Monday, 2025-10-06

opendevreviewMerged openstack/openstack-ansible-os_tempest master: setup.cfg: Replace dashes with underscores  https://review.opendev.org/c/openstack/openstack-ansible-os_tempest/+/96090711:56
admin1noonedeadpunk jrosser damiandabrowski .. you guy will be in the paris summit ? 12:27
damiandabrowskime and noonedeadpunk will be there ;) 12:28
admin1will meet you guys again then .. 12:50
damiandabrowskicool!13:06
noonedeadpunksweeeeet13:12
noonedeadpunklong time no see as well :)13:12
noonedeadpunkdamiandabrowski: I've just realized we don't have any way to set a lifetime for standalone certs atm?13:16
* noonedeadpunk looking at https://review.opendev.org/c/openstack/ansible-role-pki/+/94888013:17
noonedeadpunkprobably not smth to fix in it. but just surprised in general13:17
damiandabrowskihmmm no, I think it's not possible. But on the other hand I've never seen any certificate that is valid forever :D 13:20
jrosserit will default to this i think? https://docs.ansible.com/ansible/latest/collections/community/crypto/x509_certificate_module.html#parameter-ownca_not_after13:28
damiandabrowskiouh, I just realized I misunderstood you. I thought you're aiming to create a certificate that is valid indefinitely :D 13:32
noonedeadpunknah, that we don't pass anything to control that13:33
opendevreviewDmitriy Rabotyagov proposed openstack/ansible-role-pki master: Use ttl instead of not_after in pki_authorities  https://review.opendev.org/c/openstack/ansible-role-pki/+/94888013:33
noonedeadpunkdamiandabrowski: jrosser I've updated this one ^ according to our discussion last week13:33
noonedeadpunkand yes, using startswith is the easiest and most reliable thing :D13:34
noonedeadpunkI think it's WAY more readable now13:35
damiandabrowskiah yes, I think for standalone backends it's not possible to define certs lifetime ATM13:36
jrosserthat should be an easy fix13:36
damiandabrowskiyeah, right13:38
noonedeadpunkit is annoying13:40
damiandabrowskinoonedeadpunk: thanks, indeed it's more readable now13:43
opendevreviewMerged openstack/openstack-ansible-openstack_hosts master: Switch OpenStack codename for 2025.2  https://review.opendev.org/c/openstack/openstack-ansible-openstack_hosts/+/96260013:44
noonedeadpunksorry for chiming in, but felt it might be faster this way13:44
damiandabrowskihaha, no worries :D 13:45
opendevreviewDmitriy Rabotyagov proposed openstack/ansible-role-pki master: Allow to supply ttl for ownca certificates  https://review.opendev.org/c/openstack/ansible-role-pki/+/96318013:48
noonedeadpunkI wonder if we should allow/or define some deployment/wide defaults for this ^13:48
noonedeadpunkgiven that patches for all repos are prepared anyway...13:49
damiandabrowskimakes sense IMO13:51
jrosserspeaking of similar13:55
jrosserca.vault_path13:55
jrosseri really don't like this as it is13:55
jrosserthis should have a vault specific default value in the pki role13:56
jrosserwith then an *optional* override per CA rather than making it mandatory to put vault specific vars in the input data13:58
jrosseralso vault_root_ca_path is exactly the same as signed_by so both (all) backends should use signed_by as it's obvious by name what it does13:59
jrosserthe data we feed into the role should work for either standalone or vault backends without any changes or backend specific things (assuming that sensible defaults apply for all backends)13:59
jrosserimho we leak too much of the internal implementation of vault out into the input data currently14:00
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible master: Freeze roles for Flamingo Beta release  https://review.opendev.org/c/openstack/openstack-ansible/+/96318914:11
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible master: Fix role freeze functionality  https://review.opendev.org/c/openstack/openstack-ansible/+/96319014:12
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible master: Freeze roles for Flamingo Beta release  https://review.opendev.org/c/openstack/openstack-ansible/+/96318914:13
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible master: Bump global requirements  https://review.opendev.org/c/openstack/openstack-ansible/+/95128814:19
opendevreviewMerged openstack/openstack-ansible-plugins master: Use unique register variables for service_setup  https://review.opendev.org/c/openstack/openstack-ansible-plugins/+/96225215:01
