openstackgerrit | Merged openstack/openstack-ansible-os_manila master: Add centos-8 support https://review.opendev.org/739646 | 00:30 |
---|---|---|
*** gyee has quit IRC | 01:04 | |
*** MickyMan77 has joined #openstack-ansible | 01:17 | |
*** MickyMan77 has quit IRC | 01:25 | |
*** bgmccollum has joined #openstack-ansible | 01:47 | |
*** cyberpear has joined #openstack-ansible | 02:04 | |
*** bgmccollum has left #openstack-ansible | 02:07 | |
*** MickyMan77 has joined #openstack-ansible | 02:42 | |
*** MickyMan77 has quit IRC | 02:51 | |
*** cshen has joined #openstack-ansible | 03:02 | |
*** cshen has quit IRC | 03:07 | |
-openstackstatus- NOTICE: We are investigating an issue with our hosted Gerrit services. We will provide an update as soon as we can. If you want to follow the latest, feel free to join #opendev | 03:24 | |
*** miloa has joined #openstack-ansible | 04:07 | |
-openstackstatus- NOTICE: We identified a possible vulnerability in Gerrit and are investigating the potential impact on our services. Out of an abundance of caution we have taken our OpenDev hosted Gerrit system offline. We will update with more information once we are able. | 04:28 | |
*** evrardjp has quit IRC | 04:33 | |
*** evrardjp has joined #openstack-ansible | 04:33 | |
*** MickyMan77 has joined #openstack-ansible | 04:42 | |
*** suryasingh has joined #openstack-ansible | 04:46 | |
*** MickyMan77 has quit IRC | 04:51 | |
*** cshen has joined #openstack-ansible | 05:03 | |
*** cshen has quit IRC | 05:07 | |
*** cshen has joined #openstack-ansible | 06:00 | |
*** cshen has quit IRC | 06:04 | |
*** PTO has quit IRC | 06:17 | |
*** ianychoi_ has joined #openstack-ansible | 06:23 | |
*** ianychoi has quit IRC | 06:27 | |
*** sshnaidm|afk is now known as sshnaidm | 06:44 | |
*** frenzyfriday has joined #openstack-ansible | 06:48 | |
noonedeadpunk | seems today is a day off from upstream work:) | 06:49 |
*** PTO has joined #openstack-ansible | 06:55 | |
*** cshen has joined #openstack-ansible | 07:00 | |
*** rpittau|afk is now known as rpittau | 07:04 | |
*** andrewbonney has joined #openstack-ansible | 07:10 | |
*** PTO is now known as pto | 07:12 | |
*** shyamb has joined #openstack-ansible | 07:26 | |
*** mmethot_ has joined #openstack-ansible | 07:31 | |
*** mmethot has quit IRC | 07:33 | |
*** _mmethot_ has joined #openstack-ansible | 07:33 | |
*** shyam89 has joined #openstack-ansible | 07:34 | |
*** shyamb has quit IRC | 07:37 | |
*** mmethot_ has quit IRC | 07:37 | |
*** tosky has joined #openstack-ansible | 07:43 | |
*** shyam89 has quit IRC | 08:32 | |
-openstackstatus- NOTICE: We identified a possible vulnerability in Gerrit and are investigating the potential impact on our services. Out of an abundance of caution we have taken our OpenDev hosted Gerrit system offline. We will update with more information once we are able. | 08:34 | |
*** ChanServ changes topic to "We identified a possible vulnerability in Gerrit and are investigating the potential impact on our services. Out of an abundance of caution we have taken our OpenDev hosted Gerrit system offline. We will update with more information once we are able." | 08:34 | |
jrosser | morning | 09:03 |
noonedeadpunk | o/ | 09:04 |
*** shyamb has joined #openstack-ansible | 09:23 | |
*** fridtjof[m] has quit IRC | 09:24 | |
*** ioni has quit IRC | 09:24 | |
*** masterpe has quit IRC | 09:25 | |
pto | morning | 09:25 |
pto | jrosser: Do you have time to discuss the federated identity bugs today? | 09:25 |
*** gshippey has joined #openstack-ansible | 09:26 | |
noonedeadpunk | has it anything common with https://bugs.launchpad.net/bugs/1900410 or https://bugs.launchpad.net/bugs/1900407 ? | 09:27 |
