Tuesday, 2019-04-16

*** markvoelker has quit IRC00:00
clarkbok well maybe I should go find dinner while we wait on round two here00:01
*** tosky has quit IRC00:01
clarkbI suppose it is somewhat possible that py35 issues are related to the change? Though py36 and py37 (locally) both work00:01
clarkbyup dinner is happening I'll check in after for merged code and if things ahve merged look to restart the scheduler00:06
pabelangerack00:06
*** yamamoto has joined #openstack-infra00:13
*** bobh has quit IRC00:14
*** ijw has joined #openstack-infra00:16
*** yamamoto has quit IRC00:22
*** bobh has joined #openstack-infra00:23
*** bobh has quit IRC00:24
*** rlandy|ruck has quit IRC00:24
*** bobh has joined #openstack-infra00:25
*** bobh_ has joined #openstack-infra00:28
*** bobh has quit IRC00:33
*** mattw4 has quit IRC00:37
*** lseki has quit IRC00:37
openstackgerritIan Wienand proposed openstack-infra/system-config master: [wip] letsencrypt update idea  https://review.openstack.org/65280100:37
*** roman_g has quit IRC00:39
*** kgiusti has left #openstack-infra00:41
mnaserinfra-root: I think I've discovered the issue of our strange hands.  I think there may be a an ansible repo that has a problem that is resulting in our roles failing to clone00:45
mnasertry this: for i in `seq 20`; do rm -rf ansible-role-python_venv_build; git clone https://git.openstack.org/openstack/ansible-role-python_venv_build; done00:45
mnaserat some point, I get "fatal: The remote end hung up unexpectedly"00:45
mnaserin one of the attempts00:45
mnaseroh this is even weirder00:46
mnaserhttps://www.irccloud.com/pastebin/VvuzI3oD/00:47
mnaserit looks like the commits for stable/stein are somehow flipping changing around?00:47
pabelangermnaser: maybe issue with one of git servers? And since going via load balancer, you are bouncing around00:47
ianwbad node in the load balancer?00:47
mnaserthat's my guess00:48
pabelangermnaser: you could try cloning directory to each, to find which repo is the issue00:48
mnaseroh that's a good idea00:48
mnaserhow many git servers are there?00:48
clarkb800:48
mnasergit0[1-8] right?00:48
clarkband they listen on 8080 and 444300:48
clarkbyup00:48
pabelangerhttp://git01.openstack.org:8080/cgit00:48
pabelangeryah00:48
*** yamamoto has joined #openstack-infra00:49
mnaserhmm interesting it cloned fine from all 800:49
mnaserbut over http not https cause I got cert warnings00:49
mnaserim going to add them all as origins00:50
mnaserand see what I get00:50
pabelangerclarkb: what is with warnings on: https://review.openstack.org/#/c/652788/00:50
clarkbthereis a git env var to igbore cert errors00:50
pabelanger  Requirements ['docker-image'] not met by build 603f16194acc4cf5b5dec0055348be7f00:50
ianwmnaser: any chance you have timestamps?00:50
mnaserI have failing gate jobs, and it just failed locally for me too on my machine00:50
mnaserianw: http://logs.openstack.org/14/652314/1/check/openstack-ansible-deploy-aio_metal-centos-7/de04e8b/job-output.txt.gz#_2019-04-15_18_01_19_100792 is one00:51
clarkbpabelanger it means the image build ended uo in limestone and skipped iirc00:51
clarkbpabelanger: when we restart zuul.those will be failures00:51
ianwmnaser: hrm, so i think this lines up -> http://paste.openstack.org/show/749331/00:52
mnaseryeah we do a lot of clones so it may be hard to tell what/who00:53
mnaserbut looping over all 8 gits00:53
mnaserhasn't resulted in any problems00:53
pabelangerclarkb: kk00:53
mnaser for i in `seq 20`; do rm -rf ansible-role-python_venv_build; git clone https://git.openstack.org/openstack/ansible-role-python_venv_build; done <-- this replicates it, let me try that on each server00:53
pabelangerclarkb: should we recheck them to be safe?00:54
*** bobh_ has quit IRC00:54
ianwmnaser: what ip is that coming from?  i can filter the logs for that00:54
mnaserianw: right now im doing them from our office so 173.176.58.6900:55
mnaserthere should be a few failures not long ago hitting the main endpoint00:55
mnaserim just trying 20 attempts on each git0X right now00:55
mnaserwonder if it could be a maxconn thing, are haproxy stats exposed anywhere00:55
ianwmnaser: ok, i see them from a while ago00:56
ianwahh, i think we do send that into grafana00:56
clarkbpabelanger: I'm not too worried about it it mostly tests that the image builds which we will gate on too00:56
pabelangerk00:56
pabelanger652787 failed again00:56
mnaserhttp://grafana.openstack.org/d/MYvSHcSiz/git-load-balancer?orgId=1 this one00:56
pabelangergearman connection loss00:57
pabelangerrechecked00:57
ianwmnaser: yep, jinx :)00:57
mnaserok.  I just ran 20 'clones' against every individual git server, with no issues00:58
ianwmnaser: ok, seeing requests for git.o.o00:58
mnaserbut against the LB, 5/20 resulted in fatal: The remote end hung up unexpectedly00:58
*** bobh has joined #openstack-infra00:58
mnaserlemme try to do this for another repo00:58
*** bobh has quit IRC00:59
mnaser(it always seem to hang on this one)00:59
mnaserok01:00
ianwmnaser: maybe tcpdump on your end so we could see the outgoing port?  is there another way to narrow that down?01:00
mnaserstable/stein is two different things01:00
mnaseron different git servers01:00
mnasergit0{1,2,3,4,7,8} have -- Merge "Ensure venv_wheel_build_enable is evaluated as boolean" into stable/stein -- as HEAD of stable/stein01:01
mnasergit{5,6} have -- Merge "Ensure the build host is the first repo server" into stable/stein -- as HEAD of stable/stein01:02
mnaserhttp://git01.openstack.org:8080/cgit/openstack/ansible-role-python_venv_build/ vs http://git05.openstack.org:8080/cgit/openstack/ansible-role-python_venv_build/01:02
ianwi'm not seeing any puppeting errors for 5/6 on bridge.o.o at least01:02
ianwso they are minimally alive01:03
ianwroot     10085 10060  0  2018 ?        00:00:00 git fetch-pack --stateless-rpc --stdin --lock-pack --include-tag --thin --no-progress https://git.openstack.org/openstack-infra/project-config/01:06
ianwi'm guessing that's not working ...01:06
mnaseryeah that can do it01:10
mnaserI guess01:10
mnaserI dunno how we're getting hit by it01:10
*** bobh has joined #openstack-infra01:11
ianwthe last replication attempt for this was -> http://paste.openstack.org/show/749332/01:12
ianwwhat's the missing change?01:13
*** eharney has quit IRC01:14
ianw652252,201:15
mnaserianw: yep01:17
ianw[root@git05 ansible-role-python_venv_build.git]# ls refs/changes/10/652610/01:17
ianw101:17
ianwhttp://paste.openstack.org/show/749333/01:18
ianwi dunno what to make of that log01:18
ianwdoes NOT_ATTEMPTED actually mean it wasn't attempted?01:19
mnaserthats beyond my knowledge :)01:20
paladoxYup.01:20
ianwi think it's a red herring01:21
ianwhttp://paste.openstack.org/show/749334/ ... it completed ok01:25
mnaserim still seeing some inconsistency but idk01:27
*** hwoarang has quit IRC01:28
mnasercgit still shows things are different01:28
ianwf88af92dd34e2fe3e10f7af0e106d4e001285345 is in the git05 repo01:28
*** hwoarang has joined #openstack-infra01:28
ianwbut refs/heads/stable/stein is different!01:28
mnaseryeeeep01:29
ianwhttp://paste.openstack.org/show/749335/01:31
ianwCancelling replication event [d231dcdd] push cgit@git05.openstack.org:/var/lib/git/openstack/ansible-role-python_venv_build.git ?01:31
ianwoh dear ...01:33
clarkbfungi and dmsimard were debugging replication issues earlier today01:34
dmsimardo/01:34
ianwhttp://paste.openstack.org/show/749336/01:34
clarkbfor that we may want to force replication on that repo?01:34
ianwis it possible creating a new repo has wiped out all the pending replications?01:35
dmsimardthe issue was that the pattern for github was not matching due to lack of ^ at the beginning of the pattern01:35
* dmsimard reads back01:35
ianw$ cat replication_log.2019-04-15 | grep ff6a8e3f | grep 'Cancelling ' | wc -l01:36
ianw3238901:36
ianwif i haven't messed that up ... does that mean we dropped 32,389 replication tasks?01:36
mnaseruhoh01:37
mnaserwhy is there 32389 replication tasks for ff6a8e3f ? :\01:37
mnaseralso this was replication to the openstack git farm and not github01:37
*** jamesmcarthur has joined #openstack-infra01:37
ianwi think that's just the internal task id01:37
dmsimardwhat time are those ? do they match roughly 13 hours ago ?01:37
ianwthat's utc01:38
openstackgerritTrinh Nguyen proposed openstack-infra/irc-meetings master: Add Telemetry team meeting  https://review.openstack.org/65280901:38
dmsimardthe replication spam was likely while I was fixing the broken github replication01:38
ianwsince it's 01:37 UTC, and that happened at about 13:00 ... that's ~ 12-13 hours01:38
dmsimardok I'm caught up :D01:39
dmsimardnow what's wrong ?01:39
ianwdmsimard: well, TLDR afaict atm is that at 2019-04-15 13:07:07,797 it looks like we dropped all pending replication tasks in gerrit01:40
ianwand it looks like the git mirrors are out of sync01:40
dmsimardbut they were rescheduled afterwards, no ?01:40
dmsimardok I'm at an actual keyboard now01:42
ianwhrm, checking queu01:42
ianwthere is no replication queue in "show-queue"01:44
clarkbsoo maybe we just needed to force a rereplication globally after fixing the config?01:44
clarkbthere is a replication ssh command to do that01:44
