Tuesday, 2021-03-16

openstackgerritMerged openstack/nova master: libvirt: Add guest generation for vDPA  https://review.opendev.org/c/openstack/nova/+/77053200:03
openstackgerritVlad Gusev proposed openstack/nova stable/stein: Use subqueryload() instead of joinedload() for (system_)metadata  https://review.opendev.org/c/openstack/nova/+/76181200:13
brinzhangbauzas, gibi: hope we can continue to discuss the question with add accel_uuids in periodic task (_poll_shelved_instances) while you are all online, thanks00:47
*** mlavalle has quit IRC01:43
*** whoami-rajat_ has joined #openstack-nova03:24
*** mkrai has joined #openstack-nova03:55
*** ratailor has joined #openstack-nova04:33
*** vishalmanchanda has joined #openstack-nova04:33
openstackgerritWenping Song proposed openstack/nova-specs master: Trival change: correct some nits  https://review.opendev.org/c/openstack/nova-specs/+/78044306:31
*** whoami-rajat_ is now known as whoami-rajat07:09
*** ignaziocassano has joined #openstack-nova07:18
ignaziocassano: hello All, please any help on live migration on queens ? when I migrate the vm crash on destination node
ignaziocassanoIgnazio Cassano <ignaziocassano@gmail.com>07:20
ignaziocassanolun 15 mar, 18:59 (13 ore fa)07:20
ignaziocassanoa openstack-discuss07:20
ignaziocassanolooking at destination kvm host I got the following in instance log under /var/log/libvirt/qemu:07:20
ignaziocassano2021-03-15 11:48:31.996+0000: starting up libvirt version: 4.5.0, package: 36.el7_9.3 (CentOS BuildSystem <http://bugs.centos.org>, 2020-11-16-16:25:20, x86-01.bsys.centos.org), qemu version: 2.12.0qemu-kvm-ev-2.12.0-44.1.el7_8.1, kernel: 3.10.0-1160.15.2.el7.x86_64, hostname: podto2-kvmae07:20
ignaziocassanoLC_ALL=C \07:20
ignaziocassanoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin \07:20
ignaziocassanoQEMU_AUDIO_DRV=none \07:20
ignaziocassano-name guest=instance-00002a52,debug-threads=on \07:20
ignaziocassano-S \07:20
ignaziocassano-object secret,id=masterKey0,format=raw,file=/var/lib/libvirt/qemu/domain-73-instance-00002a52/master-key.aes \07:20
ignaziocassano-machine pc-i440fx-rhel7.6.0,accel=kvm,usb=off,dump-guest-core=off \07:20
ignaziocassano-cpu Broadwell-IBRS,vme=on,f16c=on,rdrand=on,hypervisor=on,arat=on,xsaveopt=on,abm=on \07:20
ignaziocassano-m 4096 \07:20
ignaziocassano-realtime mlock=off \07:20
ignaziocassano-smp 2,sockets=2,cores=1,threads=1 \07:20
ignaziocassano-uuid c6ea7ed2-e7ce-4df6-a767-6bb95ae8fdc6 \07:20
ignaziocassano-smbios 'type=1,manufacturer=RDO,product=OpenStack Compute,version=17.0.11-1.el7,serial=3dec30fe-a31f-4ea6-971f-6f993589ef04,uuid=c6ea7ed2-e7ce-4df6-a767-6bb95ae8fdc6,family=Virtual Machine' \07:20
ignaziocassano-no-user-config \07:20
ignaziocassano-vnc \07:21
ignaziocassano-k en-us \07:21
ignaziocassano-device cirrus-vga,id=video0,bus=pci.0,addr=0x2 \07:21
ignaziocassano-incoming defer \07:21
ignaziocassano-device virtio-balloon-pci,id=balloon0,bus=pci.0,addr=0x6 \07:21
ignaziocassano-sandbox on,obsolete=deny,elevateprivileges=deny,spawn=deny,resourcecontrol=deny \07:21
ignaziocassano-msg timestamp=on07:21
ignaziocassano2021-03-15 11:48:31.996+0000: Domain id=73 is tainted: high-privileges07:21
ignaziocassano2021-03-15T11:48:32.163025Z qemu-kvm: -chardev pty,id=charserial0,logfile=/dev/fdset/3,logappend=on: char device redirected to /dev/pts/57 (label charserial0)07:21
ignaziocassano2021-03-15T11:48:32.167206Z qemu-kvm: -drive file=/var/lib/nova/mnt/7eb4b0178ee3ec9ad7cbbc20c62b1912/volume-d5c812c5-2c27-4e82-a38d-83fc79ab848e,format=raw,if=none,id=drive-virtio-disk0,serial=d5c812c5-2c27-4e82-a38d-83fc79ab848e,cache=none,aio=native: 'serial' is deprecated, please use the corresponding option of '-device' instead07:21
ignaziocassano2021-03-15T11:48:37.779611Z qemu-kvm: Failed to load virtio_pci/modern_queue_state:desc07:21
ignaziocassano2021-03-15T11:48:37.780020Z qemu-kvm: Failed to load virtio_pci/modern_state:vqs07:21
