2025-09-03 15:30:56 <@marmijo:fedora.im> !startmeeting fedora_coreos_meeting 2025-09-03 15:30:57 <@meetbot:fedora.im> Meeting started at 2025-09-03 15:30:56 UTC 2025-09-03 15:30:58 <@meetbot:fedora.im> The Meeting name is 'fedora_coreos_meeting' 2025-09-03 15:31:04 <@marmijo:fedora.im> !topic roll call 2025-09-03 15:31:33 <@ydesouza:fedora.im> !hi 2025-09-03 15:31:34 <@zodbot:fedora.im> Yasmin Valim de Souza (ydesouza) 2025-09-03 15:31:59 <@jcapitao:fedora.im> !hi 2025-09-03 15:32:01 <@zodbot:fedora.im> Joel Capitao (jcapitao) - he / him / his 2025-09-03 15:32:02 <@hricky:fedora.im> !hi 2025-09-03 15:32:04 <@zodbot:fedora.im> Hristo Marinov (hricky) - he / him / his 2025-09-03 15:32:46 <@siosm:fedora.im> !hi 2025-09-03 15:32:47 <@zodbot:fedora.im> Timothée Ravier (siosm) - he / him / his 2025-09-03 15:34:53 <@jlebon:fedora.im> !hi 2025-09-03 15:34:53 <@nemric:relativit.fr> !hi 2025-09-03 15:35:01 <@zodbot:fedora.im> None (jlebon) 2025-09-03 15:35:03 <@zodbot:fedora.im> Emeric Chassagne (nemric) 2025-09-03 15:35:44 <@marmijo:fedora.im> !topic Action items from last meeting 2025-09-03 15:35:52 <@jbtrystram:fedora.im> !hi 2025-09-03 15:35:53 <@zodbot:fedora.im> Jean-Baptiste Trystram (jbtrystram) - he / him / his 2025-09-03 15:36:27 <@marmijo:fedora.im> Yasmin Valim de Souza to organize the test week on behalf of CoreOS. Let's get it scheduled by next wednesday. Hristo Marinov will be our Fedora QA representative, replacing Sumantro Mukherjee from previous cycles. 2025-09-03 15:36:34 <@marmijo:fedora.im> from the last meeting ^ 2025-09-03 15:37:07 <@hricky:fedora.im> 2025-09-03 15:37:07 <@hricky:fedora.im> Unfortunately, I can't create the app page and calendar event for the test week because I don't have access. However, I will create the TestdayApp Metadata page and provide the date, and Kamil will create the app page and calendar event. I should be able to do everything else. 2025-09-03 15:37:07 <@hricky:fedora.im> I opened the ticket in the QE tracker: 2025-09-03 15:37:07 <@hricky:fedora.im> https://pagure.io/fedora-qa/issue/824 2025-09-03 15:37:40 <@ydesouza:fedora.im> I create this issue: https://github.com/coreos/fedora-coreos-tracker/issues/2018 2025-09-03 15:38:04 <@ydesouza:fedora.im> And also I was thinking about propose a date for the Test Week. 2025-09-03 15:38:32 <@aaradhak:fedora.im> !hi aaradhak 2025-09-03 15:38:33 <@zodbot:fedora.im> Aashish Radhakrishnan (aaradhak) 2025-09-03 15:39:42 <@marmijo:fedora.im> Thanks Hristo Marinov and Yasmin Valim de Souza ! It looks like that tracker has a meeting label, so let's discuss the test week scheduling during that slot in today's meeting 2025-09-03 15:40:11 <@ydesouza:fedora.im> Okay :) 2025-09-03 15:40:21 <@marmijo:fedora.im> !topic Review Fedora 43 Release Schedule 2025-09-03 15:40:31 <@marmijo:fedora.im> !link https://fedorapeople.org/groups/schedule/f-43/f-43-key-tasks.html 2025-09-03 15:42:27 <@marmijo:fedora.im> !info beta freeze is ongoing with beta release scheduled for 2025-09-16. 2025-09-03 15:43:24 <@marmijo:fedora.im> There are some steps to perform around beta release in https://github.com/coreos/fedora-coreos-tracker/issues/1935 that need to be done. I'll stage some PRs before beta release. 2025-09-03 15:43:44 <@marmijo:fedora.im> Let's get right into the topics 2025-09-03 15:43:46 <@marmijo:fedora.im> !topic tracker: F43 Test Week 2025-09-03 15:43:52 <@marmijo:fedora.im> !link https://github.com/coreos/fedora-coreos-tracker/issues/2018 2025-09-03 15:44:34 <@marmijo:fedora.im> Yasmin Valim de Souza: what did you have in mind for test week scheduling? 2025-09-03 15:44:41 <@ydesouza:fedora.im> I think the test week should happen before the final freeze (2025-10-10). May be the last week of september should be nice for the test week. What do you all think about it? 2025-09-03 15:44:41 <@ydesouza:fedora.im> The beta release happens 2025-09-16, right? 