opendevreview | Merged openstack/kayobe master: CI: fix TLS job by freeing up memory https://review.opendev.org/c/openstack/kayobe/+/833159 | 01:34 |
---|---|---|
opendevreview | Merged openstack/kayobe master: CI: Move to pytest-testinfra https://review.opendev.org/c/openstack/kayobe/+/832225 | 01:34 |
opendevreview | Merged openstack/kayobe master: Bump MichaelRigart.interfaces to v1.13.1 https://review.opendev.org/c/openstack/kayobe/+/833007 | 01:34 |
opendevreview | Merged openstack/kayobe master: Only create patch links on overcloud hosts https://review.opendev.org/c/openstack/kayobe/+/833125 | 01:49 |
opendevreview | wangxiyuan proposed openstack/kolla-ansible master: [WIP]Add openEuler Distro support https://review.opendev.org/c/openstack/kolla-ansible/+/830115 | 02:09 |
opendevreview | wangxiyuan proposed openstack/kolla-ansible master: [WIP]Add openEuler Distro support https://review.opendev.org/c/openstack/kolla-ansible/+/830115 | 02:56 |
opendevreview | jinyuanliu proposed openstack/kolla master: venus: add log management system https://review.opendev.org/c/openstack/kolla/+/793795 | 03:09 |
opendevreview | jinyuanliu proposed openstack/kolla master: venus: add log management system https://review.opendev.org/c/openstack/kolla/+/793795 | 05:53 |
opendevreview | jinyuanliu proposed openstack/kolla master: venus: add log management system https://review.opendev.org/c/openstack/kolla/+/793795 | 06:04 |
opendevreview | Michal Nasiadka proposed openstack/kolla-ansible master: WIP: Run testssl.sh against HAProxy https://review.opendev.org/c/openstack/kolla-ansible/+/823499 | 07:18 |
opendevreview | Pierre Riteau proposed openstack/kayobe master: selinux: default to permissive https://review.opendev.org/c/openstack/kayobe/+/813661 | 09:58 |
opendevreview | Merged openstack/kolla-ansible stable/train: CI: Add more CentOS Stream 8 jobs https://review.opendev.org/c/openstack/kolla-ansible/+/832896 | 09:59 |
opendevreview | Pierre Riteau proposed openstack/kayobe master: Enable overcloud TLS job again https://review.opendev.org/c/openstack/kayobe/+/833977 | 10:00 |
opendevreview | Dr. Jens Harbott proposed openstack/kolla-ansible stable/xena: Add support for deploying Prometheus libvirt exporter https://review.opendev.org/c/openstack/kolla-ansible/+/831850 | 10:28 |
opendevreview | Pierre Riteau proposed openstack/kayobe master: Fix link formatting in release note https://review.opendev.org/c/openstack/kayobe/+/833985 | 10:43 |
opendevreview | Michal Nasiadka proposed openstack/kolla-ansible stable/xena: Add Rocky Linux support as Host OS https://review.opendev.org/c/openstack/kolla-ansible/+/833861 | 11:01 |
opendevreview | Michal Nasiadka proposed openstack/kolla-ansible stable/xena: Add Rocky Linux support as Host OS https://review.opendev.org/c/openstack/kolla-ansible/+/833861 | 11:03 |
opendevreview | Pierre Riteau proposed openstack/kayobe master: selinux: default to permissive https://review.opendev.org/c/openstack/kayobe/+/813661 | 11:12 |
jingvar | kayobe overcloud service upgrade - why it goes into venv/kolla-ansibe and tries update it ? | 11:25 |
jingvar | the doc - | 11:27 |
jingvar | Containerised control plane services may be upgraded by replacing existing containers with new con- | 11:27 |
jingvar | tainers using updated images | 11:28 |
jingvar | I don't see where is mentonied venvs | 11:28 |
opendevreview | Merged openstack/kayobe master: CI: Don't download Cirros or IPA in seed jobs https://review.opendev.org/c/openstack/kayobe/+/833759 | 11:41 |
opendevreview | Maksim Malchuk proposed openstack/kayobe master: Skip IP address allocation and configuration if needed https://review.opendev.org/c/openstack/kayobe/+/821129 | 11:49 |
mirek186 | Hi could someone help with deployment issue. The neutron playbook only including compute nodes but when running same invenotry but with --tags neutron it's correct | 12:01 |
opendevreview | Maksim Malchuk proposed openstack/kayobe master: Skip IP address allocation and configuration if needed https://review.opendev.org/c/openstack/kayobe/+/821129 | 12:01 |
mirek186 | TASK [neutron : include_tasks] * included: kolla_venv/share/kolla-ansible/ansible/roles/neutron/tasks/deploy.yml for 172.16.70.7, 172.16.70.8, 172.16.70.9 | 12:02 |
mirek186 | The above one is failing as it's only have compute nodes, but same inventory with --tags neutron is working as expected | 12:02 |
mirek186 | TASK [neutron : include_tasks] *kolla_venv/share/kolla-ansible/ansible/roles/neutron/tasks/deploy.yml for 172.16.70.4, 172.16.70.5, 172.16.70.6, 172.16.70.7, 172.16.70.8, 172.16.70.9 | 12:02 |
mirek186 | Is there anything in kolla-ansible deploy which will affect HOST groups during the deployment, looking at the playbooks it should just work and it used to work fine few weeks back | 12:04 |
frickler | mnasiadka: yoctozepto: ansible-lint=6.0 is causing failures on stable branches, too. do we want to backport https://review.opendev.org/c/openstack/kolla-ansible/+/833895 or cap ansible-lint<6 there? | 12:28 |
