Wednesday, 2026-08-19

-@gerrit:opendev.org- Michal Nasiadka proposed: [openstack/diskimage-builder] 1001456: CI: Disable swift in Devstack https://review.opendev.org/c/openstack/diskimage-builder/+/100145606:15
-@gerrit:opendev.org- Michal Nasiadka proposed: [openstack/diskimage-builder] 1001456: CI: Disable swift in Devstack https://review.opendev.org/c/openstack/diskimage-builder/+/100145606:15
-@gerrit:opendev.org- Michal Nasiadka proposed wip: [openstack/diskimage-builder] 1001456: CI: Disable swift in Devstack https://review.opendev.org/c/openstack/diskimage-builder/+/100145606:41
-@gerrit:opendev.org- Michal Nasiadka proposed wip: [openstack/diskimage-builder] 1001456: CI: Disable swift in Devstack https://review.opendev.org/c/openstack/diskimage-builder/+/100145606:41
-@gerrit:opendev.org- Michal Nasiadka marked as active: [openstack/diskimage-builder] 1001456: CI: Disable swift in Devstack https://review.opendev.org/c/openstack/diskimage-builder/+/100145606:41
-@gerrit:opendev.org- Michal Nasiadka proposed: [openstack/diskimage-builder] 1001465: rocky-container: Add support for DIB_DISTRIBUTION_MIRROR https://review.opendev.org/c/openstack/diskimage-builder/+/100146508:19
-@gerrit:opendev.org- Michal Nasiadka proposed: [openstack/diskimage-builder] 1001465: rocky-container: Add support for DIB_DISTRIBUTION_MIRROR https://review.opendev.org/c/openstack/diskimage-builder/+/100146508:19
-@gerrit:opendev.org- Zuul merged on behalf of Clark Boylan: [openstack/diskimage-builder] 1001395: Increase devstack Glance total image size limits https://review.opendev.org/c/openstack/diskimage-builder/+/100139509:37
-@gerrit:opendev.org- Michal Nasiadka proposed: [openstack/diskimage-builder] 1001465: rocky-container: Add support for DIB_DISTRIBUTION_MIRROR https://review.opendev.org/c/openstack/diskimage-builder/+/100146512:15
-@gerrit:opendev.org- Michal Nasiadka proposed: [openstack/diskimage-builder] 1001465: rocky-container: Add support for DIB_DISTRIBUTION_MIRROR https://review.opendev.org/c/openstack/diskimage-builder/+/100146512:16
-@gerrit:opendev.org- Michal Nasiadka proposed: [openstack/diskimage-builder] 1001483: CI: Bump dib flavor disk to 6GB https://review.opendev.org/c/openstack/diskimage-builder/+/100148312:17
-@gerrit:opendev.org- Michal Nasiadka proposed: [openstack/diskimage-builder] 1001483: CI: Bump dib flavor disk to 6GB https://review.opendev.org/c/openstack/diskimage-builder/+/100148312:17
-@gerrit:opendev.org- Michal Nasiadka proposed:13:42
- [openstack/diskimage-builder] 1001465: rocky-container: Add support for DIB_DISTRIBUTION_MIRROR https://review.opendev.org/c/openstack/diskimage-builder/+/1001465
- [openstack/diskimage-builder] 1001483: CI: Bump dib flavor disk to 6GB https://review.opendev.org/c/openstack/diskimage-builder/+/1001483
@clarkb:matrix.orgLooks like things may be quiet for the moment. I'm going to get a bike ride in first thing today before it gets hot. fungi: I'm up for landing anubis related updates today if you are14:18
@fungicide:matrix.orgClark: sounds good. keep in mind that your 1.27.0 upgrade change is redundant, we already upgraded to 1.27.2 via another change of yours last week?14:22
@fungicide:matrix.orgi left a comment on it to that effect yesterday after the meeting14:23
-@gerrit:opendev.org- Michal Nasiadka proposed:14:37
- [openstack/diskimage-builder] 1001465: rocky-container: Add support for DIB_DISTRIBUTION_MIRROR https://review.opendev.org/c/openstack/diskimage-builder/+/1001465
- [openstack/diskimage-builder] 1001483: CI: Bump dib flavor disk to 6GB https://review.opendev.org/c/openstack/diskimage-builder/+/1001483
