opendevreview | Pierre Riteau proposed openstack/kayobe master: Add overcloud_dib_upper_constraints_file variable https://review.opendev.org/c/openstack/kayobe/+/819630 | 05:28 |
---|---|---|
opendevreview | Pierre Riteau proposed openstack/kayobe master: Support building multiple disk images https://review.opendev.org/c/openstack/kayobe/+/812516 | 06:20 |
opendevreview | Pierre Riteau proposed openstack/kolla-ansible master: Move project_name to role vars https://review.opendev.org/c/openstack/kolla-ansible/+/818714 | 06:32 |
opendevreview | Pierre Riteau proposed openstack/kayobe master: Clean up release notes for Xena release https://review.opendev.org/c/openstack/kayobe/+/818521 | 06:39 |
DK4 | hello, any hints on how i can use prometheus to get opesntack metrics? i have grafana+prometheus enabled but i can only fetch system etrics of the host not openststack specific metrics of my deployment. any advice on how to enable that? | 09:08 |
priteau | Hello DK4 | 09:11 |
priteau | enable_prometheus_openstack_exporter: yes | 09:11 |
jingvar | your metrics is your pain :) as I remember grafana dashboard should be configured manualy | 09:13 |
DK4 | jingvar: ye i know, but im just wondering if the openstack metrics can also be exported as i have only system ones. priteau: thanks ill try that | 09:15 |
opendevreview | Pierre Riteau proposed openstack/kayobe master: Support building multiple disk images https://review.opendev.org/c/openstack/kayobe/+/812516 | 09:44 |
*** amoralej|off is now known as amoralej | 14:06 | |
mnasiadka | oops | 15:01 |
mnasiadka | #startmeeting kolla | 15:01 |
opendevmeet | Meeting started Wed Dec 1 15:01:25 2021 UTC and is due to finish in 60 minutes. The chair is mnasiadka. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:01 |
opendevmeet | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:01 |
opendevmeet | The meeting name has been set to 'kolla' | 15:01 |
mnasiadka | mgoddard mnasiadka hrw egonzalez yoctozepto rafaelweingartne cosmicsound osmanlicilegi bbezak parallax Fl1nt frickler adrian-a meeting now | 15:01 |
mnasiadka | #topic rollcall | 15:01 |
adrian-a | o/ | 15:02 |
mnasiadka | o/ | 15:02 |
yoctozepto-clone | o/ | 15:02 |
yoctozepto-clone | (had to use a different nick because of issues with my webclient) | 15:03 |
mnasiadka | clones welcome | 15:03 |
mnasiadka | #topic agenda | 15:05 |
mnasiadka | * Review action items from the last meeting | 15:05 |
mnasiadka | * CI status | 15:05 |
mnasiadka | * Release tasks | 15:05 |
mnasiadka | * Yoga cycle planning | 15:05 |
mnasiadka | * Python3.6 support removal in Yoga | 15:05 |
mnasiadka | * Open discussion | 15:05 |
mnasiadka | #topic Review action items from the last meeting | 15:05 |
mnasiadka | mnasiadka to triage security bugs and update them with resolution plan (if needed) | 15:06 |
mnasiadka | yoctozepto hide properly init-runonce | 15:06 |
mnasiadka | not forget to go through backports for stable branches (L248 on Whiteboard) and do stable releases afterwards. | 15:06 |
mnasiadka | mnasiadka post a patch for docs - standard topics that should be discussed over PTG and then revisited in mid-cycle | 15:06 |
mnasiadka | mnasiadka Add ansible-core 2.12 to the list of Yoga priorities | 15:06 |
mnasiadka | mnasiadka Add rabbitmq 3.9 to the list of Yoga priorities | 15:06 |
mnasiadka | I didn't do triage | 15:06 |
mnasiadka | I didn't post a patch for docs as recurring PTG topic | 15:07 |
mnasiadka | I added ansible and rmq to priorities | 15:07 |
mnasiadka | I guess nobody did go through backports for stable branches | 15:07 |
mnasiadka | and yoctozepto-clone hasn't hidden init-runonce | 15:07 |
mnasiadka | #action mnasiadka to triage security bugs and update them with resolution plan (if needed) | 15:07 |
yoctozepto-clone | yeah, sadly | 15:07 |
mnasiadka | #action yoctozepto hide properly init-runonce | 15:07 |
yoctozepto-clone | tough times | 15:07 |
