Monday, 2022-05-09

opendevreviewMerged openstack/tripleo-ansible stable/wallaby: Add ansible_playbook to support NFV deployment during "overcloud node provision" command  https://review.opendev.org/c/openstack/tripleo-ansible/+/84068002:22
*** ysandeep|out is now known as ysandeep|rover04:58
opendevreviewMerged openstack/diskimage-builder master: Ensure cloud-init is configured to generated host keys  https://review.opendev.org/c/openstack/diskimage-builder/+/84082505:24
opendevreviewSandeep Yadav proposed openstack/tripleo-quickstart-extras master: Add diskimage-builder in artg_branchless_projects  https://review.opendev.org/c/openstack/tripleo-quickstart-extras/+/84106405:39
opendevreviewSandeep Yadav proposed openstack/tripleo-quickstart-extras master: Add diskimage-builder in artg_branchless_projects  https://review.opendev.org/c/openstack/tripleo-quickstart-extras/+/84106405:40
opendevreviewSandeep Yadav proposed openstack/diskimage-builder master: [DNM] test patch  https://review.opendev.org/c/openstack/diskimage-builder/+/84106505:46
*** soniya29 is now known as soniya29|ruck06:13
opendevreviewCedric Jeanneret proposed openstack/tripleo-common master: Add cloud-init element  https://review.opendev.org/c/openstack/tripleo-common/+/84106706:48
*** soniya29 is now known as soniya29|ruck06:58
*** soniya29 is now known as soniya29|ruck07:19
*** ysandeep|rover is now known as ysandeep|rover|lunch07:20
*** jpena|off is now known as jpena07:30
*** soniya29 is now known as soniya29|ruck07:38
*** soniya29|ruck is now known as soniya29|ruck|lunch07:57
opendevreviewMarios Andreou proposed openstack/tripleo-ci master: Remove centos-7 job definitions and zuul layouts  https://review.opendev.org/c/openstack/tripleo-ci/+/83951807:59
opendevreviewMarios Andreou proposed openstack/tripleo-ansible stable/train: [train only] Remove centos-7 content provider from zuul layout  https://review.opendev.org/c/openstack/tripleo-ansible/+/84107908:07
opendevreviewMarios Andreou proposed openstack/tripleo-ci master: Remove centos-7 job definitions and zuul layouts  https://review.opendev.org/c/openstack/tripleo-ci/+/83951808:08
opendevreviewMarios Andreou proposed openstack/tripleo-heat-templates stable/train: [train only] Remove centos-7 content provider from zuul layout  https://review.opendev.org/c/openstack/tripleo-heat-templates/+/84108008:11
opendevreviewMarios Andreou proposed openstack/tripleo-ci master: Remove centos-7 job definitions and zuul layouts  https://review.opendev.org/c/openstack/tripleo-ci/+/83951808:13
*** soniya29|ruck|lunch is now known as soniya29|ruck08:23
*** ysandeep|rover|lunch is now known as ysandeep|rover08:23
opendevreviewFrancesco Pantano proposed openstack/tripleo-ansible master: Normalize the server_addr dashboard backend  https://review.opendev.org/c/openstack/tripleo-ansible/+/84108108:29
pojadhavrlanday08:58
Tenguslaweq: heya! Sooo. the testproject injecting just the policy without the chain is showing the issue is, indeed, in the fact the "drop" rule we have now is missing some packages: https://review.rdoproject.org/zuul/build/c0e5ea3dc47c4073a1609b5984f3563809:39
Tenguslaweq: failed on the ping. So my take here is: let's find the "state" of those weird packages we're missing, analyse it, and see what's going on. We're also missing them in the actual log since we're logging only NEW things.09:40
Tenguand it's a security issue in the end. To some extends. woohooo.09:41
opendevreviewFrancesco Pantano proposed openstack/tripleo-ansible master: Normalize the server_addr dashboard backend  https://review.opendev.org/c/openstack/tripleo-ansible/+/84108109:47
opendevreviewPooja Jadhav proposed openstack/tripleo-ci master: Ussuri tear down as EOL  https://review.opendev.org/c/openstack/tripleo-ci/+/83546010:10
*** rlandy|out is now known as rlandy10:24
opendevreviewFrancesco Pantano proposed openstack/tripleo-heat-templates master: Do not deploy ceph-nfs during the overcloud deploy  https://review.opendev.org/c/openstack/tripleo-heat-templates/+/83947410:28
