| opendevreview | Michael Still proposed openstack/kolla master: Revert "Switch to Gazpacho/2026.1 sources". https://review.opendev.org/c/openstack/kolla/+/991249 | 00:14 |
|---|---|---|
| mikal | ^--- mnasiadka, that change is my attempt to get the nova images building again. They need the master requirements.txt because nova bumped the version of oslo.privsep they require. | 00:21 |
| *** Viii5 is now known as Viii | 00:22 | |
| opendevreview | Michael Still proposed openstack/kolla master: Implement container image build for kerbside. https://review.opendev.org/c/openstack/kolla/+/975495 | 03:13 |
| opendevreview | Michael Still proposed openstack/kolla master: Add opt-in SPICE support for Rocky via COPR. https://review.opendev.org/c/openstack/kolla/+/986283 | 03:13 |
| opendevreview | Michael Still proposed openstack/kolla-ansible master: Deploy Kerbside with Kolla-Ansible. https://review.opendev.org/c/openstack/kolla-ansible/+/976889 | 03:14 |
| opendevreview | Michael Still proposed openstack/kolla-ansible master: Use a routable IP for qemu SPICE consoles. https://review.opendev.org/c/openstack/kolla-ansible/+/967801 | 03:14 |
| opendevreview | Michael Still proposed openstack/kolla-ansible master: Add kerbside CI scenario jobs. https://review.opendev.org/c/openstack/kolla-ansible/+/988189 | 03:14 |
| opendevreview | Michael Still proposed openstack/kolla-ansible master: Run the spice-direct tempest test in the kerbside scenario. https://review.opendev.org/c/openstack/kolla-ansible/+/988913 | 03:14 |
| opendevreview | Michael Still proposed openstack/kolla-ansible master: Run a Kerbside-fronted SPICE tempest test in the kerbside scenario. https://review.opendev.org/c/openstack/kolla-ansible/+/989614 | 03:14 |
| opendevreview | Michal Nasiadka proposed openstack/kolla-ansible master: fluentd: Use group_add to grant systemd journal access https://review.opendev.org/c/openstack/kolla-ansible/+/990819 | 04:15 |
| opendevreview | Michal Nasiadka proposed openstack/kolla-ansible master: Replace /etc/localtime bind mount with TZ env variable https://review.opendev.org/c/openstack/kolla-ansible/+/989435 | 04:16 |
| opendevreview | Michal Nasiadka proposed openstack/kolla-ansible master: Replace /etc/localtime bind mount with TZ env variable https://review.opendev.org/c/openstack/kolla-ansible/+/989435 | 04:17 |
| opendevreview | Michal Nasiadka proposed openstack/kolla-ansible master: fluentd: Use group_add to grant systemd journal access https://review.opendev.org/c/openstack/kolla-ansible/+/990819 | 05:08 |
| opendevreview | Michal Nasiadka proposed openstack/kolla-ansible master: fluentd: Use group_add to grant systemd journal access https://review.opendev.org/c/openstack/kolla-ansible/+/990819 | 05:11 |
| *** jhorstmann is now known as Guest10709 | 09:38 | |
| opendevreview | Michel Raabe proposed openstack/kolla-ansible master: keystone: allow multiple OIDCXForwardedHeaders options https://review.opendev.org/c/openstack/kolla-ansible/+/991310 | 10:55 |
| opendevreview | Michel Raabe proposed openstack/kolla-ansible master: keystone: allow multiple OIDCXForwardedHeaders options https://review.opendev.org/c/openstack/kolla-ansible/+/991310 | 11:14 |
| opendevreview | Michel Raabe proposed openstack/kolla-ansible master: keystone: allow multiple OIDCXForwardedHeaders options https://review.opendev.org/c/openstack/kolla-ansible/+/991310 | 11:16 |
| opendevreview | Matt Crees proposed openstack/kayobe master: Drop kolla-tags and kolla-limit https://review.opendev.org/c/openstack/kayobe/+/983527 | 12:08 |
