Tuesday, 2023-08-22

opendevreviewOpenStack Proposal Bot proposed openstack/project-config master: Normalize projects.yaml  https://review.opendev.org/c/openstack/project-config/+/89225702:39
opendevreviewMerged openstack/openstack-zuul-jobs master: Remove ocata branch filters  https://review.opendev.org/c/openstack/openstack-zuul-jobs/+/82535305:11
opendevreviewMerged openstack/project-config master: Normalize projects.yaml  https://review.opendev.org/c/openstack/project-config/+/89225705:14
dpawlik2fungi, clarkb: hey, did you change something related to the afs mirror/kerberos auth etc. recently?10:46
dpawlik2fungi: I got some troubles to connect to openstack afs mirror via openafs client and it seems that it missing the kerberos token12:17
dpawlik2according to the doc: https://docs.opendev.org/opendev/system-config/latest/afs.html#client-configuration 12:17
dpawlik2it says that there is some $USERNAME12:18
dpawlik2but when I try to run the kinit $USERNAME@OPENSTACK.ORG it just write "not found in Kerberos database while getting initial credentials"12:20
fricklerdpawlik2: I'm not aware of any changes, iiuc only infra-roots have kerberos accounts12:26
fricklermost read-only ops also should work without auth, as mentioned in that doc12:27
dpawlik2ack12:30
fungidpawlik2: just install an afs client (openafs, kafs...) and go to /afs/openstack.org/ in your filesystem tree. it should simply work12:37
fungithose read-only volumes are accessible publicly/anonymously12:38
fungiyou don't need to configure kerberos at all12:38
fungithat client configuration document you found is for our systems administrators, explaining how to configure authenticated write access to the tree12:39
fungii suppose we can clarify that in the document12:40
fricklerah, I guess I misread dpawlik2's question as "it fails now, but worked earlier, what did you change?"12:43
fungioh, that's how i read it, but i suspect whatever changed was on the client side12:44
fungiand then additional steps were tried based on a misunderstanding of the requirements12:44
dpawlik2that's the issue. Even on clean host, I'm not able to open "/afs/openstack.org/ "12:47
dpawlik2and wondering if you have some part of afs mirror located in Vexxhost or somewhere else12:47
fungiit's working for me with openafs-client 1.8.10-1 on debian/sid12:48
dpawlik2hmm, I have openafs-client-1.8.9-1.el7.x86_6412:48
dpawlik2I will do local VM deployment to verify that12:49
fungiit's also working from a random mirror server i jumped onto, which is using our 1.8.8.1-2~ppa0~focal backport on ubuntu jammy (i wonder why)12:49
fungidpawlik2: all of the afs servers are in rackspace (mostly in the dfw region)12:50
fungialso keep in mind that afs uses udp over ipv4, so make sure your firewalls/routing aren't blocking it for some reason i guess12:51
dpawlik2aha, good point12:52
dpawlik2very very good hint12:52
fungiokay, https://meetings.opendev.org/irclogs/%23opendev/%23opendev.2023-06-05.log.html explains why we're using a forward port of openafs 1.8.8 from focal on jammy servers12:54
funginever mind, i misread, the mirror i was looking at actually is running focal12:59
fungiwe're using jammy's normal 1.8.8.1-3ubuntu2~22.04.2 builds on the zuul executors13:00
fungidpawlik: ^ so looks like at least openafs 1.8.8 or later should work fine, modulo any bugs13:01
*** d34dh0r5- is now known as d34dh0r5313:09
clarkbfungi: we did/do have a jammy packge in our ppa but what we backported from debian I think? Is slightly older than what jammy ships for itself so apt chooses the normal distro package on jammy14:53
fungiyeah, we ended up not using it, i think i deleted it after we identified the problem was on the zuul/python side of things14:58
opendevreviewJames E. Blair proposed openstack/project-config master: Switch opendev tenant to Ansible 8  https://review.opendev.org/c/openstack/project-config/+/89240519:51
opendevreviewMerged openstack/project-config master: Switch opendev tenant to Ansible 8  https://review.opendev.org/c/openstack/project-config/+/89240520:14
*** timburke_ is now known as timburke21:28
mnaserfollowing up to the messages above23:37
mnaseri'm in the box that doesnt seem to be able to list /afs/openstack.org and it doesnt seem to work.  i can see udp traffic making its way all the way out to the afs server23:37
mnaserim seeing this kind of traffic: `23:38:12.094290 IP 38.102.83.237.7001 > 104.130.138.161.7000:  rx version (29)` and seeing responses too `23:38:13.051578 IP 104.130.138.161.7000 > 38.102.83.237.7001:  rx ack first 2 serial 0 reason ping (65)`23:38

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!