Wednesday, 2026-08-05

-@gerrit:opendev.org- Zuul merged on behalf of Michal Nasiadka: [opendev/system-config] 999383: Add infra-prod-prometheus https://review.opendev.org/c/opendev/system-config/+/99938306:19
-@gerrit:opendev.org- Michal Nasiadka proposed: [opendev/system-config] 999795: Add infra-prod-service-node-exporter job https://review.opendev.org/c/opendev/system-config/+/99979508:46
-@gerrit:opendev.org- Michal Nasiadka proposed: [opendev/system-config] 999796: Fix goaccess jobs - update static ssh host key https://review.opendev.org/c/opendev/system-config/+/99979608:57
@mnasiadka:matrix.orgClark/fungi: I think I need guidance how to use edit-secrets script (or at least the password to gpg)09:24
@mnasiadka:matrix.orgOk, prometheus and greptimedb are running on prometheus0112:51
@mnasiadka:matrix.orgOnce 999795 merges we should have a node exporter there to check if metrics end up in VexxHost S312:56
@fungicide:matrix.orgi'm disappearing to run lunch errands, when i return i'll approve and monitor the anubis upgrade, which should wrap up before we get into the gerrit upgrade timeframe15:03
@clarkb:matrix.orgsounds good. I'm catching up on stuff now15:09
@clarkb:matrix.orgI've gone ahead and approved https://review.opendev.org/c/opendev/system-config/+/998741 as I expect fungi should be back soon ish and that will take about an hour to gate16:30
@clarkb:matrix.orgthat is the anubis upgrade change16:31
@fungicide:matrix.orgyeah, back, i was just digging up the change number but that seems to be th eone16:31
@fungicide:matrix.orgthanks!16:31
@harbott.osism.tech:regio.chatcan someone check my comment on https://review.opendev.org/c/openstack/project-config/+/961499/comment/476ae21b_acbf9f3f/ regarding the legacy role? do we need to replace it (and does someone know how), or are we fine with keeping it in use (for now?)16:33
@clarkb:matrix.orgI think that the idea is modern zuul will checkout upper constraints properly if you add the repo as a required project to the job?16:40
@clarkb:matrix.orgIt's possible we can drop that entire role16:40
@fungicide:matrix.orgfor context, that seems to be specifically about the translation jobs16:40
@fungicide:matrix.orgarnaudm: in case you missed my comments earlier, on monday ovh sent us a notice that we have an invoice pending payment for `PublicCloudProject: 8bbdc6f25ee94568baea4e872f032f14 (openstackci)` with invoice id `FR79702243` (i haven't received warnings about our other project yet, and can't recall whether both vouchers typically expire at the same time)17:22
@clarkb:matrix.orgfungi: should we send an email to arnaudm maybe?17:28
@clarkb:matrix.orgdmsimard may be able to help too17:29
@fungicide:matrix.orgoh right!!! how did i forget dmsimard is there now?17:30
@dmsimard:matrix.orghi o/17:35
@dmsimard:matrix.orgArnaud has been on PTO, I'll figure something out, thanks for the ping17:36
@fungicide:matrix.orgthanks as always dmsimard and sorry i didn't think to reach out to you first!17:41
@fungicide:matrix.orgthis is the time of year for pto, especially in fr17:42
@dmsimard:matrix.orgoh yeah for sure, lots of people gone for 3 weeks+ at the same time17:51
@fungicide:matrix.orgopenmetal has sent us an e-mail notification that we need to enable 2fa for our account on their web portal by the end of next month, if any of our sysadmins finds a few minutes for that18:11
@fungicide:matrix.orger, end of month after next. by november 118:11
@clarkb:matrix.orgThat anubis change is taking forever 18:14
@fungicide:matrix.orgyeah, i didn't know how long to expect which is why i was hesitant to approve it right before leaving to run errands18:20
@fungicide:matrix.orgbut i probably could have and it still wouldn't have merged by the time i got home again18:21
-@gerrit:opendev.org- Zuul merged on behalf of Clark Boylan: [opendev/system-config] 998741: Update anubis to 1.26.2 https://review.opendev.org/c/opendev/system-config/+/99874118:30
@fungicide:matrix.orgyay!18:32
@clarkb:matrix.orgboth lists and gitea deployments are running now18:32
@fungicide:matrix.orgyep, well clear of hourly jobs this time18:33
@fungicide:matrix.orgi don't anticipate any problems, 1.26.2 has been runing on the wiki server for about a week already18:33
@fungicide:matrix.organubis has made a surprising difference for mediawiki crawler load18:34
@fungicide:matrix.orgthe server used to just be entirely unresponsive for hours a day18:34
@fungicide:matrix.orgnow it's consistently snappy for mew18:34
@fungicide:matrix.orgfor me18:34
@clarkb:matrix.orgya anubis seems to do just enough to slow the crawlers down18:35
@fungicide:matrix.orgi think i'm going to give 1.27.0.pre3 a try on one of my personal web servers18:35