mnasiadka | #action anybody not forget to go through backports for stable branches (L248 on Whiteboard) and do stable releases afterwards. | 15:07 |
yoctozepto-clone | I think we need to prioritise the deprecations | 15:08 |
mnasiadka | #action mnasiadka post a patch for docs - standard topics that should be discussed over PTG and then revisited in mid-cycle | 15:08 |
mnasiadka | yoctozepto-clone: probably | 15:08 |
mnasiadka | #topic CI status | 15:08 |
mnasiadka | Anybody wants to say that something is not green? | 15:09 |
mnasiadka | so everything green on the whiteboard | 15:09 |
mnasiadka | let's move on | 15:09 |
mnasiadka | #topic Release tasks | 15:09 |
mnasiadka | It's R-17 now | 15:09 |
mnasiadka | R-17: Switch source images to current releaseĀ¶ | 15:10 |
mnasiadka | I think mgoddard (absent) did post some changes | 15:10 |
mnasiadka | We just need to move them forward | 15:10 |
yoctozepto-clone | links please | 15:11 |
mnasiadka | (looking for them) | 15:11 |
mnasiadka | Seems I'm blind | 15:12 |
kevko_ | hi, sorry, I had a meeting in 15 :/ | 15:13 |
mnasiadka | Ok, I'll find them offline - no logical sense to wait now. | 15:14 |
mnasiadka | #topic Yoga cycle planning | 15:14 |
mnasiadka | I started to populate the whiteboard with Yoga priorities, need to be extended but there's a list | 15:15 |
mnasiadka | I agree with yoctozepto we should start deprecating binary | 15:15 |
yoctozepto-clone | and multidistros | 15:15 |
yoctozepto-clone | well, going forward there | 15:15 |
mnasiadka | around single distro - I updated https://etherpad.opendev.org/p/kolla-only-on-debian - to reflect replies I did get from various MLs and commercial customers | 15:16 |
yoctozepto-clone | we know debian images currently work universally | 15:16 |
yoctozepto-clone | hmm | 15:16 |
mnasiadka | But lacking mgoddard and hrw here - I don't know if we shouldn't discuss those next week. | 15:16 |
yoctozepto-clone | i guess these are moot points as we only ever wished to have them | 15:16 |
admin1 | is there a way to deploy docker + databases before deploying kolla ansible ? | 15:17 |
yoctozepto-clone | never had | 15:17 |
admin1 | test case .. to check if controller nodes can be re-created with just the database backup in event of a complete filesystem corrupt/crash | 15:18 |
mnasiadka | yoctozepto: well, the FIPS one is something we'll need to support soon. | 15:18 |
mnasiadka | admin1: we have a meeting now, please wait until it ends - and then ask questions :) | 15:18 |
admin1 | oh .. sorry | 15:19 |
mnasiadka | yoctozepto: as in our company ;) | 15:19 |
hrw | o\ | 15:19 |
mnasiadka | and the selinux/apparmor case is also interesting, because that's what customers are asking | 15:19 |
mnasiadka | I wouldn't like to maintain a complete downstream fork of Kolla | 15:19 |
hrw | let me read what was in meeting | 15:19 |
mnasiadka | hrw: basically https://etherpad.opendev.org/p/kolla-only-on-debian is a list of roadblocks from ML and some other sources feedback around single distro | 15:20 |
hrw | ok let me look | 15:20 |
yoctozepto-clone | is debian not compatible with fips somehow? | 15:21 |
mnasiadka | FIPS compliant, but not certified | 15:21 |
mnasiadka | IIRC | 15:22 |
yoctozepto-clone | ah | 15:22 |
yoctozepto-clone | well, it would be hard to get our images certified anyhow | 15:22 |
yoctozepto-clone | if not simply impossible | 15:22 |
mnasiadka | Probably yes, just mentioning what is on our employers radar. | 15:23 |
mnasiadka | I mean hard, not impossible. | 15:23 |
yoctozepto-clone | ok | 15:23 |
hrw | yoctozepto-clone: RHEL is FIPS certified so people were happy with CentOS | 15:23 |
mnasiadka | And I think Ubuntu is FIPS certified as well | 15:24 |
yoctozepto-clone | yeah, but centos is gone unless we go rocky and then again we need to provide openstack ourselves | 15:24 |
yoctozepto-clone | choices, choices... | 15:24 |
hrw | whatever RHEL8 based is no go for us | 15:24 |
mnasiadka | what does it mean provide openstack ourselves? | 15:24 |
hrw | does not matter is it CS8, RockyLinux, AlmaLinux | 15:25 |
