Monday, 2023-06-26

mnasiadkahrw: reminding :)07:22
hrwmnasiadka: about?07:26
hrwmnasiadka: https://copr.fedorainfracloud.org/coprs/hrw/erlang-25-for-rabbitmq/build/6113185/ started07:32
mnasiadkahrw: erlang 25 :) - it's Monday ;)07:32
mnasiadkanice, thanks07:32
hrw25.3.2 or 25.2.3 - the latest 25.x one07:32
hrw25.3.2 ;D07:33
mnasiadka25.3.2 is fine ;)07:42
hrw09:47 <fedora-notif___> hrw's erlang-25-for-rabbitmq copr build of erlang-25.3.2-1 for centos-stream-8-aarch64 finished with 'success'  https://copr.fedoraproject.org/coprs/hrw/erlang-25-for-rabbitmq/build/6113185/07:48
hrw09:48 <fedora-notif___> hrw's erlang-25-for-rabbitmq copr build of erlang-25.3.2-1 for centos-stream-9-aarch64 finished with 'success'  https://copr.fedoraproject.org/coprs/hrw/erlang-25-for-rabbitmq/build/6113185/07:48
hrwmnasiadka: so feel free to use those repos where needed07:48
mnasiadkawill do, thanks07:54
hrwyw07:58
opendevreviewMichal Nasiadka proposed openstack/kolla stable/yoga: ovsdpdk: add libdpdk-dev  https://review.opendev.org/c/openstack/kolla/+/88031708:12
opendevreviewMichal Nasiadka proposed openstack/kolla stable/yoga: Update support matrix  https://review.opendev.org/c/openstack/kolla/+/87534108:14
opendevreviewMichal Nasiadka proposed openstack/kolla master: ubuntu: mark collectd and telegraf as buildable  https://review.opendev.org/c/openstack/kolla/+/88400108:15
opendevreviewMichal Nasiadka proposed openstack/kolla master: ubuntu: mark collectd and telegraf as buildable  https://review.opendev.org/c/openstack/kolla/+/88400108:16
opendevreviewMichal Nasiadka proposed openstack/kolla stable/yoga: opensearch: move to yum/apt repos  https://review.opendev.org/c/openstack/kolla/+/88371608:17
opendevreviewMichal Nasiadka proposed openstack/kolla stable/yoga: opensearch: move to yum/apt repos  https://review.opendev.org/c/openstack/kolla/+/88371608:18
opendevreviewMichal Nasiadka proposed openstack/kolla stable/yoga: opensearch-dashboards: Fix permissions  https://review.opendev.org/c/openstack/kolla/+/88437508:18
opendevreviewMichal Nasiadka proposed openstack/kolla master: Use erlang-25 from copr on aarch64  https://review.opendev.org/c/openstack/kolla/+/88694808:37
opendevreviewMichal Nasiadka proposed openstack/kolla master: mariadb: Bump to current LTS (10.11)  https://review.opendev.org/c/openstack/kolla/+/88292408:48
opendevreviewMatt Crees proposed openstack/kolla-ansible stable/yoga: Correct [pci] syntax in Nova SRIOV documentation  https://review.opendev.org/c/openstack/kolla-ansible/+/88501009:18
opendevreviewVerification of a change to openstack/kolla stable/zed failed: opensearch: drop unnecessary workarounds  https://review.opendev.org/c/openstack/kolla/+/88683310:36
opendevreviewVerification of a change to openstack/kolla stable/2023.1 failed: opensearch: drop unnecessary workarounds  https://review.opendev.org/c/openstack/kolla/+/88683210:37
opendevreviewVerification of a change to openstack/kolla stable/zed failed: opensearch: drop unnecessary workarounds  https://review.opendev.org/c/openstack/kolla/+/88683311:20
opendevreviewVerification of a change to openstack/kolla stable/2023.1 failed: opensearch: drop unnecessary workarounds  https://review.opendev.org/c/openstack/kolla/+/88683212:20
mnasiadkahmm, The repository 'https://launchpad.net/~rabbitmq/+archive/ubuntu/rabbitmq-erlang-25 jammy Release' does not have a Release file.12:37
guesswhat[m]Why is net.ipv4.ip_forward disabled for kolla and its requirement? Thanks12:37
guesswhat[m]I would like to spin additional containers, but host mode networking is quite tricky12:37
mnasiadkaWe just don't set it, right? https://review.opendev.org/c/openstack/kolla-ansible/+/80997712:41
mnasiadkajust set it on your own if you're happy with it12:41
guesswhat[m]docker package is setting it ( otherwise bridge network would not work ), but its 0 infact12:44
guesswhat[m]so kolla is setting it12:45
guesswhat[m]https://github.com/openstack/kolla-ansible/commit/da476a7fea9f4e32e76ba6b1fbb46a3e4b78dcff12:46
SvenKieskethere's a todo comment to remove that in zed cycle, mhmm13:00
guesswhat[m]mgoddard: ping ^ 13:06
opendevreviewAdam Stackhouse proposed openstack/kolla-ansible master: Adding mariadb_port to wsrep sync status so alterative ports can be used  https://review.opendev.org/c/openstack/kolla-ansible/+/88658113:30
opendevreviewMerged openstack/kolla stable/zed: opensearch: drop unnecessary workarounds  https://review.opendev.org/c/openstack/kolla/+/88683314:00
