Tuesday, 2026-08-04

hroy_estherd[m], good morning! :)04:30
hroy_I see that in https://review.opendev.org/c/openstack/ironic/+/996347 the NodeHistory version set includes 1.4, shouldn't it be only till 1.3, or am I missing something?04:31
hroy_also, did you get a chance to send out an email to openstack mailing list requesting folks to share some use cases they have04:32
opendevreviewRiccardo Pittau proposed openstack/ironic master: Fix fast-track deployment failure with autodetect deploy interface  https://review.opendev.org/c/openstack/ironic/+/99969909:31
rpittaudtantsur: I think this ^ will fix the issue we're seeing in BMO e2e tests in metal3 from time to time, looks like a race condition09:35
opendevreviewcid proposed openstack/ironic master: Fix socat console broken by shell-quoting  https://review.opendev.org/c/openstack/ironic/+/99970109:48
dtantsurrpittau: nice catch!10:06
opendevreviewDmitry Tantsur proposed openstack/ironic master: Refresh the scaling guide in the reference architecture  https://review.opendev.org/c/openstack/ironic/+/99799810:38
dtantsurTheJulia: updated ^^^10:38
opendevreviewJulia Kreger proposed openstack/ironic bugfix/37.0: security: Fix poisoning of the allowed origin list  https://review.opendev.org/c/openstack/ironic/+/99801710:43
opendevreviewDmitry Tantsur proposed openstack/ironic bugfix/37.0: Power off before ejecting redfish virtual media on ramdisk cleanup  https://review.opendev.org/c/openstack/ironic/+/99925910:43
opendevreviewDmitry Tantsur proposed openstack/ironic bugfix/37.0: Another attempt to fix fast-track after inspection  https://review.opendev.org/c/openstack/ironic/+/99925810:43
stephenfinclif: RE: o.vo mypy plugin: thank gibi. I just took what he had and got it mergeable https://github.com/gibizer/ovo-mypy-plugin11:03
stephenfin(I'm only back to work today)11:03
stephenfinCould someone sanity check https://review.opendev.org/c/openstack/openstacksdk/+/999686 for us, please?11:24
dtantsurOooops!11:55
TheJuliagood morning13:10
opendevreviewDmitry Tantsur proposed openstack/ironic master: Fix Redfish inspection without Storage API  https://review.opendev.org/c/openstack/ironic/+/99971813:26
opendevreviewJacob Anders proposed openstack/ironic master: Unify non-BMC firmware updates under batched state machine  https://review.opendev.org/c/openstack/ironic/+/99972013:33
opendevreviewJacob Anders proposed openstack/ironic master: Document batched firmware updates and add release note  https://review.opendev.org/c/openstack/ironic/+/99972113:33
TheJuliafolks, a relatively quick review on https://review.opendev.org/c/openstack/ironic/+/999656 would be appreciated13:36
dtantsurFYI: the BMO job got broken, and it may be on the Ironic side13:40
dtantsurah, it may be the thing that rpittau posted this morning13:44
opendevreviewcid proposed openstack/ironic master: Drop the unused container_conf_file option  https://review.opendev.org/c/openstack/ironic/+/99838613:46
opendevreviewcid proposed openstack/ironic master: doc: Fix the container-based steps guide  https://review.opendev.org/c/openstack/ironic/+/99838713:46
opendevreviewcid proposed openstack/ironic master: Verify registry TLS by default for agent containers  https://review.opendev.org/c/openstack/ironic/+/99972413:46
opendevreviewcid proposed openstack/ironic-python-agent master: security: Fix the container allowlist not being enforced  https://review.opendev.org/c/openstack/ironic-python-agent/+/99837513:46
opendevreviewcid proposed openstack/ironic-python-agent master: Prevent container steps from shadowing existing steps  https://review.opendev.org/c/openstack/ironic-python-agent/+/99837613:46
opendevreviewcid proposed openstack/ironic-python-agent master: Only honor container step priorities while cleaning  https://review.opendev.org/c/openstack/ironic-python-agent/+/99837713:46
