2018-12-04 #opensuse-admin [19:50:40] I'll be a bit late to the meeting [19:52:09] okay [19:56:50] ah, another meeting >:D [19:59:30] hello [20:02:20] who else is here? [20:02:28] * cboltz waves [20:03:08] ah, on the back row. [20:05:20] should we start the meeting? We could at least do the Q&A until tampakrap is back [20:06:12] yes lets get started. [20:06:28] ok, then welcome to the heroes meeting ;-) [20:06:33] hello [20:06:48] the topics are on https://progress.opensuse.org/issues/43460 - but we can always add something [20:07:07] let's start with Q&A - does someone from the community have questions? [20:07:27] I do, but it's a long one :/ [20:07:34] lets have it [20:07:51] i'm back, hello everybody [20:07:53] this issue: https://github.com/openSUSE/static.opensuse.org/issues/1 [20:08:03] it's a long question [20:08:51] right, the "unused stuff" on static.o.o [20:09:27] you already know my opinion that it's "probably unused stuff", and that IMHO cleaning it up is not really worth the time [20:09:45] but if someone has a different opinion, I won't insist on that ;-) [20:09:59] it isn't, but on the other hand, not everything there can function as free ad for us [20:10:07] lcp: I can provide you the logs of the past year [20:10:13] if they are unused,then remove [20:10:15] that would be great [20:10:37] meh [20:10:39] was gone [20:10:49] https://progress.opensuse.org/issues/44726 < tampakrap cboltz pjessen if you are interested [20:10:58] keyserver.o.o should be "more available" now at least [20:11:07] actually, on the similar topic, is there a way for all the error pages to exist in seperate repo instead of doing repeat of them on all those subdirs in repo? [20:11:43] there's not much point to have to host a lot of the same [20:12:00] i'm aware about sks-db frequent crashes, didnt have time to investigate yet [20:12:20] tampakrap: the problem is that people push chunks of bullshit in [20:12:22] and random requests [20:12:31] it's the problem of sks [20:12:38] it was big discussed on the ML [20:12:47] all users of SKS are facing those issues since weeks [20:12:52] lcp: not that i know of [20:13:00] thomic: just curious - which file did you edit? [20:13:22] cboltz: ah sorry /usr/lib/systemd/system/sks-db + samepath/sks-recon [20:13:37] if somebody is happy [20:13:45] apply those changes to the package :D [20:13:48] i'm unhappy atm [20:13:49] understood [20:13:49] :) [20:13:53] you know that overrides should go into /etc/systemd/system/ ? ;-) [20:14:03] cboltz: well *YOLO* [20:14:20] you didn't forbid me that with your apparmor rule ;) [20:14:42] it's a nasty quickfix [20:14:55] but i don't see atm the software quality improving [20:14:58] i asked for filtering [20:15:01] i asked for more info [20:15:05] the project is stuck [20:15:18] and it seems that people start thinking of "no longer having public gpg servers" [20:15:27] instead using private-based stuff like keybase.io [20:15:33] so gated-communities [20:15:36] i'm not a fan of this [20:15:49] do you have a link of that ml discussion? [20:16:13] thomic: you can selfhost keybase, can't you? [20:17:18] lcp: well than still it stays a gated community [20:17:23] and i cant see others' keys [20:17:28] which i need to encrypt [20:17:41] tampakrap: well it's basically following - 1sec links follows [20:18:40] nice [20:18:50] that sucks big time [20:19:11] and i was really curious why it suddenly started crashing [20:19:49] i even tripled its cpu/ram and it continued crashing [20:22:30] can we move on? [20:22:34] so at least it now crashes faster and better ;-) [20:22:42] yes [20:22:42] true [20:22:50] fuck [20:22:54] i just had a linklist [20:23:02] and paste.o.o replied with "you are a spammer" [20:23:03] kthx [20:23:04] :( [20:24:04] the "back" function of your browser should help to get the link list back [20:24:15] nope [20:24:19] it was empty than [20:24:22] the input field :) [20:24:25] dont ask me why [20:24:27] :-( [20:25:51] since we already slided into status reports - does someone have more status reports? [20:26:57] not much to report. have not had much time other than for the regular stuff [20:27:16] one report from me - I made the "mistake" to install the pending updates on monitor.o.o ~2 weeks ago [20:27:23] (didn't work automatically because of a conflict) [20:27:42] the result were lots of conflicting files in the icinga config [20:28:09] I updated elsa on leap15 [20:28:14] anna is still on 42.3 [20:28:33] tampakrap cboltz https://pastebin.com/mK9Nwut5 [20:28:33] I fixed a few issues, but I'd like first to make elsa primary for a few days in case