2019-05-07 #opensuse-admin meeting [20:02:32] is someone here for the heroes meeting? [20:27:40] Hi [20:27:53] hi [20:28:04] did I miss the heroes meeting? [20:28:18] not really, nobody showed up [20:28:25] HI I'm also a bit late [20:28:50] Hi Martin [20:28:57] hi [20:29:01] cboltz: you are not alone ;) [20:29:07] :-) [20:29:27] and I hope we will see each other on osc 19 [20:29:38] yes, I'll be there [20:29:44] cboltz: Yeah, but *I* am alone. [20:29:51] I think there is a lot to talk about it [20:30:16] I will also be there at least Fri and Sat [20:31:01] Michael will give a talk about Æ-DIR on sunday, please don't miss it ;-) [20:31:14] For example the future of connect.opensuse.org. That machine needs be turn off soon . [20:31:27] yep I will be there. [20:31:52] (IMHO Æ-DIR it could replace FreeIPA,but let's talk about that after Michael's talk) [20:32:42] regarding connect - fully agreed, I hope we have a replacement ready soon [20:32:45] ae-DIR shows as ?-DIR here in pidgin [20:33:18] looks like pidgin has utf-8 issues, or you just need to switch to a bette font [20:33:51] may be a font issue. did not use that VM much otherwise. [20:34:41] one thing I added to today's agenda is [20:34:42] Same here in HexChat [20:34:46] move content of https://progress.opensuse.org/projects/opensuse-admin-wiki/wiki/Machines pages to pillar/id [20:35:05] cboltz: its more the politic desition the technical... [20:35:21] let look there [20:35:25] yet, from bmwiedemann, it shows properly [20:35:33] the reason why I propose this is that pillar/id/* is maintained, while the wiki pages are, well, less maintained ;-) [20:35:40] Fraser_Bell: because I wrote it as ascii [20:35:45] as ae-DIR [20:35:57] ?Did that show? [20:36:01] yes [20:36:17] mcaj: so, what's your polictical ;-) opinion about moving the machine details to pillar/id/ ? [20:36:19] Try it without ASCII [20:36:42] cboltz: would it be gpg-encrypted then? [20:36:44] If it works, we narrow it down to cboltz [20:37:23] bmwiedemann: no, and I see no reason to encrypt it ;-) [20:37:35] for example, look at https://progress.opensuse.org/projects/opensuse-admin-wiki/wiki/Annainfraopensuseorg [20:37:45] is there anything top-secret in it? I doubt ;-) [20:38:04] was just wondering because I saw some cert renew touched an encrypted blob, though certs are public [20:38:18] Yes. the a & the e is top secret, apparently. [20:38:58] ;-) [20:39:06] cboltz: I have mo problem to do it. But If we have a machine there we do a kernel update and machine is not able boot any more, then I see a problem... [20:39:33] bmwiedemann: we have some things gpg-encrypted, for example database passwords [20:39:48] and there's also a separate pass repo with root passwords etc. [20:40:44] mcaj: moving the machine info to pillar/id/ might even help in that case because (I hope) you have cloned the salt repo locally [20:41:15] hi pjessen [20:41:17] sorry for being late, something went wrong with konversation [20:41:31] cboltz: distributed information is indeed less likely to get lost [20:41:48] pjessen: don't worry, we started only 5 minutes ago because most people were late [20:41:49] well sure let do it , BTW what is the procedure, create a MR for it ? (fine with me) but who do the code review ? [20:42:18] haha, thanks [20:42:19] pjessen: keine stress, we just start ;) [20:42:32] yes, create a MR [20:42:42] the review can be done by each of us [20:43:32] I need to check the email setting there ... I think i'm not getting emails from infra gitlab ... [20:43:52] * mcaj knows how to do it [20:44:33] my experience is that you should simply subscribe to "everything from the salt repo" [20:44:43] (no worries, you won't get a mail flood ;-) [20:45:20] BTW what about the machine