<@yselkowitz:fedora.im>
16:01:27
!startmeeting ELN SIG 28 Jul '26
<@meetbot:fedora.im>
16:01:27
Meeting started at 2026-07-28 16:01:27 UTC
<@meetbot:fedora.im>
16:01:27
The Meeting name is 'ELN SIG 28 Jul '26'
<@yselkowitz:fedora.im>
16:01:31
!meetingname eln
<@meetbot:fedora.im>
16:01:32
The Meeting Name is now eln
<@yselkowitz:fedora.im>
16:01:38
!topic Init process
<@sgallagh:fedora.im>
16:01:54
!hi
<@supakeen:fedora.im>
16:02:20
!hi
<@jligon:matrix.org>
16:05:47
!hi
<@yselkowitz:fedora.im>
16:06:33
bot seems to be sleeping, but hello all
<@yselkowitz:fedora.im>
16:07:01
!topic bootc
<@yselkowitz:fedora.im>
16:07:04
big news!!
<@yselkowitz:fedora.im>
16:07:17
🥁 [jligon](https://matrix.to/#/@jligon:matrix.org) !
<@jligon:matrix.org>
16:08:27
All merged and ready to make containers!
<@salimma:fedora.im>
16:08:30
!hi
<@supakeen:fedora.im>
16:08:44
Awesome.
<@jligon:matrix.org>
16:08:53
Thanks to everyone(lots of people) who helped!
<@niknikovsky:fedora.im>
16:09:07
I know that it has issues with cookies (sorry to intrude)
<@niknikovsky:fedora.im>
16:09:07
Is this zodbot?
<@yselkowitz:fedora.im>
16:09:23
it already *is* building containers
<@jligon:matrix.org>
16:09:26
First ELN, tomorrow the world! Muahahahah
<@niknikovsky:fedora.im>
16:09:53
Tomorrow means the Surface.
<@niknikovsky:fedora.im>
16:09:53
(Niche reference no one will get)
<@jakubsencak:fedora.im>
16:10:02
!hi
<@yselkowitz:fedora.im>
16:10:02
https://quay.io/repository/bootc-devel/fedora-bootc-eln-standard?tab=tags
<@yselkowitz:fedora.im>
16:10:31
!info ELN bootc images are now building regularly
<@yselkowitz:fedora.im>
16:10:41
!info Fixing some minor issues found in early testing
<@supakeen:fedora.im>
16:11:20
I have a small question about the `bootc` containers, Yaakov fixed the grub2 EFI vendor being 'wrong' (based on os-id instead of efi_vendor macro), that landed in ELN *before* the bootc container of today was built but the bootc container of today had the old version in it.
<@yselkowitz:fedora.im>
16:11:23
the grub2 fix landed in the 20260728.n.0 compose, so the next bootc image build should have it (the current latest was a bit early)
<@supakeen:fedora.im>
16:11:28
Was that expected (I don't know where it builds *from*).
<@jligon:matrix.org>
16:11:30
MR in eln channel for shipping 20-RHEL.toml as well
<@supakeen:fedora.im>
16:11:33
Ah it was just timing?
<@yselkowitz:fedora.im>
16:11:39
yeah I think so
<@supakeen:fedora.im>
16:11:45
Ack.
<@yselkowitz:fedora.im>
16:12:12
[jligon](https://matrix.to/#/@jligon:matrix.org) do we have any control over the timing? because ELN composes are on a different schedule than rawhide's
<@sgallagh:fedora.im>
16:12:52
Does it need to be on a timer or could we set something up to trigger it?
<@jligon:matrix.org>
16:13:22
It builds with the rest of the bootc images. We have control over that in the form of asking them to change the cadence?
<@yselkowitz:fedora.im>
16:14:02
do you happen to know how that is defined?
<@jligon:matrix.org>
16:15:01
In the bootc-dev influx tenant
<@sgallagh:fedora.im>
16:15:36
And what is an “influx tenant”?
<@jligon:matrix.org>
16:15:54
Konflux on a phone
<@yselkowitz:fedora.im>
16:16:04
lol
<@sgallagh:fedora.im>
16:16:28
Geez, we can’t get it to work in a data center, but you have it running on your phone?! 😅
<@jligon:matrix.org>
16:16:54
Containers all the way down bud
<@sgallagh:fedora.im>
16:17:41
But what does “in the tenant” mean? It’s monkey-patched on the builder?
