*** gyee has quit IRC | 01:06 | |
*** evrardjp has quit IRC | 02:33 | |
*** evrardjp has joined #openstack-ansible | 02:33 | |
*** pto has joined #openstack-ansible | 04:52 | |
*** pto has joined #openstack-ansible | 04:53 | |
*** pto has quit IRC | 05:19 | |
*** prometheanfire has quit IRC | 05:27 | |
*** prometheanfire has joined #openstack-ansible | 05:28 | |
*** shyamb has joined #openstack-ansible | 06:05 | |
*** miloa has joined #openstack-ansible | 06:27 | |
*** pto has joined #openstack-ansible | 06:28 | |
*** miloa has quit IRC | 06:28 | |
jrosser | morning | 06:53 |
---|---|---|
*** macz_ has joined #openstack-ansible | 07:02 | |
*** sshnaidm|afk has quit IRC | 07:03 | |
*** macz_ has quit IRC | 07:07 | |
*** sshnaidm has joined #openstack-ansible | 07:20 | |
openstackgerrit | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_masakari stable/victoria: Replace deprecated host param for monitors https://review.opendev.org/c/openstack/openstack-ansible-os_masakari/+/790558 | 07:21 |
*** andrewbonney has joined #openstack-ansible | 07:23 | |
*** shyamb has quit IRC | 07:25 | |
*** crazzy has quit IRC | 07:38 | |
*** rpittau|afk is now known as rpittau | 07:38 | |
openstackgerrit | Merged openstack/openstack-ansible-os_masakari master: setup.cfg: Replace dashes with underscores https://review.opendev.org/c/openstack/openstack-ansible-os_masakari/+/788399 | 07:39 |
*** tosky has joined #openstack-ansible | 07:39 | |
*** waxfire has quit IRC | 07:49 | |
noonedeadpunk | mornings | 07:50 |
*** waxfire has joined #openstack-ansible | 07:50 | |
noonedeadpunk | andrewbonney: sorry, was off yestarday | 07:50 |
*** oleksandry has joined #openstack-ansible | 07:51 | |
andrewbonney | no worries | 07:53 |
noonedeadpunk | there's a patch for that (eventualy even 2 of them) | 08:04 |
noonedeadpunk | I think mainly we kind of aim for https://review.opendev.org/c/openstack/openstack-ansible/+/789776/ | 08:05 |
*** shyamb has joined #openstack-ansible | 08:12 | |
*** shyamb has quit IRC | 08:33 | |
*** shyamb has joined #openstack-ansible | 08:34 | |
*** oleksandry has quit IRC | 08:36 | |
openstackgerrit | Andrew Bonney proposed openstack/ansible-role-pki master: WIP - create certificate authorities https://review.opendev.org/c/openstack/ansible-role-pki/+/787404 | 08:43 |
openstackgerrit | Andrew Bonney proposed openstack/ansible-role-pki master: WIP - Create server certificates https://review.opendev.org/c/openstack/ansible-role-pki/+/788021 | 08:43 |
openstackgerrit | Andrew Bonney proposed openstack/ansible-role-pki master: WIP - Experiment with molecule testing https://review.opendev.org/c/openstack/ansible-role-pki/+/790594 | 08:43 |
*** macz_ has joined #openstack-ansible | 08:45 | |
*** waxfire has quit IRC | 08:48 | |
*** macz_ has quit IRC | 08:50 | |
*** pto has quit IRC | 08:50 | |
*** pto has joined #openstack-ansible | 09:05 | |
*** pto_ has joined #openstack-ansible | 09:11 | |
*** pto_ has joined #openstack-ansible | 09:11 | |
*** pto has quit IRC | 09:14 | |
*** maharg101 has joined #openstack-ansible | 09:17 | |
*** pto_ has quit IRC | 09:17 | |
*** pto has joined #openstack-ansible | 09:20 | |
*** macz_ has joined #openstack-ansible | 09:55 | |
*** macz_ has quit IRC | 10:00 | |
*** pto has quit IRC | 10:01 | |
*** pto has joined #openstack-ansible | 10:01 | |
noonedeadpunk | can we kindly merge https://review.opendev.org/c/openstack/openstack-ansible/+/790359 ? we need to do last release and prepare for EM-ing Train | 10:03 |
*** pto has quit IRC | 10:08 | |
openstackgerrit | Dmitriy Rabotyagov proposed openstack/openstack-ansible stable/train: Prepare Train to EM https://review.opendev.org/c/openstack/openstack-ansible/+/790655 | 10:23 |