ignaziocassano2021-03-15T11:48:37.780042Z qemu-kvm: Failed to load virtio/extra_state:extra_state07:21
ignaziocassano2021-03-15T11:48:37.780062Z qemu-kvm: Failed to load virtio-balloon:virtio07:21
ignaziocassano2021-03-15T11:48:37.780082Z qemu-kvm: error while loading state for instance 0x0 of device '0000:00:06.0/virtio-balloon'07:21
ignaziocassano2021-03-15T11:48:37.781465Z qemu-kvm: load of migration failed: Input/output error07:21
ignaziocassano2021-03-15 11:48:38.231+0000: shutting down, reason=crashed07:21
ignaziocassano"instance-00002a52.log" 102L, 7122C07:21
gibibrinzhang_: sorry, I was mostly off yesterday07:52
brinzhang_gibi: np^07:52
brinzhang_please review firstly, Ihave a meeting, after end this meeting I will back, thanks07:53
gibibrinzhang_, bauzas: replyied in https://review.opendev.org/c/openstack/nova/+/77844008:33
gibiI will have to go offline again, sorry, I will be available during the day08:33
bauzasgibi: brinzhang_: sorry, a bit not paying attention to the IRC chan as I'm trying to update the RPC API08:34
bauzasgibi: np08:34
brinzhang_gibi, bauzas: np, I will review your reply comments, thanks08:39
*** brinzhang0 has joined #openstack-nova09:12
hemanth_nsean-k-mooney stephenfin: can i get some reviews on old backport patch https://review.opendev.org/c/openstack/nova/+/761824 when you have time, thanks10:07
lyarwoodbauzas / melwitt ; https://review.opendev.org/q/b9333125790682f9d60bc74fdbb12a098565e7c2 - really simple backports if you have time this week10:48
lyarwoodah nvm I forgot to include another change so that's borked after victoria10:52
* lyarwood fixes10:52
openstackgerritLee Yarwood proposed openstack/nova stable/ussuri: Use absolute path during qemu img rebase  https://review.opendev.org/c/openstack/nova/+/75708310:54
openstackgerritLee Yarwood proposed openstack/nova stable/ussuri: Make _rebase_with_qemu_img() generic  https://review.opendev.org/c/openstack/nova/+/78078010:54
openstackgerritLee Yarwood proposed openstack/nova stable/train: Use absolute path during qemu img rebase  https://review.opendev.org/c/openstack/nova/+/75708411:00
openstackgerritLee Yarwood proposed openstack/nova stable/train: Make _rebase_with_qemu_img() generic  https://review.opendev.org/c/openstack/nova/+/78078211:00
openstackgerritLee Yarwood proposed openstack/nova stable/stein: Use absolute path during qemu img rebase  https://review.opendev.org/c/openstack/nova/+/75708511:01
openstackgerritLee Yarwood proposed openstack/nova stable/stein: Make _rebase_with_qemu_img() generic  https://review.opendev.org/c/openstack/nova/+/78078411:01
openstackgerritMerged openstack/nova master: libvirt: Wire up 'os_secure_boot' property  https://review.opendev.org/c/openstack/nova/+/77668111:47
openstackgerritMerged openstack/nova master: libvirt: Report secure boot support to scheduler  https://review.opendev.org/c/openstack/nova/+/77569011:48
openstackgerritMerged openstack/nova master: tests: Add functional tests for UEFI, secure boot  https://review.opendev.org/c/openstack/nova/+/77668211:48
openstackgerritMerged openstack/nova master: tests: Remove duplicated 'start_compute' helper  https://review.opendev.org/c/openstack/nova/+/77668311:49
hkominosHi guys. Can i please ask a quick question regarding an exception that I am facing in my deployment? I believe the input from a developer would be more helpful for me than asking in the openstack channel11:51
*** ratailor has joined #openstack-nova11:51
k-s-deanhkominos, ask away. someone might be see it later. If i can answer you I will.11:52
hkominosk-s-dean Hi!. What do you make of this : https://paste.centos.org/view/741688bb11:52
k-s-deanhkominos, are you running cyborg ?11:54
hkominosThis appeared after a host was rebooted with some Vms on it11:54
*** ratailor_ has joined #openstack-nova11:54
hkominoswhich now refuse to come up11:54
k-s-deanwhats the underlying hardware11:55