openstack | Launchpad bug 1900410 in openstack-ansible "fatal: [os_infra1_keystone_container-5999bd47]: FAILED! => {"attempts": 5, "changed": false, "msg": "No package matching 'libcurl3' is available"}" [Undecided,In progress] - Assigned to Jonathan Rosser (jrosser) | 09:27 |
openstack | Launchpad bug 1900407 in openstack-ansible "Error when evaluating variable in import path: keystone_{{ keystone_web_server }}.yml." [Undecided,New] | 09:27 |
pto | I have submitted both | 09:27 |
noonedeadpunk | ah | 09:27 |
noonedeadpunk | then we have solution for both :p | 09:28 |
pto | Crewl :-) | 09:28 |
noonedeadpunk | but since gerrit is not working, we can't really show patches... | 09:28 |
jrosser | i'll have one of them locally, just a moment | 09:29 |
noonedeadpunk | well, jrosser made patch for libcurl3 and I was going to patch another bug today but gerrit is not working | 09:29 |
noonedeadpunk | for 1900407 quick workaround will be to place keystone_sp inside user_variables but not group_vars or host_vars | 09:30 |
jrosser | pto: here is the patch for libcurl3 http://paste.openstack.org/show/799198/ | 09:31 |
jrosser | i think for focal it's possible to co-install the shibboleth and oidc apacge modules because they both depend on libcurl4, so some of the conditional logic in the focal vars file is removed there | 09:32 |
jrosser | gshippey: would be good if you could check what ive done there? | 09:32 |
gshippey | looking :) | 09:33 |
*** fridtjof[m] has joined #openstack-ansible | 09:34 | |
pto | jrosser: i will test it right away | 09:39 |
*** shyam89 has joined #openstack-ansible | 09:39 | |
pto | I have uploaded the full config (sanitized) to my git: https://github.com/pertoft/openstack-ansible-deployment/tree/master/openstack_deploy | 09:39 |
pto | Could you give it a quick look to validate its not my fault :-) | 09:39 |
jrosser | gshippey: we didnt have to do anything like this that i can find? https://github.com/pertoft/openstack-ansible-deployment/blob/master/openstack_deploy/user_variables.yml#L282 | 09:40 |
jrosser | see the error in bug 1900407 | 09:40 |
openstack | bug 1900407 in openstack-ansible "Error when evaluating variable in import path: keystone_{{ keystone_web_server }}.yml." [Undecided,New] https://launchpad.net/bugs/1900407 | 09:40 |
gshippey | if federation is being deployed you shouldnt have to specify apache as far as I'm aware | 09:40 |
jrosser | ansible seems to blow up on the task import here https://github.com/openstack/openstack-ansible-os_keystone/blob/2b125eca319271b9ad8fc700f5b5aba00dc09037/tasks/main.yml#L152 | 09:41 |
gshippey | in relation to your patch jon, that should be fine in letting both packages being installed side by side, but the logic i put in https://github.com/openstack/openstack-ansible-os_keystone/blob/dcc16da7e20f50e1f9e9cd56170427ec9491d15c/tasks/main.yml#L51 will prevent anyone from deploying both at once, so may need to look at that | 09:41 |
*** shyamb has quit IRC | 09:42 | |
jrosser | gshippey: i guess we could allow both to be deployed on an OS that supports both packages present at once | 09:46 |
pto | I just did cd /etc/ansible/roles/os_keystone; git fetch; git reset --hard origin/master; git apply idp.patch | 09:47 |
pto | And it appears to have broken the os_keystone module ERROR! couldn't resolve module/action 'community.mysql.mysql_db'. This often indicates a misspelling, missing collection, or incorrect module path. | 09:47 |
pto | What is the correct way to rollback to the release tag? | 09:47 |
jrosser | oh right, yeah | 09:47 |
jrosser | which release is this? | 09:47 |
gshippey | yes, shouldn't be an issue having them side by side. I can confirm at we don't set keystone_web_server anywhere in our user_variables | 09:48 |
