Wednesday, 2026-03-25

opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: CI: Test for leaked passwords in syslog  https://review.opendev.org/c/openstack/kolla-ansible/+/98106805:03
mnasiadkaYay, lint fixing done05:08
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: CI: Test for leaked passwords in syslog  https://review.opendev.org/c/openstack/kolla-ansible/+/98106806:01
opendevreviewMerged openstack/kolla-ansible stable/2024.2: prometheus: Sort blackbox exporters  https://review.opendev.org/c/openstack/kolla-ansible/+/97838306:25
mnasiadkablanson[m]: regarding https://review.opendev.org/c/openstack/kolla-ansible/+/971801 - what the heck do we do with podman? :)06:36
opendevreviewMerged openstack/kolla master: Update ProxySQL 3.0.x RPM repo to use almalinux 10  https://review.opendev.org/c/openstack/kolla/+/97891106:38
opendevreviewMichal Nasiadka proposed openstack/ansible-collection-kolla master: docker/podman_sdk: use become for checking if virtualenv exists  https://review.opendev.org/c/openstack/ansible-collection-kolla/+/97430006:50
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: Standardize API health check endpoints  https://review.opendev.org/c/openstack/kolla-ansible/+/96278506:52
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: Standardize API health check endpoints  https://review.opendev.org/c/openstack/kolla-ansible/+/96278506:52
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: blazar: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98145506:55
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: manila: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98145806:56
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: mistral: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146006:56
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: trove: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146706:56
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: zun: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146806:56
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: cyborg: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98147006:56
opendevreviewSeunghun Lee proposed openstack/kolla master: WIP: Update Ceph Squid RPM repo to centos-10-stream  https://review.opendev.org/c/openstack/kolla/+/98011406:57
opendevreviewMichal Nasiadka proposed openstack/kolla master: Update Ceph Squid RPM repo to centos-10-stream  https://review.opendev.org/c/openstack/kolla/+/98011406:57
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: CI: Test for leaked passwords in syslog  https://review.opendev.org/c/openstack/kolla-ansible/+/98106806:59
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: CI: Test for leaked passwords in syslog  https://review.opendev.org/c/openstack/kolla-ansible/+/98106807:02
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: kolla_container: Add support for user and security_opt parameters  https://review.opendev.org/c/openstack/kolla-ansible/+/97506507:13
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: kolla_container: Return annotation of comparison failures  https://review.opendev.org/c/openstack/kolla-ansible/+/97816207:13
opendevreviewMerged openstack/kolla master: horizon: add django-redis dependency  https://review.opendev.org/c/openstack/kolla/+/98077907:23
opendevreviewMerged openstack/kolla stable/2025.2: Add Open vSwitch/OVN versions to support matrix  https://review.opendev.org/c/openstack/kolla/+/97874407:23
blanson[m]mnasiadka: Those ulimits are not used in podman, they're retained for documentation, but I can't really find anything on the "why" we forbid users from changing those values07:43
blanson[m]podman being fairly recent, I would suspect that sometime ago, it broke stuff ? 07:43
blanson[m]but tbh I have no idea why these would get dropped, maybe we stop dropping them ? 07:44
blanson[m]I think I'll send a patch to allow them back 07:47
opendevreviewPiotr Milewski proposed openstack/kolla-ansible master: grafana: ensure custom dashboards are properly synchronized  https://review.opendev.org/c/openstack/kolla-ansible/+/96356707:50
blanson[m]can I get those chains backported pretty please mnasiadka ? :) https://review.opendev.org/c/openstack/kolla-ansible/+/972836/3 and https://review.opendev.org/c/openstack/kolla-ansible/+/972839/3 our older clusters need some love 07:51
mnasiadkablanson[m]: love on the way ;)07:55
mnasiadkablanson[m]: https://review.opendev.org/c/openstack/kolla-ansible/+/978162 - you can upgrade to +2 ;-)07:56
blanson[m]oh yes I have privileges now 07:57
blanson[m]done07:57
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: mistral: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146007:57
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: trove: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146707:57
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: zun: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146807:57
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: cyborg: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98147007:57
blanson[m]priority queue really dropped some pathces that look better now :D 07:58
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: blazar: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98145507:58
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: blazar: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98145507:58
