| Posted | Nick | Remark | |
|---|---|---|---|
| #openstack-nova - 2021-11-30 | |||
| 19:39:04 | gmann | +1. yeah its self.api and self.admin_api | |
| 19:39:06 | gmann | as of now | |
| 19:39:19 | dansmith | yup | |
| 19:39:27 | sean-k-mooney | well default to roles=None | |
| 19:39:39 | sean-k-mooney | rather then [] | |
| 19:39:40 | opendevreview | Ghanshyam proposed openstack/nova master: Introduce 'admin' policy base rule https://review.opendev.org/c/openstack/nova/+/819389 | |
| 19:39:49 | sean-k-mooney | sicne you should not use mutable defaults but same effect | |
| 19:39:56 | gmann | dansmith: ^^ this is for 'admin' basically renaming 'context_is_admin' to 'admin' | |
| 19:40:02 | dansmith | sean-k-mooney: did you look at the patch? :) | |
| 19:40:11 | dansmith | gmann: cool thanks | |
| 19:40:24 | sean-k-mooney | nope just saw the converstaion scroll by | |
| 19:40:43 | dansmith | sean-k-mooney: trying not to take offense that you think I don't know not to use mutable defaults :) | |
| 19:41:50 | sean-k-mooney | :) | |
| 19:42:58 | sean-k-mooney | i still see it in code often enough but ya you already did it the right way https://review.opendev.org/c/openstack/nova/+/819907/3/nova/tests/functional/api/client.py#140 | |
| 19:49:52 | gmann | I think we have hacking rule for that. | |
| 20:13:37 | dansmith | gmann: I don't think your admin patch works for me by itself, | |
| 20:13:44 | dansmith | since it's still requiring role:admin, which isn't what we have today | |
| 20:13:56 | dansmith | it needs to be is_admin in order to work as-is right? | |
| 20:24:52 | gmann | dansmith: context set is_admin based on this rule itself https://github.com/openstack/nova/blob/d630615a02469442fb50ed4aa7e092206a28166a/nova/context.py#L138 | |
| 20:24:58 | gmann | https://review.opendev.org/c/openstack/nova/+/819389/4/nova/policy.py | |
| 20:29:16 | gmann | but as it is two level deprecated rule combined I hope each one is logical ORed by oslo policy. but is it failing on your patch? if so then we can avoid to rename it for now. and add DEPRECATED_ADMIN_POLICY in is_context_admin rule only | |
| 20:39:49 | gmann | dansmith: yeah, i ran your patch with my change and it does not work. oslo policy add only one level of deprecated rule in logical OR. | |
| 20:40:56 | gmann | dansmith: I will abandon my patch and let's rename CONTEXT_ADMIN to ADMIN in your patch but keeping rule:is_context_admin. commented in https://review.opendev.org/c/openstack/nova/+/816206/comment/543216d1_15fecfb1/ | |
| 21:43:47 | dansmith | gmann: okay, but that's not enough, it needs to be "role:admin or is_admin:True" | |
| 21:44:21 | dansmith | so do you want me to do that on context_is_admin with a deprecated_rule= or add it to admin_api? | |
| 21:44:51 | gmann | dansmith: yeah that will add ORed both | |
| 21:45:59 | gmann | dansmith: yeah deprecated_rule=DEPRECATED_ADMIN_POLICY . | |
| 21:46:13 | dansmith | okay that's not enough either, I need this: https://termbin.com/bnqh | |
| 21:46:15 | dansmith | you okay with that? | |
| 21:46:27 | dansmith | oh wait | |
| 21:46:37 | dansmith | it's enough to use it as-is for today, you're right | |
| 21:46:45 | dansmith | I'm thinking this needs to work for both old and new, but not as of this patch | |
| 21:46:58 | dansmith | so yeah, I will just add the deprecated_admin_policy there | |
| 21:47:12 | gmann | if you do this then it should ADMIN = 'rule:context_is_admin' | |
| 21:47:58 | dansmith | yep, hadn't saved that before paste :) | |
| 21:48:31 | dansmith | running all the tests now, but expect this to work now | |
| 21:48:40 | gmann | dansmith: so with that you do not need this right? 'check_str='is_admin:True or role:admin',' | |
| 21:48:52 | dansmith | correct, for just this patch, I don't | |
| 21:48:59 | gmann | yeah. | |
| 21:50:40 | dansmith | there are just too many balls in the air with this stuff for my tiny brain :D | |
| 23:06:26 | artom | dansmith, for the record, I'm painfully aware of the door that your last line opened, but am steadfastly refusing to step through it | |
| 23:06:54 | dansmith | artom: lol, I *literally* almost pinged you, asking if you wanted to do the mriedem thing in his stead :D | |
| 23:07:48 | artom | I'm all grown up now | |
| 23:08:33 | dansmith | riiight | |
| 23:09:09 | artom | No really, I'm organizing expensive calls and everything :P | |
| 23:37:08 | opendevreview | Dan Smith proposed openstack/nova master: Revert project-specific APIs for servers https://review.opendev.org/c/openstack/nova/+/816206 | |
| 23:37:08 | opendevreview | Dan Smith proposed openstack/nova master: Allow per-context rule in error messages https://review.opendev.org/c/openstack/nova/+/816865 | |
| 23:42:42 | opendevreview | Ghanshyam proposed openstack/nova master: Convert SYSTEM_ADMIN|READER to Admin and system scope https://review.opendev.org/c/openstack/nova/+/819390 | |
| 23:44:28 | opendevreview | Ghanshyam proposed openstack/nova master: Convert SYSTEM_ADMIN|READER to Admin and system scope https://review.opendev.org/c/openstack/nova/+/819390 | |