@clarkb:matrix.orgfungi: 1.27.2 was the gitea upgrade. 1.27.0 is anubis. Overlapping version numbers with different software15:41
@fungicide:matrix.orger, oh16:20
@clarkb:matrix.orghttps://github.com/prometheus/node_exporter#enabled-by-default is the default node-exporter list of collectors16:21
@fungicide:matrix.orgokay, well i'm around and ready to approve it at this point, seems to still be the latest anubis version16:21
@clarkb:matrix.orgcool I'm back and at a computer too so ready if you are. My plan is to dig into prometheus data otherwise16:22
@clarkb:matrix.orgthe "easy" way to audit this may be to query the metrics endpoint directly then skim that data16:25
@fungicide:matrix.orgokay, anubis 1.27.0 approved16:27
@fungicide:matrix.orgi went ahead and manually upgraded the anubis package on the wiki server too16:30
@fungicide:matrix.organd restarted the daemon16:30
@clarkb:matrix.organd I can still reach the wiki16:32
@fungicide:matrix.orgyeah, i reloaded and saw the anubis splash screen briefly and it reported the new version number16:33
@fungicide:matrix.orgso seems at first pass to be functional at least16:33
@clarkb:matrix.orgthe anubis change is just about done in the gate17:55
@clarkb:matrix.orgoh I guess it has to do the testinra tests still17:58
-@gerrit:opendev.org- Zuul merged on behalf of Clark Boylan: [opendev/system-config] 1000348: Upgrade Anubis to 1.27.0 https://review.opendev.org/c/opendev/system-config/+/100034818:02
@clarkb:matrix.orghourlies enqueued just ahead of ^18:02
@clarkb:matrix.orglists has updated and seems to work for me18:12
@clarkb:matrix.orggitea is almost down. In a browser I'm getting the new anubis version for the backend I talk to and can browse around18:22
@clarkb:matrix.org* gitea is almost done. In a browser I'm getting the new anubis version for the backend I talk to and can browse around18:22
@clarkb:matrix.orgonce the cluster is done I'll test with git too18:22
@clarkb:matrix.orghttps://zuul.opendev.org/t/openstack/buildset/8def3b007ad940b18bbf8cd68ac43c43 buildset was successful and I can git clone system-config18:24
@clarkb:matrix.orgso initial checks look good. We'll have to monitor in case it degrades like last time. But assuming it doesn't we can turn on the honeypot again later today or tomorrow?18:25
@fungicide:matrix.orgyeah, i was pulling up something in gitea and saw the new version number18:35
@fungicide:matrix.orgsounds good to me18:35
@clarkb:matrix.orgcool I'm going to grab lunch now. Back in a bit18:51
@clarkb:matrix.orgI've been looking at the warnings in https://zuul.opendev.org/t/openstack/buildset/8def3b007ad940b18bbf8cd68ac43c43 and trying to find the correct place to claen up the known_hosts.old file. I had assumed that maybe https://opendev.org/opendev/base-jobs/src/branch/master/playbooks/infra-prod/setup-keys.yaml#L21-L24 was doing it but reading through the code for the known_hosts module it seems to create a named tempfile using python's tempfile module which shouldn't result in a .old file and then it does an atomic move for that file. So I don't know that it is the source of the .old file. Then I thought maybe https://opendev.org/opendev/system-config/src/branch/master/playbooks/zuul/roles/add-bastion-host/tasks/main.yaml#L2-L13 was doing it based on no complaints from the pre.yaml playbook in that set of warnings (the first warning in the zuul playbook order appears to be from opendev.org/opendev/system-config/playbooks/zuul/run-production-bootstrap-bridge.yaml and run-production-bootstra-bridge.yaml calls add-bastion-host. But add_host doesn't appear to touch known_hosts.20:34
corvus do you know if the pre.yaml playbook would warn too if setup-keys.yaml was the source of the .old file?