rsync.opensuse.org I spoke with Tbro and looks like this machine has some problems with stability ... [20:45:56] I don't know all details [20:46:00] what I know is: [20:46:15] - the machine was replaced after the old one broke last year [20:46:20] right. [20:46:24] yes [20:46:24] - the replacement is a used OBS server [20:46:39] - the harddisks are too slow for the traffic the machine gets [20:46:45] so it s a bare metal machine ? [20:47:07] yes, hosted at a sponsor's datacenter [20:47:13] there are several public mirrors that provide rsync, so I use these instead. Maybe we could convince one of those operators to let us point rsync.o.o there? [20:47:45] * mcaj have an idea : start donation for the server and buy new fast disks for it ^^ :) [20:48:07] i think rsync.o.o might be superfluous [20:48:50] anyone who wants a private mirror can create one with wget, from the rest of the mirrors [20:49:19] wget sucks for that. but rsync from public mirrors is fine. [20:50:14] basically rsync.o.o is at best a "nice to have", that's my piont. [20:50:18] there's also the idea to rent some https://www.hetzner.de/dedicated-rootserver/sx62 servers to run rsync.o.o [20:51:16] that one has spinning rust though, so only 100 IOPS [20:51:31] yes but I think the core server should be the best what we can have... why to run in on 5 or more old SATA disks ... [20:51:34] last I checked the usage (I don't have access to widehat right now), I counted some 10 mirrors I think. [20:52:13] max thruput is 100MB/s anyway. (on a 1Gbps link [20:52:28] 10 users, not 10 mirrors [20:52:46] bmwiedemann: I know, but for the disk space we need, renting 4 of them is probably still cheaper than one server with enough SSDs [20:52:48] pjessen: Why you do not have it ? I think specially you should have it ... [20:53:07] i wonder if tbro hasn't had time to set it up. [20:53:54] pjessen: I will ping him in two days. We need to fix this! [20:54:08] okay, sounds good. [20:55:25] check ;) [20:55:48] mcaj: do you have some time to setup two VMs for me? [20:56:08] maybe ^^ :) [20:56:10] * Fraser_Bell agrees with mcaj re. donations? [20:56:33] ok, so my wishlist ;-) is: [20:56:49] cboltz: send me the mail/request with spec about them. [20:57:06] ok [20:57:14] tomorrow i a day off but by end of the wee I can do it. [20:58:06] one detail I'll already mention here is that these VMs should run 15.1 ;-) [20:58:19] (I created/updated the JeOS image some weeks ago) [20:59:05] welcome to the meeting, knurpht [20:59:09] cboltz: NP to me :d [20:59:58] cboltz: Could you maybe start with your 'Couple of things' ? [21:00:05] as a sidenote - cboltz.de and blog.cboltz.de is already running on 15.1 since yesterday [21:00:14] ;-) [21:00:53] Meh. *.knurpht.nl is running Tumbleweed :-) [21:00:57] yeah for servers, 15.1 is looking very good. [21:01:23] pjessen, et al: THAT is nice to hear! [21:01:30] I'd love to do that, but there are more domains on that server, and they don't like daily upgrades too much [21:01:54] cboltz: plan is to move the thing to 15.1 [21:02:10] I test TW for servers and welll leap is leap [21:02:23] (especially new PHP versions can be interesting[tm] - but it was a good reason to finally upgrade some things ;-) [21:02:39] mcaj: Actually, leap is Leap [21:02:52] works but need constant maintanance with some m. windows ... [21:03:04] ja ja ja [21:03:14] where are we on the meeting agenda? [21:03:24] ^ ?? [21:03:30] PHP is nightmare .. [21:03:38] pjessen: we use /dev/random as meeting agenda pointer today ;-) [21:04:06] cboltz: ROTFL [21:04:07] ah, sorry. I guess I missed the introduction :-) [21:04:11] the main point should be : book a hotel and visit OSC 19 ! [21:04:38] exactly [21:04:39] Too late, mcaj: Maybe oSC 20? [21:04:56] and