mnasiadka | atmark: xena is eol, I'm afraid we can't help you, try pinning fluent-plugin-elasticsearch | 08:13 |
---|---|---|
kevko | mnasiadka: https://review.opendev.org/c/openstack/kolla-ansible/+/904566 ... would be fine to merge :) | 08:48 |
mnasiadka | bbezak, frickler ^^ pretty please | 08:49 |
mnasiadka | I'm the author, so I shouldn't merge it :D | 08:49 |
kevko | aa , yeah | 08:49 |
kevko | mnasiadka: i've also updated horizon patches ..so please check ..and comment where to add som reno etc :D | 08:50 |
mnasiadka | will do | 08:50 |
mnasiadka | but on calls for the next 2-3 hours :( | 08:50 |
kevko | mnasiadka: no problem | 08:52 |
opendevreview | Merged openstack/kolla-ansible master: openvswitch: use Ansible modules to set up bridge https://review.opendev.org/c/openstack/kolla-ansible/+/901695 | 09:02 |
opendevreview | Verification of a change to openstack/kolla stable/2023.2 failed: [follow-up] Use full binary path when invoking ip https://review.opendev.org/c/openstack/kolla/+/907575 | 09:05 |
*** darmach9 is now known as darmach | 09:11 | |
SvenKieske | mnasiadka: can you comment on https://review.opendev.org/c/openstack/kolla-ansible/+/904090/comments/0bb0539a_ec5a328a ? | 09:17 |
opendevreview | Michal Arbet proposed openstack/kolla-ansible master: Fix mariadb role when used with check mode https://review.opendev.org/c/openstack/kolla-ansible/+/907971 | 10:00 |
kevko | frickler: can u comment neutron_state review again please ? I really would like to know if this will be merged or not ..because i have it merged in downstream git repo ..and in near future i am going to upgrade such big openstack :) | 10:07 |
opendevreview | Bartosz Bezak proposed openstack/kolla-ansible master: Add service role to service users https://review.opendev.org/c/openstack/kolla-ansible/+/815577 | 10:10 |
opendevreview | Sven Kieske proposed openstack/kolla-ansible master: precheck: also check fanout and reply queues https://review.opendev.org/c/openstack/kolla-ansible/+/907977 | 10:13 |
opendevreview | Bartosz Bezak proposed openstack/kolla-ansible master: Add service role to service users https://review.opendev.org/c/openstack/kolla-ansible/+/815577 | 10:25 |
kevko | bbezak: https://review.opendev.org/c/openstack/kolla-ansible/+/904566 can u also check please ? | 10:25 |
opendevreview | Bartosz Bezak proposed openstack/kolla-ansible master: Add service role to service users https://review.opendev.org/c/openstack/kolla-ansible/+/815577 | 10:45 |
opendevreview | Bartosz Bezak proposed openstack/kolla-ansible master: Add service role to service users https://review.opendev.org/c/openstack/kolla-ansible/+/815577 | 10:54 |
kevko | frickler: replied | 10:54 |
opendevreview | Bartosz Bezak proposed openstack/kolla-ansible master: Add service role to service users https://review.opendev.org/c/openstack/kolla-ansible/+/815577 | 11:05 |
opendevreview | Bartosz Bezak proposed openstack/kolla-ansible master: Add service role to service users https://review.opendev.org/c/openstack/kolla-ansible/+/815577 | 11:07 |
frickler | mnasiadka: priteau: there have been changes merged to the kayobe stable/yoga branch after the yoga-eom tag was made. this causes the release automation to give a warning when trying to delete that branch, as those commits would get lost | 11:12 |
frickler | the simplest solution would be to simply repropose those changes against the unmaintained/yoga branch now, can you do that? | 11:12 |
frickler | priteau: (sorry for offtopic) the same holds for cloudkitty | 11:13 |
mnasiadka | frickler: that's kayobe we're talking about? | 11:15 |
mnasiadka | ah right, I'm blind | 11:15 |
mnasiadka | jovial: ^^ | 11:15 |
mnasiadka | jovial: can you have a look? | 11:15 |
