corvus | kvno service/opendev-zuul@OPENSTACK.ORG | 00:00 |
---|---|---|
corvus | service/opendev-zuul@OPENSTACK.ORG: kvno = 3 | 00:00 |
corvus | iiuc, i think that points strongly in that direction. | 00:01 |
clarkb | afs_tarballs_opendev_org ya that has the name service/opendev-zuul@OPENSTACK.ORG | 00:02 |
clarkb | so I think it was an unintentional mixup | 00:03 |
corvus | so if there is a copy of the new keytab somewhere, then the other secret can be updated and we should be okay | 00:03 |
clarkb | ya let me see if I can find fungi's decryption utility then reencrypt | 00:03 |
corvus | ie, if there's a copy of kvno 3 somewhere, we can update the opendev-zuul-tarballs secret | 00:04 |
clarkb | its in openstack/project-config | 00:04 |
corvus | clarkb: i've got a decryption utility handy | 00:04 |
clarkb | oh cool do you want to do the decrypt -> reencrypt dance then? | 00:05 |
*** rfolco has quit IRC | 00:05 | |
clarkb | I've found fungi's docs now and am reading up if not | 00:05 |
corvus | yeah | 00:06 |
corvus | https://opendev.org/openstack/project-config/commit/675bb510f1a3491bf14a6ded17faa5083395aeb9 | 00:06 |
corvus | yes, that looks like it was added around the correct time | 00:06 |
corvus | clarkb: can you look for any other instances of that principal? | 00:06 |
clarkb | corvus: yes I'll ask codesearch | 00:07 |
clarkb | corvus: opendev-zuul-docs and opendev-zuul-tarballs both in opendev/base-jobs appear to be the only two | 00:08 |
corvus | the secret as written in project-config does not have the path restriction that it has in the zuul tenant. that may be dangerous. | 00:08 |
clarkb | corvus: if preferable I think you could issue a new one instead and update base-jobs for that | 00:09 |
clarkb | then ianw can create a different keytab for !zuul | 00:09 |
corvus | clarkb: then i'd have to update 3 secrets | 00:10 |
clarkb | corvus: just two, leave the openstack side alone (it will break) and ianw can fix on monday | 00:10 |
clarkb | that stuff is still in testing so shouldn't affect anything yet | 00:10 |
corvus | well, i mean, i'm not sure that it's wrong to use this principal | 00:10 |
clarkb | ah | 00:11 |
corvus | so if i do that, then ianw will need to come back on monday and update 3 :) | 00:11 |
*** mattw4 has quit IRC | 00:13 | |
corvus | klist says that is kvno3 | 00:16 |
clarkb | which is what we expect as being the current one right? | 00:16 |
corvus | yep | 00:16 |
openstackgerrit | James E. Blair proposed opendev/base-jobs master: Update afs keytab https://review.opendev.org/705314 | 00:20 |
corvus | clarkb: ^ are those the right secrets? | 00:20 |
clarkb | yes | 00:21 |
clarkb | I've approved the change | 00:21 |
hashar | well done :] | 00:21 |
hashar | have a good rest of your day, I am escaping | 00:21 |
corvus | hashar: thanks for noticing :) | 00:21 |
hashar | you are welcome! | 00:22 |
openstackgerrit | James E. Blair proposed opendev/system-config master: Add warning about kerberos key rotation https://review.opendev.org/705316 | 00:23 |
corvus | (also i manually got a ticket using the kvno 3 keytab, so that looks good) | 00:24 |
*** rkukura has quit IRC | 00:26 | |
*** rfolco has joined #openstack-infra | 00:26 | |
*** hashar has quit IRC | 00:26 | |
clarkb | ianw: ^ to summarize you created a new keytab for tarballs afs stuff and that invalidated the existing keytab that zuul was using to upload its tarballs and docs | 00:27 |
clarkb | ianw: on top of that corvus noticed there is no more path restriction on the new keytab (something we may need to think about) | 00:27 |
corvus | well, i didn't look hard into that -- it may just be in a different place in that job. but it's something we should double check and be careful about. | 00:28 |
*** tosky has quit IRC | 00:29 | |
openstackgerrit | Merged opendev/base-jobs master: Update afs keytab https://review.opendev.org/705314 | 00:30 |
openstackgerrit | Clark Boylan proposed opendev/system-config master: WIP Deploy refstack with ansible docker https://review.opendev.org/705258 | 00:34 |
*** hwoarang has quit IRC | 00:34 | |
clarkb | explicitly setting container_command now rather than relying on the default value | 00:34 |