there let talk about it. ATM the infra is fine but I see some week points there ... [21:05:14] week? not daily? [21:05:18] mcaj: Be quick, Doug has warned lots of times on all platforms, that there is some huge opticians congress the same weekend. [21:05:27] as long as you don't see _weak_ points... ;-) [21:05:48] I wont make it, got other priorities. [21:06:04] knurpht: I can not comment that since I'm in SUSE... [21:06:07] but [21:06:20] that Su** Fu** ... [21:06:24] :( [21:06:46] SUSE has tents in Fürst. [21:07:06] And Ask there who made that time frame ... [21:07:15] it's May, termperatures only go slightly below [21:08:02] we had 2 C some morning this week [21:08:03] * knurpht slept a night outside at oSC17 due to hotel room being > 40°C [21:08:31] ice on the car this morning. [21:08:54] knurpht: sounds like "free sauna" ;-) [21:08:59] Hi [21:09:08] hi [21:09:12] sorry being late, [21:09:23] wrong timezone agaie :( [21:09:31] We is hitting 30C/89F here in Kamloops in a day or two [21:10:16] Fraser_Bell: in Canada? [21:10:43] Of course. Where else, since I do not have a passport? [21:10:56] tuanpembual: are you the correct person who is working ATM on redmine upgrade ? [21:11:20] Canada replaced passports with grass [21:11:28] yes mcaj [21:11:37] Actually, the whole country went to pot. [21:11:44] but not finish yet. [21:11:51] & US has been Trumped [21:12:27] tuanpembual: I know but is the any progress do you need any help from ENG INFRA team or from the Heores team ? [21:12:31] tuanpembual: Thanks for working on it. [21:13:27] mcaj: I cannot login to database cluster from the server [21:13:36] connect server [21:13:48] ok [21:14:22] tampakrap dont write password on crendential file. [21:14:30] tuanpembual: can tyou send me your GPG key ? I will collect and send you need passwords ... [21:15:03] noted. will dm you my gpg [21:15:28] ack [21:17:52] I think we need to look really hard at getting our infrastructure on our own servers under our own control, should start whatever campaign we need to get sponsors and get that done, as there are far too many location, connection, and similar issues the way things are. f.e.: (and only one of many) I tried adding the 15.1 release counter on my servers in Florida, New York, and Eastern Canada. Somehow it is blocked [21:17:53] (certificate? or?) and will not show up. [21:18:37] Fraser_Bell: see latest Board meeting minutes. [21:18:47] on project ML [21:18:48] ... and, as a webmaster, along with all else I am currently working on, I have no time to troubleshoot. [21:19:06] Fraser_Bell: the counter is hosted on our own servers (well, SUSE servers running openSUSE VMs) so we have full access [21:19:25] open a ticket? [21:19:25] if you tell me where embedding fails, I can check it [21:19:35] SUSE servers, and most of my connection problems I run into are SUSE-based. [21:19:46] Including accessing the Forums, from time to time. [21:20:01] we had some IPv6 trouble in some places [21:20:39] the forums live in Provo on Microfocus servers, which is a totally different story ;-) [21:21:09] Yes, but waiting for suse.com and waiting for microfocus is about equal. [21:21:33] the funny thing is that suse.com is also hosted by microfocus [21:21:59] Thanks all, Im looking forward to see you in a few weeks in Z-Bau and I need to go now.. [21:22:14] mcaj: have a good time. [21:22:16] mcaj: ciau [21:22:22] mcaj: see you there [21:22:38] thanks mcaj - same here, gotta go. (unless anyone's got anything important for me?) [21:22:52] I'm always here but in "invisible" mode :d [21:23:14] LOL I feel that way sometimes, too. [21:24:18] Leaving. See you next time, maybe. [21:35:08] good night [21:35:27] good night [22:05:28] good night all. [22:14:53] good night