jovial | sure - thanks for the heads up | 11:21 |
kevko | hmm, ansible-collections-kolla was moved from stable/yoga to unmaintained/yoga ..but now install_deps not working :( | 11:25 |
kevko | https://paste.openstack.org/show/b0XVRZxY9ocHHVkn8jYQ/ | 11:25 |
kevko | https://github.com/openstack/kolla-ansible/blob/2e552b22db31607843bbe8beca35022d90e600de/requirements.yml#L5 | 11:27 |
opendevreview | Bartosz Bezak proposed openstack/kolla-ansible master: Add service role to service users https://review.opendev.org/c/openstack/kolla-ansible/+/815577 | 11:28 |
opendevreview | Merged openstack/kolla stable/2023.2: [follow-up] Use full binary path when invoking ip https://review.opendev.org/c/openstack/kolla/+/907575 | 11:29 |
opendevreview | Bartosz Bezak proposed openstack/kolla-ansible master: Add service role to service users https://review.opendev.org/c/openstack/kolla-ansible/+/815577 | 11:47 |
opendevreview | Bartosz Bezak proposed openstack/kolla-ansible master: Keystone: Remove duplicate CLI --os-system-scope line https://review.opendev.org/c/openstack/kolla-ansible/+/907994 | 11:53 |
frickler | kevko: yes, talk to the unmaintained-cores, not a kolla problem anymore | 11:57 |
opendevreview | Bartosz Bezak proposed openstack/kolla-ansible master: Revert "Disable new defaults and scope for Ironic (RBAC)" https://review.opendev.org/c/openstack/kolla-ansible/+/907274 | 11:59 |
kevko | frickler: okay, no problem ..fixed downstream ..thanks | 12:12 |
guesswhat[m] | How is possible to use ceph-rgw role https://github.com/openstack/kolla-ansible/blob/master/ansible/roles/ceph-rgw/defaults/main.yml#L8, when the rgw is listening on all interfaces ? Thanks | 12:24 |
opendevreview | Matúš Jenča proposed openstack/kolla-ansible master: Implement Redis as caching backend https://review.opendev.org/c/openstack/kolla-ansible/+/903978 | 13:09 |
jovial | Noticed we seem to be using master upper constraints in unmaintained/yoga in the tox job. We don't set override checkout here: https://github.com/openstack/kayobe/blob/unmaintained/yoga/zuul.d/jobs.yaml#L25. Is that failing because unmaintained/yoga doesn't yet exist for requirements yet? | 13:15 |
jovial | Or rather it is falling back to master as unmaintained/yoga does not exist yet | 13:17 |
jovial | Seems so as we used to see: `Switched to branch 'stable/yoga'` | 13:24 |
opendevreview | Bartosz Bezak proposed openstack/kolla-ansible master: Ironic: enable elevated access for users with service role https://review.opendev.org/c/openstack/kolla-ansible/+/908007 | 13:39 |
opendevreview | Bartosz Bezak proposed openstack/kolla-ansible master: Ironic: enable elevated access for users with service role https://review.opendev.org/c/openstack/kolla-ansible/+/908007 | 13:40 |
opendevreview | Bartosz Bezak proposed openstack/kolla-ansible master: Ironic: enable elevated access for users with service role https://review.opendev.org/c/openstack/kolla-ansible/+/908007 | 13:41 |
opendevreview | Bartosz Bezak proposed openstack/kolla-ansible master: Revert "Disable new defaults and scope for Ironic (RBAC)" https://review.opendev.org/c/openstack/kolla-ansible/+/907274 | 13:41 |
SvenKieske | bbezak: regarding the above change (I also commented there): are you really sure this is not a slightly different incarnation of https://bugs.launchpad.net/kolla-ansible/+bug/2049762 (which is on the whiteboard for tomorrow) | 14:10 |
SvenKieske | bbezak: I'll also dig in and see if my first impression is maybe wrong (might very well be the case - I hope!) :) | 14:11 |
opendevreview | Bartosz Bezak proposed openstack/kolla-ansible master: Add service role to service users https://review.opendev.org/c/openstack/kolla-ansible/+/815577 | 14:11 |