hkominosyes. https://paste.centos.org/view/73064e38. But before I start looking for hardware vendors  I want to understand the problem. I think the issues probably more into nova placement but Idk. that is why I asked here.12:01
k-s-deanhkominos, has this machine got a graphics card in it ?12:04
k-s-deanHas the graphics card failed ?12:04
hkominoslets double check12:05
hkominosdoes not look like it.12:08
k-s-deanany reason why you have  15 instances in the placement database and 10 instances on the hypervisor.12:10
k-s-deancan you run virsh list --all on the host ?12:10
gibikashyap: I guess https://review.opendev.org/c/openstack/nova/+/682627 is not a mandatory part of the secure boot feature for W12:28
*** tbachman has quit IRC12:28
gibiam I correct?12:28
* kashyap clicks12:28
gibithe rest of the secure boot series landed12:28
kashyapgibi: Cool; just see it in the scrollback.  So that auto-detect can come later -- unfortunately, a bug in libvirt blocking that :-(12:29
kashyapgibi: Thank you.  And stephenfin, particularly12:30
gibistephenfin: will you resolve the merge conflict in the vdpa series?12:33
stephenfinworking on it atm12:33
openstackgerritLee Yarwood proposed openstack/nova stable/train: Make _rebase_with_qemu_img() generic  https://review.opendev.org/c/openstack/nova/+/78078212:57
openstackgerritLee Yarwood proposed openstack/nova stable/train: Use absolute path during qemu img rebase  https://review.opendev.org/c/openstack/nova/+/75708412:57
gibiis there anything that I should review now?13:38
hkominosk-s-dean virsh list all shows (or did show 10) VMs13:49
hkominosnow why  placement thought 15 Is because it had some garbage VMs that did not spawn on this node.13:49
k-s-deanThose should have been cleaned up.13:50
hkominosWill do13:51
stephenfingibi: I'm reworking Sean's "block unsupported ops with vDPA interface" patch to return HTTP 409 (Conflict) instead of HTTP (Forbidden) since that seems more sensible. It's not a permissions or access issue, IMO. Do you agree?14:10
Luzihey, is someone around who knows the qemu native tls config options? I think i might have found a bug in the guide: https://docs.openstack.org/nova/latest/admin/secure-live-migration-with-qemu-native-tls.html14:31
kashyapLuzi: Hi, I think I wrote that doc :)14:34
kashyapLuzi: What's the bug?  Feel free to amend / send a pull-req :)14:35
kashyapAt the bottom right, there is also "found an error? report a bug"14:36
Luzii followed that guide but got to a point when openstack did not use the tls path, but kept using the tcp path14:36
Luzii onlny found out because i used tcpdump on both ports14:36
kashyapLuzi: Hmm, if you followed that guide to the word, then your setup should definitely be using the QEMU-native TLS14:37
Luzii was looking through code and found out, that the uri used for live migration is different from the connection uri and uses a config option not mentioned in the guide14:38
kashyapLuzi: Hmm, possible the guide got slightly outdated ... as migration-related code got reworked14:39
Luzionly after i set live_migration_scheme = tls14:39
Luzithe traffic was encrypted14:39
Luziand using the correct port :)14:39
kashyapLuzi: I see.  That's correct _scheme is favoured14:41
kashyapAnd _uri parameter is deprecated in favor of the above14:41
Luzibut when you don't set it, as i had not done it, the code uses the hardcoded tcp parameter14:41
fungilooks like that config option was added by https://review.openstack.org/410817 which merged in early 201714:41
kashyapfungi: Heya; yep.  That timeframe is right ... /me clicks14:42
kashyapYep; patch is also correct.14:42
Luzilive_migration_scheme = tls14:42
fungifirst appeared in nova 15.0.0, so ocata and later14:42
kashyapLuzi: Also you don't tell what version of OpenStack you were using?14:42
kashyapYeah, what fungi says.14:43
openstackgerritStephen Finucane proposed openstack/nova master: pci: Add vDPA vnic to PCI request mapping and filtering  https://review.opendev.org/c/openstack/nova/+/77835014:43