@clarkb:matrix.orglists reports the expected version now. But still waiting for mailman to start up again18:36
@clarkb:matrix.orgI think mailman depends on anubis which is why it got restarted too18:36
@clarkb:matrix.orgmaybe we want to decouple that more? I dunno18:37
@clarkb:matrix.orggitea now too (but gitea deployment isn't complete yet_18:38
@fungicide:matrix.orgthere was a thread today on the mailman-users list about using anubis and one of the mm maintainers was talking about how a downside is that it makes the sites inaccessible for browsers without js, but actually i can connect to our sites with lynx no problem it's actually hyperkitty's use of js that makes it impossible to browse list archives18:38
@fungicide:matrix.organubis routes clients to the js challenge based on user agent strings (among other determining factors)18:39
@fungicide:matrix.orgso it lets most typical non-js browsers through unimpeded18:39
@clarkb:matrix.orgyes it is configurable. You can in theory have user agents that don't get filtered like that. Until the bots use those agents and need to be filtered anyway18:39
@clarkb:matrix.orgthe anubis code base upstream has a bunch of configuration examples too fwiw18:40
@clarkb:matrix.orgour config is quite simple, but you can get pretty crazy with it. Some of the examples do similar to what we've done elsewhere (IP block based denials, old client UA denials, etc)18:40
@clarkb:matrix.orgfungi: once this is done I'm going to find lunch. If you still think today is good for gerrit we can probably approve that change next?18:41
@clarkb:matrix.orglooks like it needs to be reviewed too18:42
@clarkb:matrix.orghttps://review.opendev.org/c/opendev/system-config/+/99493818:42
@clarkb:matrix.orgthe big change other than the version bump is switching the replication plugin from a branch to a tag now that the fix we need is on tagged releases18:42
@clarkb:matrix.orggitea deployment has succeeded now too18:43
@fungicide:matrix.orgah yeah should be fine, i'll take a quick look over 994938 and then send out the one-hour status notice18:47
@fungicide:matrix.org#status notice The Gerrit service on review.opendev.org will be offline momentarily at 20:00 UTC (an hour from now) while we restart for a patch upgrade, but should return within a few minutes.19:01
@status:opendev.org@fungicide:matrix.org: sending notice19:01
-@status:opendev.org- NOTICE: The Gerrit service on review.opendev.org will be offline momentarily at 20:00 UTC (an hour from now) while we restart for a patch upgrade, but should return within a few minutes.19:04
@status:opendev.org@fungicide:matrix.org: finished sending notice19:04
@clarkb:matrix.orgfungi: looks like gerrit image builds are failing now19:10
@fungicide:matrix.orgargh19:10
@clarkb:matrix.org`ERROR: error loading package 'plugins/zuul-results-summary/web': Unable to find package for @@aspect_rules_ts//ts:defs.bzl: The repository '@@aspect_rules_ts' could not be resolved: Repository '@@aspect_rules_ts' is not defined.`19:10
@fungicide:matrix.orgtf19:10
@clarkb:matrix.orgI don't think I'm fixing that quickly enough to make our targetted time. So I'm just goign to eat lunch and look into it later19:10
@clarkb:matrix.orgmy guess is they removed some dep from the main repo so now it isn't available to plugins19:10
@fungicide:matrix.orgyeah, let's regroup and plan for another attempt later19:11
@clarkb:matrix.orgseems like there was a similar issue I ran into at some point19:11
@clarkb:matrix.orgbut I'll dig in after lunch19:11
@fungicide:matrix.org#status notice The Gerrit service on review.opendev.org will not be restarted at 20:00 UTC after all, due to unanticipated image build regressions, and will be rescheduled to a later time/date.19:12
@status:opendev.org@fungicide:matrix.org: sending notice19:12
-@status:opendev.org- NOTICE: The Gerrit service on review.opendev.org will not be restarted at 20:00 UTC after all, due to unanticipated image build regressions, and will be rescheduled to a later time/date.19:15
@status:opendev.org@fungicide:matrix.org: finished sending notice19:15
@fungicide:matrix.orgyeah, the 3.14 build is also failing the same way19:16
@dmsimard:matrix.orgHey, just following up. I don't know much about this billing stuff 😅 I did add a new voucher but I see that the invoice is still pending. I reached out to billing for more info but will likely only hear back tomorrow.19:27
@clarkb:matrix.orgThank you for looking into it19:36
@fungicide:matrix.orgthanks!19:36
@fungicide:matrix.organd yeah, for some reason once those time-limited vouchers expire the billing department has to reverse the charges, or at least that's what they've done in the past19:37
