dustymabe changed the topic of #fedora-coreos to: Fedora CoreOS :: Find out more at https://getfedora.org/coreos/ :: Logs at https://libera.irclog.whitequark.org/fedora-coreos
bgilbert has quit [Read error: Connection reset by peer]
bgilbert_ has joined #fedora-coreos
dwalsh_ has quit [Ping timeout: 246 seconds]
paragan has joined #fedora-coreos
bgilbert_ has quit [Read error: Connection reset by peer]
bgilbert__ has joined #fedora-coreos
bgilbert_ has joined #fedora-coreos
bgilbert__ has quit [Ping timeout: 256 seconds]
bgilbert_ has quit [Read error: Connection reset by peer]
bgilbert has joined #fedora-coreos
jpn has joined #fedora-coreos
jpn has quit [Ping timeout: 256 seconds]
<jmariondev> I'm seeing a CloudFront 503 when attempting to force an update:
<jmariondev> libostree HTTP error from remote fedora for <https://d2uk5hbyrobdzx.cloudfront.net/delta-indexes/yH/bVssK19HL66KEumL3NS_xdHkeaXxq4GijNcufdoLo.index>: Server returned HTTP 503
<jmariondev> working again 👍️
bagasse_ has quit [Quit: Leaving]
gursewak has quit [Ping timeout: 248 seconds]
jpn has joined #fedora-coreos
jpn has quit [Ping timeout: 260 seconds]
gursewak has joined #fedora-coreos
gursewak has quit [Ping timeout: 248 seconds]
jpn has joined #fedora-coreos
jpn_ has joined #fedora-coreos
jpn has quit [Ping timeout: 246 seconds]
paragan has quit [Quit: Leaving]
jcajka has joined #fedora-coreos
jpn has joined #fedora-coreos
gursewak has joined #fedora-coreos
jpn_ has quit [Ping timeout: 246 seconds]
jpn has quit [Ping timeout: 246 seconds]
azukku has joined #fedora-coreos
jpn has joined #fedora-coreos
jpn has quit [Ping timeout: 260 seconds]
ravanelli has joined #fedora-coreos
ravanelli has quit [Ping timeout: 250 seconds]
Betal has quit [Quit: WeeChat 3.5]
nemric has quit [Quit: WeeChat 3.5]
<stephanepoq> we had to rollback latest stable release on one instance, because ssh to some of our other server stoped working (with unclear error message) - i checked the issue tracker (but found nothing), I trying to reproduce it on a less critical intance - have you headred of any ssh issue yet?
<lucab> stephanepoq: do you mean troubles when using the SSH client shipped on FCOS?
<stephanepoq> yes
gursewak has quit [Ping timeout: 246 seconds]
<stephanepoq> the rollback fixed the issue
<stephanepoq> but i cannot reproduce is with a other stable release on current stable version (i'm still trying there)
<lucab> interesting
<lucab> no I haven't heard of other client-side SSH issues so far
<stephanepoq> ok, there is some hints that it migh be an issue with the outgoing firewall
jpn has joined #fedora-coreos
<stephanepoq> but the switch to nft was already in the prev. version
<stephanepoq> ok, i think ssh was only a side effect, the main issue should
<stephanepoq> maybe it a ipv6 issue
<stephanepoq> ok, reading the logs, i found that there where also curl calls that sopped working
<stephanepoq> no, ipv6 is noth likely, it's our hosts, they only have A rcords
<stephanepoq> this all makes no sense at all
<stephanepoq> ok, how do we go back to current version after doint "rpm-ostree rollback -r"
eballetbo has quit [Quit: You have been kicked for being idle]
<lucab> stephanepoq: I think the rebasing instructions at https://docs.fedoraproject.org/en-US/fedora-coreos/update-streams/#_switching_to_a_different_stream should work for that case too
wjr has joined #fedora-coreos
TJR_ has joined #fedora-coreos
<stephanepoq> after doint that, is it still possilbe to go back, to the last to version?
