| opendevreview | Merged openstack/ironic-python-agent-builder master: Add minimal element ironic-python-agent-ramdisk-base https://review.opendev.org/c/openstack/ironic-python-agent-builder/+/997659 | 00:02 |
|---|---|---|
| opendevreview | Merged openstack/ironic stable/2026.1: security: Fix poisoning of the allowed origin list https://review.opendev.org/c/openstack/ironic/+/998018 | 01:22 |
| opendevreview | Jacob Anders proposed openstack/bifrost master: Add uninstall playbook to reverse bifrost install https://review.opendev.org/c/openstack/bifrost/+/999041 | 01:40 |
| opendevreview | Jacob Anders proposed openstack/bifrost master: Add uninstall playbook to reverse bifrost install https://review.opendev.org/c/openstack/bifrost/+/999041 | 01:45 |
| opendevreview | Merged openstack/ironic-python-agent-builder stable/2025.1: Fixed rescue ConditionPathExists flag https://review.opendev.org/c/openstack/ironic-python-agent-builder/+/998318 | 04:09 |
| opendevreview | Verification of a change to openstack/ironic-python-agent-builder master failed: Write container options as comma separated lists https://review.opendev.org/c/openstack/ironic-python-agent-builder/+/998389 | 04:09 |
| opendevreview | Verification of a change to openstack/ironic-python-agent-builder master failed: Do not require a container steps file to build https://review.opendev.org/c/openstack/ironic-python-agent-builder/+/998390 | 04:09 |
| opendevreview | Merged openstack/ironic-python-agent-builder stable/2025.2: Fixed rescue ConditionPathExists flag https://review.opendev.org/c/openstack/ironic-python-agent-builder/+/999025 | 04:09 |
| opendevreview | Verification of a change to openstack/ironic master failed: Remove disabling the scope enforcement https://review.opendev.org/c/openstack/ironic/+/996687 | 04:17 |
| opendevreview | Merged openstack/ironic master: Remove disabling the scope enforcement https://review.opendev.org/c/openstack/ironic/+/996687 | 06:27 |
| zigo | Hi team ! | 08:45 |
| zigo | Can someone confirm that ironic-python-agent before Caracal is not affected by CVE-2026-54422 / OSSA-2026-028 ? | 08:45 |
| zigo | I tried backporting https://review.opendev.org/c/openstack/ironic-python-agent/+/998479 but it seems the affected code isn't present. | 08:45 |
| zigo | stevebaker[m]: ^ | 08:47 |
| frickler | zigo: https://bugs.launchpad.net/ironic/+bug/2155826/comments/34 ? | 08:54 |
| zigo | Thanks, perfect ! :) | 08:55 |
| zigo | frickler: Is the team now stopping backports at 2024.1 ? | 08:56 |
| zigo | A few weeks / months, it was up to 2023.1, which was nice (ie: Antelope, and I maintain up to Zed). | 08:57 |
| frickler | well the latest maintained branch is 2025.1 as far as openstack upstream (and thus also the ironic team) is concerned. older unmaintained branches are getting updates depending on who cares for them | 09:01 |
| zigo | I know, though the team has done more, which was super nice. | 09:01 |
| zigo | Looks like it's backporting without effort, so probably not needed for me. | 09:07 |
| dtantsur | Hey folks, I've drafted an RFE based on our downstream requirements: https://bugs.launchpad.net/ironic/+bug/2162051. PTAL. | 09:55 |
| rpittau | TheJulia: I was out all morning, but I think I have a solution for that, I'll propose something during the afternoon | 10:54 |
| dtantsur | JayF: as in, you'll be willing to help with portgroups? | 10:55 |
| opendevreview | Rowan Johns proposed openstack/tenks master: Add support for persistent networking https://review.opendev.org/c/openstack/tenks/+/998806 | 12:44 |
| opendevreview | Rowan Johns proposed openstack/tenks master: Add support for persistent networking https://review.opendev.org/c/openstack/tenks/+/998806 | 12:51 |
| opendevreview | Rowan Johns proposed openstack/tenks master: Add support for persistent networking https://review.opendev.org/c/openstack/tenks/+/998806 | 13:03 |
