-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Mon, 28 Sep 2026 20:56:26 +0200
Source: openstack-cluster-installer
Architecture: source
Version: 43.0.34
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Changes:
openstack-cluster-installer (43.0.34) unstable; urgency=medium
.
* New /etc/openstack-cluster-installer/repos feature for managing
package repositories in OCI:
[8bd740a] Move the repository puppet classes into manifests/repos/
[3445260] Move the vendor and debian repository templates under repos/
[8a35cdb] Add the unified repository templates with per-repository
activation.
[ea825b2] Feed the unified repositories through the ENC and puppet.
[332f4ac] Install the unified repositories at baremetal install time.
[a1875b8] Build the live image from the repository template folders.
[9989469] Match the supported_arch values in the repositories define.
[50a781a] Keep the PoC bootstrap contract for the repository key
[c752e87] Drop the obsolete Ceph directives and flows
[ee249b7] Add the supported_role directive to the repository templates.
[03e72d9] Move the elastic and filebeat repositories to the vendors
templates
[bbfb5fd] Fix comment in elastic/repo.conf
[7be3cc1] Add the [repo_tokens] conf section and unify the repository
token resolution
[91fee0c] Tokenize the remaining repository template URLs
[0f81a96] Move the Debian mirror variables to the repository token
mechanism
[0bb4970] Drop the legacy live image backports setup flow
[d0077b9] List every repository template token in
openstack-cluster-installer.conf
[1bdd76d] Activate the shipped repository token defaults in
openstack-cluster-installer.conf
[371051e] Generalize the CEPH_OSBPO_RELEASE repository token
[4fc3f52] Drop the legacy official backports Ceph pinning flow
[dd665fb] Resolve repository filename collisions by codename
specificity
[931a8ca] Add the unsupported_codename directive to the repository
templates
[97bb2ac] Ship a bullseye-security repository template
[78df990] Fix the osbpo key path and repository URL in the cluster upgrade
tools
[c275f66] Switch the Debian deb822 sources in the cluster upgrade tools
[bac9c2c] Quote the conf values when sourcing them in the shell tools
[17bd207] Ship the repository templates to the live image builders
[69e7f59] Process the Debian base and security repositories in the bodi
hook
[470750a] Honor the Check-Valid-Until conf flags in the bodi hook
[a6506b1] Drop the dead skip-list from the live image repository installation
[2cf1a04] Stop live-build from managing the security suite
[25ab22a] Drop the classic sources.list from the live image
[9217ca3] Drop the contrib-non-free repository archive from the live image
[022dff4] Install the live image packages from the repository hook
[96f948e] Drop the classic sources.list from the live image final filesystem
[c61a93f] Remove the global Check-Valid-Until apt.conf from the live image
[2839668] Materialize the token mirrors for the target OS install
[594f16f] Let live-build manage the live image base sources
[3d4296f] Disable the elasticsearch module repo management
[6ddf25c] Recursively create missing directories in mkdir_if_not_exists
[cc35046] Remove the legacy vendor-keys staging from the install template
[69adbd7] Order packages after the OCI repositories apt-get update
[f6e363a] Drop the legacy /etc/oci_debian_mirror files channel
[27b90d5] Retire the deb822 Check-Valid-Until conf flags
[05c9def] doc fix: Debian repositories specificities section.
[7684858] PoC: Fix vigie image also seeing daily image.
[7d81e40] Add a bookworm-qemu pinning repository, like bullseye-qemu.
[5255bd1] bullseye-qemu: pin with n= rather than a=
* Misc changes:
[9ba032b] Fix the ssh known hosts CA check in oci-live
[e3bd5c6] Fix the ssh known hosts CA check in the live image builder
* Reorganize oci-agent/openstack-cluster-installer-bodi-hook-script:
[f1881d0] Split the bodi hook setup steps into functions
[356056c] Split the bodi hook package installs into a function
[807ce5d] Get the PS1 serial number from oci-system-serial
[06cacc5] Clarify hostname variable names in the bodi hook.
[a2accfa] Move the repository processing and the OCI utils install into
functions.
[0747bb7] Prepare the install-time bootstrap files on the install template.
[a49cb0e] Reorganize the bodi hook and declare its function variables
local.
* Misc:
[d859b66] Add opencode skill with OCI project knowledge
[e78ece0] Keep the repository templates on the live system and delete them
once used.
