| opendevreview | Merged openstack/kolla-ansible master: ansible-lint: fix yaml[line-length] in barbican https://review.opendev.org/c/openstack/kolla-ansible/+/970880 | 06:28 |
|---|---|---|
| opendevreview | Merged openstack/kolla-ansible master: Add logrotate configuration for OpenSearch Dashboards https://review.opendev.org/c/openstack/kolla-ansible/+/972698 | 06:36 |
| opendevreview | Michal Nasiadka proposed openstack/kolla stable/2024.2: Update repo GPG key for influxdata. https://review.opendev.org/c/openstack/kolla/+/972999 | 07:56 |
| opendevreview | Michal Nasiadka proposed openstack/kolla-ansible master: Enable TLS backend for designate https://review.opendev.org/c/openstack/kolla-ansible/+/866524 | 09:09 |
| opendevreview | Michal Nasiadka proposed openstack/kolla-ansible master: Enable TLS backend for designate https://review.opendev.org/c/openstack/kolla-ansible/+/866524 | 09:09 |
| opendevreview | Michal Nasiadka proposed openstack/kolla-ansible master: Adapt notifying handlers message https://review.opendev.org/c/openstack/kolla-ansible/+/940428 | 09:15 |
| opendevreview | Michal Nasiadka proposed openstack/kolla-ansible master: Adapt notifying handlers message https://review.opendev.org/c/openstack/kolla-ansible/+/940428 | 09:16 |
| opendevreview | Michal Nasiadka proposed openstack/kolla-ansible master: CI: Add back openstack-python3-jobs-arm64 https://review.opendev.org/c/openstack/kolla-ansible/+/945485 | 09:17 |
| opendevreview | Michal Nasiadka proposed openstack/kolla-ansible master: CI: Add back openstack-python3-jobs-arm64 https://review.opendev.org/c/openstack/kolla-ansible/+/945485 | 09:17 |
| opendevreview | Merged openstack/kolla-ansible master: Standardize naming for MariaDB recovery and backup files https://review.opendev.org/c/openstack/kolla-ansible/+/952818 | 09:19 |
| opendevreview | Michal Nasiadka proposed openstack/kolla-ansible master: Ensure neutron_bridge_name and neutron_external_interface have the same length https://review.opendev.org/c/openstack/kolla-ansible/+/943799 | 09:19 |
| opendevreview | Michal Nasiadka proposed openstack/kolla-ansible master: Ensure neutron_bridge_name and neutron_external_interface have the same length https://review.opendev.org/c/openstack/kolla-ansible/+/943799 | 09:20 |
| opendevreview | Michal Nasiadka proposed openstack/kolla-ansible master: docs: Add information about possible password leaking https://review.opendev.org/c/openstack/kolla-ansible/+/959222 | 09:22 |
| opendevreview | Michal Nasiadka proposed openstack/kolla-ansible master: docs: Add information about possible password leaking https://review.opendev.org/c/openstack/kolla-ansible/+/959222 | 09:24 |
| mnasiadka | frickler: I’d like to finally push the password leaking note forward - https://review.opendev.org/c/openstack/kolla-ansible/+/959222 - can you have a look? | 09:35 |
| frickler | ack. btw that's another good location to add a "build your own containers" note I guess | 09:48 |
| mnasiadka | I guess so | 09:49 |
| mnasiadka | frickler: https://review.opendev.org/c/openstack/kolla-ansible/+/962419 - should we disable requirements-check or what’s the best path forward? | 09:49 |
| mnasiadka | ah | 09:50 |
| mnasiadka | We probably should merge it in 2025.2 | 09:50 |
| mnasiadka | Bcrypt was removed from reqs in master | 09:50 |
| mnasiadka | So we need to get rid of it | 09:50 |
| mnasiadka | Ah no, I confused it with passlib | 09:51 |
| mnasiadka | bcrypt is 4.3.0 in reqs | 09:52 |
| frickler | hmm, difficult question. what became of the "curate a deployment-constraints.txt" SIG? | 09:55 |
| frickler | if we want to disable the reqs check, I think we would need to discuss it at the TC level first | 09:56 |
