Thursday, 2020-06-25

*** gyee has quit IRC00:07
*** spatel has joined #openstack-ansible01:01
*** cshen has joined #openstack-ansible01:34
*** cshen has quit IRC01:39
*** markvoelker has joined #openstack-ansible01:39
*** markvoelker has quit IRC01:44
*** NewJorg has quit IRC02:16
*** cshen has joined #openstack-ansible03:35
*** spatel has quit IRC03:36
*** cshen has quit IRC03:39
*** markvoelker has joined #openstack-ansible03:40
*** markvoelker has quit IRC03:50
*** udesale has joined #openstack-ansible03:52
*** pmacdonnell has quit IRC03:56
*** spikysnow_ has joined #openstack-ansible04:03
spikysnow_Hello I want to ask about cinder_service_internaluri_insecureTo ignore validate_certs cinder_service_internaluri_insecure is set to false, but based on the name like keystone's keystone_service_internaluri_insecure is set to true to disable validate_certs. https://usercontent.irccloud-cdn.com/file/ssjfuXum/image.png04:06
*** rh-jelabarre has quit IRC04:23
*** evrardjp has quit IRC04:34
*** evrardjp has joined #openstack-ansible04:34
*** cshen has joined #openstack-ansible04:45
*** cshen has quit IRC04:49
*** NewJorg has joined #openstack-ansible05:48
*** jbadiapa has quit IRC06:18
jrosserspikysnow_: the internal endpoint is normally http rather than https so there would not be a cert to validate either way06:20
*** rpittau|afk is now known as rpittau06:20
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-tests stable/ussuri: Rewrite CI provided apt sources to be http instead of https on focal  https://review.opendev.org/73790706:32
*** jbadiapa has joined #openstack-ansible06:36
*** miloa has joined #openstack-ansible06:38
*** grantza has joined #openstack-ansible06:39
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-lxc_hosts stable/ussuri: Stop installing python2.7 on debian/focal  https://review.opendev.org/73776906:47
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-lxc_hosts stable/ussuri: Add functional tests for ubuntu focal  https://review.opendev.org/73777006:49
*** spikysnow_ has quit IRC07:04
*** luksky has joined #openstack-ansible07:09
*** cshen has joined #openstack-ansible07:11
*** jcath has joined #openstack-ansible07:23
*** tosky has joined #openstack-ansible07:42
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-lxc_hosts stable/ussuri: Add functional tests for ubuntu focal  https://review.opendev.org/73777007:42
jrossernoonedeadpunk: if you're around we can start merging ussuri stuff for focal starting here https://review.opendev.org/#/c/737770/08:28
*** jawad_ax_ has joined #openstack-ansible08:35
*** spatel has joined #openstack-ansible08:37
*** jawad_axd has quit IRC08:39
*** spatel has quit IRC08:42
admin0good morning .. does osa work with external ceph ?08:55
jrosseradmin0: absolutely yes - though i think the documentation is a little weak for this08:58
jrosseradmin0: at the most basic level the integration is done here https://github.com/openstack/openstack-ansible-ceph_client/blob/master/defaults/main.yml#L48-L5009:00
jrosseryou don't do any ceph deployment with OSA09:00
jrosserbut you tell it a list of IP addresses for the mons in the external ceph, and it will then ssh to them and recover the ceph.conf and ceph keys09:00
jrosserif it is not possible to ssh to the external mons (different team maintains ceph for example) then you can provide manual ceph conf and keys on the deploy host09:01
jrosseryou have to have all the networking setup up properly so that the containers/hosts can contact the external ceph cluster over whichever interface you need it to09:02
admin0right now, i have 2 platforms with osa+ceph integrated .. i am think if i should continue let osa manage ceph, or decouple ceph from osa09:03
jrosserpersonally i separate them09:10
jrosserbecasue then i can have whatever version of ceph i want with whatever version of openstack09:10
jrosserand the upgrade cycles are decoupled09:10
jrosserbut i did plan right from the start that the ceph hardware / deployment would be independant09:11
