Earlier  
Posted Nick Remark
#openstack-nova - 2023-05-10
07:38:50 opendevreview Amit Uniyal proposed openstack/nova master: WIP: Reproducer for dangling volumes https://review.opendev.org/c/openstack/nova/+/881457
07:38:50 opendevreview Amit Uniyal proposed openstack/nova master: WIP: Delete dangling bdms https://review.opendev.org/c/openstack/nova/+/882284
08:54:39 opendevreview Sahid Orentino Ferdjaoui proposed openstack/nova master: [wip]network: convert usage of neutronclient to openstacksdk https://review.opendev.org/c/openstack/nova/+/882714
11:10:58 opendevreview Sahid Orentino Ferdjaoui proposed openstack/nova master: [wip]network: convert usage of neutronclient to openstacksdk https://review.opendev.org/c/openstack/nova/+/882714
13:20:19 sean-k-mooney sahid: when you have time can you take a look at https://review.opendev.org/c/openstack/os-vif/+/881751 and https://review.opendev.org/c/openstack/os-vif/+/882755
14:19:05 sahid sean-k-mooney: sure, sorry I just have noticed your message
14:23:21 sean-k-mooney sahid: no rush
14:40:26 opendevreview Dan Smith proposed openstack/nova master: Use force=True for os-brick disconnect during delete https://review.opendev.org/c/openstack/nova/+/882847
14:53:25 opendevreview melanie witt proposed openstack/nova master: Enable use of service user token with admin context https://review.opendev.org/c/openstack/nova/+/882852
14:57:43 opendevreview melanie witt proposed openstack/nova stable/2023.1: Use force=True for os-brick disconnect during delete https://review.opendev.org/c/openstack/nova/+/882858
14:57:44 opendevreview melanie witt proposed openstack/nova stable/2023.1: Enable use of service user token with admin context https://review.opendev.org/c/openstack/nova/+/882859
14:59:46 opendevreview melanie witt proposed openstack/nova stable/zed: Use force=True for os-brick disconnect during delete https://review.opendev.org/c/openstack/nova/+/882860
14:59:47 opendevreview melanie witt proposed openstack/nova stable/zed: Enable use of service user token with admin context https://review.opendev.org/c/openstack/nova/+/882861
15:00:51 opendevreview melanie witt proposed openstack/nova stable/yoga: Use force=True for os-brick disconnect during delete https://review.opendev.org/c/openstack/nova/+/882863
15:00:52 opendevreview melanie witt proposed openstack/nova stable/yoga: Enable use of service user token with admin context https://review.opendev.org/c/openstack/nova/+/882864
15:03:26 opendevreview melanie witt proposed openstack/nova stable/xena: Use force=True for os-brick disconnect during delete https://review.opendev.org/c/openstack/nova/+/882867
15:03:27 opendevreview melanie witt proposed openstack/nova stable/xena: Enable use of service user token with admin context https://review.opendev.org/c/openstack/nova/+/882868
15:05:58 opendevreview melanie witt proposed openstack/nova stable/wallaby: Use force=True for os-brick disconnect during delete https://review.opendev.org/c/openstack/nova/+/882869
15:05:59 opendevreview melanie witt proposed openstack/nova stable/wallaby: Enable use of service user token with admin context https://review.opendev.org/c/openstack/nova/+/882870
17:01:57 dansmith need another quick +W on this to avoid a regression introduced in the CVE fix: https://review.opendev.org/c/openstack/nova/+/882852/1
17:01:59 dansmith sean-k-mooney: ^
17:02:07 dansmith gmann: ^
17:05:18 gmann dansmith: sure, checking
17:23:21 gmann dansmith: so this is not that CVE fix regression but before also this exist right? I mean admin token was not made as service token ?
17:23:34 gmann or cinder had put the check about service token instead of just admin
17:24:10 dansmith gmann: we didn't need service token for these admins contexts before.. there was literally no reason,
17:24:16 dansmith so it's not a regression without the CVE fix (from cinder)
17:24:34 dansmith however now we *do* need service users for things other than long-running user activities
17:24:35 gmann I see, so now cinder API check service token or not.