| opendevreview | Leonie Chamberlin-Medd proposed openstack/kayobe master: Add support for fail2ban in Kayobe https://review.opendev.org/c/openstack/kayobe/+/973090 | 09:56 |
| mnasiadka | frickler: we were supposed to draft a spec, which I failed to have time to do :) | 10:02 |
| mnasiadka | (Re the deployment constraints) | 10:03 |
| opendevreview | Merged openstack/kolla-ansible master: docs: Add information about possible password leaking https://review.opendev.org/c/openstack/kolla-ansible/+/959222 | 10:06 |
| opendevreview | Pierre Riteau proposed openstack/kayobe-config-dev master: CI: Configure ansible0 as Ansible control host https://review.opendev.org/c/openstack/kayobe-config-dev/+/972842 | 10:45 |
| opendevreview | Pierre Riteau proposed openstack/kayobe master: CI: Add kayobe-ansible-control-host-configure jobs https://review.opendev.org/c/openstack/kayobe/+/972843 | 10:45 |
| opendevreview | Pierre Riteau proposed openstack/kayobe master: CI: Add kayobe-ansible-control-host-configure jobs https://review.opendev.org/c/openstack/kayobe/+/972843 | 11:22 |
| opendevreview | Merged openstack/kolla stable/2024.2: Update repo GPG key for influxdata. https://review.opendev.org/c/openstack/kolla/+/972999 | 11:24 |
| opendevreview | Leonie Chamberlin-Medd proposed openstack/kayobe master: Add support for fail2ban in Kayobe https://review.opendev.org/c/openstack/kayobe/+/973090 | 12:08 |
| opendevreview | Pierre Riteau proposed openstack/kolla-ansible master: keystone: support OIDCOutgoingProxy parameter https://review.opendev.org/c/openstack/kolla-ansible/+/973370 | 12:36 |
| opendevreview | Leonie Chamberlin-Medd proposed openstack/kayobe master: Add support for fail2ban in Kayobe https://review.opendev.org/c/openstack/kayobe/+/973090 | 13:18 |
| opendevreview | Seunghun Lee proposed openstack/kolla-ansible master: Improve Let's encrypt settings logic https://review.opendev.org/c/openstack/kolla-ansible/+/956771 | 13:41 |
| bbezak | mnasiadka bbezak frickler kevko mmalchuk gkoper jovial mattcrees dougszu darmach pabloclsn ravlew amir58118 r-krcek blanson[m] - meeting in 8 | 13:52 |
| opendevreview | Seunghun Lee proposed openstack/kolla-ansible master: Make RabbitMQ stream retention policy configurable https://review.opendev.org/c/openstack/kolla-ansible/+/953297 | 13:56 |
| bbezak | #startmeeting kolla | 14:00 |
| opendevmeet | Meeting started Wed Jan 14 14:00:39 2026 UTC and is due to finish in 60 minutes. The chair is bbezak. Information about MeetBot at http://wiki.debian.org/MeetBot. | 14:00 |
| opendevmeet | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 14:00 |
| opendevmeet | The meeting name has been set to 'kolla' | 14:00 |
| bbezak | #topic rollcall | 14:00 |
| enick_604 | o7 | 14:00 |
| jph | o7 | 14:01 |
| bbezak | #topic agenda | 14:02 |
| bbezak | * Roll-call | 14:02 |
| bbezak | * Agenda | 14:02 |
| bbezak | * Announcements | 14:02 |
| bbezak | * Review action items from the last meeting | 14:02 |
| bbezak | * CI status | 14:02 |
| bbezak | * Release tasks | 14:02 |
| bbezak | * Regular stable releases (first meeting in a month) | 14:02 |
| bbezak | * Current cycle planning | 14:02 |
| bbezak | * Additional agenda (from whiteboard) | 14:02 |
| bbezak | * Open discussion | 14:02 |
| bbezak | #topic CI status | 14:02 |
| mmalchuk_ | o/ | 14:02 |
| seunghunlee | o/ | 14:03 |
| mnasiadka | o/ (with 3g internet!) | 14:03 |
| fprzewozny | o/ | 14:03 |
| bbezak | Looking at CI front - after recent secrets rotation | 14:03 |
| bbezak | Looking ok | 14:03 |
| bbezak | #topic - Regular stable releases | 14:03 |
| bbezak | I’ll look into that, as I think we merged in all branches influx fixes | 14:04 |
| bbezak | #topic Additional agenda (from whiteboard) | 14:04 |