openstackgerritMerged openstack/openstack-ansible-lxc_container_create stable/ussuri: Add lxc config key mapping for version 4.x  https://review.opendev.org/73777909:27
openstackgerritMerged openstack/openstack-ansible-lxc_container_create stable/ussuri: Use a single vars file for all ubuntu releases  https://review.opendev.org/73777809:27
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-tests master: Bump ansible version to 2.9.10  https://review.opendev.org/73793509:33
openstackgerritJonathan Rosser proposed openstack/openstack-ansible master: Bump ansible version to 2.9.10  https://review.opendev.org/73793609:34
openstackgerritMerged openstack/openstack-ansible-lxc_container_create stable/ussuri: Use btrfs-progs instead of btrfs-tools in functional tests  https://review.opendev.org/73776709:39
*** stingrayza has joined #openstack-ansible09:48
*** also_stingrayza has quit IRC09:51
openstackgerritMerged openstack/openstack-ansible-tests stable/ussuri: Rewrite CI provided apt sources to be http instead of https on focal  https://review.opendev.org/73790709:56
*** cshen has quit IRC10:08
openstackgerritMerged openstack/openstack-ansible-plugins master: Optimise linear strategy access to physical host variables  https://review.opendev.org/73754310:14
*** rpittau is now known as rpittau|bbl10:20
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-plugins stable/ussuri: Optimise linear strategy access to physical host variables  https://review.opendev.org/73796310:52
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-plugins stable/train: Optimise linear strategy access to physical host variables  https://review.opendev.org/73796410:52
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-plugins stable/stein: Optimise linear strategy access to physical host variables  https://review.opendev.org/73796510:52
jrossernoonedeadpunk: looks like we have an issue in galera role https://opendev.org/openstack/openstack-ansible-galera_server/commit/3d405dfd52c0a5059cefd877fd578114bcdd912d11:10
jrosser2020-06-25 10:15:55.804604 | ubuntu-bionic | RUNNING HANDLER [galera_server : Start new cluster] ****************************11:10
jrosser2020-06-25 10:15:56.291103 | ubuntu-bionic | fatal: [aio1_galera_container-019ae3c4]: FAILED! => {"msg": "'hostvars' is undefined"}11:10
jrosseri think that it's not allowed to access hostvars in task variables like that11:10
jrosserbut this only becomes a problem with ansible 2.9.1011:11
openstackgerritMerged openstack/openstack-ansible-lxc_hosts stable/ussuri: Stop installing python2.7 on debian/focal  https://review.opendev.org/73776911:14
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-lxc_hosts master: Remove support for Unubut 16.04  https://review.opendev.org/73797811:20
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-lxc_hosts master: Do not install python2 or its dev package on Ubuntu Bionic hosts  https://review.opendev.org/73797911:20
openstackgerritMerged openstack/openstack-ansible-lxc_hosts stable/ussuri: Add functional tests for ubuntu focal  https://review.opendev.org/73777011:23
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-plugins master: Update CI tests for currently supported operating systems  https://review.opendev.org/73798111:24
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-galera_server master: Update CI tests for currently supported operating systems  https://review.opendev.org/73798211:28
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-tests master: Remove opensuse-15 jobs  https://review.opendev.org/73798511:32
noonedeadpunkjrosser: btw, do we have speedup on master after having https://review.opendev.org/#/c/737543 merged?11:39
*** ghanima has quit IRC11:44
openstackgerritDmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible-os_rally master: Do not install development packages on the target  https://review.opendev.org/73145911:44
openstackgerritDmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible master: [WIP] Centos-8 support  https://review.opendev.org/68962911:48
