*** rlandy has quit IRC | 00:02 | |
*** panda has quit IRC | 00:02 | |
*** panda has joined #zuul | 00:05 | |
*** jamesmcarthur has quit IRC | 00:15 | |
*** armstrongs has joined #zuul | 00:28 | |
*** jamesmcarthur has joined #zuul | 00:29 | |
*** armstrongs has quit IRC | 00:34 | |
SpamapS | fungi: oh thanks, that does look entirely relevant | 00:38 |
---|---|---|
*** michael-beaver has quit IRC | 00:43 | |
*** jamesmcarthur has quit IRC | 00:44 | |
*** pots has quit IRC | 00:54 | |
*** pots has joined #zuul | 00:55 | |
*** jamesmcarthur has joined #zuul | 01:01 | |
*** jamesmcarthur has quit IRC | 01:13 | |
*** bhavikdbavishi has joined #zuul | 02:19 | |
*** bhavikdbavishi1 has joined #zuul | 02:22 | |
*** bhavikdbavishi has quit IRC | 02:24 | |
*** bhavikdbavishi1 is now known as bhavikdbavishi | 02:24 | |
*** swest has quit IRC | 02:34 | |
*** swest has joined #zuul | 02:49 | |
*** todun has joined #zuul | 04:07 | |
*** sgw has quit IRC | 05:17 | |
*** todun has quit IRC | 05:23 | |
*** bolg has joined #zuul | 05:25 | |
*** todun has joined #zuul | 05:31 | |
*** todun has quit IRC | 05:34 | |
*** sanjayu_ has joined #zuul | 05:47 | |
*** igordc has quit IRC | 06:37 | |
*** fdegir has quit IRC | 06:40 | |
*** fdegir has joined #zuul | 06:41 | |
*** sanjayu_ has quit IRC | 07:02 | |
*** saneax has joined #zuul | 07:02 | |
*** sanjayu_ has joined #zuul | 07:04 | |
*** saneax has quit IRC | 07:05 | |
*** sanjayu__ has joined #zuul | 07:07 | |
*** sanjayu__ has quit IRC | 07:08 | |
*** pcaruana has joined #zuul | 07:09 | |
*** sanjayu_ has quit IRC | 07:09 | |
*** saneax has joined #zuul | 07:10 | |
*** sanjayu_ has joined #zuul | 07:12 | |
*** saneax has quit IRC | 07:13 | |
*** themroc has joined #zuul | 07:49 | |
*** chandankumar has quit IRC | 08:19 | |
*** chandankumar has joined #zuul | 08:20 | |
*** hashar has joined #zuul | 08:27 | |
*** jpena|off is now known as jpena | 08:37 | |
*** jangutter has joined #zuul | 08:56 | |
*** sshnaidm|afk is now known as sshnaidm | 09:21 | |
openstackgerrit | Fabien Boucher proposed zuul/zuul master: Pagure - add support for git.tag.creation event https://review.opendev.org/679938 | 09:30 |
openstackgerrit | Fabien Boucher proposed zuul/zuul master: Pagure - Support for branch creation/deletion https://review.opendev.org/685116 | 09:30 |
openstackgerrit | Fabien Boucher proposed zuul/zuul master: Pagure - add support for git.tag.creation event https://review.opendev.org/679938 | 09:32 |
openstackgerrit | Fabien Boucher proposed zuul/zuul master: Pagure - Support for branch creation/deletion https://review.opendev.org/685116 | 09:32 |
openstackgerrit | Fabien Boucher proposed zuul/zuul master: Pagure - add the enqueue_ref unit test https://review.opendev.org/687351 | 09:32 |
*** pcaruana has quit IRC | 10:35 | |
openstackgerrit | Fabien Boucher proposed zuul/nodepool master: Remove uneeded shebang and exec bit on some files https://review.opendev.org/692100 | 10:39 |