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: manila: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98145807:58
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: mistral: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146007:58
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: trove: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146707:58
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: zun: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146807:58
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: cyborg: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98147007:58
mnasiadkablanson[m]: I started remove some old unattended patches - if you have any you feel are important - give them RP+107:59
mnasiadkaI’d like to also finish the uwsgi crusade07:59
mnasiadkaSo we can drop apache+mod_wsgi usage07:59
opendevreviewPiotr Milewski proposed openstack/kolla master: Add OCI standard labels to container images  https://review.opendev.org/c/openstack/kolla/+/97168108:03
Viihttps://review.opendev.org/c/openstack/kolla-ansible/+/974515 - Fix log file permissions for MariaDB and Pacemaker08:05
Viilook, I know it's not the best solution but I don't think there's a better way to have these logs08:06
mnasiadkaVii: what about an extend_start.sh approach in hacluster-pacemaker?08:08
mnasiadkaVii: resending - the standard approach is precreating an empty log file in extend_start.sh and ensuring permissions are correct in kolla-ansible config.json (kolla_set_configs manages this) - maybe we should think of adding precreation option to kolla_set_configs so we can manage this all in one place08:13
ViiI don't remember exactly now, but I think it's the same problem as with mariadb, i.e., the 4 for "other" is always missing when "creating a file" or when it's rotated by cron.08:14
Viiignore, I'll check it again, old topic08:15
Viihttps://review.opendev.org/c/openstack/kolla-ansible/+/935704 <- barbican vault ;)  If you can, look at it better and maybe it will go away :)08:16
Viipass*08:16
Viihttps://review.opendev.org/c/openstack/kolla-ansible/+/976653 <- prometheus: add valkey exporter support (and this is probably what's missing since we switched to valkey)08:19
opendevreviewTaavi Ansper proposed openstack/kolla-ansible master: Fix keystone with IDP configured.  https://review.opendev.org/c/openstack/kolla-ansible/+/97590108:20
tafkamaxChanged keystone_wsgi_provider to apache for testing in CI08:20
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: CI: Test for leaked passwords in syslog  https://review.opendev.org/c/openstack/kolla-ansible/+/98106808:20
opendevreviewMerged openstack/kolla-ansible master: Fix ulimit defaults for Debian family container engines  https://review.opendev.org/c/openstack/kolla-ansible/+/97180108:55
opendevreviewMerged openstack/kolla-ansible master: ovn-db: add support for ovn-northd extra command-line arguments  https://review.opendev.org/c/openstack/kolla-ansible/+/97746908:55
opendevreviewPiotr Milewski proposed openstack/kolla-ansible master: Added vault support to barbican as back-end secret  https://review.opendev.org/c/openstack/kolla-ansible/+/93570408:57
opendevreviewPiotr Milewski proposed openstack/kolla-ansible master: Added vault support to barbican as back-end secret  https://review.opendev.org/c/openstack/kolla-ansible/+/93570408:58
mikalIs there a historical reason that nova_cell's qemu.conf template set's stdio_handler to "file"? Would that decision be documented anywhere?09:04
mikalThe net effect of doing that is that console log files for nova are not rotated ever, which means you can end up with the instance directory becoming very large.09:07
mnasiadkamikal: I’m sure you can find something in https://review.opendev.org/q/project:openstack/kolla-ansible+path:%22ansible/roles/nova/templates/qemu.conf.j2%2209:18
mnasiadkaBut it seems it’s older even than breaking out kolla-ansible from kolla09:18
mikalYeah, git blame says its from the 2019 split out into cells...09:19
mnasiadkamikal:https://review.opendev.org/c/openstack/kolla/+/30874909:19
mnasiadkaThat one09:19
mnasiadkaOh boy09:19
mnasiadkaIt seems it’s older than this, but before we had a sed one-liner in the dockerfile09:19
mnasiadkahttps://review.opendev.org/c/openstack/kolla/+/27991009:20
blanson[m]I was still in school at that time that's pretty funny 09:20
mnasiadkaThat reminds me we should have stopped doing monolithic libvirtd long time ago :)09:20
mikalYeah, "file" is simply not a good choice. That's why I am asking for a reason. It opens you up to relatively trivial denial of service attacks if you don't rotate that file -- you just need to smash out a lot of data on the serial console and hope the cloud has relatively small filesystems for that bit which in this case seems to be inside a docker09:20
mikalvolume.09:20
mikalblanson[m]: well, what were you doing when ocata was released? That's when virtlogd was added to nova.09:21
mikalThe irony is the Debian containers at least have virtlogd installed because they're pulled in my libvirt. Not sure about the Rocky containers though.09:21
mikalI guess I'd whip something up and see what happens.09:21
mikals/I'd/I'll/09:22
blanson[m]"Documentation for Ocata (February 2017)" so I was barely into uni lol09:22