ianwhttp://paste.openstack.org/show/749335/ appears to be the lifecycle of how the stein ref got missed on git0501:44
*** bhavikdbavishi has joined #openstack-infra01:45
ianwclarkb: replication start --all ?01:45
dmsimardthere is a pattern01:46
clarkbthat sounds right01:46
dmsimardbut yeah you can run everything :p01:46
ianwok; any idea why we had all those replications in the queue that got cancelled?01:47
clarkbit wont be quick but should resolve the discrepancies01:47
dmsimardianw: It might coincide with a reload of the config file01:47
ianwdmsimard: is it likely you had maybe triggered that?  and then a new project creation came along and cancelled everything in flight?01:47
dmsimardthe project creation had worked01:47
dmsimardbut it had not been replicated to github01:48
dmsimarddue to the missing ^01:48
ianwi don't know why the new project seemed to cancel everything ... http://paste.openstack.org/show/749336/01:48
ianwdmsimard: is openstack-infra/publications invovled ?01:48
ianwor was, rather01:48
dmsimardnot afaik, the new project was openstack/networking-omnipath I believe01:49
dmsimardfrickler pointed out that there are errors in the jeepyb logs because it tries to create the github repos for ara but they've been moved01:49
dmsimardI did not have the time to look into this one but it didn't seem fatal01:50
dmsimardI see those as separate problems, though01:51
ianwthis looks like omnipath -> http://paste.openstack.org/show/749337/01:52
*** whoami-rajat has joined #openstack-infra01:53
openstackgerritMerged openstack-infra/zuul master: Fix dynamic loading of trusted layouts  https://review.openstack.org/65278701:53
ianwi feel like what might have happened her is that the reload has triggered a global replication event; and i don't know why but it looks like a new project creation has cancelled all inflight events01:53
ianwso, any objection if i start a replication start --all to try and get us back in sync?01:53
clarkbI think dmsimard updating the replication config may have cancelled the events01:54
dmsimardianw: +1 on replication start01:55
dmsimardit can't hurt :)01:55
clarkband ya ++ to rerunning01:55
ianwclarkb: oh, that would make sense.01:55
ianwso takers on why a new project cancels all replication?01:56
dmsimardit wasn't the new project01:56
dmsimardor maybe it was01:56
dmsimardI'm confused01:56
ianw"cancelling replication event" (the error we get) appears to have no google hits01:56
clarkbI think it wasthe replication config that cancelled it not the new project?01:57
clarkbbefore we only ever changedthe config by restarting gerrit01:57
clarkbwhich then did a full replication01:57
ianwclarkb: i dunno, i'm going on the event id in http://paste.openstack.org/show/749336/01:57
clarkbbut now we can updatethe config with auto reload01:58
clarkbianw what is the timestamp on review_site/etc/replication.config?01:58
clarkbwe autoreload replication config on changes to that file now. if the timestamp on the file matches the events that may explain it01:59
ianw$ ls -l replication.config01:59
ianw-r--r--r-- 1 root root 3736 Apr 15 17:28 replication.config01:59
*** apetrich has quit IRC01:59
dmsimardianw: probably puppet once I removed the emergency file02:00
ianw  37435 tasks after the "replication start --all"02:00
dmsimardmaybe we can see matching logs around 17:2802:00
ianwwhich is the region of the ~32,000 that got cancelled02:00
*** bobh has quit IRC02:01
ianwyah, so the question for me now is what may jump in and kill this replication, leaving us again inconsistent02:01
ianwsomething touching replication.config?02:01
dmsimardcan we reproduce it ?02:02
clarkbthat is my hunch since we just updated gerrit to autoreload the replication config02:02
dmsimardif we can I would file a bug -- things should be rescheduled appropriately02:02
ianwhrm, yeah, so maybe that points at the replication *not* being rescheduled ... i can not see that it was02:03
ianw(i think that's the same thing dmsimard just said :)02:03
*** ijw has quit IRC02:04
dmsimardout of curiosity, was it a conscious decision to have gerrit push to gitea ? gitea has a built-in mirror feature but I don't know what kind of latency we'd be looking at02:04
ianwwould touching replication.config now replicate it?02:04
clarkbdmsimard: Im not sure what we would get turning ut the other way around02:07
clarkbthis way we get gerrit events and very quick updates02:07
dmsimardyes, this is probably me being curious about the mirror feature more than anything else :p02:08
*** jamesmcarthur has quit IRC02:08
openstackgerritMerged openstack-infra/zuul master: Config errors should not affect config-projects  https://review.openstack.org/65278802:10
*** hongbin has joined #openstack-infra02:12
*** bhavikdbavishi1 has joined #openstack-infra02:13
*** bhavikdbavishi has quit IRC02:14
ianwi guess we can just put this down to weirdness around playing with replication at this point, i'll stamp a log in case we have more issues02:16
ianw#status log started re-replication of all projects on review.openstack.org to bring everything in sync due to some missing references on git servers; likely related to one-off replication reconfiguration previously02:17
openstackstatusianw: finished logging02:17
*** bhavikdbavishi1 has quit IRC02:18
*** bhavikdbavishi has joined #openstack-infra02:20
*** bhavikdbavishi1 has joined #openstack-infra02:24
clarkbpuppet should update zuul01 to the change that just merged above in a few minutes. I'll be restarting the zuul scheduler at that point02:24
*** bhavikdbavishi has quit IRC02:24
*** bhavikdbavishi1 is now known as bhavikdbavishi02:24
openstackgerritMerged openstack-infra/zuul master: Add release note for broken trusted config loading fix  https://review.openstack.org/65279302:29
*** nicolasbock has quit IRC02:29
clarkbinfra-root zuul==3.7.2.dev85  # git sha 0bb220c is installed on zuul01 now which is the change prior to ^02:29
clarkbsince I don't need the release note for functionality I am going to save queues, stop zuul scheduler then start zuul scheduler and restore queues now02:30
clarkbhrm there are a couple tag and release things queued02:31
pabelangeryah, maybe double check with release team02:31
clarkbI guess I should wait for those to complete02:31
clarkbya I pinged them and let them know. I'll wait for the current queued things to finish02:32
*** bobh has joined #openstack-infra02:32
clarkbthere are two changes in the gate and ~2 in release/tag/release-post02:33
clarkbprobably about 15 minutes away from being able to restart the scheduler02:33
pabelangerwfm02:34
*** bobh has quit IRC02:37
*** hwoarang has quit IRC02:37
*** jamesmcarthur has joined #openstack-infra02:39
*** hwoarang has joined #openstack-infra02:39
*** ricolin has joined #openstack-infra02:45
*** jamesmcarthur has quit IRC02:46
*** weshay_pto is now known as weshay02:49
clarkbok release jobs are done02:55
clarkbproceeding with zuul scheduler restart now02:55
clarkb#status log Restarted zuul-scheduler and zuul-web on commit 0bb220c03:02
openstackstatusclarkb: finished logging03:02
clarkbpabelanger: ^ its done03:02
*** jamesmcarthur has joined #openstack-infra03:02
clarkbI think first thing tomorrow we cut a release03:02
pabelangerclarkb: great03:04
clarkband with that I'm going to call it a day03:09
pabelangerclarkb: thanks!03:10
pabelangerI am too03:10
openstackgerritIan Wienand proposed openstack-infra/system-config master: [wip] letsencrypt update idea  https://review.openstack.org/65280103:19
*** ramishra has joined #openstack-infra03:20
*** gregoryo has joined #openstack-infra03:20
openstackgerritIan Wienand proposed openstack-infra/system-config master: [wip] letsencrypt update idea  https://review.openstack.org/65280103:30
*** jamesmcarthur has quit IRC03:39
*** jamesmcarthur has joined #openstack-infra03:40
*** diablo_rojo has quit IRC03:41
*** jamesmcarthur has quit IRC03:45
*** _erlon_ has quit IRC04:05
*** imacdonn has quit IRC04:06
*** imacdonn has joined #openstack-infra04:07
*** jamesmcarthur has joined #openstack-infra04:11
openstackgerritIan Wienand proposed openstack-infra/system-config master: [wip] letsencrypt update idea  https://review.openstack.org/65280104:12
*** ykarel|away has joined #openstack-infra04:16
*** jamesmcarthur has quit IRC04:18
*** hwoarang has quit IRC04:21
*** ykarel_ has joined #openstack-infra04:22
*** zhurong has quit IRC04:23
*** ykarel|away has quit IRC04:24
*** hwoarang has joined #openstack-infra04:26
openstackgerritMerged openstack-infra/nodepool master: Fix for orphaned DELETED nodes  https://review.openstack.org/65272904:35
openstackgerritIan Wienand proposed openstack-infra/system-config master: [wip] letsencrypt update idea  https://review.openstack.org/65280104:38
*** hongbin has quit IRC04:40
*** bobh has joined #openstack-infra04:47
*** bobh has quit IRC04:51
*** e0ne has joined #openstack-infra04:53
*** auristor has quit IRC04:56
*** e0ne has quit IRC04:56
*** zhurong has joined #openstack-infra04:57
*** auristor has joined #openstack-infra05:03
*** gyee has quit IRC05:08
openstackgerritIan Wienand proposed openstack-infra/system-config master: [wip] letsencrypt update idea  https://review.openstack.org/65280105:11