<@yselkowitz:fedora.im>
16:17:59
seriously though, that's one of the million repos you have to touch to get anything done with konflux?
<@supakeen:fedora.im>
16:18:28
The tenant is basically a namespace with its own settings, users, and permissions within which workloads run (probably wrong terminologoy).
<@sgallagh:fedora.im>
16:21:40
And that differs from what I said in what practical way?
<@sgallagh:fedora.im>
16:23:08
Sorry, that came out argumentative
<@sgallagh:fedora.im>
16:23:21
I meant to indicate that I genuinely don't know
<@supakeen:fedora.im>
16:23:25
That's OK, I don't have a good answer either way.
<@yselkowitz:fedora.im>
16:24:33
afaik everything in konflux is defined in yaml, so probably not monkey-patched but "properly" configured, just that there's seemingly a *lot* of configuration needed for anything konflux
<@sgallagh:fedora.im>
16:25:33
From what I've seen, it's just *barely* shy of implementing a turing-complete version of YAML
<@sgallagh:fedora.im>
16:26:28
Anyway, I don't mean to rain on this achievement. Great work jligon and those that helped along the way!
<@yselkowitz:fedora.im>
16:27:24
so as mentioned above, we do have builds flowing now, and Simon found a few issues in early testing, for which fixes are incoming
<@yselkowitz:fedora.im>
16:27:54
jligon do you know how to go about getting these images published as quay.io/fedora/eln-bootc?
<@jligon:matrix.org>
16:28:18
Sorry, had to sell a piano. Reading back
<@yselkowitz:fedora.im>
16:28:29
lol
<@sgallagh:fedora.im>
16:29:08
Would this be in cloud-image-uploader?
<@sgallagh:fedora.im>
16:29:29
jligon: Not going to lie; I read that and the first thing I did was step to the side and look up.
<@jligon:matrix.org>
16:29:50
lol
<@sgallagh:fedora.im>
16:30:41
https://docs.fedoraproject.org/en-US/infra/sysadmin_sops/cloud-image-uploader/#_containers suggests so
<@sgallagh:fedora.im>
16:30:55
We should probably reach out to Jeremy Cline
<@jligon:matrix.org>
16:31:25
Are they pushing there already?
<@supakeen:fedora.im>
16:31:32
I think cloud-image-uploader doesn't handle things produced with Konflux?
<@jcline:fedora.im>
16:32:19
From my understanding of konflux, which is very little, it can push to registries so none of that goes through the uploader
<@sgallagh:fedora.im>
16:32:38
Presumably it will need credentials to do so
<@yselkowitz:fedora.im>
16:33:08
it's already pushing to quay.io/fedora/fedora-bootc, this would just be a different image to the same org
<@sgallagh:fedora.im>
16:33:21
Ah
<@jligon:matrix.org>
16:33:39
right?
<@yselkowitz:fedora.im>
16:34:57
!link https://gitlab.com/fedora/bootc/base-images/-/blob/main/RELEASE.md
<@yselkowitz:fedora.im>
16:35:32
```
<@yselkowitz:fedora.im>
16:35:32
The goal is to move to Konflux and deprecate the Pungi-IoT mechanism.
<@yselkowitz:fedora.im>
16:35:32
```
<@yselkowitz:fedora.im>
16:35:32
<@yselkowitz:fedora.im>
16:35:32
Konflux → quay.io/bootc-devel/fedora-bootc-* (Development)
<@yselkowitz:fedora.im>
16:35:32
Pungi-IoT + cloud-image-uploader → quay.io/fedora/fedora-bootc (Production)
<@yselkowitz:fedora.im>
16:35:32
<@yselkowitz:fedora.im>
16:35:32
The fedora-base-bootc image is published via two parallel mechanisms:
<@supakeen:fedora.im>
16:36:00
Oh we might've done that back in the day, but I don't know if that's still true at the moment.
<@supakeen:fedora.im>
16:36:25
If it says so I guess it still holds true.
