Monday, 2022-05-09

opendevreviewMerged openstack/tripleo-ansible stable/wallaby: Add ansible_playbook to support NFV deployment during "overcloud node provision" command
*** ysandeep|out is now known as ysandeep|rover04:58
opendevreviewMerged openstack/diskimage-builder master: Ensure cloud-init is configured to generated host keys
opendevreviewSandeep Yadav proposed openstack/tripleo-quickstart-extras master: Add diskimage-builder in artg_branchless_projects
opendevreviewSandeep Yadav proposed openstack/tripleo-quickstart-extras master: Add diskimage-builder in artg_branchless_projects
opendevreviewSandeep Yadav proposed openstack/diskimage-builder master: [DNM] test patch
*** soniya29 is now known as soniya29|ruck06:13
opendevreviewCedric Jeanneret proposed openstack/tripleo-common master: Add cloud-init element
*** soniya29 is now known as soniya29|ruck06:58
*** soniya29 is now known as soniya29|ruck07:19
*** ysandeep|rover is now known as ysandeep|rover|lunch07:20
*** jpena|off is now known as jpena07:30
*** soniya29 is now known as soniya29|ruck07:38
*** soniya29|ruck is now known as soniya29|ruck|lunch07:57
opendevreviewMarios Andreou proposed openstack/tripleo-ci master: Remove centos-7 job definitions and zuul layouts
opendevreviewMarios Andreou proposed openstack/tripleo-ansible stable/train: [train only] Remove centos-7 content provider from zuul layout
opendevreviewMarios Andreou proposed openstack/tripleo-ci master: Remove centos-7 job definitions and zuul layouts
opendevreviewMarios Andreou proposed openstack/tripleo-heat-templates stable/train: [train only] Remove centos-7 content provider from zuul layout
opendevreviewMarios Andreou proposed openstack/tripleo-ci master: Remove centos-7 job definitions and zuul layouts
*** soniya29|ruck|lunch is now known as soniya29|ruck08:23
*** ysandeep|rover|lunch is now known as ysandeep|rover08:23
opendevreviewFrancesco Pantano proposed openstack/tripleo-ansible master: Normalize the server_addr dashboard backend
Tenguslaweq: heya! Sooo. the testproject injecting just the policy without the chain is showing the issue is, indeed, in the fact the "drop" rule we have now is missing some packages:
Tenguslaweq: failed on the ping. So my take here is: let's find the "state" of those weird packages we're missing, analyse it, and see what's going on. We're also missing them in the actual log since we're logging only NEW things.09:40
Tenguand it's a security issue in the end. To some extends. woohooo.09:41
opendevreviewFrancesco Pantano proposed openstack/tripleo-ansible master: Normalize the server_addr dashboard backend
opendevreviewPooja Jadhav proposed openstack/tripleo-ci master: Ussuri tear down as EOL
*** rlandy|out is now known as rlandy10:24
opendevreviewFrancesco Pantano proposed openstack/tripleo-heat-templates master: Do not deploy ceph-nfs during the overcloud deploy
slaweqTengu: yeah, so tbh I think that currently it works fine just because we have ACCEPT as default policy, nothing else10:29
slaweqother rules aren't matched in that traffic to the router's gateway10:29
slaweqso this isn't really issue with Your patch but issue which Your patch shown us10:30
slaweqTengu: I'm deploying it now on my lab and will try to reproduce the issue to work on it without need to hold CI nodes10:35
slaweqCan You maybe open bug for that for Networking DFG?10:36
opendevreviewMerged openstack/tripleo-ansible master: ReaR needs specific configuration in RHEL9 with LVM
*** dviroel_ is now known as dviroel\11:14
*** dviroel\ is now known as dviroel11:14
Tenguslaweq: I can. on launchpad, or on rh bugzilla?11:20
Tenguslaweq: I'm getting an env without the patch up right now (it crashed before my lunch break for unrelated reason). I'll also play a bit with nftables in order to understand it better. But I have the feeling we won't be able to solve the issue using the iptables-nft wrapper, unfortunately.11:22
Tenguseems too deep.11:23
Tenguslaweq:  lemme know if you want me to copy this one in rh bugzilla.11:40
Tengufeel free to comment with your own observations.11:40
*** ysandeep|rover is now known as ysandeep|rover|break11:57
opendevreviewCedric Jeanneret proposed openstack/tripleo-heat-templates master: Manage the masquerade rules via ansible instead of puppet
slaweqTengu: thx, that should be enough12:16