| cardoe | TheJulia: that's a good change in my book | 13:10 |
| TheJulia | rpittau: ack, its just feeling weird since there are some differences | 13:34 |
| TheJulia | dtantsur: didn't I basically propose doing such during a PTG session a couple years ago? | 13:38 |
| opendevreview | Rowan Johns proposed openstack/tenks master: Add support for persistent networking https://review.opendev.org/c/openstack/tenks/+/998806 | 13:42 |
| opendevreview | Rowan Johns proposed openstack/tenks master: Add support for persistent networking https://review.opendev.org/c/openstack/tenks/+/998806 | 13:47 |
| opendevreview | Rowan Johns proposed openstack/tenks master: Add support for persistent networking https://review.opendev.org/c/openstack/tenks/+/998806 | 13:53 |
| TheJulia | fwiw, I've proposed https://review.opendev.org/c/openstack/project-config/+/999124 to clean up IRC messages | 14:02 |
| opendevreview | Rowan Johns proposed openstack/tenks master: Add support for persistent networking https://review.opendev.org/c/openstack/tenks/+/998806 | 14:02 |
| dtantsur | TheJulia: as far as my memory is concerned, if it was not a couple of weeks ago, it didn't happen :D | 14:02 |
| opendevreview | Pierre Riteau proposed openstack/tenks master: Configure sushy to listen on port 8100 https://review.opendev.org/c/openstack/tenks/+/999127 | 14:02 |
| TheJulia | dtantsur: So... no "doublespace" update ? :) | 14:03 |
| TheJulia | or... was it doubler. | 14:03 |
| dtantsur | who? what? :) | 14:03 |
| TheJulia | I don't remember anymore, it was so very very very very very long time ago | 14:03 |
| TheJulia | OH! There was a product that you installed which compressed your filesystem contents for DOS | 14:04 |
| TheJulia | I think there was a couple actually | 14:04 |
| * dtantsur is so confused | 14:06 | |
| TheJulia | https://en.wikipedia.org/wiki/DriveSpace | 14:07 |
| dtantsur | Oh, Windows Me, fun times | 14:09 |
| opendevreview | Doug Goldstein proposed openstack/ironic master: fix: TBN could not handle evaluations of items that were collections https://review.opendev.org/c/openstack/ironic/+/999138 | 14:18 |
| opendevreview | Riccardo Pittau proposed openstack/ironic bugfix/37.0: Pin upper constraints to 2026.1 release branch https://review.opendev.org/c/openstack/ironic/+/998511 | 14:25 |
| opendevreview | Pierre Riteau proposed openstack/tenks master: Configure sushy to listen on port 8100 https://review.opendev.org/c/openstack/tenks/+/999127 | 14:31 |
| opendevreview | Rowan Johns proposed openstack/tenks master: Add support for persistent networking https://review.opendev.org/c/openstack/tenks/+/998806 | 14:32 |
| cardoe | clif: https://review.opendev.org/c/openstack/ironic/+/999138 or am I crazy? | 14:33 |
| TheJulia | reading the code, I don't think so | 14:36 |
| TheJulia | tags was always a list, but that was likely more than anything, an oversight | 14:36 |
| TheJulia | or expecting direct match which might have worked for single values | 14:36 |
| cardoe | okay. So I'm trying to use TBN should be the highlighted comment here. | 14:52 |
| TheJulia | I think that was implied, fwiw | 14:53 |
| JayF | TheJulia: The original brand name of that before Microsoft bought it and put it into dos with stacker. I think stacker's a better name. | 14:53 |
| TheJulia | yeah "doublestacker" | 14:54 |
| cardoe | After the recent conversation about Waffle House, I object to using the phrase "doublestacker" so soon. It sounds like a terrifying menu option coming. | 14:58 |
| TheJulia | "scattered, smothered, covered, and peppered" is my only possible potato order. | 14:59 |
| clif | cardoe: you're not crazy | 15:11 |
| cardoe | Sorry my claude attributed a note to you... I can delete that. | 15:11 |
| clif | I was about to leave a note on that | 15:13 |
