opendevreview | Merged openstack/openstack-ansible-os_keystone stable/2024.1: federation: ensure cloud credentials are found on utility host https://review.opendev.org/c/openstack/openstack-ansible-os_keystone/+/934533 | 10:01 |
---|---|---|
opendevreview | Jonathan Rosser proposed openstack/openstack-ansible-os_neutron master: [doc] Add description of the LR binded usecase https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/932616 | 10:07 |
opendevreview | Jonathan Rosser proposed openstack/openstack-ansible stable/2024.1: Bump SHA for rabbitmq_server role https://review.opendev.org/c/openstack/openstack-ansible/+/935494 | 10:11 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible master: Move healthcheck playbooks to the collection https://review.opendev.org/c/openstack/openstack-ansible/+/933611 | 10:24 |
noonedeadpunk | I was thnking to perform sha bumps for 2024.1 overall | 10:28 |
noonedeadpunk | jsut wait for https://review.opendev.org/c/openstack/openstack-ansible-rabbitmq_server/+/931802 and https://review.opendev.org/c/openstack/openstack-ansible-os_rally/+/934815 | 10:28 |
noonedeadpunk | as sooner we get new tag the better... | 10:29 |
jrosser | did we have a topic for moving all the web serving to apache? | 10:29 |
jrosser | i think that the ironic role needs some attention for that | 10:30 |
noonedeadpunk | we had topic only for MPM selection: https://review.opendev.org/q/topic:%22osa/apache_mpm_alignment%22 | 10:31 |
noonedeadpunk | for acpache we agreed only to make a unified role for setup | 10:32 |
noonedeadpunk | but I had no progress there so far | 10:32 |
jrosser | ironic role is still dewplying ngin and fails as a result | 10:51 |
jrosser | *deploying | 10:52 |
noonedeadpunk | I somehow was totally unaware that it's installing nginx | 10:59 |
noonedeadpunk | also I can recall you saying about inspector deprecation | 10:59 |
jrosser | yes it is deprecated, but not removed | 11:33 |
jrosser | i was thinking we could deal with that next cycle | 11:33 |
noonedeadpunk | there was smth we needed to do to allow same functionality from ironic natively? | 11:33 |
opendevreview | Merged openstack/openstack-ansible-os_rally stable/2024.1: Add retries for UC fetching over HTTP https://review.opendev.org/c/openstack/openstack-ansible-os_rally/+/934815 | 11:40 |
jrosser | afaik the same/similar functionality has been merged into ironic itself | 11:47 |
noonedeadpunk | yeah I saw smth related there for sure | 11:47 |
jrosser | so it might need eventually some "sensible defaults" but otherwise overrides would be sufficient | 11:48 |
mgariepy | how far shall we backport this one: https://review.opendev.org/c/openstack/openstack-ansible/+/934686 | 13:27 |
jrosser | would not be a bad thing to put it on all the stable branches | 13:29 |
opendevreview | Marc Gariépy proposed openstack/openstack-ansible stable/2023.2: Deny access to any paths including /. for console proxies. https://review.opendev.org/c/openstack/openstack-ansible/+/935515 | 13:32 |
opendevreview | Marc Gariépy proposed openstack/openstack-ansible stable/2023.1: Deny access to any paths including /. for console proxies. https://review.opendev.org/c/openstack/openstack-ansible/+/935516 | 13:39 |
opendevreview | Marcus Klein proposed openstack/openstack-ansible-ops master: Fix Grafana deployment https://review.opendev.org/c/openstack/openstack-ansible-ops/+/935520 | 14:12 |
kleini | ^^^ as previously discussed. traefik_common role in skydive requires Ansible fact vars | 14:15 |
noonedeadpunk | I recently made a patch to elk just converting facts to reffer correctly | 14:16 |
noonedeadpunk | but I haven't looked into rest | 14:16 |
noonedeadpunk | https://review.opendev.org/c/openstack/openstack-ansible-ops/+/934547 | 14:16 |
noonedeadpunk | so in case some time on hands, I'd really prefer fixing vars used then enabling injection... | 14:17 |
kleini | https://github.com/grafana/grafana-ansible-collection/blob/main/roles/grafana/tasks/main.yml#L9 grafana collection still relies on ansible_ vars | 14:20 |
kleini | same for Prometheus collection | 14:21 |
jrosser | anyone fancy making a PR for those? | 14:30 |
noonedeadpunk | fwiw, I was able to get elk bits running standalone | 15:02 |
noonedeadpunk | (also to realize that journalbeat is replaced with filebeat anyway) | 15:02 |
noonedeadpunk | btw, somehow struggling with filebeat picking up journals for now... | 15:02 |
opendevreview | Merged openstack/openstack-ansible-rabbitmq_server stable/2024.1: Proceed with installation/upgrade even if cluster not healthy https://review.opendev.org/c/openstack/openstack-ansible-rabbitmq_server/+/931802 | 17:40 |
opendevreview | Merged openstack/openstack-ansible stable/2023.2: Deny access to any paths including /. for console proxies. https://review.opendev.org/c/openstack/openstack-ansible/+/935515 | 18:39 |
opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible stable/2024.1: Bump SHAs for 2024.1 https://review.opendev.org/c/openstack/openstack-ansible/+/935557 | 19:22 |
sykebenX | Hello, does anyone know whether there is a way to do hostname-based routing for openstack APIs and have them all bind to port 443 on HAProxy instead? I prefer not to have all the API services hosted on other ports since then I have to create firewall rules for 8-9 ports rather than just doing everything over 443 | 19:45 |
mgariepy | something like : https://review.opendev.org/c/openstack/openstack-ansible/+/934536 | 19:46 |
mgariepy | ? | 19:46 |
noonedeadpunk | there's renderred version that easier to read:) https://b4eff72617e82999ea33-03e51d134fc1c044893e5fb53732499a.ssl.cf5.rackcdn.com/934536/8/check/openstack-tox-docs/d360b2e/docs/user/prod/pretty_endpoint_naming.html | 19:53 |
mgariepy | it has colors ! | 19:54 |
noonedeadpunk | it's it really needs quite some overrides to happen, I'd say... | 19:54 |
noonedeadpunk | but already having couple of deployments on hand with this approach | 19:54 |
Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!