*** udesale_ has joined #openstack-ansible11:52
openstackgerritMaksim Malchuk proposed openstack/openstack-ansible stable/train: Fix the name of the renamed network for trove  https://review.opendev.org/73785811:54
*** udesale has quit IRC11:54
*** cshen has joined #openstack-ansible11:55
jrossernoonedeadpunk: i've not really managed to take a look yet12:01
noonedeadpunkyeah, that's ok, will see on graphs later12:02
*** cshen has quit IRC12:04
*** cshen has joined #openstack-ansible12:06
jrossernoonedeadpunk: there is a really big heap of stuff backported to ussuri for review - maybe over the first 3-4 pages of the review dashboard12:10
jrosserplus i found the centos-8 patches being a bit random between python3 and python36 in one of the package names12:10
openstackgerritMerged openstack/openstack-ansible-plugins stable/ussuri: Optimise linear strategy access to physical host variables  https://review.opendev.org/73796312:11
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-lxc_hosts master: Remove support for Ubuntu 16.04  https://review.opendev.org/73797812:11
*** rh-jelabarre has joined #openstack-ansible12:13
ioniis there a way to force python interpretor in openstack-ansible ?12:28
ionii'm trying to get magnum ussuri on top of stein :)12:29
jrosserioni: this is a starting point https://github.com/openstack/openstack-ansible-os_magnum/blob/master/defaults/main.yml#L2012:33
ionijrosser, thanks12:33
jrosserbut i think you might find in stein the repo server wheel build process does not account for python version12:33
jrosserso that might need some looking at too12:33
jrosseras in, it makes a venv for the wheel building, and i beleive in train it can make both a py2 and py3 one in parallel if necessary12:33
openstackgerritMerged openstack/openstack-ansible-plugins stable/train: Optimise linear strategy access to physical host variables  https://review.opendev.org/73796412:34
*** rpittau|bbl is now known as rpittau12:42
openstackgerritGeorgina Shippey proposed openstack/openstack-ansible-os_keystone master: Identity providers can be created with specified domain  https://review.opendev.org/73674112:54
*** gshippey has joined #openstack-ansible12:58
gshippeycheers for getting on that review so fast @noonedeadpunk12:59
*** also_stingrayza has joined #openstack-ansible13:03
*** stingrayza has quit IRC13:06
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-tests stable/stein: Add pre-run playbook to clean up CI nodes before OSA tests run  https://review.opendev.org/73801213:16
ionijrosser, openstack-ansible os-magnum-install.yml -e  'venv_rebuild=true' -e 'venv_python_executable=python3' -e 'uwsgi_python_executable=python3'13:41
ioni:D13:42
ioniworks fine now :)13:42
jrosserawesome :)13:42
ionijrosser, i just needed: https://opendev.org/openstack/ansible-role-python_venv_build/commit/fb243ea7583a1d64c2ecbc51c841c6a2eedabbf913:42
jrosserpowerful tools.....13:42
ioniindeed13:43
jrosseryeah, i remember we had to make seperate venv for that otherwise something really odd happened13:43
ionistill on stein, with magnum from ussuri13:43
ioniwith heat and octavia from train13:43
ionii have a frankenstein13:43
jrosserblimey13:43
openstackgerritMerged openstack/openstack-ansible-nspawn_hosts stable/ussuri: Update minimum tox version and remove old workaround  https://review.opendev.org/73780113:52
openstackgerritJonathan Rosser proposed openstack/openstack-ansible master: Remove opensuse jobs and project templates  https://review.opendev.org/73803113:57
openstackgerritJonathan Rosser proposed openstack/openstack-ansible master: Remove opensuse jobs and project templates  https://review.opendev.org/73803114:02
mgariepyif you need me to review something you can ping me, i have a lot to do on otehr stuff today be i can take the time to review a few patch14:03
openstackgerritGeorgina Shippey proposed openstack/openstack-ansible-os_keystone stable/ussuri: Add Paramaters to httpd.conf template  https://review.opendev.org/73803414:03
jrossermgariepy: cool thanks - almost everything for focal is now backported to ussuri, maybe not merged yet14:04
mgariepygreat :D14:04
