| Posted | Nick | Remark | |
|---|---|---|---|
| #openstack-nova - 2022-11-29 | |||
| 20:46:42 | dansmith | right, everything we do with glance is with the user's token | |
| 20:46:47 | dansmith | this is a pretty fundamental change from that | |
| 20:47:27 | sean-k-mooney | ya ok im not sure if the service_user stuff woudl help there although thats really just for working aound token exeriation | |
| 20:48:20 | dansmith | sean-k-mooney: it would require it | |
| 20:48:25 | sean-k-mooney | this would really be that large a change in nova either a specless blueprint or short spec i guess | |
| 20:48:27 | dansmith | sean-k-mooney: maybe just read the spec :) | |
| 20:48:42 | sean-k-mooney | oh we have a spec already then sure | |
| 20:49:00 | dansmith | sean-k-mooney: no, the spec on the glance side I copied you on | |
| 20:49:01 | sean-k-mooney | the current service user config we have is not for that however | |
| 20:49:03 | dansmith | no spec on the nova side, | |
| 20:49:18 | sean-k-mooney | ah righit i saw the email havent looked at it yet | |
| 20:49:26 | sean-k-mooney | https://review.opendev.org/c/openstack/glance-specs/+/863209 | |
| 20:49:31 | sean-k-mooney | the new locations api spec | |
| 20:49:43 | dansmith | but since everything in nova assumes that the user's token is used for glance interaction, I just want to be super careful that we don't accidentally use the service account for anything related to the image other than the ceph location thing | |
| 20:50:50 | sean-k-mooney | ya so the same way we have for geting an admin client for neutron we likely need to add a get_service_client funtion or similar and use it for that call explcitly | |
| 20:51:41 | dansmith | right | |
| 20:52:07 | dansmith | we discussed this earlier related to the dual internal/external glance thing was brought up | |
| 20:52:22 | dansmith | and I thought you had a good reason for why there's a gotcha there, but I don't remember what it was | |
| 20:53:19 | sean-k-mooney | the internal endpoint is also used to provide unmeetered acces to the api for tenant workloads | |
| 20:53:21 | sean-k-mooney | in public clouds | |
| 20:53:40 | sean-k-mooney | so really it woudl be nice if keystone addded a service endpoint | |
| 20:53:48 | sean-k-mooney | for service to service comunications | |
| 20:54:02 | dansmith | yeah, that's unrelated to this | |
| 20:54:02 | sean-k-mooney | although if this requried the service user | |
| 20:54:04 | dansmith | I mean, this is to avoid needing that | |
| 20:54:21 | sean-k-mooney | right if we have the service role not user | |
| 20:54:34 | sean-k-mooney | then we can just filter the filed based on teh role | |
| 20:54:38 | sean-k-mooney | like we do with server show | |
| 20:55:01 | sean-k-mooney | so only show the image location if the token has the service role | |
| 20:55:08 | sean-k-mooney | that would be the nicer way to do this | |
| 20:55:41 | dansmith | you should read the spec | |
| 20:55:43 | sean-k-mooney | you said the policy/rback stuff in glance has only recently been made capabliy of supproting somethign like that right | |
| 20:56:08 | sean-k-mooney | sure ill add it to my list for tomorrow | |
| 20:56:21 | sean-k-mooney | i was just back breifly ot check on something | |
| 20:57:58 | sean-k-mooney | skiming it without the nova changes if this was unconsitonaly added to glance | |
| 20:58:11 | sean-k-mooney | it woudl silently disable the fast clone support | |
| 20:58:43 | sean-k-mooney | and even then it woudl break the grenade upgrade rules if we did not do upgrade carfully | |
| 20:59:14 | sean-k-mooney | i.e. you shoudl not need to change the config when you upgrade | |
| 20:59:46 | dansmith | it's a new api, so they'll have to support the old one for a while, and I commented on that in the spec that it needs to hang around for a good while | |
| 21:00:05 | sean-k-mooney | ack | |
| 21:00:18 | sean-k-mooney | so they are not just doign the filtering on the old one | |
| 21:00:53 | sean-k-mooney | ya ok there is no point in me speulcating on this until i have had time to read the spec fully thanks for highlighting it | |
