| opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_ironic master: Remove Ironic Inspector https://review.opendev.org/c/openstack/openstack-ansible-os_ironic/+/976061 | 00:03 |
|---|---|---|
| opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_ironic master: Remove leftover of nova-cert https://review.opendev.org/c/openstack/openstack-ansible-os_ironic/+/976061 | 00:04 |
| opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_ironic master: Remove leftover of nova-cert https://review.opendev.org/c/openstack/openstack-ansible-os_ironic/+/976061 | 00:05 |
| opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_magnum master: Remove leftover of nova-cert https://review.opendev.org/c/openstack/openstack-ansible-os_magnum/+/982594 | 00:08 |
| opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_magnum master: Remove leftover of nova-cert https://review.opendev.org/c/openstack/openstack-ansible-os_magnum/+/982594 | 00:08 |
| opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_octavia master: Remove leftover of nova-cert https://review.opendev.org/c/openstack/openstack-ansible-os_octavia/+/982595 | 00:10 |
| opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_octavia master: Remove leftover of nova-cert https://review.opendev.org/c/openstack/openstack-ansible-os_octavia/+/982595 | 00:10 |
| opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_octavia master: Remove leftover of nova-cert https://review.opendev.org/c/openstack/openstack-ansible-os_octavia/+/982595 | 00:11 |
| opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_magnum master: Remove Neutron LBaaS from inventory https://review.opendev.org/c/openstack/openstack-ansible-os_magnum/+/982596 | 00:14 |
| opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_magnum master: Remove Neutron LBaaS from inventory https://review.opendev.org/c/openstack/openstack-ansible-os_magnum/+/982596 | 00:15 |
| opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_zun master: Remove Neutron LBaaS from inventory https://review.opendev.org/c/openstack/openstack-ansible-os_zun/+/982597 | 00:17 |
| opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_zun master: Remove Neutron LBaaS from inventory https://review.opendev.org/c/openstack/openstack-ansible-os_zun/+/982597 | 00:18 |
| opendevreview | Andrew Bonney proposed openstack/openstack-ansible-plugins master: Add magnum_capi_proxy playbook https://review.opendev.org/c/openstack/openstack-ansible-plugins/+/979969 | 07:05 |
| noonedeadpunk | mornings | 07:18 |
| noonedeadpunk | fwiw, I got pretty much working azimuth setup at this point | 07:18 |
| andrewbonney | excellent | 07:19 |
| noonedeadpunk | still testing a bit, and would also need to merge one PR to the collection | 07:19 |
| noonedeadpunk | and having some confusion with certificates (like adding k8s cert to the system trust on magnum?) | 07:19 |
| noonedeadpunk | the CI is feeling bad on magnum patch due to some issue with horizon though | 07:20 |
| andrewbonney | are we adding a k8s cert to system trust at present? I thought we just had to do things to instruct magnum where the internal or external CA cert for the wider deployment is | 07:22 |
| noonedeadpunk | no, we are not | 07:23 |
| noonedeadpunk | but I am getting smth like that: https://paste.openstack.org/show/bmAioNwUGTYSqvhz6bum/ | 07:25 |
| noonedeadpunk | though it's weird... it should be haproxy cert I assume? | 07:25 |
| noonedeadpunk | but like getting cert from existing kubeconfig and placing to the trust for magnum weirdly helped | 07:26 |
| noonedeadpunk | I think I need a clean env and try again | 07:26 |
| andrewbonney | yes I would expect all magnum comms with the control plane cluster to go via the internal haproxy endpoint | 07:27 |
| noonedeadpunk | ++ | 07:28 |
| noonedeadpunk | andrewbonney: though we're having it in TCP mode | 07:33 |
| noonedeadpunk | so I have bind *:6443 interface eth5 mode tcp | 07:34 |
| andrewbonney | yes, just checked our live ones and it's the same. i might have to defer to jrosser here to remember why it's this way | 07:38 |
| andrewbonney | I assume in this case all of our existing magnum comms with the cluster is via a k8s client which uses the k8s config file directly | 07:39 |
| noonedeadpunk | right, which is likely not the case for the azimuth driver, which does smth on it's own it seems | 07:41 |
| noonedeadpunk | while not respecting cert in kubeconfig... | 07:41 |
| noonedeadpunk | I think at this point I'd be fine starting merging things as except of the huge playbook in plugins, which potentially can be refactored, it looks quite decent | 07:42 |
| andrewbonney | sounds good | 07:43 |
| noonedeadpunk | though blocker is horizon plugin at this point :( | 07:43 |
| andrewbonney | is that waiting on something upstream or one of our patches? | 07:47 |
| jrosser | yes afaik the necessary certs are in the kubconfig file on the magnum node | 07:51 |
| jrosser | all of the TLS took a hole bunch of work with mnaser to get perfect, it’s complicated | 07:52 |
| jrosser | my suspicion would be that the azimuth driver may not be particularly rigorous about it | 07:53 |
| noonedeadpunk | yeah, as my fix was `grep 'certificate-authority-data' ~/.kube/config | awk '{print $2}' | base64 -d > kubernetes-ca.crt && update-ca-certificates` | 07:55 |
| noonedeadpunk | so I think this is around last part to figure out for azimuth part. | 07:56 |
| noonedeadpunk | and then I did quite a bunch of improvements on collection state as well | 07:57 |