mgariepyjust in time for me new deployment. ;) haha14:05
openstackgerritJonathan Rosser proposed openstack/openstack-ansible master: Drop support for openSUSE  https://review.opendev.org/72554114:05
*** spatel has joined #openstack-ansible14:10
spateljrosser: I have replied on your comments here - https://review.opendev.org/#/c/736850/2/tasks/lxc_container_network_new.yml14:12
openstackgerritDmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible-os_barbican master: Add Centos-8 support  https://review.opendev.org/73693214:12
jrosserspatel: have you pressed "reply?"14:13
spatelYes14:13
noonedeadpunkand post ?:)14:13
spateli can see i can see my reply on that link let me check14:13
noonedeadpunkregardig this topic - we should use python36-devel http://paste.openstack.org/show/795210/14:14
noonedeadpunkyeah, you will see it even without publishing it14:14
noonedeadpunkbut it will be visable only for you14:14
spatelI think i forgot to click on "done"14:14
noonedeadpunkno, that't not the reason14:14
noonedeadpunklet me make a screenshot for you or smth14:15
spatelcheck this out - https://imgur.com/a/gG2XL4X14:15
noonedeadpunkso after that you need this https://imgur.com/8tAXwvM14:17
noonedeadpunkas you saved this as draft14:17
spatelOh! i gave answer in comments section, instead of "Reply"  let me do with reply14:18
noonedeadpunkno-no14:18
jrosserspatel: its the same :)14:18
noonedeadpunkyou did right14:18
noonedeadpunkbut you need to publish them14:18
jrosseryou can either reply to someone elses comment just as a comment14:18
jrosseror you can put stuff associtated with particular lines of code like i did originally14:19
jrosserboth are fine14:19
noonedeadpunkthat reply button will publish your draft14:19
*** markvoelker has joined #openstack-ansible14:19
jrosseryou get to go back and fiddle with it all, maybe in many files before publishing it14:19
spatelI think i found it, check it out again14:20
noonedeadpunkyeah14:20
jrosserspatel: anyway - take a look at this https://github.com/openstack/openstack-ansible-lxc_hosts/blob/master/templates/prep-scripts/centos_7_prep.sh.j2#L3814:20
jrosserin the centos-7 cache prep script systemd-networkd is enabled right there14:20
jrosserso i figure we need to do same for centos-8?14:21
noonedeadpunkjrosser: I guess you pathced it for centos 8?14:22
jrosseri suspect it isn't in the centos-8 patch, lets look14:22
jrossermissing from here https://review.opendev.org/#/c/735781/4/templates/prep-scripts/centos_8_prep.sh.j214:23
jrosseralso take a look at why i -1 the patch, the mirrors are all wrong14:23
spateloh possible its missing centos8 file14:24
jrosserbecause we set a var in the CI job which overrides all the settings in lxc_hosts and is not accounting for centos-7 vs. centos-814:24
*** markvoelker has quit IRC14:24
jrosserwe need to unblock stein with this https://review.opendev.org/#/c/738012/14:26
noonedeadpunkjrosser: maybe we can wait for centos8 before updating tests?14:28
jrosserhmm?14:29
noonedeadpunkhttps://review.opendev.org/#/c/737982/114:29
noonedeadpunkand like drop suse+centos7&14:29
noonedeadpunkjust not to do the work twice14:30
openstackgerritDmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible-openstack_hosts master: Enable PowerTools repository for distro installs  https://review.opendev.org/73728414:30
jrosseroh i see yes, we can do that14:30
*** jcath has quit IRC14:30
jrossernoonedeadpunk: opensuse is properly broken for train https://zuul.openstack.org/builds?job_name=openstack-ansible-deploy-aio_metal-opensuse-1514:35
jrosserdid we agree to make that non-voting?14:36
noonedeadpunkyeah I saw that. we proably should set it to non-voting14:36
noonedeadpunkyeah14:36
jrosserok i will do that14:36
openstackgerritJonathan Rosser proposed openstack/openstack-ansible stable/train: Remove pre-gate cleanup tasks for the new plain CI images  https://review.opendev.org/73578514:38
spateljrosser: noonedeadpunk i think we are good with that patch (we just need to add re-enable in prep-scripts/centos_8_prep.sh.j2 file)14:41
spatelJust drop my patch (i don't think we need that anymore)14:42