SvenKieske | okay, looks fine on first glance, great. | 14:14 |
bbezak | ScenKieske: At this point it looks like the alternative is to implement system-scoped service user for ironic (used by nova-compute-ironic for example). Both options have similar security implications at first glance. but yeah, we need to analyze it more | 14:15 |
bbezak | that is to create system scope role of course | 14:16 |
bbezak | I think that creating global system scoped role has higher possible impact then project scoped service role, that would be system-scoped-like only for ironic | 14:17 |
SvenKieske | bbezak: you are talking about the ironic change to "rbac_service_role_elevated_access" no? because afaik this change this requires a system-scoped service user - and we should definitively implement those regardless any other issues, so thanks for working on that again. | 14:17 |
bbezak | hmm, according to this one https://review.opendev.org/c/openstack/ironic/+/907148 - it doesn't need to be system-scoped service role | 14:18 |
SvenKieske | agreed a project scoped service role would be better, but it seems it's needed for ironic, because other services need access to that. thinking about it, isn't it possible to simply allowlist the required services instead of a system scope? | 14:18 |
bbezak | but let's see | 14:18 |
SvenKieske | mhm looking at the comments, there seems to be some stuff also still unclear in ironic project, at least those were never resolved | 14:21 |
SvenKieske | https://review.opendev.org/c/openstack/ironic/+/907148?tab=comments | 14:21 |
atmark | mnasiadka: No worries. It's fixed. Pinned fluent-plugin-elasticsearch:5.2.5 instead of 5.3.0 | 14:28 |
SvenKieske | bbezak: I took the liberty and asked over in #openstack-ironic, seems your approach is correct, sorry for being a little paranoid :) now I'll do some rereading of keystone docs regarding this, so we maybe can fix https://bugs.launchpad.net/kolla-ansible/+bug/2049762 as well | 14:32 |
bbezak | yeah I say that, thx | 14:33 |
bbezak | I'll look into removing cinder service token part next | 14:35 |
opendevreview | Mark Goddard proposed openstack/kayobe master: Support credentials for custom DNF repositories https://review.opendev.org/c/openstack/kayobe/+/908142 | 15:07 |
opendevreview | Bartosz Bezak proposed openstack/kolla-ansible master: Ironic: enable elevated access for users with service role https://review.opendev.org/c/openstack/kolla-ansible/+/908007 | 15:09 |
opendevreview | Bartosz Bezak proposed openstack/kolla-ansible master: Revert "Disable new defaults and scope for Ironic (RBAC)" https://review.opendev.org/c/openstack/kolla-ansible/+/907274 | 15:09 |
opendevreview | Sven Kieske proposed openstack/kolla-ansible master: WIP: remove service_token_role admin from cinder https://review.opendev.org/c/openstack/kolla-ansible/+/908145 | 15:37 |
SvenKieske | bbezak: feel free to also hack/push on https://review.opendev.org/c/openstack/kolla-ansible/+/908145 I'm sure there is still stuff missing | 15:37 |
opendevreview | Merged openstack/kayobe master: Reload NetworkManager on DNS config change https://review.opendev.org/c/openstack/kayobe/+/907740 | 15:52 |
opendevreview | Pierre Riteau proposed openstack/kayobe stable/2023.2: Reload NetworkManager on DNS config change https://review.opendev.org/c/openstack/kayobe/+/907926 | 15:57 |
opendevreview | Pierre Riteau proposed openstack/kayobe stable/2023.1: Reload NetworkManager on DNS config change https://review.opendev.org/c/openstack/kayobe/+/907927 | 15:57 |
opendevreview | Pierre Riteau proposed openstack/kayobe stable/zed: Reload NetworkManager on DNS config change https://review.opendev.org/c/openstack/kayobe/+/907928 | 15:58 |