@fungicide:matrix.orgthey also have a fairly short fuse that disables our resources within a few days if they don't reverse the "overdue" charges fast enough, so we should be on the lookout in particular for job log upload failures to swift since i think that's where we'll see it first (manifesting as lots of post_failure job results)19:39
@clarkb:matrix.orghttps://gerrit.googlesource.com/plugins/zuul-results-summary/+/5f5466265d54345b659459fcdb8957f92215130a this is what broke us19:53
@clarkb:matrix.orgI suspect that this works when building against Gerrit master but not 3.13 or 3.1419:53
@clarkb:matrix.orgSo now I have to have an awkward conversation upstream asking them why they are breaking the plugin for it's one user19:53
@fungicide:matrix.orgyeah... :/19:53
@clarkb:matrix.orgyup confirmed master has a bunch of bazel rules for aspect_rules_ts and stable-3.14 and stable-3.13 have none19:58
@clarkb:matrix.orgso upstream updated the plugin to make it work with master and broke us in the process19:58
-@gerrit:opendev.org- Clark Boylan proposed: [opendev/system-config] 999904: Checkout working zuul-results-summary commit for stable Gerrit https://review.opendev.org/c/opendev/system-config/+/99990420:15
@clarkb:matrix.orgThis is similar to the hack I had set up with its-base when that broke in a similay way (updates that were master compatible only). I've asked on discord what the proper solution is (I'm guessing stable branches for the plugin)20:15
@jim:acmegating.comstable branches upstream and/or a temporary pin downstream sounds good to me.20:20
@jim:acmegating.comnot great that it broke the old versions, but also, maybe kind of nice of them to try to keep it updated for new versions?  :)20:21
@clarkb:matrix.orgya and maybe we should do third party ci or something20:23
@clarkb:matrix.orgwe could run our image builds and system-config-run jobs against changes to upstream things we care about maybe20:23
@jim:acmegating.comwe could.  we would need to use the deprecated checks plugin; i don't see why that wouldn't work, theoretically, as long as they continue to run it (we would be in the same boat as gerrit's zuul).20:25
@clarkb:matrix.orgoh right i forgot about them doing things differently20:27
@mnaser:matrix.orgHas there been any changes inside opendev.org filtering things in some way?23:42
I'm seeing our CI jobs fail with this:
fatal: https://opendev.org/openstack/hacking/info/refs not valid: could not determine hash algorithm; is this a git repository?
@mnaser:matrix.org(downstream CI jobs though.. on pre-commit run)23:42
@mnaser:matrix.orghttps://paste.opendev.org/show/bLwbPyj6wCdVzl9bsJ5k/23:42
@clarkb:matrix.orgwe upgraded gitea the other day23:43
@clarkb:matrix.organd upgraded anubis this morning23:43
@clarkb:matrix.orgbut no intentional config updatse as far as I know23:43
@mnaser:matrix.orgit seems non-deterministic .. so i wonder if its the scraping filters or something that caught this23:43
@clarkb:matrix.orgit seems to work fine in my browser (which has cleared anubis) and with curl which I think is what git will use (but with different user agent)23:46
@clarkb:matrix.orgdoes the log file it indicates you should check include any more info (like maybe an http return code or byte size or something)23:47
@clarkb:matrix.orgbut also this is why I hate precommit23:47
@clarkb:matrix.orgapache logs on each gitea backend report requests to hacking info are all 200 responses23:51
@mnaser:matrix.orglet me try and jump into ssh during aa run23:51
@clarkb:matrix.orgthis is interseting though. Some of those 200 responses are only 172 bytes long23:55
@clarkb:matrix.orgI see others in the 3800 range whcih more closely matches what I get when I request it23:55
@mnaser:matrix.orgmaybe thats the first intial anubis response23:55
@clarkb:matrix.orgwell anubis should ignore your client I think because its git23:55
@mnaser:matrix.org```23:58
runner@depot-worker-x7kpnhxc47zfgbqjwwh2:/home/runner/work/ironic/ironic$ git clone https://opendev.org/openstack/hacking
Cloning into 'hacking'...
fatal: https://opendev.org/openstack/hacking/info/refs not valid: could not determine hash algorithm; is this a git repository?
```
@clarkb:matrix.orgok the 172 byte response seems to be acceptable. I was able to reproduce it with git locally against gitea1023:58
@mnaser:matrix.orgsource ip is 44.212.135.823:59
@clarkb:matrix.orgthere must be some optimization in git on the client side sending the refs it already has and get back a diff or something23:59
@clarkb:matrix.orgbut when you do it with curl or the browser you get all the refs back23:59

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!