Tuesday, 2025-10-07

opendevreviewIvan Anfimov proposed openstack/openstack-ansible-os_magnum master: Remove outdate file manual-test.rc  https://review.opendev.org/c/openstack/openstack-ansible-os_magnum/+/95965500:31
opendevreviewOpenStack Proposal Bot proposed openstack/openstack-ansible master: Imported Translations from Zanata  https://review.opendev.org/c/openstack/openstack-ansible/+/96323603:49
opendevreviewDmitriy Rabotyagov proposed openstack/ansible-role-systemd_networkd master: Restart systemd-udev on link changes  https://review.opendev.org/c/openstack/ansible-role-systemd_networkd/+/95487608:10
opendevreviewDmitriy Rabotyagov proposed openstack/ansible-role-systemd_networkd master: Restart systemd-udev on link changes  https://review.opendev.org/c/openstack/ansible-role-systemd_networkd/+/95487608:11
opendevreviewMerged openstack/ansible-role-pki master: Allow to supply ttl for ownca certificates  https://review.opendev.org/c/openstack/ansible-role-pki/+/96318014:31
noonedeadpunk#startmeeting openstack_ansible_meeting15:02
opendevmeetMeeting started Tue Oct  7 15:02:13 2025 UTC and is due to finish in 60 minutes.  The chair is noonedeadpunk. Information about MeetBot at http://wiki.debian.org/MeetBot.15:02
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:02
opendevmeetThe meeting name has been set to 'openstack_ansible_meeting'15:02
noonedeadpunk#topic rollcall15:02
noonedeadpunko/15:02
DavidGomezo/15:02
NeilHanlon_o/15:02
damiandabrowskihi!15:03
noonedeadpunkcourtesy ping: jrosser15:03
jrossero/ hello15:03
noonedeadpunk#topic office hours15:03
noonedeadpunkso releases15:04
noonedeadpunkfor 2025.1 I think only rocky left15:04
noonedeadpunk#link https://review.opendev.org/q/parentproject:openstack/openstack-ansible+branch:%5Estable/2025.1+status:open+15:04
noonedeadpunk*rocky 10 backport15:04
noonedeadpunk2024.2 is waiting for another vote on bump15:05
noonedeadpunkand 2024.1 had issues yesterday with Rocky 9 mirrors15:05
noonedeadpunkI'm considering to backport https://review.opendev.org/c/openstack/openstack-ansible/+/935362 as well if it's not gonna pass today15:06
NeilHanlon_yeah i think that would make sense15:06
*** NeilHanlon_ is now known as NeilHanlon15:06
jrosseryes it looked like a big mess yesterday15:06
noonedeadpunkfor 2025.2 beta I've pushed freeze https://review.opendev.org/c/openstack/openstack-ansible/+/963189 - will push unfreeze today right after the meeting15:07
noonedeadpunkideally I should have done that yesterday15:07
noonedeadpunkI;ve also spotted a copy-paste issue during refactoring of releasing script while doing freeze, so pushed small path for it15:09
noonedeadpunkAlso run some tests/played with facts gathering yesterday evening. As today we basically are collecting all facts, as ANSIBLE_GATHER_SUBSET not respected anymore15:09
jrosserthat patch looked basically ok15:10
noonedeadpunkgot quite a massive patch out for playbooks: https://review.opendev.org/c/openstack/openstack-ansible-plugins/+/96320415:10
noonedeadpunkI was thinking if I should simplify it15:10
noonedeadpunkand drop `ANSIBLE_GATHER_SUBSET` altogether15:10
noonedeadpunkas it could be `gather_subset: "{{ osa_gather_subset | default('!all,min') }}"` instead15:11
noonedeadpunkreally no reason except some compatability concerns not to do that15:12
noonedeadpunkbut we're now on non-slurp, so eh15:12
jrosserthe env var is no longer a thing in actual ansible so yes makes sense to simplify15:12
NeilHanlonthat all feels rather fine15:12
noonedeadpunkI guess my thinking was that I didn't intend to add ansible var in place at the begining, but then realized it might be good to do it with anisble var15:13
noonedeadpunkbut left env var in place15:13
noonedeadpunkI will check on that and I guess simplify it indeed15:13
* noonedeadpunk having several envs which would need to convert from env var to ansible var15:14
* noonedeadpunk is lazy15:14
noonedeadpunkok, we got some progress on pki route I believe15:15
noonedeadpunkThere were some comments in IRC about the last patch bringing in the new driver from jrosser yesterday15:15
noonedeadpunkdamiandabrowski: have you seen them and was able to process?15:15
noonedeadpunkdo we want to discuss them now?15:15
jrosseryeah there still is vault_ vars in places15:15
jrosseri already left comments on the patch a long time ago15:16
