Wednesday, 2026-07-15

opendevreviewRiccardo Pittau proposed openstack/ironic master: Fix BIOS firmware update failure detection on Dell iDRAC  https://review.opendev.org/c/openstack/ironic/+/99736610:56
TheJuliagood morning13:09
opendevreviewRiccardo Pittau proposed openstack/ironic master: Fix BIOS firmware update failure detection on Dell iDRAC  https://review.opendev.org/c/openstack/ironic/+/99736613:49
opendevreviewJulia Kreger proposed openstack/ironic-specs master: ROCE Enabled BMaaS  https://review.opendev.org/c/openstack/ironic-specs/+/99041314:00
dtantsurYou're really making me learn more scary sounding network stuff TheJulia :D14:05
TheJulia... sorry?14:09
dtantsurROCE14:09
TheJuliaRoCE (I've heard pronounceded as RoCey or RoCe... regional dialects to add a "t" are also a thing14:10
cardoeIt's relatively simple from an Ironic standpoint. We're just better capturing the state of the hardware and exposing the BIOS knobs in the right way rather than a random collection of flags.14:11
dtantsurnice!14:18
JayFRoak is more where I was going for pronunciation14:22
JayFOr rocky14:22
TheJuliayeah14:27
TheJuliaI was talking to janders and it kept sounding like "rockt"14:27
JayFWere you listening to this while authoring 990413? https://www.youtube.com/watch?v=ob8TNqQw2hY14:30
opendevreviewRiccardo Pittau proposed openstack/ironic master: Fix BIOS firmware update failure detection on Dell iDRAC  https://review.opendev.org/c/openstack/ironic/+/99736614:31
opendevreviewMerged openstack/ironic-python-agent-builder master: Fix IPA service not starting on CentOS 10 (systemd 257)  https://review.opendev.org/c/openstack/ironic-python-agent-builder/+/99558915:12
dtantsurTheJulia: not sure if you missed the notifications: https://review.opendev.org/c/openstack/networking-generic-switch/+/981418 cannot be merged any more :(15:27
opendevreviewJay Faulkner proposed openstack/ironic-python-agent master: Fix: Remove legacy agent_token fallback code  https://review.opendev.org/c/openstack/ironic-python-agent/+/99731015:31
opendevreviewTakashi Kajinami proposed openstack/ironic master: Maintain driver dependencies as optional dependencies  https://review.opendev.org/c/openstack/ironic/+/99688215:37
TheJuliadtantsur:  ugh, joy I knew that one was going to be awful15:39
dtantsuryeah, quite a bit of technical debt to pay there..15:39
TheJuliait is what it is15:39
* dtantsur nods15:39
cardoedtantsur: so don't take this the wrong way... but the terrifying network thing is your spec.15:54
cardoeI feel like we need a white board session.15:56
dtantsurLOL, I know, it terrifies myself15:56
JayFif we barely understand it, a deploying operator has no chance :) so we gotta find and resolve the decoder rings :D 15:56
dtantsurI mean, yeah, this is why I'm trying to have a properly designed API now15:57
dtantsurguessing port.extra fields is much less fun15:57
opendevreviewJay Faulkner proposed openstack/ironic-python-agent master: Fix: Remove legacy agent_token fallback code  https://review.opendev.org/c/openstack/ironic-python-agent/+/99731015:57
dtantsur(in the ideal world, somebody much smarter and more knowledgeable would do this spec, but... reality)15:58
JayFI'll take driver_info{'what_the_hell_is': 'this'} for 200.15:58
JayFdtantsur: we are those people. we feel like we aren't because we understand enough to know how hard it is :D 15:58
JayFand if I tell you that you are capable, you will continue to do it so I never will have to ;) 15:58
cardoeWell it's the same thing I've been trying to discuss with Neutron folks.15:58
cardoeWe adopt a quick spec for OVN only.15:59
cardoeBut then there's a handful of bugs and asks about how to do it more extensively15:59
cardoeAnd whoopsie we didn't think of all that.15:59
dtantsurwhoopsie!15:59
opendevreviewJay Faulkner proposed openstack/ironic-python-agent master: Fix: Remove legacy agent_token fallback code  https://review.opendev.org/c/openstack/ironic-python-agent/+/99731015:59
JayFwe have more than our own share of whoopsies16:00
* JayF looks at the security bug he's about to open16:00
cardoeNo doubt. hindsight is 20/20.16:00
TheJuliayup16:02
JayFhttps://bugs.launchpad.net/ironic-python-agent/+bug/2160143 is now open16:02
dtantsur\o/16:05
opendevreviewJay Faulkner proposed openstack/ironic-python-agent master: Fix: Remove legacy agent_token fallback code  https://review.opendev.org/c/openstack/ironic-python-agent/+/99731016:19
JayFdtantsur: ^ sorry, had to nullify your +2, I used Gentoo syntax (Closes: not Closes-Bug:) on the bug :( 16:20
dtantsurI'm bumping my review stats really well today :D16:23
opendevreviewDmitry Tantsur proposed openstack/ironic-specs master: WIP new API for standalone networking (+ EVPN L2VNI)  https://review.opendev.org/c/openstack/ironic-specs/+/99595416:26
opendevreviewMerged openstack/ironic-python-agent-builder master: Uninstall unnecessary packages to reduce ramdisk size  https://review.opendev.org/c/openstack/ironic-python-agent-builder/+/99305016:51
