Thursday, 2026-05-28

opendevreviewThomas Goirand proposed openstack/puppet-openstack-integration master: WIP: support Debian  https://review.opendev.org/c/openstack/puppet-openstack-integration/+/98908508:13
opendevreviewThomas Goirand proposed openstack/puppet-openstack-integration master: WIP: support Debian  https://review.opendev.org/c/openstack/puppet-openstack-integration/+/98908509:00
zigotkajinam: Hi there!09:08
zigoDo you think that's ok to do this? https://review.opendev.org/c/openstack/puppet-openstack-integration/+/989085/15/manifests/ssl_key.pp09:08
tkajinamit's a bit confusing that cacert is also managed by ssl_key but it might be over-engineering to implementing a separate class for it09:28
opendevreviewTakashi Kajinami proposed openstack/puppet-openstack-integration master: wip: Add Debian Trixie jobs  https://review.opendev.org/c/openstack/puppet-openstack-integration/+/98419509:29
opendevreviewTakashi Kajinami proposed openstack/puppet-openstack-integration master: DNM: Use standalone keystone in Debian  https://review.opendev.org/c/openstack/puppet-openstack-integration/+/98441809:29
zigotkajinam: Well, ssl_key already manages the key, why can't it also manage the cert? They go together, no?09:30
opendevreviewThomas Goirand proposed openstack/puppet-openstack-integration master: WIP: support Debian  https://review.opendev.org/c/openstack/puppet-openstack-integration/+/98908509:31
tkajinamzigo, it's not cert but cacert and we already have openstack_integration::cacert .09:32
tkajinammy point is that cacert is now handled both by ::cacert and ::ssl_key which may be a bit confusing09:32
zigoOh, but then is there a cert somewhere?!?09:32
zigoI got confused between cacert and ssl cert, indeed.09:33
tkajinamhmm wait09:34
tkajinamwe might be doing something wrong here 09:34
tkajinamhmm ok so we are using cert as cacert ...09:36
tkajinamI'll take a look later09:38
zigotkajinam: Please let me know, in the mean time, I'll try like the above.09:49
zigoRight now, I can see keystone runs with:09:50
zigo--https-socket [::]:5000,/usr/local/share/ca-certificates/puppet_openstack.crt,/etc/keystone/ssl/private/poi.debian.net.pem09:50
zigoI don't even understand how that's done, as the init script doesn't do that.09:50
opendevreviewThomas Goirand proposed openstack/puppet-openstack-integration master: WIP: support Debian  https://review.opendev.org/c/openstack/puppet-openstack-integration/+/98908510:29
zigoI have 2 remaining issues (at least):10:34
zigo- Something stops neutron-api during the run, and it's not restarted before the validation that does a network list.10:34
zigo- Glance cannot be setup with SSL, because in Debian, it still uses /usr/bin/glance-api without uwsgi, because backups are otherwise broken. In production, I fixed that by using re-encryption with haproxy.10:34
zigoI currently have no clue how to fix these, but will search.10:34
zigoOh, for neutron, the issue may be:10:37
zigoapi_service_name10:37
zigothat wasn't set correctly.10:37
opendevreviewThomas Goirand proposed openstack/puppet-openstack-integration master: WIP: support Debian  https://review.opendev.org/c/openstack/puppet-openstack-integration/+/98908510:41
zigoThis last one maybe fixes the 2 issues.10:41
tkajinamcan you just start without ssl ?10:46
zigoYeah, that's what my last patch does.10:47
zigoI'm trying this in a VM in virtualbox, so it's easier to debug.10:47
opendevreviewThomas Goirand proposed openstack/puppet-openstack-integration master: WIP: support Debian  https://review.opendev.org/c/openstack/puppet-openstack-integration/+/98908510:53
opendevreviewThomas Goirand proposed openstack/puppet-openstack-integration master: WIP: support Debian  https://review.opendev.org/c/openstack/puppet-openstack-integration/+/98908511:59
*** amoralej__ is now known as amoralej12:00
opendevreviewThomas Goirand proposed openstack/puppet-openstack-integration master: WIP: support Debian  https://review.opendev.org/c/openstack/puppet-openstack-integration/+/98908512:02
opendevreviewThomas Goirand proposed openstack/puppet-openstack-integration master: WIP: support Debian  https://review.opendev.org/c/openstack/puppet-openstack-integration/+/98908512:24
opendevreviewThomas Goirand proposed openstack/puppet-watcher master: Add UWSGI support for Debian  https://review.opendev.org/c/openstack/puppet-watcher/+/99031112:31
opendevreviewTakashi Kajinami proposed openstack/puppet-heat master: Remove parameters for dedicated heat-cfn keystone user  https://review.opendev.org/c/openstack/puppet-heat/+/99050615:10
opendevreviewTakashi Kajinami proposed openstack/puppet-ironic master: Clean up parameters for inspector inspect interface  https://review.opendev.org/c/openstack/puppet-ironic/+/99050815:12
opendevreviewTakashi Kajinami proposed openstack/puppet-magnum master: Clean up deprecated domain_id parameters  https://review.opendev.org/c/openstack/puppet-magnum/+/99051115:15
opendevreviewTakashi Kajinami proposed openstack/puppet-watcher master: Clean up support for glance_client/neutron_client options  https://review.opendev.org/c/openstack/puppet-watcher/+/99051415:18
opendevreviewTakashi Kajinami proposed openstack/puppet-ironic master: Clean up parameters for inspector inspect interface  https://review.opendev.org/c/openstack/puppet-ironic/+/99050823:32

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!