mnasiadka | I would rather cap ansible-lint | 12:29 |
mnasiadka | and then we can discuss moving to FQCNs, which probably is a good idea. | 12:29 |
frickler | mnasiadka: o.k., I'll prepare a patch. also added the topic to the PTG list | 12:30 |
mnasiadka | frickler: thanks | 12:30 |
opendevreview | Dr. Jens Harbott proposed openstack/kolla-ansible stable/xena: [stable-only] Cap ansible-lint for stable branches https://review.opendev.org/c/openstack/kolla-ansible/+/833996 | 12:34 |
opendevreview | Maksim Malchuk proposed openstack/kolla-ansible master: CI: fix warnings with new ansible-lint 6.0.0 https://review.opendev.org/c/openstack/kolla-ansible/+/833895 | 12:39 |
opendevreview | Maksim Malchuk proposed openstack/kolla-ansible master: CI: fix warnings with new ansible-lint 6.0.0 https://review.opendev.org/c/openstack/kolla-ansible/+/833895 | 12:41 |
opendevreview | Maksim Malchuk proposed openstack/kolla-ansible master: Fix maximum width of the DIB Multiline-YAML https://review.opendev.org/c/openstack/kolla-ansible/+/833633 | 12:42 |
opendevreview | Juan Pablo Suazo proposed openstack/kolla-ansible master: Support Prometheus as metrics database for Ceilometer. https://review.opendev.org/c/openstack/kolla-ansible/+/832651 | 12:48 |
imran | hello hello, me again trying to get more movement on my patchset https://review.opendev.org/c/openstack/kolla-ansible/+/824566 | 12:57 |
opendevreview | Michal Nasiadka proposed openstack/kolla-ansible master: CI: pin ansible-lint to <6 https://review.opendev.org/c/openstack/kolla-ansible/+/833895 | 12:58 |
opendevreview | Radosław Piliszek proposed openstack/kolla-ansible stable/xena: testing https://review.opendev.org/c/openstack/kolla-ansible/+/833167 | 13:03 |
opendevreview | Radosław Piliszek proposed openstack/kolla-ansible stable/xena: testing https://review.opendev.org/c/openstack/kolla-ansible/+/833167 | 13:03 |
opendevreview | Maksim Malchuk proposed openstack/kolla-ansible master: CI: pin ansible-lint to <6 https://review.opendev.org/c/openstack/kolla-ansible/+/833895 | 13:13 |
opendevreview | Michal Nasiadka proposed openstack/kolla-ansible master: CI: pin ansible-lint to <6 https://review.opendev.org/c/openstack/kolla-ansible/+/833895 | 13:13 |
jingvar | mirek186: some playbooks have unclear dependencies | 13:17 |
opendevreview | Maksim Malchuk proposed openstack/kolla-ansible master: Fix maximum width of the DIB Multiline-YAML https://review.opendev.org/c/openstack/kolla-ansible/+/833633 | 13:17 |
mirek186 | jingvar: any tips how to figure it out? | 13:21 |
mnasiadka | imran: just make the *-cephadm jobs green :) | 13:25 |
imran | mnasiadka: thanks! :) | 13:25 |
jingvar | for example some playbooks wants to collect a data from controlplane nodes | 13:28 |
opendevreview | Maksim Malchuk proposed openstack/kayobe master: Skip IP address allocation and configuration if needed https://review.opendev.org/c/openstack/kayobe/+/821129 | 13:29 |
jingvar | mirek186: I 'm not figure out exectly what you do. but common sollustion insert debug into venvs/palybooks and understand what goes worong | 13:29 |
opendevreview | Maksim Malchuk proposed openstack/kolla-ansible stable/xena: CI: pin ansible-lint to <6 https://review.opendev.org/c/openstack/kolla-ansible/+/833869 | 13:31 |
opendevreview | Maksim Malchuk proposed openstack/kolla-ansible stable/wallaby: CI: pin ansible-lint to <6 https://review.opendev.org/c/openstack/kolla-ansible/+/834010 | 13:32 |
opendevreview | Maksim Malchuk proposed openstack/kolla-ansible stable/victoria: CI: pin ansible-lint to <6 https://review.opendev.org/c/openstack/kolla-ansible/+/834011 | 13:32 |
opendevreview | Imran Hussain proposed openstack/kolla-ansible master: [external-ceph] Use template instead of copy https://review.opendev.org/c/openstack/kolla-ansible/+/824566 | 13:33 |
jingvar | guys, what is rigth sequence for adding a new service on working cloud? images are pulled | 13:34 |
yoctozepto | jingvar: enable it and rerun deploy | 13:38 |
opendevreview | Maksim Malchuk proposed openstack/kolla-ansible stable/xena: CI: pin ansible-lint to <6 https://review.opendev.org/c/openstack/kolla-ansible/+/833869 | 13:38 |
opendevreview | Maksim Malchuk proposed openstack/kolla-ansible stable/victoria: CI: pin ansible-lint to <6 https://review.opendev.org/c/openstack/kolla-ansible/+/834011 | 13:38 |
mirek186 | jingvar: thanks mate, that's what I'm trying to do at the moment. Is there a common way to find out why some hosts where not included in the task. Trying to google it but can't find a good answer, thinking of injecting a small task to list all groups just before neutron task to find out whether the task is aware of them or not | 13:39 |
opendevreview | Maksim Malchuk proposed openstack/kolla-ansible stable/wallaby: CI: pin ansible-lint to <6 https://review.opendev.org/c/openstack/kolla-ansible/+/834010 | 13:39 |