Tenguslaweq: ok. I'll play a bit with nftables once I get my OC.12:16
Tenguguess it will require some arp things. it's an unpatched env, but I can emulate the issue while switching the chain policy.12:16
Tenguand, probably, adding and dropping router so that its MAC and IP change.12:16
slaweqhi tripleo stable cores, can someone check and approve ? It already have 2x +2, maybe someone can approve it?12:17
Tengushouldn't be THAT hard.12:17
slaweqthx in advanc12:17
Tenguslaweq: #done.12:18
slaweqTengu: thx a lot12:18
Tenguthough... ownership may be better in some conditions.12:18
Tengubut it would be harder to set the correct group.12:18
Tenguanywy. it's in gate now.12:18
*** pojadhav is now known as pojadhav|break12:22
opendevreviewMerged openstack/tripleo-heat-templates stable/victoria: Remove sidecar containers after SIGTERM is send to stop them
opendevreviewBrendan Shephard proposed openstack/tripleo-heat-templates stable/train: Remove legacy network-isolation env files
Tenguslaweq: stupid question - how do we remove a router? It complains because there's a port attached - may I just `router remove port ...' ?12:45
Tenguah. yep. that's that easy.12:46
slaweqYes, You need to unplug networks from the router and then you will be able to remove it12:47
bshepharfail review12:53
opendevreviewBrendan Shephard proposed openstack/tripleo-heat-templates master: Remove legacy network-isolation env files
*** ysandeep|rover|break is now known as ysandeep|rover12:57
opendevreviewRonelle Landy proposed openstack/tripleo-quickstart master: Remove excludes for libvirt in integration jobs
opendevreviewBrendan Shephard proposed openstack/tripleo-heat-templates stable/wallaby: Add sample baremetal_deployment.yaml
cloudnullmornings 13:07
opendevreviewJuan Larriba proposed openstack/tripleo-ansible stable/wallaby: ReaR needs specific configuration in RHEL9 with LVM
opendevreviewBrendan Shephard proposed openstack/tripleo-heat-templates master: Add predictable IP's sample file
dpawlikTengu++ for patch
opendevreviewBrendan Shephard proposed openstack/tripleo-heat-templates master: Add predictable IP's sample file
Tengudpawlik: ah, well, if only that element was used :)13:22
Tengudpawlik: it's not active in the tripleo-common default templates.......13:22
Tengudpawlik: so it also needs
dpawliklet's try ;)13:23
dpawlikTengu: ah, I only need dib patch13:23
dpawlikbecause c8s and c9s will fail13:23
opendevreviewBrendan Shephard proposed openstack/tripleo-heat-templates master: Add predictable IP's sample file
Tengudpawlik: fine :913:27
*** dasm|off is now known as dasm13:27
rlandyTengu: tkajinam: cloudnull: on CIX call ... they are requesting reviews on
* cloudnull looking 13:39
rlandyto unblock train with backport13:39
rlandybogdando's patch13:39
rlandyrelated card:
Tengurlandy: #done.13:44
Tenguslaweq: quick question: did you try with actual iptables? I think I recall you speaking about that last week.13:49
Tengu(i.e. no nftables compat layer)13:50
slaweqTengu: You mean iptables-legacy? I didn't try it13:50
Tenguslaweq: in order to test with iptables-legacy, I'd need to dump the current state, flush everything, switch the alternative, and reload?13:51
rlandythank you13:52
opendevreviewMerged openstack/tripleo-quickstart-extras master: Add diskimage-builder in artg_branchless_projects
*** pojadhav|break is now known as pojadhav13:57
*** soniya29 is now known as soniya29|ruck14:06
opendevreviewMerged openstack/tripleo-ansible stable/train: [train only] Remove centos-7 content provider from zuul layout
dasmdmendiza[m]: did you have time to check ?14:17
Tenguslaweq: testing with iptables-legacy from epel.14:31
slaweqI'm in the meeting now14:32
Tenguslaweq: basically, switched the alternative, rebooted.14:32
Tenguand set the POLICY to DROP14:32
Tenguand it works.14:32
Tenguso it's NOT l314:32
slaweqgood to know14:32
Tengupretty sure this is a good proof.14:32
Tenguslaweq: commented the LP.14:35
Tengudang.... so much fun :D14:35
Tenguslaweq: wow...... even after a reboot, the ping is still working with nftable and DROP policy.14:49
slaweqTengu: I'm not sure if it's not something what is done maybe earlier during the provisioning node stage what is breaking things there14:49
slaweqas iptables-nft which I tried locally worked fine14:49
slaweqit also worked fine in Your lab14:50