*** sshnaidm is now known as sshnaidm|afk | 09:48 | |
jrosser | pto: i think that your os_keystone repo would have been checked out to the correct SHA - no need to do git reset --hard origin/master | 09:49 |
jrosser | pto: the way to find the correct SHA for your release is to look here (this is an example for stable/ussuri) https://github.com/openstack/openstack-ansible/blob/stable/ussuri/ansible-role-requirements.yml#L59 | 09:55 |
jrosser | pto: the only difference i see between my keystone_sp and yours is that i have not used any {{ variables }} at all inside that dict | 09:58 |
*** masterpe has joined #openstack-ansible | 09:59 | |
*** ioni has joined #openstack-ansible | 09:59 | |
*** shyam89 has quit IRC | 10:02 | |
*** shyamb has joined #openstack-ansible | 10:03 | |
pto | Shoud i remove "keystone_web_server: apache" from user_variables.yml? | 10:13 |
pto | jrosser: The patch seem to work when the keystone_web_server is defined. However, im still stuck at "Ensure Role for external IDP users exists" | 10:18 |
gshippey | what is the error you are getting there? | 10:18 |
*** recyclehero has quit IRC | 10:20 | |
*** recyclehero has joined #openstack-ansible | 10:22 | |
pto | gshippey: http://paste.openstack.org/show/799202/ | 10:22 |
pto | gshippey: TASK [os_keystone : Ensure Group for external IDP users exists] | 10:24 |
pto | Oops. The paste was trucated | 10:25 |
pto | Here is the error shown: http://paste.openstack.org/show/799203/ | 10:27 |
pto | "msg": "Failed to get domain Default: Client Error for url: http://172.21.224.254:5000/v3/domains/Default, Could not find domain: Default." | 10:29 |
jrosser | are we talking about the same thing? the paste shows a templating error | 10:32 |
jrosser | it looks like this line https://github.com/openstack/openstack-ansible-os_keystone/blob/master/tasks/keystone_federation_sp_idp_setup.yml#L67 has got included in the previous multiline string which is really strange | 10:34 |
gshippey | https://docs.openstack.org/api-ref/identity/v3/#show-domain-details, shows that the domain id should be used. In this case https://github.com/pertoft/openstack-ansible-deployment/blob/655531057931ff03fc73c7b0e6ada31ad6b9e908/openstack_deploy/user_variables.yml#L303 should be default (lower case) | 11:00 |
gshippey | knowing when to reference Default (domain name) or default (domain id) can be quite frustrating and it's got me a few times too! | 11:01 |
-openstackstatus- NOTICE: Update on gerrit downtime: After investigation, we believe the incident is related to a compromised Gerrit user account rather than a vulnerability in Gerrit software. We are continuing to review activity to verify the integrity of git data and expect to have an additional update with possible service restoration in approximately 2 hours. | 11:03 | |
*** mgariepy has quit IRC | 11:03 | |
*** ChanServ changes topic to "Update on gerrit downtime: After investigation, we believe the incident is related to a compromised Gerrit user account rather than a vulnerability in Gerrit software. We are continuing to review activity to verify the integrity of git data and expect to have an additional update with possible service restoration in approximately 2 hours." | 11:03 | |
*** shyamb has quit IRC | 11:07 | |
*** shyamb has joined #openstack-ansible | 11:10 | |
*** mbuil has quit IRC | 11:22 | |
*** mbuil has joined #openstack-ansible | 11:23 | |
*** SecOpsNinja has joined #openstack-ansible | 11:30 | |
pto | gshippey: Sorry. I linked the wrong paste. Here is the correct one with the right error: http://paste.openstack.org/show/799205/ | 11:30 |
pto | I suspect its to be a firewall issue, where the vip.examlpe.com:5000 is not accessible from the outside. Do you know if this should be open for SAML2 "callback"? | 11:30 |