-@gerrit:opendev.org- Clark Boylan proposed: [opendev/base-jobs] 1001567: Stat known_hosts.old after updating known_hosts https://review.opendev.org/c/opendev/base-jobs/+/100156720:47
@clarkb:matrix.orgit does seem likely that the known_hosts module is side effecting this and I'm just not seeing it. ^ is an update to check that hypothesis and help me remember to keep debugging this20:47
@jim:acmegating.comClark: the warnings come from the playbook after the file is created20:48
@clarkb:matrix.orgcorvus: ya so I thought it was weird that the run playbooks don't seem to complain all that much for lists and gitea20:48
@clarkb:matrix.orgwhich is why I thought maybe it was the run playbooks or the post playbook in system-config doing it (and why I want to check in that change I just pushed)20:49
@clarkb:matrix.orgbut maybe its only the pre/post pairings not the run stuff that will complain?20:49
@jim:acmegating.comClark: `man ssh-keygen` says that `ssh-keygen -H` will write a .old file20:53
@jim:acmegating.comit doesn't say if `-R` will do the same, but that's related... so i wouldn't be surprised...20:54
@jim:acmegating.comthe known_hosts ansible module does run -R20:54
@clarkb:matrix.orgah ok so maybe we're tripping over undocumented ssh-keygen behavior20:55
@clarkb:matrix.orgin which case having a followup task remove the .ssh/known_hosts.old file is probably appropriate?20:55
@jim:acmegating.comis the only known_hosts thing we do to add the bastion?  https://zuul.opendev.org/t/openstack/build/68a84526e5534e469625da2b941a7530/console#1/0/1/localhost20:56
@clarkb:matrix.orgcorvus: as far as I can tell yes20:57
@clarkb:matrix.orgwe use that single known_hosts update. But then we have to add-bastion-host to add_host in every new playbook20:57
@jim:acmegating.comClark: i share your puzzlement and agree that triangulating like 567 is a good next step21:05
@clarkb:matrix.orgI've spot checked the anubis log on gitea09 and don't see anything immediately concerning21:42
@clarkb:matrix.orgseems like lots of indicators that actual bots are running up against the challenges which is good21:42
@mordred:waterwanders.combtw - in case nobody has noticed - codesearch links to source locations don't understand repos with main vs master22:19
@mordred:waterwanders.comit indexes and displays them just fine - but the web links to gitea seem to hardcode master22:20
@clarkb:matrix.orgmordred: I think that is a codesearch issue. It only understands a single branch (this is why no stable branch search either)22:20
@clarkb:matrix.organd we force it to look at main instead of master but I guess when it renders things it doesn't know to check the branch name?22:20
@clarkb:matrix.orger hound is the name not codesearch22:21
@mordred:waterwanders.comyeah. I mean - I'm guessing it just clones and gets default branch22:21
@mordred:waterwanders.comso it doesn't have to know anything about that branch name22:21
@clarkb:matrix.orgya and doesn't think it needs to check it either22:21
@mordred:waterwanders.comnot a big deal - just happened to notice22:21
@mordred:waterwanders.comClark: actually - I think it's a bug in jeepyb22:24
@mordred:waterwanders.comhttps://opendev.org/opendev/jeepyb/src/branch/master/jeepyb/cmd/create_hound_config.py#L5622:24
@fungicide:matrix.orgwe keep hoping longer term gitea's search function may improve enough to axe  hound22:28
@clarkb:matrix.orgoh interesting I had no idea that we set the paths like that22:28
@clarkb:matrix.orgfungi:  ya but if anything they've made it worse over time :/22:28
@fungicide:matrix.orgpoop22:29
@clarkb:matrix.orgmordred: https://opendev.org/opendev/bindep/src/branch/HEAD/bindep.txt this appears to work22:30
@clarkb:matrix.orgmordred: so maybe we can s/master/HEAD/ and let gitea figure it out on the fly?22:31
@clarkb:matrix.orgthat would mimic the source cloning behavior too22:31
@mordred:waterwanders.comClark: ooh - that's even easier. we could also template out main vs master from the projects.yaml info ... but I like HEAD instead22:32
@clarkb:matrix.orgGemini says that won't work fwiw, but experimentally gemini is wrong22:32
-@gerrit:opendev.org- Monty Taylor https://matrix.to/#/@mordred:inaugust.com proposed: [opendev/jeepyb] 1001580: Use HEAD instead of master https://review.opendev.org/c/opendev/jeepyb/+/100158022:37

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!