| opendevreview | Matt Crees proposed openstack/kayobe master: Drop kolla-tags and kolla-limit https://review.opendev.org/c/openstack/kayobe/+/983527 | 12:10 |
| opendevreview | William Tripp proposed openstack/kolla-ansible master: Change keystone_federation_oidc_response_type default to "code" https://review.opendev.org/c/openstack/kolla-ansible/+/991341 | 13:02 |
| mnasiadka | #startmeeting kolla | 13:02 |
| opendevmeet | Meeting started Wed Jun 3 13:02:45 2026 UTC and is due to finish in 60 minutes. The chair is mnasiadka. Information about MeetBot at http://wiki.debian.org/MeetBot. | 13:02 |
| opendevmeet | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 13:02 |
| opendevmeet | The meeting name has been set to 'kolla' | 13:02 |
| mnasiadka | #topic rollcall | 13:02 |
| butjar | o/ | 13:02 |
| frickler | \o | 13:03 |
| eduardomorais[m] | o/ | 13:03 |
| * frickler was just trying to remember whether we had cancelled this week ;) | 13:03 | |
| isaacvicente[m] | o/ | 13:03 |
| bbezak | o/ | 13:03 |
| mnasiadka | sorry, got caught by a wall of rain on the way to my laptop ;) | 13:04 |
| mnasiadka | #topic agenda | 13:04 |
| mnasiadka | * CI status | 13:05 |
| mnasiadka | * Release tasks | 13:05 |
| mnasiadka | * Current cycle planning | 13:05 |
| mnasiadka | * Additional agenda (from whiteboard) | 13:05 |
| mnasiadka | * Open discussion | 13:05 |
| mnasiadka | #topic CI status | 13:05 |
| mnasiadka | Anybody has any grudges against the CI? | 13:05 |
| mnasiadka | None? Fine :) | 13:06 |
| bbezak | :) | 13:07 |
| mnasiadka | #topic Release tasks | 13:07 |
| mnasiadka | It’s R-17 this week | 13:07 |
| mnasiadka | #link https://docs.openstack.org/kolla/latest/contributor/release-management.html#r-17-switch-source-images-to-current-release | 13:07 |
| mnasiadka | I think mikal already posted a revert | 13:07 |
| mnasiadka | #link https://review.opendev.org/c/openstack/kolla/+/991249 | 13:08 |
| frickler | yes, seems nova has breaking reqs by now | 13:08 |
| mnasiadka | I’m fine with pure revert, but we need a followup - the codename is used by Debian OpenStack | 13:09 |
| mnasiadka | Commented on the patch | 13:10 |
| mnasiadka | #topic Current cycle planning | 13:10 |
| mnasiadka | Let’s have a look at Kolla RP+1 | 13:11 |
| mnasiadka | We have the revert that was discussed already | 13:11 |
| mnasiadka | There’s also getting rid of kolla_el10 because EPEL 10.2 finally has mod-auth-mellon | 13:11 |
| mnasiadka | #link https://review.opendev.org/c/openstack/kolla/+/987795 | 13:12 |
| mnasiadka | There’s also YAML support for kolla_set_configs - but that is waiting on the author (or a willing core) to update it | 13:12 |
| mnasiadka | #link https://review.opendev.org/c/openstack/kolla/+/982275 | 13:12 |
| mnasiadka | And a lot of RP+1 in Kolla-Ansible | 13:13 |
| mnasiadka | I’m mostly interested in introducing service-config role | 13:13 |
| bbezak | Will try to look into those when I get the chance | 13:14 |
| mnasiadka | #link https://review.opendev.org/c/openstack/kolla-ansible/+/989961/13 | 13:14 |
| mnasiadka | Anybody else wants to discuss anything that would likely be merged this cycle? | 13:14 |
| mnasiadka | Seems not | 13:16 |
| mnasiadka | There’s additional agenda item by blanson[m] - but he’s not here | 13:16 |
| mnasiadka | So I’ll leave that for some other weekly meeting | 13:16 |
| blanson[m] | oh | 13:17 |
| blanson[m] | hello I was banging my head against some work I missed the meeting | 13:17 |
| mnasiadka | Ok then, so let’s do it | 13:17 |
| mnasiadka | #topic Additional agenda (from whiteboard) | 13:18 |