*** yann-kaelig has joined #openstack-ansible | 11:32 | |
*** frenzyfriday has quit IRC | 11:34 | |
*** shyamb has quit IRC | 11:36 | |
*** rh-jelabarre has joined #openstack-ansible | 12:01 | |
pto | gshippey: Regarding the domain name vs id. The code snip is exactly as in the reference example in the openstack-ansible-os_keystone/defaults/main.yml | 12:02 |
pto | gshippey: But you are right, fixing the domain: Default -> domain: default fixed it | 12:02 |
*** mgariepy has joined #openstack-ansible | 12:06 | |
pto | Is is possible to propose pull request when gerrit is down? | 12:09 |
*** rfolco has joined #openstack-ansible | 12:15 | |
*** sshnaidm|afk is now known as sshnaidm | 12:20 | |
*** scanepa has quit IRC | 12:41 | |
gshippey | @pto in regards to the firewall, your user agent (browser) needs to be able to communicate with keystone, but keystone should not need access to your IDP. Looking at the flows https://docs.openstack.org/keystone/latest/admin/federation/introduction.html may be useful. Will need to get the documentation updated around D/default! | 13:02 |
*** sc has joined #openstack-ansible | 13:03 | |
pto | gshippey: Thanks for the clarifications. It works when the domain was changed from Default to default. I will make a pull request and update the docs when gerrit comes back | 13:13 |
-openstackstatus- NOTICE: We've confirmed that known compromised identities have been reset or had their accounts disabled, and we are auditing other service accounts for signs of compromise before we prepare to restore Gerrit to working order. We will update again in roughly 2 hours. | 13:31 | |
*** ChanServ changes topic to "We've confirmed that known compromised identities have been reset or had their accounts disabled, and we are auditing other service accounts for signs of compromise before we prepare to restore Gerrit to working order. We will update again in roughly 2 hours." | 13:31 | |
SecOpsNinja | hi. in openstack_user_config.yml is there any way, for example, shared-infra_hosts define 3 nodes but say for example that one of them shouln't install for example rabbitmq? | 13:38 |
jrosser | SecOpsNinja: yes you can do that - the best way would be to not define shared-infra_hosts at all | 13:43 |
jrosser | for the example of rabbitmq you can see here https://github.com/openstack/openstack-ansible/blob/master/inventory/env.d/rabbitmq.yml#L25-L26 | 13:44 |
jrosser | rabbitmq containers are in the host group shared-infra_containers and mq_containers | 13:45 |
SecOpsNinja | but if i removed from openstack_user_config.yml i need to defined them for each service that is going to use it? | 13:46 |
jrosser | that means you could define mq_hosts to point to only two of your infra hosts and database_hosts to point to all three | 13:46 |
jrosser | yes you would | 13:46 |
jrosser | this can be an easy config, look at this that was shared earlier https://github.com/pertoft/openstack-ansible-deployment/blob/master/openstack_deploy/openstack_user_config.yml#L104-L105 | 13:47 |
SecOpsNinja | but can i maintain the existing shared-infra_hosts with 3 (because of galera cluster) and only for haproxy define only 2 on that override right? | 13:48 |
jrosser | you'd be replacing shared-infra_hosts with lines for database_hosts, mq_hosts, memcaching_hosts and operator_hosts | 13:49 |
SecOpsNinja | ok that is interesting because i can reduce the number of times i define my infraestructure nodes in each group | 13:50 |
jrosser | SecOpsNinja: i am confused about haproxy, i think that is defined by haproxy_hosts but not in the wider shared-infra_hosts group | 13:50 |
SecOpsNinja | but for the rabbitmq problem it seams that i need to overide so it doesnt install in one of the infraescture nodes? | 13:50 |
jrosser | it's not an override | 13:50 |