yoctozepto | mirek186: I would bet that the affected hosts simply failed earlier, in another play, and are now excluded | 13:39 |
yoctozepto | look more thoroughly at the logs | 13:39 |
jingvar | mirek186: I depends on how writen playbook, there can be something constructed from groups_by | 13:44 |
jingvar | yoctozepto: will it care about sequencial restartig containers? on a dev env I just run deploy, but now a want to simulate day2 | 13:46 |
opendevreview | Imran Hussain proposed openstack/kolla-ansible master: [external-ceph] Use template instead of copy https://review.opendev.org/c/openstack/kolla-ansible/+/824566 | 13:46 |
opendevreview | Pierre Riteau proposed openstack/kayobe master: selinux: default to permissive https://review.opendev.org/c/openstack/kayobe/+/813661 | 13:47 |
opendevreview | Merged openstack/kolla-ansible master: CI: pin ansible-lint to <6 https://review.opendev.org/c/openstack/kolla-ansible/+/833895 | 13:48 |
mirek186 | yoctozepto: I've attached deploy log, can't find anything, other then checking MariaDB ports which then been ignored, later network nodes are used in the playbook, so really stuck: https://zerobin.net/?cc110c34e3e7781a#x5lUBl6DrsZW7/amUU9/gWgfScHD2OrelJXKowIFiPQ= | 13:49 |
mirek186 | This one is for --tags neutron only and working as expected: https://zerobin.net/?56a99400e6f5b23e#2yMuqN5wp1mlujR1EM2RzCNDQ28GriBkmXOqGJ5S/vU= | 13:50 |
yoctozepto | mirek186: look at TASK [openvswitch : Ensuring OVS bridge is properly setup] ********************* | 13:52 |
yoctozepto | it killed off these 3 hosts from further plays | 13:52 |
yoctozepto | which broke the logic | 13:52 |
yoctozepto | jingvar: what do you mean? "deploy" is the one used day-2 as well | 13:57 |
jingvar | overcloud service deploy | 13:58 |
opendevreview | Radosław Piliszek proposed openstack/kolla-ansible master: [WIP] Ironic: Support both plain PXE and iPXE https://review.opendev.org/c/openstack/kolla-ansible/+/832159 | 13:59 |
jingvar | As I see , day2 kayobe overcloud service reconfigure | 13:59 |
yoctozepto | jingvar: it's practically an alias; we seem to be lazy and still did not kill off that confusing part :-) | 14:00 |
yoctozepto | whichever you use, it does the same thing | 14:00 |
mirek186 | yoctozepto: thanks mate, I tought external ovn bridge on needs to be on compute node, at least we had it this way when using Juju | 14:01 |
mirek186 | I'll dig into it | 14:01 |
opendevreview | Pierre Riteau proposed openstack/kayobe master: Run disable-selinux on seed-hypervisor https://review.opendev.org/c/openstack/kayobe/+/823418 | 14:02 |
jingvar | yoctozepto: I was believed in a magic | 14:02 |
opendevreview | Pierre Riteau proposed openstack/kayobe master: Run selinux playbook on seed hypervisor https://review.opendev.org/c/openstack/kayobe/+/823418 | 14:02 |
jingvar | thanks | 14:02 |
jingvar | juju - omg | 14:03 |
yoctozepto | mirek186: it's also required on network nodes | 14:03 |
opendevreview | Maksim Malchuk proposed openstack/kayobe master: Skip IP address allocation and configuration if needed https://review.opendev.org/c/openstack/kayobe/+/821129 | 14:11 |
opendevreview | Dr. Jens Harbott proposed openstack/kolla-ansible stable/xena: Add support for deploying Prometheus libvirt exporter https://review.opendev.org/c/openstack/kolla-ansible/+/831850 | 14:12 |
opendevreview | Radosław Piliszek proposed openstack/kolla-ansible master: [CI] Test Ironic upgrade https://review.opendev.org/c/openstack/kolla-ansible/+/834004 | 14:30 |
opendevreview | Radosław Piliszek proposed openstack/kolla-ansible master: [WIP] Ironic: Support both plain PXE and iPXE https://review.opendev.org/c/openstack/kolla-ansible/+/832159 | 14:34 |
opendevreview | Radosław Piliszek proposed openstack/kolla-ansible master: [WIP] Ironic: rename containers https://review.opendev.org/c/openstack/kolla-ansible/+/832134 | 14:38 |
opendevreview | Pierre Riteau proposed openstack/kayobe master: CI: Enable overcloud TLS job again https://review.opendev.org/c/openstack/kayobe/+/833977 | 14:40 |
opendevreview | Michal Nasiadka proposed openstack/kolla-ansible stable/ussuri: CI: pin ansible-lint to <6 https://review.opendev.org/c/openstack/kolla-ansible/+/834014 | 14:41 |
mirek186 | yoctozepto: I'm looking into openvswitch code and I think there is a bug in ovs_ensure_configured.sh https://github.com/openstack/kolla/blob/master/docker/openvswitch/openvswitch-db-server/ovs_ensure_configured.sh | 14:42 |
opendevreview | Radosław Piliszek proposed openstack/kolla-ansible stable/xena: testing https://review.opendev.org/c/openstack/kolla-ansible/+/833167 | 14:43 |
mirek186 | I'm not OVN expert but with my past experienice with Juju where they using Juju for few years, you only do external ports on your compute nodes, they go directly from VM-OVN-external port | 14:43 |