opendevreviewcid proposed openstack/ironic-python-agent master: Accept whitespace separated container options  https://review.opendev.org/c/openstack/ironic-python-agent/+/99837813:46
opendevreviewcid proposed openstack/ironic-python-agent master: Check that the configured container runtime is present  https://review.opendev.org/c/openstack/ironic-python-agent/+/99837913:46
opendevreviewcid proposed openstack/ironic-python-agent master: Report errors reading the container steps file  https://review.opendev.org/c/openstack/ironic-python-agent/+/99838013:46
opendevreviewcid proposed openstack/ironic-python-agent master: Ignore the transport prefix when matching allowed containers  https://review.opendev.org/c/openstack/ironic-python-agent/+/99838113:46
opendevreviewcid proposed openstack/ironic-python-agent master: Drop the unused container_conf_file option  https://review.opendev.org/c/openstack/ironic-python-agent/+/99838213:46
opendevreviewcid proposed openstack/ironic-python-agent master: Rename container_clean_step to generic_container_step  https://review.opendev.org/c/openstack/ironic-python-agent/+/99838313:46
opendevreviewcid proposed openstack/ironic-python-agent master: Verify registry TLS by default  https://review.opendev.org/c/openstack/ironic-python-agent/+/99972513:46
dtantsurrpittau: either https://review.opendev.org/c/openstack/ironic/+/999699 does not work, or we're not actually testing with new ironic13:47
dtantsurthe fact that we missed the breakage initially makes me suspect the latter...13:47
rpittaummmm let me triple check then13:57
dtantsurTesting a revert in https://github.com/metal3-io/ironic-image/pull/1150 (while also checking whether the job picks up ironic changes at all)14:11
opendevreviewcid proposed openstack/ironic-python-agent master: Check that the configured container runtime is present  https://review.opendev.org/c/openstack/ironic-python-agent/+/99837914:23
iurygregorygood morning ironic14:26
rpittaudtantsur: so it looks like we're testing autodetect in ironic CI, but not with fast_track 14:29
rpittauso the "broken" part is skipped14:30
dtantsurrpittau: I mean the ironic-image CI when we enabled autodetect14:30
rpittauoh! I think BMO e2e is the only place then14:31
dtantsurExactly. But why did it succeed if now it fails more or less always?14:31
dtantsurrpittau: there is a suspicious gap though. stevebaker[m]'s patch merged on Jul 24th, BMO failures started around Jul 30th per https://zuul.opendev.org/t/openstack/builds?job_name=metal3-baremetal-operator-functional&project=openstack%2Fironic&branch=master&skip=014:33
dtantsurI wonder if there is an interplay with https://review.opendev.org/c/openstack/ironic/+/998628 too14:34
rpittauI considered this ^ but I excluded it for some reason that I don't recall now14:36
dtantsurrpittau: I'm like 90% sure that these patches together break BMO14:37
rpittauok, let'14:38
rpittaus give it another look14:38
dtantsurrpittau: what makes me confident is the fact that your 38.0 PR fails with this error, while master BMO does not. Master BMO is pinned to an old version because https://github.com/metal3-io/ironic-image/pull/1127 got misteriously closed14:38
dtantsurNot BMO, sorry, ironic-image14:38
rpittauright, that I noticed too14:38
rpittauwell, I can test that actually14:39
dtantsurrpittau: in your patch, it does not look like we receive any heartbeats. The only one I see was rejected because the node was locked.14:42
rpittaummm ok let me check the logs, we're talkgin about the BMO job, right ?14:45
dtantsurrpittau: yep. Ironic https://c16ba2cc0921cdf6518d-f5e06fd9232d0500a75b50f2bf1ad7e1.ssl.cf2.rackcdn.com/openstack/d2916c46bc864f899ab24da3e8bb0cb2/ubuntu-noble/logs/baremetal-operator-system/ironic-service/ironic-service-7bfd6498bb-qr89f/ironic.log IPA https://c16ba2cc0921cdf6518d-f5e06fd9232d0500a75b50f2bf1ad7e1.ssl.cf2.rackcdn.com/openstack/d2916c46bc864f899ab24da3e8bb0cb2/ubuntu-noble/network-data/bmo-e2e-1-serial0.log14:46