[0d2a8ef] Drop the backports flags and fix the radosgw typo in
variables.json. Note: admins should manually remove the column in the OCI
"machines" table.
* Refacto the enc.php:
[0892125] Replace the repeated ENC password fetch pattern with a helper.
[93cae4f] Convert the ENC to build a yaml object and dump it.
[79e4657] Convert the DB-sourced booleans to real PHP booleans.
[2177748] Unify the common role parameters.
[9bc0915] Run the ENC SQL queries through a throwing helper.
[10a9014] Count the role nodes with a dedicated helper.
[f057cef] Fix empty haproxy_custom_url redirect breaking the API frontend.
[5b22eaa] Cast the ENC netmask values to integers.
[723510a] Fix the ENC DB-sourced scalar types.
[8625b33] enc: emit nothing for unset repository directives.
* General OCI refacto:
[7de53ab] Remove the use_ssl parameter: SSL is always on.
[67c7c38] Pass the PoC mirrors to the amphora image build
[28cb4bf] PoC: Add python3-cloudkittyclient before provisionning.
* General bug-fixes:
[0bc392d] Always register the cloudkitty rating endpoint.
* Tempest run fix:
[d9c2dd8] Fix the Octavia failures seen in the PoC tempest runs
Checksums-Sha1:
3e933eec603e2ecab8a944f7a6575843298203be 2647 openstack-cluster-installer_43.0.34.dsc
53cc2fea62950d1200874808431e77d6365fc191 512836 openstack-cluster-installer_43.0.34.tar.xz
8822ca25da45ea8b9ace8eb69cfcd07b6c77f7d5 9772 openstack-cluster-installer_43.0.34_amd64.buildinfo
Checksums-Sha256:
1168ff817d3b337f4d2899a2ee1f480a31fb863ca0320f6bb6b28a4233ab4553 2647 openstack-cluster-installer_43.0.34.dsc
2a7c3e30845c07ad0cf0353118f00ba630f9fe45efd3e25019d3571c3a87e78a 512836 openstack-cluster-installer_43.0.34.tar.xz
aa641bc54b92dcabed222b5e0d59e1e45df795abbb9a36613df50e2ae241e240 9772 openstack-cluster-installer_43.0.34_amd64.buildinfo
Files:
938b313db68b7bc24f73174c6672c714 2647 net optional openstack-cluster-installer_43.0.34.dsc
6ffca435664a91bf28500386053e83e1 512836 net optional openstack-cluster-installer_43.0.34.tar.xz
38f5ad8b46f585cea9c7e3a94ca648a4 9772 net optional openstack-cluster-installer_43.0.34_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmq6uSYACgkQ1BatFaxr
Q/7DEw/9FR7lhL3cwUJ+Jkfu6ElBFg64ceaAvUui8Rr4gE/Ok/6ZSLF3XZNSfe/s
pyS78gl2W+UXVTnsaVqYP/WrhUTl9FkiVBFMNYQcij5EBQIPdL+6KgyDlAZ/10t0
oyW1szpzR5JWlWuX3OVr2aaObvkhK+BvDwgUM/rNoZEJSYKu5XgX1srbOYuh3Fvy
d+1PuOKIzE0qpkGckH17HzMAQ3MDNAuzJcIwpz8uMVDfsdHbRan3Szk7OURXBt7z
tTb7I3Yg1wkEL7LuHueFzZkkpgEGugbEt5onxwuMwc5pc/9Qo/H8BHJKBgRvGak0
j3f8bSQ9kLfZQ6nQJyAT+SyM31CGk3N2aZergZXajN/a6sy2lyYk8iNliFm9XbRQ
SDCzU1NLk6NhpHTyyvFaaRmBg/jVFWvl/MrKz5807i5o8qL5XHbxU2T8w/cGMhEH
RgEaXuOwQtlqMEI45Bb3BvAvpfAuPcGGU7jgdkpwSRzky1DqVF+mFOM+Ug5d09EC
vNvrCMsBtG5o2W6sJMfhz36kyzmGlDS98FniZDSS05ajF2fbmYKDlBHsv0UkqnWM
XZL7ZQ5az+rqRagt0OzAkcbVFO5OoJkdh9Bx+XYnZkbzgfChnmMnmFE75gemE1x1
BEJVlw+5VwhNGd4cUxZe+DV9G0qTQ6QwZG4s3dmSC5HU1a1u/8U=
=qYti
-----END PGP SIGNATURE-----