vcswatch reports that
this package seems to have new commits in its VCS but has
not yet updated debian/changelog. You should consider updating
the Debian changelog and uploading this new version into the archive.
Here are the relevant commit logs:
commit 3882661ac912a35c4a139e39775fac2b2f8913f3
Author: Thomas Goirand <zigo@debian.org>
Date: Tue Oct 6 14:48:52 2026 +0200
Read the archive policy from the metric answers
commit b685f16ec22c948a0f1712b5a7fd78cfdfa414f4
Author: Thomas Goirand <zigo@debian.org>
Date: Tue Oct 6 14:45:41 2026 +0200
Document the Gnocchi maintenance in the skill
commit 0b225aab4ca1586ce81ee848e5b5c76c4fa88eb1
Author: Thomas Goirand <zigo@debian.org>
Date: Tue Oct 6 14:45:25 2026 +0200
Add the Gnocchi commands to vgt
commit ed289821e8bd519748c5e1385c5f7dd0a4775570
Author: Thomas Goirand <zigo@debian.org>
Date: Tue Oct 6 14:43:21 2026 +0200
Add the Gnocchi purge option and deletion guard
commit 6945b7797a4f193152df54b5b1fe35d02e40ea92
Author: Thomas Goirand <zigo@debian.org>
Date: Tue Oct 6 14:40:45 2026 +0200
Add the Gnocchi maintenance core
commit 56e2d0d46d2b97756632b9321a6cf8aa205bcb84
Author: Thomas Goirand <zigo@debian.org>
Date: Mon Oct 5 22:18:01 2026 +0200
Tell when the purge kept the project
commit 465faf9216abddd775e6360071d0a7974502901c
Author: Thomas Goirand <zigo@debian.org>
Date: Mon Oct 5 21:25:13 2026 +0200
Document the temp user domain handling
commit 4083b84c666883aa18f6e8412895c45b57ef6fc2
Author: Thomas Goirand <zigo@debian.org>
Date: Mon Oct 5 21:21:33 2026 +0200
Fix the temp user auth in non-default domains
commit bb1d60f8c5c3ee71851788a6b062a7785e2c860f
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 13:22:15 2026 +0200
Retry the deletions on a dropped connection
commit a42fae1662c8b172041cdde8c6a01edc74d85f6c
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 02:38:11 2026 +0200
Fix the unit tests on Python < 3.13
The three tests failing on the bullseye build patched the clock
with mock.patch.object(pr.time, 'time', ...): pr.time being the
real time module, this patched time.time() process-wide. On
Python < 3.13, logging.LogRecord calls the patched time.time()
for every log record, burning one FakeClock step (100s) per
logged line, which exhausted the wait deadlines and raised
TimeoutError in the tests logging while waiting.
Scope the clock to project.py's namespace instead, with a new
FakeTime stand-in in base.py: logging keeps the real clock, and
the tests behave identically on every Python version. Verified
on Python 3.9 (bullseye), 3.11 (bookworm) and 3.13.
commit 6c70ac015fdee3ea5845044030c32e5b4bc7e6b2
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 02:31:23 2026 +0200
Skip the steps of the kinds which listed nothing.
The wave of the purge knows exactly what has to be deleted: a step
whose kind listed nothing is now skipped entirely (no thread, no
wait, no listing) - nothing creates resources during a purge, so
an empty listing at the beginning stays empty. The volumes step
also receives the group snapshots and the volume groups from the
wave, and the first poll of every wait is now immediate instead of
after the 10s poll interval: the synchronous deletions (ports,
floating IPs, security groups, routers) are confirmed in one round
trip. Only the final check still lists everything a second time:
it is the verdict before the irreversible deletion of the keystone
project.
commit 8239338b35e348042c60e0a64475cc08cd263714
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 02:24:07 2026 +0200
Report the project-owned counts in the wave and the rounds.
The plan of the purge counts what will be deleted (the project
owned subnets and networks, the deletable ports), but the listing
outcome lines counted everything visible to the project user: a
plan of '1 network(s)' was followed by '3 network(s) found', which
looked wrong (the 2 extra ones were the shared and external
networks, which are never deleted). The subnets, the networks and
the ports are now filtered inside their listing callables, so that
every 'N found' line agrees with the plan.
commit 1f6f02f83cf99742d825925030967d73d041e0ca
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 02:17:08 2026 +0200
Retry a dropped connection in every wait poll.
