 | |
*** Underknowledge has quit IRC | 23:54 | |
*** Underknowledge has joined #openstack-kolla | 23:54 | |
*** Underknowledge has quit IRC | 23:59 | |
*** Underknowledge has joined #openstack-kolla | 23:59 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!