Tuesday, 2024-08-20

fricklercloudflare does seem to have configured the openstack.org zone on their nameservers, but the switch of the delegation from .org is still pending?08:53
fricklerI also notice that the TTL for e.g. the CNAME record for docs.openstack.org has been reduced from 3600 to 300? I'm hoping that that would only the for the transition?08:54
frickleralso "curl https://openstack.org --resolve openstack.org:443:172.66.43.113" (one of the IPs in cloudflare DNS) results in "cert expired" :-/09:00
fricklerchecking the openmetal LE issue, it seems they changed the email to be used from "infra-root@openstack.org" to something @openmetal.io, which explains why the former is getting a warning now10:49
fricklersadly the new acc isn't working either, the logs repeats "Account xxx@openmetal.io is not registered. Use 'run' to register a new account."10:50
fricklerbut looks to me like something the openmetal team should look at, not sure whether just sending a mail or opening a ticket via their portal would be better10:51
frickler.oO(if only every cloud would be doing support via IRC *sigh*)10:52
opendevreviewBenjamin Schanzel proposed zuul/zuul-jobs master: Add build-diskimage role  https://review.opendev.org/c/zuul/zuul-jobs/+/92291111:09
opendevreviewBenjamin Schanzel proposed zuul/zuul-jobs master: Add build_diskimage_environment role variable  https://review.opendev.org/c/zuul/zuul-jobs/+/92622411:09
opendevreviewBenjamin Schanzel proposed zuul/zuul-jobs master: Add a diskimage-builder job  https://review.opendev.org/c/zuul/zuul-jobs/+/92622511:09
fungifrickler: apparently the domain registrar used by the openinfra foundation doesn't have any automated way to change ns delegation, the process is that one of the executive staff e-mails the support address of the registrar with the requested change and then waits for it to be processe12:28
fungid12:28
fungicscglobal.com parties like it's 199912:29
fricklerwelcome to the real world ;)12:31
fricklerit still might be good to check the cert issue before the ns change becomes active12:32
fungibut yeah, their whois still lists rackspace's nameservers at the moment, and afilias (the org tld registrar) still returns rackspace's nameservers12:32
fungifrickler: interestingly, if i set openstack.org to 172.66.43.113 in /etc/hosts i don't have any problem with the cert12:34
fungior rather my browser doesn't have any problem12:34
fungialso your curl command doesn't give me "cert expired" but rather "server certificate verification failed."12:36
fricklerhmm, still repeats for me. likely they're anycasting things depending on the source (region) of the request. though the final result doesn't seem better in your case12:40
fungiand as for the ttl on records there, they all start out at "auto" which is i guess 5 minutes, but i can individually set them to fairly arbitrary lengths from a drop-down (1m,2m,5m,10m,15m,30m,1h,2h,5h,12h,1d)12:46
fungilooks like if it was an enterprise account there would also be a 30s ttl option12:47
fricklerhmm, I really don't want to make you click through all our 100+ records to do that, is there any automation they offer? or a zone default that is used for "auto" which could be bumped to 1h?12:56
fungithere may be a bulk operation option in this interface, i just need to look around a bit12:59
fungiwell, at the very least there's https://developers.cloudflare.com/api/operations/dns-records-for-a-zone-update-dns-record13:00
fungiand https://developers.cloudflare.com/api/operations/dns-records-for-a-zone-patch-dns-record13:01
fungilooks like a patch operation can set the ttl of a record13:01
clarkbfrickler: when you say they changed email addresses for the LE thing in the openmetal cloud do you mean that happend without our intervention or was that a side effect of running some kolla commands?14:52
clarkbfrickler: I think we can start with email and ask them if they want us to file a ticket instead. In particular I think we are a bit of a demo cloud so its good to talk directly to people who can figure things out rather than going through their normal ticket system I suspect14:53
clarkbfrickler: not sure if you want to send that email as you probably have a better grasp on the situation or draft something and I can send it or just help me draft something14:54
clarkbre low TTLs I think people are under the assumption that is always better because it is more nimble, but it also means more opportunity for failed lookups14:54
fungiand also more load on resolvers14:59
