vcswatch reports that
this package seems to have a new changelog entry (version
43.0.39, distribution
unstable) and new commits
in its VCS. You should consider whether it's time to make
an upload.
Here are the relevant commit messages:
commit 46d2dd6c9b0d386065465e8077894c0e99c3ddf6
Author: Thomas Goirand <zigo@debian.org>
Date: Tue Oct 6 14:22:43 2026 +0200
Break the vigie-worker / mistral-endpoint dependency cycle
The require => Class['::mistral::keystone::auth'] added to the
vigie::worker class created a dependency cycle:
Anchor[keystone::service::end]
=> Keystone_endpoint[cluster1/mistral::workflowv2]
=> Keystone::Resource::Service_identity[mistral]
=> Class[Mistral::Keystone::Auth]
=> Class[Vigie::Worker]
=> Package[vigie-worker]
=> Anchor[keystone::service::end]
The two outside edges are from puppet-keystone's keystone::deps:
Package<| tag == 'openstack' |> is ordered before
Anchor['keystone::service::end'] (the vigie-worker package carries
the 'openstack' tag), and every Keystone_endpoint is ordered after
that same anchor. A class-level dependency on a class containing a
keystone endpoint therefore can never work for a package tagged
'openstack'.
Replace the require with an ordering of the Mistral keystone
endpoint class before Anchor['vigie::service::begin'], so that the
Vigie services (including the worker) only start once the Mistral
endpoint exists, without involving the vigie-worker package. The
intent of the original dependency is preserved.
Validated with puppet parser validate on Bullseye's puppet 5.5.22.
commit 88d142e823b5fbce8730a9e01d5db80700d6db96
Author: Thomas Goirand <zigo@debian.org>
Date: Tue Oct 6 13:06:32 2026 +0200
Write /root/openrc even when using the external keystone
On clusters using the external keystone (external_keystone_activate
set to true), the whole local keystone section is skipped, which also
skipped the /root/openrc file resource. On Yoga to Bobcat,
puppet-keystone's providers resolve their authentication URL by
reading /root/openrc (fallback: ENV, then an authenticated
configuration request that can't work on its own). Without the file,
every Keystone_user provider failed its password check and reset the
password on every single puppet run (observed as 'changed password
(corrective)' for gnocchi, ceilometer, cloudkitty, aodh, octavia,
designate, ... on a Zed cluster).
Move the /root/openrc if/else block out of the local keystone section
to the class body, so that it is evaluated in both cases.
commit f0424bf60292bf9730c6265762af9ea5e3c88f31
Author: Thomas Goirand <zigo@debian.org>
Date: Tue Oct 6 12:57:56 2026 +0200
vigie::worker require => Class['::mistral::keystone::auth']
commit 37441147af2ec1490e388d31429121b06d24eb34
Author: Thomas Goirand <zigo@debian.org>
Date: Tue Oct 6 09:14:13 2026 +0200
oci controller: mistral parameters now depend on the release
Installing a Zed cluster failed with:
Class[Mistral]:
has no parameter named 'amqp_auto_delete'
has no parameter named 'rabbit_quorum_queue'
has no parameter named 'rabbit_transient_quorum_queue'
has no parameter named 'rabbit_use_queue_manager'
has no parameter named 'rabbit_stream_fanout'
has no parameter named 'rabbit_qos_prefetch_count'
has no parameter named 'rabbit_transient_queues_ttl'
The ::mistral call passed all of the newer RabbitMQ parameters to
every release, but they only appeared over time in puppet-mistral:
rabbit_quorum_queue in Bobcat, rabbit_transient_quorum_queue in
Caracal. Upstream only added amqp_auto_delete,
rabbit_transient_queues_ttl, rabbit_use_queue_manager,
rabbit_stream_fanout, rabbit_qos_prefetch_count and
rabbit_enable_cancel_on_failover in Flamingo, however the Debian
packages of Caracal, Dalmatian and Epoxy carry quilt patches adding
them, so Caracal and up can be passed the full set of parameters.