The polls of the waits reuse a connection which idled for the poll
interval (10s, the keep-alive timeout of the HAProxy frontends):
each poll was one dropped connection away from failing its whole
step, like the routers interface wait which failed a purge. The
wait polls are now consumed (and retried once) inside
_retry_on_drop().
commit 6d305e927849e5624fecb6279893fe0020e22cd3
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 02:14:43 2026 +0200
Silence the benign urllib3 pool-full discard warnings.
The purge runs many threads on one OpenStack connection: bursts of
requests can exceed the 10-connections-per-host pool of urllib3,
which then discards (closes) the surplus connections and warns.
No request fails: the next one simply opens a fresh connection.
The warnings are dropped by a logging filter, installed by the
'vgt' command on the root logger handlers.
commit fa76060fc143e439b23426c8cf7bd3cdc5a58db3
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 02:10:32 2026 +0200
Carry the total deletion time in the purge verdicts.
The success and the failure verdicts now both end with the time it
took to delete the whole project, e.g. 'Success, deleted project
'x' in 93s.'
commit 4806f1b5522cbd5ab11f8c7d4468094e1d8967ff
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 02:05:14 2026 +0200
List every resource in parallel, then plan, delete and report.
The purge now runs exactly in this order: every resource of the
project (all services, all the network resources included) is
listed at once, in parallel, at the very beginning; a plan line
shows what is about to be deleted; the deletion then follows the
deterministic order (the parallel phase 1, then the network
sequence once every stack is gone); a report shows what has been
deleted, and what failed to be deleted; and the run ends with an
explicit verdict: 'Success, deleted project' or 'Failure: some
resources could not be deleted, not deleting project.'
Every step works on the pre-listed resources and only re-lists
inside its waits and rounds; a failed up-front listing warns, and
its step lists again (and records the failure) when it runs.
commit a202426ffd2ed75433b7f4c1139e6ebfda986e66
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 01:59:04 2026 +0200
List the network resources while the parallel branch deletes.
The main thread of a purge used to sit idle while it waited for
its parallel branch: it now lists up front what the network steps
will need (floating IPs, routers, ports, security groups), so that
the phase 2 deletions start with their listings already done
instead of running six sequential listings after the join. The
subnets and the networks keep listing inside their deletion
rounds. A listing which fails up front is only warned about: the
step lists again (and records the failure) when it runs.
_attempt() also stopped aborting the purge when the step callable
has no __name__ (any non-function callable), and the step order
test harness accepts the step kwargs.
commit 4d184379498dafb1e34f7ef599dc5b5ac5b246af
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 01:58:02 2026 +0200
Bench the tests with stestr slowest, per the skill.
commit 61d821b4502023dc8cccb631cc5671e18eb0db12
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 01:52:39 2026 +0200
Record the purge census banner in the skill.
commit 084bf1efa7e3b5c42376241e71a9bf2cc035a8f2
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 01:52:33 2026 +0200
End a successful purge with a census banner.
The purge now counts every deletion (per kind of resource, thread
safely, the already-gone ones excluded), and a successful purge
ends with a single banner after the 'deleting project' step:
✅ Purge of project 'x' succeeded in 74s: deleted 2 stack(s),
5 server(s), 4501 object(s), ...
or 'nothing to delete' when the project was already empty.
commit f1ccc368c2815e5c2ea3a003bc2cb7e7bb95fd22
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 01:48:46 2026 +0200
Retry a dropped connection in every listing.
While the purge waits for its parallel branch, the main thread's
pooled connections idle past the keep-alive timeout of the HAProxy
frontends (10s): the first phase 2 listing reusing one of them is
reset without reaching the API, and the step failed with a
RemoteDisconnected on the routers listing.
The Swift dropped-connection retry is generalized into
_retry_on_drop(), and _listing() consumes every listing (and
retries it once) inside it: the SDK returns generators, whose HTTP
request only runs when the listing is consumed.
commit 1a45c4dc6e0fcacc172019777a330221b4d89bf3
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 01:32:14 2026 +0200
Record the two-phase purge order and the generator rule in the skill.
commit 9fef9c79891a06daed8a14b0a6a103fb71aade8a
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 01:32:09 2026 +0200
Delete the network resources last, the rest in parallel.