*** auristor has quit IRC05:14
*** benj_ has quit IRC05:15
*** auristor has joined #openstack-infra05:18
*** e0ne has joined #openstack-infra05:21
openstackgerritTobias Henkel proposed openstack-infra/zuul master: Support fail-fast in project pipelines  https://review.openstack.org/65276405:22
*** jbadiapa has quit IRC05:25
*** e0ne has quit IRC05:25
*** benj_ has joined #openstack-infra05:26
*** kjackal has joined #openstack-infra05:29
*** ykarel_ is now known as ykarel05:31
*** quiquell|off is now known as quiquell|rover05:49
openstackgerritTobias Henkel proposed openstack-infra/zuul master: Support fail-fast in project pipelines  https://review.openstack.org/65276405:59
*** lpetrut has joined #openstack-infra06:02
*** kopecmartin|off is now known as kopecmartin06:07
*** lpetrut has quit IRC06:16
*** lpetrut has joined #openstack-infra06:16
*** kjackal has quit IRC06:23
*** pcaruana has joined #openstack-infra06:26
*** nickv1985 has quit IRC06:27
*** masayukig has quit IRC06:27
*** rpittau|afk has quit IRC06:28
*** kmalloc has quit IRC06:28
*** vdrok has quit IRC06:28
*** serverascode has quit IRC06:29
*** TheJulia has quit IRC06:29
*** kmalloc has joined #openstack-infra06:30
*** hogepodge has quit IRC06:32
*** serverascode has joined #openstack-infra06:32
*** johnsom has quit IRC06:32
*** serverascode has quit IRC06:38
*** kmalloc has quit IRC06:40
*** TheJulia has joined #openstack-infra06:43
*** markvoelker has joined #openstack-infra06:43
*** dangtrinhnt has quit IRC06:44
*** benj_ has quit IRC06:44
*** benj_ has joined #openstack-infra06:45
*** TheJulia has quit IRC06:47
*** slaweq has joined #openstack-infra06:49
*** TheJulia has joined #openstack-infra06:52
*** pgaxatte has joined #openstack-infra06:52
*** nickv1985 has joined #openstack-infra06:52
*** kmalloc has joined #openstack-infra06:53
*** rpittau|afk has joined #openstack-infra06:53
*** johnsom has joined #openstack-infra06:55
*** apetrich has joined #openstack-infra06:55
*** masayukig has joined #openstack-infra06:55
*** quiquell|rover is now known as quique|rover|brb06:55
*** hogepodge has joined #openstack-infra06:56
*** gfidente has joined #openstack-infra06:56
*** vdrok has joined #openstack-infra06:58
*** ginopc has joined #openstack-infra07:01
*** serverascode has joined #openstack-infra07:02
*** bobh has joined #openstack-infra07:04
*** e0ne has joined #openstack-infra07:06
*** rpittau|afk is now known as rpittau07:06
*** florianf has joined #openstack-infra07:07
*** quique|rover|brb is now known as quiquell|rover07:09
*** bobh has quit IRC07:09
*** e0ne has quit IRC07:09
*** e0ne has joined #openstack-infra07:16
*** rcernin has quit IRC07:20
*** tosky has joined #openstack-infra07:23
*** bhavikdbavishi has quit IRC07:28
*** dkushwaha has quit IRC07:28
*** bhavikdbavishi has joined #openstack-infra07:29
openstackgerritSimon Westphahl proposed openstack-infra/zuul master: Ensure correct state in MQTT connection  https://review.openstack.org/65293207:29
*** jbadiapa has joined #openstack-infra07:31
*** ykarel is now known as ykarel|lunch07:33
*** bobh has joined #openstack-infra07:37
*** bobh has quit IRC07:41
*** yamamoto has quit IRC07:41
*** helenafm has joined #openstack-infra07:42
*** ccamacho has joined #openstack-infra07:48
*** yamamoto has joined #openstack-infra07:48
*** iurygregory has joined #openstack-infra07:52
*** e0ne has quit IRC07:52
*** roman_g has joined #openstack-infra07:58
*** e0ne has joined #openstack-infra07:58
*** e0ne has quit IRC07:59
*** harlowja has quit IRC08:01
*** jpich has joined #openstack-infra08:03
*** johnsom has quit IRC08:04
openstackgerritIan Wienand proposed openstack-infra/system-config master: [wip] letsencrypt update idea  https://review.openstack.org/65280108:04
*** johnsom has joined #openstack-infra08:05
*** masayukig_ has joined #openstack-infra08:05
*** rpittau_ has joined #openstack-infra08:05
*** masayukig has quit IRC08:05
*** masayukig_ is now known as masayukig08:05
*** rpittau_ is now known as rpittua08:05
*** rpittua is now known as rpittau_08:05
*** rpittau has quit IRC08:06
*** rpittau_ is now known as rpittau08:06
*** kjackal has joined #openstack-infra08:06
*** florianf has quit IRC08:08
*** priteau has joined #openstack-infra08:09
*** e0ne has joined #openstack-infra08:10
openstackgerritM V P Nitesh proposed openstack/diskimage-builder master: Adding 'oel' as a new dib element  https://review.openstack.org/62550108:13
*** harlowja has joined #openstack-infra08:15
*** tkajinam has quit IRC08:24
openstackgerritIan Wienand proposed openstack-infra/system-config master: [wip] letsencrypt update idea  https://review.openstack.org/65280108:25
*** Lucas_Gray has joined #openstack-infra08:26
*** janki has joined #openstack-infra08:28
*** ykarel|lunch is now known as ykarel08:30
*** lucasagomes has joined #openstack-infra08:34
openstackgerritDaniel Mellado proposed openstack-infra/reviewstats master: Add Kuryr to projects  https://review.openstack.org/65294308:35
*** adriancz has joined #openstack-infra08:36
*** bhavikdbavishi1 has joined #openstack-infra08:37
*** bhavikdbavishi has quit IRC08:38
*** bhavikdbavishi1 is now known as bhavikdbavishi08:38
openstackgerritMerged openstack-infra/irc-meetings master: Add Telemetry team meeting  https://review.openstack.org/65280908:39
openstackgerritDaniel Mellado proposed openstack-infra/project-config master: Announce stable branches for Kuryr  https://review.openstack.org/65294708:49
*** gregoryo has quit IRC08:54
openstackgerritDaniel Mellado proposed openstack-infra/reviewstats master: Add Kuryr to projects  https://review.openstack.org/65294308:56
openstackgerritIan Wienand proposed openstack-infra/system-config master: [wip] letsencrypt update idea  https://review.openstack.org/65280109:04
openstackgerritBrendan proposed openstack-infra/zuul master: gerrit: Add support for 'oldValue' comment-added field  https://review.openstack.org/64990009:31
*** dtantsur|afk is now known as dtantsur09:35
openstackgerritIan Wienand proposed openstack-infra/system-config master: [wip] letsencrypt update idea  https://review.openstack.org/65280109:40
*** yamamoto has quit IRC09:45
*** yamamoto has joined #openstack-infra09:46
*** yamamoto has quit IRC09:46
*** yamamoto has joined #openstack-infra09:47
openstackgerritBrendan proposed openstack-infra/zuul master: gerrit: Add support for 'oldValue' comment-added field  https://review.openstack.org/64990009:49
*** yamamoto has quit IRC09:52
*** rcernin has joined #openstack-infra10:01
openstackgerritIan Wienand proposed openstack-infra/system-config master: Use handlers for letsencrypt cert updates  https://review.openstack.org/65280110:12
openstackgerritBrendan proposed openstack-infra/zuul master: gerrit: Add support for 'oldValue' comment-added field  https://review.openstack.org/64990010:27
*** yamamoto has joined #openstack-infra10:30
*** yamamoto has quit IRC10:39
*** yamamoto has joined #openstack-infra10:40
*** yamamoto has quit IRC10:47
*** nicolasbock has joined #openstack-infra10:55
*** yamamoto has joined #openstack-infra10:58
*** jpich has quit IRC10:58
*** jpich has joined #openstack-infra10:59
*** panda is now known as panda|lunch11:05
*** Lucas_Gray has quit IRC11:09
*** jpich has quit IRC11:12
*** Lucas_Gray has joined #openstack-infra11:12
*** jpich has joined #openstack-infra11:13
*** jpich has quit IRC11:14
*** pcaruana has quit IRC11:17
*** sshnaidm has quit IRC11:17
openstackgerritBrendan proposed openstack-infra/zuul master: gerrit: Add support for 'oldValue' comment-added field  https://review.openstack.org/64990011:18
*** quiquell|rover is now known as quique|rover|eat11:25
*** sshnaidm has joined #openstack-infra11:26
*** jpich has joined #openstack-infra11:30
*** jpich has quit IRC11:30
*** ccamacho has quit IRC11:34
openstackgerritTobias Henkel proposed openstack-infra/zuul master: Support fail-fast in project pipelines  https://review.openstack.org/65276411:37
*** dtantsur is now known as dtantsur|brb11:45
*** bobh has joined #openstack-infra11:48
*** Lucas_Gray has quit IRC11:52
*** lpetrut has quit IRC11:52
*** bobh has quit IRC11:53
*** lpetrut has joined #openstack-infra12:00
*** pcaruana has joined #openstack-infra12:04
*** jcoufal has joined #openstack-infra12:07
*** quique|rover|eat is now known as quiquell|rover12:07
openstackgerritboden proposed openstack-infra/project-config master: update vmware-nsx jobs  https://review.openstack.org/65268012:08
*** rh-jelabarre has joined #openstack-infra12:10
*** bobh has joined #openstack-infra12:10
*** priteau has quit IRC12:17
*** bobh has quit IRC12:18
*** priteau has joined #openstack-infra12:18
*** rlandy has joined #openstack-infra12:19
*** rlandy is now known as rlandy|ruck12:20
*** jamesmcarthur has joined #openstack-infra12:21
*** panda|lunch is now known as panda12:22
*** jpich has joined #openstack-infra12:25
*** jamesmcarthur has quit IRC12:30
*** bhavikdbavishi has quit IRC12:31
*** jbadiapa has quit IRC12:32
*** kgiusti has joined #openstack-infra12:35
*** bhavikdbavishi has joined #openstack-infra12:35
*** jamesmcarthur has joined #openstack-infra12:48
*** aaronsheffield has joined #openstack-infra12:57
openstackgerritMerged openstack-infra/nodepool master: Gather host keys for connection-type network_cli  https://review.openstack.org/65277812:58