| bbezak | I deliberately leaving those entries on whiteboard - until they are reviewed | 14:05 |
| *** mmalchuk_ is now known as mmalchuk | 14:05 | |
| bbezak | Unfortunately I’m a bit busy on customer’s work | 14:05 |
| bbezak | But trying my best to review stuff | 14:05 |
| bbezak | I wanted to say that I remember about all of you, and try to progress as much as I can :) | 14:06 |
| bbezak | Other reviewers as well | 14:06 |
| bbezak | There is new entry by frickler | 14:06 |
| bbezak | #link - https://etherpad.opendev.org/p/KollaWhiteBoard#L95 | 14:07 |
| bbezak | I agree, that is basically a reality for a long time | 14:07 |
| bbezak | Images on quay.io are not meant to be consumed directly. i.e. only for testing purposes | 14:08 |
| bbezak | mnasiadka | 14:09 |
| bbezak | Also did make notes on whiteboard | 14:09 |
| bbezak | Please take a look on your entries | 14:09 |
| bbezak | As I can see there are some patches in merge conflicts there | 14:09 |
| blanson[m] | Been using kolla for a while now, I agree at first sight that's not entirely obvious imo that the quay images aren't meant for production (aside from a single line I believe in the documentation stating it? ) | 14:09 |
| bbezak | Yes, that is the goal of frickler’s readme change I believe | 14:11 |
| bbezak | To reflect reality better | 14:11 |
| mnasiadka | I need to check if we could have some description in quay.io | 14:11 |
| mnasiadka | And we should drop docker hub content and account | 14:11 |
| mnasiadka | Anybody disagrees? | 14:11 |
| blanson[m] | we had dockerhub uploads ? | 14:12 |
| mnasiadka | Long time ago | 14:12 |
| mnasiadka | #link https://hub.docker.com/u/kolla | 14:12 |
| mnasiadka | Last working 2025.1 publish was 3 months ago | 14:13 |
| bbezak | +1 | 14:13 |
| blanson[m] | I think dropping it is fine I don't think it was ever mentioned in the documentation ? everything points to quay now, so +1 | 14:13 |
| mnasiadka | It was mentioned long time ago, we switched to quay.io before I became PTL :) | 14:14 |
| mnasiadka | Which was around… Xena? | 14:14 |
| bbezak | #topic Open discussion | 14:14 |
| yuval | I didnt fully understand the issue with quay. its not for production, only for testing. is there an image that is good for production or each user need to creates its own? | 14:15 |
| mnasiadka | Each user should build his own, we can’t guarantee that the images in quay.io are fit for production (vulnerabilities, etc) | 14:16 |
| jph | I would like mention that I am exploring adding OpenBao as a service within kolla/kolla-ansible. I think it would be nice addition as it would provide a common solution for PKI and Barbican integration. | 14:17 |
| blanson[m] | I think there was a review to add vault support for barbican a while ago idk if it's been merged | 14:18 |
| blanson[m] | #link https://review.opendev.org/c/openstack/kolla-ansible/+/935704 | 14:18 |
| blanson[m] | I think that's the one | 14:18 |
| mnasiadka | jph: openbao is MPL 2.0, wondering what are the implications - but that should be fine | 14:19 |
| bbezak | I think for deployment project mixing licenses is ok | 14:19 |
| bbezak | Even non compatible ones | 14:19 |
| mnasiadka | Well, Ansible modules are complicated :) | 14:20 |
| mnasiadka | But yes, I agree | 14:21 |
| jph | Good to know. I am just having an issue with sources definition they don't match ${debian_arch}. | 14:21 |
| fprzewozny | If anyone here is open to check / test, you are welcome: https://review.opendev.org/c/openstack/kolla-ansible/+/970594 :) I'm running this virtual routing config in multiple clusters, and it was kinda game changer | 14:21 |
| mnasiadka | Added RP+1 and will try to review | 14:25 |
| fprzewozny | thanks! | 14:25 |