*** openstackstatus has quit IRC | 10:44 | |
*** mgoddard has quit IRC | 10:46 | |
*** mgoddard has joined #zuul | 10:47 | |
*** rfolco|off has joined #zuul | 10:54 | |
*** panda is now known as panda|pto | 11:00 | |
*** arxcruz is now known as arxcruz|lunch | 11:10 | |
*** sshnaidm has quit IRC | 11:23 | |
*** rfolco|off has quit IRC | 11:35 | |
*** sshnaidm has joined #zuul | 11:43 | |
*** bolg has quit IRC | 11:57 | |
*** jpena is now known as jpena|lunch | 11:59 | |
*** pcaruana has joined #zuul | 12:00 | |
*** rlandy has joined #zuul | 12:13 | |
*** arxcruz|lunch is now known as arxcruz | 12:18 | |
*** hashar is now known as hasharAway | 12:25 | |
*** hasharAway has quit IRC | 12:32 | |
*** hashar has joined #zuul | 12:34 | |
*** hashar is now known as hasharAway | 12:35 | |
*** bolg has joined #zuul | 12:37 | |
*** gtema_ has joined #zuul | 12:40 | |
*** Goneri has joined #zuul | 12:49 | |
*** rfolco has joined #zuul | 13:01 | |
*** jpena|lunch is now known as jpena | 13:02 | |
*** bolg has quit IRC | 13:03 | |
*** sgw has joined #zuul | 13:03 | |
*** hasharAway has quit IRC | 13:13 | |
*** hashar has joined #zuul | 13:14 | |
*** hashar_ has joined #zuul | 13:15 | |
*** bolg has joined #zuul | 13:26 | |
*** hashar_ has quit IRC | 13:37 | |
*** hashar has quit IRC | 13:38 | |
*** hashar has joined #zuul | 13:38 | |
*** gtema_ has quit IRC | 13:56 | |
*** mattw4 has joined #zuul | 14:04 | |
*** mattw4 has quit IRC | 14:16 | |
*** jamesmcarthur has joined #zuul | 14:24 | |
*** jamesmcarthur has quit IRC | 14:31 | |
*** bolg has quit IRC | 14:32 | |
fungi | reminder for folks who are joining us in shanghai next week, there are (at least) 5 talks about zuul: https://www.openstack.org/summit/shanghai-2019/summit-schedule/global-search?t=Zuul | 14:36 |
fungi | probably also plenty of opportunities to discuss zuul in other sessions too | 14:37 |
*** Goneri has quit IRC | 14:49 | |
Shrews | So, looks like our buildset-registry jobs are failing because we are expecting a buildset_proxy container to be running, but it is not. Trying to figure out if the fix is to plan for it to NOT be running (we currently do not), or to figure out why it isn't running in the first place | 14:58 |
Shrews | Here is where we expect it to be running (and thus failing): https://opendev.org/opendev/base-jobs/src/branch/master/playbooks/buildset-registry/post.yaml#L20 | 15:00 |
Shrews | Unfortunately, I'm not up-to-speed enough to know what the proxy is | 15:01 |
clarkb | the buildset proxy wasacaching proxy for dockerhub I believe the new zuul registry which runs as buildset registry is meant to provide that functionality too | 15:03 |
Shrews | buildset_proxy shows up in only that post playbook if i search codesearch | 15:03 |
clarkb | likely the case we dont want to run the buildset proxy anymore | 15:03 |
*** jpena is now known as jpena|off | 15:04 | |
Shrews | well, afaict, we don't run it :) | 15:04 |
*** rfolco is now known as rfolco|ruck | 15:08 | |
*** sanjayu_ has quit IRC | 15:10 | |
Shrews | ah, i think this explains it: https://review.opendev.org/689238 | 15:11 |
Shrews | fix incoming | 15:12 |
*** rfolco|ruck is now known as rfolco|rucker | 15:13 | |
Shrews | remote: https://review.opendev.org/692167 Remove buildset_proxy reference | 15:16 |
*** rfolco|rucker has quit IRC | 15:26 | |
*** jamesmcarthur has joined #zuul | 15:29 | |
*** michael-beaver has joined #zuul | 15:39 | |
*** jamesmcarthur has quit IRC | 15:41 | |
*** Goneri has joined #zuul | 15:49 | |
*** bhavikdbavishi has quit IRC | 15:53 | |
*** mattw4 has joined #zuul | 16:14 | |
*** jamesmcarthur has joined #zuul | 16:18 | |
*** igordc has joined #zuul | 16:21 | |
*** jamesmcarthur has quit IRC | 16:22 | |
*** jamesmcarthur has joined #zuul | 16:22 | |
*** hashar has quit IRC | 16:49 | |
*** hashar has joined #zuul | 16:59 | |
*** openstackstatus has joined #zuul | 