mikalMate, we're going to have to have a very depressing (for me) conversation about where you were when I had my first OpenStack patch land one day...09:22
blanson[m]hahahahahaha some of you contributed before I even had a computer at home I'm pretty sure 09:23
blanson[m]playing lego in my bedroom while you guys were doing python 2 contribs 09:24
mikalI think this was my first commit:09:24
mikalcommit 605c22b1804f0a34d400eb57e1954c3fc3a20c8809:24
mikalAuthor: Michael Still <mikal@stillhq.com>09:24
mikalDate:   Wed Feb 1 11:41:22 2012 +110009:24
mikalWhen do you guys intend to cut a stable/2026.1 branch? Soon I assume?09:27
blanson[m]I think this was talked about last week. from what I remember, about a month after project releases is the deadline for trailing projects ? you can probbly find it from last wed in the channel, under the pile of ansible-lint patches09:28
opendevreviewPiotr Milewski proposed openstack/kolla-ansible master: Added vault support to barbican as back-end secret  https://review.opendev.org/c/openstack/kolla-ansible/+/93570409:29
blanson[m]mikal: so I'd say late april ? but I've been on the job for like a week so idk much about this stuff :D 09:30
mnasiadkamikal: there has not been a coordinated release of non-cycle-trailing deliverables - so yes, soon - but soon in Kolla world means around June 1st, maybe earlier :)09:31
chembervinthi! if somebody has a few mins - take a look please on our micro-patch :) https://review.opendev.org/c/openstack/kolla-ansible/+/97886909:31
mikalmnasiadka / blanson[m]: cool, no rush, just trying to work out when you're going to stop landing things etc.09:32
opendevreviewMichael Still proposed openstack/kolla master: Implement container image build for kerbside.  https://review.opendev.org/c/openstack/kolla/+/97549509:33
opendevreviewMichael Still proposed openstack/kolla-ansible master: Add additional SPICE configuration options.  https://review.opendev.org/c/openstack/kolla-ansible/+/96780009:33
opendevreviewMichael Still proposed openstack/kolla-ansible master: Allow requiring secure channels with SPICE.  https://review.opendev.org/c/openstack/kolla-ansible/+/96780209:33
opendevreviewMichael Still proposed openstack/kolla-ansible master: Simplify cron jobs for log rotate.  https://review.opendev.org/c/openstack/kolla-ansible/+/96913809:33
opendevreviewMichael Still proposed openstack/kolla-ansible master: Deploy Kerbside with Kolla-Ansible.  https://review.opendev.org/c/openstack/kolla-ansible/+/97688909:33
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: manila: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98145809:34
*** jhorstmann is now known as Guest585209:39
opendevreviewVerification of a change to openstack/kolla-ansible master failed: blazar: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98145509:42
egonzalezo/ long time not joining in here. Hows everything going? Glad to see the project still rocking high09:43
opendevreviewPiotr Milewski proposed openstack/kolla-ansible master: Added vault support to barbican as back-end secret  https://review.opendev.org/c/openstack/kolla-ansible/+/93570409:44
opendevreviewMerged openstack/kolla master: kolla-toolbox: Add ansible-runner  https://review.opendev.org/c/openstack/kolla/+/98078809:47
opendevreviewMerged openstack/kolla master: Drop Telegraf  https://review.opendev.org/c/openstack/kolla/+/97431909:47
opendevreviewPiotr Milewski proposed openstack/kolla-ansible master: kolla_container: Add support for user and security_opt parameters  https://review.opendev.org/c/openstack/kolla-ansible/+/97506509:53
opendevreviewBertrand Lanson proposed openstack/kolla-ansible master: keystone: Setup fernet credentials encryption keys  https://review.opendev.org/c/openstack/kolla-ansible/+/97086110:01
opendevreviewPiotr Milewski proposed openstack/kolla-ansible master: kolla_container: Add support for user and security_opt parameters  https://review.opendev.org/c/openstack/kolla-ansible/+/97506510:02
mikalmnasiadka / blanson[m]: herm, I have conflated two uses of virtlogd. I am going to have to dig deeper into this when it is not bed time.10:09
opendevreviewPiotr Milewski proposed openstack/kolla-ansible master: Standardize API health check endpoints  https://review.opendev.org/c/openstack/kolla-ansible/+/96278510:10
blanson[m]mikal: sure, you have patches to review in the meantime ? if so you can link I will put some of them RP+1 :)10:11
opendevreviewVerification of a change to openstack/kolla-ansible stable/2025.1 failed: Fix idempotence on comparing capabilities for podman  https://review.opendev.org/c/openstack/kolla-ansible/+/97283610:11
opendevreviewVerification of a change to openstack/kolla-ansible stable/2025.1 failed: Fix podman idempotence on comparing container dimensions  https://review.opendev.org/c/openstack/kolla-ansible/+/97283710:11
opendevreviewVerification of a change to openstack/kolla-ansible stable/2025.1 failed: Fix idempotence on podman volume comparison  https://review.opendev.org/c/openstack/kolla-ansible/+/97283810:11
blanson[m](I saw you upload a bunch earlier that's why I'm asking)10:11
blanson[m]oh no I broke ci10:11
mikalblanson[m]: most of those are the kerbside support patches, which seem unlikely to land in 2026.1. That said, I'd say that https://review.opendev.org/c/openstack/kolla-ansible/+/967800, https://review.opendev.org/c/openstack/kolla-ansible/+/967802, and https://review.opendev.org/c/openstack/kolla-ansible/+/969138 are _not_ kerbside specific and are10:12