jrosser | shared-infra_hosts is an ansible group which will contain all of galera/rabbit/memcached/utility *if* you define it | 13:51 |
jrosser | if you want to change the service layout from that then you should not define it | 13:51 |
SecOpsNinja | in the exmaple it says | 13:51 |
SecOpsNinja | # galera, memcache, rabbitmq, utility | 13:51 |
SecOpsNinja | shared-infra_hosts: | 13:51 |
jrosser | this link is important https://github.com/openstack/openstack-ansible/blob/master/inventory/env.d/rabbitmq.yml#L25-L26 | 13:52 |
*** sshnaidm is now known as sshnaidm|afk | 13:52 | |
jrosser | the hosts for rabbitmq containers are defined by either mq_hosts or shared-infra_hosts | 13:53 |
jrosser | if you want a specific layout for rabbitmq then you should define mq_hosts and not shared-infra_hosts | 13:53 |
SecOpsNinja | yep the problem is that i mess the instalation regarding rabbitmq before installing 2ª and 3ª nodes and now the first instalation is also failing. what i think was to try to override rabiitmq settings to think that only as 1 member that is the first node but mantain the setting of the 3 nodes in the shared-infra_hosts... | 13:53 |
*** wpp has quit IRC | 13:59 | |
*** wpp has joined #openstack-ansible | 14:01 | |
SecOpsNinja | jrosser, let me see if i can understand how can i resolve this without messing with the other service like galera that is using the shared-infra_hosts with 3 nodes. So the recomendation is not define any hosts in https://github.com/pertoft/openstack-ansible-deployment/blob/master/openstack_deploy/openstack_user_config.yml#L104-L105 but use mq_host? | 14:02 |
jrosser | if you want a custom layout of the services then i think you need to define them individually rather than use shared-infra_hosts | 14:05 |
SecOpsNinja | ok i will try to override my instalation with that to see if i can resolve my problem. thank jrosser | 14:06 |
jrosser | i am not sure this is going to resolve a broken rabbitmq installation though? | 14:06 |
SecOpsNinja | i have the rabbitmq runing in 1º node becuase i removed all the othe nodes. the problems is that i have all in shared-infra_hosts whe it runs TASK [rabbitmq_server : Apply rabbitmq policies] tryies to apply to 2ª and 3ª nodes | 14:08 |
SecOpsNinja | and because i messed my instalation with ips in container is then worse... but i think i resolved that problm but was forced to reconfigure some service because of each container ip | 14:08 |
*** spatel has joined #openstack-ansible | 14:11 | |
*** sshnaidm|afk is now known as sshnaidm | 14:12 | |
*** cshen has quit IRC | 14:12 | |
pto | I deleted all containers (lxc-container-destroy.yml) and ran everything again. This time keystone is breaking, because the table is locked by the sql trigger. Commenting out keystone_federation_sp_idp_setup.yml and running it later or running keystone-manage db_sync --contract will fix the problem. Any clues why this happes? I have cleaned the ansible facts on the host | 14:31 |
*** macz_ has joined #openstack-ansible | 14:48 | |
*** cshen has joined #openstack-ansible | 14:51 | |
-openstackstatus- NOTICE: Auditing is progressing but not particularly quickly. We'll keep updating every 2 hours or so. | 15:39 | |
*** ChanServ changes topic to "Auditing is progressing but not particularly quickly. We'll keep updating every 2 hours or so." | 15:39 | |
*** spatel has quit IRC | 15:46 | |
*** klamath_atx has joined #openstack-ansible | 15:49 | |
*** gyee has joined #openstack-ansible | 15:50 | |
noonedeadpunk | #startmeeting openstack_ansible_meeting | 16:00 |
openstack | Meeting started Tue Oct 20 16:00:16 2020 UTC and is due to finish in 60 minutes. The chair is noonedeadpunk. Information about MeetBot at http://wiki.debian.org/MeetBot. | 16:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 16:00 |
