Monday, 2026-02-23

tafkamaxPodman is daemon less so you can't bork something when you restart docker.service accidentally06:37
tafkamaxBut I think docker in kolla-ansible is more used, so more robust.06:38
tafkamaxHmm maybing using th example from kolla-toolbox.py with module_extra_vars might help07:21
opendevreviewTaavi Ansper proposed openstack/kolla-ansible master: Fix keystone with IDP configured.  https://review.opendev.org/c/openstack/kolla-ansible/+/97590107:25
tafkamaxNobody has used the example from the kolla-toolbox.py docs though :D module_extra_vars.07:26
tafkamaxLet's see if it will help.07:26
opendevreviewLeonie Chamberlin-Medd proposed openstack/kayobe master: Add support for fail2ban in Kayobe  https://review.opendev.org/c/openstack/kayobe/+/97309008:09
opendevreviewPierre Riteau proposed openstack/kayobe master: CI: Add kayobe-ansible-control-host-configure jobs  https://review.opendev.org/c/openstack/kayobe/+/97284308:14
blanson[m]Moha_: we went with podman to avoid the spof that is an accidental docker restart. Podman is less used, but I've merged quite a few patches recently to get it to work nicely, and avoid regressions (mainly idempotence was broken for a bit). I'd say it's now just as good as docker (but less usage so, you're the one finding bugs lol)08:43
tafkamaxWe had unattended upgrades on docker pkgs08:45
tafkamaxand had a hit :D08:45
blanson[m]there is still one issue if you're having the combo of debian 12 + podman where nova-compute cannot be idempotent because the version of podman shipped with debian 12 has an api bug. You can install a more recent version, or choose any other OS tho 08:45
tafkamaxafter that we used blacklist to blacklist docker pkgs for updates08:45
tafkamaxwe use security pkgs only though for unattended08:45
tafkamaxbut hasnt happened after08:46
tafkamaxin HCI we run cephadm with podman and docker for kolla to separate the two08:46
blanson[m]unattended upgrades is one thing, the other is if you ever need to update docker for a CVE for example 08:46
blanson[m]that will restart your cluster08:46
tafkamaxyes08:46
blanson[m]when we chose podman I kinda regretted it at first cause I spent 2 months fixing it, but now it works well :D 08:48
tafkamaxWhy is my CI failing 🥲08:49
blanson[m]oh no.. 975901  ? 08:49
blanson[m]I can take a look maybe today 08:49
tafkamaxSeems that using the variable that nobody has used module_extra_vars didn't help.08:49
tafkamaxI spent way too many hours debugging it yesterday to understand it comes from the toolbox, maybe fixes for the secret exposure will fix it though, but I haven't tested them with my patch.08:50
opendevreviewTaavi Ansper proposed openstack/kolla-ansible master: Fix keystone with IDP configured.  https://review.opendev.org/c/openstack/kolla-ansible/+/97590109:16
opendevreviewMerged openstack/kayobe-config master: Synchronise configuration with master  https://review.opendev.org/c/openstack/kayobe-config/+/97743609:38
opendevreviewLeonie Chamberlin-Medd proposed openstack/kayobe master: Deploy more containers  https://review.opendev.org/c/openstack/kayobe/+/92240209:50
*** jhorstmann is now known as Guest348910:09
opendevreviewPierre Riteau proposed openstack/kolla master: Update Prometheus to version 3.5.1  https://review.opendev.org/c/openstack/kolla/+/97760910:41
opendevreviewMerged openstack/kayobe-config-dev master: Synchronise configuration with master  https://review.opendev.org/c/openstack/kayobe-config-dev/+/97743711:15
opendevreviewVerification of a change to openstack/kolla-ansible master failed: Allow SNI frontend when using a single haproxy VIP  https://review.opendev.org/c/openstack/kolla-ansible/+/97542111:15
opendevreviewLeonie Chamberlin-Medd proposed openstack/kayobe master: Add support for fail2ban in Kayobe  https://review.opendev.org/c/openstack/kayobe/+/97309011:17
bbezakSomething changed in tempest, all CI is broken11:42
bbezak:)11:42
bbezaktempest: 'run --config-file etc/tempest.conf --regex .*smoke.*' is not a tempest command. See 'tempest --help'.11:42
bbezakDid you mean one of these?11:42
bbezak  help11:42
bbezak  init11:42
tafkamaxwoah11:48
bbezakchecking11:48
fricklerbbezak: I'm pretty sure nothing changed in tempest itself recently. at first sight this looks like maybe a quoting issue?11:52
bbezakI think this is because tempest 46.0 tag don’t include this https://opendev.org/openstack/tempest/commit/f9a7a6d2c08184c2cf03619f86ab49410d60ddc411:58
bbezakAnd recently bumped oslo.utils https://review.opendev.org/c/openstack/requirements/+/977444 doesn’t work with secretutils.md5. - it seems11:58