mikalgenerally desirable. Especially the last one.10:12
blanson[m]yh the last one seems pretty cool 10:14
mikalblanson[m]: by way of context, kerbside is the SPICE protocol native proxy envisaged by https://specs.openstack.org/openstack/nova-specs/specs/2025.1/implemented/libvirt-spice-direct-consoles.html10:14
mikalblanson[m]: which is basically about delivering Citrix-like VDI capabilites to OpenStack, but has been very hard to land because as best as I can tell that's not a thing people actually want.10:15
blanson[m]I'll read this spec 10:16
blanson[m]oh this is your spec10:16
blanson[m]lol that explains why you know so much about it 10:16
opendevreviewSeunghun Lee proposed openstack/kolla master: Update Ceph Squid RPM repo to centos-10-stream  https://review.opendev.org/c/openstack/kolla/+/98011410:19
mikalblanson[m]: yeah, this has been the least rewarding hobby ever for like three years now. if I'd known it was going to take this long to land I wouldn't have bothered.10:21
opendevreviewBertrand Lanson proposed openstack/kolla-ansible master: keystone: Setup fernet credentials encryption keys  https://review.opendev.org/c/openstack/kolla-ansible/+/97086110:37
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: blazar: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98145510:51
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: manila: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98145810:51
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: manila: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98145810:51
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: mistral: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146010:52
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: mistral: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146010:52
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: trove: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146710:52
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: zun: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146810:53
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: zun: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146810:53
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: trove: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146710:53
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: zun: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146810:53
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: cyborg: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98147010:53
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: cyborg: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98147010:53
opendevreviewPierre Riteau proposed openstack/kolla-ansible master: Add Prometheus integration for Docker  https://review.opendev.org/c/openstack/kolla-ansible/+/93674210:56
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: CI: Test for leaked passwords in syslog  https://review.opendev.org/c/openstack/kolla-ansible/+/98106810:57
opendevreviewTaavi Ansper proposed openstack/kolla-ansible master: Fix keystone with IDP configured.  https://review.opendev.org/c/openstack/kolla-ansible/+/97590110:57
tafkamaxOK I think I have an idea for apache wsgi provider.10:57
tafkamaxLet's see :-)10:57
tafkamaxit's like a pandoras box10:57
mnasiadkaOther option is to drop apache+mod_wsgi after my uwsgi patches land ^^10:58
tafkamaxTrue. I just am hoping the pandoras box will be empty soon and it can land faster that way :D11:00
tafkamaxalso it needs to be backported11:00
tafkamaxto 2025.211:01
blanson[m]mnasiadka: how'd you know this would break keystone_wsgi_provider apache ?11:07
tafkamaxIt might not break it for non-federation, but it would for federation enabled...11:10
tafkamaxKeystone-httpd is not used if keystone wsgi is apache. Because httpd and apache are the same things11:11
tafkamaxThe httpd is needed mostly for the redirect afaik to oidc11:11
tafkamaxThere is the mod_oidc plugin or whatever it is called in apache11:11
opendevreviewMerged openstack/kolla-ansible stable/2024.2: Fix idempotence on comparing capabilities for podman  https://review.opendev.org/c/openstack/kolla-ansible/+/97283911:15
mnasiadkablanson[m]: I did the original keystone uwsgi patch and I think I didn’t do a good job :) Basically when provider=apache - we do it the old way, and when it’s uwsgi we stand up keystone-httpd in front for federation11:15
tafkamaxI think another plugin like mod_oidc needs to be found for uwsgi?11:16
tafkamaxOr what would be the solution?11:16
opendevreviewMerged openstack/kolla-ansible stable/2024.2: Fix podman idempotence on comparing container dimensions  https://review.opendev.org/c/openstack/kolla-ansible/+/97284011:19
opendevreviewMerged openstack/kolla-ansible stable/2024.2: Fix idempotence on podman volume comparison  https://review.opendev.org/c/openstack/kolla-ansible/+/97284111:19
tafkamaxhttps://github.com/OpenIDC/mod_auth_openidc this is the module i am talking about11:20
mnasiadkaWe don’t do federation in uwsgi, it doesn’t support that and is not for that - that’s why we run apache in front if you have federation enabled11:21
tafkamaxI think uwsgi itself is too low-level or barebones, what you wanna call it...11:21
tafkamaxyeah11:21
