mnaser | gagehugo, lamt: i just found out that https://review.opendev.org/c/openstack/openstack-helm/+/814693 is caused a serious security issue.. we are symlinking the files but the problem is rotating keys means the files its pointing at are no longer there | 04:55 |
---|---|---|
mnaser | https://www.irccloud.com/pastebin/low4jIju/ | 04:55 |
mnaser | which means its only using the `0` key cause thats the only one that actually exists with the biggest id, the rest all give ENOFILE | 04:56 |
mnaser | this means all tokens issued are invalidated | 04:57 |
gagehugo | hmm | 05:04 |
gagehugo | if so probably easiest to revert and deal with the spam | 05:05 |
opendevreview | Gage Hugo proposed openstack/openstack-helm master: Revert "fix(log): reduces chattiness in keystone log" https://review.opendev.org/c/openstack/openstack-helm/+/827391 | 05:17 |
opendevreview | Gage Hugo proposed openstack/openstack-helm master: Revert "fix(log): reduces chattiness in keystone log" https://review.opendev.org/c/openstack/openstack-helm/+/827391 | 05:18 |
opendevreview | Gage Hugo proposed openstack/openstack-helm master: Revert "fix(log): reduces chattiness in keystone log" https://review.opendev.org/c/openstack/openstack-helm/+/827391 | 05:20 |
gagehugo | lamt: ^ Can you take a look? | 05:20 |
opendevreview | Mohammed Naser proposed openstack/openstack-helm master: Revert "fix(log): reduces chattiness in keystone log" https://review.opendev.org/c/openstack/openstack-helm/+/827389 | 05:29 |
mnaser | gagehugo: oh oops i just made the revert lol | 05:29 |
mnaser | looks like we did exactly the same thing :p | 05:29 |
mnaser | ill abandon mine | 05:29 |
gagehugo | no worries | 05:36 |
gagehugo | thanks for investigating that | 05:36 |
mnaser | no problem, we only realized it since we saw a bunch of 403s happening at 00:00 and 12:00 utc and then the digging got me there | 05:38 |
opendevreview | Oleksandr Kozachenko proposed openstack/openstack-helm-infra master: Use rclone for mysql remote backup to enable both s3 and swift backup https://review.opendev.org/c/openstack/openstack-helm-infra/+/780027 | 12:18 |
opendevreview | Maik Catrinque proposed openstack/openstack-helm-infra master: Add force_boot command to rabbit start template https://review.opendev.org/c/openstack/openstack-helm-infra/+/824796 | 16:55 |
opendevreview | Andrii Ostapenko proposed openstack/openstack-helm-images master: Fix gates https://review.opendev.org/c/openstack/openstack-helm-images/+/827531 | 17:13 |
opendevreview | Francis Bacon Yi proposed openstack/openstack-helm-infra master: Syslog Fix https://review.opendev.org/c/openstack/openstack-helm-infra/+/827534 | 17:56 |
opendevreview | Anjeev Kumar proposed openstack/openstack-helm-infra master: Added pgcrypto extension https://review.opendev.org/c/openstack/openstack-helm-infra/+/824004 | 18:00 |
opendevreview | Anjeev Kumar proposed openstack/openstack-helm-infra master: Added pgcrypto extension https://review.opendev.org/c/openstack/openstack-helm-infra/+/824004 | 18:02 |
opendevreview | Merged openstack/openstack-helm-images master: Fix gates https://review.opendev.org/c/openstack/openstack-helm-images/+/827531 | 18:07 |
opendevreview | Stephen Taylor proposed openstack/openstack-helm-infra master: Move ceph-mgr deployment to the ceph-mon chart https://review.opendev.org/c/openstack/openstack-helm-infra/+/827552 | 20:11 |
opendevreview | Stephen Taylor proposed openstack/openstack-helm-infra master: Move ceph-mgr deployment to the ceph-mon chart https://review.opendev.org/c/openstack/openstack-helm-infra/+/827552 | 20:14 |
opendevreview | Stephen Taylor proposed openstack/openstack-helm-infra master: Move ceph-mgr deployment to the ceph-mon chart https://review.opendev.org/c/openstack/openstack-helm-infra/+/827552 | 20:34 |
opendevreview | Stephen Taylor proposed openstack/openstack-helm-infra master: Move ceph-mgr deployment to the ceph-mon chart https://review.opendev.org/c/openstack/openstack-helm-infra/+/827552 | 20:48 |
opendevreview | Stephen Taylor proposed openstack/openstack-helm-infra master: Move ceph-mgr deployment to the ceph-mon chart https://review.opendev.org/c/openstack/openstack-helm-infra/+/827552 | 21:12 |
opendevreview | Stephen Taylor proposed openstack/openstack-helm-infra master: Move ceph-mgr deployment to the ceph-mon chart https://review.opendev.org/c/openstack/openstack-helm-infra/+/827552 | 21:17 |
opendevreview | Stephen Taylor proposed openstack/openstack-helm-infra master: Move ceph-mgr deployment to the ceph-mon chart https://review.opendev.org/c/openstack/openstack-helm-infra/+/827552 | 21:27 |
opendevreview | Vladimir Sigunov proposed openstack/openstack-helm-infra master: [CEPH] Discovering ceph-mon endpoints https://review.opendev.org/c/openstack/openstack-helm-infra/+/821474 | 22:08 |
opendevreview | Merged openstack/openstack-helm master: Revert "fix(log): reduces chattiness in keystone log" https://review.opendev.org/c/openstack/openstack-helm/+/827391 | 22:42 |
Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!