17:04 | |
*** ChanServ sets mode: +v openstackstatus | 17:04 | |
*** rfolco has joined #zuul | 17:04 | |
*** jamesmcarthur has quit IRC | 17:38 | |
*** jamesmcarthur has joined #zuul | 17:39 | |
*** jamesmcarthur has quit IRC | 17:44 | |
*** hashar has quit IRC | 17:44 | |
*** jamesmcarthur has joined #zuul | 17:51 | |
*** jamesmcarthur has quit IRC | 17:58 | |
*** jamesmcarthur has joined #zuul | 18:00 | |
*** hashar has joined #zuul | 18:01 | |
*** jamesmcarthur has quit IRC | 18:05 | |
*** pcaruana has quit IRC | 18:10 | |
*** jamesmcarthur has joined #zuul | 18:13 | |
*** jamesmcarthur has quit IRC | 18:15 | |
*** jamesmcarthur has joined #zuul | 18:16 | |
*** chandankumar is now known as raukadah | 18:17 | |
*** jamesmcarthur has quit IRC | 18:23 | |
*** jamesmcarthur has joined #zuul | 18:24 | |
*** stevthedev has joined #zuul | 18:31 | |
*** Goneri has quit IRC | 18:46 | |
*** jamesmcarthur has quit IRC | 18:58 | |
*** jamesmcarthur has joined #zuul | 18:58 | |
*** jamesmcarthur has quit IRC | 19:03 | |
*** pcaruana has joined #zuul | 19:05 | |
*** jamesmcarthur has joined #zuul | 19:16 | |
*** hashar has quit IRC | 19:24 | |
*** pcaruana has quit IRC | 19:29 | |
*** jamesmcarthur has quit IRC | 19:34 | |
*** Goneri has joined #zuul | 19:36 | |
*** pcaruana has joined #zuul | 19:39 | |
*** pcaruana has quit IRC | 20:09 | |
*** rfolco has quit IRC | 20:12 | |
*** jamesmcarthur has joined #zuul | 20:13 | |
*** Goneri has quit IRC | 20:22 | |
*** hashar has joined #zuul | 20:28 | |
*** jamesmcarthur has quit IRC | 20:29 | |
*** jamesmcarthur has joined #zuul | 20:50 | |
SpamapS | Anybody know exactly why we chose 1024 bits for the Zuul build SSH key? | 20:50 |
SpamapS | (It's incompatible with AWS's ec2 instance connect feature...they won't let you use less than 2048 bits.. would have been a nice win if I could re-use it for testing some utilities that use that. ;) | 20:50 |
SpamapS | https://opendev.org/zuul/zuul-jobs/src/branch/master/roles/add-build-sshkey/tasks/create-key-and-replace.yaml#L2 for reference | 20:51 |
SpamapS | the first commit goes back to openstack-zuul-jobs so it's an old choice | 20:51 |
SpamapS | one I think is worth re-evaluating. | 20:51 |
fungi | i expect the idea was that it's only used for a few hours anyway, so the odds that there exists hardware to brute-force a 1024-bit ssh key in a few hours is slim for the foreseeable future. but yes, no idea why we even applied the -b at all. could have just let ssh-keygen pick its default keysize | 20:53 |
fungi | i have no objections to changing that | 20:54 |
clarkb | we need a newone for every build so may be an effort to use entropy efficiently | 20:54 |
*** hashar has quit IRC | 20:55 | |
fungi | we shouldn't really "use" entropy. but people may not be running executors on recently enlightened kernels/tools which know that you don't need to extract entropy from the pool over time | 20:59 |
fungi | ideally the kernel is seeding a cryptographically-strong prng and then re-seeding it with a bit of entropy over time, but the amount of re-seeding doesn't need to scale with the use of the prng | 20:59 |
*** jamesmcarthur has quit IRC | 21:00 | |
*** hashar has joined #zuul | 21:03 | |
clarkb | we've definitely hadproblems when haveged isnt running but should have haveged everywhere ourselves | 21:07 |
