16:00:01 #startmeeting openstack_ansible_meeting 16:00:02 Meeting started Tue Mar 30 16:00:01 2021 UTC and is due to finish in 60 minutes. The chair is noonedeadpunk. Information about MeetBot at http://wiki.debian.org/MeetBot. 16:00:03 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 16:00:06 The meeting name has been set to 'openstack_ansible_meeting' 16:00:10 o/ 16:00:18 #topic rollcall 16:01:54 o/ hello 16:03:59 #topic bug triage 16:04:15 Let's start from https://bugs.launchpad.net/openstack-ansible/+bug/1921354/ 16:04:17 Launchpad bug 1921354 in openstack-ansible "Value Error for Multiple Swift Services" [High,In progress] - Assigned to Dmitriy Rabotyagov (noonedeadpunk) 16:05:33 errr 16:05:42 ok, according to the last comment, I think he just pulled instead of cherry-picked 16:07:25 but also the last task is 'install python packages into the venv' but we still see the src url to install git+https://opendev.org/openstack/swift@26a20516005b1eca162da7f1d203c413e27c6104#egg=swift 16:07:28 thats wrong 16:07:55 yeah, that's from master 16:09:14 btw, there's another topic from the same user in ML 16:09:40 http://lists.openstack.org/pipermail/openstack-discuss/2021-March/021144.html 16:09:51 there're quite a lot mails atm... 16:10:38 http://lists.openstack.org/pipermail/openstack-discuss/2021-March/021386.html that's by far the last one.... 16:15:42 ok, let's go forward 16:15:45 https://bugs.launchpad.net/openstack-ansible/+bug/1921861 16:15:46 Launchpad bug 1921861 in openstack-ansible "Add table encryption support?" [Undecided,New] 16:15:59 that;'s really interesting, and looks pretty valid 16:16:02 what do you think? 16:16:17 i just tried to reply to the lxc/dnsmasq mail and deleted it instead :( 16:16:50 I think I missed that one as ususal:( 16:17:40 oh actually i think he fixed it 16:18:04 i need to improve my mail filter, i'm missing a lot of these 16:20:10 yes so the db encryption stuff looks good - would probably want some value from user_secrets to be used as the key 16:22:10 yeah 16:22:24 I miss so _much_ stuff 16:22:47 but my biggest issue are gerrit email and have no idea how to filter out zuul there... but oftopic 16:22:48 though it's a bit odd though, encryption-at-rest with the decryption key also stored on the node? 16:23:35 from: 16:24:25 But I mean it would filter both zuul and comments the same way. It's just sender name that differs, not email 16:25:06 hm, yeah, I guess key should be on the deploy host? 16:25:40 file_key_management_filekey = FILE:/etc/mysql/encryption/.keyfile.key 16:25:46 ^ that just can't be right 16:26:09 but it then leads on to what you do to restart the service 16:26:45 (we've been messing with vault today, all this crypto chicken/egg stuff is fresh in my mind) 16:27:41 well, according to doc, vault is not supported there yet, only file, aws and Eperi? 16:28:36 so not huge amout of options 16:28:55 Well, I think that he should fire up a patch, and we will be able to comment it then? 16:29:53 yes thats probably best 16:30:04 maybe need a good explanation of the use case 16:30:17 becasue if someone steals your server they have the db and the key 16:30:54 but perhpas the risk is some adjacent process getting compromised and being able to read the disk 16:30:55 well, I think if we have that set, and AWS key storage is an option, it would be better 16:31:47 would require to insall extra plugin though 16:32:21 timezone shift means i need to be out for a bit now 16:32:45 ok 16:32:59 https://etherpad.opendev.org/p/osa-wallaby still relevant for what needs pushing forward 16:33:20 i looked at some of the policy patches and there were some handlers not all the same, didnt know if that was intended 16:33:21 #topic office hours 16:33:37 * jrosser has to go 16:34:16 trove is also unblocked 16:34:39 but it has so much to adjust... 16:34:58 Today I pushed some patches to add support of image tags to collections and openstacksdk 16:35:35 because what we have in octavia is not cool regarding image upload https://opendev.org/openstack/openstack-ansible-os_octavia/src/branch/master/tasks/octavia_amp_image.yml 16:36:35 Also we need to merge https://review.opendev.org/c/openstack/openstack-ansible-os_cinder/+/782963 for V 16:51:37 And vote for https://review.opendev.org/c/openstack/openstack-ansible/+/783720 would be awesome, since it fixes fuctional jobs 16:52:03 that I just learned, used not only in osa, but also for sahara, and they're voting 16:52:12 https://zuul.opendev.org/t/openstack/build/fe2c21b0087b4d81b9d5503f23984f6b 17:00:36 #endmeeting