15:01:08 <JayF> #startmeeting ironic
15:01:08 <opendevmeet> Meeting started Mon May 11 15:01:08 2026 UTC and is due to finish in 60 minutes.  The chair is JayF. Information about MeetBot at http://wiki.debian.org/MeetBot.
15:01:08 <opendevmeet> Useful Commands: #action #agreed #help #info #idea #link #topic #startvote.
15:01:08 <opendevmeet> The meeting name has been set to 'ironic'
15:01:10 <TheJulia> o/
15:01:14 <rpittau> o/
15:01:30 <JayF> It's a meeting! Hooray. As usual we operate under the OpenInfra Code of Conduct and the general attitude of "be kind, dudes"
15:01:33 <TheJulia> JayF: I was about to go ahead and start the meeting :)
15:01:37 <JayF> #topic Announcements/Reminders
15:02:06 <JayF> #link https://tinyurl.com/ironic-weekly-prio-dash please review things hashtagged:ironic-week-prio -- to get your changes reviewed more quickly, hashtag them :)
15:02:13 <dtantsur> o/
15:02:35 <JayF> #link https://releases.openstack.org/hibiscus/schedule.html It's R-20, do you know where your releases are? (It's OK, you don't need to know where they are, there are no deadlines)
15:02:47 <JayF> I'm going to give until :05 for more folks to trickle in
15:03:04 <TheJulia> Surely the release is tucked in it's bed for a nap!
15:03:32 <clif> o/
15:03:50 <mumesan[m]> o/
15:04:42 <JayF> OK, starting things
15:04:46 <JayF> #topic Working Group Updates
15:05:05 <JayF> I pruned this list down in the agenda, it seems like maybe teh Async group is the only one still relevant to the Hibiscus cycle, yeah?
15:05:18 <dtantsur> I hope it is :)
15:06:03 <JayF> Anything to say about it?
15:06:03 <dtantsur> For standalone networking, we're still working on the Metal3 side
15:06:28 <dtantsur> No updates for asyncio, and I'll probably pass the lead to one of my colleagues
15:06:56 <cid> o/
15:07:01 <JayF> Please feel free to edit the agenda if anyone wants to spin up any further working groups
15:07:06 <TheJulia> Aside from async, I wonder if we'll want to treat deferred tasks similarly, but we actually need to begin to build momentum there.
15:07:08 <JayF> we probably should have the nova/ironic group there at some point
15:07:15 <TheJulia> ++
15:07:18 <JayF> but similarly to TheJulia we just need spare time to kickoff
15:07:24 <TheJulia> yup
15:07:27 <JayF> #topic Discussion Topics
15:07:34 <JayF> We have quite a few CI issues comments here.
15:07:38 <JayF> And a lot of topics in general.
15:07:46 <TheJulia> So, I think the glance image issue is resolved at this point
15:07:47 <JayF> I think 99% of the are TheJulia-adjacent? /me hands over the podiuym
15:07:55 <TheJulia> lol
15:08:35 <JayF> The AKI/ARI stuff was weird, re: the glance image CI breakage
15:08:47 <JayF> but is a harsh reminder that it's a steep, steep price to embargo issues and work in quiet
15:08:48 <TheJulia> So, there is an open question regarding the firefox PPA, I know steve has started work on trying to bring the graphical console testing job back into the running state. I know early last week, the launchpad PPA repo was unresponsive
15:08:54 <JayF> which can lead to weird miscomms like what happened there
15:08:54 <TheJulia> yup
15:09:42 <JayF> TheJulia: I am generally concerned that such a job is, by it's nature, more likely to bitrot than most of our jobs... I wonder if it's reasonable to keep it nonvoting, experimental, periodic ... something to make it so it's not going to break the whole cloud if it breaks
15:09:46 <TheJulia> Skipping the glance stuff which we discussed/retrospected on last week
15:10:04 <TheJulia> So, looking at our non-voting jobs, non-voting basically leads directly to bitrot
15:10:24 <TheJulia> over stupid stuff typically, but there is a point where we likely need to recognize we can't prefectly test everything
15:10:29 <TheJulia> where that is, I don't know
15:10:43 <JayF> I don't know how to solve this problem directly, but we have so many jobs, the matrix is so big, even a small % failure chance cascades
15:11:09 <TheJulia> We likely need to have the human discussion of "what can be reasonably done" disjointed from the job voting level discussion
15:11:10 <JayF> It makes it feel more sisyphean than usual to work on CI
15:11:20 <TheJulia> Yeah, agreed
15:11:44 <TheJulia> I haven't had a chance to look at what steve is doing exactly, cardoe did propose maybe doing a cached container image
15:11:53 <TheJulia> but we also saw quay.io break last week
15:11:58 <TheJulia> so...
15:12:28 <TheJulia> dunno, as long as there is some aware and that we follow-up on the issues, we're likely in a better place
15:12:41 <TheJulia> but yeah, things like graphical are also a bit of a longer tail.
15:12:48 <TheJulia> Anyone have anything else to add before we move on ?