| mnasiadka | bbezak, frickler: I’ve cleaned up RP+1 for patches that had merge conflict, so the list should be usable now to do reviews - so if you have time - just focus on these for this/next week | 14:25 |
| mnasiadka | Let’s treat it as a weekly list to go through, we can’t really review everything | 14:26 |
| mnasiadka | blanson[m]: it would be beneficial if you could also review the patches from RP+1 list and whiteboard - that would help us a lot | 14:26 |
| blanson[m] | I will | 14:26 |
| blanson[m] | it's in the kolla/kolla-ansible dashboard ? | 14:26 |
| mnasiadka | yes | 14:27 |
| mnasiadka | The links to dashboards are on the whiteboard | 14:27 |
| mnasiadka | (More boards!) | 14:27 |
| mnasiadka | That’s all from me and bbezak I guess | 14:27 |
| blanson[m] | yes I have themn bookmarked, will try to go through a bunch | 14:27 |
| bbezak | cool | 14:28 |
| bbezak | Let’s try to improve review velocity :) | 14:28 |
| bbezak | Thank you for joining today! | 14:30 |
| bbezak | #endmeeting | 14:30 |
| opendevmeet | Meeting ended Wed Jan 14 14:30:04 2026 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 14:30 |
| opendevmeet | Minutes: https://meetings.opendev.org/meetings/kolla/2026/kolla.2026-01-14-14.00.html | 14:30 |
| opendevmeet | Minutes (text): https://meetings.opendev.org/meetings/kolla/2026/kolla.2026-01-14-14.00.txt | 14:30 |
| opendevmeet | Log: https://meetings.opendev.org/meetings/kolla/2026/kolla.2026-01-14-14.00.log.html | 14:30 |
| blanson[m] | thank you ! | 14:30 |
| mnasiadka | thanks bbezak | 14:30 |
| fprzewozny | thanks! | 14:30 |
| mnasiadka | Of course if others have time for doing meaningful reviews (especially on patches that have RP+1) - that’s all appreciated - we need to make the project running at some steam again :) | 14:32 |
| fprzewozny | regarding streams, I really hope we could push a bit that one: https://review.opendev.org/c/openstack/kolla-ansible/+/953297 | 14:33 |
| *** mmalchuk_ is now known as mmalchuk | 14:33 | |
| mmalchuk | thanks all | 14:34 |
| axeljacquet[m] | hello i will try to help for reviews of patches from RP+1 :) | 14:35 |
| mnasiadka | fprzewozny: it’s been a topic for a while, and I don’t seem to understand if the default retention policy is bad or not :) | 14:36 |
| opendevreview | Seunghun Lee proposed openstack/kolla-ansible master: Improve Let's encrypt settings logic https://review.opendev.org/c/openstack/kolla-ansible/+/956771 | 14:36 |
| fprzewozny | default one fot streams is not existing? messages are kept in queues forever | 14:37 |
| fprzewozny | without stream queues (so old behaviour) number of messages may show potential issues | 14:38 |
| fprzewozny | and being honest it looks just bad to have it there | 14:38 |
| seunghunlee | There is one for stream queues but they're very generous, so until some number of stream ready messages are gone, the number of ready messages will grow a lot | 14:39 |
| seunghunlee | Hence the patch link: https://review.opendev.org/c/openstack/kolla-ansible/+/953297 | 14:40 |
| fprzewozny | asked a collegue from other company, and there were totally not aware of 250k+ ready messages in cinder-scheduler_fanout | 14:40 |
| fprzewozny | and I don't want to ask what will happen in case of single RabbitMQ restart ... | 14:41 |
| seunghunlee | I couldn't find the effect of having large number of ready messages for stream queues but it would be better to remove them earlier than currently retention period to prevent this large number of messages hides actual problem (if there's one) | 14:41 |
| fprzewozny | I can only suspect that this can be potential memory leak issue? And what happens if one of the MQ nodes needs resyncing? | 14:43 |
| *** mmalchuk_ is now known as mmalchuk | 14:46 | |