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-lxc_hosts master: Add centos-8 support  https://review.opendev.org/73578114:45
jrosserspatel: ^ i added it, lets see what happens14:46
spateli can verify in my lab and see how it goes..14:46
noonedeadpunkjrosser: btw I've covered that override https://review.opendev.org/#/c/689629/70/tests/roles/bootstrap-host/tasks/prepare_aio_config.yml14:48
openstackgerritMerged openstack/openstack-ansible-lxc_hosts stable/ussuri: Download yum keys to host before installing  https://review.opendev.org/73777714:49
openstackgerritMerged openstack/openstack-ansible-lxc_hosts stable/ussuri: Do not set PYTHONPATH for tox tests  https://review.opendev.org/73777614:49
openstackgerritMerged openstack/openstack-ansible-lxc_hosts stable/ussuri: copy the actual keyring  https://review.opendev.org/73728014:49
openstackgerritMerged openstack/openstack-ansible-os_nova stable/ussuri: Install netcat-openbsd for live migration  https://review.opendev.org/73778714:49
*** watersj has joined #openstack-ansible14:50
jrossernoonedeadpunk: is it right to have the rdo mirror url inside the centos-7 test here https://review.opendev.org/#/c/689629/70/tests/roles/bootstrap-host/tasks/prepare_aio_config.yml ?14:54
noonedeadpunkuh.... dunno, it was there.... But eventually I think it just brongs no effect...14:58
noonedeadpunk*brings14:59
noonedeadpunkas it just equal to default fromwhat I see14:59
noonedeadpunkoh, it's master for all branches...15:03
jrosseralmost - i have a patch for that here https://review.opendev.org/#/c/734418/15:05
openstackgerritMaksim Malchuk proposed openstack/openstack-ansible stable/train: Fix the name of the renamed network for trove  https://review.opendev.org/73785815:05
jrosserwe need a similar one for ussuri i guess15:05
noonedeadpunkbut we don't have them15:05
noonedeadpunkthere're no ussuri rdo packages for centos 715:06
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-openstack_hosts stable/ussuri: Use Ussuri branch RDO repo on OSA Ussuri branch  https://review.opendev.org/73804815:07
jrosseroh...15:07
jrosserwell i guess this is a thing for the distro jobs15:08
noonedeadpunkyeah15:08
jrosserthe source jobs shouldnt be affected15:08
noonedeadpunkso upgrade for centos distro is not present15:08
openstackgerritMerged openstack/openstack-ansible-os_swift stable/ussuri: Cleanup ansible_python_interpreter  https://review.opendev.org/73779315:09
openstackgerritMerged openstack/openstack-ansible-os_ironic stable/ussuri: inspector: fix service catalog creation  https://review.opendev.org/73778515:13
openstackgerritMerged openstack/openstack-ansible-os_placement stable/ussuri: Cleanup ansible_python_interpreter  https://review.opendev.org/73779015:13
openstackgerritJonathan Rosser proposed openstack/openstack-ansible stable/ussuri: Add Ubuntu Focal support  https://review.opendev.org/73777115:14
openstackgerritMerged openstack/openstack-ansible-tests stable/stein: Add pre-run playbook to clean up CI nodes before OSA tests run  https://review.opendev.org/73801215:14
*** jawad_ax_ has quit IRC15:16
noonedeadpunkjrosser: focal distro packages are going to appear only for victoria http://ubuntu-cloud.archive.canonical.com/ubuntu/dists/focal-proposed/15:17
jrosseryes, i think that means that UCA is not a thing for this cycle15:17
noonedeadpunkand bionic will stop on ussuri...15:17
jrosserit's set to an empty var for ussuri15:17
*** jawad_axd has joined #openstack-ansible15:18
jrosserso does that mean we have bionic distro jobs that are not what we think they are?15:18
noonedeadpunkI wean they include ussuri but bionic won't have victoria distro packages15:19
* noonedeadpunk wondering how canonical see their customer upgrade workflow15:19
*** jawad_axd has quit IRC15:22
jrosseryes so on our ussuri branch we have ussuri UCA for bionic and no repo for focal15:22
noonedeadpunkyeah15:23
jrosseri'll update master for victoria15:23
openstackgerritMerged openstack/openstack-ansible-os_octavia stable/ussuri: Cleanup ansible_python_interpreter  https://review.opendev.org/73778815:24