<@supakeen:fedora.im>
16:36:35
In that case the bootc container should actually be built ... in Koji?
<@yselkowitz:fedora.im>
16:37:38
doesn't look like there have been any such builds in koji for a while
<@sgallagh:fedora.im>
16:37:58
Yeah, I assume the docs just got left behind
<@yselkowitz:fedora.im>
16:38:03
but quay.io/fedora/fedora-bootc is current
<@sgallagh:fedora.im>
16:38:07
(as usual for software development)
<@yselkowitz:fedora.im>
16:38:09
so yeah old docs
<@supakeen:fedora.im>
16:38:35
Yea, I'd have assumed so; though I still see an `ostree_container` section in IoT's pungi config.
<@supakeen:fedora.im>
16:39:21
I don't recall if `ostree_container` actually is a Koji task or if it runs locally on the compose host.
<@supakeen:fedora.im>
16:39:30
Let's just assume it's old docs.
<@yselkowitz:fedora.im>
16:39:37
I concur
<@supakeen:fedora.im>
16:40:09
(seems to be that `ostree_container` spawns a `runroot` task in Koji).
<@yselkowitz:fedora.im>
16:40:11
so something is uploading the konflux bootc-devel builds over to fedora, but we have no idea what?
<@supakeen:fedora.im>
16:40:49
I think it's a good summary that we have no idea what is producing and uploading the containers that are published under the `quay.io/fedora` namespace.
<@sgallagh:fedora.im>
16:41:59
I think that's an accurate summary. A good one...
<@supakeen:fedora.im>
16:42:04
But we *do* know that the containers under the `quay.io/bootc-devel` namespace are produced and uploaded through Tekton tasks on Konflux.
<@yselkowitz:fedora.im>
16:43:10
there is a mention of fedora-bootc in https://forge.fedoraproject.org/infra/ansible/src/commit/d34b8df20477ccb5de503d5e7eabeb6484992577/roles/openshift-apps/cloud-image-uploader/templates/config.toml#L120
<@supakeen:fedora.im>
16:43:11
Anyhow, maybe !action to figure it out :)
<@yselkowitz:fedora.im>
16:43:46
anyone volunteering?
<@supakeen:fedora.im>
16:44:03
Yes, I need to learn Konflux.
<@supakeen:fedora.im>
16:44:11
Even though I don't like it, feel free to give it to me.
<@yselkowitz:fedora.im>
16:44:26
!action Simon de Vlieger to figure out how to get bootc builds uploaded from konflux to quay.io/fedora/eln-bootc
<@yselkowitz:fedora.im>
16:45:07
anything else on this?
<@jligon:matrix.org>
16:46:07
should probably update the tracker, that should be me
<@yselkowitz:fedora.im>
16:47:28
already done
<@jligon:matrix.org>
16:47:40
sweet!
<@yselkowitz:fedora.im>
16:47:53
I'll open a new ticket for the quay.io/fedora publishing
<@supakeen:fedora.im>
16:48:05
Yep and please assign that one to me so it shows up in my overview :)
<@yselkowitz:fedora.im>
16:48:26
ack
<@yselkowitz:fedora.im>
16:48:32
!topic image-builder
<@yselkowitz:fedora.im>
16:48:50
!info qcow2 and ec2 images are now being built with image-builder
<@supakeen:fedora.im>
16:49:08
Yep, and I've validated the ec2 images by spinning them up on AWS.
<@supakeen:fedora.im>
16:49:49
Let me do the other updates as well, I don't have much time before I have to run to the FESco meeting.
<@yselkowitz:fedora.im>
16:49:58
go ahead
<@supakeen:fedora.im>
16:50:20
There's a PR open for Azure + GCE; we noticed that there were no RHEL definitions for GCE/aarch64. I've created and merged a PR upstream to enable GCE/aarch64 in `image-builder` for ELN.
<@supakeen:fedora.im>
16:50:29
This is in 77.0 which is currently going through rawhide.
<@supakeen:fedora.im>
16:50:52
I'll update the PR to also enable aarch64 builds tomorrow (or as soon as 77.0 is in ELN) and then it should be ready to merge?
<@yselkowitz:fedora.im>
16:51:19
yeah, do you have a way of testing any of those?