| mnasiadka | (blanson) improve certificate management for TLS stuff. I've worked on an addon to k-a that generates a full CA with per-host certificates etc... handles renewal, all the goodies. | 13:18 |
| mnasiadka | maybe this could be put in place of the current certificate management system ? | 13:18 |
| mnasiadka | renewal is I think especially important | 13:18 |
| mnasiadka | allow to configure the CA, do additional SANs, etc... | 13:18 |
| mnasiadka | or keep it separate and open source the kolla-ca thingy ? | 13:18 |
| blanson[m] | what did I put up the white board | 13:18 |
| blanson[m] | oh it's the TLS thingy yes so basically | 13:18 |
| blanson[m] | we had some needs to maintain internal cluster CAs for possibly multiple clusters, and poking around at the certificate generation from k-a I though it was lacking some features for customization | 13:19 |
| blanson[m] | so I made a quick ansible-collection that does pretty much the exact same but we can customize the CA to our liking | 13:19 |
| blanson[m] | maybe it could be bundled into a replacement role for the current one ? | 13:19 |
| blanson[m] | or just open source it and let it live outside k-a | 13:20 |
| mnasiadka | Well, in the past there was a discussion of properly doing auto certificates renewal using PKI such as OpenBao? | 13:20 |
| mnasiadka | I’m fine with extending what we have now, but we had multiple discussions that it shouldn’t be the production-ready solution | 13:21 |
| mnasiadka | Which I basically agree | 13:21 |
| mnasiadka | with | 13:21 |
| mnasiadka | bbezak, frickler - opinions? | 13:22 |
| blanson[m] | yh, well we tried this but it's more of a pain that we though cause it means lots of external dependencies on openbao/vault and so on + something on every node to rotate them like consul-template or some other magic ( I think vault has an acme-like api now) | 13:22 |
| mnasiadka | (I hate calling people to the board) :D | 13:22 |
| frickler | 5 different customers have 6 different CA solutions anyway, yes. so anything needed to get the CI to work is good enough for me | 13:22 |
| mnasiadka | Yeah, acme-like API is probably better | 13:22 |
| mnasiadka | There’s no really open-source consul alternative | 13:22 |
| isaacvicente[m] | i dont know if im missing something, this solution is for self-assign certs? or theres a renew request to a CA? | 13:22 |
| mnasiadka | And I think there’s work already to package openbao in Kolla | 13:22 |
| blanson[m] | I think it's just work for barbican secret backend ? | 13:23 |
| mnasiadka | isaacvicente[m]: we still generate CA for self-signed certs used only for CI, so that’s basically the same | 13:23 |
| blanson[m] | I reviewed this sometime this week | 13:23 |
| mnasiadka | blanson[m]: yes, but we can extend it | 13:23 |
| mnasiadka | But I understand that it’s probably not trivial task | 13:23 |
| mnasiadka | Anyway - if you want to propose what you have - we can take it off from there for now | 13:24 |
| mnasiadka | But I can’t promise we’re going to maintain it forever | 13:24 |
| mnasiadka | (Or at all) | 13:24 |
| blanson[m] | isaacvicente: so my understanding is that currently the certificate role is mainly used for CI, and anyone who wants production CA does its own thing. so we made our own thing which turns out is an ansible collection, that manages all of our certificates for the cluster. so maybe this new one could replace the current one if anyone thinks it'd be good | 13:25 |
| blanson[m] | mnasiadka: I will try to bundle everything up and send it so you guys can take a look | 13:25 |
| mnasiadka | Ok, thanks | 13:25 |
| mnasiadka | no other topics on the whiteboard | 13:25 |
| mnasiadka | #topic Open discussion | 13:25 |