*** jamesmcarthur has quit IRC12:58
Shrewsinfra-root: i saw that nl0[123] had nodepool-launcher restarted last night. don't see that running at all on nl04. investigating...13:00
pabelangerShrews: ah, I forgot to check nl04 yesterday, wonder if corvus did too13:01
mordredShrews: oh goodie!13:01
ShrewsApr 14 18:19:47 nl04 kernel: [38625591.436648] nodepool-launch invoked oom-killer13:04
Shrews*sigh*13:04
Shrews!status log nodepool-launcher was not running on nl04 due to OOM. Restarted13:05
openstackShrews: Error: "status" is not a valid command.13:05
Shrewsgrr13:05
Shrews#status log nodepool-launcher was not running on nl04 due to OOM. Restarted13:06
openstackstatusShrews: finished logging13:06
fungiconsistent at least13:06
fungieerie they all went at around the same timeframe13:06
*** yamamoto has quit IRC13:07
Shrewsuh... it didn't restart13:07
*** bobh has joined #openstack-infra13:07
*** pcaruana has quit IRC13:07
openstackgerritSlawek Kaplonski proposed openstack-infra/project-config master: Add openstacksdk-functional-devstack-networking job to Neutron dashboard  https://review.openstack.org/65299313:08
Shrewsok, now it is13:09
Shrewsfungi: yeah13:10
fungii suppose that points to some triggering event they share in common (central network disruption, configuration change deploy, package update)13:12
openstackgerritboden proposed openstack-infra/project-config master: update vmware-nsx jobs  https://review.openstack.org/65268013:12
mnaserhas replication caught up since yesterday btw?13:16
fungioh, yeah, that only took maybe 90 minutes once fixed and triggered13:16
*** ccamacho has joined #openstack-infra13:20
*** Goneri has joined #openstack-infra13:20
*** mriedem has joined #openstack-infra13:21
*** eharney has joined #openstack-infra13:22
*** bhavikdbavishi has quit IRC13:23
*** yamamoto has joined #openstack-infra13:24
*** yamamoto has quit IRC13:24
*** dtantsur|brb is now known as dtantsur13:24
*** yamamoto has joined #openstack-infra13:24
*** lseki has joined #openstack-infra13:25
*** yamamoto has quit IRC13:25
*** yamamoto has joined #openstack-infra13:25
*** jpich has quit IRC13:25
*** jpich has joined #openstack-infra13:26
*** egonzalez has quit IRC13:30
*** egonzalez has joined #openstack-infra13:30
*** efried_pto is now known as efried13:31
*** tobiash has quit IRC13:31
*** tobiash has joined #openstack-infra13:32
*** lennyb has quit IRC13:32
*** pcaruana has joined #openstack-infra13:33
openstackgerritMalek Karray proposed openstack-infra/storyboard-webclient master: Allowing the user to choose what Columns are seen  https://review.openstack.org/65127013:41
*** sthussey has joined #openstack-infra13:44
*** lennyb has joined #openstack-infra13:45
*** bobh has quit IRC13:50
smcginnisLooks like all release tag-release jobs failed last night with the "Unable to freeze job graph" error here: http://paste.openstack.org/show/749355/13:53
smcginnisWondering if that could be caused from https://review.openstack.org/#/c/652659/13:54
smcginnisAnd if so, how/why and wondering how we would go about increasing that job timeout.13:54
*** yamamoto has quit IRC13:57
*** yamamoto has joined #openstack-infra13:58
fungismcginnis: i think so. looks like we need that timeout set in opendev/base-jobs/zuul.yaml because tag-releases is defined there as a "final" job (meaning variants are forbidden). not sure why that didn't get raised as an error by zuul in 652659 (maybe something to do with speculative execution and opendev/base-jobs being a trusted config repo?)13:58
*** yamamoto has quit IRC13:58
smcginnisfungi: OK, we were thinking we could probably work around that timeout anyway, so I guess I can just revert that.13:59
smcginnisfungi: We had a few patches approved last night and unfortunately the error emails don't give any reference to which ones were failed.13:59
smcginnisI can figure out what was impacted, but looks like we'll have to do some kind of clean up work on those.14:00
fungioh, part of why we didn't find out until tag-releases ran is that it's not run in check/gate (for obvious reasons)14:01
smcginnisYeah, was thinking that. I don't suppose there's an easy zuul check we can run only on patches that modify zuul.yaml files?14:01
fricklerzuul still might or maybe even should be able to verify this at definition time and not only at runtime14:02
*** kopecmartin is now known as kopecmartin|off14:02
fungihrm, tag-releases isn't actually defined at opendev/base-jobs/zuul.yaml@master#11214:02
fungithat's the base job14:02
fungiconfusing error for sure14:02
frickleropenstack-infra/project-config/zuul.d/jobs.yaml@master#1089 from http://logs.openstack.org/80/804d609460e6b165e0549e6759b1d0ee277a970a/release-post/tag-releases/a1dd193/zuul-info/inventory.yaml14:03
fungihttp://zuul.opendev.org/t/openstack/job/tag-releases14:04
fungihttps://opendev.org/openstack-infra/project-config/src/branch/master/zuul.d/jobs.yaml#L108914:06
fungidoes indeed have final:true there so that's where we'd need to set the timeout if we wanted one (or remove the finality, if we determine it's an unwarranted protection in this particular case)14:06
*** ramishra has quit IRC14:06
*** markvoelker has quit IRC14:07
fricklerfungi: IIUC we want to avoid doing variants of the job that might expose the secrets, so setting the timeout in the job definition directly seems to be the proper solution14:07
fungiyeah, i guess that's more risk for jobs defining this one as a parent, not for variants?14:09
fungithough maybe there's some way to expose them with a variant too and i'm just not thinking of it14:10
*** Lucas_Gray has joined #openstack-infra14:13
frickleryeah, maybe just setting "protected" instead of "final" might be good enough in that case14:13
*** eernst has joined #openstack-infra14:13
*** jbadiapa has joined #openstack-infra14:15
*** priteau has quit IRC14:19
smcginnisJust curous, what is the functional difference between "protected" and "final"?14:24
*** iurygregory_ has joined #openstack-infra14:25
AJaegersmcginnis: you can inherit a protected only in the same repo, you cannot inherit a final job at all14:26
smcginnisMakes sense. Thanks AJaeger.14:26
*** rcernin has quit IRC14:27
*** janki has quit IRC14:27
*** iurygregory has quit IRC14:27
*** dtantsur has quit IRC14:27
*** iurygregory_ is now known as iurygregory14:27
*** dpawlik has quit IRC14:28
openstackgerritMalek Karray proposed openstack-infra/storyboard-webclient master: Allowing the user to choose what Columns are seen  https://review.openstack.org/65127014:29
*** dtantsur has joined #openstack-infra14:31
*** iurygregory_ has joined #openstack-infra14:32
*** iurygregory has quit IRC14:33
*** iurygregory_ is now known as iurygregory14:33
corvusclarkb: the registry is at 32% usage today, so i guess we have ~3 days worth of storage?  seems like we should move it to a large cinder volume.  also the docs at https://docs.docker.com/registry/garbage-collection/ (search for "Note: You should ensure that the registry is in read-only mode") explain why we always need to run gc with the registry offline -- so i guess we should plan on a nightly14:35
corvusstop/gc/start cron?14:35
*** lpetrut has quit IRC14:36
mordredcorvus: needing to stop it to gc is so cloud native14:37
*** priteau has joined #openstack-infra14:37
mgagneinfra-root: fyi, we need to perform an emergency maintenance on inap-mtl0114:37
corvusmordred: right?14:37
corvusmordred: i think after this we should find a better registry14:37
mordredcorvus: ++14:38
*** bobh has joined #openstack-infra14:39
*** quiquell|rover is now known as quiquell|off14:41
*** bobh has quit IRC14:41
mordredcorvus: maybe we shoudl consider the swift driver for the docker registry?14:44
mordredcorvus: https://docs.docker.com/registry/storage-drivers/swift/14:44
mordredI hear object storage is all the rage with the cloud-native set14:44
corvusmordred: ooh, we could avoid using cinder then (and therefore have an arbitrary cap on our size)14:44
mordredcorvus: ++14:45
corvusit looks like it can or does use tempurl?14:45
corvus(i wonder why)14:46
corvusmordred: also, check out the docs for "accesskey"14:46
mordredcorvus: that's amazing14:48
openstackgerritboden proposed openstack-infra/project-config master: update vmware-nsx related jobs  https://review.openstack.org/65268014:48
*** dklyle has quit IRC14:49
*** dklyle has joined #openstack-infra14:50
*** pgaxatte has quit IRC14:56
*** jamesmcarthur has joined #openstack-infra14:56
*** helenafm has quit IRC14:57
*** ykarel is now known as ykarel|away14:57
openstackgerritJeremy Stanley proposed openstack-infra/project-config master: Temporarily disable inap-mtl01 for maintenance  https://review.openstack.org/65301714:57
openstackgerritJeremy Stanley proposed openstack-infra/project-config master: Revert "Temporarily disable inap-mtl01 for maintenance"  https://review.openstack.org/65301814:57
fungimgagne: ^14:57
fungiconfig-core: can we get 653017 expedited for mgagne?14:57
mgagnefungi: ty14:57
clarkbreviewing now14:57
