*** dviroel|afk is now known as dviroel | 00:26 | |
*** ysandeep|out is now known as ysandeep | 01:53 | |
*** ysandeep is now known as ysandeep|breakfast | 03:14 | |
*** ysandeep|breakfast is now known as ysandeep|afk | 03:35 | |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible stable/xena: Bump keepalived role back https://review.opendev.org/c/openstack/openstack-ansible/+/852934 | 04:42 |
---|---|---|
*** ysandeep|afk is now known as ysandeep | 05:35 | |
noonedeadpunk | fwiw centos 9 seems to be fixed now | 07:21 |
noonedeadpunk | https://zuul.opendev.org/t/openstack/build/f43ea70f8e0d439fa11ebd1363495fc1 | 07:21 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible master: Set the number of threads for processes to 2 https://review.opendev.org/c/openstack/openstack-ansible/+/850942 | 07:24 |
noonedeadpunk | snadge: regarding aodh issue it's caused with this commit if you're interested https://opendev.org/openstack/aodh/commit/0564e94c50f327a36ab686c6a96dd653fe4eceb4 | 07:25 |
noonedeadpunk | I already proposed revert of it and patch u-c as alternative | 07:25 |
*** ysandeep is now known as ysandeep|lunch | 07:31 | |
*** ysandeep|lunch is now known as ysandeep | 08:34 | |
opendevreview | Merged openstack/openstack-ansible-lxc_hosts stable/yoga: Prevent lxc.service from being restarted on package update https://review.opendev.org/c/openstack/openstack-ansible-lxc_hosts/+/852497 | 08:43 |
noonedeadpunk | ok, I have recalled what I tried to cover with keystone X-forwarded-Proto | 08:44 |
noonedeadpunk | basically case when haproxy http -> keystone https, as then we need to set proto http and not https | 08:45 |
noonedeadpunk | That's why or won't work | 08:45 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_keystone master: Fix keystone_secure_proxy_ssl_header logic https://review.opendev.org/c/openstack/openstack-ansible-os_keystone/+/852943 | 08:55 |
noonedeadpunk | jrosser_: please, check this assumption out ^ | 08:55 |
noonedeadpunk | damn, formating went nasty ( | 08:55 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_keystone master: Fix keystone_secure_proxy_ssl_header logic https://review.opendev.org/c/openstack/openstack-ansible-os_keystone/+/852943 | 08:57 |
noonedeadpunk | this one ;) ^ | 08:57 |
noonedeadpunk | well, I see how logic can be simplified now | 08:58 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_keystone master: Fix keystone_secure_proxy_ssl_header logic https://review.opendev.org/c/openstack/openstack-ansible-os_keystone/+/852943 | 08:59 |
andrewbonney | noonedeadpunk: would it be better to fix this in haproxy? That already covers the https case which Apache seems happy to forward if it's not explicitly set. We could explicitly set 'http' as an 'else' for this condition: https://github.com/openstack/openstack-ansible-haproxy_server/blob/master/templates/service.j2#L73 | 09:01 |
noonedeadpunk | I don't think it's enough? | 09:03 |
noonedeadpunk | As here apache is yet another proxy basically | 09:04 |
noonedeadpunk | or well, we need to pass X-Forwarded-Proto that it recieves in request | 09:04 |
andrewbonney | Yeah, I assumed it was doing that by default, but perhaps it doesn't | 09:04 |
noonedeadpunk | I tried to use expr=%{REQUEST_SCHEME} there but I can remember you need to teach apache | 09:05 |
noonedeadpunk | let me try again, I guess I've recalled smth | 09:05 |
* noonedeadpunk haven't really worked with apache for last 4 years | 09:05 | |
andrewbonney | Either way I think the fix you're suggesting will work | 09:06 |
noonedeadpunk | Ah, you needed smth like Real_ip module to get X-Forwarded-* respected | 09:07 |
noonedeadpunk | and probably we don't want that | 09:08 |
noonedeadpunk | or maybe we do.... | 09:08 |
noonedeadpunk | like https://httpd.apache.org/docs/2.4/mod/mod_remoteip.html#remoteipproxyprotocol | 09:09 |
noonedeadpunk | but that's completely different story I guess | 09:12 |
noonedeadpunk | and nah, it does not really respect X-Forwarded-Proto | 09:12 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_keystone master: Fix keystone_secure_proxy_ssl_header logic https://review.opendev.org/c/openstack/openstack-ansible-os_keystone/+/852943 | 09:13 |
*** ysandeep is now known as ysandeep|bbl | 10:05 | |
opendevreview | Merged openstack/openstack-ansible-os_keystone master: Check the service status during bootstrap against the internal VIP https://review.opendev.org/c/openstack/openstack-ansible-os_keystone/+/852451 | 10:48 |
opendevreview | Merged openstack/openstack-ansible-os_keystone master: tls1.2: update ciphers to latest recommendations https://review.opendev.org/c/openstack/openstack-ansible-os_keystone/+/852246 | 10:55 |
opendevreview | Merged openstack/openstack-ansible-lxc_hosts master: Define coherent safe default for package state https://review.opendev.org/c/openstack/openstack-ansible-lxc_hosts/+/852569 | 11:00 |
opendevreview | Merged openstack/openstack-ansible-os_cinder master: Remove oslo_policy section from cinder.conf https://review.opendev.org/c/openstack/openstack-ansible-os_cinder/+/852515 | 11:12 |
*** ysandeep|bbl is now known as ysandeep | 11:16 | |
opendevreview | Merged openstack/openstack-ansible-os_keystone master: Add PKCE method for OIDC https://review.opendev.org/c/openstack/openstack-ansible-os_keystone/+/852390 | 11:30 |