| mnasiadka | Anybody anything? | 13:25 |
| butjar | I have a general question | 13:25 |
| eduardomorais[m] | me | 13:25 |
| butjar | We are currently reworking our upgrading processes and we wanted to ask why the version of the container engine is not pinned in kolla. | 13:26 |
| mnasiadka | butjar: that’s up to the operator, we provide ansible-collection-kolla as a convenience - you can use anything else | 13:26 |
| blanson[m] | use podman so that upgrading is transparent to the cluster :)))) | 13:27 |
| mnasiadka | And transparently breaks everything? :) | 13:27 |
| blanson[m] | we'll find out soon enough 2026.1 upgrade is approaching :D | 13:27 |
| butjar | I mean why the version of docker/ podman are not pinned to a certain version | 13:27 |
| mnasiadka | butjar: why would they be? | 13:28 |
| butjar | Because it can break things, we just had the ulimit thing couple of weeks ago :) | 13:28 |
| mnasiadka | First of all - are you asking about the container runtime or docker-py and podman-py? | 13:28 |
| butjar | Container runtime. The podman or docker release. | 13:29 |
| mnasiadka | Because we’re not pinning, we never pinned, managed the breakage in CI | 13:29 |
| mnasiadka | We would need to manage the pin in stable branches - and nobody volunteered to do this | 13:30 |
| mnasiadka | And that would be problematic, because somebody else would come and ask why are we pinning :) | 13:30 |
| mnasiadka | As I said, that’s up to the deployer/operator | 13:30 |
| mnasiadka | eduardomorais[m]: now it’s your turn | 13:30 |
| isaacvicente[m] | A requirements.txt solves this issue, and the operator can pin to whichever version they like | 13:31 |
| eduardomorais[m] | ok | 13:31 |
| butjar | Ok, so its a general decicion not to pin dependencies in k-a (heavy maintanance) | 13:31 |
| eduardomorais[m] | I'm working on the ovs-to-ovn migration and I was facing a error with ovn-metadata. The logs are https://paste.openstack.org/show/833857/ | 13:31 |
| isaacvicente[m] | ack | 13:31 |
| mnasiadka | isaacvicente[m]: requirements.txt is for python packages | 13:31 |
| isaacvicente[m] | oh I see | 13:31 |
| mnasiadka | And the mechanism in OpenStack for testing is upper-constraints.txt from openstack/requirements repository - but still for python packages | 13:32 |
| eduardomorais[m] | in 2025.2 and backwards i dont get it? anyone know anything ? | 13:32 |
| blanson[m] | butjar: tho the bootstrap steps in k-a are fairly light, so you could imagine moving them to an in-house playbook that pins stuff | 13:32 |
| mnasiadka | eduardomorais[m]: that question would rather be for #openstack-neutron channel | 13:32 |
| eduardomorais[m] | the first phrase its no a question sorry | 13:32 |
| eduardomorais[m] | mnasiadkaok | 13:33 |
| mnasiadka | Ok then, I think all is clear | 13:33 |
| mnasiadka | eduardomorais[m]: any outlook when you’ll propose a patch for the OVN migration tooling? | 13:34 |
| butjar | blanson[m]: Yep, this is probably what we are going to do. Thanks for the advice. Im still analyzing, the container engine is only touched on bootstrap? | 13:34 |
| blanson[m] | yup | 13:34 |
| opendevreview | William Tripp proposed openstack/kolla-ansible master: Change keystone_federation_oidc_response_type default to "code" https://review.opendev.org/c/openstack/kolla-ansible/+/991341 | 13:34 |
| isaacvicente[m] | mnasiadkawe are working on it | 13:34 |
| butjar | blanson[m]: perfect, so should not break an upgrade anyway. | 13:34 |
| isaacvicente[m] | its in WIP right now | 13:35 |
| mnasiadka | isaacvicente[m]: url? | 13:35 |
| isaacvicente[m] | I will drop, just a sec | 13:35 |