mordredrosmaita: are virtdriver image properties documented anywhere other than https://wiki.openstack.org/wiki/VirtDriverImageProperties ?14:58
mnaserfungi: +2'd14:58
clarkband I +3'd14:58
fungii've marked the revert wip for now so it won't be accidentally merged14:58
mnasermordred, corvus: the cool thing about using it with swift is afaik it doesn't proxy things through14:59
mnasercreates a one time url with tempurl and hands that over to docker client14:59
clarkbmnaser: that must be what the tmpurls are for14:59
mnaserand docker clients pull directly from object storage14:59
corvusmnaser, mordred: that explains the tempurl reqs14:59
mnaserafaik14:59
mordredah - that is pretty cool15:00
mnaserfwiw: https://opendev.org/vexxhost/ansible-role-docker-distribution :P15:00
mnaserhaven't gotten around adding CI to that though15:00
clarkbswift stores the storage size problem, but we still want to clean up after the registry. Any idea what that looks like if using swift?15:02
clarkbmaybe we can configure it to set expire dates on the swift objects?15:02
mnaserhttps://github.com/docker/distribution/blob/0d3efadf0154c2b8a4e7b6621fff9809655cc580/registry/storage/driver/swift/swift.go#L605-L65815:03
mnaserhttps://github.com/lazyfrosch/docker-registry-cleanup is an interesting approach15:05
mnaserit starts it up in read only mode15:05
*** iurygregory has quit IRC15:05
*** kaiokmo has quit IRC15:06
rosmaitamordred: https://docs.openstack.org/glance/latest/admin/useful-image-properties.html15:06
*** yboaron has quit IRC15:07
mordredrosmaita: thanks! I also bugged the nova folks about it and made some grumpy noises about trait:<trait-name> in their channel15:07
rosmaitamordred: a problem with cross-project stuff is that nothing is ever completely up to date15:08
*** sreejithp has joined #openstack-infra15:09
openstackgerritBen Nemec proposed openstack-infra/reviewstats master: Remove some non-oslo projects from oslo.json  https://review.openstack.org/65302315:18
openstackgerritBen Nemec proposed openstack-infra/reviewstats master: Load subproject data from governance  https://review.openstack.org/65302415:18
openstackgerritMerged openstack-infra/project-config master: Temporarily disable inap-mtl01 for maintenance  https://review.openstack.org/65301715:22
*** ykarel|away is now known as ykarel15:22
*** hamzy has quit IRC15:22
*** mujahidali has joined #openstack-infra15:24
*** pcaruana has quit IRC15:27
openstackgerritsebastian marcet proposed openstack-infra/openstackid-resources master: Updated validation rules  https://review.openstack.org/65302715:27
openstackgerritMerged openstack-infra/openstackid-resources master: Updated validation rules  https://review.openstack.org/65302715:28
*** pcaruana has joined #openstack-infra15:30
*** e0ne has quit IRC15:31
*** iurygregory has joined #openstack-infra15:31
Shrewsinfra-root: i'd like to add some logging lines to the launcher on nl04 and restart it to track down an annoying issue. Any issues with me doing that now-ish?15:38
fungino objection from me15:38
clarkbI have no objection. Beware the ansible/puppet setting things back unexpectedly if you don't add it to hte emergency file15:39
*** pcaruana has quit IRC15:40
*** pcaruana has joined #openstack-infra15:46
openstackgerritFabien Boucher proposed openstack-infra/zuul master: WIP - Pagure driver - https://pagure.io/pagure/  https://review.openstack.org/60440415:46
Shrewsok, got what i needed. running as normal now15:46
*** gyee has joined #openstack-infra15:50
*** nickv1985 has quit IRC15:54
*** nickv1985 has joined #openstack-infra15:54
*** pcaruana has quit IRC15:55
*** bhavikdbavishi has joined #openstack-infra16:00
*** ykarel is now known as ykarel|away16:00
*** pcaruana has joined #openstack-infra16:02
Shrewsamorin: I just sent you an email regarding a problematic instance we have in OVH. Hoping you can help when you get the chance.16:02
*** jpich has quit IRC16:04
*** jamesmcarthur has quit IRC16:04
*** dtruong has left #openstack-infra16:05
clarkbprometheanfire: tonyb[m] github is complaning about our sqlalchemy requirement. Says we should bump to >= 1.3.016:06
*** ykarel|away has quit IRC16:07
*** lucasagomes has quit IRC16:07
*** pcaruana has quit IRC16:08
fungiclarkb: you looked at the root alias inbox, huh?16:13
*** jamesmcarthur has joined #openstack-infra16:13
fungii've been systematically moving those to the service.github mailbox. i recommend you don't peek in there16:14
clarkbfungi: those actually still go to my gmail account too because I haven't removed my personal user. We keep finding a new reason the github sahred account needs updating so I haven't removed mine yet16:14
fungiwe get dozens of notifications a day from them on average16:14
clarkbbut ya I also occasioanlly peak into that imap connection16:14
fungiincluding yesterday(?) when they notified us of vulnerabilities for the wrong version of ansible16:15
clarkbmy all time favorite was demanding we upgrade to a prerelease pyyaml over the default to safe loading16:15
fungiwe had something like ansible>=2.5,<2.6 declared and the warning was about a vulnerability in 2.616:15
pabelangerfungi: so, you are getting that from github vulnerability scanner thing they run?16:18
clarkbpabelanger: ya16:18
pabelangerthere is a API to disable it16:18
pabelangermaybe we should update manage-projects16:18
fungii get the impression you have to set it per repository, though i haven't looked closely16:20
pabelangeryah, I think that is right16:20
fungiand am looking forward to the day we (opendev infra) just don't have any group ownership of github mirrors16:20
*** Lucas_Gray has quit IRC16:20
mujahidaliHi infra team, I am  trying to update nodepool from(0.3.0 to 0.5.0 can’t upgrade to latest due to some dependencies). I am not able to ping the instances spawned using the image uploaded by nodepool. For 0.3.0 version I was running prepare-node script which was doing some networking stuff for me, now I am not sure from which section I need to invoke the same script. new nodepool.yml http://paste.openstack.org/show/749374/ and ol16:22
mujahidalid nodepool.yaml http://paste.openstack.org/show/749369/  error http://paste.openstack.org/show/749376/16:22
mujahidaliCan anyone help me to figure out the correct nodepool config file ? or any other missing config ?16:23
clarkbmujahidali: you probably need to set config drive enabled on that provider16:23
clarkband possibly add the simple-init element16:24
clarkbmujahidali: the problem there is you need something like glean (simple-init) or cloud-init to bootstrap networking and credentials on the instance after booting16:27
clarkbmujahidali: the simple-init element will install glean which only uses config drive as a data source. You can theoretically also install cloud-init then other data sources will work, but I don't have any exampels of that16:28
mujahidaliclarkb: thanks, I will add  simple-init element and set config-drive true for provider and retry.16:29
*** ykarel|away has joined #openstack-infra16:31
Shrewsclarkb: looks like we have about 13 instances total in ovh-gra1 in a similar state. i sent a follow up email with those16:34
clarkbShrews: thanks!16:35
Shrewsregion BHS1 seems clean16:36
*** pcaruana has joined #openstack-infra16:36
fungithe gh spam is getting worse. i see some announcements about the same dependency in different files of the same repo, notified via separate e-mails :/16:38
*** mattw4 has joined #openstack-infra16:39
*** kjackal has quit IRC16:42
*** rpittau is now known as rpittau|afk16:43
*** kjackal has joined #openstack-infra16:43
*** armax has quit IRC16:48
*** jamesmcarthur_ has joined #openstack-infra16:48
*** jamesmcarthur has quit IRC16:52
*** markvoelker has joined #openstack-infra16:52
*** ccamacho has quit IRC16:53
*** bhavikdbavishi1 has joined #openstack-infra16:55
*** bhavikdbavishi has quit IRC16:56
*** bhavikdbavishi1 is now known as bhavikdbavishi16:56
*** markvoelker has quit IRC16:56
fungi167 notifications from github today about suspected vulnerable dependencies in our mirrors16:56
fungi(and counting)16:56
*** yolanda_ has quit IRC16:57
*** ginopc has quit IRC17:00
*** ijw has joined #openstack-infra17:00
pabelangerouch17:00
fungiup to 177 now17:01
fungibasically one e-mail for every file, branch and repo which mentions a version of sqlalchemy older than the new release17:01
fungilike they couldn't batch these up or something?17:02
*** priteau has quit IRC17:11
*** diablo_rojo has joined #openstack-infra17:21
*** bhavikdbavishi has quit IRC17:23
*** bhavikdbavishi has joined #openstack-infra17:25
*** ricolin has quit IRC17:25
*** hamzy has joined #openstack-infra17:27
openstackgerritMerged openstack-infra/openstackid master: Migrated Mail from native to Sendgrid API  https://review.openstack.org/65179417:31
*** bhavikdbavishi has quit IRC17:32
*** e0ne has joined #openstack-infra17:32
*** armax has joined #openstack-infra17:34
*** dtantsur is now known as dtantsur|afk17:36
*** kaiokmo has joined #openstack-infra17:38
*** ijw has quit IRC17:40
*** eernst has quit IRC17:41
*** ijw has joined #openstack-infra17:42
*** dklyle has quit IRC17:45
clarkbShrews: I'd like to merge https://review.openstack.org/#/c/650379/3 today if possible, but I'll defer to you on whether or not that impacts your debugging efforts17:45