| 23:44:33 | opendevreview | Ghanshyam proposed openstack/nova master: Convert SYSTEM_ADMIN|READER to Admin and system scope https://review.opendev.org/c/openstack/nova/+/819390 | |
| #openstack-nova - 2021-12-01 | |||
| 02:29:47 | opendevreview | Ghanshyam proposed openstack/nova master: Convert SYSTEM_ADMIN|READER to Admin and system scope https://review.opendev.org/c/openstack/nova/+/819390 | |
| 08:42:49 | luk4s | Good morning all | |
| 08:44:07 | luk4s | We enabled tenant isolation with placement https://docs.openstack.org/nova/wallaby/admin/aggregates.html#tenant-isolation-with-placement and have two aggregates: one for private tenants and one for generic use. | |
| 08:45:55 | luk4s | For private tenants we want the allocations to happened first on the private aggregate and when that is full we want to move on to the generic one once the private one is full. | |
| 08:46:14 | luk4s | Is this possible? | |
| 08:48:23 | luk4s | I have added the relevant project id to both aggregates, but the allocation is a little bit random. Can priority/weight be assigned to prioritise one over other, i.e. always prioritise the private over generic one. | |
| 09:46:19 | bauzas | luk4s: hola | |
| 09:46:37 | bauzas | luk4s: so you want to stack first for one aggregate and then another one ? | |
| 09:49:34 | luk4s | bauzas, yes. | |
| 09:51:11 | luk4s | i.e. always fill up private aggregate first before moving on to the generic one. | |
| 09:51:13 | bauzas | for this tenant ? | |
| 09:51:37 | bauzas | if so, you need a weigher | |
| 09:52:32 | luk4s | I have already looked at that but it looks like existing weighters may not do what I want - I presume I would have to write a new one? | |
| 09:53:53 | luk4s | would like to avoid writing one if possible :) | |
| 09:57:32 | bauzas | luk4s: AFAIK, there are no ways to tell Nova to do this for the moment | |
| 09:58:50 | luk4s | bauzas, cheers and thank you for the information | |
| 09:59:10 | luk4s | I mean thank you for the information :) | |
| 11:14:28 | bauzas | cores, a documentation change simple https://review.opendev.org/c/openstack/nova/+/814561 | |
| 12:59:57 | stephenfin | gibi: care to send https://review.opendev.org/c/openstack/nova/+/814561 on its way | |
| 12:59:58 | stephenfin | ? | |
| 13:07:39 | sean-k-mooney | stephenfin: has you mock to unittest.mock patch merged yet | |
| 13:07:53 | brinzhang_ | gmann: hi, would you like to review the series of remove tenant_id patches https://review.opendev.org/q/topic:%22bp%252Fremove-tenant-id%22+(status:open%20OR%20status:merged) | |
| 13:08:33 | sean-k-mooney | hum no https://review.opendev.org/c/openstack/nova/+/714676 oh takashi thing its causing nova.tests.unit.api.openstack.test_wsgi_app.WSGIAppTest.test_init_application_called_twice to fail | |
| 13:36:26 | gibi | bauzas, stephenfin: on itr | |
| 13:38:55 | gibi | done | |
| 13:49:55 | bauzas | gibi: t | |
| 13:49:58 | bauzas | ta even | |
| 14:16:03 | artom | Am I the only one for whom `git review -d` appears to timeout? | |
| 14:16:20 | sean-k-mooney | which review | |
| 14:16:22 | sean-k-mooney | ill try it | |
| 14:16:47 | artom | sean-k-mooney, https://review.opendev.org/c/openstack/whitebox-tempest-plugin/+/805300, but presumably if it's a gerrit issue it would be all reviews | |
| 14:17:21 | sean-k-mooney | just worked | |
| 14:18:00 | artom | Just me then? That's annoying | |
| 14:19:05 | artom | The hell, it's as though all Python IO is b0rk | |
| 14:19:07 | sean-k-mooney | i assume you have the corfrect url | |
| 14:19:09 | sean-k-mooney | gerrit ssh://sean-k-mooney@review.opendev.org:29418/openstack/whitebox-tempest-plugin | |
| 14:19:16 | artom | pip install --upgrade --user git-review does the same thing | |
| 14:19:18 | sean-k-mooney | with your user name | |
| 14:19:27 | sean-k-mooney | are you out of disk space | |
| 14:19:31 | artom | Or just... super slow | |
| 14:19:41 | artom | No... | |
| 14:34:59 | artom | So that worked, though I had to disable IPv6 after rebooting to be able to connect here | |
| 14:54:41 | sean-k-mooney | ipv6 might have been the issue | |
| 14:54:47 | sean-k-mooney | if you dont have native ipv6 | |
| 15:02:21 | pslestang | Hey all, what's the next step once we created a blueprint? https://blueprints.launchpad.net/nova/+spec/delete-instance-actions | |
| 15:08:33 | sean-k-mooney | pslestang: in this case since its requesting a config option not a api change it can be added to the team meeting adgenda and you can request this to be done as a specless blueprint | |
| 15:09:28 | sean-k-mooney | pslestang: if that is approved then you just submit a patch referince the bluepirnt in the commit and topic "bp/delete-instance-actions" with a release note and docs for the new feature | |
| 15:10:22 | sean-k-mooney | pslestang: if its determined that we have upgrade conscerns or other topics that need detailed discussion then we would ask for a spec to discuss the desgin but i dont think that will be required in this case | |
| 15:11:16 | pslestang | sean-k-mooney: thanks for your answer, how can I add it to the meeting agenda? | |
| 15:17:04 | sean-k-mooney | edit https://wiki.openstack.org/wiki/Meetings/Nova and add it to the open discussion section | |