16:02:38 #startmeeting openstack_ansible_meeting 16:02:39 Meeting started Tue Dec 5 16:02:38 2017 UTC and is due to finish in 60 minutes. The chair is evrardjp. Information about MeetBot at http://wiki.debian.org/MeetBot. 16:02:40 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 16:02:42 The meeting name has been set to 'openstack_ansible_meeting' 16:02:48 #topic rollcall 16:02:56 anyone here? 16:03:06 o/ 16:03:08 i'm here :D 16:03:36 noope not here 16:03:42 I know the integrated build is borked, and I will think of a way to either revert the whole thing or go ahead. But bug triage time first:) 16:03:48 I'm here. 16:03:56 #topic pending bugs 16:04:07 woot we are 5, I think we can go ahead. 16:04:11 so. 16:04:14 #link https://bugs.launchpad.net/openstack-ansible/+bug/1736087 16:04:14 Launchpad bug 1736087 in openstack-ansible "Run playbooks in OpenStack-Ansible" [Undecided,New] 16:04:24 Merged openstack/openstack-ansible-os_sahara master: Remove pip_install dependency https://review.openstack.org/525564 16:04:41 incomplete? 16:04:54 yeah 16:05:06 the title needs some fixing too... 16:05:22 yeah... 16:05:36 but I can't change it until I understand :) 16:05:39 next 16:05:42 #link https://bugs.launchpad.net/openstack-ansible/+bug/1735994 16:05:42 Launchpad bug 1735994 in openstack-ansible "OSA AIO build fails on CentOS7 stable/pike during 'TASK [pip_install : Install EPEL and yum priorities plugin]' on first run" [Undecided,New] 16:06:00 mgariepy: what's your opinion on this one? 16:06:41 Cannot find a valid baseurl for repo: base/7/x86_64 makes me think it's not an OSA issue, but apparently it doesn't cause issues before running OSA? 16:06:48 network issue ? ,maybe the repos were down. ? 16:07:50 copr ? 16:08:05 this is anoying 16:08:24 Merged openstack/openstack-ansible-os_horizon master: Remove pip_install dependency https://review.openstack.org/525553 16:08:58 mgariepy: Or sometimes just a bad mirror too 16:09:47 I don't know which one, I hoped that with base/ and the files someone would understand better than me:) 16:09:56 ok so how do we mark this? 16:10:14 I think that if one repo is down it will prevent yum to work as expeected 16:10:15 unconfirmed? 16:10:16 Asking if the issue still appears? 16:10:30 yeah that's true mgariepy 16:10:43 since it doenst know what pkg are in the failing repo. 16:10:49 Yeah it'll bork everything 16:11:14 kinda like if apt-get update has an error for a GPG key it stops 16:11:32 ok I'll ask if that was a transient issue, and if not, I will ask to have more details about which repo is failing. 16:12:02 +1 16:13:09 perfect. 16:13:20 next 16:13:23 #link https://bugs.launchpad.net/openstack-ansible/+bug/1735942 16:13:23 Launchpad bug 1735942 in openstack-ansible "github" [Undecided,New] - Assigned to Amy Marrich (amy-marrich) 16:13:29 invalid? 16:13:47 I'll double check it, I think it's similar to the repo issue that it can be transient 16:14:19 i dont understand this bug (and the title is again awful) 16:14:27 hwoarang: agreed :) 16:14:53 hwoarang: for me, the bug poster says that https://git.openstack.org/openstack/openstack-ansible isn't reachable. 16:15:35 it works for me 16:15:40 evrardjp: That's how I read it and he could only clone when he added the .git likn 16:15:56 I think he could only clone when he moved to github 16:16:01 hence the title 16:16:37 evrardjp: So maybe we just add both options but stress the openstack.org link is the real one and the github is a mirror that could be out of date 16:16:53 oh I see what you mean spotz 16:17:04 yeah we could change the docs 16:17:19 Ok I will rename the bug to 16:17:53 maybe he is behind firewall or something ;p 16:17:59 In case of temporary sync issues to github, mark the source of repo to clone to git.openstack.org and github.com in the docs. 16:18:15 hwoarang: maybe 16:18:31 hwoarang: I've seen it happen, whether it's DNS or something else.No harm providing an alt in the docs 16:18:41 sure 16:18:55 I'm definitely not behind a firewall:) 16:19:20 confirmed and wishlist 16:19:24 ok for everyone? 16:19:43 next 16:19:43 Yeah I took like 3 docs related ones, should have some time to know them out this week 16:19:46 #link https://bugs.launchpad.net/openstack-ansible/+bug/1735709 16:19:46 Launchpad bug 1735709 in openstack-ansible "Grub authentication is not applied on Fedora 26 and Ubuntu 16.04 (at least)" [Undecided,New] - Assigned to Major Hayden (rackerhacker) 16:20:28 maybe he have MTU ussues 16:21:46 ? 16:21:52 how is that related to grub? 16:22:09 lagg, github stuff 16:22:55 New feature for grub not getting applied? 