<stephanepoq> (rpm-ostree rollback -r)
<lucab> where "last" is what you are currently on, i.e. "stable - 1"?
<lucab> I think so yes, it should keep the rollback deployment in place, but honestly I haven't manually tried that
TJR_ has left #fedora-coreos [#fedora-coreos]
<stephanepoq> ok, i'm not shure how the rollback magic works, and anything will got lost
QuentinTheJerky has joined #fedora-coreos
<QuentinTheJerky> hello, I swapped hard drives in on my home server (previously running ubuntu server) and decided to change to fedora coreos. The ignition provisioning system looks like it would fit the bill much better for cloud/scaling systems, but for home use, all I have done is provide an ssh key and installed coreos on to bare metal.
<QuentinTheJerky> What I'd like to know for that is whether my changes that I make to the system (adding systemd units etc) will come undone during the automatic upgrade process (in other words, is it required that everything must be configured in an ignition file to weather system updates?)
wjr has quit [Quit: Client closed]
<lucab> QuentinTheJerky: no, changes in /etc and /var will persist through upgrades
dwalsh_ has joined #fedora-coreos
<QuentinTheJerky> lucab great, thanks for that. I also have some docker containers ready to be moved to coreos - I am wondering if now is the time to use podman instead, and if I do am I required to set up systemd units for each container to ensure they start at boot?
<stephanepoq> yes
<stephanepoq> but it's pretty easy
<stephanepoq> podman generates them for you
<QuentinTheJerky> stephanepoq great, thanks. will they live in /etc/systemd/system ?
<QuentinTheJerky> even better, thankyou
<stephanepoq> we needed the --new flag (without knowing that excist, we were confused, now to handle things)
<stephanepoq> yes they live there
<QuentinTheJerky> perfect, Ill do some more reading then
QuentinTheJerky has quit [Quit: My MacBook Air has gone to sleep. ZZZzzz…]
ravanelli has joined #fedora-coreos
ravanelli has quit [Remote host closed the connection]
ravanelli has joined #fedora-coreos
TJR_ has joined #fedora-coreos
ravanelli has quit [Remote host closed the connection]
dwalsh_ has quit [Ping timeout: 258 seconds]
pbrezina has joined #fedora-coreos
<stephanepoq> sudo rpm-ostree rebase "fedora/${ARCH}/coreos/${STREAM}" --bypass-driver
<stephanepoq> error: Old and new refs are equal: fedora:fedora/x86_64/coreos/stable
<stephanepoq> hmm, this is not the correct way
<stephanepoq> deployment 36.20220522.3.0 (c876d5b2c2b5f472fae8a12e98bdcd4bfc5d1e479a5f1ab81a28cd72e7dda0ba) will be excluded from being a future update target
ravanelli has joined #fedora-coreos
cyberpear has joined #fedora-coreos
TJR_ has quit [Quit: Textual IRC Client: www.textualapp.com]
QuentinTheJerky has joined #fedora-coreos
QuentinTheJerky has quit [Client Quit]
QuentinTheJerky has joined #fedora-coreos
<QuentinTheJerky> hello, some of my existing docker containers were made with docker-compose. is the correct way to install docker-compose (or any package) on coreos to use rpm-ostree install x ?
<stephanepoq> intalling docker-compose with rpm-ostree will work
<QuentinTheJerky> great thanks (sounds like thats only half the solution however as I still want it to work with podman)
nalind has joined #fedora-coreos
<stephanepoq> ok, found it, we are using a static (secondary) ip, with the old release all trafic is route via the ip addedn to NetworkManger, with the new release it's using the ip, the system got via dhcp
dwalsh_ has joined #fedora-coreos
<stephanepoq> NetworkManager 1:1.36.4-1.fc36.x86_64 → 1:1.38.0-1.fc36.x86_64
<dustymabe> stephanepoq: so you don't have a problem?