Shrewsclarkb: i've completed my debugging efforts for the ovh stuff17:47
Shrewsso go for it17:47
clarkbok I'll queue that up for after today's meeting17:48
*** priteau has joined #openstack-infra17:49
*** e0ne has quit IRC17:49
*** igordc has joined #openstack-infra17:50
*** mattw4 has quit IRC18:00
openstackgerritMerged openstack-infra/puppet-openstackid master: Add sendgrid support  https://review.openstack.org/65179818:05
prometheanfireclarkb: github is?18:06
*** iurygregory has quit IRC18:07
prometheanfireclarkb: well, for train we probably can, we are close, 1-2 projects still have issues with sqlalchemy>=1.3.018:07
openstackgerritMerged openstack-infra/system-config master: Added openstackid dev sendgrid support  https://review.openstack.org/65180618:08
fungiin the past we haven't updated stable branches for such things, considering updating dependencies something that distros handle18:08
fungias they're going to backport the security fixes to something which claims to still be the version our stable branch depends on, essentially18:08
clarkbprometheanfire: ya they email you when they detect dependencies that have known security bugs18:09
fungior in many cases, misdetect18:11
prometheanfireclarkb: ah, that github feature, ya18:11
prometheanfirewell, it's in progress18:12
prometheanfiresee https://review.openstack.org/65159118:12
fungiour root alias is now up to 183 notifications from them today alone18:12
fungiit's absurd18:12
*** electrofelix has quit IRC18:13
clarkbI took it as motivation to clean up some subscriptions I didn't need on my personal email18:15
*** ijw has quit IRC18:15
*** ijw has joined #openstack-infra18:16
mordredprometheanfire: "feature"18:21
*** ijw has quit IRC18:22
*** jamesmcarthur_ has quit IRC18:25
*** jamesmcarthur has joined #openstack-infra18:26
openstackgerritsebastian marcet proposed openstack-infra/openstackid-resources master: Materials API bug fixing  https://review.openstack.org/65307618:31
openstackgerritMerged openstack-infra/openstackid-resources master: Materials API bug fixing  https://review.openstack.org/65307618:32
*** priteau has quit IRC18:33
*** ijw has joined #openstack-infra18:35
*** jamesmcarthur has quit IRC18:35
openstackgerritsebastian marcet proposed openstack-infra/openstackid-resources master: Presentation Links api bug fixing  https://review.openstack.org/65307818:37
openstackgerritMerged openstack-infra/openstackid-resources master: Presentation Links api bug fixing  https://review.openstack.org/65307818:37
*** irclogbot_0 has quit IRC18:39
*** jamesmcarthur has joined #openstack-infra18:40
*** irclogbot_1 has joined #openstack-infra18:40
*** ykarel|away has quit IRC18:41
clarkbInfra meeting in ~10 minutes18:50
clarkbwe'll be in #openstack-meeting for that18:50
*** mujahidali has quit IRC19:14
*** eharney has quit IRC19:17
openstackgerritBen Nemec proposed openstack-infra/reviewstats master: Load subproject data from governance  https://review.openstack.org/65302419:21
openstackgerritBen Nemec proposed openstack-infra/reviewstats master: Handle all exceptions loading pickled data  https://review.openstack.org/65310619:21
openstackgerritIan Wienand proposed openstack-infra/zone-opendev.org master: Add review.opendev.org  https://review.openstack.org/65310819:22
*** bobh has joined #openstack-infra19:25
Shrewsinfra-root: just fyi, we finally hit the thing that caused nodepool builder to leak images over the weekend, and verified that the new code handled it properly. so... win19:27
mordredShrews: \o/19:27
*** bobh has quit IRC19:28
fungiright on!19:29
*** bobh has joined #openstack-infra19:37
openstackgerritPaul Belanger proposed openstack-infra/zuul-jobs master: Add test_setup_reset_connection setting  https://review.openstack.org/65313019:38
openstackgerritBen Nemec proposed openstack-infra/reviewstats master: Remove some non-oslo projects from oslo.json  https://review.openstack.org/65302319:49
openstackgerritBen Nemec proposed openstack-infra/reviewstats master: Load subproject data from governance  https://review.openstack.org/65302419:49
openstackgerritBen Nemec proposed openstack-infra/reviewstats master: Handle all exceptions loading pickled data  https://review.openstack.org/65310619:49
openstackgerritBen Nemec proposed openstack-infra/reviewstats master: Import Zuul job settings  https://review.openstack.org/65313319:49
*** dklyle has joined #openstack-infra19:58
corvusdtroyer: what is it you're looking to do?20:00
*** jamesmcarthur has quit IRC20:00
dtroyercorvus: starlingx will be carrying a stable/stein branch for additional backports during Train, I'd like to be able to run at least a handful of tests for PRs to that branch20:01
dtroyerfor Nova only20:01
corvusdtroyer: where does github come into play?20:01
dtroyerthat is where the branch lives  https://github.com/starlingx-staging/stx-nova/tree/stx/stein.120:02
corvusdtroyer: is it not going to move into gerrit (along with these? https://git.starlingx.io/cgit )20:02
clarkbcorvus: aiui the old plan was not to do that because people didn't want to have a fork of nova hosted on the opnstack infrastructure. We might have a bit more leeway when things are opendev'd20:03
dtroyerno.  nothing more from github moves into gerrit, that was settled last summer.  This is what used to be the 'fork' of nova that WRS carried20:03
dtroyeralso, this is only for the train cycle, I'll have words if it extends beyond that20:04
corvusdtroyer: is that repo going to be eliminated eventually?20:04
dtroyeryes20:04
corvusgotcha20:04
clarkbI take it the backports people want to make to stein won't fit into openstack's stable maintenance policy?20:04
clarkbor we arent unforked enough yet?20:04
dtroyercorrect, things like Artom's NUMA live migration patches which almost made stein but didn't20:05
dtroyerno, this is the only thing left of the forks.  We have 11 'things' on the list to backport when they merge upstream20:05
mordreddtroyer: so - the fork that's there isn't something that needs to be tested/gated itself - as much as it needs to be available to be pulled in to jobs for other things - yeah?20:05
*** igordc has quit IRC20:05
dtroyerI am just looking to sanity check the PRs proposed to github before merging them.  otherwise we have to create the docker image and test it the long way20:06
dtroyeror di a devstack/tempest run manually.20:06
dtroyerthis is not going to be a frequent thing, I can live with that20:06
dtroyerif Zuul + github isn't a happy thing, that's fine20:07
mordrednod - so you _would_ like to run tests on PRs to that repo - but it's primarily a place where some stuff you're working to get rid of is living20:07
dtroyermore specifically 'stuff from upstream train we need before the train release'20:08
clarkbthinking out loud here20:12
clarkbwhat are the chances nova would host a less stable stein branch?20:12
clarkbcinder did similar in the past for "driverfixes"20:12
dtroyerclarkb: it may be a realistic possibility now but given the history I chose not to persue that.20:14
*** eharney has joined #openstack-infra20:14
dtroyerI don't know of the 'for train only' would make it more or less likely for that to be a good idea20:14
*** weshay has quit IRC20:14
*** weshay has joined #openstack-infra20:15
clarkbfwiw the trouble we've had with zuul + github are largely on the engagement side of things. I think if a project is off doing most of its own stuff and only consuming zuul its been hard for us to build effective communication back and forth20:15
clarkbI don't expect dtroyer will have problems with that. Which makes my biggest concern here the reaction to the forking that happened20:15
dtroyerthat is good to know, I was wondering if it was technical or cultural20:15
corvusthis is not the only problem i have with supporting github in opendev's zuul20:16
clarkbcorvus: ya there are other concerns from a software freenes perspective. But from a "things don't physically work" that has been the issue20:16
dtroyerthe reaction so far has been minimal… more on twitter than anywhere else I've seen20:16
corvusreaction to what?  (i don't use twitter so i don't know what people are saying on it)20:17
dtroyerreaction to stx carrying a fork of stable/stein.  I'm trying to do it as transparently as possible, which helped20:17
dtroyer(for nova)20:18
corvusah20:18
openstackgerritJeremy Stanley proposed openstack-infra/system-config master: Add a opendev migration repo name mapping script  https://review.openstack.org/65313820:18
fungiwoohoo! i got the rename mapping generator working, just need to fiddle with output formatting now20:18
fungiand with that, going to go get dinner with some friends, then get back to it20:19
*** pcaruana has quit IRC20:19
clarkbI think from our perspective a less stable stein branch in gerrit would be easiest to accomodate20:21
*** priteau has joined #openstack-infra20:23
dtroyerclarkb: ok, I'll talk over beer to some folks about it in Denver and see where we may stand.  thanks20:24