there are more issues [20:28:37] here you go [20:28:40] and then move anna as wewll to leap15 [20:28:41] with all of the needed links [20:28:42] :) [20:28:44] I got that fixed by renaming or commenting out "our" custom icinga config, but the monitoring config might now be slightly different than before [20:29:08] it's mostly the gdpr + keyservers + MAGNET URI + attack from raspberry pi possible [20:29:14] that in combined words says - it sucks [20:29:49] nice[tm] [20:29:58] nevertheless, thanks for the links! [20:30:28] no problem you're welcome [20:30:38] in one of those, this guy quote my mail to the mailinglist [20:30:42] without even asking me [20:31:09] it's all a firespitting against sks i think [20:31:16] but they are not really willing as well [20:31:22] so i don't know what will happen in future [20:31:31] i just know - it is really bad sit atm [20:31:56] cboltz: thomic also found an issue on the check_mk package recently [20:32:22] lol [20:32:22] =) [20:32:24] ... and I thought finding nasty bugs is my job ;-) [20:32:27] that was a n1 one [20:32:45] check_mk renamed its firewall file from check_mk-service to check_mk [20:33:00] but nobody told SuSEFirewall2 in /etc/sysconfig about it [20:33:02] =) [20:33:24] I can imagine that this caused some fun ;-) [20:33:37] Error 111 - Connection refused [20:33:38] =) [20:34:15] it's time to migrate to firewalld =) [20:35:02] most of the service files don't exist there - because packagers seem not to care that much about firewalld =) - which puts the blame back to us and our own salt configured service files [20:35:12] which in general - i could support [20:36:50] well, people are used to SUSEfirewall and, as long as it works, why replace it? ;-) [20:37:03] note that is the "user view", probably not the "maintainer view" [20:37:31] (but I have to admit that I prefer sysconfig style over XML config ;-) [20:37:54] i have to say, after using firewalld - it's not completely finished yet - but it has very nice concepts [20:38:02] which take some pain away [20:38:08] and with Leap15 you should use it [20:39:59] actually - to avoid the XML, https://github.com/saltstack-formulas/firewalld-formula/ could help (just found it, no idea if it works ;-) [20:42:11] different topic - [20:42:21] we have pending kernel updates for lots of VMs [20:42:44] I already updated a few I know, or at least know good enough to know that they survive a reboot [20:43:02] but I'm not too keen on rebooting machines I never touched before ;-) [20:44:21] so [20:44:21] does someone who knows those VMs better volunteer to do the kernel updates? [20:44:33] i can help out with that tommorow [20:44:38] but now i need to get to know my bed [20:44:38] =) [20:45:26] ok, then thanks and good night ;-) [20:46:00] are you around (by any chance) tommorow morning [20:46:01] otherwise [20:46:09] how about thursday afternoon? [20:46:39] I'm usually available if it's raining or dark ;-) [20:46:53] so full week - :D [20:46:56] it's raining [20:47:33] it didn't rain today [20:47:38] anything urgent? [20:47:53] but in general, the forecast looks like it will rain more than once this week ;-) [20:48:08] anything with public interface would be mostly urgent imho [20:49:33] check the list in the monitoring - or just assume that everything I didn't touch is waiting for the kernel update ;-) [20:50:12] okay [20:50:18] for public interfaces, candidates are at laanna, baloo, [20:50:25] err... [20:50:33] for public interfaces, candidates are at least aanna and baloo, [20:51:00] but I don't have a full list of machines with public interface in my head [20:51:11] okay no worries [20:51:22] I might check this week if time permits [20:52:10] ok, thanks [20:54:05] I'd like also to finish the anna/elsa leap15 update as well, so I can move to the daffys [20:56:19] so anything else? [20:56:58] nope [20:57:21] didn't check the tickets, but ive been wokring a couple [20:58:01] I believe we didn't take many after my last cleanup last month [21:00:25] cboltz: anything else from your side or can we close? [21:00:49] IMHO we can close [21:01:01] so that I don't have to do two meetings in parallel (the board meeting is just starting ;-) [21:01:11] cool [21:01:38] yeah - merry xmas everyone! [21:02:19] one last question - date of the next meeting [21:02:51] do you like January 1st, or should we move it by a week? [21:03:07] maybe postpone until feb? not much is likely to be done over the holidays I think [21:03:16] yes let's postpone please [21:03:27] ok [21:03:46] so feb 5 [21:09:17] perfect [21:09:29] thanks everybody, have a nice christmas