mirek186 | however, the code in the script does a check whether the interface exists first and if you run it on every openvsiwtch host which is both network and compute nodes it will fail | 14:44 |
yoctozepto | mirek186: well, then the bug is in kolla-ansible, not kolla anyhow, the script is called only when and where k-a wants it | 14:44 |
yoctozepto | mnasiadka knows OVN better, might say something more regarding why it's like it is | 14:45 |
yoctozepto | it could also be the case we are not flexible enough atm or whatever | 14:45 |
mnasiadka | If I understand correctly, the question is why we are configuring external bridge on the network nodes? | 14:46 |
mirek186 | mnasiadka: Well, yes | 14:46 |
mnasiadka | And how do you expect SNAT to be working? | 14:46 |
mirek186 | With OVN when you do external it's attached directly to external network at least I had it this way with Juju OpenStack | 14:47 |
mnasiadka | What do you mean by "when you do external"? | 14:47 |
mirek186 | not a overlay, physnet1 | 14:48 |
opendevreview | Radosław Piliszek proposed openstack/kolla master: venus: add log management system https://review.opendev.org/c/openstack/kolla/+/793795 | 14:48 |
mirek186 | my understading was with OVN it's simplified where you have port directly attached to VM on the compute node, it's not going on overlay at all | 14:49 |
mnasiadka | mirek186: you mean you are spawning instances directly using a vlan network called external? | 14:49 |
mirek186 | yes | 14:49 |
mnasiadka | it doesn't matter if it's ML2/OVN or ML2/OVS | 14:49 |
mnasiadka | it is simple, so what is the problem? | 14:49 |
mirek186 | the problem is the code in ovs_ensure_configured.sh | 14:50 |
mnasiadka | well, that is a script, I guess the problem rather is in kolla-ansible's usage of this script | 14:50 |
mirek186 | basiclliy it's run on every network and compute node and first bit of the code is checking whether the intrface exists on the host, where it dosne't have to exists on network nodes | 14:50 |
mnasiadka | Normally, people deploy an SDN to use overlay networks. We assume this is the case, and ensure required interfaces/bridges exist. | 14:51 |
mirek186 | I'm happy with that it was more to find out why, so I know how to address it, but my understading is correct, you don't need porvider ports on network nodes if they are only used by compute, am I right? At least it's a setup we have with Juju | 14:52 |
mnasiadka | If you want to use ONLY provider networks - then yes, bridges need to exist only on computes. | 14:53 |
opendevreview | Merged openstack/kolla-ansible stable/xena: CI: pin ansible-lint to <6 https://review.opendev.org/c/openstack/kolla-ansible/+/833869 | 14:54 |
mirek186 | we do have overlay ports on both network and compute. | 14:54 |
opendevreview | Michal Nasiadka proposed openstack/kolla-ansible master: WIP: Run testssl.sh against HAProxy https://review.opendev.org/c/openstack/kolla-ansible/+/823499 | 14:55 |
opendevreview | Merged openstack/kolla-ansible stable/wallaby: CI: pin ansible-lint to <6 https://review.opendev.org/c/openstack/kolla-ansible/+/834010 | 14:55 |
opendevreview | Merged openstack/kolla-ansible stable/victoria: CI: pin ansible-lint to <6 https://review.opendev.org/c/openstack/kolla-ansible/+/834011 | 14:55 |
mnasiadka | mgoddard mnasiadka hrw egonzalez yoctozepto rafaelweingartne cosmicsound osmanlicilegi bbezak parallax Fl1nt frickler adrian-a - meeting in 5 | 14:55 |
opendevreview | Radosław Piliszek proposed openstack/kolla-ansible master: [CI] Add Venus scenario https://review.opendev.org/c/openstack/kolla-ansible/+/823222 | 14:57 |
yoctozepto | mnasiadka, mirek186: ok, so I understand the issue is that kolla-ansible is not flexible enough (like I thought before) and does not offer a way to avoid non-provider (overlay) networks? | 14:59 |
mnasiadka | That's how I understand that issue - anyway meeting time | 15:00 |
mnasiadka | #startmeeting kolla | 15:00 |
opendevmeet | Meeting started Wed Mar 16 15:00:19 2022 UTC and is due to finish in 60 minutes. The chair is mnasiadka. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:00 |
opendevmeet | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:00 |
opendevmeet | The meeting name has been set to 'kolla' | 15:00 |
mnasiadka | #topic rollcall | 15:00 |
mnasiadka | o/ | 15:00 |
frickler | \o | 15:00 |
jinyuanliu_ | o\ | 15:00 |
yoctozepto | o/ | 15:01 |
mgoddard | \o | 15:03 |
mnasiadka | #topic agenda | 15:03 |
mnasiadka | * Announcements | 15:03 |
mnasiadka | * Review action items from the last meeting | 15:03 |
mnasiadka | * CI status | 15:03 |
mnasiadka | * Release tasks | 15:03 |
mnasiadka | * Current cycle planning | 15:03 |
mnasiadka | * Additional agenda (from whiteboard) | 15:03 |
mnasiadka | * Open discussion | 15:03 |
mnasiadka | #topic Announcements | 15:03 |
mnasiadka | I've proposed frickler to gain core reviewer privileges in both Kolla and Kolla-Ansible - please vote on the mailing list. | 15:04 |
mnasiadka | #topic Review action items from the last meeting | 15:04 |