damiandabrowskiyeah, i think it's related to: https://review.opendev.org/c/openstack/ansible-role-pki/+/948881/comment/ee0404e1_b5ac6aae/15:16
damiandabrowskiI tried to explain there why I've implemented it like this15:17
noonedeadpunkyeah, I hardly dealt with vault so it's hard to judge for me without deeper dive into specifics 15:19
noonedeadpunkat glance explanation kinda make sense15:20
noonedeadpunkbtw it's in merge conflict now 15:20
damiandabrowskiyeah, I'll handle it during the evening15:21
noonedeadpunkWill put some effort into reviewing this. As I was postponing this last bit for too long15:23
noonedeadpunkBut I think my main problem is that I'm really not sure what is the most widespread or reasonable pattern of vault usage is15:24
damiandabrowskiyeah, me neither. Didn't really have any experience with Vault before I started working on this integration15:24
damiandabrowskiokok, I'm currently adoping sevice roles to recent pki changes we made(type, dynamic permission/owner etc.)15:25
damiandabrowskiit's going slower than I expected but today I aim to finish patching and start testing it locally15:26
noonedeadpunkok, sounds good then15:26
noonedeadpunkDebian 13 - I don't have any updates so far. Was not looking there :(15:26
damiandabrowskibtw. how can I upload a new patchset to the propsoed change but avoid triggerring CI jobs? Would workflow -1 do the job?15:26
noonedeadpunknope, I don't think you can do this15:26
noonedeadpunkas jobs are triggered based of file changes and the trigger is new patchset15:27
damiandabrowskiahh okok :/ thanks15:27
noonedeadpunklabels do not really matter afaik15:27
noonedeadpunkyou can make a typo in zuul.d so that they instantly fail :D15:27
noonedeadpunkor comment out jobs in project.yaml15:28
noonedeadpunkbut yeah15:28
noonedeadpunkI wanna check on Debian 13 this week, but really no time to be frank, as need to prepare plenty of stuff for the summit15:30
noonedeadpunkanything else for today?15:35
jrossersorry fire alarm here - back now15:40
jrossermy only objection to the vault_* vars is that they look mandatory15:40
jrosserif they defaulted to some sensible value and did not need always to be in the input data to the pki role it would be much cleaner15:40
jrosseri also don't see why we can't use signed_by for either backend15:41
damiandabrowskihmm, I can define some default values for vault_path and vault_root_ca_path, so they won't have to be explicitly defined15:44
damiandabrowskiI was thinking about  getting rid of vault_root_ca_path and using signed_by for both backends, but I was afraid it would be too confusing for users15:45
damiandabrowskivault_root_ca_path specifies a vault path where the root certificate is stored. It doesn't point to the issuing certificate directly15:45
damiandabrowskiso that's quite a difference, comparing to how signed_by is used in standalone backend15:46
noonedeadpunk#endmeeting16:02
opendevmeetMeeting ended Tue Oct  7 16:02:02 2025 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)16:02
opendevmeetMinutes:        https://meetings.opendev.org/meetings/openstack_ansible_meeting/2025/openstack_ansible_meeting.2025-10-07-15.02.html16:02
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/openstack_ansible_meeting/2025/openstack_ansible_meeting.2025-10-07-15.02.txt16:02
opendevmeetLog:            https://meetings.opendev.org/meetings/openstack_ansible_meeting/2025/openstack_ansible_meeting.2025-10-07-15.02.log.html16:02
opendevreviewIvan Anfimov proposed openstack/ansible-role-systemd_networkd master: tox: Remove ineffective ignore_basepython_conflict and bump minimum version  https://review.opendev.org/c/openstack/ansible-role-systemd_networkd/+/96331818:40
opendevreviewIvan Anfimov proposed openstack/ansible-role-systemd_networkd master: tox: Remove ineffective ignore_basepython_conflict and bump minimum version  https://review.opendev.org/c/openstack/ansible-role-systemd_networkd/+/96331818:42
opendevreviewIvan Anfimov proposed openstack/ansible-role-systemd_networkd master: wip  https://review.opendev.org/c/openstack/ansible-role-systemd_networkd/+/96331918:42
opendevreviewIvan Anfimov proposed openstack/ansible-role-systemd_networkd master: wip  https://review.opendev.org/c/openstack/ansible-role-systemd_networkd/+/96331918:43