<stephanepoq> i think, the networkmanager update changed the default behaviour
<stephanepoq> we used: nmcli con mod "Wired connection 1" +ipv4.addresses 'x.x.x.x'
<stephanepoq> in the other servers firewall only x.x.x.x is open, now, the system is not using x.x.x.x as source, be y.y.y.y the ip it got from dhcp
<dustymabe> so it's routing traffic out of the wrong IP (i.e. using the wrong source IP)?
<dustymabe> I would compare the route table on the old versus new release to see the differences
<dustymabe> `ip route show`
<stephanepoq> yes, that has as "src" only the dhcp (wrong) ip
<stephanepoq> where is the config file for that?
<dustymabe> that's the kernel route table (in memory)
<dustymabe> there's no config file for it. It's generated on the fly when interfaces are configured
<dustymabe> stephanepoq: I would open an issue for this problem
<dustymabe> it's possible the behavior you were experiencing was undefined
<dustymabe> i.e. it was working but there was no guarantee (you got lucky)
<dustymabe> or it's possible a bug was introduced in the stack
<dustymabe> in the issue you open please include the NetworkManager config files under /etc/NetworkManager/system-connections/
<stephanepoq> i think it likely, that's now defined diffrently
<stephanepoq> do you think, this might be relate: autoconnect-priority=-999 (from theNetworkManager config)
<dustymabe> maybe? is that a newly introduced config option (i.e. if you diff the config from an old system versus a new system?)
<dustymabe> i'm not a NetworkManager expert so we'd have to ask someone who knows more
<dustymabe> you can also browse the NM sources to see if there are any commits between those two tags that would indicate a behavior change
<stephanepoq> I'm already there
<stephanepoq> "* Support enabling ipv4ll alongside DHCPv4 and static addressing."
<dustymabe> is the address you are adding a link local address?
<stephanepoq> it's a hetzner cloud machine, hetzner is calling them "floating ip" I can assing them to any of my machines
<dustymabe> yeah - floating IP is a normal ipv6
<dustymabe> yeah - floating IP is a normal ipv4
<dustymabe> link local is like those auto configured 169.254 addresses
<dustymabe> open an issue with the details and we'll get someone from the NM team to take a look
<stephanepoq> will do, for now i try a bit to find a work arroud before reverting aggain
<dustymabe> you should be able to update the settings in the NM config file (keyfile) just like when you added ipv4.addresses
<dustymabe> ipv4.routes
crobinso has quit [Ping timeout: 276 seconds]
QuentinTheJerky has quit [Quit: My MacBook Air has gone to sleep. ZZZzzz…]
plarsen has joined #fedora-coreos
QuentinTheJerky has joined #fedora-coreos
mheon1 has joined #fedora-coreos
mheon1 has quit [Quit: WeeChat 3.4]
mheon has joined #fedora-coreos
<stephanepoq> ip route replace default via 172.31.1.1 dev enp1s0 src X.X.X.X
<stephanepoq> => that's fixing the current problem
<stephanepoq> will open an issue with work arround
<stephanepoq> I there a well known place in fedora to save that line to?
<dustymabe> stephanepoq: you'd need to update the NM connection to add the route
<stephanepoq> ok
<dustymabe> see those links from above ^^
QuentinTheJerky has quit [Quit: My MacBook Air has gone to sleep. ZZZzzz…]
QuentinTheJerky has joined #fedora-coreos
plarsen has quit [Quit: NullPointerException!]
plarsen has joined #fedora-coreos
nalind has quit [Ping timeout: 260 seconds]
guesswhat has joined #fedora-coreos
<guesswhat> Guys?  I am trying to mount /var/lib/containers to secondary disk, but have problem on FCOS36.., seems its selinux related ( https://pastebin.com/raw/zHQSZXu8 ) , fails to /bin/sh: error while loading shared libraries: libc.so.6: cannot change memory protections
<guesswhat> Any ideas? Not sure if its fixable via Ignition ?
nalind has joined #fedora-coreos
<stephanepoq> guesswhat: is a disc > 2TB used?