tafkamaxSomekind of proxy is needed11:21
tafkamaxI have deployed recently this proxy https://github.com/oauth2-proxy/oauth2-proxy11:23
tafkamaxbut all-in-all I think if the apache one works there is no point in changing it11:23
tafkamaxI have deployed the oauth2-proxy for another use case. Serving static docs pages with authentication pretty much.11:24
tafkamaxIf the oauth2-proxy does not give any benefits11:24
mnasiadkaApache is fine, there’s oidc and saml2 support, so let’s not break people that have custom configs for federation :)11:30
tafkamaxYep11:34
tafkamaxJust expanding ze view11:34
opendevreviewPiotr Milewski proposed openstack/kolla master: Add Dockerfile for neutron-ovn-vpn-agent  https://review.opendev.org/c/openstack/kolla/+/92430211:36
opendevreviewMerged openstack/kolla master: rabbitmq: Update to 4.2  https://review.opendev.org/c/openstack/kolla/+/96601712:05
opendevreviewMerged openstack/kolla master: Update component list and versions  https://review.opendev.org/c/openstack/kolla/+/97930612:06
opendevreviewMerged openstack/kayobe stable/2025.1: Split Python installation from user bootstrap  https://review.opendev.org/c/openstack/kayobe/+/97847412:06
opendevreviewMerged openstack/kayobe stable/2025.2: Support Python installation through Apt proxy  https://review.opendev.org/c/openstack/kayobe/+/97847612:06
opendevreviewVerification of a change to openstack/kolla-ansible master failed: kolla_container: Return annotation of comparison failures  https://review.opendev.org/c/openstack/kolla-ansible/+/97816212:06
tafkamaxI don't know exactly, but would it be possible to import globals in test run.yml?12:12
tafkamaxOr is there any reason not to reference them that early?12:12
tafkamaxcant reference keystone_wsgi_provider in run.yml :D12:14
opendevreviewMerged openstack/kolla-ansible master: Ensure neutron_bridge_name and neutron_external_interface have the same length  https://review.opendev.org/c/openstack/kolla-ansible/+/94379912:15
tafkamaxok i have an radical idea just for testing in ci12:20
opendevreviewTaavi Ansper proposed openstack/kolla-ansible master: Fix keystone with IDP configured.  https://review.opendev.org/c/openstack/kolla-ansible/+/97590112:21
opendevreviewPiotr Milewski proposed openstack/kolla-ansible master: Implement neutron-ovn-vpn-agent  https://review.opendev.org/c/openstack/kolla-ansible/+/92457512:33
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: manila: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98145812:52
opendevreviewVerification of a change to openstack/kolla-ansible master failed: kolla_container: Return annotation of comparison failures  https://review.opendev.org/c/openstack/kolla-ansible/+/97816213:01
opendevreviewDoug Szumski proposed openstack/kolla-ansible master: Support multiple Nova Compute Ironic instances  https://review.opendev.org/c/openstack/kolla-ansible/+/97388113:11
opendevreviewSeunghun Lee proposed openstack/kolla-ansible master: Make RabbitMQ stream retention policy configurable  https://review.opendev.org/c/openstack/kolla-ansible/+/95329713:22
opendevreviewPiotr Milewski proposed openstack/kolla-ansible master: Fix: Update outdated documentation  https://review.opendev.org/c/openstack/kolla-ansible/+/98208913:30
opendevreviewSeunghun Lee proposed openstack/kolla-ansible stable/2025.1: [2025.1 only] Support ProxySQL 3.0.x on 2025.1  https://review.opendev.org/c/openstack/kolla-ansible/+/97471213:48
mnasiadkaApologies, meeting will be late, my sickness kicked in to a new level14:00
mnasiadka#startmeeting kolla14:04
opendevmeetMeeting started Wed Mar 25 14:04:09 2026 UTC and is due to finish in 60 minutes.  The chair is mnasiadka. Information about MeetBot at http://wiki.debian.org/MeetBot.14:04
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.14:04
opendevmeetThe meeting name has been set to 'kolla'14:04
mnasiadka#topic rollcall14:04
darmach1o/14:04
darmach1o714:04
butjaro/14:04
seunghunleeo/14:04
frickler\o14:04
dougszu\o14:05
mnasiadka#topic announcements14:06
mnasiadkaI booked PTG slots for Kolla/Kolla-Ansible/Kayobe14:06
mnasiadkaAnd created an etherpad14:06
mnasiadka#link https://etherpad.opendev.org/p/kolla-hibiscus-ptg14:06
mnasiadka#link https://ptg.opendev.org/ptg.html14:06
mnasiadkaIt’s 20-24 April 202614:07
blanson[m]hello 14:07
mnasiadka#topic CI status14:07
mnasiadkaLooks good, some occasional noble-upgrade and bookworm-upgrade failures, would be nice to analyse them one day :)14:08
mmalchuko/14:08
mnasiadka#topic Release tasks14:08
mnasiadkaIt’s R-1 week, we should be starting to think about branching - but first we need to start using stable/2026.1 in Kolla14:09
mnasiadkaThis patch14:09
mnasiadka#link https://review.opendev.org/c/openstack/kolla/+/98112314:09
mmalchukmnasiadka what about Kayobe PTG? it would be combined with Kolla?14:10
opendevreviewMichal Nasiadka proposed openstack/kolla master: Switch to Gazpacho/2026.1 sources  https://review.opendev.org/c/openstack/kolla/+/98112314:10
mmalchukwhich day?14:10
mnasiadkammalchuk: It’s on Thursday, as usual14:11
mnasiadkaIt’s all in the etherpad14:11
mnasiadka#topic Current cycle planning14:11
mmalchukgreat. thanks14:11
mnasiadkaSo, we merged RMQ 4.2 finally14:11
mnasiadkaAre there any other things Kolla wise (than 981123) that we need to merge?14:11
Vii#link https://review.opendev.org/c/openstack/kolla-ansible/+/935704 14:12
Vii? :)14:12