mnasiadka | frickler, bbezak, kevko: I guess we should do https://review.opendev.org/c/openstack/kolla/+/907901 now (since we merged the change in k-a yesterday) ;-) | 16:14 |
frickler | mnasiadka: hmm, ovn jobs are failing for that ... :-/ | 16:27 |
frickler | actually were failing on https://review.opendev.org/c/openstack/kolla-ansible/+/901695 already without anyone noticing (blaming myself). might need a revert unless there's an easy fix | 16:29 |
mnasiadka | frickler: it's not only that patch that we're failing on OVN, I'll have a look tomorrow why | 16:30 |
mnasiadka | I doubt that caused those failures | 16:31 |
mnasiadka | but let's try a revert if that fixes | 16:32 |
opendevreview | Michal Nasiadka proposed openstack/kolla-ansible master: Revert "openvswitch: use Ansible modules to set up bridge" https://review.opendev.org/c/openstack/kolla-ansible/+/907931 | 16:32 |
SvenKieske | mhm, can we make these jobs voting then, maybe? I still don't get when to look at failed non voting jobs, and when not to. it also seems nobody else does it right as well, because apparently no one looked at that jobs. | 16:35 |
frickler | mnasiadka: well there were some successful runs yesterday | 16:35 |
frickler | yes, we should make them voting again, but there's the proposal to switch the default anyway, which would implicitly do that I guess | 16:36 |
mnasiadka | yup | 16:36 |
SvenKieske | true, should I prepare a special patch for that or should that be handled by the "make ovn default" patch? | 16:37 |
mnasiadka | let's handle that in make ovn default, and ensure ovs jobs will also be voting | 16:39 |
opendevreview | Michal Nasiadka proposed openstack/kolla-ansible master: openvswitch: Use fail_mode standalone for br-ex https://review.opendev.org/c/openstack/kolla-ansible/+/908166 | 16:40 |
mnasiadka | and let's see if that fixes OVN as well | 16:40 |
opendevreview | Bartosz Bezak proposed openstack/kolla-ansible master: Template system scoped admin-openrc and clouds.yml files https://review.opendev.org/c/openstack/kolla-ansible/+/908168 | 16:41 |
opendevreview | Bartosz Bezak proposed openstack/kolla-ansible master: Template system scoped admin-openrc and clouds.yml files https://review.opendev.org/c/openstack/kolla-ansible/+/908168 | 16:42 |
opendevreview | Bartosz Bezak proposed openstack/kolla-ansible master: Revert "Disable new defaults and scope for Ironic (RBAC)" https://review.opendev.org/c/openstack/kolla-ansible/+/907274 | 16:42 |
opendevreview | Michal Nasiadka proposed openstack/kolla master: Add ovn-bgp-agent / FRR / Horizon BGPVPN dashboard https://review.opendev.org/c/openstack/kolla/+/891617 | 16:47 |
opendevreview | Dawud proposed openstack/kolla-ansible master: Remove the `grafana` volume https://review.opendev.org/c/openstack/kolla-ansible/+/899136 | 17:41 |
opendevreview | Bartosz Bezak proposed openstack/kolla-ansible master: Template system scoped admin-openrc and clouds.yml files https://review.opendev.org/c/openstack/kolla-ansible/+/908168 | 17:54 |
opendevreview | Bartosz Bezak proposed openstack/kolla-ansible master: Revert "Disable new defaults and scope for Ironic (RBAC)" https://review.opendev.org/c/openstack/kolla-ansible/+/907274 | 17:54 |
mnasiadka | frickler: https://review.opendev.org/c/openstack/kolla-ansible/+/908166 seems to fix ovn | 20:10 |
opendevreview | Bartosz Bezak proposed openstack/kayobe master: DNM: ironic secure rbac test https://review.opendev.org/c/openstack/kayobe/+/908198 | 20:16 |
opendevreview | Bartosz Bezak proposed openstack/kayobe master: DNM: ironic secure rbac test https://review.opendev.org/c/openstack/kayobe/+/908198 | 20:18 |
Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!