17:24:38 dansmith right
17:24:43 gmann got it
17:26:14 gmann +W
17:26:46 dansmith gmann: thanks :)
17:29:34 sean-k-mooney dansmith: sorry distracted but i was starting to review those now too
17:29:52 dansmith ack, I think we're good now
17:30:20 dansmith sailed through zuul first time.. probably because some awesome guy did a bunch of volume test hardening the last few weeks :P
17:30:32 dansmith or luck. yeah, it's probably luck :)
17:30:44 sean-k-mooney :)
17:31:04 sean-k-mooney there is a serprising amouth of doc updates in the previos patch
17:31:05 gmann I am sure its a special treatment given for volume test fixes :)
17:31:29 dansmith sean-k-mooney: yeah it's a pretty big change required for deployers
17:31:40 sean-k-mooney not that im complaing really but i was expecing ti to be more targeted
17:31:51 sean-k-mooney ack i have not read it all yet but that was just my intial reaction
17:31:57 dansmith no real option to be targeted unfortunately
17:32:12 dansmith a bunch of smart people spent the last 90 days trying to figure out a better way to do it
17:33:33 sean-k-mooney ok so the service user is now required
17:33:54 sean-k-mooney ok
17:34:45 dansmith the ossa went to the ML with more summary which might be good reading
17:35:01 sean-k-mooney ill read that after
17:35:12 sean-k-mooney we debated making the service user required in the past
17:35:26 sean-k-mooney not that it is we can use that for other usecases going forward
17:35:32 dansmith yup
17:35:42 sean-k-mooney like the manila stuff
17:35:57 dansmith yup, it was hard not to mention this during that discussion :)
17:36:11 dansmith seems like we could extend that to neutron and avoid nova having to be admin too
17:36:12 sean-k-mooney or any other interaction with other service where we need service to service interaction
17:36:18 dansmith yup
17:36:25 sean-k-mooney yep
17:36:43 sean-k-mooney we could simply nova config ot just need service user and no other sections for other services
17:36:50 sean-k-mooney at least by defualt
17:36:53 dansmith it's unfortunate to have to force that on a bunch of old deployments without a grace period, but.. not much choice
17:37:23 sean-k-mooney for what its worth i think many installer tools started using the service user a few years ago by default
17:37:37 dansmith yeah tripleo did
17:37:41 sean-k-mooney i think downstream its on by default in 17/train
17:37:50 dansmith and 16
17:37:57 dansmith but it's not just the service user that is required, but also the role on that user
17:38:05 sean-k-mooney sorry 16/train ya
17:38:24 sean-k-mooney OSA and kolla have supprot but i dont know if its on by default
17:38:46 dansmith s'gonna be soon :)
17:39:54 sean-k-mooney unfortunetly it looks like no but looking at there config
17:40:11 melwitt oh huh, is stable/wallaby ci known to not work?
17:40:30 sean-k-mooney when the service user is not configred it may have been possibel to fallback to the info form the keystone authtoken section
17:40:52 gmann melwitt: what is failing, it should be green
17:40:54 sean-k-mooney melwitt: no but devstack might not have service users configred htere
17:41:12 melwitt gmann: ERROR: Could not find a version that satisfies the requirement tempest>=30.0.0 (from cinder-tempest-plugin) https://zuul.opendev.org/t/openstack/build/4c8a3d86710a4d50871613e2e578831a
17:41:54 gmann melwitt: oh, we did recent change there, let me check if cinder-tempest-pluing is not pinned there. we did pin the tempest. its incompatible tempest and c-t-p
17:42:25 dansmith incompatible because of me
17:43:25 gmann dansmith: no, you just exposed that but we should pin all plugin along with tempest to have such issue coming in future.
17:43:38 dansmith \o/
17:44:31 gmann melwitt: dansmith: ah I pushed change while pinning tempest but did not realize it is not merged https://review.opendev.org/c/openstack/devstack-plugin-ceph/+/871920
17:44:59 gmann and that was the only change left for tempest pin on wallaby, :( https://review.opendev.org/q/topic:wallaby-pin-tempest
17:45:09 melwitt ah ok
17:46:50 melwitt I shan't recheck those then :)
17:48:47 gmann melwitt: yeah, it will fail until 871920 is merged, I will check it but not sure if ceph testing on wallaby is all working or not.
17:49:01 melwitt the plugin patch failed 25 tests ... not sure if they're unrelated fails
17:49:27 gmann melwitt: if urgent as CVE fix then we can make ceph job as n-v in wallaby for now to merge your fix
17:49:47 gmann yeah, I am not very positive of everything on ceph will work in wallaby
17:50:19 melwitt gmann: wallaby is nice-to-have I think, I just proposed it bc there was no change needed from the xena patch
17:51:03 gmann k
18:42:23 dansmith so I just noticed we're running a n-v job in the gate queue.. the ceph migration one
19:04:50 dansmith sean-k-mooney: so I've seen something that looks like this a number of times recently: https://92f377bbda976b6da17f-b08d635a9941444d91f5e0463ea7a01d.ssl.cf2.rackcdn.com/882852/1/gate/nova-grenade-multinode/b8a7af9/testr_results.html
19:05:40 sean-k-mooney test_list_migrations_in_flavor_resize_situation thats an interesting testname...
19:06:02 dansmith melwitt: dammit, ceph job timed out
19:06:03 sean-k-mooney hum binding failed
19:06:08 dansmith thought we were going to win the lottery
19:06:23 melwitt aw man
19:06:27 sean-k-mooney dansmith: the nv one or the working one. i guess the later
19:06:39 melwitt I've seen the port binding fail one a lot recently
19:06:44 dansmith the important one
19:07:14 dansmith we might want to up the timeout on the ceph job because it definitely takes legitimately longer with all the validations

Earlier   Later