openstackgerritStephen Finucane proposed openstack/nova master: api: Block unsupported actions with vDPA  https://review.opendev.org/c/openstack/nova/+/78033314:43
openstackgerritStephen Finucane proposed openstack/nova master: tests: Add functional test for vDPA device  https://review.opendev.org/c/openstack/nova/+/78011214:43
openstackgerritStephen Finucane proposed openstack/nova master: WIP: tests: Make mdev stubs work like vDPA  https://review.opendev.org/c/openstack/nova/+/78023414:43
openstackgerritStephen Finucane proposed openstack/nova master: Add release note for vDPA  https://review.opendev.org/c/openstack/nova/+/78086614:43
stephenfingibi: lyarwood: ^14:43
Luzii am working on train and looking to upgrade soon14:43
Luzii posted the line of code which seems to be still on master14:44
fungisame change deprecated live_migration_uri14:45
*** sapd1 has joined #openstack-nova14:45
Luziin the guide the only config option which is mentioned is live_migration_with_native_tls = true14:46
Luziwhich is definitely not enough to enable native tls14:46
kashyapLuzi: So, indeed - it checks if the config option is set, then uses the _scheme, if not defaults to TLS14:46
fungiso alternatively, the document could warn that setting the _scheme will prevent a natural fallback to tls14:47
Luziwell i thought it worked, until i started tcpdump14:47
Luzithe default in code is tcp14:47
kashyapLuzi: Err, defaults to TCP, I mean, I'm sorry.14:48
Luzithe guid should at least say it is needed to set the _scheme to tls14:48
fungiayup, i agree it defaults to 'tcp' there14:48
kashyapLuzi: Right; I'll check the installer code to double-confirm; and then can update the doc14:49
fungiokay, so the doc just needs updating to mention setting live_migration_scheme="tls"?14:49
Luzii'm just worried, that this may also concern some users which did not check their deployment with a tcpdump :D14:49
fungiit got mentioned in the release notes (under features) but yeah that's fairly hidden14:49
Luziit should be enough, to update the guide, i think14:50
fungiand even the release note doesn't come out and say it's needed for turning on tls14:50
Luzifungi, yeah thats the point14:50
Luzii needed a whole day to find out :D14:51
kashyapfungi: Yep - on the doc needs updating.  Luzi: Good catch!14:51
fungiLuzi: if you're worried that we need to do some outreach, the typical process for that is an openstack security note: https://wiki.openstack.org/wiki/Security/Security_Note_Process14:51
Luzii need to go off now, thank you for replying so quickly kashyap and fungi :)14:52
kashyapLuzi: So you need _both_:14:52
kashyap - live_migration_scheme14:52
fungionce published, we can send a copy to the openstack-announce and openstack-discuss mailing lists14:52
kashyap - live_migration_with_native_tls14:52
Luzifungi, i will do that when i'm at home :)14:52
Luzikashyap, yes14:52
*** Luzi has quit IRC14:53
*** macz_ has joined #openstack-nova14:54
kashyap(Ah, Luzi is gone before I wanted to mention a way to actually verify how to check native TLS is in effect for disks during migration w/ low-level logs.)14:54
lyarwoodstephenfin: https://review.opendev.org/c/openstack/nova/+/780333 - quick commit message nit in there but otherwise LGTM15:03
openstackgerritStephen Finucane proposed openstack/nova master: api: Block unsupported actions with vDPA  https://review.opendev.org/c/openstack/nova/+/78033315:07
openstackgerritStephen Finucane proposed openstack/nova master: tests: Add functional test for vDPA device  https://review.opendev.org/c/openstack/nova/+/78011215:07
openstackgerritStephen Finucane proposed openstack/nova master: Add release note for vDPA  https://review.opendev.org/c/openstack/nova/+/78086615:07
openstackgerritStephen Finucane proposed openstack/nova master: WIP: tests: Make mdev stubs work like vDPA  https://review.opendev.org/c/openstack/nova/+/78023415:07