*** priteau has quit IRC20:27
*** kgiusti has left #openstack-infra20:28
anteayaclarkb: I missed the meeting, I see 1500UTC was decided as the start time, and you are going to update the emails?20:29
clarkbanteaya: I am, but I need to take a break as this headache isn't going away20:30
openstackgerritJames E. Blair proposed openstack-infra/system-config master: Prune the intermediate registry before GCing  https://review.openstack.org/65314820:30
anteayaclarkb: I'm sorry to hear that, I hope some time away from keyboard bring relief20:31
corvusclarkb: then do not look at that change unless you find jq and awk an effective remedy for headaches ^20:31
anteayabrings*20:31
mordredcorvus: jq and awk are an effective remedy for something?20:31
clarkbI just had some toast so I can take the painkillers. Hopefully that gets me sorted. Back in a bit20:31
anteayaI favour a big glass of water and darkness myself20:31
corvusmordred: i've decided awk is under-appreciated and i should use it more20:33
corvusmordred: it's like... i dunno, as effective as perl, but more arcane and compact! :)20:33
corvusevery character of those awk programs represents about 5 minutes of careful work20:34
openstackgerritBen Nemec proposed openstack-infra/project-config master: Remove reviewstats Zuul job config  https://review.openstack.org/65315020:34
*** mnencia_ has joined #openstack-infra20:34
*** mnencia has quit IRC20:35
*** mnencia_ is now known as mnencia20:35
corvusclarkb, mordred: i'm going to poke at the swift driver next20:36
*** ijw has quit IRC20:42
pabelangerianw: any ideas why DIB is rasing an exception? http://paste.openstack.org/show/749392/20:44
pabelangeralso seems to be leaking mounts20:44
pabelangerhttp://paste.openstack.org/show/749393/20:47
pabelangerlet me move to better channel20:47
*** ijw has joined #openstack-infra20:47
*** ijw has quit IRC20:54
*** hamzy has quit IRC20:54
*** bobh has quit IRC20:56
mordredcorvus: I have amazed and astounded people while doing consulting engagements simply with command-line awk20:56
corvusmordred: cool!  you can let me know if i did it right :)20:57
*** Goneri has quit IRC21:00
mordredcorvus: you'd think that ... but I've already learned things from your patch :)21:00
mordredcorvus: also - I love that you have a command-line python in there too21:00
corvusheh, i copied that from a similar ansible thing from a while back -- i could not find a way to get the exact format i needed with 'date'21:01
*** jamesmcarthur has joined #openstack-infra21:01
mordredcorvus: I feel like 'date' is sort of like 'find' - if I knew the right combo of flags it should be fully turing complete21:02
mordredbut like find - there is no way as a human that I could possibly know the right combo of flags21:02
corvusfortunately, stackoverflow knows... though it's also been trying to tell me spoilers about GoT... so i've been using it less today.21:03
corvus(i'm guessing their product managers did not see that one coming)21:04
mordredcorvus: GoT is the one show where we've chosen to actively watch it immediately when available - because avoiding spoilers is so darned hard21:05
*** jcoufal has quit IRC21:07
*** kaiokmo has quit IRC21:10
*** gfidente has quit IRC21:22
*** kjackal has quit IRC21:23
*** ijw has joined #openstack-infra21:25
corvusregistry_1  | panic: Swift authentication failed: Bad Request21:35
corvussigh21:35
corvusmordred: ^ i'm not having much luck with the swift driver21:35
corvusi assume there's something wonky with the parameters21:35
corvusregistry_1  | panic: Failed to retrieve info about container insecure_registry (Operation forbidden)21:36
corvusi've managed to get 2 kinds of errors21:36
corvusi guess the second one is better?  i'm not sure.21:36
mordredcorvus: can you show me how you're mapping in values to their input parameters?21:36
corvusyep21:36
mordredsweet21:36
corvusmordred: http://paste.openstack.org/show/749396/21:37
corvusmordred: i elided 2 things with <brackets>21:38
corvusotherwise that's the config file i have21:38
mordredcorvus: can you try changing tenant to tenantid21:38
corvusdid, same error21:39
mordredhrm. I don't suppose you've found a way to get the docker to print a trace of its http interactions have you?21:40
corvusno, i was hoping logging: level: debug would do that but :(21:41
mordredcorvus: does the insecure_registry container exist?21:42
ianwpabelanger: 2019-04-16 20:35:57.885 | chown: cannot access '/etc/unbound/conf.d/forwarding.conf': Not a directory21:42
corvusmordred: gah!  no.  but intermediate_registry does exist, and still produces the same orror.21:43
mordredcorvus: poop21:44
corvusmordred: apparently we're here: https://github.com/docker/distribution/blob/master/registry/storage/driver/swift/swift.go#L22221:46
corvusmordred: oh, wow, i also put in the wrong region21:47
corvusmordred: apparently i need a break.  sorry for the goose chase and thanks for the help.21:47
mordredcorvus: oh! well - sure thing!21:47
corvusit seems to be doing something without errors now :)21:47
mordredcorvus: \o/21:47
* mordred is super helpful21:48
*** Goneri has joined #openstack-infra21:48
corvusi seem to be able to push images into it21:50
corvusthough it looks like any layers > 40MB may have failed...21:54
*** ijw has quit IRC21:55
*** ijw has joined #openstack-infra21:55
openstackgerritsebastian marcet proposed openstack-infra/openstackid-resources master: Fixed materials api bugs  https://review.openstack.org/65316021:58
mordredcorvus: chunksize should default to 5M22:00
mordredso I do't know why layers over 40M would be a problem22:00
mordred(if it was layers over 5M I'd say chunk size was borked)22:01
openstackgerritMerged openstack-infra/openstackid-resources master: Fixed materials api bugs  https://review.openstack.org/65316022:02
corvusit's really hard to tell what's going on; tcpdump traffic between my workstation and cloud files continues long after the 'docker push' command has failed22:03
corvusi don't know if the docker daemon is still pushing stuff to the registry, or the registry is still pushing stuff to swift, or if the docker daemon is pushing stuff to swift...22:03
corvusbut this is the output at the end of a push command: http://paste.openstack.org/show/749401/22:04
mordreduh22:04
corvusmeanwhile, the registry occasionally emits a log line like this: swift.PutContent("/docker/registry/v2/repositories/sshd/_uploads/020f4ceb-637b-4a3e-9540-926fba453663/hashstates/sha256/29704593")"22:05
mordredcorvus: that unauthorized line doesn't look like an error from swift22:05
corvusmordred: oh... hrm...22:06
corvusmordred: i wonder if i messed up the auth config when i switched over to using swift22:06
*** sreejithp has quit IRC22:10
fungiand back22:11
corvusthat doesn't seem to be the issue22:12
fungiand yes, not to knock perl, but i do prefer awk myself22:13
corvusapparently you can't delete a folder in a rax cloudfiles container unless it's empty22:16
corvusand you can't delete a rax cloudfiles container unless *it* is empty22:16
corvus"For bulk deletes, we recommend using a free third-party cloud storage browser such as Cyberduck or Cloudberry Explorer."22:16
fungi"For bulk deletes, we recommend switching to a better service"22:19
fungiokay, back to the repo namespace mapping generator. it's scary when one script needs to grok yaml, json *and* csv22:19
ianwfungi: easy, convert it all to xml :)22:20
fungioh, right! the "enterprise" solution22:20
fungion its five-year mission to chart new serialization22:20
mordredinfra-root: I must now AFK - it is time to go pick up many pounds of crawfish22:26
fungii fully endorse this priority of yours22:26
fungigumbo? étouffée?22:27
fungieven just straight up steamed is good22:28
fungii chose the wrong beach for crawdads22:28
fungiwe make do with shrimp22:29
*** rcernin has joined #openstack-infra22:38
pabelangerianw: yah, fixing that, but was surprised to see dib leak the mounts22:43
corvusmordred: i have a theory -- i think the auth error (and subsequent failures) are due to this failure:22:46
corvusApr 16 15:38:05 fuligin dockerd[23164]: time="2019-04-16T15:38:05.624032957-07:00" level=debug msg="Failed to check for presence of layer sha256:fd3cdb0bc0a09eddd99259cda1de9f0303bbea05004a9a87c3871a22199bc614 (sha256:41381f6a2bc0fc86e5b258de9a54bd86691f6bca07b589cb68c241b390de8e66) in localhost:5000/sshd" error="unauthorized: authentication required"22:46
corvusas that's a 'get' opreation, perhaps that's using tempurl stuff, whereas the uploads are not22:47
corvusor....22:50
corvusthis is somehow running afoul of the rax swift/cdn stuff22:50
*** Goneri has quit IRC22:50
corvusgah... the registry swift driver config lets you specify the tempurl methods, but it does *not* let you override what the server returns; the value is only used if the server doesn't return anything22:53
corvusthat seems really backwards22:53
*** tkajinam has joined #openstack-infra22:54
*** whoami-rajat has quit IRC23:02
tonyb[m]clarkb: Can you forward me/us the details?  why would github care?23:06
*** jamesmcarthur has quit IRC23:06
*** Goneri has joined #openstack-infra23:06
ianwpabelanger: are you on a current release?  we did merge a fix hopefully for leaking23:06