hrw | Yoga is last py3.6 cycle | 15:25 |
yoctozepto-clone | mnasiadka: no packages for rocky | 15:25 |
hrw | please s/rocky/rockylinux | 15:25 |
mnasiadka | Yes, there's the python3.6 drop that TC has... dropped on us. | 15:25 |
mnasiadka | yoctozepto-clone: yeah well, we're dropping binary anyway, so that's only a couple of packages. | 15:25 |
adrian-a | I guess wouldn't be hard to support Debian+Ubuntu based images, where Ubuntu would be FIPS certified? | 15:25 |
hrw | we need to depracate CentOS in Yoga | 15:26 |
kevko | Ubuntu is FIPS certified ..and ubuntu is ..you know ..just debian :D | 15:26 |
kevko | adrian-a: +1 | 15:26 |
yoctozepto-clone | +1 hrw and adrian-a | 15:26 |
yoctozepto-clone | works for me | 15:26 |
yoctozepto-clone | centos is the biggest pain point | 15:26 |
yoctozepto-clone | I mean - currently | 15:27 |
mnasiadka | Currently the biggest pain point is OpenStack forcing us to go cs9 in Yoga, or drop CentOS at all. | 15:28 |
mnasiadka | But let's see how tomorrows TC meeting will play out. | 15:29 |
jingvar | I 'm working on ISO image builder that will provision baremetal kayobe control host | 15:29 |
yoctozepto-clone | I think we will revert this one | 15:29 |
kevko | mnasiadka: why "openstack forcing us" ? | 15:29 |
yoctozepto-clone | as there is no certain win to drop py3.6 in yoga | 15:29 |
mnasiadka | kevko: do you read the openstack ML sometimes? | 15:29 |
hrw | kevko: drop of py3.6 | 15:29 |
* frickler waves late and tries to catch up | 15:30 | |
frickler | and also admits that possibly the suggestion to drop py36 might have initiated from me | 15:31 |
* hrw waves finger at frickler. bad, bad boy! | 15:31 | |
yoctozepto-clone | well, I guess I was overly optimistic there as well | 15:32 |
yoctozepto-clone | always forgetting non-default python version on centos in nerfed | 15:32 |
mnasiadka | Ok then, let's assume it gets reverted or worry if it is not for now. | 15:32 |
mnasiadka | What about deprecating binary? We have some TODOs related with it. | 15:33 |
mnasiadka | L322 on https://etherpad.opendev.org/p/KollaWhiteBoard | 15:34 |
yoctozepto-clone | need to work on them | 15:35 |
hrw | added links to my patches there | 15:35 |
mnasiadka | Great, added your name in TODO | 15:35 |
mnasiadka | So - are there any volunteers for the rest of unassigned tasks? | 15:36 |
mnasiadka | ok then, no volunteers, I'll ask again next week ;-) | 15:38 |
frickler | I can start looking into "How to locally patch source images" | 15:38 |
yoctozepto-clone | great | 15:38 |
mnasiadka | Sure, add it in the whiteboard that you'll be working on it | 15:39 |
kevko | frickler: add me to cc if you will have something .. | 15:39 |
frickler | kevko: sure | 15:39 |
hrw | took over 2 entries | 15:40 |
mnasiadka | ok, something is moving, nice - thanks ) | 15:40 |
mnasiadka | :) | 15:40 |
hrw | btw - until nova gets rid of powervm dependency we are ...ed with source builds | 15:41 |
hrw | INFO:kolla.common.utils.nova-base:The conflict is caused by: | 15:41 |
hrw | INFO:kolla.common.utils.nova-base: pypowervm 1.1.26 depends on futures>=3.0; python_version == "3.6" | 15:41 |
hrw | INFO:kolla.common.utils.nova-base: The user requested (constraint) futures===3.0.5 | 15:41 |
yoctozepto-clone | argh | 15:41 |
mnasiadka | So nova enforces everybody to install pypowervm, although less than 1% of users use that functionality? | 15:41 |
frickler | wasn't that cleaned up already? maybe not backported | 15:42 |
hrw | you are overoptimistic with that 1% | 15:42 |
frickler | also this is hidden in upstream CI due to cached wheels sadly. | 15:43 |
yoctozepto-clone | indeed | 15:44 |
yoctozepto-clone | we have experimental jobs that ignore the wheels | 15:44 |
yoctozepto-clone | we can run them less experimentally | 15:44 |
mnasiadka | Are we also trying to get rid of RDO/UCA during deprecating binary? | 15:44 |
hrw | they both provide missing deps | 15:44 |
hrw | and/or updates | 15:45 |