slaweqTengu: yeah, so tbh I think that currently it works fine just because we have ACCEPT as default policy, nothing else10:29
slaweqother rules aren't matched in that traffic to the router's gateway10:29
slaweqso this isn't really issue with Your patch but issue which Your patch shown us10:30
slaweqTengu: I'm deploying it now on my lab and will try to reproduce the issue to work on it without need to hold CI nodes10:35
slaweqCan You maybe open bug for that for Networking DFG?10:36
opendevreviewMerged openstack/tripleo-ansible master: ReaR needs specific configuration in RHEL9 with LVM  https://review.opendev.org/c/openstack/tripleo-ansible/+/83734711:05
*** dviroel_ is now known as dviroel\11:14
*** dviroel\ is now known as dviroel11:14
Tenguslaweq: I can. on launchpad, or on rh bugzilla?11:20
Tenguslaweq: I'm getting an env without the patch up right now (it crashed before my lunch break for unrelated reason). I'll also play a bit with nftables in order to understand it better. But I have the feeling we won't be able to solve the issue using the iptables-nft wrapper, unfortunately.11:22
Tenguseems too deep.11:23
Tenguslaweq: https://bugs.launchpad.net/tripleo/+bug/1972283  lemme know if you want me to copy this one in rh bugzilla.11:40
Tengufeel free to comment with your own observations.11:40
*** ysandeep|rover is now known as ysandeep|rover|break11:57
opendevreviewCedric Jeanneret proposed openstack/tripleo-heat-templates master: Manage the masquerade rules via ansible instead of puppet  https://review.opendev.org/c/openstack/tripleo-heat-templates/+/83687212:09
slaweqTengu: thx, that should be enough12:16
Tenguslaweq: ok. I'll play a bit with nftables once I get my OC.12:16
Tenguguess it will require some arp things. it's an unpatched env, but I can emulate the issue while switching the chain policy.12:16
Tenguand, probably, adding and dropping router so that its MAC and IP change.12:16
slaweqhi tripleo stable cores, can someone check and approve https://review.opendev.org/c/openstack/tripleo-heat-templates/+/838755 ? It already have 2x +2, maybe someone can approve it?12:17
Tengushouldn't be THAT hard.12:17
slaweqthx in advanc12:17
slaweq*advance12:17
Tenguslaweq: #done.12:18
slaweqTengu: thx a lot12:18
Tenguthough... ownership may be better in some conditions.12:18
Tengubut it would be harder to set the correct group.12:18
Tenguanywy. it's in gate now.12:18
*** pojadhav is now known as pojadhav|break12:22
opendevreviewMerged openstack/tripleo-heat-templates stable/victoria: Remove sidecar containers after SIGTERM is send to stop them  https://review.opendev.org/c/openstack/tripleo-heat-templates/+/84074012:40
opendevreviewBrendan Shephard proposed openstack/tripleo-heat-templates stable/train: Remove legacy network-isolation env files  https://review.opendev.org/c/openstack/tripleo-heat-templates/+/84111112:44
Tenguslaweq: stupid question - how do we remove a router? It complains because there's a port attached - may I just `router remove port ...' ?12:45
Tenguah. yep. that's that easy.12:46
slaweqYes, You need to unplug networks from the router and then you will be able to remove it12:47
bshepharfail review12:53
opendevreviewBrendan Shephard proposed openstack/tripleo-heat-templates master: Remove legacy network-isolation env files  https://review.opendev.org/c/openstack/tripleo-heat-templates/+/84111212:54
*** ysandeep|rover|break is now known as ysandeep|rover12:57
opendevreviewRonelle Landy proposed openstack/tripleo-quickstart master: Remove excludes for libvirt in integration jobs  https://review.opendev.org/c/openstack/tripleo-quickstart/+/84091712:58
opendevreviewBrendan Shephard proposed openstack/tripleo-heat-templates stable/wallaby: Add sample baremetal_deployment.yaml  https://review.opendev.org/c/openstack/tripleo-heat-templates/+/84111413:06
cloudnullmornings 13:07