mnasiadkaThat’s kolla-ansible - I wanted to focus on Kolla first :D14:12
Viiok :)14:12
Viivault exporter14:12
Vii*valkey 14:13
Vii#link https://review.opendev.org/c/openstack/kolla/+/97665014:13
seunghunleehttps://review.opendev.org/c/openstack/kolla/+/980114 This one?14:14
seunghunleeoh you already put PR +114:14
seunghunleeRP*14:14
mnasiadkaOk, I think we have enough RP+1 on Kolla side14:14
mnasiadkaLet’s try to go through them, fellow cores14:14
mnasiadkaAnd then we’ll focus on Kolla-Ansible next week, I want to try get Kolla out through the door first (although there are K-A patches related to K patches - but let’s see how that goes)14:15
mnasiadka#topic Open discussion14:15
mnasiadkaAnybody wants to discuss anything?14:16
chembervinthi, could you please review out tiny-patch https://review.opendev.org/c/openstack/kolla-ansible/+/978869 ?:)14:16
seunghunleeThanks for reviewing https://review.opendev.org/c/openstack/kolla-ansible/+/953297  I made changes based on the reviews14:17
Viihave a topic related to VPN in Kolla Ansible - is there a chance it’ll be accepted, or probably not?14:17
chembervintthanks!14:17
Vii#link https://review.opendev.org/c/openstack/kolla-ansible/+/92457514:18
Viitest moving to Debian and Ubuntu14:18
mnasiadkaVii: I have that on my radar, but we need the security_opt patch as well, right?14:18
Viibut there is a problem with rocylinux, there is a new package in the system14:18
Viiand a fix for OpenStack Neutron probably won't be released anytime soon14:19
Vii#link https://bugs.launchpad.net/neutron/+bug/214630814:19
Vii EL10 ships with libreswan >= 5.x. The Libreswan upstream project has completely removed the _stackmanager script in the 5.x series. ....14:20
mnasiadkaWhat about moving to strongswan?14:21
Viiits similar but testing14:21
Viihttps://github.com/openstack/kolla/blob/6a1d383c48eda9fd9c1c55474d29bdba0f06a52f/docker/neutron/neutron-l3-agent/Dockerfile.j2#L1214:21
ViiI'm worried about that because it's here too ^14:21
blanson[m]chembervint: will take a look at it td hopefully I have some time 14:21
ViiI don't use it, but it might be a problem14:22
chembervintblanson: thank you!14:22
mnasiadkaVii: well, ideally we should have some vpnaas tests, but I don’t know how feasible this is14:23
ViiThe container now works without privileges: true14:23
ViiTheoretically, you could mark it BETA? and say it only works for Debian/Ubuntu :P :P14:23
Viilogs test-ovn #link https://zuul.opendev.org/t/openstack/build/34adeebcb14643dbaf5fe53e11aa5137/logs14:24
mnasiadkaWell, the fun is it’s buildable, but not functional14:26
ViiI using this code since 2024.2 and it works in production14:27
Viion ubuntu14:27
mnasiadkaWell, we could do a precheck that it’s not working on Rocky14:27
mnasiadkaAnd point to the bug14:27
ViiIt should work on Rocky Linux 9, but we probably don't want to make an exception14:28
blanson[m]that would work 14:28
mnasiadkaYou raised it 3 hours ago, I guess the vpn agent needs some love, question if Neutron team has capacity to fix it :)14:28
ViiI know, but there probably won't be a fix for 2026.114:28
mnasiadkaWell, fixes should be backported14:28
Viiso another half year of waiting14:28
mnasiadkaAnyway, it’s not for us to decide for now14:29
mnasiadkaI’ll put some of my thoughts in gerrit14:29
blanson[m]quick question while we're on neutron, do we need to do anything extra for the native ovn bgp thing coming to neutron to work on our side ? 14:29
ViiOK, so we wait thx14:29
blanson[m]the one that replaces ovn-bgp-agent 14:29
mnasiadkablanson[m]: probably we do, because something needs to run frr - but I haven’t looked into that yet14:29
blanson[m]we asked in neutron channel and it should be coming in a 2026.1 point release, so I was wondering 14:30
blanson[m]does it still need frr ? 14:30
mnasiadkablanson[m]: https://review.opendev.org/c/openstack/neutron-specs/+/952872 - that’s the spec - IIRC it does need FRR14:30
mnasiadkaL57 - Each compute node requires a running FRR instance14:31
chembervintwe have implementation for ovn-bgp-agent and frr roles in kolla-ansible + kolla. could it be interesting?14:31
mnasiadkachembervint: we don’t want to implement ovn-bgp-agent, just go with the native bgp integration in OVN - check the spec14:31
mnasiadkablanson[m]:it seems bgp extension should land/has landed in OVN Agent14:32
mnasiadkaWe don’t use it really, but the deployment support is there14:32
chembervintmnasiadka: ok, interesting. will see. thanks14:32
mmalchukwaiting for a native BGP in OVN14:33
mnasiadkaBut yeah, we might want to extract the frr role - but I don’t think it’s 2026.1 material - there’s not enough time14:33
mmalchukchembervint you can ask me offline)14:33
blanson[m]so "all there is to do" would in theory be make a kolla-frr container 14:33
blanson[m](and deploy it and test it and whatnot)14:33
chembervintmmalchuk: I will :)14:33
ViiI also use this role of frr and bgp in production, which someone once suggested, and it works14:34
Vii#link https://review.opendev.org/c/openstack/kolla-ansible/+/93706614:35
mnasiadkablanson[m]: well, in theory yes - but somebody would need to spend time to have that working (and ideally testable in our CI)14:35
mnasiadkaOk, I think we’ve had enough of a discussion :)14:38
mnasiadkaThank you all for coming, see you next week :)14:39
mnasiadka#endmeeting14:39