mnasiadka | well true | 15:45 |
yoctozepto-clone | yeah, we neede some deps I think | 15:45 |
yoctozepto-clone | like ceph libs | 15:45 |
mnasiadka | I think Ceph libs should follow RabbitMQ/MariaDB (use vendor repos) | 15:45 |
mnasiadka | Now that they build Debian as well | 15:45 |
hrw | mnasiadka: with aarch64 ones? | 15:45 |
mnasiadka | at least Debian has arm64 packages on download.ceph.com | 15:46 |
hrw | o! things changed | 15:47 |
hrw | RUN ln -s nova-base-source/* nova \ | 15:47 |
hrw | + && sed -i -e "/^pypowervm/d" nova/requirements.txt \ | 15:47 |
hrw | and nova builds ;D | 15:47 |
yoctozepto-clone | hrw, mnasiadka: re ceph: wonderful! | 15:48 |
yoctozepto-clone | hrw: I guess we can do this with a reno and be good | 15:48 |
mnasiadka | Added that to Yoga priorities list | 15:49 |
mnasiadka | Ok then, I think the binary deprecation is pretty well covered. | 15:50 |
yoctozepto-clone | indeed | 15:50 |
mnasiadka | Let's discuss the single distro again next week, we should have some more insight from py36 drop and I'll investigate the FIPS/SELinux/AppArmor things, if this is really something we want to do next year (as a company). | 15:51 |
mnasiadka | I think we already covered the py36 drop topic that was the next one | 15:52 |
mnasiadka | So unless anybody has any additional topics around Yoga priorities - let's move to Open Discussion. | 15:52 |
opendevreview | Marcin Juszkiewicz proposed openstack/kolla master: nova: drop pypowervm dependency https://review.opendev.org/c/openstack/kolla/+/820042 | 15:52 |
mnasiadka | #topic Open discussion | 15:53 |
opendevreview | Marcin Juszkiewicz proposed openstack/kolla master: switch source images to follow master branches https://review.opendev.org/c/openstack/kolla/+/820043 | 15:54 |
ohorecny2 | Hi, my team proposed change for refactoring of kolla_docker, can you please review guys? We would like to move forward. Change is here: https://review.opendev.org/c/openstack/kolla-ansible/+/817954 | 15:54 |
hrw | mnasiadka: please take care of 820043 patch - it may need better commit message | 15:54 |
mnasiadka | sure, I'll check previous similar changes and adapt if needed. | 15:55 |
hrw | mnasiadka: thx | 15:55 |
* hrw on sick leave this week | 15:55 | |
yoctozepto-clone | get well hrw! | 15:56 |
mnasiadka | ok, I see we're done for today | 15:56 |
mnasiadka | #endmeeting | 15:57 |
opendevmeet | Meeting ended Wed Dec 1 15:57:00 2021 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:57 |
opendevmeet | Minutes: https://meetings.opendev.org/meetings/kolla/2021/kolla.2021-12-01-15.01.html | 15:57 |
opendevmeet | Minutes (text): https://meetings.opendev.org/meetings/kolla/2021/kolla.2021-12-01-15.01.txt | 15:57 |
opendevmeet | Log: https://meetings.opendev.org/meetings/kolla/2021/kolla.2021-12-01-15.01.log.html | 15:57 |
mnasiadka | hrw: get well | 15:57 |
mnasiadka | thanks for attending! | 15:57 |
hrw | mnasiadka: whiteboard L326 edited | 15:57 |
opendevreview | Marcin Juszkiewicz proposed openstack/kolla master: qdrouterd: add release note with deprecation notice https://review.opendev.org/c/openstack/kolla/+/820045 | 16:01 |
opendevreview | Marcin Juszkiewicz proposed openstack/kolla master: Debian: enable building Bifrost images on x86-64 https://review.opendev.org/c/openstack/kolla/+/814783 | 16:01 |
hrw | rebased on top of 'let switch to master' | 16:02 |
hrw | as this should make it buildable | 16:02 |
hrw | hm. 11 opened patches. | 16:03 |
* hrw out | 16:03 | |
jingvar | Is it a good place for questions about Bifrost (manual installation)? | 16:24 |
opendevreview | Pierre Riteau proposed openstack/kayobe master: Support building multiple disk images https://review.opendev.org/c/openstack/kayobe/+/812516 | 16:26 |
opendevreview | Pierre Riteau proposed openstack/kolla-ansible master: Update noVNC URL for noVNC >= 1.0.0 https://review.opendev.org/c/openstack/kolla-ansible/+/820048 | 16:41 |
yoctozepto-clone | jingvar: more likely #openstack-ironic | 17:00 |