opendevreviewJulia Kreger proposed openstack/ironic-specs master: Backlog: NVMe-oF boot/data volumes  https://review.opendev.org/c/openstack/ironic-specs/+/99053217:26
cardoeWell if ya want you can read the completely rewritten spec... https://review.opendev.org/c/openstack/ironic-specs/+/98459618:01
opendevreviewMerged openstack/ironic-python-agent master: Fix: Remove legacy agent_token fallback code  https://review.opendev.org/c/openstack/ironic-python-agent/+/99731018:29
opendevreviewJay Faulkner proposed openstack/ironic-python-agent bugfix/11.6: Fix: Remove legacy agent_token fallback code  https://review.opendev.org/c/openstack/ironic-python-agent/+/99744619:32
opendevreviewJay Faulkner proposed openstack/ironic-python-agent stable/2025.2: Fix: Remove legacy agent_token fallback code  https://review.opendev.org/c/openstack/ironic-python-agent/+/99744919:50
keekzi'm hitting a weird issue with 1 of our environments when attempting to delete a baremetal node: https://gist.github.com/nicholaskuechler/6ce63fd5e773eb60212d85b9ff588075 - for the user and in the logs there are errors and a trace. i can re-add the node and delete again and get the same errors. has anyone else encountered this? 19:58
TheJulia.... Uhh... hmmm20:49
TheJuliakeekz: do you have notifications turned on? 20:50
TheJuliahttps://github.com/openstack/ironic/blob/master/ironic/api/controllers/v1/node.py#L3371-L337220:50
keekzyes but we don't have a good way to read notifications :(20:51
keekzwhy do you ask, should i dump all the messages and find the one for this delete?20:53
keekzactually you might have led me towards the answer. i think our rabbit is 100% full20:56
TheJuliaso yeah heh20:57
TheJuliaokay20:57
TheJuliaits a straight forward bug fix... I think20:57
TheJuliaI suspect20:57
TheJuliabut yeah, your officially the only operator I know of really using notifications now20:57
JayF<--20:57
TheJuliaoh, okay20:57
* TheJulia will go fix20:57
JayFnotifications are in heavy use20:57
TheJuliaor at least try to20:57
keekz@jayf what's that look like for you, where do you send the notifications, what tools do you use to read them, etc?20:58
JayFkeekz: I don't have that level of operational detail. It goes out over kafka into [black hole of operational magic]20:59
keekzi've hit weird issues before when the rabbit gets full, but we had previously set up ttls to purge messages older than like 3 days. something is funky in this environment though as it's using queues/exchanges we aren't ttl'ing. not sure how to share screenshots on old timey irc20:59
keekzi have around 10 or so queues named like 'ironic-neutron-agent-member-manager-pool-55c5b75a-60f4-4de5-89cf-1c045dca69bf' each with over 500k messages. i haven't seen these queues grow so large before21:01
TheJuliadidn't you also have some issues with like retires being turned way up and timer counts also bein gturned way up?21:04
TheJuliaThose should just be heartbeats afaik21:10
keekzi don't think we're doing anything special with retries / timer counts.. just the defaults afaik21:10
TheJuliakeekz: what version of ironic is this?21:14
keekz2026.1 with some recent cherrypicks21:15
keekzi call it the cardoe special21:15
TheJuliaits a race condition it looks like21:15
* cardoe looks up from neutron21:15
TheJuliaso, claude thinks something different a than me right now21:16
cardoehttps://github.com/rackerlabs/ironic/tree/understack/2026.1 is the literal code21:16
TheJuliawhich is actually more in line with what your errors indicate as well21:16
cardoeIt's stable/2026.1 with the runbooks v2 backported21:17
TheJuliathe tl;dr is sort of along the lines the db's record deletion is immediate in your case where as its likely not in most other cases so things sort of go sideways later on21:18
TheJulialikely just super spiffy database21:19
JayFor rabbitmq slower than molasses?21:19
TheJuliaeh, That likely doesn't play in here21:19
TheJuliathe issue is the db has already committed the delete commit and then the task goes to unwind the task again which is wrong21:20
JayFoh that's a weird race21:20
TheJuliabut it woudl work if that row is still lingering for a little bit21:20
JayFthe DB holds the reservation21:20
TheJuliayeah, but destroy nukes the row21:20
JayFbut deleting the row also deletes the reservation21:20
TheJuliabut that is not always the fastest thing on DBs21:21
TheJuliayup21:21
TheJuliaits literally a one-liner but I have claude making a unit test21:21
TheJuliaoh, its worse of sorts21:24
TheJuliait the record still lingers for a little while and finds the lock record it seems21:24
TheJuliaat least, thats its write-up21:24
TheJuliawe've seen something like this before, I just don't remember how exaclty it presented21:26
TheJuliaalso, read replicas21:31
opendevreviewJulia Kreger proposed openstack/ironic master: Fix destroy_node race condition  https://review.opendev.org/c/openstack/ironic/+/99745821:32
TheJuliathey will lag and still show a lock21:32
