Monday, 2026-03-09

-@gerrit:opendev.org- Riccardo Pittau proposed: [opendev/glean] 979471: Fix systemd ordering cycle in glean service units https://review.opendev.org/c/opendev/glean/+/97947109:18
-@gerrit:opendev.org- yatin proposed: [zuul/zuul-jobs] 961208: Make fips setup compatible to 10-stream https://review.opendev.org/c/zuul/zuul-jobs/+/96120812:02
-@gerrit:opendev.org- yatin proposed: [zuul/zuul-jobs] 961208: Make fips setup compatible to 10-stream https://review.opendev.org/c/zuul/zuul-jobs/+/96120812:04
@clarkb:matrix.orginfra-root: is anyone else interested in doing the gerrit account surgery for sehun.jeong ? It has been a while since I did one but I'm happy to walk through the process if someone else is interested in doing it (I'm not sure if anyone else has done this since we switched to notedb)14:25
@fungicide:matrix.orgi can try to look into it later today, but am about to disappear for lunch errands14:53
@fungicide:matrix.orgthe process is 1. look up the old account id(s) by e-mail address, mark the account(s) inactive, push a change to All-Users cleaning up external ids?14:55
@clarkb:matrix.orgfungi: close, the mark accounts inactive step goes last and is the git push because we remove the preferred email id from the all users record. Before we do that we clean up the external ids via the API since we can't update the external ids with a git push due to the inconsistencies that persists in that dataset14:56
@clarkb:matrix.orgso basically find the old account, use api to remove the conflictingexternal ids, then push a change to all users to disable the account and remove the conflicting preferred email address and that should do it14:56
@fungicide:matrix.orgokay, so don't set them inactive via the api?15:01
@fungicide:matrix.orgbut delete the addresses via api15:03
@clarkb:matrix.orgyes that is what I was doing in the past iirc15:04
@fungicide:matrix.orgcool15:04
@clarkb:matrix.orgwhen you do the git push you can set them disabled and remove their preferred email address record at the same time since those are both in the user record. The external ids are all in one flat db space so updating one via git push requires the whole set to check out cleanly. Using the api works around this problem15:05
@fungicide:matrix.orgokay, heading out now, back in a while15:06
-@gerrit:opendev.org- Zuul merged on behalf of yatin: [zuul/zuul-jobs] 961208: Make fips setup compatible to 10-stream https://review.opendev.org/c/zuul/zuul-jobs/+/96120815:12
-@gerrit:opendev.org- Clark Boylan proposed: [opendev/system-config] 976282: Start testing Ansible 9 on bridge https://review.opendev.org/c/opendev/system-config/+/97628215:46
@clarkb:matrix.orgThis is the promised Ansible 9 instaed of 10 test change15:46
@clarkb:matrix.orgAnsible 9 has better python support range for our current systems so if that fixes the pkg_resources problem I think it is a better upgrade candidate than 10 for now15:46
@clarkb:matrix.orgCouple of other items to call out. First is mnasiadka's change to add a user and ssh key to our list: https://review.opendev.org/c/opendev/system-config/+/978980 if others can weigh in on that it would be great just to capture the general consensus. And second now is a good time to call out meeting agenda items that need to be added/removed/edited. If you let me know I can make the edits or feel free to make them yourself cc infra-root16:46
-@gerrit:opendev.org- Clark Boylan proposed: [opendev/system-config] 976282: Start testing Ansible 9 on bridge https://review.opendev.org/c/opendev/system-config/+/97628217:07
@fungicide:matrix.orgnf_conntrack_count on static02 fell to 7694 after a week, presumably just had to wait out a few hundred thousand tcp sockets that never got closed properly when it was in severe distress17:26
@clarkb:matrix.orgnice17:29
@fungicide:matrix.orgserver-status indicates apache is quite busy, but has a good balance of states and plenaty of available headroom still17:33
@fungicide:matrix.orgplenty17:33
@fungicide:matrix.orghits on the mod_security waf rules are coming in less often too, last new block was added a little over an hour ago17:35
@clarkb:matrix.orgfungi: I'm looking at https://review.opendev.org/q/hashtag:%22apache-waf%22+status:open as part of meeting agenda prep and notice some of them are fialing in ci18:18
@clarkb:matrix.orgnot sure if you'd seen that yet18:18
@fungicide:matrix.orgi have, just need to switch gears and look into logs18:18
@fungicide:matrix.orgat least some of those failures are the `tox --show-config` removal18:25
@fungicide:matrix.orgClark: but you were right, mod_security rule ids need to be unique: https://zuul.opendev.org/t/openstack/build/6f15219d3d594140bc6c8f15c3c33cf6/log/static99.opendev.org/syslog.txt#169718:28
@fungicide:matrix.orgi half expected that to error18:28
@fungicide:matrix.orgmain problem is, i don't know whether it's okay to renumber rules during restarts, or if that throws off the persistent database18:28
@fungicide:matrix.orgi would guess not?18:29
@fungicide:matrix.orgthat is, probably it's fine to renumber rules and restart18:29
@fungicide:matrix.orgmaybe i'll make that block rule into 9999 so it doesn't have to be renumbered in the future when we add more before it18:30
@clarkb:matrix.orgI think its fine to renumber them since corvus' db data doesn't include a rule id in the rows18:31
@fungicide:matrix.orggreat point18:31
@clarkb:matrix.orgMy first pass of meeting agenda edits is in18:33
-@gerrit:opendev.org- Jeremy Stanley https://matrix.to/#/@fungicide:matrix.org proposed:18:39
- [opendev/system-config] 979089: Add WAF rules for docs.openstack.org https://review.opendev.org/c/opendev/system-config/+/979089
- [opendev/system-config] 979090: Add our tripwire SecRule to docs.openstack.org https://review.opendev.org/c/opendev/system-config/+/979090
@clarkb:matrix.orgfungi: the security alert for a new login to infra-root is me21:06
@clarkb:matrix.orgalso when I logged it forced me to choose between turning on and off smart features. I elected to turn them off since this account is primarily for email through imap we shouldn't need any smart magic21:06
@fungicide:matrix.orgsgtm22:15
@clarkb:matrix.orgok last call on the meeting agenda. Also friendly reminder that some of us experiences the DST time change over the weekend and the 1900 UTC meeting time will haev shifted an hour later on your local clock in North America22:41
@clarkb:matrix.orgApparently my neighbors to the north have just done this for the last time and they will not be shifting back to standard time in the fall. I'm a bit jealous actually22:42
@fungicide:matrix.orgi heard, that's awesome news for bc22:42
@clarkb:matrix.orgthe meeting agenda should be in inboxes now22:53

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!