opendevreviewIvan Anfimov proposed openstack/ansible-role-systemd_networkd master: Use full service name in task name  https://review.opendev.org/c/openstack/ansible-role-systemd_networkd/+/96331918:43
opendevreviewDamian Dąbrowski proposed openstack/openstack-ansible-os_nova master: Add hashi_vault pki backend support  https://review.opendev.org/c/openstack/openstack-ansible-os_nova/+/94942619:35
opendevreviewDamian Dąbrowski proposed openstack/ansible-role-httpd master: Add hashi_vault pki backend support  https://review.opendev.org/c/openstack/ansible-role-httpd/+/94943019:37
opendevreviewDamian Dąbrowski proposed openstack/openstack-ansible-os_placement master: Add hashi_vault pki backend support  https://review.opendev.org/c/openstack/openstack-ansible-os_placement/+/94891319:38
opendevreviewDamian Dąbrowski proposed openstack/openstack-ansible-os_cinder master: Add hashi_vault pki backend support  https://review.opendev.org/c/openstack/openstack-ansible-os_cinder/+/94942719:38
opendevreviewDamian Dąbrowski proposed openstack/openstack-ansible-os_neutron master: Add hashi_vault pki backend support  https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/94942019:40
opendevreviewDamian Dąbrowski proposed openstack/openstack-ansible-os_keystone master: Add hashi_vault pki backend support  https://review.opendev.org/c/openstack/openstack-ansible-os_keystone/+/94942519:41
opendevreviewDamian Dąbrowski proposed openstack/openstack-ansible-os_glance master: Add hashi_vault pki backend support  https://review.opendev.org/c/openstack/openstack-ansible-os_glance/+/94942819:41
opendevreviewDamian Dąbrowski proposed openstack/openstack-ansible-os_horizon master: Change horizon_pki_san format  https://review.opendev.org/c/openstack/openstack-ansible-os_horizon/+/94942919:42
opendevreviewDamian Dąbrowski proposed openstack/openstack-ansible-os_octavia master: Add hashi_vault pki backend support  https://review.opendev.org/c/openstack/openstack-ansible-os_octavia/+/94941919:43
opendevreviewDamian Dąbrowski proposed openstack/openstack-ansible-galera_server master: Add hashi_vault pki backend support  https://review.opendev.org/c/openstack/openstack-ansible-galera_server/+/94942419:44
opendevreviewDamian Dąbrowski proposed openstack/openstack-ansible-rabbitmq_server master: Add hashi_vault pki backend support  https://review.opendev.org/c/openstack/openstack-ansible-rabbitmq_server/+/94942319:45
opendevreviewDamian Dąbrowski proposed openstack/openstack-ansible-haproxy_server master: Add hashi_vault pki backend support  https://review.opendev.org/c/openstack/openstack-ansible-haproxy_server/+/94941819:54
opendevreviewDamian Dąbrowski proposed openstack/openstack-ansible-haproxy_server master: Fix 'Regen pem' handler  https://review.opendev.org/c/openstack/openstack-ansible-haproxy_server/+/94941720:03
opendevreviewDamian Dąbrowski proposed openstack/openstack-ansible-haproxy_server master: Add hashi_vault pki backend support  https://review.opendev.org/c/openstack/openstack-ansible-haproxy_server/+/94941820:05
opendevreviewDamian Dąbrowski proposed openstack/openstack-ansible-haproxy_server master: Add hashi_vault pki backend support  https://review.opendev.org/c/openstack/openstack-ansible-haproxy_server/+/94941820:07
opendevreviewDamian Dąbrowski proposed openstack/ansible-role-zookeeper master: Add hashi_vault pki backend support  https://review.opendev.org/c/openstack/ansible-role-zookeeper/+/94942220:08
opendevreviewDamian Dąbrowski proposed openstack/ansible-role-pki master: Add hashi_vault backend  https://review.opendev.org/c/openstack/ansible-role-pki/+/94888120:17
opendevreviewIvan Anfimov proposed openstack/openstack-ansible master: docs: small fix for previous release number on main page  https://review.opendev.org/c/openstack/openstack-ansible/+/96079823:00
opendevreviewIvan Anfimov proposed openstack/openstack-ansible master: docs: small fix for previous release number on main page  https://review.opendev.org/c/openstack/openstack-ansible/+/96079823:00
opendevreviewIvan Anfimov proposed openstack/openstack-ansible master: docs: small fix for previous release number on main page  https://review.opendev.org/c/openstack/openstack-ansible/+/96079823:02

Generated by irclog2html.py 4.0.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!