lyarwoodstephenfin: https://review.opendev.org/c/openstack/nova/+/780866 - same in the releasenote btw15:17
stephenfingdi :)15:17
stephenfinwill fix15:17
lyarwoodnp my review ratio thanks you ;)15:18
lyarwoodjoys of being a stable core15:18
gibistephenfin: ack, I have no problem with 409, and I will review the series soon15:21
openstackgerritKashyap Chamarthy proposed openstack/nova master: libvirt: Deprecate `live_migration_tunnelled`  https://review.opendev.org/c/openstack/nova/+/78090815:52
kashyapgibi: stephenfin: Would be nice to get it going in Wallaby --^.  Will reduce some future "live migration config fatigue"15:54
gibikashyap: ack, I will check after the vdpa series15:55
kashyapSure; no prob.  It's just a deprecation meta-work; that's all.15:55
kashyapI'll add a code-reference in the change comment15:55
lyarwoodkashyap: random question, do we have coverage of live_migration_with_native_tls in the gate somewhere?15:58
lyarwoodkashyap: I can't find anything but that smells like something we should enable in nova-next at least15:59
kashyaplyarwood: Good question, I do not know; and near as I know, no.  It requires a full TLS env to be setup -- which is what TripleO does15:59
kashyapSee my prerequisite here: https://docs.openstack.org/nova/latest/admin/secure-live-migration-with-qemu-native-tls.html#prerequisites15:59
kashyaplyarwood: I swear there is some automated test of this upstream (perhaps the upstream whitebox from OSP QE folks), can't find a link yet16:00
lyarwoodkashyap: yeah it's likely on the TripleO side and sorry I thought the virt tools would automate the CA creation etc, if not ignore me as it's going to be too much work to enable in devstack for nova-next etc16:01
kashyaplyarwood: Yeah, it requires good old PKI setup. It _can_ be automated, using GnuTLS16:01
kashyaplyarwood: If you don't mind holding your nose, something like ... https://kashyapc.fedorapeople.org/Auto-Setup-GnuTLS/Setup-GnuTLS-CA-and-ServerCert.bash16:02
lyarwoodthat said we do have some novnc tls stuff in devstack so...16:02
kashyapI see16:03
*** vishalmanchanda has quit IRC16:03
kashyapBut pretty sure I recall chatting w/ TripleO folks to have an automated test.  Once I find a URL, I'll link it in the change or post here16:03
gibibauzas: ack, have a nice celebration!16:32
gibibauzas: will you push a new rev from the rpc bump patch before you leave?16:33
bauzasgibi: not sure :(16:34
bauzasstill fixing to not support 5.016:34
gibibauzas: no worries just preparing my review queue16:36
Luzikashyap, are you around?16:39
kashyapLuzi: Hi, yes16:39
kashyapLuzi: So, I wanted to mention one more to thing to you, before you left16:39
kashyapLuzi: If you want to see native TLS is *actually* in effect, you can verify it by a slightly tedious method in logs16:40
kashyapLuzi: Is your env. production?  Or do you have a staging setup?16:40
Luzitesting setup16:40
kashyapLuzi: Perfect.  So here we go:16:41
kashyapLuzi: What OS do you have?  Ubuntu or Fedora?  Doesn't matter: install the "libvirt-admin" tool16:41
kashyapTo get the 'virt-admin' tool.  Note: Ubuntu might name it differently.  So "grep" your package repository for the tool.  In Fedora, I can do it like this: `dnf whatprovides *virt-admin`16:43
kashyapLuzi: Then follow this to enable the dynamic libvirt log filters on your compute nodes: https://kashyapc.fedorapeople.org/virt/virt-admin.txt16:43
kashyapOnce you have that setup; you can migrate a guest, and then you can look for: `grep tls-creds-x509` on your source and destination libvirtd.log.16:45
kashyapLuzi: Did you hav a different question for me?  I began talking right after you pinged me :)16:45
*** Luzi_ has joined #openstack-nova16:46
*** Luzi has quit IRC16:46
Luzi_here again, needed to change to vpn16:46
Luzi_i missed the last 6 minutes or so - did you wrote something kashyap ?16:47
kashyapLuzi_: Yes, I did post something.  I was talking to myself.  Let me post a pastebin16:47
