Wednesday, 2023-07-26

opendevreviewPiotr Parczewski proposed openstack/kayobe master: Fix CentOS / Rocky route options  https://review.opendev.org/c/openstack/kayobe/+/88968008:30
opendevreviewMichal Arbet proposed openstack/kolla-ansible master: [CI] Add skyline scenario  https://review.opendev.org/c/openstack/kolla-ansible/+/86168708:36
opendevreviewMerged openstack/kolla master: Fix dockerhub secret name  https://review.opendev.org/c/openstack/kolla/+/88948208:40
basileus@guesswhat Hi, I come back, after figuring out some issues, it seemed like my iptables rules were wrong, ended up doing some postrouting on the neutron interface for the external network, now I can ping my VMs, however they can't seem to access internet, is there additional routing commands that should be done? 12:13
basileusFigured it out, ended doing the routing rules on the wrong itnerface, everything seems to work now !12:18
opendevreviewVerification of a change to openstack/kolla-ansible master failed: Set HAProxy server timeout for openstack exporter  https://review.opendev.org/c/openstack/kolla-ansible/+/87271812:19
mnasiadkafrickler: I don't think a lot of people are using dockerhub, we changed the defaults long time ago - didn't we?12:23
fricklermnasiadka: I'm fine with dropping the jobs instead and removing old images, but running failing jobs every week seems wrong12:39
mnasiadkafrickler: let's discuss that on the meeting today12:39
mnasiadkamgoddard mnasiadka hrw  bbezak frickler kevko SvenKieske mmalchuk gkoper - meeting in 912:51
mnasiadka#startmeeting kolla13:00
opendevmeetMeeting started Wed Jul 26 13:00:01 2023 UTC and is due to finish in 60 minutes.  The chair is mnasiadka. Information about MeetBot at http://wiki.debian.org/MeetBot.13:00
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.13:00
opendevmeetThe meeting name has been set to 'kolla'13:00
mnasiadka#topic rollcall13:00
mnasiadkao/13:00
kevko\o/13:00
mmalchuk\o13:00
mgoddard\o13:00
bbezako/13:00
mhinero/13:00
ihalomi\o13:01
mattcreeso/13:01
frickler\o/13:01
mnasiadka#topic agenda13:02
mnasiadka* Review action items from the last meeting13:02
mnasiadka* CI status13:02
mnasiadka* Release tasks13:02
mnasiadka* Regular stable releases (first meeting in a month)13:02
mnasiadka* Current cycle planning13:02
mnasiadka* Additional agenda (from whiteboard)13:02
mnasiadka* Open discussion13:02
mnasiadkawell, not action items from last meeting13:03
mnasiadka#topic CI status13:03
mnasiadkaI've been off for the last three weeks - whiteboard says Kolla xena/wallaby is RED13:03
mnasiadkawallaby is heading for EOL so probably not an issue13:04
bbezakwallaby EOL 13:04
bbezakyeap13:04
mnasiadkawe also agreed for xena to be EOL, but maybe let's first wait for wallaby to be marked EOL13:04
mmalchukoutdated info for xena? needs check13:04
mnasiadkaall the rest of the whiteboard says CI is green otherwise13:04
mnasiadkawould be nice if the person marking something as RED would write why ;-)13:04
mnasiadka#topic Release tasks13:05
mnasiadkait's R-1013:05
mnasiadkanothing to do13:06
mnasiadka#topic Current cycle planning13:06
mnasiadkalet's check status of some features13:06
mnasiadkaihalomi: Podman?13:06
kevkoi've approved https://review.opendev.org/c/openstack/kolla/+/888335 without second +2 because of gate blocker ...13:06
kevkoso maybe xena red to xena green ? 13:07
ihalomimnasiadka: working only one test failing for unknown reasons13:07
mnasiadkaI assume the rocky9 one13:07
kevkoihalomi link ? 13:07
mnasiadkahttps://storage.bhs.cloud.ovh.net/v1/AUTH_dcaab5e32b234d56b626f72581e3644c/zuul_opendev_logs_bfc/799229/77/check/kolla-ansible-rocky9-podman/bfc1625/primary/logs/ansible/deploy-prechecks13:07
ihalomii think the problem is in image since it was working and started failing without change 13:07
ihalomihttps://zuul.opendev.org/t/openstack/build/bfc1625b4e0f4788be21f3bf5454ba4d13:07