mnasiadka | mnasiadka to triage security bugs and update them with resolution plan (if needed) | 15:04 |
mnasiadka | mnasiadka to update kolla review dashboard with kolla collection | 15:04 |
mnasiadka | hrw Enable osbpo in Debian APT sources, abandon extrepo command use then? | 15:04 |
mnasiadka | I updated the review dashboard | 15:04 |
mnasiadka | sec bugs in progress, I proposed a patch to use testssl.sh to validate haproxy ssl ciphers (one of the bugs mentions ssl ciphers) | 15:05 |
mnasiadka | needs some update, but should ensure this is covered a bit better than in past | 15:05 |
mnasiadka | hrw is not here, so let's reapply this action item | 15:05 |
mnasiadka | #action mnasiadka to triage security bugs and update them with resolution plan (if needed) | 15:06 |
mnasiadka | #action hrw Enable osbpo in Debian APT sources, abandon extrepo command use then? | 15:06 |
mnasiadka | #topic CI status | 15:06 |
mnasiadka | We've seen breakage from ansible-lint complaining on us not using FQCNs for core modules | 15:06 |
mnasiadka | it has been capped to <6 - it's fine now | 15:07 |
frickler | ubuntu-binary seems also broken | 15:07 |
frickler | some issue with trove-dashboard afaict | 15:07 |
frickler | https://storage.gra.cloud.ovh.net/v1/AUTH_dcaab5e32b234d56b626f72581e3644c/zuul_opendev_logs_de8/793897/33/check/kolla-ansible-ubuntu-binary/de8b1e3/primary/logs/kolla/horizon/horizon.txt | 15:07 |
yoctozepto | that's why we are dropping support for binary | 15:07 |
yoctozepto | well, one of the reasons | 15:07 |
frickler | but as of now we still should try to fix it? | 15:08 |
mnasiadka | I think i've seen something similar in the Magnum CI job (where we enable Trove I think) | 15:08 |
mnasiadka | frickler: at least we should raise a Launchpad bug in UCA | 15:08 |
mnasiadka | that's what we've done in the past | 15:08 |
yoctozepto | yeah, raise a bug in UCA | 15:09 |
frickler | ah, o.k., I can do that and ping some ubuntu-server ppl | 15:09 |
mnasiadka | but they're usually not the fastest, so it will drag around | 15:09 |
mnasiadka | and IIRC Trove doesn't have a PTL for Z | 15:09 |
yoctozepto | yes | 15:10 |
mnasiadka | So I don't know how long will it stay with us ;) | 15:10 |
mnasiadka | anyway, let's continue | 15:10 |
mnasiadka | #topic Release tasks | 15:10 |
mgoddard | wuchunyang stepped up for trove PTL | 15:11 |
yoctozepto | oh, good to know, I missed that | 15:11 |
yoctozepto | so it's only adjutant going away | 15:12 |
mnasiadka | anyway it would be good to understand if we don't hit that in source as well - I've seen trove being enabled in magnum jobs | 15:12 |
yoctozepto | thankfully, we did not merge its support | 15:12 |
mnasiadka | Kolla feature freeze: Mar 21 - Mar 25 | 15:12 |
wuchunyang | yes, we will maintain trove in z | 15:12 |
mnasiadka | It's next week | 15:12 |
mnasiadka | #topic Current cycle planning | 15:13 |
mnasiadka | So, what is possibly going to get merged? | 15:13 |
yoctozepto | mnasiadka: we always have all horizon plugins around so it would break source already, no? | 15:13 |
yoctozepto | mnasiadka: I've reviewed venus | 15:13 |
yoctozepto | i've also added it to the other topics for today | 15:14 |
wuchunyang | venus +2 from me | 15:14 |
yoctozepto | feel free to skip then | 15:14 |
mnasiadka | yoctozepto: True, we only enable plugins per project I think, but who knows what fails | 15:14 |
mnasiadka | ok | 15:14 |
mnasiadka | so - what about - Systemd containers: https://review.opendev.org/c/openstack/kolla-ansible/+/816724 | 15:14 |
mnasiadka | mgoddard, yoctozepto: you've been actively reviewing, right? | 15:14 |
mgoddard | I haven't looked recently | 15:14 |
yoctozepto | me neither | 15:15 |
mnasiadka | Ok, would be nice to get this in though, right? | 15:15 |
yoctozepto | right | 15:15 |
yoctozepto | and my ironic patches | 15:16 |
yoctozepto | :-) | 15:16 |
mnasiadka | we'll get to that (if those are listed on the whiteboard) :) | 15:16 |
mnasiadka | kolla collection long list of patches - yoctozepto you promised to review two, haven't done that :D | 15:17 |
mnasiadka | https://review.opendev.org/c/openstack/ansible-collection-kolla/+/821015 | 15:17 |
mnasiadka | https://review.opendev.org/c/openstack/ansible-collection-kolla/+/821016 | 15:17 |
mnasiadka | and there are like 5 more on the list | 15:17 |
mnasiadka | L433 on the whiteboard | 15:17 |
yoctozepto | mnasiadka: oh noez, so many things to do | 15:17 |
mnasiadka | need reviewers, if not - it's not going to get in | 15:18 |
mnasiadka | maybe there are some other cores happy to assist? | 15:18 |
mnasiadka | anyway, let's move on - libvirt on host the same - I'll do reviews and need a second core | 15:19 |
opendevreview | Will Szumski proposed openstack/kolla-ansible master: Adds keystone_authtoken.service_type https://review.opendev.org/c/openstack/kolla-ansible/+/834035 | 15:19 |
mnasiadka | and magically Ironic appeared on the whiteboard! | 15:19 |