openstackgerritJonathan Rosser proposed openstack/openstack-ansible-openstack_hosts master: Update UCA repo for Victoria  https://review.opendev.org/73805015:28
*** udesale_ has quit IRC15:28
openstackgerritMerged openstack/openstack-ansible-os_ironic stable/ussuri: Cleanup ansible_python_interpreter  https://review.opendev.org/73778615:30
*** udesale has joined #openstack-ansible15:34
mgariepyfocal has usuri directly in the main repos. https://wiki.ubuntu.com/FocalFossa/ReleaseNotes#OpenStack_Ussuri15:39
mgariepyso it doesn't need uca for focal + usuri15:40
mgariepyussuri*15:40
mgariepyfrom now on i'll call it U.15:41
*** cshen has quit IRC15:43
noonedeadpunkso, we just should try to add distro job for focal?15:47
*** cshen has joined #openstack-ansible15:47
noonedeadpunkinteresting...15:47
openstackgerritDmitriy Rabotyagov (noonedeadpunk) proposed openstack/openstack-ansible master: Add ubuntu focal distro jobs  https://review.opendev.org/73805415:49
noonedeadpunklet's see...15:49
*** cshen has quit IRC15:52
*** jawad_axd has joined #openstack-ansible15:53
openstackgerritMerged openstack/openstack-ansible-ceph_client stable/ussuri: Cleanup ansible_python_interpreter  https://review.opendev.org/73778315:54
*** jawad_axd has quit IRC15:57
*** rpittau is now known as rpittau|afk16:11
vakuznetwhat is changed in 20.1.2 that caused octavia to fail http://paste.openstack.org/show/795218/16:12
vakuznetrequest goes to publicURL despite neutron.endpoint_type is internalURL (no SSL)16:14
jrosserout of interest which branch?16:14
jrosserok stable/train?16:16
vakuznetstable train from 20.1.1 to 20.1.216:16
jrosservakuznet: as far as i know nothing ha changed in train, though i'm surprised to see a python 2.7 venv there16:16
openstackgerritKevin Carter (cloudnull) proposed openstack/ansible-config_template master: Update config_template to use the builtin _get_remote_user function  https://review.opendev.org/73805816:16
vakuznetit's centos7 -> so python 2.716:17
noonedeadpunkoctavia sha has changed16:18
openstackgerritKevin Carter (cloudnull) proposed openstack/ansible-config_template master: Update config_template to use the builtin _get_remote_user function  https://review.opendev.org/73805816:18
noonedeadpunkrole is exactly the same16:19
noonedeadpunkhttps://opendev.org/openstack/openstack-ansible/src/tag/20.1.2/playbooks/defaults/repo_packages/openstack_services.yml#L27416:19
noonedeadpunkfrom dcd80d3028e989fe5f2147b3ea8f074765eb953d to 09e863eb539e29c8950ddfce12d602c0e77c1b7e16:20
jrosseroh hah16:21
jrosserdoh https://github.com/openstack/octavia/commit/09e863eb539e29c8950ddfce12d602c0e77c1b7e16:21
jrosserargh this is going to break my deployment too :(16:22
noonedeadpunkso we kida need to set endpoint in neutron section16:22
noonedeadpunkI won't expect such changes to be backported tbh16:23
jrosserjohnsom: you around?16:24
johnsomo/16:24
noonedeadpunkvakuznet: so it seems that instead of neutron.endpoint_type we need to set neutron.endpoint16:25
*** jawad_axd has joined #openstack-ansible16:25
jrosserjohnsom: read back about 10 lines up there ^^^16:25
johnsomAh, I see the bug in that patch yeah, it's not honoring the endpoint type...  Sigh16:27
*** cshen has joined #openstack-ansible16:27
jrosserjohnsom: so i think from deployment tool point of view there needs to be very strong understanding of which endpoint is used in which circumstances16:27
johnsomThis was backported as it is a low level security fix with neutron16:27
jrosserwe have users where the services incl octavia cannot reach the public endpoint16:28
jrosseronly internal16:28
johnsomYeah, the new code missed a few parameters when it looks up the endpoint in keystone.16:28
johnsomThey left out a few parameters it looks like16:31
jrossershould this change what we need in the config file?16:31
johnsomNo, they messed up this patch16:32
*** cshen has quit IRC16:32
johnsomYou can work around the bug by changing your config file, but there is no reason you should have to16:32