| clif | So glad clankers will blame me for things it wrote | 15:13 |
| dtantsur | Can I do that too? :-P | 15:14 |
| clif | :D | 15:14 |
| clif | blame me for things I actually did at least! | 15:15 |
| TheJulia | Ohhh! Ahhh! can we "sell" blame permission ?!? | 15:15 |
| TheJulia | Yeah, I'd fix the inline note and have updated my vote as such | 15:16 |
| TheJulia | I didn't even parse that because I was focusing on the code path | 15:16 |
| JayF | TheJulia: selling blame is already a market cornered by anthropic/openai/friends | 15:17 |
| TheJulia | Well, I mean among friends | 15:18 |
| opendevreview | Merged openstack/ironic bugfix/33.0: security: Fix poisoning of the allowed origin list https://review.opendev.org/c/openstack/ironic/+/998021 | 15:20 |
| opendevreview | Merged openstack/ironic bugfix/34.0: security: Fix poisoning of the allowed origin list https://review.opendev.org/c/openstack/ironic/+/998020 | 15:20 |
| opendevreview | Merged openstack/ironic stable/2025.2: security: Fix poisoning of the allowed origin list https://review.opendev.org/c/openstack/ironic/+/998019 | 15:20 |
| opendevreview | Merged openstack/ironic master: Switch jobs to build centos10 IPA images https://review.opendev.org/c/openstack/ironic/+/992573 | 15:20 |
| opendevreview | Riccardo Pittau proposed openstack/ironic bugfix/37.0: Set tox_constraints_file for bugfix branch Zuul jobs https://review.opendev.org/c/openstack/ironic/+/998511 | 15:25 |
| dtantsur | Looking for a 2nd +2 for a relatively easy bug fix: https://review.opendev.org/c/openstack/ironic/+/998628 | 15:25 |
| TheJulia | If anyone is interested in moving more towards netconf + libssh for ngs, please take a look at https://review.opendev.org/c/openstack/ironic-specs/+/997653 | 15:25 |
| cardoe | Been trying out the clanker for more OpenStack writing... like it transformed my bug report... https://bugs.launchpad.net/neutron/+bug/2162072 | 15:26 |
| dtantsur | TheJulia: maybe merge https://review.opendev.org/c/openstack/ironic-specs/+/998363/ in? I'm normally all for smaller bits, but this one changes some of the decisions we do in the first one. | 15:26 |
| opendevreview | Doug Goldstein proposed openstack/ironic master: fix: TBN could not handle evaluations of items that were collections https://review.opendev.org/c/openstack/ironic/+/999138 | 15:27 |
| cardoe | TheJulia: ^ if ya wanna reapply your review now that the note is clif-less. | 15:27 |
| TheJulia | dtantsur: we likely need to improve the docstring of that method to detail return values, but that would "e nice" | 15:28 |
| dtantsur | I can follow-up | 15:28 |
| TheJulia | dtantsur: I'd kind of prefer to keep them separated, because we're functionally talking very different things. The libssh direct modeling for running a single command doesn't work in any case where we need to do more switch level config ui state engagement | 15:29 |
| opendevreview | cid proposed openstack/ironic-tempest-plugin master: Add graphical console API tests https://review.opendev.org/c/openstack/ironic-tempest-plugin/+/999143 | 15:30 |
| dtantsur | TheJulia: it's just odd to discuss certain claims in the spec knowing that we want to change them completely.. | 15:31 |
| TheJulia | such as rip/replace paramiko entirely? | 15:32 |
| TheJulia | This is a middle ground path to at *least* get us to a better place where non-paramiko paths exist | 15:32 |
| TheJulia | (responses will be delayed, on a call | 15:33 |
| dtantsur | Okay, I can live with that. | 15:33 |
| opendevreview | cid proposed openstack/ironic master: A non-voting job for the container console provider https://review.opendev.org/c/openstack/ironic/+/998934 | 15:33 |
| opendevreview | Serhii Ivanov proposed openstack/sushy-tools master: Add empty BootOptions collection stub and Boot navigation links https://review.opendev.org/c/openstack/sushy-tools/+/991910 | 15:38 |