*** openstack changes topic to " (Meeting topic: openstack_ansible_meeting)" | 16:00 | |
openstack | The meeting name has been set to 'openstack_ansible_meeting' | 16:00 |
noonedeadpunk | #topic office hours | 16:00 |
*** openstack changes topic to "office hours (Meeting topic: openstack_ansible_meeting)" | 16:00 | |
noonedeadpunk | well, seems we can't discuss today our current status and patches that are due because of the gerrit situation | 16:01 |
*** klamath_atx has quit IRC | 16:01 | |
noonedeadpunk | but we can probably discuss plan for ptg that will take place next monday | 16:02 |
noonedeadpunk | #link https://etherpad.opendev.org/p/osa-wallaby-ptg | 16:02 |
*** miloa has quit IRC | 16:02 | |
noonedeadpunk | I've just placed topics in the doc we took for V | 16:02 |
noonedeadpunk | we didn't do much since we had really lot's of stuff on our hands with centos 8, ubuntu focal, new ceph and galera and etc | 16:03 |
jrosser | o/ hello | 16:04 |
noonedeadpunk | I think we still can do several during this cycle:) like mark nspawn for removal for example | 16:06 |
jrosser | i get kind of fed up trying to fix the roles there | 16:06 |
jrosser | we also have to do some migration on ansible group names | 16:07 |
noonedeadpunk | so they have only underscore? | 16:07 |
noonedeadpunk | `TRANSFORM_INVALID_GROUP_CHARS`? | 16:07 |
noonedeadpunk | well yes, this seems like important part | 16:08 |
jrosser | yes was just looking at https://docs.ansible.com/ansible/latest/reference_appendices/config.html#transform-invalid-group-chars | 16:08 |
noonedeadpunk | well, I see nothing about it's deprecation.... | 16:09 |
jrosser | iirc it's in the warnings on the zuul logs :/ | 16:09 |
jrosser | maybe 2.12? cant remember | 16:10 |
jamesdenton | o/ hi | 16:10 |
*** cshen has quit IRC | 16:10 | |
jrosser | hello | 16:11 |
noonedeadpunk | well, there would be deprecated_in option then... | 16:11 |
noonedeadpunk | hey! | 16:11 |
noonedeadpunk | s/option/field | 16:11 |
jamesdenton | i see ironic listed as a broken role. what's broken? besides inspector... | 16:11 |
noonedeadpunk | I think it was result of haproxy tbh | 16:13 |
noonedeadpunk | and probably it's fixed nowadays - dunno.... | 16:13 |
jamesdenton | oh, the baremetal issue? | 16:13 |
noonedeadpunk | hard to say without gerrit | 16:13 |
jamesdenton | hah yeah | 16:13 |
jrosser | oh hold on | 16:14 |
jamesdenton | the one day i have some patches to upload... | 16:14 |
jrosser | the logs still work | 16:14 |
jrosser | if you've got emails from gerrit the links to job results are still working | 16:14 |
noonedeadpunk | well, I have 2700 emails from gerrit at the moment.... | 16:14 |
jamesdenton | i don't have them. | 16:15 |
jrosser | heres what happened in the last os_ironic job http://paste.openstack.org/show/799220/ | 16:15 |
noonedeadpunk | https://zuul.opendev.org/t/openstack/build/f65e2435af0f448a8a13bfbcbea0de23 | 16:15 |
noonedeadpunk | ok | 16:16 |
*** ianychoi_ is now known as ianychoi | 16:16 | |
jrosser | looks like db setup? | 16:17 |
noonedeadpunk | looks like swidft issue | 16:17 |
noonedeadpunk | Account POST failed: http://172.29.236.101:8080/v1/AUTH_3e09bb30f84c4e2d98c249da5a48bb14 503 Service Unavailable [first 60 chars of response] b'<html><body><h1>503 Service Unavailable</h1>\\nNo server is av'" | 16:17 |
nurdie | Does anyone know of any writeups, additional help, or examples for deploying Magnum on an existing OSA cluster? I find the existing "openstack-ansible-os_magnum/latest" to be mildly daunting | 16:18 |
jamesdenton | jrosser noonedeadpunk might be easier for me to pull down master and run tests locally | 16:18 |
noonedeadpunk | oh, and swift can;'t work with bind-to-mgmt at the moment | 16:19 |