| 21:03:18 | dansmith | I just want to make sure that nova people are aware of when glance people say "we'll just change nova to do X" with no planning on this side, and potentially nobody signing up to do it or review it | |
| 21:52:24 | opendevreview | Merged openstack/nova master: Handle mdev devices in libvirt 7.7+ https://review.opendev.org/c/openstack/nova/+/838976 | |
| 22:02:06 | opendevreview | Merged openstack/nova master: Don't provide MTU value in metadata service if DHCP is enabled https://review.opendev.org/c/openstack/nova/+/855664 | |
| 22:02:17 | opendevreview | Merged openstack/nova master: extend_volume of libvirt/volume/fc should not use device_path https://review.opendev.org/c/openstack/nova/+/858129 | |
| 22:54:45 | opendevreview | melanie witt proposed openstack/nova stable/xena: Retry attachment delete API call for 504 Gateway Timeout https://review.opendev.org/c/openstack/nova/+/866083 | |
| 22:57:29 | opendevreview | melanie witt proposed openstack/nova stable/wallaby: Fix the wrong exception used to retry detach API calls https://review.opendev.org/c/openstack/nova/+/866084 | |
| 22:57:30 | opendevreview | melanie witt proposed openstack/nova stable/wallaby: Retry attachment delete API call for 504 Gateway Timeout https://review.opendev.org/c/openstack/nova/+/866085 | |
| 23:09:51 | opendevreview | melanie witt proposed openstack/nova stable/victoria: Fix the wrong exception used to retry detach API calls https://review.opendev.org/c/openstack/nova/+/866086 | |
| 23:09:52 | opendevreview | melanie witt proposed openstack/nova stable/victoria: Retry attachment delete API call for 504 Gateway Timeout https://review.opendev.org/c/openstack/nova/+/866087 | |
| 23:16:54 | opendevreview | melanie witt proposed openstack/nova stable/ussuri: Fix the wrong exception used to retry detach API calls https://review.opendev.org/c/openstack/nova/+/866088 | |
| 23:16:55 | opendevreview | melanie witt proposed openstack/nova stable/ussuri: Retry attachment delete API call for 504 Gateway Timeout https://review.opendev.org/c/openstack/nova/+/866089 | |
| 23:19:16 | opendevreview | melanie witt proposed openstack/nova stable/train: Fix the wrong exception used to retry detach API calls https://review.opendev.org/c/openstack/nova/+/866090 | |
| 23:19:17 | opendevreview | melanie witt proposed openstack/nova stable/train: Retry attachment delete API call for 504 Gateway Timeout https://review.opendev.org/c/openstack/nova/+/866091 | |
| 23:44:59 | clarkb | sean-k-mooney: bauzas: not urgent, but the other piece of info that is probably worht remembering for slow jobs is that we are our own noisy neighbor in some of these clouds. This means our own inefficiencies add up across jobs too not just within them. | |
| #openstack-nova - 2022-11-30 | |||
| 00:08:30 | opendevreview | Merged openstack/nova stable/xena: Fix the wrong exception used to retry detach API calls https://review.opendev.org/c/openstack/nova/+/829049 | |
| 04:05:27 | opendevreview | Ghanshyam proposed openstack/placement master: Policy defaults improvement spec https://review.opendev.org/c/openstack/placement/+/864385 | |
| 04:06:00 | gmann | gibi: sean-k-mooney: ^^ added the BP link in the placement policy spec | |
| 04:07:03 | gmann | bauzas: all done for placement project in LP, updated Driver and Maintainer to 'Nova Drivers' group https://launchpad.net/placement | |
| 04:08:27 | opendevreview | Ghanshyam proposed openstack/placement master: Policy defaults improvement spec https://review.opendev.org/c/openstack/placement/+/864385 | |
| 05:13:32 | opendevreview | Takashi Kajinami proposed openstack/os-vif master: Fix how deprecated_reason of ovsdb_interface is logged https://review.opendev.org/c/openstack/os-vif/+/866102 | |
| 08:24:07 | gibi | gmann: thanks, I'm +2 | |
| 08:35:48 | bauzas | gmann: cool, thanks for the LP janitoring | |
| 08:53:23 | opendevreview | Sahid Orentino Ferdjaoui proposed openstack/nova-specs master: fixing: allowing target state for evacuate https://review.opendev.org/c/openstack/nova-specs/+/866108 | |
| 09:37:00 | opendevreview | Fabian Wiesel proposed openstack/nova master: Add more password generation options https://review.opendev.org/c/openstack/nova/+/865669 | |