*** jamesmcarthur has joined #zuul | 21:07 | |
*** jamesmcarthur_ has joined #zuul | 21:09 | |
*** jamesmcarthur has quit IRC | 21:12 | |
*** panda|pto has quit IRC | 21:14 | |
*** panda has joined #zuul | 21:18 | |
*** jamesmcarthur_ has quit IRC | 21:24 | |
*** jamesmcarthur has joined #zuul | 21:27 | |
*** jamesmcarthur has quit IRC | 21:29 | |
*** jamesmcarthur has joined #zuul | 21:32 | |
*** jamesmcarthur has quit IRC | 21:44 | |
*** jamesmcarthur has joined #zuul | 21:44 | |
*** jamesmcarthur has quit IRC | 21:49 | |
*** jamesmcarthur has joined #zuul | 21:50 | |
*** jamesmcarthur has quit IRC | 21:55 | |
*** jamesmcarthur has joined #zuul | 21:56 | |
*** jamesmcarthur has quit IRC | 22:00 | |
*** hashar has quit IRC | 22:15 | |
*** hashar has joined #zuul | 22:17 | |
*** igordc has quit IRC | 22:25 | |
*** hashar has quit IRC | 22:42 | |
*** rlandy has quit IRC | 23:00 | |
*** mattw4 has quit IRC | 23:14 | |
mordred | I'm fine changing | 23:16 |
fungi | with modern kernels/userland the main reasons to install something like haveged is if the server lacks a good source of entropy at boot and so blocks on reads from /dev/random for too long while it's getting seeded | 23:19 |
fungi | (well, /dev/random or equivalent kernel syscall) | 23:19 |
mordred | nod | 23:21 |
fungi | i think once things are running, repeated ssh-keygen calls shouldn't be significantly impeded regardless of keysize, but that can be tested fairly easily | 23:23 |
fungi | yeah, running ssh-keygen in a loop (-P '' will bypass the passphrase prompt) gets me a couple keys a second with no sign of depleting the system entropy pool | 23:27 |
fungi | this is on debian/sid, so not sure how far back to expect that sort of behavior, but probably ubuntu bionic and rhel/centos 8 at least | 23:28 |
clarkb | we are still on xenial fwiw | 23:28 |
fungi | xenial may be recent enough, but would want to test | 23:29 |
fungi | just needs to be new enough that it's not using the old kernel model where every read from /dev/random sucked an equivalent number of bytes from the entropy pool | 23:31 |
fungi | kinda sad the linux kernel community was so slow to move to the new model. the *bsds had it (/dev/random basically being identical to /dev/urandom) for years | 23:32 |
fungi | once the prng was implemented via a strong encryption cipher in counter mode, there was no need for them to be different | 23:34 |
fungi | other than blocking reads until sufficient initial seeding has been achieved | 23:40 |
SpamapS | I wonder how much of "BSD is better for web serving" came from that. | 23:40 |
SpamapS | anyway, sounds like a small patch to drop the -b would be welcomed. | 23:41 |
fungi | yes, if nothing else, it gives us somewhere to post some benchmarks | 23:42 |
mordred | SpamapS: I would +2 such a patch | 23:42 |
* SpamapS dons helmet and shouts: INCOMING! | 23:43 | |
mordred | assuming benchmarks on the appropriate platforms are acceptabler | 23:43 |
openstackgerrit | Clint 'SpamapS' Byrum proposed zuul/zuul-jobs master: Remove argument to ssh-keygen for key size https://review.opendev.org/692244 | 23:44 |
fungi | on a booted ubuntu/xenial vm in rackspace's dfw region with no haveged installed, i can loop this and get 3 or 4 keys a second... while :;do rm -f foo{,.pub};ssh-keygen -P '' -b 2048 -f foo -t rsa;done | 23:47 |
*** EmilienM has quit IRC | 23:47 | |
fungi | so i think it's probably fine | 23:47 |
*** EmilienM has joined #zuul | 23:48 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!