Split the call in 4 tiers following what each release's puppet-mistral
actually declares (Debian patches included), like it is already done
for keystone and nova: Rocky and Stein get the base parameters, Train
to Antelope the same plus mistral_config for enable_cancel_on_failover,
Bobcat adds rabbit_quorum_queue, and Caracal and up keep the full
current set.
Each tier was cross-checked against the class declaration of the
matching puppet-module-mistral branch (including its Debian quilt
patches), and the result validates with puppet parser validate on
Bullseye's puppet 5.5.22.
commit 95269a40ab841fa792e794cbfa6fee50c1e5fbd6
Author: Thomas Goirand <zigo@debian.org>
Date: Tue Oct 6 08:50:50 2026 +0200
Also install mistral, needed by vmms.
commit 804a7dda7c1b3c6cc7c3529a8a7eccdd107ddfd3
Author: Thomas Goirand <zigo@debian.org>
Date: Tue Oct 6 01:44:30 2026 +0200
vigie: only pass the quorum/stream and amqp_auto_delete options to
class { '::vigie': } for OpenStack releases newer than antelope: older
releases ship a puppet-oslo which doesn't support them, and they now
default to undef in puppet-vigie >= 1.0.3, so the options are left
unmanaged there.
commit 37e3d215425e8acdbd8b7cf4f5e95e5128501ae6
Author: Thomas Goirand <zigo@debian.org>
Date: Tue Oct 6 01:22:20 2026 +0200
Releasing.
commit d0baa4441272e57f1dbfe63fcd8020397cb3aae6
Author: Thomas Goirand <zigo@debian.org>
Date: Tue Oct 6 01:20:58 2026 +0200
ENC: quote HH:MM-style scalars to avoid sexagesimal parsing
The puppet master parses the ENC YAML with ruby's psych (YAML 1.1),
which resolves plain scalars like 02:00 or 06:00 as sexagesimal
integers (7200 and 21600). A Zed cluster install then failed with:
Class[Vmms::Worker]:
parameter 'migration_start_time' expects a String value, got Integer
parameter 'migration_end_time' expects a String value, got Integer
as the oci module passes vmms_migration_start_time and
vmms_migration_end_time (both declared as strings in variables.json,
with 02:00 / 06:00 defaults) to the vmms::worker class, which types
them as String.
Post-process the final ENC YAML to quote any plain scalar made of
colon-separated digits, forcing string resolution. This preserves
the string value exactly, and can never touch int/float typed
variables (their values are pure digits), URLs, UUIDs, MAC or IPv6
addresses. It also covers time-like values coming from the hiera
snippets appended to the ENC.
Validated against the real ENC of cl1-controller-1.infomaniak.ch on
the Zed PoC: with the fix, ruby 2.7 psych (the production puppet
5.5.22 parser on Bullseye) resolves both parameters as the strings
'02:00' and '06:00', and the parsed ENC differs on exactly those two
keys.
commit 22aa603f3d2c9186ab60351d089789d39f33b532
Author: Thomas Goirand <zigo@debian.org>
Date: Tue Oct 6 00:31:50 2026 +0200
ocicli machine/cluster-show: faster field extraction
These two functions used to spawn one cat|jq process per field:
a cluster-show took 3.0 s and a machine-show 1.7 s, with ~420
process spawns over the 204 cluster / 33 machine entries of
variables.json. Two targeted optimizations, keeping the rest of
the code untouched:
- All OCICLI_MACHINE_SHOW_* / OCICLI_CLUSTER_SHOW_* attributes
are extracted by a single jq @sh pass emitting shell-quoted
assignments, eval'ed once.
- The variables.json option loops are now a single jq call using
--slurpfile, sorted by key like the old keys[] loop, with the
machine role gating done in jq.
cluster-show now runs in 0.9 s (was 3.0 s), machine-show in
1.0 s (was 1.7 s), the API round-trip being the remaining cost.