opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_cinder master: Implement variables to address oslo.messaging improvements https://review.opendev.org/c/openstack/openstack-ansible-os_cinder/+/914143 | 07:21 |
---|---|---|
noonedeadpunk | o/ | 08:14 |
noonedeadpunk | so, I think I was able to make a working apache config for Skyline | 08:23 |
noonedeadpunk | smth like this: https://paste.openstack.org/show/bjmrjAn8qGclV24Wqf49/ | 08:26 |
jrosser_ | o/ morning | 08:32 |
noonedeadpunk | but kinda lack time to further work on that.... I think main idea for apache (except alignment) was shiboleth support or oidc? | 08:48 |
opendevreview | Andrew Bonney proposed openstack/openstack-ansible master: Remove service-specific tags from service playbooks https://review.opendev.org/c/openstack/openstack-ansible/+/918615 | 08:52 |
opendevreview | Andrew Bonney proposed openstack/openstack-ansible master: docs: demonstrate quick method to move between HA/Quorum queues https://review.opendev.org/c/openstack/openstack-ansible/+/919062 | 08:52 |
jrosser_ | noonedeadpunk: yes, if you want horizon+oidc then it must be apache | 08:54 |
jrosser_ | and i think we were talking about trying to collapse to just one web server for everything especially for metal deploys | 08:55 |
jrosser_ | we really do have a ton of stuff to merge for the oslo messaging improvements | 09:03 |
noonedeadpunk | yeah, I found a mistake during weekends I patched... | 09:08 |
noonedeadpunk | so it should be fine now | 09:08 |
noonedeadpunk | though some services are borked | 09:08 |
noonedeadpunk | like zun and masakari at least | 09:08 |
jrosser_ | yeah i was just looking trying to work out what was actual errors an what was CI failures | 09:08 |
jrosser_ | but still quite some CI failures, and lots of them feel like on rocky | 09:09 |
jrosser_ | andrew had a query on this as well https://review.opendev.org/c/openstack/openstack-ansible-os_trove/+/917226 | 09:09 |
noonedeadpunk | and on upgrade jobs? | 09:09 |
noonedeadpunk | ah, yes... | 09:10 |
noonedeadpunk | and also trove tempest testing failing on not having shared network | 09:10 |
noonedeadpunk | (which is last patch in series) | 09:11 |
noonedeadpunk | actually it's a good question of what behaviour it should be | 09:12 |
jrosser_ | then also i was wondering why this was abandoned https://review.opendev.org/c/openstack/openstack-ansible-os_cinder/+/919083/1 | 09:13 |
jrosser_ | probably i miss something there | 09:13 |
noonedeadpunk | I've realized that previous patch in chain was failing without it, so I squashed it | 09:14 |
jrosser_ | oh yes i see now - i was looking at rev3 of the previous patch | 09:15 |
noonedeadpunk | about trove - my idea was that you kinda should be able to just disable notification regardless designate/ceilometer... | 09:15 |
noonedeadpunk | like trove_guest_oslomsg_notify_configure for having precedence... but not sure it's right... | 09:16 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_trove master: Add variable to globally control notifications enablement https://review.opendev.org/c/openstack/openstack-ansible-os_trove/+/917226 | 09:17 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_trove master: Implement variables to address oslo.messaging improvements https://review.opendev.org/c/openstack/openstack-ansible-os_trove/+/917997 | 09:18 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_tempest master: Add ability to make public network shared https://review.opendev.org/c/openstack/openstack-ansible-os_tempest/+/919489 | 09:43 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible master: Add trove tempest testing https://review.opendev.org/c/openstack/openstack-ansible/+/784379 | 09:45 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_trove master: Manage trove images through openstack_resources role https://review.opendev.org/c/openstack/openstack-ansible-os_trove/+/918103 | 09:45 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible master: Add trove tempest testing https://review.opendev.org/c/openstack/openstack-ansible/+/784379 | 09:46 |
opendevreview | Merged openstack/openstack-ansible-os_tacker master: Add service policies defenition https://review.opendev.org/c/openstack/openstack-ansible-os_tacker/+/919071 | 10:42 |
opendevreview | Merged openstack/openstack-ansible-os_nova master: Add service policies defenition https://review.opendev.org/c/openstack/openstack-ansible-os_nova/+/919074 | 10:44 |