15:13:28 <cardoe> it's just building a container each time and installing A LOT OF packages. Cause it's starting with a minimal ubuntu and installing firefox
15:13:31 <cardoe> and X11
15:13:48 <TheJulia> each download is an opportunity for job failure
15:13:56 <TheJulia> so, simplifying that would be for the best
15:14:01 <dtantsur> Can we publish and reuse a base container?
15:14:07 <JayF> yep, especially ones that don't use CI mirrors (I don't know if our container build does; but PPAs def. don't)
15:15:29 <TheJulia> fwiw, it looks like the PPA mirror is back up, but it seems like we should just publish a container
15:15:34 <TheJulia> or a base container
15:15:49 <TheJulia> stevebaker[m]: fyi the consensus seems to be ^
15:15:54 <TheJulia> onward?
15:15:55 <dtantsur> I'm pondering the same thing for metal3 jobs btw
15:16:05 <dtantsur> building iPXE from source each time is annoying at best
15:16:21 <dtantsur> yeah, onward, not going to diverge the conversation :)
15:16:23 <TheJulia> it really wouldn't be a bad idea, although leveraging quay right now is why we had to take it out of voting at one point last week and then add it right back in
15:16:35 * dtantsur nods
15:16:48 <dtantsur> Quay is a pain in all parts of our team's bodies
15:17:44 <TheJulia> Next topic: During the PTG or right after it we discussed software raid and one item which was raised was software raid testing is limited, which has me thinking if we should put an explicit feature flag around sofware raid
15:18:15 <TheJulia> Specifically: limited testing upstream, limited ability to test it, you need to accept it might not work or you might be trying to do something it can't do
15:19:10 <JayF> I think any of our features which could: 1) expose additional security surface and 2) already require significant operator setup to work should be treated that way
15:19:14 <TheJulia> I mean, we could sink resources into testing it, but I think we're also heading into a state where distributions start backing off including modules because distros are more centered around end workstations with single devices and clouds, not servers with multiple devices and even then hardware raid is relatively inexpensive now
15:19:27 <JayF> if they already have to do a bucketload of manual config, add "turn it on" to the list
15:19:51 <TheJulia> So, anyone objecting to us adding a knob around software raid in general?
15:20:16 * TheJulia waits the customary minute
15:20:53 <TheJulia> Okay, I think we've agreed then...
15:20:59 <TheJulia> Onward!
15:21:17 <TheJulia> Next topic: A quick one for sure: We're retiring virutalpdu right?
15:21:39 * TheJulia hears crickets
15:21:59 <TheJulia> cid: I think you have a patch up but the repo still has some testing someplace?
15:22:09 <cid> I do !
15:22:30 <TheJulia> I think it needs to be marked in the releases stuff that its being retired, but I haven't done a retirement in a very long time
15:22:32 <cid> I think it's currently blocked by reivews, if I remember correctly.
15:22:49 <TheJulia> oh, is there more than one ? because the one I found on the virtualpdu repo is blocked on tests
15:22:57 <JayF> maybe worth spinning up an etherpad with the steps and where we're at
15:23:04 <JayF> so that folks can intervene to get reviews if needed?
15:23:12 <TheJulia> ++
15:23:17 <rpittau> should we announce that in the mailing list ?
15:23:21 <JayF> just links to the outstanding stuff pending review, and the next steps once they land
15:23:22 <TheJulia> we should!
15:23:24 <cid> Following the project retirement guide, I think I am at a point where a liason will have to check off on the patch, then we get the retirement date to put on a follow on commit
15:23:49 <JayF> !action cid to email list about virtualpdu retirement; create documentation around where things are and what is the next stsp
15:23:49 <opendevmeet> JayF: Error: "action" is not a valid command.
15:24:00 <TheJulia> heh, agreed ?
15:24:02 <JayF> #action cid to email list about virtualpdu retirement; create documentation around where things are and what is the next step
15:24:04 <TheJulia> heh
15:24:06 <TheJulia> okay
15:24:10 <TheJulia> Anything else on this topic?
15:24:53 <cid> Not really
15:25:14 <TheJulia> For our last topic on today's topic marathon, TLS versions! As some of you might be aware, I've been working on adding knobs for ciphers and tls versions, and I'm curious if folks have thoughts on just explicitly starting to default ironicy things to utilizing TLS 1.3 by default. Thoughts?
15:25:30 <JayF> I don't mind that change; I do not want the PQC ciphers used by default.
15:25:56 <TheJulia> Yeah, I'm not thinking of doing anything beyond asserting a default version at some point to 1.3
15:26:10 <cardoe> Is that for IPA or for everything like the BMCs?
15:26:11 <JayF> There are many folks outside of US jurisdictions worried about the introduction of net-new crypto algorithms as part of the PQC push.
15:26:15 <dtantsur> What's the scope?