| noonedeadpunk | except, for containerd role, I did not explicitly added variables for proxy | 07:57 |
| noonedeadpunk | but there's a `containerd_service_environment` variable, which can be populated with env vars needed | 07:59 |
| opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_octavia master: Rename Octavia groups to remove dashes https://review.opendev.org/c/openstack/openstack-ansible-os_octavia/+/978680 | 08:03 |
| noonedeadpunk | will try to make a tag for the collection fork tomorrow, so we can fully utilize this in a-c-r | 08:13 |
| noonedeadpunk | just to mention that - I did not just rig dependent roles from vexxhost.containers, but fully refactored them | 08:14 |
| opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_octavia stable/2025.2: Fix default type for octavia_user_haproxy_templates https://review.opendev.org/c/openstack/openstack-ansible-os_octavia/+/982410 | 10:39 |
| opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_skyline master: Fix Object Storage section for RGW https://review.opendev.org/c/openstack/openstack-ansible-os_skyline/+/982629 | 10:47 |
| opendevreview | Merged openstack/openstack-ansible-os_neutron stable/2025.2: Retry adding ovs bridges to overcome error from ovs-vsctl https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/982591 | 14:27 |
| opendevreview | Merged openstack/openstack-ansible-os_neutron stable/2025.1: Retry adding ovs bridges to overcome error from ovs-vsctl https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/982592 | 14:28 |
| opendevreview | Merged openstack/openstack-ansible-os_neutron stable/2025.1: Define start-time for uWSGI https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/982403 | 14:28 |
| noonedeadpunk | we need another review on https://review.opendev.org/c/openstack/openstack-ansible/+/982072 | 14:31 |
| noonedeadpunk | as it's blocking everything in plugins | 14:31 |
| noonedeadpunk | that's a backport to 2025.1 | 14:31 |
| opendevreview | Merged openstack/openstack-ansible-os_neutron stable/2025.2: Define start-time for uWSGI https://review.opendev.org/c/openstack/openstack-ansible-os_neutron/+/982402 | 14:32 |
| opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_octavia stable/2025.2: Fix default type for octavia_user_haproxy_templates https://review.opendev.org/c/openstack/openstack-ansible-os_octavia/+/982410 | 14:33 |
| andrewbonney | done | 14:46 |
| noonedeadpunk | also this one workaround swift issue: https://review.opendev.org/c/openstack/openstack-ansible-os_glance/+/982526 | 16:08 |
| opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible master: Migrate k8s cluster from osa ops into main tree https://review.opendev.org/c/openstack/openstack-ansible/+/975277 | 16:24 |
| opendevreview | Dmitriy Rabotyagov proposed openstack/openstack-ansible-plugins master: Add sonobuoy role for testing k8s clusters https://review.opendev.org/c/openstack/openstack-ansible-plugins/+/975393 | 16:27 |
| opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_octavia stable/2025.2: Drop non-existent options from service_auth https://review.opendev.org/c/openstack/openstack-ansible-os_octavia/+/982694 | 16:59 |
| opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_octavia stable/2025.2: Drop non-existent options from service_auth https://review.opendev.org/c/openstack/openstack-ansible-os_octavia/+/982694 | 17:00 |
| opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_octavia stable/2025.1: Drop non-existent options from service_auth https://review.opendev.org/c/openstack/openstack-ansible-os_octavia/+/982717 | 19:54 |
| opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_octavia stable/2025.1: Drop non-existent options from service_auth https://review.opendev.org/c/openstack/openstack-ansible-os_octavia/+/982717 | 19:54 |
| opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_octavia stable/2025.2: Add keystoneauth options to [neutron] https://review.opendev.org/c/openstack/openstack-ansible-os_octavia/+/982718 | 19:56 |
| opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_octavia stable/2025.2: Add keystoneauth options to [neutron] https://review.opendev.org/c/openstack/openstack-ansible-os_octavia/+/982718 | 19:56 |
| opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_octavia stable/2025.1: Add keystoneauth options to [neutron] https://review.opendev.org/c/openstack/openstack-ansible-os_octavia/+/982719 | 19:57 |
| opendevreview | Ivan Anfimov proposed openstack/openstack-ansible-os_octavia stable/2025.1: Add keystoneauth options to [neutron] https://review.opendev.org/c/openstack/openstack-ansible-os_octavia/+/982719 | 19:57 |
| opendevreview | Merged openstack/openstack-ansible-apt_package_pinning master: Add CONTRIBUTING.rst file https://review.opendev.org/c/openstack/openstack-ansible-apt_package_pinning/+/971784 | 21:42 |
| opendevreview | Merged openstack/openstack-ansible-os_tempest master: Add freezer venv to the PATH when enabled https://review.opendev.org/c/openstack/openstack-ansible-os_tempest/+/981533 | 22:07 |
| opendevreview | Merged openstack/openstack-ansible-os_glance master: Temporary disable swift retries https://review.opendev.org/c/openstack/openstack-ansible-os_glance/+/982526 | 22:25 |
| opendevreview | Merged openstack/openstack-ansible-os_cinder master: Update outdate information in bindep.txt https://review.opendev.org/c/openstack/openstack-ansible-os_cinder/+/973120 | 23:02 |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!