jrosserif it's possible to give vakuznet a pointer to get unstuck, that would be cool16:33
johnsomvakkuznet Yeah, so it looks like this patch didn't include some of the criteria it should have when it looks up the neutron endpoint in keystone. I will create a patch to fix this now. To work around it until we can get a patch out, you can set your desired neutron endpoint in the octavia.conf file on the API instances in the [neutron] endpoint setting.16:37
johnsomThat will override this broken keystone lookup16:37
jrosservakuznet: actually you can put octavia_git_install_branch: dcd80d3028e989fe5f2147b3ea8f074765eb953d into your /etc/openstack_deploy/user_variables.yml and that will wind you back to what you had before16:37
vakuznetsorry for not responding, in a meeting, but i'm reading :)16:39
jrosseror to do what johnsom and add a new config option for the endpoint you would put this in user_variables.yml http://paste.openstack.org/show/795220/16:40
jrosserso you've got two options there16:40
*** gshippey has quit IRC16:41
vakuzneti've downdraded to 20.1.1. I think the issue will surface only with self-signed certs.16:44
jrosservakuznet: i will have a different problem, theres no network path at all for that endpoint16:45
*** gyee has joined #openstack-ansible16:46
*** udesale has quit IRC16:53
johnsomIt looks like they left out both interface/endpoint_type and region_name from the keystone endpoint lookup. Sigh16:55
*** jawad_axd has quit IRC16:57
johnsomI have a fix I am going to propose and will poke cores to review and get it out.17:00
jrosserjohnsom: awesome, thankyou for taking a look17:02
johnsomNP. FYI I am going track this here: https://storyboard.openstack.org/#!/story/200786317:05
vakuznetcool. thanks17:42
openstackgerritKevin Carter (cloudnull) proposed openstack/ansible-config_template master: Update config_template to use the builtin _get_remote_user function  https://review.opendev.org/73805817:52
openstackgerritMerged openstack/openstack-ansible-rabbitmq_server master: Add Centos-8 support  https://review.opendev.org/73555217:55
noonedeadpunkjrosser: I'm wondering if didn't we break stein or smth with https://review.opendev.org/#/c/732750/118:03
jrosseroh hmm18:03
jrosserthat has +2 +W on it from before we had other trouble with branchless there18:04
jrosseruncool18:04
noonedeadpunkeventually it can break only train18:05
noonedeadpunkas we didn't use required-repos on stein18:06
jrossershould we just revert?18:06
noonedeadpunkor backport py3 bits...18:07
jrosserbut centos18:08
* jrosser end of day now18:08
noonedeadpunkWe have everything we need to run ansible on py3 on centos, aren't we?18:08
noonedeadpunklike libselinux module18:09
jrosserif it's just the ansible runtime venv then maybe yes18:09
noonedeadpunkI'm not sure, but iirc action plugins are supposed to run on ansible host...18:10
noonedeadpunkalso we probabbly will have issues soon with py2 deployment because of missing py2 pip in default repos...18:11
noonedeadpunkfor centos18:11
noonedeadpunkactually, https://review.opendev.org/#/c/735785/ seems to be ok, so probably I just started panic too early18:12
*** spatel has quit IRC18:15
*** spatel has joined #openstack-ansible18:16
*** mmercer has joined #openstack-ansible18:17
*** markvoelker has joined #openstack-ansible18:21
vakuznetdo you mind reviewing https://review.opendev.org/#/c/737375/ ?18:22
*** Open10K8S has quit IRC18:24
*** Open10K8S has joined #openstack-ansible18:25
noonedeadpunkjamesdenton: I guess there's a reply to your comment, so once you have time on your hands would be cool if you can check this out ^18:26
jamesdentonahh yes, sure thing18:26
*** markvoelker has quit IRC18:26
*** cshen has joined #openstack-ansible18:28
*** cshen has quit IRC18:32
*** jawad_axd has joined #openstack-ansible18:41
*** itandops has quit IRC18:43
openstackgerritMerged openstack/openstack-ansible-galera_server stable/ussuri: Use temporary repository for MariaDB 10.4.14 for Ubuntu focal  https://review.opendev.org/73778219:00
openstackgerritMerged openstack/openstack-ansible-galera_server master: Remove Suse tests.  https://review.opendev.org/73611619:00