opendevreview | Merged openstack/openstack-ansible-os_horizon master: tls1.2: update ciphers to latest recommendations https://review.opendev.org/c/openstack/openstack-ansible-os_horizon/+/852247 | 11:41 |
opendevreview | Merged openstack/openstack-ansible-os_horizon master: Add support for websso http referer variable added in yoga https://review.opendev.org/c/openstack/openstack-ansible-os_horizon/+/851960 | 12:00 |
opendevreview | Andrew Bonney proposed openstack/openstack-ansible-os_horizon stable/yoga: Add support for websso http referer variable added in yoga https://review.opendev.org/c/openstack/openstack-ansible-os_horizon/+/852952 | 12:03 |
opendevreview | Merged openstack/openstack-ansible master: Remove ironic_compute container from ironic_all https://review.opendev.org/c/openstack/openstack-ansible/+/852197 | 12:19 |
opendevreview | Merged openstack/openstack-ansible master: tls1.2: update ciphers to latest recommendations https://review.opendev.org/c/openstack/openstack-ansible/+/852244 | 12:19 |
*** ysandeep is now known as ysandeep|afk | 12:55 | |
*** ysandeep|afk is now known as ysandeep | 13:52 | |
*** ysandeep is now known as ysandeep|out | 14:04 | |
opendevreview | Merged openstack/openstack-ansible master: Stop NetworkManager on RHEL https://review.opendev.org/c/openstack/openstack-ansible/+/850667 | 14:13 |
opendevreview | Merged openstack/openstack-ansible master: Deprecate openstack_hostnames_ips https://review.opendev.org/c/openstack/openstack-ansible/+/851363 | 14:13 |
*** dviroel is now known as dviroel|out | 14:31 | |
noonedeadpunk | So, if https://review.opendev.org/c/openstack/openstack-ansible-os_keystone/+/852943 works - we should beackport it to Yoga as well, as it's quite valid bug | 15:20 |
noonedeadpunk | ah, and this one https://review.opendev.org/c/openstack/openstack-ansible-os_horizon/+/852952 | 15:23 |
opendevreview | Merged openstack/openstack-ansible-haproxy_server master: tls1.2: update ciphers to latest recommendations https://review.opendev.org/c/openstack/openstack-ansible-haproxy_server/+/852245 | 16:00 |
opendevreview | Burkhard Ott-Langer proposed openstack/openstack-ansible-memcached_server master: bugfix: memcache template variable memcached_file_limits https://review.opendev.org/c/openstack/openstack-ansible-memcached_server/+/853009 | 17:00 |
jrosser_ | watch out for https://bugs.launchpad.net/nova/+bug/1951656 if you update to yoga | 17:35 |
opendevreview | Merged openstack/openstack-ansible stable/xena: Increase ControlPersist timeout to 300 seconds https://review.opendev.org/c/openstack/openstack-ansible/+/852108 | 17:43 |
opendevreview | Jonathan Rosser proposed openstack/openstack-ansible-os_keystone stable/yoga: Add PKCE method for OIDC https://review.opendev.org/c/openstack/openstack-ansible-os_keystone/+/852959 | 17:47 |
opendevreview | Jonathan Rosser proposed openstack/openstack-ansible-os_cinder stable/yoga: Remove oslo_policy section from cinder.conf https://review.opendev.org/c/openstack/openstack-ansible-os_cinder/+/852960 | 17:48 |
opendevreview | Merged openstack/openstack-ansible-os_horizon stable/yoga: Add support for websso http referer variable added in yoga https://review.opendev.org/c/openstack/openstack-ansible-os_horizon/+/852952 | 18:42 |
spatel | jrosser_ good to know that | 19:08 |
spatel | Good news! i have upgraded openstack wallaby running ovn deployment to Xena without any hiccups | 19:09 |
spatel | look like OSA ovn deployment is stable enough now | 19:09 |
opendevreview | Merged openstack/openstack-ansible-os_keystone master: Fix keystone_secure_proxy_ssl_header logic https://review.opendev.org/c/openstack/openstack-ansible-os_keystone/+/852943 | 19:15 |
jamesdenton | nice work | 19:36 |
spatel | jamesdenton are you doing any other experiment with ovn? | 19:52 |
spatel | what next :) | 19:52 |
jamesdenton | nothing substantial, no. I am looking to test the latest OVN+DHCP patches for ironic, though | 19:53 |
jamesdenton | kindof a pain to run legacy dhcp agent, too | 19:53 |
jrosser_ | we never did finish ssl for the OVN stuff properly | 19:55 |
opendevreview | Merged openstack/openstack-ansible stable/xena: Bump keepalived role back https://review.opendev.org/c/openstack/openstack-ansible/+/852934 | 19:59 |
spatel | jrosser_ yes we didn't :( | 20:00 |
spatel | my bad... | 20:00 |
spatel | next month deploying ovn for large scale VDI solution | 20:01 |
spatel | for VDI i need good networking solution so picking OSA+OVN | 20:01 |
spatel | using DVR | 20:02 |
spatel | jrosser_ I will see if i can find some slot or time to look into SSL deployment. | 20:02 |
spatel | if you have time then i can give you recipe because you are most SSL expert here :) | 20:03 |
spatel | In my case i need to understand OSA PKI | 20:03 |
jrosser_ | hopefully it is easy :) | 20:09 |
jrosser_ | there are lots of examples in the code now | 20:09 |
spatel | jrosser_ I am sure you will figure out, here i created blog about OVN SSL - https://satishdotpatel.github.io/ovn-ssl-setup-with-openstack/ | 20:12 |
opendevreview | Merged openstack/openstack-ansible stable/wallaby: Set zuul post-timeout to 3 hours https://review.opendev.org/c/openstack/openstack-ansible/+/847991 | 22:00 |
Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!