16:23:16 It looks serious to me 16:23:34 but I cannot confirm I haven't configured grub for ages. 16:23:48 evrardjp: I'm a grub v1 person:) 16:24:10 (nit hte title should be about ansible-hardening not openstack-ansible) 16:24:15 mhayden thought it important enough to grab it, so I'd give it at leat a medium? 16:24:42 trying to get more info from the reporter 16:24:57 seems like our current process gets it close but doesn't do a final step perhaps 16:25:09 mhayden: should we leave it as new? 16:25:18 this way we talk about it next week 16:25:32 ok for everyone? 16:25:44 ok 16:25:51 #link https://bugs.launchpad.net/openstack-ansible/+bug/1735644 16:25:51 Launchpad bug 1735644 in openstack-ansible "Wrong filename of "os_horizon : Enable the neutron-fwaas-dashboard Horizon panel"" [Undecided,New] 16:25:55 incomplete? 16:26:56 #link https://bugs.launchpad.net/openstack-ansible/+bug/1733540 16:26:56 Launchpad bug 1733540 in openstack-ansible "Prepare the deployment host in OpenStack-Ansible" [Undecided,New] - Assigned to Amy Marrich (amy-marrich) 16:27:04 let's move to next one ^ 16:27:15 spotz: do you deal with the gating? 16:27:25 I think this bug can be marked as confirmed 16:27:30 I confirm it right now :p 16:27:35 I think odyssey4me worked on this 16:27:43 evrardjp: I figured I'd hit docs up. SOmetimes we just need something 'new' to get stuff to build 16:28:13 evrardjp: If odyssey4me is already working oon it pass it to him though 16:28:33 odyssey4me: is sick, so we should deal with that right away 16:28:40 marking it as confirmed and high 16:28:48 critical 16:29:10 ok for everyone? Gates publication are obviously wrong, so it needs quick fixing... 16:29:18 Ok let me go hit docs up now. I took one other ping if you need me backin thise channel 16:29:43 we can finish the triage first, don't worry :) 16:30:27 ok next 16:30:29 #link https://bugs.launchpad.net/openstack-ansible/+bug/1732786 16:30:29 Launchpad bug 1732786 in openstack-ansible "update pw-token-gen.py" [Undecided,New] 16:30:53 might take that long for someone in docs to reply:) Chennel is quiet 16:31:05 I'd say confirmed wishlist 16:31:15 it's not bad but I can see the improvement there 16:31:25 Manuel Buil proposed openstack/openstack-ansible-os_neutron master: Provide support for SFC deployments https://review.openstack.org/510909 16:31:45 ok for confirmed/wishlist everyone? 16:31:50 yeah 16:31:56 ok next 16:32:02 #link https://bugs.launchpad.net/openstack-ansible/+bug/1732528 16:32:02 Launchpad bug 1732528 in openstack-ansible "playbook creates duplicate configuration lines" [Undecided,New] 16:32:43 hmm 16:32:51 not sure to understand 16:32:58 I have submitted a comment just right now 16:33:16 I have definitely NO CLUE of what's going on there. 16:33:49 duplicatioon steps needed? 16:34:01 yeah I think so 16:34:20 Incomplete then? 16:34:51 ok next... 16:34:54 #link #link https://bugs.launchpad.net/openstack-ansible/+bug/1732481 16:34:54 Launchpad bug 1732481 in openstack-ansible "qemu config should set security driver to apparmor on ubuntu" [Undecided,New] 16:34:55 #link https://bugs.launchpad.net/openstack-ansible/+bug/1732481 16:36:53 confirmed medium? I'd say high due to the importance, but because even the reporter isn't 100% sure this is the cause of an issue (vs a new feature), I'd limit to medium. 16:38:17 guys we are not even at the third of the elements to triage... 16:38:19 medium 16:38:34 ok thanks for the confirmation! 16:38:48 #link https://bugs.launchpad.net/openstack-ansible/+bug/1731186 16:38:48 Launchpad bug 1731186 in openstack-ansible "vpnaas_agent.ini wrong config" [Undecided,New] 16:38:53 20 minutes remaining! 16:39:32 this is not even a path we've followed in our gates... 16:39:34 evrardjp: I havn't played with the vpn stuff to know if he's right or wrong:( 16:39:39 yeah 16:39:41 same fo rme 16:39:50 let's leave it open for now, because we can't triage it 16:39:57 next 16:40:01 #link https://bugs.launchpad.net/openstack-ansible/+bug/1730998 16:40:01 Launchpad bug 1730998 in openstack-ansible "ClamAV update fails if install forces update" [Undecided,New] 16:40:45 I'd say confirm and medium, and we already have a fix, so low_hanging_fruit on top 16:40:54 or confirmed and low 16:40:54 sounds good 16:41:14 I'd say low, there is no big urgency 16:41:19 if we tag it low haning we should probably go with low 16:41:22 sorry for my change of mind :) 16:41:25 hehe 16:41:25 ok 16:41:39 So glad you can read my typos:) 16:42:04 I didn't even notice there was a typo, I just read it! 16:42:06 :D 16:42:08 amazing! 