kashyapLuzi_: http://paste.openstack.org/show/803621/16:48
*** hamalq has joined #openstack-nova16:48
kashyapLuzi_: For comparison, you should see commands like these in your _destination_ libvirt log file: https://kashyapc.fedorapeople.org/Native-TLS/Test-Evidence/DEST-QMP-commands-TLS-over-NBD-guestHyp2.log16:50
kashyapLuzi_: I need to head out shortly.  If you have a question, ask now :-)  (Assuming you're not disconnected again.)16:54
Luzi_okay, it seems i adjusted the log level, I will now migrate with and without the config option set16:54
Luzi_i would still open a bug and display the commands i used to catch the traffic with - for both ways17:02
*** ociuhandu_ has quit IRC17:03
*** tesseract has quit IRC17:04
gibikashyap: Im +2 on the deprecation of the tunneled live migration patch17:05
kashyapLuzi_: Strange, do you already have the config settings manually done in /etc/libvirt/libvirtd.conf?17:06
kashyapLuzi_: Check if you have these two configs set in your /etc/libvirt/libvirtd.conf:17:07
kashyap  - log_filters17:07
openstackgerritSylvain Bauza proposed openstack/nova master: Bump the Compute RPC API to version 6.0  https://review.opendev.org/c/openstack/nova/+/76145217:07
kashyap  - log_outputs17:07
kashyapgibi: Thank you!17:07
bauzasgibi: I eventually gave up given the time, and I just fixed dansmith's nits17:08
bauzasdansmith: gibiI'll try to still work on no longer supporting 5.0 on Thursday17:08
kashyapLuzi_: I need to head out for a walk, but feel free to gather your thoughts in a file.17:08
kashyap(And email here, or post them in a non-expiring pastebin somewhere.  I'll come back and check.)17:10
kashyapLuzi_: In short, use either manual approach or the dynamic filters.  See the "Gathering libvirt logs..." section here: https://kashyapc.fedorapeople.org/virt/openstack/request-nova-libvirt-qemu-debug-logs.txt17:13
Luzi_I need to head out too, so I just complete the bug report and maybe add some more tomorrow17:15
gibibauzas: ack, I will review what you pushed17:20
gibibauzas: have a nice PTO tomorrow17:20
*** READ10 has quit IRC17:59
*** whoami-rajat has quit IRC19:26
openstackgerritStephen Finucane proposed openstack/nova master: libvirt: Delegate OVS plug to os-vif  https://review.opendev.org/c/openstack/nova/+/60243219:41
melwittgmann: hey, wondering if you have seen this tempest-slow-py3 gate failure before ""tempest.scenario.test_network_v6.TestGettingAddress Bad router request: Cidr 2001:db8::/64 of subnet f3908f8d-a960-444f-9708-78ae906fbd63 overlaps with cidr 2001:db8::/64 of subnet d8fe1d15-5cdd-40e1-96e5-d1ac105253c3" I only see it on stable/stein in nova19:55
openstackgerritStephen Finucane proposed openstack/nova master: pci: Add vDPA vnic to PCI request mapping and filtering  https://review.opendev.org/c/openstack/nova/+/77835020:39
openstackgerritStephen Finucane proposed openstack/nova master: api: Block unsupported actions with vDPA  https://review.opendev.org/c/openstack/nova/+/78033320:39
openstackgerritStephen Finucane proposed openstack/nova master: tests: Add functional test for vDPA device  https://review.opendev.org/c/openstack/nova/+/78011220:39
openstackgerritStephen Finucane proposed openstack/nova master: Add release note for vDPA  https://review.opendev.org/c/openstack/nova/+/78086620:39
openstackgerritMerged openstack/nova master: libvirt: Deprecate `live_migration_tunnelled`  https://review.opendev.org/c/openstack/nova/+/78090821:13
*** Techy2493 has joined #openstack-nova21:43
spotzIs there a maximum number of security groups you cane have? Not talking about quota restricted22:21
melwittspotz: security groups will be a question for the neutron team, nova hasn't done them since the olden days of nova-network22:37
spotzhaha thanks melwitt!22:37
*** gyee has quit IRC22:40
openstackgerritmelanie witt proposed openstack/nova stable/stein: [stable-only] Specify IPv6 CIDR in tempest-slow-py3  https://review.opendev.org/c/openstack/nova/+/78099122:47