slaweqmaybe the issue is related only to u/s CI14:50
slaweqI have deployed OSP-17 on RHEL 9 already and want to try to reproduce same issue there14:50
Tenguit worked under some conditions, that aren't the same as "non-DROP-policy"14:50
slaweqbut probably I will do it tomorrow morning14:50
Tengubtw - now, for unknown reason, it's working every time...14:50
TenguI'm using iptables-nft, policy is DROP, I just dropped and created a new router, and it works.14:51
Tenguthe only diff: a reboot.14:51
Tenguof the controller14:51
* Tengu doesn't understand anything now14:51
Tengunft list filter shows the drop policy14:51
Tenguah. ok. maybe I reused a known IP.14:53
Tenguyeah. apparently it was a reused IP or something.14:53
*** pojadhav is now known as pojadhav|afk14:54
*** soniya29|ruck is now known as soniya29|ruck|dinner14:54
opendevreviewKevin Carter proposed openstack/tripleo-docs master: add title to the repos doc
*** dviroel is now known as dviroel|lunch15:10
opendevreviewBrendan Shephard proposed openstack/tripleo-common master: Revert "task-core file generation"
opendevreviewBrendan Shephard proposed openstack/tripleo-heat-templates master: Revert "task-core basic framework"
opendevreviewBrendan Shephard proposed openstack/tripleo-heat-templates master: Revert "task-core basic framework"
vkmchi all, in order to disable a service in a brownfield deployment 1. change the service env file with OS::Heat::None 2. run overcloud deploy again15:32
vkmcbut that won't tear down related containers or resources under pcmk, no? 15:33
vkmcalso, is there a way to remove a network if it has been deployed with composable networks?15:34
vkmcnot sure if my question makes sense, but I can provide more context if needed15:34
vkmcany help is appreciated15:34
opendevreviewBogdan Dobrelya proposed openstack/tripleo-ansible stable/wallaby: Add cell internalapi VIP in controllers /etc/hosts
*** soniya29|ruck|dinner is now known as soniya29|ruck15:36
cloudnullvkmc I don't believe the system will cleanup removed services -- I think the state change is just None so further action is omitted 15:36
* cloudnull knows very little what would happen in the composable network case. 15:36
opendevreviewBogdan Dobrelya proposed openstack/tripleo-ansible stable/train: Add cell internalapi VIP in controllers /etc/hosts
vkmccloudnull, hm yes, I just got that process is incremental only... so basically you cannot unset what you already set15:38
vkmcI assume that manual intervention is required to remove lingering services/containers15:38
*** marios is now known as marios|out15:50
cloudnullI think that's right 15:51
opendevreviewRonelle Landy proposed openstack/tripleo-quickstart master: Remove excludes for libvirt in check jobs
opendevreviewRonelle Landy proposed openstack/tripleo-quickstart master: Remove excludes for libvirt in check jobs
*** ysandeep|rover is now known as ysandeep|out16:09
opendevreviewTakashi Kajinami proposed openstack/validations-libs master: Remove six
*** soniya29|ruck is now known as soniya29|out16:12
*** dviroel|lunch is now known as dviroel16:24
opendevreviewFrancesco Pantano proposed openstack/tripleo-ansible master: Normalize the server_addr dashboard backend
opendevreviewFrancesco Pantano proposed openstack/tripleo-ansible master: Fix ceph_vip variable name
opendevreviewFrancesco Pantano proposed openstack/python-tripleoclient master: Call the right process_daemon function
opendevreviewMerged openstack/tripleo-heat-templates stable/wallaby: Install ansible.posix.debug stdout callback plugin
*** jpena is now known as jpena|off17:17
opendevreviewMerged openstack/puppet-tripleo stable/train: [train-only] Fix certmonger vnc key file data race
opendevreviewMerged openstack/tripleo-heat-templates stable/train: [train only] Remove centos-7 content provider from zuul layout
opendevreviewMerged openstack/puppet-tripleo master: Fix noop_resource function with package resource
opendevreviewMerged openstack/tripleo-heat-templates master: Add predictable IP's sample file
slaglehmm. why is container-puppet-swift trying to dnf install xinetd. is this a known issue?19:35
slagleguess master no longer officially works on cs-819:42
opendevreviewMerged openstack/tripleo-ansible master: Avoid failing if no pools/keys are specified
opendevreviewDavid Hill proposed openstack/tripleo-validations master: Add libvirtd.socket to list of services