mnasiadkawell, maybe it's some newer podman version13:08
mnasiadkado we need to pin to older or something similar?13:08
ihalomiidk i couldnt build that image on my own so i dont know the reason of failure but podman-py should be frozen not sure about podman 13:10
mnasiadkabbezak: probably we should spawn some test environment to help ihalomi 13:10
mnasiadkaok, I'll have a look into that next week13:11
bbezakmakes sense mnasiadka13:11
mnasiadkaok then13:13
mnasiadkakevko: you did have a look in Let's Encrypt patches, right?13:13
mnasiadkamattcrees: how is the "changing default to RMQ HA mode" going?13:14
kevkomnasiadka: yep, rewritten a lot ...but for now it is HA and working like a charm ...13:15
mnasiadkakevko: nice, then now we need some reviewers13:15
kevkoi can review it :D 13:15
mnasiadkaanyone signing up for reviewing Let's Encrypt patch?13:15
mattcreesRMQ patch still needs more work to automate out the manual steps. I'm working on it, but slowly as other things have taken priority 13:15
mnasiadkakevko: if you rewrote a lot - then probably add yourself as a co-author :)13:16
opendevreviewMichal Nasiadka proposed openstack/kayobe master: Fix firewalld configuration for monitoring hosts  https://review.opendev.org/c/openstack/kayobe/+/88326313:17
mnasiadkaok then, no reviewers, will try to chase some people :)13:17
mmalchukI'm back from vacation and ready to review)13:18
mnasiadkaok, let's move on13:19
mnasiadka#topic Additional agenda (from whiteboard)13:19
mnasiadkafailing podman test - this has been raised in previous topic13:19
mnasiadkafrickler - octavia jobboard13:19
mnasiadka#link https://review.opendev.org/c/openstack/kolla/+/88858713:19
mnasiadka#link https://review.opendev.org/c/openstack/kolla-ansible/+/88858813:19
mnasiadkafrickler: I asked a question in the first patch, although it's merged ;-)13:20
fricklerkevko already reviewed, need to update the second one13:20
fricklermnasiadka: this is not a new feature, but not sure whether we'd want to backport, either13:21
mnasiadkaok, so let's not backport for now, unless somebody really needs that13:22
mnasiadkareviewed the k-a one13:23
mnasiadkaok then13:25
fricklerthx, will check those things with christian13:25
mnasiadka#topic Open discussion13:25
mnasiadkaAnybody?13:25
fricklerwhat I missed to add to the agenda is bookworm13:25
mnasiadkaI think hrw is not here, and probably he knows latest status13:27
frickler#link https://review.opendev.org/c/openstack/kolla/+/88608813:27
opendevreviewMichal Nasiadka proposed openstack/kolla master: rabbitmq: bump version to 3.12  https://review.opendev.org/c/openstack/kolla/+/88722513:27
fricklerI added some fixes in k-a and now it seems to work in CI at least13:27
mnasiadkanice13:27
mnasiadkashould we bump rmq now?13:27
fricklerwhat version of 3.12.x is this now?13:28
kevkowhy in bookworm erlang is installed from debian and not from ppa ? 13:29
kevkodoesn't exist for bookworm ? 13:29
fricklerit didn't exist when the patch was created at least13:29
frickleralso the version in debian looked recent enough13:29
mnasiadkafrickler: 3.12.213:29
frickler3.12.2 sounds ok-ish13:30
mnasiadkathere are still some months before the release13:32
mnasiadkaUpgrading to Erlang 26 and RabbitMQ 3.12 at the Same Time13:32
mnasiadkaWhen upgrading from 3.11.x on Erlang 25 to 3.12.x on Erlang 26,13:32
mnasiadkathe cluster must be on at least version 3.11.17 for a safe upgrade of quorum queues.13:32
mnasiadkain theory we don't do quorum queues yet, but there might be users with such13:33
mnasiadkashould we put in a precheck?13:33
frickleryes13:33
mattcreesA precheck for tht sounds good, yes13:33
mnasiadkaOk, I'll work on it (and updating the feature flags)13:34
mnasiadkaAnd need to have a look in Ansible bump (so we don't start running and screaming just before the release because something stops working)13:35
mnasiadkaUnless anyone has anything else - I'll end the meeting for today13:35