TheJuliaso... yeah, this can happen21:32
TheJuliakeekz: cardoe: There you go21:32
cardoeTheJulia: remember when you came to my Ted Talk about a TaskManager object having a None node and that being a really weird case and I'm trying to teach the type checking about it?21:33
TheJuliaAye, and I'm sure that fix is making you twitch21:34
TheJuliaBut it does short circuit the attempt to cleanup21:34
keekzthanks @thejulia!21:35
cardoeTheJulia: not really making me twitch but just highlighting the case where I think I'm right21:37
TheJuliaWe're going to need an asylumn for ironic contributors, aren't we?/21:38
cardoeLet's just say Claude ran away and is sitting in the corner rocking back and forth crying.21:38
TheJuliaClearly claude forgot it's self hugging jacket!21:39
cardoeThe reason I haven't make the patch yet is cause it's blown its 1M context window and threw itself into multiple compacting loops and forgot what it was doing.21:39
cardoeI think the right fix is that we don't actually grab the node in the __init__ of TaskManager21:39
cardoeWe've provided a contextmanager __enter__ which just returns self. I think we move that logic into __enter__21:40
TheJulia++21:40
TheJuliaI think that makes a lot of sense actually21:40
TheJuliawe might need to re-write some tests21:41
TheJuliabut yeah21:41
cardoeYeah. That's where it got bogged down and lost.21:41
TheJuliatechincally if not already loaded acquire could populate it21:41
TheJuliathat wouldn't really require test changes...21:41
TheJuliaand sort of follows the same pattern21:41
cardoeacquire just returns self21:41
cardoeBut yes21:42
TheJuliai thought it executes21:42
cardoehrm maybe21:42
cardoetoo much neutron in context right now21:42
cardoeI'm lost in oslo.policy hell21:43
TheJuliaugh21:43
TheJuliaMay I recommend a Tuacca Alexander as a soothing beverage to address all pains of RBAC21:43
TheJuliaSorry, Tuaca Alexander, only one C in Tuaca21:45
JayFit's like if jameison was vanilla21:45
TheJuliablending is also acceptable21:45
TheJulia+++21:45
JayF(that was one of my best friends' drinks when I drank decades ago)21:45
cardoeSome objects don't have a project_id but users need to be able to read them. But the migration from tenant_id to project_id seems to have a band aid to always attempt to get project_id into the policy check.21:46
JayFFrom an Ironic POV, those objects need to be made project-aware21:46
JayFlike runbooks are21:46
JayFto be seen by someone with project scope21:46
JayFunless you wanna start handing out system scoped reader roles like candy21:46
TheJuliaI think he is talking of neutron, fwiw21:47
TheJuliaWe may want to see if claude can bring him a nice jacket21:47
JayFoooh21:47
JayFNeutron, same as the old tron21:47
TheJuliaJayF wins21:47
cardoeYeah the issue is that you cannot have both system scope and project scope21:49
cardoeThe failure is "openstack router create --flavor my-flavor my-router"21:49
cardoeCause a regular user can no longer lookup my-flavor21:50
JayFyou should be making noise on the list about some of this21:50
JayFmake sure to tag [rbac] so folks like g maan will see it can can help drive improvement21:50
opendevreviewJulia Kreger proposed openstack/ironic master: Add two-step deferred actions cleanup DB methods  https://review.opendev.org/c/openstack/ironic/+/99494821:55
opendevreviewJulia Kreger proposed openstack/ironic master: Add config options, reschedule exception, and action creation helper  https://review.opendev.org/c/openstack/ironic/+/98922521:55
opendevreviewJulia Kreger proposed openstack/ironic master: Add deferred action launcher periodic and executor  https://review.opendev.org/c/openstack/ironic/+/98922621:55
opendevreviewJulia Kreger proposed openstack/ironic master: Add deferred action cleanup periodic and stuck recovery  https://review.opendev.org/c/openstack/ironic/+/98922721:55
opendevreviewJulia Kreger proposed openstack/ironic master: Add notifications for deferred action terminal states  https://review.opendev.org/c/openstack/ironic/+/98922821:55
opendevreviewJulia Kreger proposed openstack/ironic master: Add metrics gauges and enhanced logging for deferred actions  https://review.opendev.org/c/openstack/ironic/+/98922921:55
opendevreviewJulia Kreger proposed openstack/ironic master: Add upgrade check for deferred action backlog  https://review.opendev.org/c/openstack/ironic/+/98923021:56
opendevreviewJulia Kreger proposed openstack/ironic master: Decompose redfish firmware stability validation into deferred actions  https://review.opendev.org/c/openstack/ironic/+/98923121:56
opendevreviewMerged openstack/ironic master: Drop unused bandit  https://review.opendev.org/c/openstack/ironic/+/99688322:21
opendevreviewVerification of a change to openstack/ironic master failed: Add TLS hardening for kickstart configdrive and inspection rule connections  https://review.opendev.org/c/openstack/ironic/+/98880423:32

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!