cloudnullslagle is that a thing?20:31
cloudnullidk why swift would even need xinetd ?20:31
cloudnullif it is needed, then we should add it to the TCIB definitions 20:31
slaglecloudnull: this is the patch that broke it for me,
slagleit removed mapping the puppet xinetd resource to noop20:32
cloudnulloic ?20:32
slaglei'm not totally sure how that comes into play with a centos-8-stream host. given that all container images are ubi8 anyway?20:32
slaglemaybe host facts are inherited in the puppet containers or something?20:32
cloudnull yeah we cache our facts on the host20:33
cloudnullso i suspect there's some cross pollination 20:33
opendevreviewTom Weininger proposed openstack/tripleo-heat-templates stable/wallaby: Use Octavia's own default user_log_format value
*** dviroel is now known as dviroel|afk20:43
opendevreviewJames Slagle proposed openstack/tripleo-heat-templates master: Use tripleo_keystone role
opendevreviewJames Slagle proposed openstack/tripleo-heat-templates master: Use tripleo_kernel standalone role for upgrade_tasks
opendevreviewJames Slagle proposed openstack/tripleo-heat-templates master: Use tripleo_iscsid standalone ansible role
opendevreviewJames Slagle proposed openstack/tripleo-heat-templates master: Use tripleo_mysql_client standalone ansible role
opendevreviewJames Slagle proposed openstack/tripleo-heat-templates master: Use standalone playbooks from tripleo-ansible
opendevreviewJames Slagle proposed openstack/tripleo-heat-templates master: Use standalone bootstrap playbook from tripleo-ansible
opendevreviewJames Slagle proposed openstack/tripleo-ansible master: Add tripleo_iscsid role
opendevreviewJames Slagle proposed openstack/tripleo-ansible master: Add tripleo_mysql_client role
opendevreviewJames Slagle proposed openstack/tripleo-ansible master: Add initial standalone playbooks and inventory for a compute node
opendevreviewJames Slagle proposed openstack/tripleo-ansible master: Add tripleo_bootstrap role to standlone install phase
opendevreviewJames Slagle proposed openstack/tripleo-ansible master: Add tripleo_ssh_known_hosts role to standalone configure phase
opendevreviewJames Slagle proposed openstack/tripleo-ansible master: Add standalone bootstrap phase and playbook
opendevreviewJames Slagle proposed openstack/tripleo-ansible master: Add pre-network and network phase and playbooks
opendevreviewFrancesco Pantano proposed openstack/tripleo-ansible master: Normalize the server_addr dashboard backend
opendevreviewFrancesco Pantano proposed openstack/tripleo-heat-templates master: Do not deploy ceph-nfs during the overcloud deploy
opendevreviewMerged openstack/tripleo-quickstart master: Remove excludes for libvirt in integration jobs
*** rlandy is now known as rlandy|bbl22:13
*** dasm is now known as dasm|off22:16
opendevreviewMerged openstack/tripleo-quickstart master: Remove excludes for libvirt in check jobs
opendevreviewBrendan Shephard proposed openstack/tripleo-common master: Revert "task-core file generation"
opendevreviewSteve Baker proposed openstack/tripleo-image-elements stable/wallaby: Disable auto discovery
opendevreviewSteve Baker proposed openstack/tripleo-image-elements stable/wallaby: Migrate from testr to stestr
*** cloudnull8 is now known as cloudnull23:04
opendevreviewSteve Baker proposed openstack/tripleo-image-elements stable/wallaby: Migrate from testr to stestr, disable auto discovery
opendevreviewSteve Baker proposed openstack/tripleo-image-elements stable/wallaby: Add element reset-bls-entries
stevebaker[m]Hey, I had to combine 2 wallaby backports to fix tripleo-image-elements CI
opendevreviewTakashi Kajinami proposed openstack/tripleo-validations master: Remove six
opendevreviewSteve Baker proposed openstack/tripleo-puppet-elements stable/wallaby: Migrate from testr to stestr, disable auto discovery Change-Id: I4cf10643a18fbc331213b5a3f3d4e4f207f49527 (cherry picked from commit 66f8964f59342d99f7115b16ac8629382279e918)                 and commit 1e3b5a1cd4932c0897bff9359bfd5576865cd5a2)
opendevreviewSteve Baker proposed openstack/tripleo-puppet-elements stable/wallaby: Migrate from testr to stestr, disable auto discovery
opendevreviewTakashi Kajinami proposed openstack/tripleo-validations master: Remove six

Generated by 2.17.3 by Marius Gedminas - find it at!