*** shyamb has quit IRC | 10:33 | |
admin0 | is there any file in OSA that can tell me about what branch the repo is in | 10:56 |
admin0 | there is a very old cluster ( neuton/ocata/pike -- one of those) .. where the osa repo was changed and merged as a new git master branch internally .. i need to upgrade this osa .. but since i don't have the original version info, i am checking here if there is any file in the osa deploy that can give me an idea of the branch | 10:58 |
admin0 | or the tag | 10:58 |
admin0 | i think found one -- openstack_ansible.egg-info/PKG-INFO | 11:00 |
*** pto has joined #openstack-ansible | 11:11 | |
*** pto has quit IRC | 11:21 | |
*** shyamb has joined #openstack-ansible | 11:25 | |
*** shyamb has quit IRC | 11:27 | |
*** jbadiapa has quit IRC | 11:31 | |
*** pto has joined #openstack-ansible | 11:35 | |
*** pto has quit IRC | 11:41 | |
*** pto has joined #openstack-ansible | 11:42 | |
*** jbadiapa has joined #openstack-ansible | 11:43 | |
*** pto has quit IRC | 11:47 | |
*** pto has joined #openstack-ansible | 11:51 | |
manti | I need to disable vxlan setup, preferably so that everything else still keeps working... Would simply setting neutron_vxlan_enabled=false to user_variables accomplish this even though even openstack_user_config would still have vxlan type network defined? | 11:55 |
*** pto has quit IRC | 11:55 | |
manti | Or actually, what I really need is a way to set the default network type as vlan, when the network is created from horizon. But disabling the vxlan is only thing that came to mind | 11:56 |
*** pto has joined #openstack-ansible | 12:02 | |
*** dpawlik has quit IRC | 12:12 | |
jrosser | manti: i think that the only way you can do that is to disable vxlan, otherwise you'll get vxlan networks by default | 12:12 |
jrosser | it's not really a horizon issue, it would happen also at the CLI when you create a network as a non-admin, the next available one in the database is given out to normal users. Theres no way to choose the type | 12:13 |
jrosser | you'd have to experiment with neutron_vxlan_enabled to see if thats sufficient, vxlan is also listed in tenant_network_types in ml2_conf.ini | 12:19 |
*** dpawlik3 has joined #openstack-ansible | 12:20 | |
*** dpawlik3 is now known as dpawlik | 12:26 | |
manti | ok, have to try it out | 12:27 |
manti | I'm using CLI as admin, so didn't think that the type option is not available for non-admins | 12:27 |
jrosser | you can create vlan provider networks as an admin and share them with specific projects using neutron RBAC | 12:33 |
jrosser | it really depends what you want to achieve | 12:33 |
manti | I want the vlan to be default, so that in 3/6/12 months when I have forgotten that new network must be created as admin and with specific type, I don't accidentally get vxlan type network and spend hours finding out why it doesn't work | 12:37 |
manti | second option is documenting the whole thing, but I suspect reading the document is not the first thing that happens if there is a need to create new network for some tests or something | 12:39 |
openstackgerrit | Merged openstack/openstack-ansible stable/train: Bump SHAs for stable/train https://review.opendev.org/c/openstack/openstack-ansible/+/790359 | 12:42 |
*** dwilde has joined #openstack-ansible | 12:53 | |
*** spatel_ has joined #openstack-ansible | 13:00 | |
*** spatel_ is now known as spatel | 13:00 | |
openstackgerrit | Jonathan Rosser proposed openstack/openstack-ansible-haproxy_server master: WIP - Use external PKI role to manage haproxy self-signed certificates https://review.opendev.org/c/openstack/openstack-ansible-haproxy_server/+/790078 | 13:01 |
openstackgerrit | Jonathan Rosser proposed openstack/ansible-role-pki master: WIP - Create server certificates https://review.opendev.org/c/openstack/ansible-role-pki/+/788021 | 13:03 |