guesswhat[m]Is Skyline tested enough ? Trying to logging via admin, but getting Username or password is incorrect, while horizon auth is working correctly. Thanks14:09
opendevreviewMerged openstack/kolla stable/2023.1: opensearch: drop unnecessary workarounds  https://review.opendev.org/c/openstack/kolla/+/88683214:15
SvenKieskeguesswhat[m]:  do you mean the k-a side or skyline in general? I'd be interested in an answer for skyline in general as well, as i've never used it personally, yet.15:00
mnasiadkaSvenKieske: it has been removed AFAIK15:16
mnasiadkaguesswhat[m]: we are not responsible for testing an OpenStack project, we just deploy it - if it's in early stages (like skyline) - expect a bumpy ride.15:16
kevkoSvenKieske i've replied to  your comment15:17
mnasiadkakevko, hrw, frickler: https://review.opendev.org/c/openstack/kolla/+/886948 rabbitmq centos/rocky aarch64 is happy, ubuntu needs to be solved with a separate patch15:18
hrwbumped to +215:21
mnasiadkathanks15:24
fricklerip_forward was removed in zed https://review.opendev.org/c/openstack/kolla-ansible/+/85525915:46
mnasiadkafrickler: I think you're designate savvy - any idea what to do with this https://review.opendev.org/c/openstack/kolla/+/886636 ? Either we switch the user to root - or add an option in kolla_docker to specify a user and in infoblox case run it as root16:00
mnasiadkaand I think it's time for https://review.opendev.org/c/openstack/kolla-ansible/+/886485?tab=change-view-tab-header-zuul-results-summary16:01
guesswhat[m]SvenKieske: k-a as its proly not configured correctly, so just asking :)16:18
fricklermnasiadka: ack for the latter, -2 for the former16:19
mnasiadkafrickler: ah, haven't noticed that we have a docs entry to build your own container16:19
mnasiadkalet me update my comment ;)16:19
SvenKieskekevko: ah thank you! I didn't expect to have multiple checks in place for the same thing, so didn't bother to look elsewhere16:19
guesswhat[m]frickler: so since zed its always 0, and its not possible to use bridge networking for docker containers, right?16:20
SvenKieskeyou can if you set it manually to 1?16:21
guesswhat[m]not sure which host vulnerability relates to this, theres no mention 16:24
mnasiadkaif you don't have a firewall - and have forwarding enabled globally - this can be a security flaw16:26
guesswhat[m]i see, its not possible to enable forwarding per interface, right16:29
SvenKieskeyes, it is possible to define that per interface: https://serverfault.com/a/85701316:35
SvenKieskemost network sysctls work that way16:35
guesswhat[m]edit: its possible, so if I enable it for non mangement, non external should do the trick16:36
guesswhat[m]Got single baremetal, two nics ( ip of server, range for for external network ), two dummy nics ( management, octavia )16:37
guesswhat[m]I just need to create few containers , reverse proxy, openid provider, nfs, etc.. its doable with host networking , but binding it to management dummy interface ip is not always possible16:39
opendevreviewVerification of a change to openstack/kolla master failed: Use erlang-25 from copr on aarch64  https://review.opendev.org/c/openstack/kolla/+/88694816:53
opendevreviewMerged openstack/kolla-ansible stable/2023.1: Refactor MariaDB and RabbitMQ restart procedure  https://review.opendev.org/c/openstack/kolla-ansible/+/88648517:37
guesswhat[m]hmm, this one ( docker_disable_default_iptables_rules )  https://github.com/openstack/kolla-ansible/blob/master/ansible/group_vars/all.yml#L116 is probably breaking networking for docker containers19:04
guesswhat[m]so kayobe custom containers probably also using host networking19:05
guesswhat[m]I dont understand to this (" A common problem is that Docker sets the default policy of the19:17
guesswhat[m]    ``FORWARD`` chain in the ``filter`` to ``DROP``. " ) https://github.com/openstack/kolla-ansible/blob/1e9f19aa6b2278fe4cd6399a33dff130a48586de/releasenotes/notes/docker-disable-iptables-e9a248a0515f30a6.yaml#L8-L9 , so what would be the ideal state ?19:17
guesswhat[m]<mnasiadka> "if you don't have a firewall..." <- how this firewall rule should look like ?20:53
guesswhat[m]<guesswhat[m]> "how this firewall rule should..." <- or can I use docker_disable_default_iptables_rules: "no", which will enable iptables and forwarding ( for all interfaces ) and manually disable net.ipv4.conf.br-ex.forwarding and net.ipv4.conf.br-int.forwarding ?21:03

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!