Wednesday, 2026-09-16

opendevreviewMerged openstack/kolla master: Pin Lego to v4  https://review.opendev.org/c/openstack/kolla/+/100519200:32
opendevreviewOpenStack Proposal Bot proposed openstack/kolla master: Updated from check-sources  https://review.opendev.org/c/openstack/kolla/+/100547902:54
opendevreviewPierre Riteau proposed openstack/kayobe stable/2025.2: CI: Bump kayobe-tox-ansible to one hour  https://review.opendev.org/c/openstack/kayobe/+/100583006:11
opendevreviewPierre Riteau proposed openstack/kayobe master: CI: Enable EPEL only when required  https://review.opendev.org/c/openstack/kayobe/+/100583106:59
opendevreviewPierre Riteau proposed openstack/kayobe master: CI: Enable EPEL only when required  https://review.opendev.org/c/openstack/kayobe/+/100583107:23
opendevreviewMerged openstack/kolla master: Updated from check-sources  https://review.opendev.org/c/openstack/kolla/+/100547907:48
opendevreviewMerged openstack/kayobe stable/2025.2: CI: Bump kayobe-tox-ansible to one hour  https://review.opendev.org/c/openstack/kayobe/+/100583007:48
opendevreviewRowan Johns proposed openstack/kayobe master: Move package installs into a single script  https://review.opendev.org/c/openstack/kayobe/+/100519408:06
opendevreviewRowan Johns proposed openstack/kayobe master: Move package installs into a single script  https://review.opendev.org/c/openstack/kayobe/+/100519408:08
opendevreviewRowan Johns proposed openstack/kayobe master: Move package installs into a single script  https://review.opendev.org/c/openstack/kayobe/+/100519408:11
opendevreviewFreerk-Ole Zakfeld proposed openstack/kolla-ansible master: Support proxy environment for grafana  https://review.opendev.org/c/openstack/kolla-ansible/+/100584809:08
opendevreviewFreerk-Ole Zakfeld proposed openstack/kolla-ansible master: Support proxy environment for grafana  https://review.opendev.org/c/openstack/kolla-ansible/+/100584809:09
opendevreviewFreerk-Ole Zakfeld proposed openstack/kolla-ansible master: Support proxy environment for grafana  https://review.opendev.org/c/openstack/kolla-ansible/+/100584809:34
opendevreviewFreerk-Ole Zakfeld proposed openstack/kolla-ansible master: Add `letsencrypt_lego_force_active` option  https://review.opendev.org/c/openstack/kolla-ansible/+/100273909:42
opendevreviewClaudia Watson proposed openstack/kolla stable/2026.1: Fix: Zstd missing from ironic conductor container.  https://review.opendev.org/c/openstack/kolla/+/100585009:42
mnasiadkablanson[m]: it is always fun :)11:09
mnasiadkablanson[m]: willing to have a look at https://review.opendev.org/c/openstack/kolla/+/994460 ?11:50
blanson[m]mnasiadka: sure, there's more comment than code I like these patches :)11:51
blanson[m]LP is absurdly slow for me ? is that a me-problem ?11:52
bbezak(Works OK here - LP)11:54
blanson[m]hmm 11:57
mnasiadkaInternet is dying :)12:00
blanson[m]I hope not lol, that's the only thing I'm good at 12:02
opendevreviewMatt Crees proposed openstack/kayobe master: Add support for configuring Dell SONiC switches  https://review.opendev.org/c/openstack/kayobe/+/100457412:05
opendevreviewClaudia Watson proposed openstack/kolla master: Fix: Zstd missing from ironic conductor container.  https://review.opendev.org/c/openstack/kolla/+/100586912:16
opendevreviewMichal Nasiadka proposed openstack/kolla master: Ensure git cloned dirs are writable for the executing user  https://review.opendev.org/c/openstack/kolla/+/99446012:19
opendevreviewAlex Welsh proposed openstack/kolla stable/2026.1: grafana: install Prometheus datasource plugin  https://review.opendev.org/c/openstack/kolla/+/100587112:36
opendevreviewAlex Welsh proposed openstack/kolla stable/2026.1: grafana: install Prometheus datasource plugin  https://review.opendev.org/c/openstack/kolla/+/100587112:40
dcapone2004I posted the other day about a letsencrypt issue I am facing with KA and certificates not generating.  I initially thought the issue was because the LE webserver was bound to the internal API interface, but after spending time combing through documentation I see this is by design and that the requests all filter through and are proxied through horizon / HAProxy which makes sense12:41