2025-09-03 15:45:06 <@ydesouza:fedora.im> 25-09-22 to 25-09-22 2025-09-03 15:45:17 <@marmijo:fedora.im> yes, beta release is scheduled for 2025-09-16 2025-09-03 15:45:58 <@marmijo:fedora.im> I think there may have been a typo, those are the same dates :) 2025-09-03 15:46:54 <@ydesouza:fedora.im> Yep, sorry. 25-09-26* 2025-09-03 15:47:16 <@siosm:fedora.im> right after the beta release sounds good. we need to get our branched & next streams ready 2025-09-03 15:47:57 <@marmijo:fedora.im> That week should be good for test week. We'll want to coordinate a high bandwidth session to kick off the week (although it doesn't have to be at the beginning of the week). 2025-09-03 15:50:47 <@marmijo:fedora.im> We could have the live "Test Day" call on Monday 22 September and then allocate that whole week for test week. 2025-09-03 15:51:39 <@ydesouza:fedora.im> Sound good to me. Can we agree on those dates? 2025-09-03 15:51:39 <@ydesouza:fedora.im> I will work on the initial tasks for that :) 2025-09-03 15:51:52 <@jbtrystram:fedora.im> dates SGTM 2025-09-03 15:52:00 <@jbtrystram:fedora.im> should we vote ? 2025-09-03 15:52:05 <@marmijo:fedora.im> I'll do a proposed 2025-09-03 15:52:10 <@aaradhak:fedora.im> Week of Sep 22 sounds good to me 2025-09-03 15:54:10 <@marmijo:fedora.im> !proposed Fedora 43 CoreOS Test Week to be 2025-09-22 through 2025-09-26, with a live "Test Day" session on 2025-09-22. The meeting time is TBD and will be announced in the tracker issue. 2025-09-03 15:54:39 <@jbtrystram:fedora.im> +1 2025-09-03 15:54:47 <@aaradhak:fedora.im> +1 2025-09-03 15:54:52 <@ydesouza:fedora.im> +1 2025-09-03 15:54:54 <@hricky:fedora.im> +1 2025-09-03 15:55:32 <@marmijo:fedora.im> !agreed Fedora 43 CoreOS Test Week to be 2025-09-22 through 2025-09-26, with a live "Test Day" session on 2025-09-22. The meeting time is TBD and will be announced in the tracker issue. 2025-09-03 15:56:11 <@marmijo:fedora.im> Anything else to discuss on this topic before we go to the next? 2025-09-03 15:57:00 <@ydesouza:fedora.im> That's all for my side. Thanks for your insights in this subject! :) 2025-09-03 15:57:32 <@marmijo:fedora.im> !topic Create a konflux-rawhide stream to exercise konflux builds 2025-09-03 15:57:40 <@marmijo:fedora.im> !link https://github.com/coreos/fedora-coreos-tracker/issues/2025 2025-09-03 15:58:33 <@marmijo:fedora.im> jbtrystram would you like to introduce this one? 2025-09-03 15:58:39 <@jbtrystram:fedora.im> yup 2025-09-03 15:59:38 <@jbtrystram:fedora.im> So we are making good progress with Konflux and i'd like to set up a new stream in the Jenkins pipeline to have daily builds and tests using the OCI produced by Konflux 2025-09-03 15:59:50 <@jlebon:fedora.im> Wait sorry, jbtrystram could we discuss https://github.com/coreos/fedora-coreos-tracker/issues/1969 first? I think they're related. 2025-09-03 15:59:58 <@jlebon:fedora.im> or we can discuss them together 2025-09-03 16:00:06 <@jbtrystram:fedora.im> yes they are tied in some ways 2025-09-03 16:00:22 <@jbtrystram:fedora.im> I agree that this topic is of higher priority 2025-09-03 16:00:24 <@marmijo:fedora.im> Should I switch to that topic first? 