*** dwilde has quit IRC | 13:04 | |
*** dwilde has joined #openstack-ansible | 13:25 | |
openstackgerrit | Jonathan Rosser proposed openstack/openstack-ansible master: WIP - Test PKI role https://review.opendev.org/c/openstack/openstack-ansible/+/788031 | 13:26 |
jrosser | noonedeadpunk: i think i've done as much as a want to on the PKI role for the time being, in case theres some issue needs dealing with | 13:26 |
jrosser | you were right though about nova-conductor, there is an issue with that | 13:27 |
noonedeadpunk | o_O molecule test | 13:28 |
jrosser | well yeah, just playing/experiment | 13:28 |
jrosser | the templated transport_url is causing some trouble for nova | 13:29 |
jrosser | as far as i can see it's not picking up ssl_version from the config file | 13:30 |
*** dwilde has quit IRC | 13:34 | |
noonedeadpunk | hm, at it's not valid for query either, right? as see no https://www.rabbitmq.com/uri-query-parameters.html | 13:36 |
jrosser | noonedeadpunk: for the galera 10.5.10 patch i could just revert the previos release note | 13:36 |
jrosser | though i wasnt sure if that was a good thing to do or not | 13:36 |
noonedeadpunk | oh, well, thinking about reverting release not, I'm not sure either if it's good idea... | 13:37 |
noonedeadpunk | I think it should be fine.... | 13:37 |
noonedeadpunk | but can't recall doing that actually | 13:37 |
jrosser | it would be tidier, becasue it's kind of like 10.5.9 never happend for W | 13:39 |
noonedeadpunk | yeah | 13:39 |
jrosser | i am wondering if https://www.rabbitmq.com/uri-query-parameters.html are the same as transport_url query parameters, because even ssl=1 is not one of the rabbitmq ones | 13:43 |
jrosser | i think there is parsing of this in nova | 13:43 |
noonedeadpunk | yep, tempalte parses transport_url - that's 100% | 13:43 |
noonedeadpunk | cell template | 13:43 |
openstackgerrit | Jonathan Rosser proposed openstack/openstack-ansible-galera_server master: Update mariadb version to 10.5.10 https://review.opendev.org/c/openstack/openstack-ansible-galera_server/+/790329 | 13:45 |
jrosser | i think what i'm not understanding is why the ssl_version setting is in [oslo_messaging_rabbit] and how that can be affected by using a transport_url template, or not | 13:53 |
noonedeadpunk | well, template is stored inside nova database in cell. And conductor with request to it evaluates this template based on the transport_url only. | 13:56 |
*** dwilde has joined #openstack-ansible | 13:57 | |
jrosser | the version looks like it is set OK https://zuul.opendev.org/t/openstack/build/dfeadfcf2f90485f940288f6bf620779/log/logs/openstack/aio1_nova_api_container-352f42ff/nova-conductor.service.journal-18-02-02.log.txt#1616 | 13:57 |
noonedeadpunk | this is from config opts I guess | 13:58 |
jrosser | yeah, and i think i expect that to be used by oslo.messaging, not nova itself | 13:58 |
*** dwilde has quit IRC | 13:59 | |
noonedeadpunk | yeah, I think that's the question here | 13:59 |
*** dwilde has joined #openstack-ansible | 13:59 | |
noonedeadpunk | s/question/problem/ | 13:59 |
noonedeadpunk | so we kind of need to either find and fix default tls version, or find the way to pass version as a part of the query | 14:00 |
noonedeadpunk | even if not to use template in cell, it won't solve issue I think | 14:02 |
noonedeadpunk | as still we need to pass everything required to the connection string itself | 14:02 |
jrosser | whats a bit surprising is that as far as i can tell, other things are working OK with this configuration | 14:03 |
noonedeadpunk | I think literally no other service does store database connection credentials in database... | 14:03 |
noonedeadpunk | (and messaging as well) | 14:04 |