opendevreviewJuan Larriba proposed openstack/tripleo-ansible stable/wallaby: ReaR needs specific configuration in RHEL9 with LVM  https://review.opendev.org/c/openstack/tripleo-ansible/+/84093613:14
opendevreviewBrendan Shephard proposed openstack/tripleo-heat-templates master: Add predictable IP's sample file  https://review.opendev.org/c/openstack/tripleo-heat-templates/+/84111713:20
dpawlikTengu++ for patch https://review.opendev.org/c/openstack/diskimage-builder/+/84082513:20
opendevreviewBrendan Shephard proposed openstack/tripleo-heat-templates master: Add predictable IP's sample file  https://review.opendev.org/c/openstack/tripleo-heat-templates/+/84111713:21
Tengudpawlik: ah, well, if only that element was used :)13:22
Tengudpawlik: it's not active in the tripleo-common default templates.......13:22
Tengu"yay".13:22
Tengudpawlik: so it also needs https://review.opendev.org/c/openstack/tripleo-common/+/84106713:23
dpawliklet's try ;)13:23
dpawlikTengu: ah, I only need dib patch13:23
dpawlikbecause c8s and c9s will fail13:23
opendevreviewBrendan Shephard proposed openstack/tripleo-heat-templates master: Add predictable IP's sample file  https://review.opendev.org/c/openstack/tripleo-heat-templates/+/84111713:24
Tengudpawlik: fine :913:27
*** dasm|off is now known as dasm13:27
rlandyTengu: tkajinam: cloudnull: on CIX call ... they are requesting reviews on https://review.opendev.org/c/openstack/puppet-tripleo/+/83995713:39
* cloudnull looking 13:39
rlandyto unblock train with backport13:39
rlandybogdando's patch13:39
rlandyhttps://trello.com/c/rwXMXKHV/2480-cixbz2079767osp162securitycomputetripleo-heat-templatephase2freeipa-vnc-cert-issue13:39
rlandyrelated card: https://trello.com/c/2CAk8C4p/2330-cixlp1959328tripleociproa-tempestscenariotestnetworkbasicopstestnetworkbasicopstestnetworkbasicops-failing-on-periodic-tripleo-c13:40
Tengurlandy: #done.13:44
Tenguslaweq: quick question: did you try with actual iptables? I think I recall you speaking about that last week.13:49
Tengu(i.e. no nftables compat layer)13:50
slaweqTengu: You mean iptables-legacy? I didn't try it13:50
Tenguah13:50
Tenguslaweq: in order to test with iptables-legacy, I'd need to dump the current state, flush everything, switch the alternative, and reload?13:51
rlandythank you13:52
opendevreviewMerged openstack/tripleo-quickstart-extras master: Add diskimage-builder in artg_branchless_projects  https://review.opendev.org/c/openstack/tripleo-quickstart-extras/+/84106413:53
*** pojadhav|break is now known as pojadhav13:57
*** soniya29 is now known as soniya29|ruck14:06
opendevreviewMerged openstack/tripleo-ansible stable/train: [train only] Remove centos-7 content provider from zuul layout  https://review.opendev.org/c/openstack/tripleo-ansible/+/84107914:07
dasmdmendiza[m]: did you have time to check https://review.opendev.org/c/openstack/tripleo-heat-templates/+/840534 ?14:17
Tenguslaweq: testing with iptables-legacy from epel.14:31
slaweqok14:31
slaweqI'm in the meeting now14:32
Tenguslaweq: basically, switched the alternative, rebooted.14:32
Tenguand set the POLICY to DROP14:32
Tenguand it works.14:32
Tengubam.14:32
Tenguso it's NOT l314:32
slaweqgood to know14:32
Tengupretty sure this is a good proof.14:32
Tenguslaweq: commented the LP.14:35
Tengudang.... so much fun :D14:35
Tenguslaweq: wow...... even after a reboot, the ping is still working with nftable and DROP policy.14:49
slaweqTengu: I'm not sure if it's not something what is done maybe earlier during the provisioning node stage what is breaking things there14:49
slaweqas iptables-nft which I tried locally worked fine14:49
slaweqit also worked fine in Your lab14:50
slaweqmaybe the issue is related only to u/s CI14:50
slaweqI have deployed OSP-17 on RHEL 9 already and want to try to reproduce same issue there14:50
Tenguit worked under some conditions, that aren't the same as "non-DROP-policy"14:50
slaweqbut probably I will do it tomorrow morning14:50
Tengubtw - now, for unknown reason, it's working every time...14:50
