Monday, 2024-07-29

opendevreviewRoman Krček proposed openstack/kolla-ansible master: Refactor services' check-containers and optimise  https://review.opendev.org/c/openstack/kolla-ansible/+/77324306:58
opendevreviewIvan Halomi proposed openstack/kolla-ansible master: Refactor of docker worker  https://review.opendev.org/c/openstack/kolla-ansible/+/90829507:00
*** SvenKieske|OSISM|PTOuntil2024- is now known as SvenKieske|OSISM[m]07:03
opendevreviewRoman Krček proposed openstack/kolla-ansible master: Fix unintentional trigger of ansible handlers  https://review.opendev.org/c/openstack/kolla-ansible/+/92414507:09
opendevreviewSven Kieske proposed openstack/kolla stable/2024.1: Trivial fix letsencrypt base image  https://review.opendev.org/c/openstack/kolla/+/92508007:50
matusjencaGood morning. Can someone please review my ProxySQL tls patch https://review.opendev.org/c/openstack/kolla-ansible/+/90991207:50
opendevreviewSven Kieske proposed openstack/kolla stable/2023.2: Trivial fix letsencrypt base image  https://review.opendev.org/c/openstack/kolla/+/92508107:50
SvenKieskematusjenca: I'm just back from vacation, I'll have a look!07:52
opendevreviewIvan Halomi proposed openstack/ansible-collection-kolla master: Add uninstall tasks  https://review.opendev.org/c/openstack/ansible-collection-kolla/+/92508308:47
opendevreviewMatt Crees proposed openstack/kayobe master: Bump stackhpc.linux collection to v1.2.3  https://review.opendev.org/c/openstack/kayobe/+/92448008:52
opendevreviewMatúš Jenča proposed openstack/kolla-ansible master: Switch mariadb's loadbalancer from HAProxy to ProxySQL  https://review.opendev.org/c/openstack/kolla-ansible/+/91372409:36
opendevreviewMatúš Jenča proposed openstack/kolla-ansible master: Add backend TLS between MariaDB and ProxySQL  https://review.opendev.org/c/openstack/kolla-ansible/+/90991209:36
opendevreviewMatúš Jenča proposed openstack/kolla-ansible master: Add documentation for caching.  https://review.opendev.org/c/openstack/kolla-ansible/+/91828510:41
opendevreviewMatúš Jenča proposed openstack/kolla-ansible master: Implement TLS for Redis  https://review.opendev.org/c/openstack/kolla-ansible/+/90918810:51
opendevreviewMatúš Jenča proposed openstack/kolla-ansible master: Add Redis as caching backend for Keystone  https://review.opendev.org/c/openstack/kolla-ansible/+/90920110:51
opendevreviewMatúš Jenča proposed openstack/kolla-ansible master: Add Redis as caching backend for Nova  https://review.opendev.org/c/openstack/kolla-ansible/+/90920310:52
opendevreviewMatúš Jenča proposed openstack/kolla-ansible master: Add Redis as caching backend for Placement  https://review.opendev.org/c/openstack/kolla-ansible/+/90922210:53
opendevreviewMatúš Jenča proposed openstack/kolla-ansible master: Add Redis as caching backend for Heat  https://review.opendev.org/c/openstack/kolla-ansible/+/90922410:54
deflatedHi people, trying to deploy tls for the backend, how do i deploy official certs and not self signed ones? is there a tag i can pass ..multinoide certificates or use the same cert as for internal? Can't seem to figure it out without seeing some kind of error regarding ssl in the attempted deployment11:09
PrzemekKFollow https://docs.openstack.org/kolla-ansible/latest/admin/tls.html we have in globals haproxy_backend_cacert_dir: "/etc/ssl/certs" openstack_cacert: "/etc/ssl/certs/ca-certificates.crt" kolla_enable_tls_internal: "yes" kolla_enable_tls_external: "yes"11:19
PrzemekK.11:20
PrzemekKand /etc/kolla/certificates/: ca  haproxy-internal.pem  haproxy.pem /etc/kolla/certificates/ca: prodca.crt  root.crt11:20
deflatedthank you!11:21
deflatedi'll give it a go now11:21
PrzemekKand kolla_copy_ca_into_containers: "yes"11:23
deflatedi assume kolla_enable_tls_backend/11:27
deflatedkolla_verify_tls_backend should also be yes?11:27
PrzemekKit is enabled by default i think / By default, the TLS certificate will be verified as trustable by the OpenStack services. Although not recommended for production, it is possible to disable verification of the backend certificate:11:33
deflatedThey are and I certainly do want it to be secure. can you tell me what your prodca/root.crt relate to? i would assume root.crt is LE's ISRG Root X1 and prodca is the equivalent of LE's cert.pem?11:36
deflatedi'm coming from osa so its a learning curve, i do really appreciate your help11:37
PrzemekKIf You Talking about LetsEncrypt its different story. Then You use letsencrypt module https://docs.openstack.org/kolla-ansible/latest/admin/tls.html#generating-tls-certificates-with-let-s-encrypt but i dont have practise with it11:42
dougszuDoes anyone know what's preventing this merging? I guess it needs W+1 from someone else? https://review.opendev.org/c/openstack/kolla-ansible/+/91248312:19
SvenKieskeit nees BackportCandidate votes12:24
SvenKieskethat's why it's called "NonZero" dougszu, but it's maybe still not obvious12:24
SvenKieskeguess that should be backported12:26
dougszuah, thanks SvenKieske, i'd missed that. I agree - it should be fine to backport. 12:38
opendevreviewMerged openstack/kolla-ansible master: Support custom Nova Compute Ironic host names  https://review.opendev.org/c/openstack/kolla-ansible/+/91248314:01
opendevreviewMerged openstack/kayobe master: Bump stackhpc.linux collection to v1.2.3  https://review.opendev.org/c/openstack/kayobe/+/92448014:16
opendevreviewSven Kieske proposed openstack/kolla-ansible stable/2024.1: Fix keystone configuration for haproxy.  https://review.opendev.org/c/openstack/kolla-ansible/+/92510114:19
opendevreviewSven Kieske proposed openstack/kolla-ansible stable/2023.2: Fix keystone configuration for haproxy.  https://review.opendev.org/c/openstack/kolla-ansible/+/92510214:19
opendevreviewSven Kieske proposed openstack/kolla-ansible stable/2023.1: Fix keystone configuration for haproxy.  https://review.opendev.org/c/openstack/kolla-ansible/+/92510314:22
opendevreviewSven Kieske proposed openstack/kolla-ansible stable/2023.1: Fix keystone configuration for haproxy.  https://review.opendev.org/c/openstack/kolla-ansible/+/92510314:30
opendevreviewPierre Riteau proposed openstack/kayobe stable/2024.1: Bump stackhpc.linux collection to v1.2.3  https://review.opendev.org/c/openstack/kayobe/+/92510414:41
stromgrenHi, I have an issue where one of my compute nodes is missing the secret for "cinder_rbd_secret_uuid". When I try to fetch it using "virsh secret-get-value <uuid>" inside the nova_libvirt container it fails. It works for the other hosts. I've tried to reconfigure, but that doesn't help. Do anyone have any input on what would be the next troubleshooting step. Thanks!17:35

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!