Thursday, 2026-09-24

-@gerrit:opendev.org- Monty Taylor https://matrix.to/#/@mordred:inaugust.com proposed: [opendev/system-config] 1007077: Mirror pigsty/silo https://review.opendev.org/c/opendev/system-config/+/100707700:16
@mordred:waterwanders.comClark: ^^ there's the followup to your zuul-jobs patch :) corvus 00:17
-@gerrit:opendev.org- Monty Taylor https://matrix.to/#/@mordred:inaugust.com proposed: [opendev/system-config] 1007077: Mirror pigsty/silo https://review.opendev.org/c/opendev/system-config/+/100707700:23
@mordred:waterwanders.comthis time spelled correctly00:23
-@gerrit:opendev.org- Zuul merged on behalf of Clark Boylan: [zuul/zuul-jobs] 1005764: Convert mc to mcli in s3 tests https://review.opendev.org/c/zuul/zuul-jobs/+/100576400:32
-@gerrit:opendev.org- Zuul merged on behalf of Clark Boylan: [zuul/zuul-jobs] 1005755: Switch minio/minio to pigsty/silo https://review.opendev.org/c/zuul/zuul-jobs/+/100575500:32
-@gerrit:opendev.org- Zuul merged on behalf of James E. Blair https://matrix.to/#/@jim:acmegating.com: [opendev/system-config] 1006632: Reset podman data on zuul components https://review.opendev.org/c/opendev/system-config/+/100663214:37
-@gerrit:opendev.org- Zuul merged on behalf of Monty Taylor https://matrix.to/#/@mordred:inaugust.com: [opendev/system-config] 1007077: Mirror pigsty/silo https://review.opendev.org/c/opendev/system-config/+/100707714:46
-@gerrit:opendev.org- Clark Boylan proposed: [openstack/project-config] 1007269: Add prometheus as a grafana datasource https://review.opendev.org/c/openstack/project-config/+/100726916:07
@clarkb:matrix.orgI have no idea if ^ is correct, but I think if it passes testing then getting that in will make it easier to test in the running instance or with held test nodes?16:07
@clarkb:matrix.orgI'm also going to approve https://review.opendev.org/c/opendev/system-config/+/1000873 to have prometheus collect greptimedb metrics16:08
@clarkb:matrix.orgactually before I do that I'm going to review the metrics reported at that endpoint16:09
@clarkb:matrix.orgya I don't see anything concerning in there. It does list some paths that greptimedb uses but I think those are all in public config anyway16:15
@clarkb:matrix.orgJens Harbott: did you have a chance to look at https://review.opendev.org/c/opendev/system-config/+/1006976 fungi pointed out that one of the two routers does not appear to currently be valid. I'm not sure if we can determien whether it should be without asking vexxhost though?16:20
@clarkb:matrix.orgin the meantime do we want to proceed with config that has a single router in it? I can't imaging that would be worse than the current situation?16:28
@fungicide:matrix.orgi don't think it will be different than the current situation16:28
@clarkb:matrix.orgWouldn't it be better as long as the single router doesn't go down?16:29
@fungicide:matrix.orgi haven't seen any cases of review.o.o having incorrect entries in its routing table16:29
@clarkb:matrix.orgThe issue aiui is that our config is being unconfigured by stray RAs. Switching to a static config that ignores those RAs should be more reliable?16:29
@fungicide:matrix.orgoh maybe, but i haven't observed that16:29
@fungicide:matrix.orgin the cases i personally saw, one of the two core routers was getting incoming packets and didn't know where the review server was16:30
@clarkb:matrix.orgoh so this is different to the behavior we saw on review02 then? In that case the static config may not help?16:30
@clarkb:matrix.orgI was under the impression that we thought it was the same thing with RAs coming from elsewhere confusing things16:31
@fungicide:matrix.orgit seems different to me, but it's been getting debugged independently by multiple people who may have been coming to different conclusions16:31
@clarkb:matrix.orgya double checking right now what I see is ping6 google.com does not succeed. But ip addr reports the expected ipv6 global address and ip -6 route shows the route to the one of two routers that we expect to work right now.16:32
@clarkb:matrix.orgWhich I think backs up what you are saying and statically configuring things may not actually help here (since the host isn't confuised about who it is or who it should talk to)16:33
@clarkb:matrix.orgoh the pings do eventually go through they just take a while to get going16:33
@clarkb:matrix.orgI'll defer to others who have done much more debugging on whether or not we want to try the static config afterall. I'm happy to edit it to drop the second route if so (as that one appears to be invalid at the moment)16:35
@fungicide:matrix.orgalso it sounded like a lot of the troubleshooting had been focused on the mirror server in that region, and i don't know that we can assume whatever's happening on it is the same problem review is having16:36
@mnasiadka:matrix.orgThese are the same problems, any routing outside of that network there is problematic (in any direction)16:37
@fungicide:matrix.orgyeah, in which case static or dynamic route configuration on the servers won't do anything to fix inbound routing16:38
@mnasiadka:matrix.orgKolla-Ansible had to disable mirror usage in that region and set to prefer ipv4 in gai.conf16:38
@mnasiadka:matrix.orgAnd to make things more stable - before VexxHost fixes the problem - probably removing AAAA entry for review and switching gai.conf to prefer ipv4 on the mirror would be the things that would help regain stability16:39