| eduardomorais[m] | we need work more because of the new version mnasiadka | 13:35 |
| eduardomorais[m] | https://review.opendev.org/c/openstack/kolla-ansible/+/989830 | 13:35 |
| mnasiadka | thanks | 13:35 |
| mnasiadka | Ok, that’s probably enough for today | 13:36 |
| mnasiadka | Thank you all for coming | 13:36 |
| mnasiadka | Ah! | 13:36 |
| mnasiadka | The meeting next week will be cancelled | 13:36 |
| mnasiadka | Me and bbezak are on full-day meetings next week | 13:36 |
| mnasiadka | I’ll send notification to the ML | 13:37 |
| frickler | enjoy ;) | 13:37 |
| mnasiadka | That’s it for today :) | 13:37 |
| butjar | have fun :) | 13:37 |
| mnasiadka | frickler: we will NOT | 13:37 |
| mnasiadka | #endmeeting | 13:37 |
| opendevmeet | Meeting ended Wed Jun 3 13:37:17 2026 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 13:37 |
| opendevmeet | Minutes: https://meetings.opendev.org/meetings/kolla/2026/kolla.2026-06-03-13.02.html | 13:37 |
| opendevmeet | Minutes (text): https://meetings.opendev.org/meetings/kolla/2026/kolla.2026-06-03-13.02.txt | 13:37 |
| opendevmeet | Log: https://meetings.opendev.org/meetings/kolla/2026/kolla.2026-06-03-13.02.log.html | 13:37 |
| blanson[m] | that sounds like a full-day of fun :) | 13:37 |
| blanson[m] | mnasiadka: I sent some review for service-config patch | 13:37 |
| blanson[m] | earlier this week I think | 13:38 |
| mnasiadka | blanson[m]: thanks, I’ll have a look | 13:40 |
| mnasiadka | blanson[m]: full week of full day negligible fun | 13:41 |
| blanson[m] | oh no it's meeting week next week ? | 13:47 |
| opendevreview | Matt Crees proposed openstack/kayobe master: Drop kolla-tags and kolla-limit https://review.opendev.org/c/openstack/kayobe/+/983527 | 14:57 |
| opendevreview | Matt Crees proposed openstack/kayobe master: Drop kolla-tags and kolla-limit https://review.opendev.org/c/openstack/kayobe/+/983527 | 15:26 |
| opendevreview | William Tripp proposed openstack/kolla-ansible master: Change keystone_federation_oidc_response_type default to "code" https://review.opendev.org/c/openstack/kolla-ansible/+/991341 | 15:27 |
| opendevreview | Maksim Malchuk proposed openstack/kayobe stable/2025.2: Adds support for custom watcher configuration files https://review.opendev.org/c/openstack/kayobe/+/991480 | 17:18 |
| opendevreview | Maksim Malchuk proposed openstack/kayobe stable/2025.1: Adds support for custom watcher configuration files https://review.opendev.org/c/openstack/kayobe/+/991481 | 17:20 |
| opendevreview | Pierre Riteau proposed openstack/kayobe stable/2026.1: CI: Remove override-checkout for stable/2026.1 https://review.opendev.org/c/openstack/kayobe/+/990791 | 18:24 |
| opendevreview | Michael Still proposed openstack/kolla master: Master is now Hibiscus OpenStack release. https://review.opendev.org/c/openstack/kolla/+/991249 | 19:22 |
| opendevreview | Pierre Riteau proposed openstack/kayobe master: CI: Stop using image from Docker Hub https://review.opendev.org/c/openstack/kayobe/+/991505 | 20:59 |
| jwitko | Hey All! I'm looking at kolla-ansible for valkey implementation and I'm noticing there doesn't seem to be any valkey or valkey-sentinel TLS configuration options. Is this an accurate assessment or maybe I'm missing something? If so does anyone know of any reason why this may be or is it simply that it didn't get done and someone could submit a PR? | 21:01 |
| opendevreview | Pierre Riteau proposed openstack/kayobe master: Replace `which` with `command` https://review.opendev.org/c/openstack/kayobe/+/991507 | 21:17 |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!