Heat stacks can hold resources which block the deletion of network
resources: the network sequence (floating IPs, routers, ports,
subnets, networks, security groups) now only runs once every stack
is gone. Everything else (stacks, servers, volumes, images, DNS
zones, Swift data, load balancers, secrets) does not depend on
each other and is deleted in parallel, the failures collected in
the same list.
Deleting in parallel races the Heat teardown: a resource already
gone is now a success, not a failure (_delete_best_effort and the
stack deletion treat the 404s as 'already gone', the server unlock
failures are debug-logged).
The Swift container listing is now consumed inside the retry
helper: the SDK returns generators, whose HTTP request only runs
when the listing is consumed, so the dropped-connection retry
never fired on the real failure.
commit 8a0249aaca9f642ccf83bbc4f2ad39365351474d
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 01:21:46 2026 +0200
Cap the investigation polls at 30 seconds in the skill.
commit 57b43f55474edbd5f368d0e5e834a64b555e1625
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 01:19:29 2026 +0200
Retry a Swift container listing dropped by the proxy frontend.
The HAProxy frontend of the Swift proxy closes the idle pooled
connections after its keep-alive timeout: the final wait polls the
container listing every 10 seconds, and reuses a connection right
in the idle-close window, getting its connection reset without the
request ever reaching the Swift proxy.
The listing is idempotent: retry it once on a dropped connection
(RemoteDisconnected or ConnectFailure) before recording the
failure, so a transient keep-alive race does not count as a
resource that failed to be deleted.
commit 75af82277a596b502f76f3e0e5dada114d7e64aa
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 01:13:15 2026 +0200
Add the purge order, the fail-at-end rule and the polling discipline to the skill.
commit 5acc7c69d2252bab24e4e6d900628884789e1916
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 01:13:15 2026 +0200
Delete the Heat stacks first, the independent steps in parallel.
The Heat stacks are now deleted first: a stack tears down every
resource it holds coherently, which is faster and safer than
deleting them from under Heat. The DNS zones, the Glance images
and the Swift data do not depend on the compute/network sequence:
they are deleted in parallel with it.
Every failure of the purge (per resource, or step level: listing
errors and wait timeouts through _attempt()) is now collected, and
the purge fails AT THE END when anything failed: the keystone
project is then never deleted, so that the caller sees the project
deletion in error instead of a silent half-purge.
commit 287f37883db972d71aaf02b17694ed3ecf49318f
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 01:03:50 2026 +0200
Tolerate the Swift listing and metadata failures.
The Swift proxy of the PoC cloud closed the connections of the
purged project (RemoteDisconnected) during the container listing,
aborting the purge at the purging Swift data step. The container
listing, the container metadata reads, the object listings and the
final container wait are now tolerated: each failure is logged
with the ⚠ marker, the step skips what it cannot see, and the
final resources check does not look at the Swift data.
commit 18130100b7e36e181483b3f7b219024a8c396f63
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 01:00:45 2026 +0200
Add the uncaught-error rule to the vgt skill.
commit 668bc5a3c975b6b33e37ac4df2e118fd0ba89c60
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 01:00:45 2026 +0200
Tolerate a broken Heat in the stack listing.
The Heat of the PoC cloud returns an internal error for the stack
listings (as admin with a project filter, and project-scoped
alike), which aborted the purge at the deleting stacks step, and
would have aborted the final resources check the same way. Log the
listing failure with the ⚠ marker, skip the step, and let the
final check go on: the stacks are then invisible to it, like for
every service which cannot be reached.
commit dff628a9cb3f9cf9d5f4dd7c283cb815cde2b755
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 00:57:51 2026 +0200
Add the 10 second rule to the vgt skill logging discipline.
commit da17f19e810542a97527af624329d20890cc9af3
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 00:57:47 2026 +0200
Bracket every listing with log lines, and poll at most every 10s.
A single listing call takes tens of seconds on a loaded cloud:
between the step start and its first deletion, the run was silent.
Every listing of the purge now logs 'listing the X' before the
call and 'N X found' after it, so the exploration phase is
visible. The wait polls never sleep for more than 10 seconds
anymore (they could sleep 30), the Swift global timeout included,
and the Swift metadata and image deletion polls log their
progress.
commit 351ed5f6d214604f7d1d39942a08a9319609286f
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 00:54:53 2026 +0200
Never abort the purge on one broken resource.