bbezakhttps://review.opendev.org/c/openstack/tempest/+/94771412:04
bbezakfrickler12:04
bbezakhttps://review.opendev.org/c/openstack/oslo.utils/+/97504812:16
bbezakhttps://review.opendev.org/c/openstack/releases/+/97695812:16
bbezak(Posted info on #openstack-qa)12:17
bbezakIt is not directly seen, but easily reproducable https://paste.openstack.org/show/831117/12:20
opendevreviewDoug Szumski proposed openstack/kolla-ansible master: Support multiple Nova Compute Ironic instances  https://review.opendev.org/c/openstack/kolla-ansible/+/97388112:35
bbezakhttps://review.opendev.org/c/openstack/releases/+/97762412:42
fricklerbbezak: oh, so you (we?) are using tagged tempest with master u-c? that sounds like a bad combination12:58
tafkamaxfor master it should be non-tagged, just latest?13:00
bbezakWell, upper-constraints combinations for each branch should work :)13:03
bbezakBut you may be right, as tempest is not in upper-constraints13:06
bbezakIn any case latest tempest tag is broken with latest oslo-utils tag13:06
bbezakLet’s fix it13:06
mnasiadkaJust add tempest in required projects and install from the checkout - I didn’t think it through properly ;)13:12
mnasiadkaThis way we’ll get depends-on support13:13
bbezakok13:14
opendevreviewTaavi Ansper proposed openstack/kolla-ansible master: Fix keystone with IDP configured.  https://review.opendev.org/c/openstack/kolla-ansible/+/97590113:21
opendevreviewBartosz Bezak proposed openstack/kolla-ansible master: CI: use Tempest checkout in master jobs  https://review.opendev.org/c/openstack/kolla-ansible/+/97766514:21
opendevreviewBartosz Bezak proposed openstack/kolla-ansible master: CI: use Tempest checkout in master jobs  https://review.opendev.org/c/openstack/kolla-ansible/+/97766514:22
bbezakYet another breakage :) - https://zuul.opendev.org/t/openstack/build/75820ae4876b4135bd1490d87d1af90314:29
bbezakThe conflict is caused by:14:29
bbezak    kolla-ansible 21.1.0.dev446 depends on bcrypt<5 and >=4.3.014:29
bbezak    The user requested (constraint) bcrypt===5.0.014:29
tafkamaxIt's break city in here!14:33
bbezakhttps://review.opendev.org/c/openstack/requirements/+/96587314:34
bbezakBrypt bumped here14:34
bbezakPotential fix in WIP - https://review.opendev.org/c/openstack/kolla-ansible/+/96986714:37
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: WIP: Switch from passlib to internal bcrypt filter  https://review.opendev.org/c/openstack/kolla-ansible/+/96986714:39
opendevreviewWill Szumski proposed openstack/kayobe master: Bump stackhpc.openstack to 0.10.0  https://review.opendev.org/c/openstack/kayobe/+/97698518:58
opendevreviewWill Szumski proposed openstack/kayobe master: Template disabled repositories  https://review.opendev.org/c/openstack/kayobe/+/97661518:58
opendevreviewWill Szumski proposed openstack/kayobe master: Adds dnf_repo_state_overrides  https://review.opendev.org/c/openstack/kayobe/+/97702818:58
opendevreviewWill Szumski proposed openstack/kayobe master: WIP: Adds ansible-inventory wrapper  https://review.opendev.org/c/openstack/kayobe/+/97771419:39
opendevreviewWill Szumski proposed openstack/kayobe master: WIP: Adds ansible-inventory wrapper  https://review.opendev.org/c/openstack/kayobe/+/97771420:01
opendevreviewPierre Riteau proposed openstack/kolla-ansible master: WIP: Switch from passlib to internal bcrypt filter  https://review.opendev.org/c/openstack/kolla-ansible/+/96986720:18
opendevreviewPierre Riteau proposed openstack/kolla-ansible master: WIP: Switch from passlib to internal bcrypt filter  https://review.opendev.org/c/openstack/kolla-ansible/+/96986720:24
opendevreviewVerification of a change to openstack/kolla-ansible master failed: Allow SNI frontend when using a single haproxy VIP  https://review.opendev.org/c/openstack/kolla-ansible/+/97542120:25
opendevreviewPierre Riteau proposed openstack/kolla-ansible master: WIP: Switch from passlib to internal bcrypt filter  https://review.opendev.org/c/openstack/kolla-ansible/+/96986720:29
opendevreviewPierre Riteau proposed openstack/kolla-ansible master: WIP: Switch from passlib to internal bcrypt filter  https://review.opendev.org/c/openstack/kolla-ansible/+/96986720:35
opendevreviewPierre Riteau proposed openstack/kolla-ansible master: WIP: Switch from passlib to internal bcrypt filter  https://review.opendev.org/c/openstack/kolla-ansible/+/96986721:15
opendevreviewMichal Arbet proposed openstack/kolla-ansible master: Add service-api-paste role for api-paste.ini management  https://review.opendev.org/c/openstack/kolla-ansible/+/95270022:29

Generated by irclog2html.py 4.0.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!