2025-09-03 16:00:50 <@marmijo:fedora.im> !topic Build FCOS based on Fedora 43 using podman build`` 2025-09-03 16:00:55 <@marmijo:fedora.im> !link https://github.com/coreos/fedora-coreos-tracker/issues/1969 2025-09-03 16:01:48 <@jbtrystram:fedora.im> I added the meeting label to that one 2025-09-03 16:02:00 <@jbtrystram:fedora.im> But I see Jonathan typing :) 2025-09-03 16:02:59 <@jlebon:fedora.im> So the main remaining blocker there was signing, but I think I've found a way to do that using the official Fedora GPG keys. 2025-09-03 16:03:48 <@siosm:fedora.im> Note that we realized with JB that we would have to require all nodes to rebase to a new URL as part of the switch if we stop signing the ostree commit 2025-09-03 16:04:17 <@jlebon:fedora.im> Right yeah. Could be an origin in-place tweak too. 2025-09-03 16:05:23 <@jlebon:fedora.im> Anyway, ideally we would turn on container signing now so that we can then turn off ostree signing (doesn't have to be the same release) and then that unblocks moving to the buildah path 2025-09-03 16:05:25 <@siosm:fedora.im> testing all that in time for the beta might be challenging 2025-09-03 16:05:41 <@siosm:fedora.im> agree with the signing 2025-09-03 16:05:44 <@jlebon:fedora.im> i don't think for beta, yeah 2025-09-03 16:05:51 <@siosm:fedora.im> how would things go with gpg? 2025-09-03 16:06:12 <@jlebon:fedora.im> meaning? 2025-09-03 16:06:45 <@siosm:fedora.im> what would that look like for the container images? 2025-09-03 16:06:58 <@jlebon:fedora.im> containers/image supports gpg signing of images. the signatures are stored in a lookaside. for us, we could store them in S3 2025-09-03 16:06:58 <@jbtrystram:fedora.im> can you elaborate on "turn on container signing"? 2025-09-03 16:07:00 <@siosm:fedora.im> like a "regular" gpg signed container image? 2025-09-03 16:07:23 <@jlebon:fedora.im> https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/building_running_and_managing_containers/assembly_signing-container-images_building-running-and-managing-containers#proc_signing-container-images-with-gpg-signatures_assembly_signing-container-images 2025-09-03 16:07:28 <@siosm:fedora.im> (as much as regular means given that we probably don't have that many people using that) 2025-09-03 16:08:00 <@jlebon:fedora.im> the default configuration for RHEL today is that all images coming from the Red Hat registries are signature verified using this flow 2025-09-03 16:08:36 <@jlebon:fedora.im> obviously, we want to move to sigstore, but things are just not there yet in Fedora 2025-09-03 16:09:11 <@siosm:fedora.im> would that mean uploading signatures to another server? (and not the registry if I understand correctly) 2025-09-03 16:09:42 <@jlebon:fedora.im> right, for us we could store them in our S3 bucket and point clients at it 2025-09-03 16:10:22 <@jbtrystram:fedora.im> that mean writing up some pipeline/cosa code to support this and having to change again when moving to konflux-signed images. Is it worth it ? We could keep ostree signatures for another cycle 2025-09-03 16:10:46 <@jlebon:fedora.im> I'm not convinced we should be using Konflux signatures as it stands today. 2025-09-03 16:10:50 <@siosm:fedora.im> and we need to make sure skopeo/rpm-ostree validate all that as well 2025-09-03 16:11:04 <@jlebon:fedora.im> I've validated (parts of) it :) 2025-09-03 16:11:30 <@jbtrystram:fedora.im> IIUC this is regular /etc/containers/policies and rpm-ostree follows that 2025-09-03 16:11:57 <@jlebon:fedora.im> right. (more precisely, it calls out to skopeo, which uses c/image) 2025-09-03 16:12:28 <@siosm:fedora.im> yes but you know, unused code path, not that many users 2025-09-03 16:13:12 <@siosm:fedora.im> If we can do that we could also do https://github.com/fedora-infra/siguldry/issues/49 which do not have us rely on gpg 2025-09-03 16:13:15 <@jlebon:fedora.im> In Fedora, yeah. As mentioned, it's heavily used downstream at least. And there's good CI coverage from what I see (added a test myself) 2025-09-03 16:13:58 <@siosm:fedora.im> do you mean it's used in RHCOS? 