noonedeadpunk | https://zuul.opendev.org/t/openstack/build/9e9e951822754be9b544bbce8066141a/log/logs/host/swift-proxy-server.service.journal-11-21-58.log.txt#63 | 16:19 |
noonedeadpunk | well, seems we've missed it | 16:19 |
jrosser | oh no! missed one | 16:19 |
jamesdenton | is there no var set for that? | 16:19 |
jamesdenton | kk | 16:19 |
noonedeadpunk | well, if it wasn;'t swift, I'd say we will easily fix that... | 16:20 |
noonedeadpunk | but at least we understand the issue:) | 16:20 |
jrosser | https://github.com/openstack/openstack-ansible-os_swift/blob/master/templates/proxy-server.conf.j2#L6 | 16:22 |
noonedeadpunk | yeah. the thing is it has more bindings:) | 16:22 |
noonedeadpunk | but probably we don't use haproxy for them.... | 16:23 |
jrosser | https://github.com/openstack/openstack-ansible-os_swift/blob/master/defaults/main.yml#L231-L237 | 16:24 |
jamesdenton | there's a similar issue i found with the spicehtml5proxy service. i defaults to 0.0.0.0 and you need to set html5proxy_host (!= server_listen) | 16:24 |
jamesdenton | i have a patching waiting | 16:24 |
noonedeadpunk | awesome | 16:25 |
jrosser | thats kind of interesting defauilting the swift ports to ansible_host | 16:25 |
jrosser | that means storage traffic on the mgmt network even though theres a storage interface? wonder what the intention is here | 16:25 |
noonedeadpunk | yeah.... but anyway, the only problem should probably be swift-proxy, as we use only 8080 in haproxy | 16:26 |
noonedeadpunk | jrosser: well, in aio we have storage traffic over mgmt anyway - ceph does exact same thing | 16:26 |
jrosser | it does | 16:26 |
noonedeadpunk | nothing to be proud of but we have what we have | 16:27 |
noonedeadpunk | but agree that super weird | 16:28 |
jrosser | theres storage and storage i guess | 16:28 |
jrosser | iscsi != swift != ceph | 16:28 |
noonedeadpunk | but all of them are supposed to use storage net by default anyway? except swift proxy or rgw, which is under haproxy | 16:30 |
noonedeadpunk | ah, another question - have anyone played with new pip resolver? | 16:32 |
noonedeadpunk | except placing patch which has shown that we don't fit | 16:32 |
noonedeadpunk | as I wanted to look into it during this week | 16:33 |
*** mgariepy has quit IRC | 16:35 | |
jrosser | i've not done anything beyond the patch to test it | 16:36 |
jrosser | i think i figured some new defaults/overrides need adding to python-venv-build | 16:36 |
jrosser | as the existing var to enable things like the new resolver gets passed to the system python before you upgrade the one in the venv | 16:37 |
jrosser | and the system python doesnt understand the new flags, so that needs splitting into two vars | 16:37 |
jrosser | sorry system pip | 16:38 |
*** rpittau is now known as rpittau|afk | 16:38 | |
noonedeadpunk | sounds reasonable despite I didn't have much dive into the topic yet | 16:40 |
noonedeadpunk | well, moving to it might be challenging | 16:41 |
jrosser | seems to be what we put in constraints for source git repos now needs to be in requirements, or similar | 16:41 |
noonedeadpunk | yep | 16:41 |
noonedeadpunk | that the only thing I brought out of this actually | 16:42 |
jrosser | and i guess we have to be careful to keep python2 support there for the os_tempest role | 16:42 |
noonedeadpunk | I'm wondering if tripleo uses py3 for centos7 there | 16:43 |
noonedeadpunk | as probably we shouldn't be so carefull:) | 16:43 |
noonedeadpunk | arxcruz: have any insights?:) | 16:47 |
noonedeadpunk | well, will ask them later then | 16:54 |
noonedeadpunk | #endmeeting | 16:54 |