noonedeadpunk | https://docs.openstack.org/oslo.messaging/latest/reference/transport.html#oslo_messaging.TransportURL `Permits passing driver-specific options which override the corresponding values from the configuration file` | 14:05 |
noonedeadpunk | have you tried setting just `ssl_version` as query arg? | 14:06 |
noonedeadpunk | *param | 14:06 |
jrosser | no, i've not, can try though | 14:06 |
jrosser | maybe if that works out ok then it's time to ask the nova people what they expect for this | 14:06 |
jrosser | as thats exactly what i saw in the docs and thought it would be fine to leave the normal entry in the config file | 14:07 |
jrosser | but maybe the docs don't quite mean that | 14:07 |
noonedeadpunk | yeah, I think just docs are confusing really | 14:07 |
noonedeadpunk | as for nova case you need to have that nasty url either in config, or populate database with it | 14:08 |
noonedeadpunk | well, or split nova.conf and nova-conductor.conf | 14:08 |
jrosser | oh well there is that whole business of db connection strings too | 14:11 |
noonedeadpunk | yep | 14:11 |
noonedeadpunk | they literally store db connection params in db | 14:11 |
*** macz_ has joined #openstack-ansible | 14:15 | |
openstackgerrit | Merged openstack/openstack-ansible-os_masakari stable/victoria: Replace deprecated host param for monitors https://review.opendev.org/c/openstack/openstack-ansible-os_masakari/+/790558 | 14:16 |
noonedeadpunk | ah, you mean alike with rabbit | 14:17 |
noonedeadpunk | #startmeeting openstack_ansible_meeting | 15:02 |
openstack | Meeting started Tue May 11 15:02:55 2021 UTC and is due to finish in 60 minutes. The chair is noonedeadpunk. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:02 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:02 |
*** openstack changes topic to " (Meeting topic: openstack_ansible_meeting)" | 15:02 | |
openstack | The meeting name has been set to 'openstack_ansible_meeting' | 15:03 |
noonedeadpunk | #topic office hours | 15:03 |
*** openstack changes topic to "office hours (Meeting topic: openstack_ansible_meeting)" | 15:03 | |
noonedeadpunk | o/ | 15:03 |
*** dave-mccowan has quit IRC | 15:10 | |
jrosser | o/ sorry in another meeting for a while | 15:12 |
noonedeadpunk | np) | 15:12 |
noonedeadpunk | so, the main thing from me, is that this week we move train to EM | 15:13 |
noonedeadpunk | also https://review.opendev.org/c/openstack/openstack-ansible/+/790042 is super close, but upgrade jobs fail in pretty frustrating way tbh | 15:14 |
noonedeadpunk | oh, well, once I said that, I got the reason:) | 15:15 |
noonedeadpunk | I had pretty short previous week because of public holidays here, so didn't acomplish much | 15:16 |
noonedeadpunk | centos failure for manila is an issue btw, which prevents from fixing a lot of the stuff for the role | 15:17 |
noonedeadpunk | and it's failing with connection timeouts, like it's oom, but see nothing that would point to it in logs | 15:17 |
noonedeadpunk | and test_mount_share_one_vm passes there... | 15:18 |
noonedeadpunk | so really not sure what's wrong there - probably should spawn an aio to check out | 15:19 |
noonedeadpunk | Regarding PKI role - looks really awesome. | 15:19 |
noonedeadpunk | I think I will try it out during the week and check how things look like with it | 15:19 |
jrosser | i need to push a few syntax fixes later | 15:19 |
noonedeadpunk | probably worth slowly removing wip? | 15:20 |
jrosser | but i think i'm very happy with how it's slotted into rabbitmq and haproxy | 15:20 |
noonedeadpunk | yeah, roles are now soooo much cleaner | 15:20 |
noonedeadpunk | with amount of stuff dropped from them | 15:20 |
noonedeadpunk | will try to also pick this up and do galera part in case you haven't started that yet | 15:21 |