rpittauok, let's see14:46
dtantsurHere is how I see it: before my fix, fast-track was just broken, and we used to do a normal deployment.14:46
dtantsurNow fast-track works during inspection, but if the heartbeat never arrives at the right time, deployment is broken instead.14:46
rpittausoemthing on the conductor side ?14:47
dtantsurThe right answer seems to be "we need to send agent_url during inspection", but I don't know how to produce a backportable fix14:47
rpittauanyway it looks like just adding HeartbeatMixin does not fix the issue14:47
dtantsurI'm also not sure why autodetect seems to play a role14:47
dtantsurwell, it's an improvement. but the node is locked, so we still cannot record agent URL14:48
dtantsur(another "thank you" to our love for free-form JSON fields...)14:48
dtantsurrpittau: where does the agent_url validation happen? can we park the node until the next heartbeat?14:50
opendevreviewMerged openstack/ironic master: Drop nonexistent irrelevant-files; update the list in metal3-jobs  https://review.opendev.org/c/openstack/ironic/+/99830114:50
dtantsur(this is going to make the whole thing ~ 30 seconds longer, which is also terrible)14:50
opendevreviewMerged openstack/ironic master: Portgroup shard filter bypasses scope to project  https://review.opendev.org/c/openstack/ironic/+/99965614:52
rpittauthe agent_url sohuld be stored after HeartbeatMixin state check14:54
rpittaubut it never happen14:54
rpittauthe upgrade_lock fails because inspector is holding the lock, so yeah we need to send that during the inspection14:54
rpittauwe can park the node in DEPLOYWAIT ?14:55
opendevreviewcid proposed openstack/ironic-python-agent master: Check that the configured container runtime is present  https://review.opendev.org/c/openstack/ironic-python-agent/+/99837914:57
dtantsurTechnically, we can pause a step until the next heartbeat14:57
opendevreviewcid proposed openstack/ironic-python-agent master: Report errors reading the container steps file  https://review.opendev.org/c/openstack/ironic-python-agent/+/99838014:57
opendevreviewcid proposed openstack/ironic-python-agent master: Ignore the transport prefix when matching allowed containers  https://review.opendev.org/c/openstack/ironic-python-agent/+/99838114:57
opendevreviewcid proposed openstack/ironic-python-agent master: Drop the unused container_conf_file option  https://review.opendev.org/c/openstack/ironic-python-agent/+/99838214:57
opendevreviewcid proposed openstack/ironic-python-agent master: Rename container_clean_step to generic_container_step  https://review.opendev.org/c/openstack/ironic-python-agent/+/99838314:57
opendevreviewcid proposed openstack/ironic-python-agent master: Verify registry TLS by default  https://review.opendev.org/c/openstack/ironic-python-agent/+/99972514:57
rpittauok, makes sense,I can proabbly add that to the fix patch14:59
dtantsurrpittau: dunno if a 30 sec delay can be considered acceptable.. but let's see if it even helps15:01
dtantsurI'd rather revert the autodetect switch tbh. Then update Ironic in ironic-image. Then see how we re-introduce autodetect.15:02
dtantsurIF autodetect has a part in it at all15:02
rpittauI'll write something quickly15:02
opendevreviewRiccardo Pittau proposed openstack/ironic master: Fix fast-track deployment failure with autodetect deploy interface  https://review.opendev.org/c/openstack/ironic/+/99969915:50
rpittaudtantsur: new code makes bmo e2e test fails -> https://github.com/metal3-io/ironic-image/pull/115115:54
rpittaulet's see how the fix behaves now15:54