opendevmeetMeeting ended Wed Mar 25 14:39:05 2026 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)14:39
opendevmeetMinutes:        https://meetings.opendev.org/meetings/kolla/2026/kolla.2026-03-25-14.04.html14:39
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/kolla/2026/kolla.2026-03-25-14.04.txt14:39
opendevmeetLog:            https://meetings.opendev.org/meetings/kolla/2026/kolla.2026-03-25-14.04.log.html14:39
blanson[m]I mean we will need it otherwise ovn is not happening for us, so most likely I will (or someone from my company) end up spending time on it 14:39
Viiahh trivial: https://review.opendev.org/c/openstack/kolla-ansible/+/98208914:39
Viispring cleaning ;)14:40
mmalchukmnasiadka thanks 14:40
opendevreviewMerged openstack/kayobe stable/2025.1: Support Python installation through Apt proxy  https://review.opendev.org/c/openstack/kayobe/+/97847714:41
opendevreviewMerged openstack/kolla-ansible master: blazar: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98145514:41
opendevreviewMerged openstack/kolla-ansible stable/2025.1: Fix idempotence on comparing capabilities for podman  https://review.opendev.org/c/openstack/kolla-ansible/+/97283614:41
opendevreviewMerged openstack/kolla-ansible master: manila: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98145814:41
opendevreviewMerged openstack/kolla-ansible stable/2025.1: Fix podman idempotence on comparing container dimensions  https://review.opendev.org/c/openstack/kolla-ansible/+/97283714:42
opendevreviewMerged openstack/kolla-ansible stable/2025.1: Fix idempotence on podman volume comparison  https://review.opendev.org/c/openstack/kolla-ansible/+/97283814:42
opendevreviewPiotr Milewski proposed openstack/kolla master: Prometheus: add valkey exporter image  https://review.opendev.org/c/openstack/kolla/+/97665014:44
blanson[m]for people that mentioned having working frr implementations, I'd be interested to work on integrating it to kolla(-ansible), so if you can share your work I'll take it :D 14:46
opendevreviewTaavi Ansper proposed openstack/kolla-ansible master: Fix keystone with IDP configured.  https://review.opendev.org/c/openstack/kolla-ansible/+/97590114:46
opendevreviewMichal Nasiadka proposed openstack/kolla master: Switch to Gazpacho/2026.1 sources  https://review.opendev.org/c/openstack/kolla/+/98112314:46
opendevreviewMichal Nasiadka proposed openstack/kolla master: Switch to Gazpacho/2026.1 sources  https://review.opendev.org/c/openstack/kolla/+/98112314:47
opendevreviewMichal Nasiadka proposed openstack/kolla master: Switch to Gazpacho/2026.1 sources  https://review.opendev.org/c/openstack/kolla/+/98112314:49
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: mistral: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146014:50
opendevreviewPiotr Milewski proposed openstack/kolla-ansible master: Fix: Update outdated documentation  https://review.opendev.org/c/openstack/kolla-ansible/+/98208914:51
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: mistral: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146014:52
Vii blanson[m]:   https://review.opendev.org/c/openstack/kolla-ansible/+/93706614:54
ViiI've been using this since 2024.114:55
Viiin production and so far we haven't had any problems14:55
blanson[m]I bookmarked this one, I'll try to do something with it. You're using it right ? 14:55
blanson[m]as-is or are there patches that need to be added on top ? 14:55
ViiI use it as is14:56
blanson[m]ok great, thanks ! 14:57
Vii:)14:58
Viiopenstack.kolla/frr:2025.2-ubuntu-noble                        "dumb-init --single-…"   5 weeks ago   5 weeks ago (healthy)             frr14:58
Vii:)14:58
Viiopenstack.kolla/ovn-bgp-agent:2025.2-ubuntu-noble                 "dumb-init --single-…"   5 weeks ago   5 weeks ago                       ovn_bgp_agent14:58
Viibut as I wrote, I also used it in earlier versions14:59
chembervintwe've implemented very close to https://review.opendev.org/c/openstack/kolla-ansible/+/93706 in 2022, and using to till today15:00
chembervintif anybody are interested in it - I can ask the team to prepare commit15:00
blanson[m]chembervint: I mean if you have the bandwidth to do so it'd be very cool, we can also probbly allocate some time to work on it but it'd be better to start from somewhere if you already have something (hopefully it's not too much work as only frr should be required?)15:13
blanson[m]Vii: we're most likely only going to use it on releases where the bgp-agent is dropped just because we can afford to do so, but knowing it runs it pretty helpful :D 15:15
opendevreviewOwen Jones proposed openstack/kayobe master: Build Rocky based IPA images  https://review.opendev.org/c/openstack/kayobe/+/98210915:15
blanson[m]chembervint: I think your patch link is missing a digit 15:20
Viithis is the same link only the last digit has been removed15:24
blanson[m]oh15:26
blanson[m]well15:26
tafkamaxSo two different parties are using it already?15:27
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: mistral: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146015:34
blanson[m]Taavi Ansper: apparently so 15:36
opendevreviewBertrand Lanson proposed openstack/kolla-ansible master: keystone: Improve fernet/credential key bootstrap and distribution  https://review.opendev.org/c/openstack/kolla-ansible/+/98211315:40
