Tuesday, 2026-02-10

opendevreviewMerged openstack/openstack-ansible-plugins master: Allow to run openstack_resources with tags  https://review.opendev.org/c/openstack/openstack-ansible-plugins/+/97420210:29
opendevreviewIvan Anfimov proposed openstack/openstack-ansible-plugins stable/2025.2: Allow to run openstack_resources with tags  https://review.opendev.org/c/openstack/openstack-ansible-plugins/+/97621810:31
opendevreviewIvan Anfimov proposed openstack/openstack-ansible-plugins stable/2025.1: Allow to run openstack_resources with tags  https://review.opendev.org/c/openstack/openstack-ansible-plugins/+/97621910:33
opendevreviewMerged openstack/openstack-ansible-os_magnum stable/2025.2: Do not remove policy.yaml file  https://review.opendev.org/c/openstack/openstack-ansible-os_magnum/+/97482410:45
opendevreviewMerged openstack/openstack-ansible-plugins master: Use Display for deprecated filter  https://review.opendev.org/c/openstack/openstack-ansible-plugins/+/97514611:08
opendevreviewAndrew Bonney proposed openstack/openstack-ansible master: Migrate k8s cluster from osa ops into main tree  https://review.opendev.org/c/openstack/openstack-ansible/+/97527714:31
opendevreviewAndrew Bonney proposed openstack/openstack-ansible-os_magnum master: Migrate capi driver installation from osa-ops  https://review.opendev.org/c/openstack/openstack-ansible-os_magnum/+/97626114:31
opendevreviewAndrew Bonney proposed openstack/openstack-ansible-os_magnum master: Migrate capi driver installation from osa-ops  https://review.opendev.org/c/openstack/openstack-ansible-os_magnum/+/97626114:33
opendevreviewAndrew Bonney proposed openstack/openstack-ansible-os_magnum master: Migrate capi driver installation from osa-ops  https://review.opendev.org/c/openstack/openstack-ansible-os_magnum/+/97626114:36
noonedeadpunk#startmeeting openstack_ansible_meeting15:00
opendevmeetMeeting started Tue Feb 10 15:00:18 2026 UTC and is due to finish in 60 minutes.  The chair is noonedeadpunk. Information about MeetBot at http://wiki.debian.org/MeetBot.15:00
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:00
opendevmeetThe meeting name has been set to 'openstack_ansible_meeting'15:00
noonedeadpunk#topic rollcall15:00
noonedeadpunkI'm semi around today tbh15:00
noonedeadpunkneed to sort out some personal things :(15:00
jrossero/ hello15:05
damiandabrowskihi!15:05
jrossershould we talk about www_authenticate_uri15:07
jrosserandrewbonney: ^ did you see this15:08
jrosserhttps://review.opendev.org/q/topic:%22use-public-www-authenticate-uri%2215:08
andrewbonneyyes I did - how has that not come up before?15:08
noonedeadpunk#topic www_authenticate_uri15:10
noonedeadpunkI kinda failed to look into the keystoneauthtoken code yesterday15:10
noonedeadpunkBut reading around it sounds like it make sense overall, if we do have a way to ensure that services themselves would not use it to talk to the keystone15:11
noonedeadpunkI think we can be adding some simple firewall rule for AIO/CI for that?15:11
noonedeadpunkas I bet we're missing services' defenition here and there15:12
opendevreviewIvan Anfimov proposed openstack/openstack-ansible-plugins stable/2025.1: wip  https://review.opendev.org/c/openstack/openstack-ansible-plugins/+/97611515:15
opendevreviewIvan Anfimov proposed openstack/openstack-ansible-plugins stable/2025.1: Pin setuptools  https://review.opendev.org/c/openstack/openstack-ansible-plugins/+/97611515:16
opendevreviewIvan Anfimov proposed openstack/openstack-ansible-plugins stable/2025.1: Pin setuptools  https://review.opendev.org/c/openstack/openstack-ansible-plugins/+/97611515:17
opendevreviewIvan Anfimov proposed openstack/openstack-ansible-plugins stable/2025.1: Pin setuptools  https://review.opendev.org/c/openstack/openstack-ansible-plugins/+/97611515:18
noonedeadpunkis there anything specific we wanna to talk regarding www_authenticate_uri ?15:18
noonedeadpunkduring this/next week I'm having really limited availability, so in fact won't be able to pull up some testing for it15:18
noonedeadpunkLike most important thing to check wrt the topic, is that this doesn't make services to talk over public endpoints15:22
noonedeadpunk#topic gate health15:29
noonedeadpunkI think our gates are just broken now15:29