<@supakeen:fedora.im>
16:51:24
I do.
<@supakeen:fedora.im>
16:51:37
We have cloud accounts everywhere in our team, so I should be able to spin them up everywhere.
<@yselkowitz:fedora.im>
16:51:43
wonderful
<@yselkowitz:fedora.im>
16:51:56
I've used AWS before but not the others
<@supakeen:fedora.im>
16:52:00
As for Azure and EC2 we already test these images by booting them in the respective clouds in `image-builder` CI but it's good to verify that it works end-to-end as well.
<@supakeen:fedora.im>
16:52:10
GCE support for our CI isn't there yet, so that one I'll have to do manually.
<@supakeen:fedora.im>
16:52:27
Other than that; after those the hyperscalers are done and we can take a look at container/wsl I think.
<@yselkowitz:fedora.im>
16:52:50
sounds good!
<@supakeen:fedora.im>
16:52:52
I've also spoken to cloud-virt about ELN and they don't have capacity /right now/ but want to start thinking and looking at things soon.
<@yselkowitz:fedora.im>
16:53:08
for what?
<@supakeen:fedora.im>
16:53:18
What they want for RHEL 11 in regards to the cloud images.
<@supakeen:fedora.im>
16:53:23
For example, dropping all that firmware.
<@yselkowitz:fedora.im>
16:53:51
imo we should just drop it in ELN, and then they can decide what to do for rhel 11
<@yselkowitz:fedora.im>
16:54:18
it will give them something to help evaluate the decision
<@supakeen:fedora.im>
16:54:19
Yea the question here is how close should ELN adhere to be RHEL.
<@supakeen:fedora.im>
16:54:30
But that's above my idea, if you want me to drop it; I'll drop it.
<@supakeen:fedora.im>
16:54:36
And then if it needs to go back, that's a separate discussion.
<@yselkowitz:fedora.im>
16:54:54
we should be targeting where RHEL is heading, or where we think it's heading with whatever information we have
<@supakeen:fedora.im>
16:54:56
(apparently we support passthrough even on hyperscalers, thus the firmware)
<@yselkowitz:fedora.im>
16:55:09
ah
<@salimma:fedora.im>
16:55:24
linux-firmware, right?
<@supakeen:fedora.im>
16:55:26
So it's not as cut and dry as 'it never gets used'.
<@yselkowitz:fedora.im>
16:55:31
let's discuss this separately then
<@supakeen:fedora.im>
16:55:34
Yep.
<@salimma:fedora.im>
16:55:39
interested in that discussion myself
<@yselkowitz:fedora.im>
16:55:44
we're just about out of time
<@supakeen:fedora.im>
16:55:46
Thank you; that's all from me and I really have to run so I can grab a drink before the next meeting.
<@supakeen:fedora.im>
16:55:55
If you file an issue about it we can chat about it there.
<@yselkowitz:fedora.im>
16:56:01
thank *you* for all your work on this
<@salimma:fedora.im>
16:56:03
my pipe dream is have it like in suse where we can load firmware on demand, but out of caution we're still installing a lot of firmware at work too, we just contributed to making it a bit more modular
<@yselkowitz:fedora.im>
16:56:35
sorry but need to wrap up so that some of you can get over to fesco
<@yselkowitz:fedora.im>
16:56:43
!topic Next meeting
<@yselkowitz:fedora.im>
16:56:49
any conflicts next week?
<@salimma:fedora.im>
16:57:00
I'm running FESCo so I also need to run :P
<@salimma:fedora.im>
16:57:05
I think I'll be here
<@yselkowitz:fedora.im>
16:57:31
!info Next meeting is next Tuesday 04 August 12:00 EDT
<@yselkowitz:fedora.im>
16:57:36
!topic Open floor
<@yselkowitz:fedora.im>
16:57:44
2 minutes left
<@salimma:fedora.im>
16:58:43
let's wrap it up?
<@salimma:fedora.im>
16:58:53
Simon's already gone anyway
<@yselkowitz:fedora.im>
17:00:35
thank you all for coming, see you in channel or back here next week
<@yselkowitz:fedora.im>
17:00:35
!endmeeting
<@yselkowitz:fedora.im>
17:00:48
!endmeeting