| seunghunlee | I also expected some kind of performance issue but couldn't verify that. oslo.messaging guys also says this large number of ready messages is expected and encouraging the use of custom retention policy. | 14:51 |
| opendevreview | Leonie Chamberlin-Medd proposed openstack/kayobe master: Add support for fail2ban in Kayobe https://review.opendev.org/c/openstack/kayobe/+/973090 | 15:13 |
| opendevreview | Seunghun Lee proposed openstack/kolla-ansible master: Make RabbitMQ stream retention policy configurable https://review.opendev.org/c/openstack/kolla-ansible/+/953297 | 16:09 |
| opendevreview | Piotr Milewski proposed openstack/kolla-ansible master: Pin bcrypt to < 4.0.0 to fix Prometheus configuration failure https://review.opendev.org/c/openstack/kolla-ansible/+/973409 | 16:17 |
| *** jhorstmann is now known as Guest35863 | 16:23 | |
| opendevreview | Leonie Chamberlin-Medd proposed openstack/kayobe master: Add support for fail2ban in Kayobe https://review.opendev.org/c/openstack/kayobe/+/973090 | 17:08 |
| opendevreview | Matt Anson proposed openstack/kolla master: Add purity_fb to python deps for manila-base https://review.opendev.org/c/openstack/kolla/+/973417 | 17:21 |
| opendevreview | Pierre Riteau proposed openstack/kayobe master: Sync host configuration with Ansible defaults https://review.opendev.org/c/openstack/kayobe/+/973422 | 18:17 |
| opendevreview | Pierre Riteau proposed openstack/kolla-ansible master: keystone: support OIDCOutgoingProxy parameter https://review.opendev.org/c/openstack/kolla-ansible/+/973370 | 18:21 |
| mnasiadka | frickler, bbezak: I think the bcrypt problem comes from the 72 characters limit, which was a warning (and automatically truncated in the past) and now is an error - we need to limit what we pass to bcrypt to be only 72 chars | 18:31 |
| Vii | not 7x characters, only 72-byte password limit | 18:49 |
| Vii | This triggers an incorrect error message regarding password length (72 bytes limit), even if the password is much shorter (in this case, 40 characters). | 18:50 |
| Vii | from what I understand, when Kolla-Ansible uses password_hash('bcrypt'), Ansible relies on passlib as the underlying engine. The misleading '72 bytes' error happens because passlib fails to detect the backend version in bcrypt 4.0.0+ and falls back to a generic error message based on the native bcrypt/Blowfish limit of 72 characters. Downgrading to bcrypt<4.0.0 fixes the handshake between these libs | 18:56 |
| Vii | https://passlib.readthedocs.io/en/stable/lib/passlib.hash.bcrypt_sha256.html | 18:57 |
| Vii | https://foss.heptapod.net/python-libs/passlib/-/issues?show=eyJpaWQiOiIxOTYiLCJmdWxsX3BhdGgiOiJweXRob24tbGlicy9wYXNzbGliIiwiaWQiOjIyMjYxMX0%3D | 19:00 |
| mnasiadka | Well, passlib is dead, so we should rather be moving away from it. | 19:50 |
| mnasiadka | Ansible devel has added support for libcrypt/libxcrypt, but that doesn’t help anyone using a stable release. | 19:52 |
| Vii | or make bcrypt>=3.0.0,<4.0.0 for older versions, and in new ones switch to libcrypt/libxcrypt | 20:04 |
| Vii | Or, as a note for older versions, generate a hash and put it in the passwords file. And in the code, add an exception stating that if there's a hash, copy it. | 20:06 |
| niux | I would be ok to work on this. So what would be the best approach ? | 21:27 |
| opendevreview | Michael Still proposed openstack/kolla master: Re-enable SPICE support on Debian. https://review.opendev.org/c/openstack/kolla/+/972441 | 22:29 |
| opendevreview | Michael Still proposed openstack/kolla-ansible master: Simplify cron jobs for log rotate. https://review.opendev.org/c/openstack/kolla-ansible/+/969138 | 22:33 |
Generated by irclog2html.py 4.0.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!