opendevreview | Merged openstack/openstack-ansible-os_nova master: Add variable to globally control notifications enablement https://review.opendev.org/c/openstack/openstack-ansible-os_nova/+/919076 | 10:46 |
opendevreview | Merged openstack/openstack-ansible-os_tacker master: Add variable to globally control notifications enablement https://review.opendev.org/c/openstack/openstack-ansible-os_tacker/+/919072 | 10:49 |
opendevreview | Merged openstack/openstack-ansible-os_tacker master: Implement variables to address oslo.messaging improvements https://review.opendev.org/c/openstack/openstack-ansible-os_tacker/+/919073 | 10:49 |
opendevreview | Merged openstack/openstack-ansible-os_designate master: Add qos_prefetch_count to variables https://review.opendev.org/c/openstack/openstack-ansible-os_designate/+/919085 | 10:54 |
opendevreview | Merged openstack/openstack-ansible-os_mistral master: Implement variables to address oslo.messaging improvements https://review.opendev.org/c/openstack/openstack-ansible-os_mistral/+/918128 | 10:54 |
opendevreview | Merged openstack/openstack-ansible-os_cloudkitty master: Add qos_prefetch_count to variables https://review.opendev.org/c/openstack/openstack-ansible-os_cloudkitty/+/919084 | 10:56 |
opendevreview | Merged openstack/openstack-ansible-os_swift master: Add service policies defenition https://review.opendev.org/c/openstack/openstack-ansible-os_swift/+/919070 | 10:58 |
opendevreview | Merged openstack/openstack-ansible-os_barbican master: Add qos_prefetch_count to variables https://review.opendev.org/c/openstack/openstack-ansible-os_barbican/+/919079 | 10:58 |
noonedeadpunk | and I think manila even don't start jobs as probably has broken zuul config | 10:58 |
opendevreview | Merged openstack/openstack-ansible-os_heat master: Add qos_prefetch_count to variables https://review.opendev.org/c/openstack/openstack-ansible-os_heat/+/919088 | 10:58 |
opendevreview | Merged openstack/openstack-ansible-os_nova master: Implement variables to address oslo.messaging improvements https://review.opendev.org/c/openstack/openstack-ansible-os_nova/+/919077 | 11:00 |
jrosser_ | yes there is something strange with the manila jobs indeed | 11:01 |
opendevreview | Merged openstack/openstack-ansible-os_octavia master: Add service policies defenition https://review.opendev.org/c/openstack/openstack-ansible-os_octavia/+/919067 | 11:02 |
opendevreview | Merged openstack/openstack-ansible-os_keystone master: Add qos_prefetch_count to variables https://review.opendev.org/c/openstack/openstack-ansible-os_keystone/+/919089 | 11:05 |
opendevreview | Jonathan Rosser proposed openstack/openstack-ansible master: Collect kubelet logs generated on magnum k8s control plane https://review.opendev.org/c/openstack/openstack-ansible/+/919493 | 11:12 |
opendevreview | Jonathan Rosser proposed openstack/openstack-ansible-os_magnum master: DNM - 919493 https://review.opendev.org/c/openstack/openstack-ansible-os_magnum/+/919494 | 11:13 |
opendevreview | Merged openstack/openstack-ansible-os_neutron master: Add service policies defenition https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/919051 | 11:15 |
opendevreview | Merged openstack/openstack-ansible-os_neutron master: Add variable to globally control notifications enablement https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/919055 | 11:19 |
opendevreview | Merged openstack/openstack-ansible-os_neutron master: Implement variables to address oslo.messaging improvements https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/919059 | 11:27 |
opendevreview | Merged openstack/openstack-ansible-ceph_client master: Switch default ceph version to reef https://review.opendev.org/c/openstack/openstack-ansible-ceph_client/+/917015 | 11:29 |
opendevreview | Merged openstack/openstack-ansible-ceph_client master: reno: Update master for unmaintained/zed https://review.opendev.org/c/openstack/openstack-ansible-ceph_client/+/919126 | 12:05 |
opendevreview | Merged openstack/openstack-ansible-os_cinder master: Implement variables to address oslo.messaging improvements https://review.opendev.org/c/openstack/openstack-ansible-os_cinder/+/914143 | 13:14 |
opendevreview | Merged openstack/openstack-ansible stable/2023.2: Bump SHAs for 2023.2 https://review.opendev.org/c/openstack/openstack-ansible/+/919044 | 13:20 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_trove master: Manage trove images through openstack_resources role https://review.opendev.org/c/openstack/openstack-ansible-os_trove/+/918103 | 13:25 |