| 10:33:18 | opendevreview | Kirill proposed openstack/nova-specs master: new spec: support of vnc console for ironic https://review.opendev.org/c/openstack/nova-specs/+/863773 | |
| 11:00:13 | opendevreview | Merged openstack/nova stable/victoria: Adds a repoducer for post live migration fail https://review.opendev.org/c/openstack/nova/+/863902 | |
| 11:55:32 | sean-k-mooney | gmann: fyi im adding you to https://review.opendev.org/c/openstack/nova-specs/+/863773 to check my reasoning for why this would be ok to implemtne without an api microversion | |
| 12:18:47 | opendevreview | Merged openstack/placement master: Policy defaults improvement spec https://review.opendev.org/c/openstack/placement/+/864385 | |
| 13:01:53 | opendevreview | Takashi Kajinami proposed openstack/os-vif master: Fix how deprecated_reason of ovsdb_interface is logged https://review.opendev.org/c/openstack/os-vif/+/866102 | |
| 13:04:49 | opendevreview | Sylvain Bauza proposed openstack/nova stable/zed: Reproducer for bug 1951656 https://review.opendev.org/c/openstack/nova/+/866151 | |
| 13:04:50 | opendevreview | Sylvain Bauza proposed openstack/nova stable/zed: Handle mdev devices in libvirt 7.7+ https://review.opendev.org/c/openstack/nova/+/866152 | |
| 13:06:30 | opendevreview | Sylvain Bauza proposed openstack/nova stable/yoga: Reproducer for bug 1951656 https://review.opendev.org/c/openstack/nova/+/866153 | |
| 13:06:31 | opendevreview | Sylvain Bauza proposed openstack/nova stable/yoga: Handle mdev devices in libvirt 7.7+ https://review.opendev.org/c/openstack/nova/+/866154 | |
| 13:07:32 | opendevreview | Sylvain Bauza proposed openstack/nova stable/xena: Reproducer for bug 1951656 https://review.opendev.org/c/openstack/nova/+/866155 | |
| 13:07:33 | opendevreview | Sylvain Bauza proposed openstack/nova stable/xena: Handle mdev devices in libvirt 7.7+ https://review.opendev.org/c/openstack/nova/+/866156 | |
| 13:08:46 | opendevreview | Sylvain Bauza proposed openstack/nova stable/wallaby: Reproducer for bug 1951656 https://review.opendev.org/c/openstack/nova/+/866157 | |
| 13:08:47 | opendevreview | Sylvain Bauza proposed openstack/nova stable/wallaby: Handle mdev devices in libvirt 7.7+ https://review.opendev.org/c/openstack/nova/+/866158 | |
| 15:36:25 | gmann | sean-k-mooney: sure, I will check | |
| 16:54:01 | gmann | dansmith: when you will start your leave? | |
| 16:54:18 | dansmith | gmann: next weds is my first day gone | |
| 16:54:19 | gmann | I wanted to discuss about service role in nova. we can discuss now if you are ok? | |
| 16:54:22 | gmann | ok | |
| 16:54:44 | dansmith | sure | |
| 16:56:04 | gmann | dansmith: I was testing service role in tempest and it seems the APIs we are targeting for service role (swap volume, sever external) need to get the server and service role cannot do that, https://review.opendev.org/c/openstack/tempest/+/864595 | |
| 16:56:33 | gmann | they need admin permission also to get the servers (as it is of other project) | |
| 16:56:47 | dansmith | gmann: meaning you can't run the whole test with just the service role right? | |
| 16:57:08 | gmann | dansmith: yes, it fail on 404 for server not found | |
| 16:57:44 | gmann | either we need to allow get server to service user or keep these internal APIs as admin access | |
| 16:57:57 | dansmith | right so you'll have to do everything *except* swap_volume with a user token, and only swap_volume with the service token right? | |
| 16:58:36 | gmann | yeah | |
| 16:59:03 | dansmith | isn't that what we expect cinder to do? *only* call swap_volume with the service user | |
| 16:59:03 | gmann | but that need to be further tested if volume get in same situation as service role cannot get volume in cinder | |
| 16:59:27 | dansmith | oh, you mean nova tries to get volume during swap_volume/ | |
| 16:59:54 | gmann | not nova. may be server external event is good example | |
| 17:00:13 | sean-k-mooney | gmann: for the tempest user could have both both admin and service | |
| 17:00:22 | bauzas | dansmith: when you mean a "leave", you mean a PTO or something else ? | |
| 17:00:25 | sean-k-mooney | and you coudl drop admin later | |
| 17:00:26 | dansmith | sean-k-mooney: I think that's a bad idea | |