kevkoi would like to just again ask anyone to review letsencrypt as for now i have a time to rework 13:36
mnasiadkaI'll try to find somebody from SHPC, we need that feature as well.13:37
kevkothanks 13:37
mmalchukkevko please repeat links13:37
kevkoand i  have one question regarding CADF13:37
mnasiadka(and will have a look in the code, but we also need some testing on a real env)13:37
kevkoi have master deployed with lets encrypt if anyone wants to connect i can put ssh key there13:38
mnasiadkaI'll remember that ;-)13:38
mnasiadkakevko: what about CADF? Keystone CADF?13:39
mmalchukkevko I can help next week if it is not too late13:39
kevkowe are using this in our downstream repositories 13:39
kevkohttps://docs.openstack.org/keystonemiddleware/pike/audit.html13:39
kevkowhat is needed is  add https://github.com/sapcc/openstack-audit-middleware to openstack images 13:40
kevkoand amend kolla-ansible to support custom api-paste files 13:40
fricklerwe use that middleware, too, so +1 to adding it13:41
mnasiadkasure, makes sense to make lifes easier13:42
mnasiadka(we don't use that, but who knows what future brings) ;)13:42
kevkoso i will prepare patches and i will ask you for review then ...13:42
kevkowell, we are not using it for all customers ...but for some yes ...13:42
mnasiadkagreat, nice addition13:46
mnasiadkaok, I guess it's enough for today13:46
mnasiadkathanks for coming!13:47
mnasiadka#endmeeting13:47
opendevmeetMeeting ended Wed Jul 26 13:47:02 2023 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)13:47
opendevmeetMinutes:        https://meetings.opendev.org/meetings/kolla/2023/kolla.2023-07-26-13.00.html13:47
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/kolla/2023/kolla.2023-07-26-13.00.txt13:47
opendevmeetLog:            https://meetings.opendev.org/meetings/kolla/2023/kolla.2023-07-26-13.00.log.html13:47
mmalchukthanks mnasiadka 13:47
kevkommalchuk: https://review.opendev.org/c/openstack/kolla-ansible/+/74134013:47
mmalchukoh thanks13:48
mmalchukmerge conflict13:48
kevkoyeah, see13:48
mmalchukfix and I'll look it later13:48
mmalchukI'm in reviewers 13:49
kevkolet me rebase13:49
opendevreviewMichal Arbet proposed openstack/kolla-ansible master: Add support for LetsEncrypt-managed certs  https://review.opendev.org/c/openstack/kolla-ansible/+/74134014:00
fricklerkevko: fwiw see https://review.opendev.org/c/openstack/kolla/+/349006 and https://review.opendev.org/c/openstack/kolla-ansible/+/711086 regarding cadf. seems that it didn't get much traction earlier14:09
kevkofrickler: well, we can propose universal patches ... 1. kolla - include sappc openstack audit middleware into openstack-base image  , 2 . Allow override of api-paste files 14:13
kevkoother stuff can be still done via config overries 14:13
mnasiadkawould be nice to include some minimal docs14:49
hrwmnasiadka: I sent patches for bookworm and did nothing with them since then14:49
hrwmnasiadka: so check how CI goes and decide14:50
mnasiadkahrw: if it's moving forward that's good14:52
opendevreviewMichal Nasiadka proposed openstack/kolla master: mariadb: Add log for mariadb-upgrade  https://review.opendev.org/c/openstack/kolla/+/88972515:20
-opendevstatus- NOTICE: The Gerrit service on review.opendev.org will be offline briefly for a minor upgrade at 21:00 utc, approximately an hour from now20:03
opendevreviewMichal Arbet proposed openstack/kolla-ansible master: Add support for LetsEncrypt-managed certs  https://review.opendev.org/c/openstack/kolla-ansible/+/74134020:37
-opendevstatus- NOTICE: The Gerrit service on review.opendev.org will be offline briefly for a minor upgrade, but should return shortly21:01
opendevreviewGerman Espinoza Tuesta proposed openstack/kolla-ansible master: Horizon: restrict access to Apache's server-status endpoint.  https://review.opendev.org/c/openstack/kolla-ansible/+/88978423:53

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!