opendevreviewAlex Welsh proposed openstack/kolla stable/2025.2: grafana: install Prometheus datasource plugin  https://review.opendev.org/c/openstack/kolla/+/100587212:42
opendevreviewAlex Welsh proposed openstack/kolla stable/2025.1: grafana: install Prometheus datasource plugin  https://review.opendev.org/c/openstack/kolla/+/100587312:42
dcapone2004that caused me to dig into the HAProxy logs and see what is occuring.  When manually running the letsencrypt-lego-run.sh script inside of the container, I get an unauthorized 403 unauthorized.  Cross checking with the HAProxy logs shows that it is getting a 404 file not found for the URL requested by the LE servers12:43
dcapone2004is this a bug, or what might be incorrectly configured to cause this?  The settings for LE in globals.yml are quite minimal and seemingly self explanatory, so if it is a configuration issue, I am guessing it has to do with some HAProxy settings that needs to match or someting12:44
bbezakdcapone2004: https://review.opendev.org/c/openstack/kolla-ansible/+/1002207 maybe because of that?12:47
bbezakTry setting enable_letsencrypt12:47
bbezak== yes :)12:48
dcapone2004enable_letsencrypt is set to true and I have a valid email, looking at the report URL now12:48
bbezakExactly, please set it to “yes” :)12:49
bbezakCurrent check is only checking statement to == yes12:49
bbezakAnd not | bool12:49
bbezakSo only “yes” will work12:50
mnasiadka bbezak frickler kevko mmalchuk gkoper jovial mattcrees dougszu darmach pabloclsn ravlew salmankh amir58118 r-krcek blanson[m] fprzewozn - meeting in 9 minutes12:51
Guest17740o/12:52
mnasiadkaIn 9 minutes, not now Guest1774012:52
Guest17740just checking in :D12:53
opendevreviewJack Hodgkiss proposed openstack/kolla-ansible master: fix: ironic `tftp_server` tracks `ironic_tftp_listen_address`  https://review.opendev.org/c/openstack/kolla-ansible/+/100587412:53
mnasiadka#startmeeting kolla13:01
opendevmeetMeeting started Wed Sep 16 13:01:00 2026 UTC and is due to finish in 60 minutes.  The chair is mnasiadka. Information about MeetBot at http://wiki.debian.org/MeetBot.13:01
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.13:01
opendevmeetThe meeting name has been set to 'kolla'13:01
mnasiadka#topic rollcall13:01
mnasiadkaO/13:01
Guest17740\o13:01
kkaptanoglu1o/13:01
bbezak\o13:01
mnasiadka#topic agenda13:03
mnasiadka#link https://docs.openstack.org/kolla/latest/contributor/meeting.html#agenda13:03
*** Guest17740 is now known as ravlew13:03
mnasiadka#topic Announcements13:03
mnasiadkaJust a reminder, that Kolla is not having a regular session during the upcoming PTG - just the operator hour slot will happen at that time13:03
mnasiadka#topic CI status13:04
mnasiadkaAfter fixing the Debian OpenDev mirror - I think we’re fine again13:04
mnasiadkaNot counting the jobs that fail every time and we don’t care for them13:04
mnasiadka#topic Release tasks13:05
mnasiadkaWe should be switching to use stable/2026.2 soon, although there’s no requirements stable/2026.2 yet13:05
mnasiadka#topic Current cycle planning13:05
mnasiadkaAnybody anything?13:06
KurtBo/13:06
mnasiadkaI assume we’ve merged Ansible bump, RMQ and other components are in good shape - so we should be good to release?13:07
opendevreviewPierre Riteau proposed openstack/kolla stable/2026.1: grafana: install Prometheus datasource plugin  https://review.opendev.org/c/openstack/kolla/+/100587113:07
ravlewansible-bump is merged13:07
mnasiadkaOk then, seems nobody disagrees :)13:07
mnasiadkaThere are two additional topics on the whiteboard, but people who proposed them are not on the meeting13:08
opendevreviewPierre Riteau proposed openstack/kolla stable/2025.2: grafana: install Prometheus datasource plugin  https://review.opendev.org/c/openstack/kolla/+/100587213:09
fprzewozno/13:09
fprzewoznsorry for being late13:09
fprzewoznjust in time I see13:09