15:26:30 <cardoe> Cause afaik a lot of BMCs don't do 1.3
15:26:33 <dtantsur> Ironic<->IPA traffic - sure. Ironic<->BMC rather no
15:26:34 <TheJulia> I presently have a change working its way thorugh CI which forces apache to 1.3, the downside in our model is we use apache and uwsgi (another item we should discuss at some point) front-ending it
15:26:53 <TheJulia> So, I'm thinking for BMC access, we let it fall to system policy unless an operator wishes to configure it explicitly
15:27:12 <dtantsur> apache - that's devstack-only, right? we cannot change how users configure the API?
15:27:12 <TheJulia> but frontend API wise, default wise, IPA wise, all 1.3 by default and make operators dial it back
15:27:29 <TheJulia> well, for those users, but we also have different launch models and controls all over the place
15:28:40 <TheJulia> Alternatively, my set of changes are starting to lock everything to 1.2, but since 1.3 actually seems to "just work" in devstack (like, jobs have passed when I edited apache config via sed, maybe 1.3 is okay
15:29:03 <TheJulia> again, bmcs themselves are out of that scope, only getting the knob, not a default
15:29:17 <dtantsur> bifrost may also be an okay target, although it might share its TLS settings with its vmedia server..
15:29:23 <TheJulia> (in that that ecosystem moves way slower than OSes in general)
15:29:24 <JayF> We need to make sure this is about as loud of an upgrade note as possible, since this may need infra changes on the operator side as well.
15:29:27 <JayF> Even if we exclude BMCs
15:30:01 <TheJulia> Yeah, there are already some loud notes in the release notes already in my patch series, I'd do a 1.3 change as a standalone change where I update defaults and unit tests
15:30:18 <TheJulia> Seems like we're arriving at "reasonable" ?
15:30:53 <TheJulia> Anyone seeking to object?
15:31:25 <JayF> maybe email the list if you want more input?
15:31:30 <JayF> Operators aren't usually at this meeting.
15:31:44 <TheJulia> dtantsur: the tls enpoint for getting vmedia default artifacts is a super good callout, but also that endpoint is externally managed
15:31:52 <TheJulia> yeah, I'll take that as an action item
15:32:35 <TheJulia> Cool, I guess we can proceed onward!
15:32:50 * TheJulia returns the podium to the chair
15:34:18 <TheJulia> JayF: we can move on to bug deputy updates
15:34:25 <JayF> #topic Bug Deputy Updates
15:34:29 * JayF hands chair to cid :D
15:34:40 <TheJulia> lol
15:34:44 <JayF> There are 7 new public bugs listed.
15:34:45 <cid> lol
15:34:49 <cid> Yup
15:34:57 <JayF> I'll note we had a security bug or two that went public as well that might not be in this list.
15:35:55 <JayF> Anything worth specific note? The full list is in the agenda.
15:36:04 <JayF> Looks like the RFEs are things previously discussed at the PTG?
15:36:28 <cid> 7 new bugs and no new RFES... I went through the list this "morning" so my filter must have missed the security bugs
15:36:54 <cid> I don't think there's anyting worthy of note.
15:36:54 <JayF> well it's more that they aren't "new"
15:37:09 <JayF> they come in private, ironic coresec triages them, and changes to public security if they are eligible
15:37:16 <JayF> so basically coresec does bug triage part of this
15:37:17 <cid> I understand there's a new action item to pay a little more attention to ancient bugs.
15:38:07 <cid> ++
15:38:11 <JayF> Yeah, I think we just have bugs that stick in Fix Committed instead of Fix Released
15:38:17 <JayF> just a task-thing to clean it up
15:39:00 <cid> acknwoledge.
15:39:08 <cid> handing the chair over to the chair
15:40:23 <JayF> who wants to be the deputy next week?
15:40:28 <JayF> Someone should give CID a break from it lol
15:41:33 <cardoe> I'd sign up if I knew I wasn't gonna drop the ball.
15:41:46 <JayF> I mean, make an effort, if you miss you miss
15:41:47 <clif> I can do it I suppose
15:42:05 * JayF locks clif and cardoe in a cage match to see who ends up deputy
15:42:41 <cid> lol :D
15:42:50 * JayF puts down clif and moves on
15:42:58 <JayF> There is nothing for RFE Review.
15:43:02 <JayF> #topic Open Discussion
15:43:10 <JayF> Any items for discussion not previously added to the agenda?
15:43:15 <TheJulia> lol
15:43:17 <TheJulia> oh my
15:43:21 <JayF> Also call for volunteers to chair the next meeting.
15:43:24 <TheJulia> this meeting has brought a smile to my face
15:43:29 <TheJulia> I can chair next week.
15:44:13 <cardoe> I'll be out at the end of the month and the beginning of next.
15:44:29 <TheJulia> glorius vacation?
15:44:31 <cardoe> just as fyi
15:44:33 <cardoe> yes
15:44:37 <TheJulia> Nice!
15:45:16 <JayF> #note cardoe to be unavailable end of May/early June
15:46:13 <JayF> Last call for the meeting
15:47:38 <JayF> Have a good week o/
15:47:39 <JayF> #endmeeting