jrosser | sure, that would be really nice validation if someone other than me could understand and use it | 15:21 |
noonedeadpunk | also massive part there would be documentation of the way we handle SSLs nowadays | 15:22 |
noonedeadpunk | but lets merge main things first | 15:22 |
jrosser | i did a small part on that in the latest WIP patch to openstack-ansible | 15:22 |
jrosser | but i think it needs some thought as it's kind of totally configurable | 15:22 |
noonedeadpunk | oh, I think I just haven't seen it yet :( | 15:22 |
noonedeadpunk | I think except rabbit/galera/haproxy would be awesome to finally encrypt live migrations as well, but I suspect that there might be pretty tricky things | 15:24 |
noonedeadpunk | oh, wait. don't we leverage https://review.opendev.org/c/openstack/openstack-ansible-haproxy_server/+/790078/5/tasks/haproxy_ssl_key_distribute.yml for let's encrypt? | 15:25 |
jrosser | no, each instance is independant | 15:25 |
noonedeadpunk | even when we first time issue? | 15:26 |
jrosser | i think with the PKI role it will run for each host | 15:26 |
jrosser | rather than need to distribute, and it puts in a SAN for the external_vip | 15:26 |
noonedeadpunk | but for sun you need dns-01? | 15:27 |
jrosser | no, only for wildcard | 15:27 |
jrosser | oh well hold on | 15:27 |
noonedeadpunk | ah, ok, agree, sorry | 15:27 |
jrosser | for the initial selfsigned kind of anything will do | 15:27 |
jrosser | just enough to make haproxy start | 15:27 |
noonedeadpunk | hm, I stopped understanding how lets encrypt works in our scenario :( to make it issue cert we need to stop all haproxy except one, so that VIP was moving between nodes? | 15:31 |
noonedeadpunk | otherwise how it's passing http-01 | 15:32 |
noonedeadpunk | (without shared storage at least) | 15:32 |
jrosser | no they all run | 15:32 |
jrosser | there is a backend to haproxy which looks for N possible certbots running | 15:32 |
noonedeadpunk | oh | 15:33 |
jrosser | there will only ever be one running on one haproxy when the cert is issued / renewed for *that* node | 15:33 |
jrosser | we use haproxy to direct traffic from the VIP to the backend that needs it | 15:33 |
noonedeadpunk | yeah, agree | 15:33 |
noonedeadpunk | I kind of recalled why I did all sorts of nasty stuff when wanted let's encrypt to be issues certs behind haproxy | 15:34 |
noonedeadpunk | because that haproxy was in octavia, so disregard please:) | 15:34 |
jrosser | aah ok | 15:34 |
noonedeadpunk | I wonder if we can in some time also cover internal endpoints with ssl having pki role on hands | 15:35 |
jrosser | so i was thinking were do we want to call "done" for W | 15:35 |
noonedeadpunk | well, we can, technically, but I meant more about if it makes sense | 15:35 |
jrosser | it could be haproxy+rabbit then the rabbit and tempest problems go away | 15:36 |
jrosser | ssl for everything else could be for X | 15:36 |
noonedeadpunk | haproxy+rabbit+galera? | 15:36 |
jrosser | could do | 15:36 |
noonedeadpunk | we can stop actually just with rabbit. but want to play with role anyway) | 15:37 |
jrosser | haproxy might need some work to have different certs on the inside and outside | 15:37 |
jrosser | that would be ideal to terminate and re-encrypt with the private CA | 15:37 |
noonedeadpunk | I'd say let's do this for X ? | 15:38 |
jrosser | i would say yes, keep it minimal for W | 15:38 |
noonedeadpunk | For W I think we need to repair manila and adjutant at least | 15:38 |
jrosser | it also protects against problem / design issue with the PKI role as it's use is quite minimal | 15:38 |
noonedeadpunk | oh, well, Bullseye image has landed | 15:39 |
noonedeadpunk | so probably worth looking it's shape... | 15:39 |
jrosser | yeah, maybe even condsidering making W the transition if it was possible | 15:39 |