| TheJulia | Yeah, the other reason is ncclient also has a dependency on paramiko, but the reason I've avoided making transport configurable, and even even preferred putting libssh as the transport in the name it lock down "what we know is good to be as clear as possible | 15:41 |
| TheJulia | tailing " needed there | 15:42 |
| TheJulia | I guess the underlying tl;dr is there is a method to my madness | 15:44 |
| opendevreview | Merged openstack/networking-generic-switch master: Remove Python 3.10 support https://review.opendev.org/c/openstack/networking-generic-switch/+/998642 | 15:51 |
| opendevreview | Serhii Ivanov proposed openstack/sushy-tools master: Add empty FirmwareInventory collection stub under UpdateService https://review.opendev.org/c/openstack/sushy-tools/+/991905 | 15:55 |
| opendevreview | Serhii Ivanov proposed openstack/sushy-tools master: Add EthernetInterface UefiDevicePath derived from PCI topology https://review.opendev.org/c/openstack/sushy-tools/+/991909 | 16:06 |
| JayF | TheJulia: https://review.opendev.org/c/openstack/ironic-specs/+/997653/3#message-4c038362bf0209aa11b7403f0befcb20f6d77f82 | 16:10 |
| JayF | TheJulia: tl;dr: I have reports, in the wild (from testing at Rackspace, on an OnMetal time frame) of NETCONF being so slow and unusable on some switches that we had to use SSH instead | 16:10 |
| JayF | TheJulia: so I am highly skeptical of the claims throughout that spec that SSH->NETCONF is a guaranteed performance boost in all cases; especially since I know at least one case in my not-that-extensive-history-of-networking where it wasn't the case. | 16:11 |
| JayF | The -1 is because of the insistence throughout of a path to deprecation of netmiko/paramiko drivers. I do not believe we should commit to any of that in a spec until the drivers using a new method exist and have proven themselves to be performant. Adding a new, parallel driver framework for science? Yes. Committing to replacing existing stuff with code that doesn't exist yet? No way. | 16:12 |
| TheJulia | le sigh, I mean, the paramiko stuff is not super performant, either | 16:13 |
| JayF | No, but it has known performance characteristics that folks have been dealing with for a while | 16:14 |
| TheJulia | fair, I guess. | 16:14 |
| JayF | I'd believe 100% that the stuff at Rackspace was some environental-based issue I didn't know enough about to remember now, but those kinda environmental things are exactly what I'm guarding against | 16:15 |
| JayF | I don't want all Ironic customers to have to have THE CONVERSATION(tm) with their NoC again. | 16:15 |
| TheJulia | If we dial back explicit early deprecation, then maybe just having the alternate path will be enough to make consumers happy | 16:16 |
| JayF | yeah I mean, to me NGS is the ultimate "bag full o'hacks" | 16:16 |
| JayF | and I don't wanna commit to throwing out all our dirty tricks until we know the proper paths are production ready :) | 16:17 |
| JayF | ugly, gross, and working: NGS for a decade | 16:17 |
| JayF | lol | 16:17 |
| TheJulia | oh my | 16:23 |
| TheJulia | yeah, I was thinking deprecate just to signal "not the preferred path" once we had the new path | 16:24 |
| JayF | I think that's a good move once we have anyone at all running with the new driver :D | 16:24 |
| cardoe | JayF, TheJulia: NETCONF is a protocol over SSH | 16:32 |
| TheJulia | <teal'c>indeed.</teal'c> | 16:32 |
| TheJulia | w/r/t running, I was thinking the bar upfront as "we've done basic evaluation and we're seeing it work", but that is different. I guess the concern is placing an expectation on working upon the known problematic feedback loop | 16:35 |
| JayF | TheJulia: you think https://docs.google.com/document/d/1UWPpvmzanmqHIsQOalEwM0yJWbxAx9x4Qz1ofnaiMJw/edit?tab=t.0 (a final draft of a blogpost you reviewed earlier) would be a good candidate for ironicbaremetal.org? | 16:37 |