noonedeadpunkI did not check much detauls, and if that is related to setuptools, like for all other projects15:29
noonedeadpunkBut it seems to fail on horizon deployment15:30
noonedeadpunkwhich is like... some git issue?15:30
noonedeadpunk#link https://zuul.opendev.org/t/openstack/build/9f446f5c7a2a459280ea4b6e138c7246/log/job-output.txt#1362315:31
noonedeadpunkthis needs kinda some investigation, as it seems to be consistent right now15:34
noonedeadpunk#topic office hours15:34
noonedeadpunkit would be nice to have another vote on https://review.opendev.org/c/openstack/openstack-ansible/+/97611615:37
noonedeadpunkas I did not actually released previous buymnp, as this includes quite nice fixes as well15:37
noonedeadpunkI wonder if I should make it as X.1.0 15:38
jrossersorry got distracted15:44
jrosseryes i was also thinking that we should forcibly blackhole the public endpoint IP from the mgmt network15:44
noonedeadpunk++ ok, that makes sense then15:49
jrosseriirc we already have iptables stuff doing nat there so there should be an obvious place to add it15:55
noonedeadpunk#endmeeting16:00
opendevmeetMeeting ended Tue Feb 10 16:00:54 2026 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)16:00
opendevmeetMinutes:        https://meetings.opendev.org/meetings/openstack_ansible_meeting/2026/openstack_ansible_meeting.2026-02-10-15.00.html16:00
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/openstack_ansible_meeting/2026/openstack_ansible_meeting.2026-02-10-15.00.txt16:00
opendevmeetLog:            https://meetings.opendev.org/meetings/openstack_ansible_meeting/2026/openstack_ansible_meeting.2026-02-10-15.00.log.html16:00
hamburgler3hey hey - ran into a bit of an issue with the os neutron role - expanding an ovn cluster or perhaps even if a member needed its addresses updated - existing nodes will not get an updated db list and for example taking a cluster from 3 > 5 if a leader for nb or sb is running on the new node 4 or 5, 1,2,3 will not have the updated client list because the template to create /etc/default/ovn-central has a 17:56
hamburgler3when condition that prevents it from running and updating - note that this is not for raft peering but for client connections to leader - it ends up just creating a non stop cycle of 2026-02-06T18:00:04.637Z|5012324|ovsdb_cs|INFO|ssl:10.103.215.20:6641: clustered database server is not cluster leader; trying another server because they are unaware of the updated list. This under the right circumstances 17:56
hamburgler3where an election cycled a leader caused ovn controller/metadata agents to still be in an up state - but not an alive state - no heartbeats - though an additional note is that the hypervisor hosts were all aware of all client addresses in the list for SB connections but it was the northd cluster where original nodes had been expanded that having not been updated caused the issue - https://paste.openstac17:56
hamburgler3k.org/show/boFMEi237jDeAXXx38c5/17:56
hamburgler3oops - https://paste.openstack.org/show/boFMEi237jDeAXXx38c5/17:56
jrosserhamburgler3: is it just that there are too many conditions on the task?18:45
jrosserwell or the line you highlight `_check_cluster_db.rc != 0` is just not needed at all18:46
hamburgler2jrosser: I think it's the when condition - though I do understand that it would also make the task/template not fully idempotent in that the current leader could change on part of the template above it - and there is a set fact check to see who the leader is at run time - I don't think that is a big issue but seeing the template change for users without knowing context (even if it wasnt the ip list 18:54
hamburgler2being updated) could cause concern but I don't really think that should matter in terms of cluster stability18:54
hamburgler2https://paste.openstack.org/show/bar4BmJYhHd07gNekmpK/18:55
hamburgler2added comments to the other part that would change if the when condition is removed 18:56
hamburgler2i dont think that should be an issue though18:56
hamburgler2the second ansible task in my first pb snippet runs after the cluster is already up and running so should not be problematic 18:57

Generated by irclog2html.py 4.0.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!