mnasiadkaOh yes13:09
fprzewoznso13:09
fprzewoznbiggest one: Aetos13:09
fprzewozngot full kolla + kolla-ansible code ready for some time now13:10
fprzewoznhttps://review.opendev.org/c/openstack/kolla/+/997478 https://review.opendev.org/c/openstack/kolla-ansible/+/99752213:10
opendevreviewPierre Riteau proposed openstack/kolla stable/2025.1: grafana: install Prometheus datasource plugin  https://review.opendev.org/c/openstack/kolla/+/100587313:10
fprzewoznGot it also running on one of customers envs, no issues so far there13:10
fprzewoznthen there's a topic you closed mnasiadka before meeting :) https://review.opendev.org/c/openstack/kolla-ansible/+/1003377 13:11
fprzewoznso got both precheck fixes in place, now time for backporting13:11
fprzewoznand third one 13:11
fprzewoznProxySQL, got change of the group mode: https://review.opendev.org/c/openstack/kolla-ansible/+/100513813:11
fprzewoznI've got it implemented partially and looks fine for me, no issues just benefits :)13:12
fprzewoznbut it would be cool if anyone could test it as well 13:13
blanson[m]the proxysql thing is cool thanks ! 13:13
fprzewoznand there's an older, but still active topic of mtls control in proxysql https://review.opendev.org/c/openstack/kolla-ansible/+/96429913:13
fprzewoznand that is where proxysql connects to DB13:13
mnasiadkaProxysql writer is also reader is merging13:13
fprzewoznthanks!13:14
fprzewoznmtls thingy is a bit more complex one13:14
fprzewoznI'm running this patch on multiple production clusters, where internal certs are managed outside K-A 13:15
tafkamaxhi13:15
fprzewoznand clientAuth for different reasons are not possible for my certs 13:15
tafkamaxsorry i am late13:15
fprzewozno/13:15
mnasiadkamtls  reviewed13:15
fprzewoznthat was quick 13:15
fprzewozn:P 13:16
mnasiadkaOk then, tafkamax is next13:16
mnasiadkanova-cell upgrade task with nova_safety_upgrade=true13:16
blanson[m]Aetos is the thing that's supposed to allow replacing gnocchi right ?13:16
tafkamaxYes I have a bug report aswell13:16
fprzewoznblanson[m] yes! and also watcher has deprecated prometheus as data source in 2026.1, aetos is the required one (it's just tenant-aware proxy for metrics that expose it via API)13:17
mnasiadkatafkamax: attach the bug report to 100253013:17
tafkamaxhttps://bugs.launchpad.net/kolla-ansible/+bug/216498213:18
tafkamaxwill do13:18
mnasiadkaAnd let’s continue the discussion in Gerrit :)13:18
kkaptanogluhi, https://review.opendev.org/c/openstack/kolla-ansible/+/1000300 I originally opened this as a bugfix because opensearch_address was removed during the 2025.1 to 2026.1 upgrade. the discussion has now expanded into multiple external opensearch support, which is more of a feature request. I’d prefer to keep this change focused on the original bugfix and handle multiple external opensearch support separately. 13:18
opendevreviewTaavi Ansper proposed openstack/kolla-ansible master: Fix upgrade with nova_safety_upgrade  https://review.opendev.org/c/openstack/kolla-ansible/+/100253013:19
tafkamaxLinked it13:19
mnasiadkaI don’t think we really want to support multiple external opensearch13:19
mnasiadkaThe existing broken external opensearch support (and external mariadb support) are not tested at all - and nobody really cares about them13:20
mnasiadkaSo let’s just fix what is broken and leave it be13:20
kkaptanogluI don't want to either :)13:20
kkaptanogluI have already fixed broken variable13:21
ViiHi, I have a couple of really simple fixes - Board13:22
mnasiadkakkaptanoglu: I’ll have a look later this week in your patch13:22
ViiThey’re mostly cleanup and optimization changes.13:22
mnasiadkaVii: we can talk about them next week - please add such things before the meeting.13:22
kkaptanoglumnasiadka: thanks13:22
mnasiadkaI don’t accept changing the meeting agenda during the meeting itself.13:22
Viiok, ty13:23
mnasiadka(I’ll try to review them this or next week anyway - thanks for the list)13:23
mnasiadkaOk then, open discussion13:23
mnasiadka#topic Open discussion13:24