TenguI'm using iptables-nft, policy is DROP, I just dropped and created a new router, and it works.14:51
Tenguthe only diff: a reboot.14:51
Tenguof the controller14:51
* Tengu doesn't understand anything now14:51
slaweq:/14:51
Tengunft list filter shows the drop policy14:51
Tenguah. ok. maybe I reused a known IP.14:53
Tenguyeah. apparently it was a reused IP or something.14:53
Tengumeh.14:53
*** pojadhav is now known as pojadhav|afk14:54
*** soniya29|ruck is now known as soniya29|ruck|dinner14:54
opendevreviewKevin Carter proposed openstack/tripleo-docs master: add title to the repos doc  https://review.opendev.org/c/openstack/tripleo-docs/+/82517015:06
*** dviroel is now known as dviroel|lunch15:10
opendevreviewBrendan Shephard proposed openstack/tripleo-common master: Revert "task-core file generation"  https://review.opendev.org/c/openstack/tripleo-common/+/84113015:20
opendevreviewBrendan Shephard proposed openstack/tripleo-heat-templates master: Revert "task-core basic framework"  https://review.opendev.org/c/openstack/tripleo-heat-templates/+/84113115:23
opendevreviewBrendan Shephard proposed openstack/tripleo-heat-templates master: Revert "task-core basic framework"  https://review.opendev.org/c/openstack/tripleo-heat-templates/+/84113115:23
vkmchi all, in order to disable a service in a brownfield deployment 1. change the service env file with OS::Heat::None 2. run overcloud deploy again15:32
vkmcbut that won't tear down related containers or resources under pcmk, no? 15:33
vkmcalso, is there a way to remove a network if it has been deployed with composable networks?15:34
vkmcnot sure if my question makes sense, but I can provide more context if needed15:34
vkmcany help is appreciated15:34
opendevreviewBogdan Dobrelya proposed openstack/tripleo-ansible stable/wallaby: Add cell internalapi VIP in controllers /etc/hosts  https://review.opendev.org/c/openstack/tripleo-ansible/+/84093915:36
*** soniya29|ruck|dinner is now known as soniya29|ruck15:36
cloudnullvkmc I don't believe the system will cleanup removed services -- I think the state change is just None so further action is omitted 15:36
* cloudnull knows very little what would happen in the composable network case. 15:36
opendevreviewBogdan Dobrelya proposed openstack/tripleo-ansible stable/train: Add cell internalapi VIP in controllers /etc/hosts  https://review.opendev.org/c/openstack/tripleo-ansible/+/84113315:37
vkmccloudnull, hm yes, I just got that process is incremental only... so basically you cannot unset what you already set15:38
vkmcI assume that manual intervention is required to remove lingering services/containers15:38
*** marios is now known as marios|out15:50
cloudnullI think that's right 15:51
opendevreviewRonelle Landy proposed openstack/tripleo-quickstart master: Remove excludes for libvirt in check jobs  https://review.opendev.org/c/openstack/tripleo-quickstart/+/84114016:08
opendevreviewRonelle Landy proposed openstack/tripleo-quickstart master: Remove excludes for libvirt in check jobs  https://review.opendev.org/c/openstack/tripleo-quickstart/+/84114016:09
*** ysandeep|rover is now known as ysandeep|out16:09
opendevreviewTakashi Kajinami proposed openstack/validations-libs master: Remove six  https://review.opendev.org/c/openstack/validations-libs/+/84114116:11
*** soniya29|ruck is now known as soniya29|out16:12
*** dviroel|lunch is now known as dviroel16:24
opendevreviewFrancesco Pantano proposed openstack/tripleo-ansible master: Normalize the server_addr dashboard backend  https://review.opendev.org/c/openstack/tripleo-ansible/+/84108116:35
opendevreviewFrancesco Pantano proposed openstack/tripleo-ansible master: Fix ceph_vip variable name  https://review.opendev.org/c/openstack/tripleo-ansible/+/84114516:43
opendevreviewFrancesco Pantano proposed openstack/python-tripleoclient master: Call the right process_daemon function  https://review.opendev.org/c/openstack/python-tripleoclient/+/84114616:46