jingvar | yoctozepto-clone: thanks | 17:05 |
jingvar | I think will simple use Kolla for Bifrost, but it uses more resources | 17:10 |
opendevreview | Marcin Juszkiewicz proposed openstack/kolla master: build: 5s delay + note when binary images are used https://review.opendev.org/c/openstack/kolla/+/818378 | 17:27 |
hrw | mnasiadka: let us deprecate and drop vmtp. it is not maintained | 17:35 |
hrw | INFO:kolla.common.utils.vmtp:The conflict is caused by: | 17:36 |
hrw | INFO:kolla.common.utils.vmtp: vmtp 2.5.1.dev18 depends on PrettyTable<0.8 | 17:36 |
hrw | INFO:kolla.common.utils.vmtp: The user requested (constraint) prettytable===2.4.0 | 17:36 |
hrw | similar with watcher | 17:45 |
hrw | mnasiadka: we need to deprecate vmtp and watcher. both are not buildable in Yoga due to prettytable version conflicts | 17:55 |
opendevreview | Marcin Juszkiewicz proposed openstack/kolla master: switch source images to follow master branches https://review.opendev.org/c/openstack/kolla/+/820043 | 18:15 |
hrw | marked both as unbuildable | 18:15 |
*** amoralej is now known as amoralej|off | 18:37 | |
opendevreview | MargaritaShakhova proposed openstack/kolla-ansible master: Add ironic-inspector policy configuration https://review.opendev.org/c/openstack/kolla-ansible/+/820063 | 19:22 |
opendevreview | MargaritaShakhova proposed openstack/kolla-ansible master: Add ironic-inspector policy configuration https://review.opendev.org/c/openstack/kolla-ansible/+/820063 | 19:24 |
opendevreview | MargaritaShakhova proposed openstack/kolla-ansible master: Add ironic-inspector policy configuration https://review.opendev.org/c/openstack/kolla-ansible/+/820063 | 19:25 |
opendevreview | MargaritaShakhova proposed openstack/kolla-ansible master: Add ironic-inspector policy configuration https://review.opendev.org/c/openstack/kolla-ansible/+/820063 | 19:28 |
guesswhat | Guys? Anyone is running certbot{lego with DNS0! method ? Authenticate via TXT in DNS zone.. Seems that kolla use only HTTP01 method. | 20:05 |
guesswhat | *TLS for horizon | 20:12 |
frickler | experimental job confirms the failure for centos. maybe make that a periodic (weekly) job, too? https://904f7d6c49a5f1a28a62-cd221b105c4d18d37b6dac96e24d6617.ssl.cf2.rackcdn.com/820043/2/experimental/kolla-build-no-infra-wheels-centos8s-source/d5aa3ce/kolla/build/000_FAILED_nova-base.log | 21:02 |
frickler | guesswhat: I've tested lego with designate, but not within kolla yet | 21:03 |
guesswhat | frickler: and are you running some systemd timer service, or how are you automatically renewing expired certificates ? or did you use it only with designate to generate certificate for internal service in openstack ? | 21:12 |
guesswhat | guys? i can not enable freezer, i am getting {"msg": "'dict object' has no attribute 'domain_name'"} do i need to preset some domain in keystone ? thanks | 21:15 |
guesswhat | probably iam missing kolla_internal_fqdn and kolla_external_fqdn | 21:17 |
guesswhat | hmm ,seems that domain_name is renamed to user_domain_name ( https://github.com/openstack/kolla-ansible/blob/stable/xena/doc/source/user/multi-regions.rst#deployment-of-other-regions ), but freezer requires domain_name ... | 21:43 |
guesswhat | or https://github.com/openstack/kolla-ansible/blob/stable/xena/ansible/roles/freezer/templates/freezer.conf.j2#L19 | 21:45 |
opendevreview | Dr. Jens Harbott proposed openstack/kolla-ansible master: WIP: Update previous_release to Xena https://review.opendev.org/c/openstack/kolla-ansible/+/820074 | 21:49 |
guesswhat | https://stackoverflow.com/questions/65900315/how-to-configure-multi-region-deployment-in-openstack-kolla | 21:52 |
guesswhat | this line https://github.com/openstack/kolla-ansible/blob/stable/xena/ansible/roles/freezer/templates/freezer.conf.j2#L19 should be probably os_project_domain_name = {{ openstack_auth.project_domain_name }}, its not possible to install freezer ,,,,, | 22:03 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!