<guesswhat> stephanepoq no, its empty one ( AWS )
<guesswhat> containers folder ( mounted from sendondary disk ) is missing container_var_lib_t label
jpn has quit [Quit: leaving]
jpn has joined #fedora-coreos
gursewak has joined #fedora-coreos
jcajka has quit [Quit: Leaving]
shanduur[m] has quit [Quit: You have been kicked for being idle]
azukku has quit [Remote host closed the connection]
crobinso has joined #fedora-coreos
<QuentinTheJerky> can you use bind mounts in coreos / podman ?
crobinso has quit [Remote host closed the connection]
<dustymabe> QuentinTheJerky: should be able to (I do)
<dustymabe> aaradhak davdunc dustymabe gurssing jaimelm jbrooks jcajka jdoss jlebon jmarrero lorbus miabbott nasirhm ravanelli saqali skunkerk walters
<dustymabe> FCOS community meeting in #fedora-meeting-1
<dustymabe> If you don't want to be pinged remove your name from this file: https://github.com/coreos/fedora-coreos-tracker/blob/main/meeting-people.txt
<QuentinTheJerky> dustymabe looks like I needed to add :Z at the end to ensure the container could access the bind
dwalsh__ has joined #fedora-coreos
<dustymabe> yeah, if the directory doesn't already have the right labels you'd need to do something like that
<dustymabe> just be careful.. relabeling some host mounts could be baed
<dustymabe> bad*
<dustymabe> i.e. you wouldn't want to :Z your home directory
<QuentinTheJerky> not quite sure what it means tbh
<QuentinTheJerky> I am trying to get a samba docker service to access a mounted usb drive
<dustymabe> TL:DR the safest thing to do is create a new empty directory to bind mount in
dwalsh_ has quit [Ping timeout: 248 seconds]
<jlebon> QuentinTheJerky: in that case, you might consider disabling labeling protection using `--security-opt=label=disable`
<QuentinTheJerky> jlebon thankyou - that seems to have solved the problem
cyberpear has quit [Quit: Connection closed for inactivity]
jpn has quit [Ping timeout: 258 seconds]
QuentinTheJerky has quit [Quit: My MacBook Air has gone to sleep. ZZZzzz…]
<guesswhat> I am trying to do ExecStart=semanage fcontext -a -e /var/lib/containers /mnt/containers && restorecon -Rv /mnt/containers, but semanage is not installed on FCOS by default, any ideas?
QuentinTheJerky has joined #fedora-coreos
QuentinTheJerky has quit [Read error: Connection reset by peer]
guesswhat has quit [Quit: Client closed]
guesswhat has joined #fedora-coreos
jpn has joined #fedora-coreos
Betal has joined #fedora-coreos
jpn has quit [Ping timeout: 248 seconds]
jpn has joined #fedora-coreos
<dustymabe> walters: mind stamping ^^
ravanelli has quit [Remote host closed the connection]
bgilbert_ has joined #fedora-coreos
bgilbert has quit [Ping timeout: 248 seconds]
bgilbert_ is now known as bgilbert
dwalsh__ has quit [Quit: Leaving]
dwalsh has joined #fedora-coreos
<dwalsh> dustymabe, Is there a fedora-coreos meeting now?
<bgilbert> dwalsh: there was one a couple hours ago
<dustymabe> dwalsh: ^^
<jlebon> miabbott[m]: did you want someone else to stamp https://github.com/coreos/coreos-assembler/pull/2924 too?
<miabbott[m]> jlebon: nope, was letting you merge; probably should have said that 😉
<jlebon> ahhh heh gotcha
ravanelli has joined #fedora-coreos
ravanelli has quit [Remote host closed the connection]
ravanelli has joined #fedora-coreos
<guesswhat> whats the alternative to semanage ? its not installed by default, i dont want to this via rpm-ostree as it takes some time and I have a lot of servers...