*** hwoarang has joined #openstack-infra | 00:35 | |
*** dpawlik has quit IRC | 00:38 | |
*** ahosam has quit IRC | 00:42 | |
*** irclogbot_3 has quit IRC | 00:45 | |
clarkb | if ^ doesn't change anything I'll plan to set zuul verbose on monday | 00:46 |
clarkb | but I'm running out of week now | 00:46 |
*** irclogbot_1 has joined #openstack-infra | 00:49 | |
*** Lucas_Gray has quit IRC | 00:57 | |
*** Lucas_Gray has joined #openstack-infra | 00:57 | |
openstackgerrit | Merged opendev/system-config master: Add warning about kerberos key rotation https://review.opendev.org/705316 | 01:01 |
*** Wryhder has joined #openstack-infra | 01:06 | |
*** Lucas_Gray has quit IRC | 01:08 | |
*** Wryhder is now known as Lucas_Gray | 01:08 | |
*** Lucas_Gray has quit IRC | 01:20 | |
*** Lucas_Gray has joined #openstack-infra | 01:22 | |
*** rfolco has quit IRC | 01:24 | |
*** armax has quit IRC | 01:30 | |
*** Lucas_Gray has quit IRC | 01:33 | |
*** HenryG has quit IRC | 01:45 | |
*** HenryG has joined #openstack-infra | 01:47 | |
*** armax has joined #openstack-infra | 02:00 | |
*** ociuhandu has joined #openstack-infra | 02:22 | |
*** rfolco has joined #openstack-infra | 02:23 | |
*** ociuhandu has quit IRC | 02:27 | |
*** zxiiro has quit IRC | 02:41 | |
*** gyee has quit IRC | 02:51 | |
ianw | corvus/clarkb: arrgghhh i'm very sorry! that's exactly what i did; i did an ACL copy to tarballs.opendev.org volume and, i thought, issued an additional key ... i didn't realise i'd invalidate the current one | 03:15 |
*** rfolco has quit IRC | 03:42 | |
*** artom has quit IRC | 03:58 | |
*** artom has joined #openstack-infra | 04:00 | |
*** artom has quit IRC | 04:01 | |
*** bnemec has quit IRC | 04:13 | |
*** factor has joined #openstack-infra | 05:07 | |
*** evrardjp has quit IRC | 05:33 | |
*** evrardjp has joined #openstack-infra | 05:34 | |
*** kjackal has joined #openstack-infra | 06:26 | |
*** ramishra has quit IRC | 06:27 | |
*** ramishra has joined #openstack-infra | 06:30 | |
*** ramishra has quit IRC | 06:38 | |
*** kjackal has quit IRC | 06:40 | |
*** Tengu has quit IRC | 06:42 | |
*** Tengu has joined #openstack-infra | 07:00 | |
*** lbragstad_ has joined #openstack-infra | 07:17 | |
*** lbragstad has quit IRC | 07:19 | |
openstackgerrit | Elod Illes proposed openstack/devstack-gate master: Do not gzip files under logs in job results https://review.opendev.org/705255 | 08:48 |
*** roman_g has joined #openstack-infra | 10:11 | |
*** slaweq has quit IRC | 10:15 | |
*** roman_g has quit IRC | 11:12 | |
*** Lucas_Gray has joined #openstack-infra | 11:14 | |
*** roman_g has joined #openstack-infra | 11:23 | |
*** slaweq has joined #openstack-infra | 12:11 | |
*** slaweq has quit IRC | 12:16 | |
*** adriant has quit IRC | 12:31 | |
*** iokiwi has quit IRC | 12:31 | |
*** adriant has joined #openstack-infra | 12:32 | |
*** iokiwi has joined #openstack-infra | 12:32 | |
*** tobiash has quit IRC | 13:05 | |
*** tobiash has joined #openstack-infra | 13:06 | |
*** tobiash has quit IRC | 13:12 | |
*** tobiash has joined #openstack-infra | 13:15 | |
*** ahosam has joined #openstack-infra | 13:48 | |
*** tosky has joined #openstack-infra | 13:58 | |
*** Lucas_Gray has quit IRC | 14:07 | |
*** slaweq has joined #openstack-infra | 14:11 | |
*** slaweq has quit IRC | 14:16 | |
*** smarcet has joined #openstack-infra | 14:28 | |
*** smarcet has quit IRC | 14:30 | |
*** bnemec has joined #openstack-infra | 14:37 | |
*** rfolco has joined #openstack-infra | 14:49 | |
*** lxkong has quit IRC | 14:59 | |
*** lxkong has joined #openstack-infra | 15:00 | |
*** ildikov has quit IRC | 15:03 | |
*** ildikov has joined #openstack-infra | 15:04 | |
*** bnemec has quit IRC | 15:10 | |
*** cjohnston has quit IRC | 15:25 | |
*** cjohnston has joined #openstack-infra | 15:25 | |
*** rfolco has quit IRC | 15:57 | |
*** armax has quit IRC | 16:06 | |
*** slaweq has joined #openstack-infra | 16:11 | |
*** davecore has quit IRC | 16:14 | |
*** davecore has joined #openstack-infra | 16:14 | |
*** slaweq has quit IRC | 16:16 | |
*** csatari has quit IRC | 16:16 | |
*** csatari has joined #openstack-infra | 