dtantsurrpittau: if we go down ^^^ path, maybe we need to add the 3rd part to heartbeat manager in the conductor: if agent_url is not recorded and node.reservation is set, fail immediately with CONFLICT15:55
rpittauoh ok15:55
dtantsurrpittau: why: current upgrade_lock happens in a thread and never reaches IPA, so it cannot retry quickly15:55
dtantsurthere is conflict logic in IPA which cannot be reached this way15:55
rpittaummm I was taking that into consideration, ok15:56
rpittauI was NOT!15:56
dtantsurNOOOOO!!15:56
dtantsur:D15:56
rpittau:D15:56
dtantsurrpittau: meanwhile, https://github.com/metal3-io/ironic-image/pull/1150 should tell us if autodetect plays a role15:56
rpittauack15:56
dtantsur(I've changed it to also update the Ironic pin)15:56
dtantsurUnrelated, but I'd appreciate reviews on https://review.opendev.org/c/openstack/ironic/+/999718. It's blocking testing redfish inspection with sushy-tools.15:58
dtantsuron this note, I'll go try to cool down15:59
opendevreviewMohammed Naser proposed openstack/sushy master: Handle incomplete TaskMonitor responses  https://review.opendev.org/c/openstack/sushy/+/99974116:06
opendevreviewRiccardo Pittau proposed openstack/ironic master: Fix fast-track deployment failure with autodetect deploy interface  https://review.opendev.org/c/openstack/ironic/+/99969916:13
opendevreviewYorick proposed openstack/sushy master: system: guard HttpBootUri writes against iDRAC 10 removal  https://review.opendev.org/c/openstack/sushy/+/99974316:20
cardoeBoy... mnaser opening that change against sushy TaskMonitor makes me look at the API and say... wat?16:46
opendevreviewJulia Kreger proposed openstack/ironic master: Add image_server_auth_hosts to restrict credential scope  https://review.opendev.org/c/openstack/ironic/+/99974416:57
TheJuliaJayF: replied on https://review.opendev.org/c/openstack/ironic/+/99974417:02
TheJuliaother ironic-cores, might be good to take a look17:03
TheJuliacardoe:  the redfish API or what vendors do with it?17:03
JayFYeah I mean, you're not wrong per se, but I also suspect we'll have operators who will not be able to use the feature as written17:03
TheJuliaso then do we globify everything?17:05
TheJuliaand even then, the other stuff is all CDN'ed anyhow17:05
TheJuliado we open that door, or not I guess is the bigger question17:06
JayFI was thinking something simpler than a glob might be easier to implement17:06
JayF"example.com" matches example.com17:06
JayF".example.com" matches *.example.com17:06
TheJuliaso, allow pure domain name matching in addition to FQDN matching17:06
JayFthis would also allow `.internal` as a config17:06
TheJuliatrue17:06
JayFthis is basically the case I'm thinking, re: internal domains17:06
TheJuliaxupdating17:08
opendevreviewJulia Kreger proposed openstack/ironic master: Add image_server_auth_hosts to restrict credential scope  https://review.opendev.org/c/openstack/ironic/+/99974417:26
adam-metal3hello18:12
TheJuliagreetings18:17
opendevreviewJay Faulkner proposed openstack/ironic stable/2026.1: Portgroup shard filter bypasses scope to project  https://review.opendev.org/c/openstack/ironic/+/99976220:28
opendevreviewJay Faulkner proposed openstack/ironic bugfix/38.0: Portgroup shard filter bypasses scope to project  https://review.opendev.org/c/openstack/ironic/+/99976320:33
opendevreviewJay Faulkner proposed openstack/ironic bugfix/37.0: Portgroup shard filter bypasses scope to project  https://review.opendev.org/c/openstack/ironic/+/99976420:33
opendevreviewJay Faulkner proposed openstack/ironic bugfix/34.0: Portgroup shard filter bypasses scope to project  https://review.opendev.org/c/openstack/ironic/+/99976520:34
JayFRFR https://review.opendev.org/c/openstack/ossa/+/999767 [OSSA-2026-033] Ironic portgroup scoping20:43
cardoeReviewed and merged.23:17

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!