Monday, 2026-01-12

ttxOK I'll have a look this morning09:02
ttxok old key disabled and new key generated and uploaded on GitHub. Looking into updating the secret now10:00
ttxNot sure which tenant / project I'm supposed to include in the zuul-client encrypt command, so I'll wait for guidance10:06
fricklerttx: you use tenant "openstack" and the project is the repo in which the secret file is located, "openstack/project-config" in this case10:11
ttxfrickler: ok, thanks! Also in the patch where you set all secrets to "dummy", for openstack-mirroring you set two dummy values: one for the ssh_key (which I'm about to update) and one for a "api_token" which was not there before. Can I just remove that one in the updating patch?10:15
fricklerttx: the api_token was added by you in https://review.opendev.org/c/openstack/project-config/+/738228 ? iiuc that would need to be regenerated, too?10:18
ttxah... now I need to remember how this all works :)10:20
ttxprobably need to rotate that token as well10:21
ttxAlright, submitted10:43
fricklermerged and working, see e.g. https://zuul.opendev.org/t/openstack/build/e942db0dfb7e49cba64d3f896dba7c3a, thx ttx11:38
ttx\o/11:44
fricklernow I need to check what else is missing before we can create a test release again11:46
fungiwe still need https://review.opendev.org/973029 so the release bot can push tags14:15
fungii was planning to follow up and coordinate a test release once that merges14:15
fungibut i guess i didn't communicate that clearly14:16
fungii'll just self-approve it to get that going14:16
fungiokay, that's merged, so should be able to test again?14:29
fricklerwe have https://review.opendev.org/c/openstack/releases/+/972859 prepared, so let me review and approve14:43
opendevreviewMerged openstack/releases master: Test release with release-test 8.3.0  https://review.opendev.org/c/openstack/releases/+/97285914:56
elodillessomething is not correct yet :S  https://zuul.opendev.org/t/openstack/build/3fa6961cff25471982b3e42a584b7e9f15:20
fricklerthat looks like an issue with the pypi token I encrypted earlier :(15:30
clarkbfrickler: ttx  I suspect api_token is for creating new repos and then the ssh key is for pushing to them15:47
ttxclarkb: indeed16:12
clarkbwe have a similar setup for quay.io container repo management16:13
clarkbthe pypi secret has been updated with a suspected fix. Do we have a new release-test test or do we reenqueue the last one?17:41
fricklerI was thinking to reenqueue https://zuul.opendev.org/t/openstack/buildset/4f87cc7c63554f38a1dbfb8ad26f90e6, rerunning the github mirror should not hurt18:00

Generated by irclog2html.py 4.0.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!