mnasiadkaAnybody anything?13:24
mnasiadkaSeems not13:26
mnasiadkaThanks for coming and see you next week :)13:26
AlmaMC[m]Nop13:26
mnasiadka#endmeeting13:26
opendevmeetMeeting ended Wed Sep 16 13:26:43 2026 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)13:26
opendevmeetMinutes:        https://meetings.opendev.org/meetings/kolla/2026/kolla.2026-09-16-13.01.html13:26
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/kolla/2026/kolla.2026-09-16-13.01.txt13:26
opendevmeetLog:            https://meetings.opendev.org/meetings/kolla/2026/kolla.2026-09-16-13.01.log.html13:26
ravlewthanks 13:26
ViiFYI: VPNaaS is now working. A fix has been implemented in Neutron.13:27
dcapone2004bbezak: set enable_letencrypt to yes instead of true, ran a reconfigure, still getting a 404.  Any more thoughts?13:28
opendevreviewTaavi Ansper proposed openstack/kolla-ansible master: Add safe-upgrade scenario to CI  https://review.opendev.org/c/openstack/kolla-ansible/+/100244913:29
dcapone2004I did notice that despite running reconfigure, none of my containers appear to have restarted. lego container still shows as up 12 hours (from when it last restarted when I was playing with things yesterday)13:29
dcapone2004could it be this?  https://review.opendev.org/c/openstack/kolla/+/100519213:30
tafkamaxIf you are running from master and not 2026.1?13:32
dcapone2004I am running from 2026.113:38
dcapone2004stable13:38
tafkamaxin the container what is the lego version?13:43
dcapone2004hmmm, in the deployed letsencrypt_lego container I have lego is not an accepted command.  The container uses a script letsencrypt-lego-run.sh that calls /usr/bin/letsencrypt-certificates13:51
dcapone2004I assumed this was some type of lego wrapper, but I cannot find a way to get a version number from it13:52
opendevreviewMerged openstack/kayobe master: CI: Enable EPEL only when required  https://review.opendev.org/c/openstack/kayobe/+/100583113:52
dcapone2004I am using ubuntu 24.04 in case OS matters13:53
kkaptanogluVii: yes, VPNaaS is running, but i think there's an issue with the neutron-rpc-server's rabbitmq connection. I'll look this in detail on the neutron side14:02
opendevreviewPierre Riteau proposed openstack/kayobe stable/2026.1: CI: Enable EPEL only when required  https://review.opendev.org/c/openstack/kayobe/+/100588514:04
opendevreviewPierre Riteau proposed openstack/kayobe stable/2025.2: CI: Enable EPEL only when required  https://review.opendev.org/c/openstack/kayobe/+/100588614:06
Viikkaptanoglu: It’s working now. The issue was fixed by this patch in neutron-vpnaas:14:07
Viihttps://github.com/openstack/neutron-vpnaas/commit/2b5a4a674147830d204c505b99b325a2105d5edb14:07
opendevreviewPierre Riteau proposed openstack/kayobe stable/2025.1: CI: Enable EPEL only when required  https://review.opendev.org/c/openstack/kayobe/+/100588714:08
ViiI’m currently testing the upgrade to 2026.1, and VPNaaS works without any issues there.14:08
ViiThe fix hasn’t been backported to 2025.2, so VPNaaS may still not work there. It works fine on 2025.1, which I’m using continuously.14:08
dcapone2004I just updated to latest KA in 2026.1@stable and reran reconfigure, no restart to letsencrypt or HAproxy containers, same errors when running /usr/local/bin/letsencrypt-lego-run.sh14:22
dcapone20042026/09/16 09:21:49 [INFO] [sub.domain.com] invalid authorization: acme: error: 403 :: urn:ietf:params:acme:error:unauthorized :: 1.xxx.xxxx.xxx2: Invalid response from https://sub.domain.com/.well-known/acme-challenge/tpsSQzCBSEZKUV3wqeqA-d8VKt4nleV4ONurMp18Llo: 404 cron: can't lock /var/run/crond.pid, otherpid may be 114: Resource temporarily unavailable14:24
dcapone2004urls and IPs are obviously substituted and scrubbed for posting, the actual output matches what is expected14:24
dcapone2004if anyone has any thoughts, they would be appreciated :-) ... I will likely add a launchpad report if I cannot resolve.  Next step is likely going to be trying to set enable_letsencrypt to no, run reconfigure, rm the letsencrypt containers, and then set back to yes and see what happens.  However, slightly nervous about doing so as I know KA does not exactly cleanly handle disabling services14:28