opendevreviewMerged openstack/openstack-ansible-plugins master: Ensure default for glusterfs_package_repo_keys exists  https://review.opendev.org/c/openstack/openstack-ansible-plugins/+/96226315:01
opendevreviewMerged openstack/openstack-ansible master: Add RockyLinux 10 to CI testing  https://review.opendev.org/c/openstack/openstack-ansible/+/95515015:03
opendevreviewMerged openstack/openstack-ansible master: [doc] Do not used duplicated keys in examples  https://review.opendev.org/c/openstack/openstack-ansible/+/96107415:03
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible stable/2025.1: Add RockyLinux 10 to CI testing  https://review.opendev.org/c/openstack/openstack-ansible/+/96319615:05
opendevreviewMerged openstack/openstack-ansible-os_keystone stable/2024.2: Fix package name for mod_auth_openidc  https://review.opendev.org/c/openstack/openstack-ansible-os_keystone/+/96108715:05
opendevreviewDmitriy Rabotyagov proposed openstack/ansible-role-pki master: Allow to supply ttl for ownca certificates  https://review.opendev.org/c/openstack/ansible-role-pki/+/96318015:14
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible stable/2025.1: Add RockyLinux 10 to CI testing  https://review.opendev.org/c/openstack/openstack-ansible/+/96319615:18
opendevreviewDmitriy Rabotyagov proposed openstack/ansible-role-pki master: Allow to supply ttl for ownca certificates  https://review.opendev.org/c/openstack/ansible-role-pki/+/96318015:37
opendevreviewDamian DÄ…browski proposed openstack/ansible-role-pki master: Add hashi_vault backend  https://review.opendev.org/c/openstack/ansible-role-pki/+/94888115:40
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible stable/2024.1: Bump SHAs for 2024.1  https://review.opendev.org/c/openstack/openstack-ansible/+/96250615:48
opendevreviewMerged openstack/openstack-ansible master: Switch services to track 2025.2  https://review.opendev.org/c/openstack/openstack-ansible/+/96233616:04
opendevreviewMerged openstack/openstack-ansible master: [doc] Add documentation around EL 10 support  https://review.opendev.org/c/openstack/openstack-ansible/+/95685616:04
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible-plugins master: Adopt playbooks for ANSIBLE_GATHER_SUBSET removal  https://review.opendev.org/c/openstack/openstack-ansible-plugins/+/96320416:37
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible master: Remove deprecated ANSIBLE_GATHER_SUBSET  https://review.opendev.org/c/openstack/openstack-ansible/+/96320616:41
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible stable/2024.1: Revert "Do not disable configure_mirrors extra repos for debian"  https://review.opendev.org/c/openstack/openstack-ansible/+/96320716:44
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible stable/2024.1: Bump SHAs for 2024.1  https://review.opendev.org/c/openstack/openstack-ansible/+/96250616:54
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible stable/2025.1: [doc] Add documentation around EL 10 support  https://review.opendev.org/c/openstack/openstack-ansible/+/96321217:03
*** starkis is now known as Guest2851418:47
opendevreviewDmitriy Chubinidze proposed openstack/openstack-ansible master: docs: updated information in the troubleshooting guide  https://review.opendev.org/c/openstack/openstack-ansible/+/95996520:39
opendevreviewDmitriy Chubinidze proposed openstack/openstack-ansible master: docs: updated information in the troubleshooting guide  https://review.opendev.org/c/openstack/openstack-ansible/+/95996520:54
opendevreviewJonathan Rosser proposed openstack/openstack-ansible-openstack_hosts master: Pass pki_authorities var when installing CA certs  https://review.opendev.org/c/openstack/openstack-ansible-openstack_hosts/+/94888420:56
opendevreviewMerged openstack/ansible-role-pki master: Use ttl instead of not_after in pki_authorities  https://review.opendev.org/c/openstack/ansible-role-pki/+/94888022:30
opendevreviewIvan Anfimov proposed openstack/openstack-ansible-os_tempest master: Tenant replaced to Project in tasks name  https://review.opendev.org/c/openstack/openstack-ansible-os_tempest/+/96254023:20
opendevreviewDmitriy Rabotyagov proposed openstack/ansible-role-systemd_networkd master: Restart systemd-udev on link changes  https://review.opendev.org/c/openstack/ansible-role-systemd_networkd/+/95487623:49

Generated by irclog2html.py 4.0.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!