mgoddard | I think kevko approved libvirt on the host | 15:19 |
mnasiadka | but not the kolla collection patch | 15:19 |
yoctozepto | mnasiadka: yup, it's magix | 15:19 |
mgoddard | true | 15:20 |
mnasiadka | ok, let's review Radek's Ironic patches, and he'll be happy to review all the rest! ;-) | 15:21 |
mnasiadka | Kayobe seems we have a lot of patches that need updates | 15:22 |
mnasiadka | probably the multiple environments part 2 won't be merged in Yoga | 15:22 |
priteau | :( | 15:22 |
mnasiadka | Haven't seen updates on those patches, and there's a lot to improve judging by mgoddard's comments | 15:23 |
priteau | Will was planning to update but he's been busy | 15:23 |
mnasiadka | As we all are unfortunately | 15:24 |
mnasiadka | Let's go through additional agenda | 15:24 |
mnasiadka | #topic Additional agenda (from whiteboard) | 15:24 |
mnasiadka | (yoctozepto) Venus | 15:24 |
mnasiadka | So what's up with Venus? | 15:25 |
yoctozepto | mnasiadka: already discussed, move on | 15:26 |
mnasiadka | ok | 15:27 |
mnasiadka | If we're at Venus - what's up with skyline? | 15:27 |
yoctozepto | I did not have time / it was less active/ready? | 15:27 |
yoctozepto | let's check | 15:27 |
wuchunyang | i can try to add a ci for skyline. | 15:27 |
wuchunyang | follow by venus. | 15:27 |
yoctozepto | wuchunyang: that would be appreciated | 15:28 |
wuchunyang | https://review.opendev.org/c/openstack/kolla-ansible/+/828464 | 15:28 |
yoctozepto | (fwiw, I'm reviewing various changes atm) | 15:29 |
mnasiadka | wuchunyang: the Kolla part has some comments, like why it's not using upper-constraints, I see Skyline would need more work than Venus to get in | 15:29 |
opendevreview | Pierre Riteau proposed openstack/kayobe master: Use naming convention to infer VLAN tagging https://review.opendev.org/c/openstack/kayobe/+/833052 | 15:30 |
mnasiadka | Ok, let's keep reviewing - hope the authors will update | 15:30 |
wuchunyang | yes, skyline need more work. | 15:31 |
mnasiadka | Next additional topic is (mgoddard): Libvirt SASL issues | 15:31 |
mgoddard | I had some issues today when rolling out the libvirt SASL change | 15:31 |
mgoddard | I'm still not really sure exactly what happened, but wanted to bring it up | 15:32 |
mgoddard | Possibly there is a window when enabling SASL where it breaks the connection from nova-compute to libvirt | 15:32 |
mgoddard | and some instances get broken | 15:33 |
mnasiadka | oops | 15:33 |
yoctozepto | oh my | 15:33 |
yoctozepto | how broken are we talking about? | 15:33 |
yoctozepto | data loss? | 15:33 |
mnasiadka | or just powered off / wrong state in Nova? | 15:33 |
mgoddard | libvirt VM stopped | 15:34 |
mgoddard | I managed to get it running again with an openstack server stop, openstack server start | 15:35 |
yoctozepto | hmm | 15:35 |
mgoddard | but it took me a while to figure it out | 15:35 |
yoctozepto | I don't see how it would stop the instance by itself | 15:35 |
yoctozepto | maybe it was on user req? | 15:35 |
yoctozepto | but the sync back did not happen | 15:35 |
yoctozepto | I'm not entirely sure when nova compute updates its state | 15:35 |
mnasiadka | when backporting the libvirt sasl patch - did we enable sasl by default? | 15:36 |
mgoddard | yes | 15:36 |
mnasiadka | so basically this can now happen to anyone? | 15:36 |
yoctozepto | yes | 15:37 |
mgoddard | potentially, but haven't reproduced it | 15:37 |
mnasiadka | interesting | 15:37 |
mgoddard | if my theory is correct, we could stop nova-compute first, then restart nova-libvirt, then start nova-compute | 15:38 |
mgoddard | that would be a simple fix to backport | 15:38 |
mgoddard | but really I'd like to reproduce it to be confident | 15:38 |
yoctozepto | ++ | 15:39 |
mnasiadka | Sure, we'll be waiting for updates mgoddard | 15:39 |
mgoddard | ok | 15:40 |
mnasiadka | #topic Open discussion | 15:42 |
choooze | Hello guys. Wanna ask your advice about separating LB for several groups. My colleague tried to do some [https://review.opendev.org/c/openstack/kolla-ansible/+/833535]. But for now we can't decide which way to choose, simple one (just a small patch to separate ELK's LB (what we want to achieve for now)) or hard one (provide some way to have an option for several LB groups with service groups mapping to them). Thanks in advance for | 15:42 |
mnasiadka | mgoddard: seems you've been giving your thoughts on this one ^^ | 15:43 |
mgoddard | yes | 15:44 |
mgoddard | the generic solution would be to have some flag per service | 15:44 |
choooze | yup sounds reasonable | 15:45 |
mgoddard | elasticsearch_enable_loadbalancer | 15:45 |
mgoddard | then incorporate that into elasticsearch_services.elasticsearch.haproxy | 15:45 |
yoctozepto | but loadbalancer might not be on the same nodes as these services | 15:45 |
yoctozepto | and it's fine | 15:45 |
yoctozepto | it's even on network nodes, not control nodes | 15:46 |