HappyHappyMan has quit [Ping timeout: 244 seconds]
cyberpear has joined #fedora-coreos
HappyMan has joined #fedora-coreos
<walters> guesswhat: https://github.com/coreos/coreos-layering-examples/tree/main/selinux could likely be enhanced to install it, run it, then remove it (optionally)
<guesswhat> walters now sure if i understand to this
<jlebon> guesswhat: there isn't any direct alternative. depending on what you're trying to do, it's possible you could do it directly.
<jlebon> for more details on the layering examples, see the readme in https://github.com/coreos/coreos-layering-examples/
<guesswhat> jlebon:  I am trying to mount /var/lib/containers to secondary disk, but it fails due to missing selinux labels...
pbrezina has quit [Remote host closed the connection]
<jlebon> guesswhat: are you creating the filesystem using Ignition?
<guesswhat> jlebon: no, via systemd, there is a problem with mounting disk on AWS  ( can not find the issue on GH ) see https://pastebin.com/raw/63D3cjvF
<guesswhat> so its not possible to use ignition as there is race condition where disk name is not static
<jlebon> ahh right ok
<jlebon> so you should be able to mount it at /var/lib/containers directly, then restorecon it
<jlebon> if you really want to keep it at /mnt/containers and point the container stack at that, you can add a rule in /etc/selinux/targeted/contexts/files/file_contexts
<jlebon> it'd be
<jlebon> /mnt/containers /var/lib/containers
<jlebon> and then restorecon
<guesswhat> hm, interesting
<jlebon> sorry, i pasted the wrong path
<jlebon> it's file_contexts.subs
<guesswhat> first one would be better option
<guesswhat> restorecon -Rv /var/lib/containers should be enough, right?
<jlebon> indeed, i'd agree
<jlebon> yup
<guesswhat> thanks, going to try
<jlebon> once we gain stable symlinks, Ignition will do that for you
ravanelli has quit [Remote host closed the connection]
<guesswhat> thanks, seems its working !
<guesswhat> is there any Issue to track for stable symlinks support for datadisks
<guesswhat> ?
<jlebon> great!
<guesswhat> oh, its my issue :D
<guesswhat> totally forgot
<jlebon> haha
guesswhat has quit [Quit: Client closed]
<dwalsh> dustymabe, Got pulled away.
jpn has quit [Ping timeout: 248 seconds]
plarsen has quit [Remote host closed the connection]
jpn has joined #fedora-coreos
nalind has quit [Quit: bye]
mnguyen has quit [Ping timeout: 240 seconds]
rishi```` has joined #fedora-coreos
gotmax_ has joined #fedora-coreos
jdoss_ has joined #fedora-coreos
jdoss_ has quit [Client Quit]
jdoss_ has joined #fedora-coreos
jdoss_ has quit [Client Quit]
gotmax has quit [Ping timeout: 250 seconds]
jdoss has quit [Ping timeout: 250 seconds]
brtknr has quit [Ping timeout: 250 seconds]
rishi``` has quit [Ping timeout: 250 seconds]
gotmax_ is now known as gotmax
jdoss has joined #fedora-coreos
brtknr has joined #fedora-coreos
plarsen has joined #fedora-coreos
ccha has quit [Ping timeout: 258 seconds]
ccha has joined #fedora-coreos
plarsen has quit [Quit: NullPointerException!]
plarsen has joined #fedora-coreos
jpn has quit [Ping timeout: 240 seconds]
ravanelli has joined #fedora-coreos
jpn has joined #fedora-coreos
heldwin has quit [Quit: Teleporting ...]
plarsen has quit [Quit: NullPointerException!]
mheon has quit [Ping timeout: 246 seconds]
jpn has quit [Ping timeout: 256 seconds]