blanson[m]I now made a chain for my eternal crusade to encrypt database credentials https://review.opendev.org/c/openstack/kolla-ansible/+/982113/1 I have no idea if it works or not yet, but feel free to chime in :)15:46
blanson[m]Vii chembervint: do I understand correctly the ovn-bgp thing ? you only need to have frr on the machine for it to work, then it's either directly baked into ovn or via the bgp-agent that you interact with it ? I'm not sure I understand the spec correctly but I'm asking because we already do bgp to the host so we already have frr installed (just not containerized but the frr install predates kolla it's essentially installed during16:05
blanson[m]the host initial configuration)16:05
blanson[m]so we could just reuse this daemon ?16:05
ViiYes, your understanding is spot on.16:08
Viiovn-bgp-agent itself doesn't actually speak BGP. It acts as a middleman: it watches the OVN databases (NB/SB) for things like Floating IPs or provider networks that need to be exposed, and then it translates them and configures FRR to actually advertise those routes to your physical fabric.16:09
Viiyou can absolutely reuse your existing daemon You don't have to use the containerized FRR provided by this Kolla patch.16:09
ViiThe only requirement is that the containerized ovn-bgp-agent needs to be able to talk to your host's FRR16:10
Vii If you look at the patch, the agent container mounts /var/run/frr/:/run/frr/. 16:10
blanson[m]yh that's when I started to connect my 3 neurons together 16:10
blanson[m]that's very cool, well, now I want to work on this thing 16:11
Viiit works, I don't know why this patch didn't go through, I wasn't that interested16:12
opendevreviewTaavi Ansper proposed openstack/kolla-ansible master: Fix keystone with IDP configured.  https://review.opendev.org/c/openstack/kolla-ansible/+/97590116:13
blanson[m]I think the reason is that it was "late" and bgp-agent was already being sunset by neutron in favor or the native bgp driver in ovn 16:14
blanson[m]so people didn't want to maintain the ovn-bgp-agent for just 1 cycle 16:14
Viimaybe16:15
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: CI: Test for leaked passwords in syslog  https://review.opendev.org/c/openstack/kolla-ansible/+/98106816:18
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: CI: Test for leaked passwords in syslog  https://review.opendev.org/c/openstack/kolla-ansible/+/98106816:19
opendevreviewMichal Nasiadka proposed openstack/kolla master: Switch to Gazpacho/2026.1 sources  https://review.opendev.org/c/openstack/kolla/+/98112316:24
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: trove: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146716:26
opendevreviewWill Szumski proposed openstack/kolla stable/2025.1: Install iptables-nft in Rocky 9 containers  https://review.opendev.org/c/openstack/kolla/+/98109616:34
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: trove: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146716:58
opendevreviewMerged openstack/kolla-ansible master: mistral: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146016:58
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: zun: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146817:32
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: cyborg: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98147017:32
opendevreviewPiotr Milewski proposed openstack/kolla-ansible master: Add Galera cluster event notifications to Alertmanager  https://review.opendev.org/c/openstack/kolla-ansible/+/98214218:18
opendevreviewPiotr Milewski proposed openstack/kolla-ansible master: Add Galera cluster event notifications to Alertmanager  https://review.opendev.org/c/openstack/kolla-ansible/+/98214218:36
opendevreviewVerification of a change to openstack/kolla master failed: Prometheus: add valkey exporter image  https://review.opendev.org/c/openstack/kolla/+/97665018:39
opendevreviewPiotr Milewski proposed openstack/kolla-ansible master: Add Galera cluster event notifications to Alertmanager  https://review.opendev.org/c/openstack/kolla-ansible/+/98214218:43
opendevreviewTaavi Ansper proposed openstack/kolla-ansible master: Fix keystone with IDP configured.  https://review.opendev.org/c/openstack/kolla-ansible/+/97590119:13
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: CI: Test for leaked passwords in syslog  https://review.opendev.org/c/openstack/kolla-ansible/+/98106819:15
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: kolla_toolbox: fix secrets leaking  https://review.opendev.org/c/openstack/kolla-ansible/+/98078719:15
opendevreviewMichal Nasiadka proposed openstack/kolla master: Switch to Gazpacho/2026.1 sources  https://review.opendev.org/c/openstack/kolla/+/98112319:20
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: CI: Test for leaked passwords in syslog  https://review.opendev.org/c/openstack/kolla-ansible/+/98106819:21
opendevreviewMichal Nasiadka proposed openstack/kolla-ansible master: trove: Switch to uWSGI  https://review.opendev.org/c/openstack/kolla-ansible/+/98146719:31
opendevreviewPiotr Milewski proposed openstack/kolla-ansible master: Fix: Update outdated documentation  https://review.opendev.org/c/openstack/kolla-ansible/+/98208920:07
opendevreviewHao Wang proposed openstack/kolla-ansible master: Support deploy Zaqar with kolla-ansible  https://review.opendev.org/c/openstack/kolla-ansible/+/89261521:26

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!