noonedeadpunk | damiandabrowski: can you take a look at https://review.opendev.org/c/openstack/openstack-ansible/+/916900 please? as this makes distro job for EL to fail | 13:32 |
noonedeadpunk | (due to absent murano client) | 13:32 |
noonedeadpunk | (it also has 1 unmerged dependency) | 13:33 |
noonedeadpunk | https://review.opendev.org/c/openstack/openstack-ansible-os_murano/+/916891 | 13:33 |
*** Guest6102 is now known as starkis | 13:40 | |
opendevreview | Merged openstack/openstack-ansible-os_murano master: reno: Update master for unmaintained/zed https://review.opendev.org/c/openstack/openstack-ansible-os_murano/+/919178 | 13:52 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_skyline master: Add designate and masakari to service mapping https://review.opendev.org/c/openstack/openstack-ansible-os_skyline/+/919523 | 13:57 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_skyline master: Reflect keystone service variables in config https://review.opendev.org/c/openstack/openstack-ansible-os_skyline/+/918160 | 14:00 |
opendevreview | Merged openstack/openstack-ansible-os_murano master: Preserve actual production playbook in examples https://review.opendev.org/c/openstack/openstack-ansible-os_murano/+/916891 | 14:21 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_skyline master: Switch nginx with Apache https://review.opendev.org/c/openstack/openstack-ansible-os_skyline/+/919529 | 15:03 |
noonedeadpunk | jrosser_: this pretty much works for me, at least on Ubuntu aio ^ | 15:09 |
noonedeadpunk | one thing I don't know how to workaround - binding gunicorn to unix socket as was with nginx | 15:10 |
noonedeadpunk | seems apache really wants to have port binding | 15:10 |
noonedeadpunk | and from here - I think we can potentially proceed with internal TLS and might be oidc bits? | 15:11 |
jrosser_ | tbh i have no idea about the oidc bit | 15:15 |
jrosser_ | as skyline seem to only care about oauth | 15:16 |
jrosser_ | which != oidc | 15:16 |
noonedeadpunk | `Add single sign-on (SSO) support. Skyline login with SSO configured with OpenID Connect.` ? https://docs.openstack.org/releasenotes/skyline-apiserver/zed.html | 15:17 |
noonedeadpunk | like I have no idea how to configure that properly... But on other side - I don't know precisely how to do that in horizon either.... | 15:18 |
noonedeadpunk | OpenID Connect is OIDC, right? | 15:29 |
noonedeadpunk | the patch: https://review.opendev.org/c/openstack/skyline-apiserver/+/852394 | 15:31 |
jrosser_ | yes that is openid | 15:35 |
jrosser_ | any everything about all of that is using confusing / contradictory / not precise terms | 15:40 |
jrosser_ | *and | 15:40 |
jrosser_ | for example /o\ https://bugs.launchpad.net/skyline-apiserver/+bug/1972736 | 15:41 |
noonedeadpunk | yeah... this is the patch related to the report.... | 15:52 |
noonedeadpunk | I kinda really struggle to find anything configurable about skyline frankly speaking... | 15:52 |
noonedeadpunk | like - hide Domain dropdown, as that is /o\ in multi-domain setups | 15:52 |
noonedeadpunk | s/hide/let it be a field/ | 15:53 |
jrosser_ | i still think that in their sso stuff they talk about (and mean) openid | 15:54 |
jrosser_ | mention of openid-connect feels wrong - else it is somehow working magically and theres just a total lack of documentation | 15:56 |
noonedeadpunk | well, documentation is just absent | 15:58 |
noonedeadpunk | it's very hard to argue | 15:59 |
jrosser_ | tbh i could be totally wrong about all this as well | 16:00 |
jrosser_ | as actually the mod_auth_oidc stuff is in the keystone tole | 16:01 |
jrosser_ | role | 16:01 |
* noonedeadpunk needs to catch up on keyscloack/oidc/saml asap.... | 16:11 | |
jrosser_ | hmm zun looks to have some sql mess https://zuul.opendev.org/t/openstack/build/c8a58e43598d44b2a794a9c656b26f6f/log/logs/host/zun-compute.service.journal-20-21-23.log.txt | 16:57 |
jrosser_ | masakari upgrade jobs look like te fail db sync | 16:58 |
opendevreview | Merged openstack/openstack-ansible-os_octavia master: Add variable to globally control notifications enablement https://review.opendev.org/c/openstack/openstack-ansible-os_octavia/+/919068 | 18:11 |
opendevreview | Merged openstack/openstack-ansible master: Move Murano/Senlin/Sahara to Inactive state https://review.opendev.org/c/openstack/openstack-ansible/+/916900 | 20:58 |
Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!