opendevreviewminwoo seo proposed openstack/kolla master: mariadb: Remove unused replica backup script  https://review.opendev.org/c/openstack/kolla/+/100092814:36
opendevreviewMerged openstack/kolla-ansible master: Drop unset values from kolla_toolbox module_args  https://review.opendev.org/c/openstack/kolla-ansible/+/99849914:39
opendevreviewMerged openstack/kolla-ansible master: prometheus: accept vault-encrypted values in precheck  https://review.opendev.org/c/openstack/kolla-ansible/+/100337714:39
opendevreviewPierre Riteau proposed openstack/kayobe stable/2025.1: CI: Bump kayobe-tox-ansible to one hour  https://review.opendev.org/c/openstack/kayobe/+/100590614:58
dcapone2004ok, problem resolved.  The yes must be explicitly within quotes "yes" for it to properly validate and configure properly right now it seems.  Gave this a shot after reading the report more in depth15:15
opendevreviewMerged openstack/kolla-ansible master: Fix ProxySQL not using backup writer node for reads  https://review.opendev.org/c/openstack/kolla-ansible/+/100513815:40
opendevreviewMerged openstack/kolla-ansible master: Update enable_letsencrypt to boolean validation  https://review.opendev.org/c/openstack/kolla-ansible/+/100220716:47
opendevreviewMerged openstack/kayobe stable/2025.1: CI: Bump kayobe-tox-ansible to one hour  https://review.opendev.org/c/openstack/kayobe/+/100590616:47
opendevreviewBartosz Bezak proposed openstack/kolla-ansible stable/2026.1: Update enable_letsencrypt to boolean validation  https://review.opendev.org/c/openstack/kolla-ansible/+/100593718:57
opendevreviewFranciszek Przewoźny proposed openstack/kolla-ansible stable/2026.1: prometheus: accept vault-encrypted values in precheck  https://review.opendev.org/c/openstack/kolla-ansible/+/100594119:08
opendevreviewFranciszek Przewoźny proposed openstack/kolla-ansible stable/2025.2: prometheus: accept vault-encrypted values in precheck  https://review.opendev.org/c/openstack/kolla-ansible/+/100594219:09
opendevreviewFranciszek Przewoźny proposed openstack/kolla-ansible stable/2025.1: prometheus: accept vault-encrypted values in precheck  https://review.opendev.org/c/openstack/kolla-ansible/+/100594319:10
opendevreviewMohsen Sepandar proposed openstack/kolla-ansible master: Fix gnocchi incoming storage override when redis is enabled  https://review.opendev.org/c/openstack/kolla-ansible/+/100595520:11
opendevreviewRowan Johns proposed openstack/kayobe master: Move package installs into a single script  https://review.opendev.org/c/openstack/kayobe/+/100519420:52
opendevreviewVerification of a change to openstack/kolla stable/2026.1 failed: grafana: install Prometheus datasource plugin  https://review.opendev.org/c/openstack/kolla/+/100587122:16
opendevreviewMerged openstack/kayobe stable/2026.1: CI: Download cirros images instead of using cache  https://review.opendev.org/c/openstack/kayobe/+/100492623:01
opendevreviewMerged openstack/kolla-ansible stable/2026.1: Update enable_letsencrypt to boolean validation  https://review.opendev.org/c/openstack/kolla-ansible/+/100593723:15
opendevreviewMerged openstack/kolla-ansible stable/2026.1: prometheus: accept vault-encrypted values in precheck  https://review.opendev.org/c/openstack/kolla-ansible/+/100594123:16
opendevreviewMerged openstack/kolla-ansible stable/2025.2: prometheus: accept vault-encrypted values in precheck  https://review.opendev.org/c/openstack/kolla-ansible/+/100594223:16
opendevreviewMerged openstack/kolla-ansible stable/2025.1: prometheus: accept vault-encrypted values in precheck  https://review.opendev.org/c/openstack/kolla-ansible/+/100594323:32
blanson[m]for the ealry risers tomorrow :) https://review.opendev.org/c/openstack/kolla-ansible/+/995006 I took over this one to fix the little things that were missing it should be good now 23:41

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!