| JayF | I can ungenericize it and make it about Ironic specifically if desired and we go that route | 16:37 |
| TheJulia | I think so, but it might also be better for superuser | 16:39 |
| JayF | I just need it to have a home. There's a long enough backlog for GR blog that I need to find somewhere else. The other fallback option is a medium account we have at gr-oss ... but I think medium is gross (no hyphen) so I'm avoiding that | 16:40 |
| JayF | if for superuser, what's the route to make that happen? | 16:40 |
| TheJulia | I'd normally ping allison price | 16:41 |
| opendevreview | Merged openstack/ironic master: Power off before ejecting redfish virtual media on ramdisk cleanup https://review.opendev.org/c/openstack/ironic/+/998640 | 16:41 |
| opendevreview | Merged openstack/ironic master: Another attempt to fix fast-track after inspection https://review.opendev.org/c/openstack/ironic/+/998628 | 16:41 |
| JayF | I'll assume I should act normally? | 16:42 |
| TheJulia | Generally yes. I mean, I guess you could emulate your spirit animal? | 16:47 |
| TheJulia | "oh, sun puddle! *flop" | 16:47 |
| JayF | my spirit animal is another, angrier me | 16:47 |
| TheJulia | then no spirit animal :) | 16:48 |
| TheJulia | So, the other reason I had regarding deprecation was to begin to flag and signal some drivers as items we're not spending time on | 16:55 |
| TheJulia | like.. c300, FastIron, and others | 16:55 |
| TheJulia | if someone wants to put more effort into them that is fine, but we presently have no means to signal that besides some sort of deprecation. | 16:56 |
| TheJulia | OR, we create a $new_bat_signal | 16:56 |
| TheJulia | It *appears* that renting an explicit bat signal is not an option at the moment | 16:57 |
| TheJulia | JayF: would you instead agree that we likely need to state our expectations regarding some of the legacy drivers and that we can handle that in a separate spec to add a log warning? | 16:59 |
| JayF | I think just a PR marking those as unsupported is sufficient without mentioning it in the spec | 17:03 |
| JayF | for that section of like "btw, these drivers are all crappy: " | 17:03 |
| JayF | As long as our definition of legacy is ^^^ and not "any *miko drivers" | 17:04 |
| TheJulia | well, trying to set a tone more so that "we're not going to invest in these drivers" | 17:04 |
| JayF | That's only a true statement if the netconf drivers have performance and feature partity | 17:05 |
| JayF | Your brain is visioned into the future that doesn't exist yet :) I'm happy to shelve the past once the future is the present | 17:06 |
| TheJulia | I mean, its not like these devices even support netconf either or any mode of configuration we can adapt so why not draw a line upfront? | 17:07 |
| TheJulia | I guess I was hoping to make it clear upfront | 17:07 |
| TheJulia | and your preferring the keep everything and not signal at all approach | 17:08 |
| JayF | I don't think it is clear though, regardless of what we say. We have likely hundreds of working NGS installs using existing drivers, across who-knows how many switch/firmware models in those families? | 17:08 |
| TheJulia | which doesn't really work for me because then I risk inherent scope creep unless I explicitly limit for netconf supporting devices | 17:08 |
| JayF | Honestly, I see this as like ... ipmitool vs ipminative | 17:09 |
| JayF | ipminative was cool and better 100% on paper | 17:09 |
| JayF | but never panned out in the real world | 17:09 |
| JayF | I think this is much, much more likely to pan out -- but I don't wanna tell people to stop using the old, tested way until we *know* that | 17:09 |