16:42:19 heheh, next! 16:42:22 * evrardjp has english skills +1 16:42:25 #link https://bugs.launchpad.net/openstack-ansible/+bug/1730722 16:42:25 Launchpad bug 1730722 in openstack-ansible "Pike Horizon Image Create Fails" [Undecided,New] 16:43:56 If we can't create images that's high. But I'm not seeing where it's horizon and not glance except for the fact CLI does work 16:44:38 so unless we're doing something to the horizon local_settings.py this could be a real horizon bug? 16:45:39 I don't think we have enough information. It should work. 16:47:05 asked a few questions 16:47:16 I'll mark it as incomplete 16:47:30 next 16:47:33 #link https://bugs.launchpad.net/openstack-ansible/+bug/1730688 16:47:33 Launchpad bug 1730688 in openstack-ansible "Missing document for link http://docs.openstack.org/developer/openstack-ansible/developer-docs/inventory.html " [Undecided,New] - Assigned to Amy Marrich (amy-marrich) 16:49:14 looks confirmed and high 16:49:28 I'll get the linkage fixed and we can always re-address a rewrite if needed 16:49:38 ok 16:49:54 next 16:49:57 #link https://bugs.launchpad.net/openstack-ansible/+bug/1729792 16:49:57 Launchpad bug 1729792 in openstack-ansible "openstack ansible error when execute setup-openstack.yml" [Undecided,New] 16:51:32 I'd say we should either mark this as invalid or confirmed low 16:51:44 hwoarang: what do you think? 16:52:01 yep 16:52:36 ok next 16:52:39 #link https://bugs.launchpad.net/openstack-ansible/+bug/1729661 16:52:39 Launchpad bug 1729661 in openstack-ansible "Map instances to new Cell1 takes excessive amounts of time to run on upgraded cloud" [Undecided,New] 16:52:57 logan-: 's bug 16:53:09 confirmed and wishlist for now? 16:53:26 sur 16:53:46 next 16:53:49 #link https://bugs.launchpad.net/openstack-ansible/+bug/1729525 16:53:49 Launchpad bug 1729525 in openstack-ansible "Can't run bootstrap_ansible with encrypted user_secrets.yml (prompting for password) " [Undecided,New] 16:55:21 the problem of --ask-vault-pass is that it will systematically ask the vault pass, even if there is no vaulted file. On top of that, that's very intrusive. 16:55:58 I see a value of the encrypted passwords, if we backup. 16:56:11 but I'd rather backup something unencrypted, and have encrypted backups. 16:56:21 but again, that's me 16:56:33 and I like the idea of using vault 16:56:36 can we pull from barbican or something? 16:56:39 ansible-vault* 16:56:43 k 16:56:56 nah that would be too tedious, no openstack is available there. 16:57:12 I'd say that we should be able to take CLI arguments, and I don't understand why this wouldn't work 16:57:33 so what's the question here? use --ask-vault-pass when we detect an encrypted user_secrets? 16:58:35 no because any user_* variable file could be encrypted 16:58:39 we cannot detect reliably 16:58:40 just pass it if provided 16:58:50 yeah but it says it doesn't work 16:59:16 :however there's no way to pass '--ask-vault-pass' to that wrapped execution" 16:59:21 "however there's no way to pass '--ask-vault-pass' to that wrapped execution" * 17:00:08 right 17:00:49 basically just need a way to provide args to https://github.com/openstack/openstack-ansible/blob/master/scripts/bootstrap-ansible.sh#L285-L288 17:00:56 ok just tested, and it works. 17:02:10 he could workaround it with ANSIBLE_VAULT_PASSWORD_FILE in environment but thats not always preferable to providing the password directly on terminal 17:02:41 yeah 17:02:56 well it works for me to do openstack-ansible --ask-vault-pass 17:03:09 yeah that'll work 17:03:20 ok 17:03:27 so I'll mark this as incomplete 17:03:35 because I don't understand the issue :) 17:03:38 it is complete 17:03:44 oh 17:03:46 so invalid? 17:03:48 the github link above ^ 17:04:03 aside from envvar there is no way to pass the vault pass arg to that 17:04:22 but that doesn't matter for this part 17:04:23 we should just support ANSIBLE_PARAMETERS env like other places I guess 17:04:28 does it? 17:04:34 I think on rebootstrap it might 17:04:38 in an existing env with vars files deployed 17:05:05 oh i see 17:05:11 but this doesn't take env vars 17:05:12 he is running it directly without bootstrap-ansible 17:05:19 so it is going thru the wrapper 17:05:40 oh yeh I see 17:06:01 from my ansible.cfg vault_password_file=pull_vault_password.sh <- is that any help? 17:06:01 i think calling it ansible-playbook directly in the venv will work like we do in bootstrap-ansible 17:06:05 because it won't load the vars then 17:06:35 logan-: yeah 17:06:44 so I think it's an invalid bug here. 17:06:55 yeah 17:07:08 ok 17:07:12 we are done for today 17:07:16 thanks everyone! 17:07:23 #endmeeting