opendevreviewMerged openstack/tripleo-heat-templates stable/wallaby: Install ansible.posix.debug stdout callback plugin  https://review.opendev.org/c/openstack/tripleo-heat-templates/+/84073516:53
*** jpena is now known as jpena|off17:17
opendevreviewMerged openstack/puppet-tripleo stable/train: [train-only] Fix certmonger vnc key file data race  https://review.opendev.org/c/openstack/puppet-tripleo/+/83995717:56
opendevreviewMerged openstack/tripleo-heat-templates stable/train: [train only] Remove centos-7 content provider from zuul layout  https://review.opendev.org/c/openstack/tripleo-heat-templates/+/84108017:57
opendevreviewMerged openstack/puppet-tripleo master: Fix noop_resource function with package resource  https://review.opendev.org/c/openstack/puppet-tripleo/+/84102717:57
opendevreviewMerged openstack/tripleo-heat-templates master: Add predictable IP's sample file  https://review.opendev.org/c/openstack/tripleo-heat-templates/+/84111718:42
slaglehmm. why is container-puppet-swift trying to dnf install xinetd. is this a known issue?19:35
slagleguess master no longer officially works on cs-819:42
opendevreviewMerged openstack/tripleo-ansible master: Avoid failing if no pools/keys are specified  https://review.opendev.org/c/openstack/tripleo-ansible/+/84044919:48
opendevreviewDavid Hill proposed openstack/tripleo-validations master: Add libvirtd.socket to list of services  https://review.opendev.org/c/openstack/tripleo-validations/+/84116620:08
cloudnullslagle is that a thing?20:31
cloudnullidk why swift would even need xinetd ?20:31
cloudnullif it is needed, then we should add it to the TCIB definitions 20:31
slaglecloudnull: this is the patch that broke it for me, https://review.opendev.org/c/openstack/tripleo-heat-templates/+/83896720:31
slagleit removed mapping the puppet xinetd resource to noop20:32
cloudnulloic ?20:32
slaglei'm not totally sure how that comes into play with a centos-8-stream host. given that all container images are ubi8 anyway?20:32
slaglemaybe host facts are inherited in the puppet containers or something?20:32
cloudnull yeah we cache our facts on the host20:33
cloudnullso i suspect there's some cross pollination 20:33
opendevreviewTom Weininger proposed openstack/tripleo-heat-templates stable/wallaby: Use Octavia's own default user_log_format value  https://review.opendev.org/c/openstack/tripleo-heat-templates/+/84092520:34
*** dviroel is now known as dviroel|afk20:43
opendevreviewJames Slagle proposed openstack/tripleo-heat-templates master: Use tripleo_keystone role  https://review.opendev.org/c/openstack/tripleo-heat-templates/+/83664421:13
opendevreviewJames Slagle proposed openstack/tripleo-heat-templates master: Use tripleo_kernel standalone role for upgrade_tasks  https://review.opendev.org/c/openstack/tripleo-heat-templates/+/83850721:13
opendevreviewJames Slagle proposed openstack/tripleo-heat-templates master: Use tripleo_iscsid standalone ansible role  https://review.opendev.org/c/openstack/tripleo-heat-templates/+/83890421:13
opendevreviewJames Slagle proposed openstack/tripleo-heat-templates master: Use tripleo_mysql_client standalone ansible role  https://review.opendev.org/c/openstack/tripleo-heat-templates/+/84032221:13
opendevreviewJames Slagle proposed openstack/tripleo-heat-templates master: Use standalone playbooks from tripleo-ansible  https://review.opendev.org/c/openstack/tripleo-heat-templates/+/84051021:13
opendevreviewJames Slagle proposed openstack/tripleo-heat-templates master: Use standalone bootstrap playbook from tripleo-ansible  https://review.opendev.org/c/openstack/tripleo-heat-templates/+/84067421:13
opendevreviewJames Slagle proposed openstack/tripleo-ansible master: Add tripleo_iscsid role  https://review.opendev.org/c/openstack/tripleo-ansible/+/83890721:14
opendevreviewJames Slagle proposed openstack/tripleo-ansible master: Add tripleo_mysql_client role  https://review.opendev.org/c/openstack/tripleo-ansible/+/84032121:14