clarkbtonyb[m]: github scans your dependency lists for versions with known security issues then spams you when they find them23:06
tonyb[m]Ahh okay23:07
*** jamesmcarthur has joined #openstack-infra23:07
tonyb[m]Does it tell you which branch?23:07
pabelangerianw: no, https://github.com/ansible-network/windmill-config/blob/master/ansible/group_vars/nodepool-builder.yaml#L1423:07
pabelangerI had to pin to get fedora-29 images working23:07
fungitonyb[m]: it does, yes23:07
pabelangerI should try to uncap and see if it's working again23:07
ianwpabelanger:  yeah, https://git.openstack.org/cgit/openstack/diskimage-builder/commit/?id=528456407131c8771588fd3d53f91785b728752e is the change23:08
clarkbin this case it was like 180 emails so I deleted them23:09
pabelangerianw: ack, thanks23:09
fungii stashed all the ones which came to the infra root alias23:09
fungiin case they're needed23:09
fungibut we have some 2+k notices like that from github over past months in the same mailbox23:10
*** jamesmcarthur has quit IRC23:11
fungiinfra-root: config-core: infra-puppet-core: i meant to bring this up during the meeting, but the namespace decision reached for openstack is that *all* official repos which aren't currently in the openstack namespace are moving to the openstack namespace (this includes things in openstack-infra and openstack-dev), so if there are infra repos we *don't* want moved, we should work with clarkb to get23:13
fungithem out of openstack governance23:13
fungi(before friday)23:14
*** Goneri has quit IRC23:14
fungior at least come to some agreement to whitelist specific things in the short term23:15
corvusi think that's swell; i expect the next big task for us is to set up governance for opendev to normalize "opendev/" repos23:15
*** jcoufal has joined #openstack-infra23:15
fungiyes, i agree23:15
corvusin the interim, i do think openstack/system-config might be a teensy bit awkward23:15
fungisure, as i said, i'm not against whitelisting things in the generator script23:16
corvusso we may want to look for things like that where we might want to do that ^ :)23:16
fungii'll have the list up shortly (containing the 925 moves the algorithms have identified)23:17
fungier, 82523:17
corvus(it doesn't bother me wearing my infra hat, it's more that wearing my openstack hat, i think openstack/system-config will do a disservice to the branding effort that the openstack project is trying to do)23:17
fungisure, i also think there are more things which are likely to move out of the openstack namespace after migration (for example, talking the osf staff and board into moving repos under the jurisdiction of board working groups and staff efforts to an "osf" namespace)23:19
*** tosky has quit IRC23:19
*** guimaluf has quit IRC23:21
*** rlandy|ruck is now known as rlandy|ruck|biab23:22
openstackgerritJeremy Stanley proposed openstack-infra/system-config master: Add a opendev migration repo name mapping script  https://review.openstack.org/65313823:24
fungithis is a preliminary list based on ^ http://paste.openstack.org/show/749402/23:24
pabelangerfungi: nice, ethercalc stuff good23:27
tonyb[m][tony@thor ~]$ ssh review gerrit ls-projects | grep inaugust23:30
tonyb[m]inaugust/inaugust.com23:30
tonyb[m]inaugust/src.sh23:30
tonyb[m]inaugust/ttrun23:30
tonyb[m]mordred: shouls ^^^ that be a thing?23:31
fungiyep, welcome to opendev!23:31
tonyb[m]okay23:31
fungithose aren't moving, as they're already in their intended namespace23:31
tonyb[m]I see some scripting updates in my future23:31
fungiyeah, for many of us23:31
tonyb[m]okay23:32
fungiyou can no longer expect any particular namespaces, so may want to do some filtering23:32
fungion a positive note, after friday all official openstack projects will be in the "openstack" namespace23:32
fungiso if that's what you care about, it may make your filtering rule remarkably trivial ;)23:32
tonyb[m]I think I care about zuul, airship and starlingX too23:33
tonyb[m]but none of it is too hard23:33
fungieach of those will have their own namespaces too (and you just guessed the names for them)23:33
tonyb[m]hehe23:34
funginote however around line 181 in my example paste, some of them are dropping basename prefixes when they move23:35
tonyb[m]so ... gerrit ls-projects | grep -Ei '^(openstack|staringx|zuul|airship)' will basically do what I want?23:35
fungiyou may want a / there too, i don't know how open-ended you care to be23:35
tonyb[m]okay23:35
tonyb[m]So another question I just remembered I wanted to ask ....23:36
*** rh-jelabarre has quit IRC23:36
tonyb[m]There is a project on gihub (https://github.com/redhat-cip/hardware) for which travis isn't working23:36
tonyb[m]can I a) setup zuul to run jobs on any PRs for that repo ; and b) assuming the answer to a is 'sure' are there docs?23:37
fungitonyb[m]: see if http://lists.openstack.org/pipermail/openstack-infra/2019-January/006269.html answers it for you23:39
fungiif not, happy to dig deeper23:39
*** jcoufal has quit IRC23:41
fungi(tl;dr is that zuul.opendev.org exists to test software hosted on review.opendev.org and possibly some of those projects dependencies on github or other external services, but is not intended as a stand-alone tool for projects hosted outside review.opendev.org)23:41
tonyb[m]okay so this library is used by ironic23:42
fungithe argument could be made that's third-party testing of an ironic dependency23:42
fungihowever, if the project in question is under an open license and the maintainers are interested in moving it to review.opendev.org i think we'd be thrilled to help23:42
tonyb[m]but some members of the core team don't want to move it to opendev :(23:43
* tonyb[m] would love to move it23:43
clarkbthats actually a big part of my concern doing testing for github projects. experience says in those cases communication is poor and we get blamed rather that collaborated eith in fixing things23:44
fungiif that project is a pain point for ironic and the goal is to run some jobs to integration-test pull requests for it with ironic to make sure they don't break ironic, then that's probably in keeping with the other examples we have23:44
tonyb[m]Okay I don't think I can quite make that argument23:47
tonyb[m]I think I just need to work out how to fix Travis23:47
tonyb[m]:(23:47
* tonyb[m] wouldnm23:47
fungibut as a rule, we don't want opendev to be seen as endorsing some proprietary hosting service, and directly integrating with it for the benefit of projects who don't want to host in opendev's infrastructure is a bridge to far23:47
tonyb[m]'t enable anythign without the permission of the otehr core reviewers23:47
tonyb[m]okay23:47
tonyb[m]That's a clear answer and I have a path forward23:48
fungiexcellent! it wasn't entirely clear for many of us for a long time, which is why we needed to come up with a good position statement23:48
*** sshnaidm is now known as sshnaidm|afk23:50
fungiit's hard for us to toe the free/libre open source tools line and at the same time say we're okay with serving as an a la carte menu of services for projects who don't believe that's important23:51
pabelangerI actually had a question, is there policy in place that would prevent me from creating a repo in opendev.org/inaugust ?23:52
pabelangeror opendev.org/vexxhost23:52
fungithis is something i was wanting to bring up, though it's not necessary to solve before friday23:53
openstackgerritMerged openstack-infra/system-config master: Add Puppet-Version: !X skip to apply tests  https://review.openstack.org/65247223:53
fungiwe likely need some way to track points of contact for namespaces23:53
pabelangeryah, I could see in some case, project doesn't want to use opendev but also doesn't wait their namespace to be used23:53
fungiat the moment we know who they are, but that sort of relationship doesn't scale forever23:54
fungior maybe even past june23:54
clarkbbut also one thing at a time so that we can remain sane :P23:54
fungiyes23:54
pabelangeryah23:54
fungiwhich is why i hadn't planned to bring it up yet23:54
pabelangerokay cool23:54
pabelangerhopefully people don't try to do a land grab on things23:55
fungion the "project doesn't want to use opendev" point, i'm not sure i care that we have some way for them to squat namespaces in our service23:55
*** rlandy|ruck|biab is now known as rlandy|ruck23:55
fungicurrently the only way (afaik) to create a namespace in our gitea is to create a git repository in it through our new project creation workflow, and that has people reviewing config changes as gatekeepers23:56
pabelangeryah23:56
fungiso hopefully anything wild would come to our attention fairly quickly23:56
*** hwoarang has quit IRC23:57
fungii think if and when request volume rises to the point where we need to take more people out of the workflow, we'll likely add more safeguards at the same time23:57
*** hwoarang has joined #openstack-infra23:58
clarkbconfig-core I just sent email out about the new project ceration freeze to the infra mailing list23:59
fungithanks!23:59
clarkbnow to send email about the gerrit fun starting at 1500UTC23:59
fungii'll be putting together some (individualized) e-mails to various mailing lists with the straw man renames list23:59

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!