mgoddard | yes, that was my comment | 15:46 |
jingvar | what about hostgroup_vip | 15:46 |
choooze | but in that case VIP will be attached to host_group? | 15:46 |
mgoddard | the VIP is associated with haproxy hosts | 15:46 |
jingvar | yep | 15:47 |
yoctozepto | i.e., we have one loadbalancer solution | 15:47 |
yoctozepto | that is HA | 15:47 |
yoctozepto | and shuffles VIP to ensure that HA | 15:47 |
jingvar | to separete newtwork flow | 15:47 |
mgoddard | if you have your own LB for elastic, you'd need to set elasticsearch_enable_loadbalancer=false and elasticsearch_internal_endpoint to point to your LB | 15:47 |
yoctozepto | the proxied services might exists anywhere | 15:47 |
jingvar | I have monitoring_vip and a several services on this group | 15:48 |
mgoddard | or perhaps you could just set elasticsearch_address | 15:48 |
jingvar | I did | 15:48 |
choooze | so the way where there might be more than 1 LB in HA placed on control nodes isn't the way you want to see? :] | 15:49 |
jingvar | why we cant have itsown loadbalancer on group | 15:49 |
mgoddard | oh, so you want kolla to deploy multiple LBs? | 15:50 |
jingvar | I had Virtual contrail Plane at least 9 nodes with | 15:50 |
jingvar | yes | 15:50 |
jingvar | I have it already | 15:50 |
choooze | to have that possibility | 15:50 |
yoctozepto | what do you use multiple LBs for? only es? | 15:51 |
wuchunyang | we have the same scenario. i use kolla to deploy two lbs, but es exists in both them. | 15:51 |
jingvar | as first run | 15:51 |
choooze | by default okay. everything is going thorugh control-nodes. by for some cases it might be unnecessary and should be avoidable. like ELK-case | 15:51 |
yoctozepto | choooze: it goes through network nodes | 15:52 |
yoctozepto | you can have a separate network node from control nodes | 15:52 |
yoctozepto | (or multiple for that matter) | 15:52 |
choooze | anyway I hope you've got the point :] | 15:52 |
yoctozepto | so-so I'd say | 15:54 |
yoctozepto | to me it makes sense to have a separate loadbalancer for elk | 15:54 |
yoctozepto | well, more like efk | 15:54 |
jingvar | there are core components of Openstack and additional services - And I want' mix traffic | 15:54 |
mnasiadka | But that means, you'd want to have a second instance of keepalived and haproxy - and possibly on a different set of physical hosts? | 15:55 |
choooze | yup | 15:56 |
jingvar | 2 strings into haproxyconfig.j2 :0 | 15:56 |
mnasiadka | Well, sounds like a nice feature, that we could discuss over PTG for the Z cycle. | 15:56 |
yoctozepto | ++ | 15:57 |
choooze | Nice guys! | 15:58 |
mgoddard | sounds similar to the multiple mariadb feature, which was quite fiddly to get right | 15:58 |
choooze | We could help somehow if you'll show the right way :] | 15:58 |
mnasiadka | Sure, please add a topic on the bottom of Zed etherpad - https://etherpad.opendev.org/p/kolla-zed-ptg | 15:59 |
mnasiadka | and of course show up for the discussion :) | 15:59 |
mgoddard | Update on the libvirt SASL issue discussed earlier: I think this was actually caused by some previous failed evacuations. nova-compute restart caused them to get cleaned up, which destroyed the instances | 15:59 |
opendevreview | Imran Hussain proposed openstack/kolla-ansible master: [external-ceph] Use template instead of copy https://review.opendev.org/c/openstack/kolla-ansible/+/824566 | 16:00 |
choooze | mnasiadka next Wed you mean? or some other time? | 16:00 |
mnasiadka | mgoddard: should we make an update in the reno - that this might cause unplanned instance downtime? | 16:00 |
mgoddard | mnasiadka: no, it was unrelated to libvirt SASL AFAICT | 16:01 |
mgoddard | I will keep investigating | 16:01 |
mnasiadka | choooze: PTG (Project Teams Gathering) is 4-6 April (Kolla-Ansible topics 4-5 April) | 16:01 |
yoctozepto | thanks | 16:01 |
choooze | okaaaay sounds nice | 16:01 |
choooze | thank you guys! | 16:02 |
mnasiadka | choooze: I added an Eventbrite link for the event, make sure you order a virtual ticket ;-) | 16:03 |
mnasiadka | ok, we're over time. | 16:03 |
mnasiadka | Thanks for coming! | 16:03 |
mnasiadka | #endmeeting | 16:03 |
opendevmeet | Meeting ended Wed Mar 16 16:03:30 2022 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 16:03 |
opendevmeet | Minutes: https://meetings.opendev.org/meetings/kolla/2022/kolla.2022-03-16-15.00.html | 16:03 |
opendevmeet | Minutes (text): https://meetings.opendev.org/meetings/kolla/2022/kolla.2022-03-16-15.00.txt | 16:03 |
opendevmeet | Log: https://meetings.opendev.org/meetings/kolla/2022/kolla.2022-03-16-15.00.log.html | 16:03 |
opendevreview | Radosław Piliszek proposed openstack/ansible-collection-kolla master: baremetal: Add support for git http/https proxy setup https://review.opendev.org/c/openstack/ansible-collection-kolla/+/832770 | 16:03 |
yoctozepto | thanks mnasiadka for chairing | 16:04 |
frickler | I don't understand why people want to give their data to eventbrite, with the virtual ptg I see no reason to do so | 16:10 |