opendevreviewJames Slagle proposed openstack/tripleo-ansible master: Add initial standalone playbooks and inventory for a compute node  https://review.opendev.org/c/openstack/tripleo-ansible/+/84050921:14
opendevreviewJames Slagle proposed openstack/tripleo-ansible master: Add tripleo_bootstrap role to standlone install phase  https://review.opendev.org/c/openstack/tripleo-ansible/+/84067521:14
opendevreviewJames Slagle proposed openstack/tripleo-ansible master: Add tripleo_ssh_known_hosts role to standalone configure phase  https://review.opendev.org/c/openstack/tripleo-ansible/+/84067621:14
opendevreviewJames Slagle proposed openstack/tripleo-ansible master: Add standalone bootstrap phase and playbook  https://review.opendev.org/c/openstack/tripleo-ansible/+/84067721:14
opendevreviewJames Slagle proposed openstack/tripleo-ansible master: Add pre-network and network phase and playbooks  https://review.opendev.org/c/openstack/tripleo-ansible/+/84090321:14
opendevreviewFrancesco Pantano proposed openstack/tripleo-ansible master: Normalize the server_addr dashboard backend  https://review.opendev.org/c/openstack/tripleo-ansible/+/84108121:22
opendevreviewFrancesco Pantano proposed openstack/tripleo-heat-templates master: Do not deploy ceph-nfs during the overcloud deploy  https://review.opendev.org/c/openstack/tripleo-heat-templates/+/83947421:28
opendevreviewMerged openstack/tripleo-quickstart master: Remove excludes for libvirt in integration jobs  https://review.opendev.org/c/openstack/tripleo-quickstart/+/84091722:07
*** rlandy is now known as rlandy|bbl22:13
*** dasm is now known as dasm|off22:16
opendevreviewMerged openstack/tripleo-quickstart master: Remove excludes for libvirt in check jobs  https://review.opendev.org/c/openstack/tripleo-quickstart/+/84114022:36
opendevreviewBrendan Shephard proposed openstack/tripleo-common master: Revert "task-core file generation"  https://review.opendev.org/c/openstack/tripleo-common/+/84113022:38
opendevreviewSteve Baker proposed openstack/tripleo-image-elements stable/wallaby: Disable auto discovery  https://review.opendev.org/c/openstack/tripleo-image-elements/+/83568423:01
opendevreviewSteve Baker proposed openstack/tripleo-image-elements stable/wallaby: Migrate from testr to stestr  https://review.opendev.org/c/openstack/tripleo-image-elements/+/84117323:01
*** cloudnull8 is now known as cloudnull23:04
opendevreviewSteve Baker proposed openstack/tripleo-image-elements stable/wallaby: Migrate from testr to stestr, disable auto discovery  https://review.opendev.org/c/openstack/tripleo-image-elements/+/83568423:04
opendevreviewSteve Baker proposed openstack/tripleo-image-elements stable/wallaby: Add element reset-bls-entries  https://review.opendev.org/c/openstack/tripleo-image-elements/+/84038623:13
stevebaker[m]Hey, I had to combine 2 wallaby backports to fix tripleo-image-elements CI https://review.opendev.org/c/openstack/tripleo-image-elements/+/83568423:21
opendevreviewTakashi Kajinami proposed openstack/tripleo-validations master: Remove six  https://review.opendev.org/c/openstack/tripleo-validations/+/84117623:29
opendevreviewSteve Baker proposed openstack/tripleo-puppet-elements stable/wallaby: Migrate from testr to stestr, disable auto discovery Change-Id: I4cf10643a18fbc331213b5a3f3d4e4f207f49527 (cherry picked from commit 66f8964f59342d99f7115b16ac8629382279e918)                 and commit 1e3b5a1cd4932c0897bff9359bfd5576865cd5a2)  https://review.opendev.org/c/openstack/tripleo-puppet-elements/+/83579223:29
opendevreviewSteve Baker proposed openstack/tripleo-puppet-elements stable/wallaby: Migrate from testr to stestr, disable auto discovery  https://review.opendev.org/c/openstack/tripleo-puppet-elements/+/83579223:35
opendevreviewTakashi Kajinami proposed openstack/tripleo-validations master: Remove six  https://review.opendev.org/c/openstack/tripleo-validations/+/84117623:45

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!