fricklerclarkb: the change of email addresses is what I can see in the log, I do see the new one in the current kolla config and I don't think that we touched that file15:09
fricklerI can try to draft a mail later or maybe tomorrow, need to chair the TC session today so will be a bit busy with preparing15:10
clarkbfrickler: got it so likely something they changed. I guess the email should be along the lines of "The letsencrypt provisioned cert from the initial deployment is going to expire soon (I can check the actual timeframe before sending). We noticed some recent updates to the kolla config around this, but it seems to still not be getting reissued. Is there anything we should be doing to15:10
clarkbhelp with this process?"15:10
clarkbfrickler: thanks!15:10
fricklerclarkb: maybe also mention the error I pasted, but then that already sounds good to go I'd say15:11
clarkbfrickler: the error about registering the account? sounds good I can send that out after my morning meeting15:11
frickleryes15:12
clarkbemail sent15:47
fungithe foundation just got confirmation back from the registrar that the openstack.org dns change has been put in16:20
fungiwhois has updated now16:20
fungiafilias still has rackspace's nameservers, but with a 1-hour ttl so hopefully won't take too long when it updates16:23
fungialso ramon from openmetal already replied16:27
clarkboh nice sounds like they think things should provision todayish16:29
fungii just got a pair of cloudflare ns records back from b2.org.afilias-nst.org16:35
fungiand my local resolver is returning them now as well16:36
clarkbnow resolve soemthign you don't already haev cached16:37
clarkbI too am getting back cloudflare NS records and swift.openstack.org resolves for me16:38
clarkbI guess I don't know what my dns server has cached though16:38
clarkb(for the ns records)16:38
fricklerand I get an error from chromium for https://openstack.org/ :(16:47
fungifrickler: yes, we confirmed that with the folks managing it and they're putting a workaround in place16:47
fungishould go back to normal momentarily16:47
fungithankfully it only serves a permanent redirect under normal circumstances, so hopefully most people have that cached in their browsers and won't hit it in the near term16:47
fricklerredirect to what? www.o.o isn't working either. "too many redirects"16:48
fungito that, and yeah it was working moments ago but maybe they switched it backwards16:49
fungiyeah, seems the attempted fix is what has now created the redirect loop there16:50
fungifrickler: looks like they got it worked out, try again?16:54
frickleryep, looking better now16:56
fungithanks for confirming!16:56
SvenKieskedon't forget to check different dns caches, e.g. via https://dnschecker.org/#A/openstack.org dns changes need most of the time more time than pure TTL to propagate16:56
fungiyeah, we're/they're avoiding making unrelated dns changes for a while until the ns delegation settles out16:57
SvenKieskegood luck with the work going forward :)16:58
fungithanks! luckily from an opendev perspective the only important bits for us are mostly just cnames into domains we operate the nameservers for16:59
clarkbthere are a couple exceptions to that but ya impact to us should be limited16:59
fungiexcept for afs/kerberos which is still in openstack.org because moving domains is challenging16:59
fungiand with the funky (from a typical dns perspective) records involved in those protocols we should definitely keep an eye out for oddities in case something in the import wasn't quite right17:00
opendevreviewMerged opendev/zone-opendev.org master: Add DNS for new Vexxhost mirrors  https://review.opendev.org/c/opendev/zone-opendev.org/+/92543719:07
opendevreviewMerged opendev/system-config master: Add Noble nodes to system-config-run testing  https://review.opendev.org/c/opendev/system-config/+/92544719:24
opendevreviewMerged opendev/system-config master: Track our OpenMetal environment HTTPS cert expiry  https://review.opendev.org/c/opendev/system-config/+/92648820:05
clarkbtonyb: I made one minor update to the wiki announcement etherpad (changed a '.' to a ' ' on line 22) otherwise this looks good to me20:07
clarkbwe probably don't need to get into that level of detail for the upgrade process but I don't think it hurts either20:07
tonybthanks.20:09
tonybI'll refresh the reviews, with some questions on the reviews.  from there we can think about timing, and send the announcement.20:10
clarkbsounds good. I'm going to pop out on a bike ride now. Back in a bit20:13
tonybenjoy20:14

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!