jrosser | to reduce the amount of stuff to cover for X | 15:40 |
noonedeadpunk | yeah... | 15:40 |
jrosser | could probably find in ~ 1 day if it's going to work or not | 15:40 |
noonedeadpunk | jsut found your comments on https://review.opendev.org/c/openstack/openstack-ansible/+/789376 - will take care of them | 15:41 |
noonedeadpunk | I also have pretty vague memories about distro upgrade path... | 15:41 |
openstackgerrit | Dmitriy Rabotyagov proposed openstack/openstack-ansible master: [DNM] Add Debian Bullseye support https://review.opendev.org/c/openstack/openstack-ansible/+/783606 | 15:53 |
openstackgerrit | Dmitriy Rabotyagov proposed openstack/openstack-ansible master: [DNM] Add Debian Bullseye support https://review.opendev.org/c/openstack/openstack-ansible/+/783606 | 15:57 |
noonedeadpunk | #endmeeting | 15:57 |
*** openstack changes topic to "Launchpad: https://launchpad.net/openstack-ansible || Weekly Meetings: https://wiki.openstack.org/wiki/Meetings/openstack-ansible || Review Dashboard: http://bit.ly/osa-review-board-v3" | 15:57 | |
openstack | Meeting ended Tue May 11 15:57:35 2021 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:57 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/openstack_ansible_meeting/2021/openstack_ansible_meeting.2021-05-11-15.02.html | 15:57 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/openstack_ansible_meeting/2021/openstack_ansible_meeting.2021-05-11-15.02.txt | 15:57 |
openstack | Log: http://eavesdrop.openstack.org/meetings/openstack_ansible_meeting/2021/openstack_ansible_meeting.2021-05-11-15.02.log.html | 15:57 |
*** jamesden_ has joined #openstack-ansible | 16:16 | |
*** jamesdenton has quit IRC | 16:17 | |
*** dwilde has quit IRC | 16:18 | |
*** dwilde has joined #openstack-ansible | 16:25 | |
*** dwilde has quit IRC | 16:35 | |
*** rpittau is now known as rpittau|afk | 16:36 | |
*** dwilde has joined #openstack-ansible | 16:41 | |
*** andrewbonney has quit IRC | 17:07 | |
*** dwilde has quit IRC | 17:34 | |
*** spatel has quit IRC | 17:42 | |
*** dwilde has joined #openstack-ansible | 17:48 | |
*** spatel_ has joined #openstack-ansible | 17:57 | |
*** spatel_ is now known as spatel | 17:57 | |
*** dwilde has quit IRC | 18:05 | |
*** dwilde has joined #openstack-ansible | 18:07 | |
*** pto has quit IRC | 18:19 | |
*** pto has joined #openstack-ansible | 18:35 | |
*** gyee has joined #openstack-ansible | 18:45 | |
*** dwilde has quit IRC | 19:39 | |
*** spatel has quit IRC | 19:50 | |
*** dwilde has joined #openstack-ansible | 19:57 | |
*** macz_ has quit IRC | 20:09 | |
*** rh-jelabarre has quit IRC | 20:09 | |
*** Adri2000 has quit IRC | 20:09 | |
*** macz_ has joined #openstack-ansible | 20:13 | |
*** rh-jelabarre has joined #openstack-ansible | 20:13 | |
*** Adri2000 has joined #openstack-ansible | 20:13 | |
*** fridtjof[m] has quit IRC | 20:16 | |
*** manti has quit IRC | 20:16 | |
*** masterpe has quit IRC | 20:16 | |
openstackgerrit | Slawek Kaplonski proposed openstack/openstack-ansible-os_tempest master: Make list of Neutron API extensions to be configurable https://review.opendev.org/c/openstack/openstack-ansible-os_tempest/+/790818 | 20:28 |
*** masterpe has joined #openstack-ansible | 20:37 | |
*** masterpe has quit IRC | 21:02 | |
*** dwilde has quit IRC | 21:03 | |
*** manti has joined #openstack-ansible | 21:08 | |
*** fridtjof[m] has joined #openstack-ansible | 21:14 | |
*** masterpe has joined #openstack-ansible | 21:30 | |
*** kleini has quit IRC | 22:24 | |
*** Carcer has quit IRC | 23:08 | |
*** Carcer has joined #openstack-ansible | 23:08 | |
*** macz_ has quit IRC | 23:17 | |
*** tosky has quit IRC | 23:24 | |
*** ebbex has quit IRC | 23:31 | |
*** ebbex has joined #openstack-ansible | 23:51 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!