frickler | also, if people like the ptg being virtual, you should tell the foundation. they seem to be planning for the AA ptg to be in person again or hybrid | 16:10 |
mnasiadka | I don't mind having a physical PTG, but that's rather a collective decision for the project members, not the foundation decision :) | 16:11 |
mnasiadka | Anyway, need to run. | 16:11 |
hrw | mnasiadka: enabling osbpo was voted against. we stay with extrepo. | 16:12 |
frickler | well the foundation sets up the whole event, we as a team could of course decide to do something different, like have sessions outside the allocated times in order to reduce overlap for multi-project people like me | 16:12 |
hrw | frickler: Since I joined Kolla (iirc 4y ago) I was on one physical PTG. | 16:17 |
hrw | not everyone has company behind paying €€€ for flights and hotel | 16:18 |
hrw | Dublin one was ~1500 EUR. And flights were just inside of EU... | 16:20 |
hrw | 100$ for registration, 200€ for flights, 930€ for conference hotel + other travel/food/etc. costs | 16:21 |
frickler | hrw: I'm 100% for doing virtual-only PTGs and summits, I just feel quite alone in voicing that opinion | 16:24 |
hrw | frickler: I would like to meet other kollas. Just do not sure is everyone capable of covering the costs. | 16:25 |
hrw | I had luck of meeting several in Dublin and then mnasiadka and yoctozepto here in Poland at some events. | 16:26 |
frickler | cost is one thing, CO2 emissions the next, C19 another | 16:26 |
frickler | and people may have yet other issues limiting their ability to travel | 16:27 |
opendevreview | Radosław Piliszek proposed openstack/kolla-ansible master: [CI] Test Ironic upgrade https://review.opendev.org/c/openstack/kolla-ansible/+/834004 | 16:29 |
frickler | I found this bug for trove-dashboard, but not sure if it is the same as ours, as it should affect source builds, too https://bugs.launchpad.net/trove-dashboard/+bug/1965028 | 16:29 |
frickler | hmm, seems we install it only in binary? | 16:33 |
yoctozepto | frickler: possibly because of UCA dependency chain | 16:42 |
yoctozepto | but we do have horizon-plugin-trove-dashboard in source | 16:43 |
yoctozepto | possibly we disable the init properly in source case | 16:43 |
yoctozepto | and not binary case | 16:43 |
* yoctozepto just throwing random ideas | 16:43 | |
* yoctozepto off | 16:46 | |
opendevreview | Mark Goddard proposed openstack/kayobe stable/xena: CI: Don't download Cirros or IPA in seed jobs https://review.opendev.org/c/openstack/kayobe/+/834018 | 17:01 |
opendevreview | Mark Goddard proposed openstack/kayobe stable/wallaby: CI: Don't download Cirros or IPA in seed jobs https://review.opendev.org/c/openstack/kayobe/+/834019 | 17:01 |
opendevreview | Mark Goddard proposed openstack/kayobe stable/victoria: CI: Don't download Cirros or IPA in seed jobs https://review.opendev.org/c/openstack/kayobe/+/834020 | 17:01 |
opendevreview | Mark Goddard proposed openstack/kayobe stable/victoria: CI: Don't download Cirros or IPA in seed jobs https://review.opendev.org/c/openstack/kayobe/+/834020 | 17:02 |
opendevreview | Mark Goddard proposed openstack/kolla master: Add enabled flag for sources https://review.opendev.org/c/openstack/kolla/+/833644 | 17:07 |
opendevreview | Merged openstack/kolla-ansible master: Adds etcd endpoints as a Prometheus scrape target https://review.opendev.org/c/openstack/kolla-ansible/+/831848 | 17:55 |
opendevreview | Will Szumski proposed openstack/kolla-ansible master: Adds keystone_authtoken.service_type https://review.opendev.org/c/openstack/kolla-ansible/+/834035 | 18:06 |
opendevreview | Merged openstack/kayobe master: CI: Enable overcloud TLS job again https://review.opendev.org/c/openstack/kayobe/+/833977 | 18:46 |
opendevreview | Merged openstack/kayobe master: Fix link formatting in release note https://review.opendev.org/c/openstack/kayobe/+/833985 | 18:46 |
opendevreview | Radosław Piliszek proposed openstack/kolla-ansible master: [CI] Test Ironic upgrade https://review.opendev.org/c/openstack/kolla-ansible/+/834004 | 20:09 |
opendevreview | Radosław Piliszek proposed openstack/kolla-ansible master: [CI] Test Ironic upgrade https://review.opendev.org/c/openstack/kolla-ansible/+/834004 | 20:11 |
opendevreview | Radosław Piliszek proposed openstack/ansible-collection-kolla master: [CI] pin ansible-lint to <6 https://review.opendev.org/c/openstack/ansible-collection-kolla/+/834069 | 20:16 |
opendevreview | Radosław Piliszek proposed openstack/ansible-collection-kolla master: baremetal: Add support for git http/https proxy setup https://review.opendev.org/c/openstack/ansible-collection-kolla/+/832770 | 20:16 |
opendevreview | Pierre Riteau proposed openstack/kayobe stable/victoria: Build CentOS stream images https://review.opendev.org/c/openstack/kayobe/+/834078 | 22:08 |
Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!