openstackgerritMerged openstack/openstack-ansible-galera_server stable/stein: Move to PyMySQL instead of MySQLDB for ansible-2.7  https://review.opendev.org/73129119:00
*** jawad_axd has quit IRC19:15
*** miloa has quit IRC19:18
openstackgerritKevin Carter (cloudnull) proposed openstack/ansible-config_template master: Update config_template to use the builtin _get_remote_user function  https://review.opendev.org/73805819:19
jamesdentonvakuznet were you able to replicate the vlan tag change via an ovs-vsctl command?19:24
jamesdentonWith br-ex:bond1,br-lbaas:bond1.202, the way the task is currently written, it would try to add the bond1.202 interface to br-lbaas and then apply the 202 tag. but bond1.202 doesn't exist19:25
jamesdentonand because bond1 is already attached to br-ex, you couldn't use it for br-lbaas19:25
vakuznetbond1 and bond1.202 interfaces are linux intarfacea and they are precreated19:26
jamesdentonahh ok19:26
jamesdentonso if that's the case, then bond1.202 is already tagged by the OS and you don't need to tag again with ovs19:27
jamesdentonbr-ex:bond1,br-lbaas:bond1.202 would just work19:27
vakuznethttp://paste.openstack.org/show/795227/19:29
*** markvoelker has joined #openstack-ansible19:29
vakuzneti think it needs to be tagged19:29
jamesdentonit is tagged, by the OS19:29
vakuznetlet me find the error i got19:31
vakuznethttp://paste.openstack.org/show/795228/19:33
*** markvoelker has quit IRC19:34
jamesdentonwhere's that tag directive coming from?19:34
jamesdentonone sec19:34
*** cshen has joined #openstack-ansible19:37
vakuznetfrom https://opendev.org/openstack/openstack-ansible-os_neutron/src/branch/master/tasks/providers/ovs_config.yml#L3119:38
jamesdentonyes, but /usr/bin/ovs-vsctl -t 5 set port bond1.566 tag=None and the tag=None is invalid19:39
jamesdentonhttp://paste.openstack.org/show/795229/19:41
jamesdentoni created eno3.3999 and used it for br-ex. the command does not issue the tag argument, and it's null in the args19:41
jamesdenton*br-ex219:41
*** cshen has quit IRC19:41
jamesdentonthe error you got... was that with modified playbooks?19:43
vakuznetno, it's original19:43
jamesdentonhmm. what OS and ansible version?19:44
vakuznetcentos7, ansible comes with osa - it's 2.8.819:44
jamesdentonany chance you could remove the interfaces from your provider bridges (the bond1 and bond1.x) and rerun os-neutron-install.yml with -vvvv?19:53
jamesdentonso we can see what it's doing for both bridges?19:54
jamesdentonand use the vanilla role w/o the patch?19:54
chandankumarjrosser, noonedeadpunk please have  a look at this patch https://review.opendev.org/736507 when free19:58
*** dave-mccowan has quit IRC20:01
*** dave-mccowan has joined #openstack-ansible20:05
vakuznetjamesdenton: i'm running the test20:15
jamesdentonthanks!20:16
*** jawad_axd has joined #openstack-ansible20:32
*** markvoelker has joined #openstack-ansible20:48
*** markvoelker has quit IRC20:53
*** jawad_axd has quit IRC21:06
*** markvoelker has joined #openstack-ansible21:14
*** markvoelker has quit IRC21:18
*** spatel has quit IRC21:26
*** cshen has joined #openstack-ansible21:37
*** cshen has quit IRC21:42
openstackgerritMerged openstack/openstack-ansible-os_horizon stable/ussuri: Compile mod-wsgi module for CentOS 7  https://review.opendev.org/73778421:57
*** jawad_axd has joined #openstack-ansible22:24
*** tosky has quit IRC22:40
*** luksky has quit IRC22:50
*** jawad_axd has quit IRC22:56
*** markvoelker has joined #openstack-ansible23:15
*** markvoelker has quit IRC23:20
openstackgerritMerged openstack/openstack-ansible stable/ussuri: Fix inventory_manage when the component for a host is not defined  https://review.opendev.org/73780323:30
openstackgerritMerged openstack/openstack-ansible stable/ussuri: Correct a typo in the document  https://review.opendev.org/73780923:30
*** cshen has joined #openstack-ansible23:38
*** cshen has quit IRC23:42
*** mrda has quit IRC23:59
*** gyee has quit IRC23:59

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!