2025-09-03 16:14:58 <@jlebon:fedora.im> travier: yeah I think https://github.com/fedora-infra/siguldry/issues/49 is what we want though ideally integrated into Fedora Konflux 2025-09-03 16:15:42 <@jlebon:fedora.im> RHCOS inherits that configuration from RHEL, yeah. but I more mean: 2025-09-03 16:15:42 <@jlebon:fedora.im> > the default configuration for RHEL today is that all images coming from the Red Hat registries are signature verified using this flow 2025-09-03 16:16:56 <@jlebon:fedora.im> anyway, how i see this relate to JB's topic is that I think we should get the f43 situation stabilized and then to me at least I would be fine iterating on Konflux directly in rawhide. but we'll need to discuss signing there too 2025-09-03 16:17:17 <@jlebon:fedora.im> assuming you've got clean runs in staging already, right? 2025-09-03 16:18:45 <@jbtrystram:fedora.im> I wanted to have a separated stream to have minimal disruption (and also because we'd stop using `cosa build_with_buildah`) but if folks are fine with going with rawhide that works for me 2025-09-03 16:19:28 <@jbtrystram:fedora.im> a smaller step could be to have a mechanical stream going in the devel pipeline but I'd like the idea of having more eyes seeing this 2025-09-03 16:19:43 <@jbtrystram:fedora.im> Joel Capitao WDYT 2025-09-03 16:20:38 <@jcapitao:fedora.im> yeah devel pipeline first and then production one for rawhide 2025-09-03 16:21:10 <@jlebon:fedora.im> definitely interested in other opinions and Dusty's when he's back, but yeah hopefully we could pull the trigger on it soon. the reason to not do it now is because we're already going through a lot of churn with the podman build change. 2025-09-03 16:21:53 <@jlebon:fedora.im> all that work of course is preparations for the konflux flow too since it's just the beginning that's different (import vs build-with-buildah) 2025-09-03 16:21:57 <@jcapitao:fedora.im> also, I think we should validate with Konflux folks that the Fedora cluster is production ready 2025-09-03 16:22:48 <@jlebon:fedora.im> and i would actually not bother signing with Konflux and rely on the same GPG flow for now 2025-09-03 16:24:31 <@jbtrystram:fedora.im> side question : are ostree commits not deterministic ? What would prevent us to import the container (after the podman build) to the ostree repo, and sign the resulting commit and publish the signature to the fedora remote ? 2025-09-03 16:27:14 <@jlebon:fedora.im> i considered this yeah :) 2025-09-03 16:28:36 <@jlebon:fedora.im> We did do some work recently to make the merge commit reproducible (see https://github.com/bootc-dev/bootc/pull/1421) but I wouldn't consider having it be reproducible a top-level priority in that code, and I'd be worried to be make that assumption load-bearing across ostree versions etc... 2025-09-03 16:29:51 <@jlebon:fedora.im> basically, clients would do work to compute the commit and that introduces risk 2025-09-03 16:30:18 <@jbtrystram:fedora.im> ok thanks for the clarification 2025-09-03 16:30:24 <@jbtrystram:fedora.im> to summarize the stream topic: let's setup a mechanical stream in the devel pipeline until `cosa build with buildah` settles a bit and we'll switch rawhide to use konflux images with `cosa import` later. There are still some baking we can do in staging. 2025-09-03 16:31:22 <@jlebon:fedora.im> that SGTM 👍️ 2025-09-03 16:31:22 <@jlebon:fedora.im> related to devel/staging though, ICYMI: https://github.com/coreos/fedora-coreos-pipeline/issues/1210 2025-09-03 16:31:51 <@jlebon:fedora.im> anyway, probably should move on. i'll update https://github.com/coreos/fedora-coreos-tracker/issues/1969 and we still need to discuss timing for all this. 2025-09-03 16:32:29 <@marmijo:fedora.im> thanks for updating the tracker Jonathan Lebon 2025-09-03 16:32:41 <@marmijo:fedora.im> We're just over time 2025-09-03 16:32:54 <@marmijo:fedora.im> !topic Open Floor 2025-09-03 16:34:24 <@marmijo:fedora.im> Thanks for joining everyone! 2025-09-03 16:34:27 <@marmijo:fedora.im> !endmeeting