| TheJulia | I guess I'd still like to explicitly signal "hey, we're not investing in these drivers", but that can be another document | 17:10 |
| TheJulia | which is fine | 17:10 |
| JayF | I think *Redhat* is not investing in those drivers. I have a downstream running them, and so do many others, for a while still -- and so there are folks in the community invested in maintaining them and keeping them going. | 17:11 |
| JayF | the only reason the status quo drivers aren't OK is because of the PQC push, and that's not something that every openstack user has as a priority ... or on their radar at all | 17:12 |
| TheJulia | Okay, I just didn't think anyone would realistically be using any of those given the age of the gear at this point. Someone actually saying there is use changes things | 17:12 |
| JayF | so to be clear; two things here: | 17:12 |
| JayF | 1) the big list of drivers in the spec -> JFDI deprecate/notice/whatever I am +1 to | 17:13 |
| JayF | 2) any *miko driver -> JFDI deprecate/notice/whatever I am -1 to | 17:13 |
| TheJulia | okay, I think I can work with that slicing | 17:13 |
| JayF | I think those are getting conflated | 17:13 |
| TheJulia | And part of it is I want to frame this as advancing more modern mechanims as well | 17:14 |
| JayF | yeah, my main thing is "let's not mark the most well implemented, maintained drivers in NGS as anything-negative until they have better replacements" (even in a spec) | 17:14 |
| TheJulia | and some of these others, its more full of nope because they are more "legacy" than somethihng more "modern" | 17:14 |
| TheJulia | fair enough | 17:15 |
| TheJulia | rpittau: I guess what I've been forgetting is the overall file to use is set as an environment variable, we just need to change the branch to use a local file and entirely disregard the environment variable | 17:43 |
| cardoe | hjensas: https://review.opendev.org/c/openstack/neutron/+/999158 I needed that fwiw | 18:33 |
| TheJulia | hjensas is out for a few weeks | 18:57 |
| TheJulia | jfyi | 18:57 |
| opendevreview | cid proposed openstack/ironic-python-agent-builder master: Write container options as comma separated lists https://review.opendev.org/c/openstack/ironic-python-agent-builder/+/998389 | 19:09 |
| opendevreview | cid proposed openstack/ironic-python-agent-builder master: Do not require a container steps file to build https://review.opendev.org/c/openstack/ironic-python-agent-builder/+/998390 | 19:09 |
| opendevreview | cid proposed openstack/ironic-python-agent-builder master: Verify registry TLS by default in the podman element https://review.opendev.org/c/openstack/ironic-python-agent-builder/+/999178 | 19:09 |
| opendevreview | Jay Faulkner proposed openstack/ironic-python-agent master: Security: Make mDNS discovery explicitly opt-in https://review.opendev.org/c/openstack/ironic-python-agent/+/997637 | 19:18 |
| opendevreview | Jay Faulkner proposed openstack/ironic-python-agent master: Allow limiting what config can be set in mDNS https://review.opendev.org/c/openstack/ironic-python-agent/+/997638 | 19:18 |
| opendevreview | Jay Faulkner proposed openstack/ironic-python-agent master: Allow limiting what config can be set in mDNS https://review.opendev.org/c/openstack/ironic-python-agent/+/997638 | 19:18 |
| JayF | TheJulia: ^ had to add a Related-bug, if you get a chance and wanna restore your +2 | 19:18 |
| opendevreview | Steve Baker proposed openstack/ironic-python-agent-builder master: Add podman package to ironic-python-agent-ramdisk https://review.opendev.org/c/openstack/ironic-python-agent-builder/+/970336 | 22:14 |
| JayF | ^ We should absolutely not do that. We basically double the attack surface of our default IPA image by enabling bootc and containerhardwaremanager in default ramdisks. :( | 22:36 |
| * JayF has placed that comment on there | 22:36 | |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!