16:17 | |
*** rfolco has joined #openstack-infra | 16:26 | |
*** setuid has quit IRC | 16:28 | |
*** setuid has joined #openstack-infra | 16:28 | |
*** abelur has quit IRC | 16:38 | |
*** abelur has joined #openstack-infra | 16:39 | |
*** rkukura has joined #openstack-infra | 16:45 | |
*** srwilkers has quit IRC | 16:54 | |
*** srwilkers has joined #openstack-infra | 16:55 | |
*** tosky has quit IRC | 16:59 | |
*** knikolla has quit IRC | 17:02 | |
*** knikolla has joined #openstack-infra | 17:02 | |
*** rpioso has quit IRC | 17:05 | |
*** rpioso has joined #openstack-infra | 17:06 | |
*** yolanda has joined #openstack-infra | 17:07 | |
*** slaweq has joined #openstack-infra | 17:11 | |
*** yolanda has quit IRC | 17:12 | |
*** slaweq has quit IRC | 17:16 | |
*** rfolco has quit IRC | 17:26 | |
*** evrardjp has quit IRC | 17:33 | |
*** evrardjp has joined #openstack-infra | 17:34 | |
*** mattw4 has joined #openstack-infra | 17:34 | |
*** mattw4 has quit IRC | 17:43 | |
*** mattw4 has joined #openstack-infra | 17:43 | |
openstackgerrit | Clark Boylan proposed zuul/zuul-jobs master: Debug weird Ansible loop behavior https://review.opendev.org/705312 | 17:48 |
*** tonyb[m] has quit IRC | 17:55 | |
*** tonyb[m] has joined #openstack-infra | 17:55 | |
openstackgerrit | Sorin Sbarnea proposed zuul/zuul master: Add build history link to summary https://review.opendev.org/705049 | 18:04 |
*** slaweq has joined #openstack-infra | 18:11 | |
*** slaweq has quit IRC | 18:16 | |
*** mattw4 has quit IRC | 18:20 | |
ykarel|away | clarkb, commented can u try that | 19:02 |
openstackgerrit | Clark Boylan proposed zuul/zuul-jobs master: Debug weird Ansible loop behavior https://review.opendev.org/705312 | 19:08 |
clarkb | ykarel|away: ^ https://review.opendev.org/#/c/705258/10 system-config-run-refstack is the job check that | 19:09 |
*** zzzeek has quit IRC | 19:09 | |
ykarel|away | clarkb, yup i saw that before suggeting | 19:09 |
ykarel|away | i commented the reason why i suggested so | 19:10 |
ykarel|away | because of https://review.opendev.org/#/c/705258/10/playbooks/zuul/run-base-post.yaml@24 | 19:10 |
clarkb | wow ok | 19:10 |
clarkb | I guess it is good hygiene to use a good unique name in a role naytime you might be run with a loop | 19:11 |
ykarel|away | if there are nested loops yes it should be done | 19:11 |
ykarel|away | for sure | 19:11 |
clarkb | well in a role you dont know if you will be nested so good idea to assume it is possible | 19:23 |
ykarel|away | hmm ack | 19:26 |
*** zzzeek has joined #openstack-infra | 19:28 | |
* ykarel|away out | 19:51 | |
AJaeger | that's sad - nesting loops is common and if they all share the same namespace, you'll easily get these behaviours ;( | 19:51 |
*** smarcet has joined #openstack-infra | 20:03 | |
*** slaweq has joined #openstack-infra | 20:11 | |
*** slaweq has quit IRC | 20:16 | |
*** jamesmcarthur has joined #openstack-infra | 20:20 | |
*** dciabrin_ has quit IRC | 20:23 | |
*** jamesmcarthur has quit IRC | 20:30 | |
*** jamesmcarthur has joined #openstack-infra | 20:30 | |
*** jamesmcarthur has quit IRC | 20:36 | |
*** jamesmcarthur has joined #openstack-infra | 20:40 | |
*** jamesmcarthur has quit IRC | 20:49 | |
*** yolanda has joined #openstack-infra | 21:00 | |
*** smarcet has left #openstack-infra | 21:49 | |
*** Lucas_Gray has joined #openstack-infra | 21:58 | |
*** slaweq has joined #openstack-infra | 22:11 | |
*** slaweq has quit IRC | 22:16 | |
openstackgerrit | Clark Boylan proposed zuul/zuul-jobs master: Don't use item in collect container logs loop https://review.opendev.org/705312 | 22:25 |
openstackgerrit | Clark Boylan proposed opendev/system-config master: WIP Deploy refstack with ansible docker https://review.opendev.org/705258 | 22:27 |
*** Lucas_Gray has quit IRC | 22:37 | |
openstackgerrit | Clark Boylan proposed zuul/zuul-jobs master: Use unique loop vars to avoid conflicts https://review.opendev.org/705337 | 22:41 |
*** tosky has joined #openstack-infra | 22:55 | |
*** tosky has quit IRC | 23:41 | |
*** Goneri has quit IRC | 23:45 | |
*** ahosam has quit IRC | 23:58 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!