*** openstack changes topic to "Auditing is progressing but not particularly quickly. We'll keep updating every 2 hours or so." | 16:54 | |
openstack | Meeting ended Tue Oct 20 16:54:53 2020 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 16:54 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/openstack_ansible_meeting/2020/openstack_ansible_meeting.2020-10-20-16.00.html | 16:54 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/openstack_ansible_meeting/2020/openstack_ansible_meeting.2020-10-20-16.00.txt | 16:54 |
openstack | Log: http://eavesdrop.openstack.org/meetings/openstack_ansible_meeting/2020/openstack_ansible_meeting.2020-10-20-16.00.log.html | 16:54 |
*** mgariepy has joined #openstack-ansible | 17:09 | |
arxcruz | noonedeadpunk: sorry, late here, i'm pretty sure it has python3 but i can double check tomorrow | 17:10 |
*** gyee has quit IRC | 17:10 | |
noonedeadpunk | well, then we can at least don't care about py2 in tempest | 17:12 |
noonedeadpunk | *os_tempest | 17:12 |
*** cshen has joined #openstack-ansible | 17:18 | |
*** gyee has joined #openstack-ansible | 17:21 | |
*** cshen has quit IRC | 17:23 | |
*** SecOpsNinja has left #openstack-ansible | 17:27 | |
-openstackstatus- NOTICE: Gerrit is offline due to a security compromise. Please refer to https://review.opendev.org/maintenance.html or #opendev for the latest updates. | 17:59 | |
*** ChanServ changes topic to "Gerrit is offline due to a security compromise. Please refer to https://review.opendev.org/maintenance.html or #opendev for the latest updates." | 17:59 | |
recyclehero | jrosser: hi, do u have the patch u made for nova allocation ratios at hand? | 18:01 |
*** cshen has joined #openstack-ansible | 18:03 | |
*** andrewbonney has quit IRC | 18:09 | |
*** cshen has quit IRC | 18:11 | |
*** MickyMan77 has joined #openstack-ansible | 18:29 | |
noonedeadpunk | the latest gerrit news are super sad | 18:31 |
noonedeadpunk | we've landed tons of things for the last 3 weeks.... | 18:31 |
*** MickyMan77 has quit IRC | 18:37 | |
guilhermesp | noonedeadpunk: yeah that's pretty sad , lets hope things gets less damaged | 18:45 |
*** tosky has quit IRC | 19:54 | |
*** cshen has joined #openstack-ansible | 20:07 | |
*** cshen has quit IRC | 20:11 | |
*** thefish has joined #openstack-ansible | 20:11 | |
thefish | jrosser: thank you that makes sense (i ended up rerunning them all as per your first comment, but ill use this next time) - I guess also these are all idempotent as well, is that right? | 20:13 |
*** yolanda has quit IRC | 20:24 | |
*** yolanda has joined #openstack-ansible | 20:24 | |
jrosser | thefish: yes, they should be idempotent | 20:48 |
*** rfolco has quit IRC | 20:56 | |
*** MickyMan77 has joined #openstack-ansible | 21:01 | |
MickyMan77 | How can I solve this issue that I have with boto3, Could not load 'glance.store.s3.Store': No module named 'boto3' ---> http://paste.openstack.org/show/799233/ | 21:06 |
jrosser | MickyMan77: i do not think that boto3 missing is causing it to fail, see a similar thing here https://bugs.launchpad.net/kolla/+bug/1884259 | 21:18 |
openstack | Launchpad bug 1884259 in kolla "Glance Ussuri missing boto3 after S3 backend addition" [Undecided,Invalid] | 21:18 |
jrosser | i would be much more trying to find out what is causing "rados.PermissionDeniedError: [errno 13] RADOS permission denied (error connecting to the cluster)" | 21:18 |
*** yann-kaelig has quit IRC | 21:46 | |
*** cshen has joined #openstack-ansible | 22:07 | |
*** cshen has quit IRC | 22:11 | |
*** gshippey has quit IRC | 22:18 | |
*** nurdie has quit IRC | 22:53 | |
*** jbadiapa has quit IRC | 22:54 | |
*** thefish has quit IRC | 23:00 | |
*** macz_ has quit IRC | 23:13 | |
*** spatel has joined #openstack-ansible | 23:18 | |
*** spatel has quit IRC | 23:23 | |
*** MickyMan77 has quit IRC | 23:24 | |
*** spatel has joined #openstack-ansible | 23:34 | |
*** renich has joined #openstack-ansible | 23:56 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!