Every per-resource action of the purge (deleting a load balancer,
server, floating IP, router, port, subnet, network, security
group, DNS zone, image, volume, snapshot, secret, stack or Swift
object, and the untangling of the routers and servers) now catches
its own errors, logs them with the ⚠ marker, and lets the run
continue with the other resources. A stuck Swift container is
skipped the same way instead of raising. The final resources check
stays the verdict: leftovers fail the purge, with every resource
named in the log.
commit 43329dfd9cae65db3da89ca5a158ffdedeaddd3a
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 00:51:31 2026 +0200
Add the vgt opencode skill.
Holds the project-operations knowledge built during the PoC purge
training: the deletion order contract, the temporary user and the
admin/project-user deletion split, the shared-resource scope
discipline, the per-resource error tolerance rules, the neutron
and openstacksdk facts, the emoji logging discipline, and the PoC
training loop with its test rig.
commit d90e35089d55e3b7708bcf161d7b6f7d9a1dfd21
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 00:48:24 2026 +0200
Support the renamed network attributes of the new SDKs.
The recent openstacksdk releases renamed the router_external and
shared attributes of Network into is_router_external and is_shared:
deleting the networks of a project crashed with an AttributeError
on them. Try the new names first, and fall back to the old ones.
commit 07b0b74176bd19bd01a66a77c0d89051d18a386e
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 00:48:14 2026 +0200
Mark every log line of the project operations with an emoji.
The per-resource action lines, the checks and decisions, the
warnings and the aborts were printed without the semantic markers
of the vigietools logs: ⚙ for the actions, ⧱ for the checks and
decisions, ⚠ for the warnings and ✕ for the aborts.
commit baa01b46240d33e8c7503f65e4cc12cf10cd9cd4
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 00:42:00 2026 +0200
Mark the temporary user log lines with the ⚙ emoji.
Like every other log line of the project operations.
commit 2951012b1999348573a89e423f82b211151b2dd2
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 00:39:22 2026 +0200
Only purge the subnets owned by the project.
The shared subnets of the other projects are visible to the
project users: the purge listed them and tried to delete them.
On the PoC cloud, purging any project attempted to remove the
shared public IPv6 subnet of the admin project (ext-net1-v6subnet1),
which neutron only refused because its own ports still hold IP
allocations from it. Only delete and report the subnets whose
project_id matches the purged project.
commit c3b0a4daa3362e921e8634cb09cf6db983726f09
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 00:38:40 2026 +0200
Retry the subnet and network deletions in rounds.
A subnet whose IP allocations are still held by ports cannot be
deleted: the blocking ports are deleted (including the DHCP ones),
and the deletion is retried in rounds. A network whose ports are
not all gone yet cannot be deleted either: the deletion is retried
while the DHCP ports drain, instead of failing the whole purge.
commit 33a8775adc4a78ce94c5922e98e1457fda75eb23
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 00:38:21 2026 +0200
Log every step of the project operations.
The steps of the project operations were only reported through the
callback, which the stand-alone vgt does not use: between two
actions, a run exploring what the project holds (or waiting for a
slow service listing) looked hung. Log each step as it starts with
the ⚙ marker, so that the run always tells what it is doing.
commit 2db9dae7cda9762139adc45b469c0523e99af2a2
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 00:31:26 2026 +0200
Delete the project ports, subnets and networks as admin.
The ports, subnets and networks were deleted with the temporary
user connection. On the clouds where the neutron policies restrict
their deletion to the administrators, the purge failed with a
403 'rule:delete_subnet is disallowed by policy', leaving the
project half-purged. Delete them with the admin connection
instead, like the floating IPs and the security groups already
were.
commit a504e605510b5318aabfe2559f885b144425e500
Author: Thomas Goirand <zigo@debian.org>
Date: Sat Oct 3 00:31:20 2026 +0200
Log the progress of the project operation waits.
The wait loops of the project operations (waiting for the servers,
the routers, the ports, ... to be gone, the Heat stack actions and
deletions, the volumes and snapshots deletions, and the server
untangling of the suspension) were silent: a long wait looked like
a hung run. Log the number of resources which are still around at
the info level on every poll of the empty-waits, and the polled
statuses and counts at the debug level for the other loops.