@mnasiadka:matrix.orgThis is the merged K-A patch for reference: https://review.opendev.org/c/openstack/kolla-ansible/+/100710216:40
@fungicide:matrix.orgwe could drop the aaaa record for the mirror server there as well16:40
@clarkb:matrix.orgwith the mirror it proxies to pypi and elsewhere which is why the ipv4 preference would help I think16:41
@clarkb:matrix.orgbut ya dropping AAAA records may be necessary if we think this is all upstream of us16:41
@mnasiadka:matrix.orgIpv6 works flawlessly inside the network, any connection to/from outside is flawed (I tested both mirror and review from another US ipv6 capable cloud and my home broadband in Europe)16:42
@mnasiadka:matrix.orgThe worst problem is it’s intermittent :)16:43
@mnaser:matrix.orgSorry we're working on this but it's been hard identifying the root exact cause.. but we have a lead16:43
@fungicide:matrix.orgsounds promising, thanks mnaser!16:43
@mnasiadka:matrix.orgmnaser: no need to be sorry, networking is hard :) maybe that’s some OVN bug?16:43
@mnaser:matrix.orgNo it's actually a physical router thing it seems16:44
@clarkb:matrix.orghow exciting16:45
@fungicide:matrix.orgi recommend percussive maintenance, the bigger the hammer the better16:45
@clarkb:matrix.orgI'll go ahead and WIP the static  config change as thsi seems to confirm it is unlikely to help16:46
-@gerrit:opendev.org- Zuul merged on behalf of Michal Nasiadka: [opendev/system-config] 1000873: prometheus: Add scraping of greptimedb metrics https://review.opendev.org/c/opendev/system-config/+/100087316:48
@mnasiadka:matrix.orgmnaser: Arista is playing tricks? Interesting16:56
-@gerrit:opendev.org- Clark Boylan proposed: [openstack/project-config] 1007269: Add prometheus as a grafana datasource https://review.opendev.org/c/openstack/project-config/+/100726918:29
@clarkb:matrix.orgLooks like there may be name normalization and if you're not using a normalized name then uid stuff gets confused and we try to create a datasource that already exists? In any case I'm hoping that simply using a normalized name will make that happier18:30
@clarkb:matrix.orgok 1007269 passes now. In theory if we get that landed we can start constructing new dashbaord via grafana's web ui that we then port into grafyaml config for everyone to see19:44
@clarkb:matrix.orgThe pre ptg is next week. Organizational notes and other details are going here: https://etherpad.opendev.org/p/opendev-preptg-202609 I've been trying to add a few more ideas on topics to cover as they occur to me. Feel free to add your own or add more information/questions/etc to the ones already on there20:58
@fungicide:matrix.orglooks like anubis 1.28 is going to add webassembly challenges for browsers that support it (which will likely improve the human experience since it can take advantage of hardware accelerated computation too)21:40
@fungicide:matrix.orgv1.28.0-pre2 was tagged a week ago, so the full release is probably coming in the next few weeks21:41
@fungicide:matrix.orgi've upgraded one of my personal servers to it, just to try it out early21:45
@clarkb:matrix.orgit will but it won't be used by default. Its also a bit unclear to me if it will actually be better at keeping the bots at bay (I think the theory is that memory is more expensive than compute now so memory heavy challenges are better_21:48
@fungicide:matrix.orgyeah i don't think it's aimed as much at making things harder for bots than the prior version, just making it less annoying for !bots21:49
@clarkb:matrix.orgright but we rely on it slowing down the bost currently :)21:50
@fungicide:matrix.orgdoesn't look like it will make it any easier for the bots though21:51
@clarkb:matrix.orgI think it is expected to be much quicker21:51
@clarkb:matrix.orgwhich is the part I'm not sure I understand properly21:51
@clarkb:matrix.orgsince the time required is what effectively acts as the metering function21:51
@clarkb:matrix.org(the bots are doing the challenge they are not failing it for the most part these days but anubis is still helpful and keeping the thundering herd at bay due to the time required)21:52
@fungicide:matrix.orgbots able to run webassembly challenges and offload them to hardware acceleration may be able to punch through easier, yes21:52
@fungicide:matrix.orgit also might make it less annoying for normal users even if we wanted to shorten the cookie validity lifetime21:54
@fungicide:matrix.orgso basically we could make things harder/slower for bulk access without as much impact to normal browser users21:55
@fungicide:matrix.organecdotal evidence, upgrading from 1.27.0 to 1.28.0-pre2 with no changes to configuration, trying it out with some of my smaller netbooks that often struggle to solve anubis challenges quickly are now getting through to sites almost instantaneously21:58
@clarkb:matrix.orgfungi: I thought the wasm was opt in so required config updates22:05
@clarkb:matrix.orgyou have to set the challenge method or something22:06
@clarkb:matrix.orgya I think you haev to set the challenge algorithm to argon2id22:06
@fungicide:matrix.orginteresting that i'm seeing better performance automatically22:08
@fungicide:matrix.orgbut this is also admittedly not scientific benchmarking22:08
@clarkb:matrix.orghttps://anubis.techaro.lol/blog/2026/anubis-wasm/ the first config block shows an example. its also possible they shipped it by default and the blog post is wrong or out of date22:09

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!