►
From YouTube: INFRA Weekly Meeting 2020 04 28
Description
Jenkins Infrastructure Project Meeting - 2020-04-28
Notes - http://bit.ly/2T0oZ9v
A
Now
recordings,
and
so
welcome
for
this
new
Jenkins
infrastructure
meeting
I
put
several
action
that
I
would
like
to
discuss
in
this
meeting
in
the
Google
Doc,
so
the
first
one
is
obviously
to
get
infra
knowledge
written
ten,
which
is
about
automating,
changing
score
of
a
business
we
did
up
today.
Up
to
now
we
did
three
releases.
The
third
one
was
video
success,
so
I
think
it's
it's
ready
that
we
start
looking
at
the
security
and
the
stable
one.
I
have
a
meeting
for
the
security
releases.
A
I
had
a
meeting
with
Daniel
tomorrow
to
discuss
how
we
can
implement
artifact
promotion.
So
the
main
requirement
that
the
security
team
has
is
that
they
want
to
be
able
to
believe
a
new
Jenkins
version,
publish
that
in
a
private
man
repository
and
once
it's
approved,
they
can
promote
that
from
the
map
and
repository
to
the
to
the
master
one
to
the
one
that
everybody
is
using.
So
we
just
have
to
modify
a
little
bit
to
change.
Densify
parameter.
Those
reports,
that's
and
I
will
also
would
like
to
introduce
a
real
artifact
promotion.
A
So
not
only
we
push
in
so
we
could
also
use
that
photo
for
the
weekly
release,
which
would
simplify
the
process.
So
we
can,
for
example,
release
in
advance,
for
example,
on
Sunday
and
then
officially
promote
this
on
Monday
morning
when
everybody's
available,
so
that
that
would
be
the
ideal
and
once
once
the
security
once
it's
supported
on
the
security
part,
then
we
can
start
working
and
on
them
on
this
table
for
the
stable
releases.
A
B
So
you'll
you
said
you'll
discuss
with
the
annual,
so
we
are
you
now.
Sometimes
security
things
have
to
be
kept
relatively
quiet.
Do
you
have
a
sense
of
how
much
of
that
you
can
share
publicly
later
I
mean.
Certainly
the
code
will
eventually
be
public,
because
we
can,
we
can
see
the
or
there
are
many
portions
that
are
public.
What
portions
are
you
sentencing?
Oh
you
can't.
We
won't
won't
be
able
to
discuss
that
publicly.
It'll
have
to
be
kept
private
because
of
the
security
processes,
so.
A
Basically,
in
the
security
process,
the
person
will
report
a
security
issue,
we'll
have
a
private
communication
with
the
security
team,
so
they
can
work
on
security
issues,
and
so
the
idea
here
and
that's
what
then
it
is
already
doing
with
the
current
process.
So
the
idea
is
when
you
want
to
release
a
new
version,
you
just
trigger
the
release
on
a
specific
branch
and
push
the
artifacts
in
a
private
repository.
So
it's
still
it's
still
on
reporter
Jenkins
here
and
already
accepted
that
only
the
security
team
and
the
people
who
contribute
the
security
reported.
A
The
security
issue
can
don't
know
the
Jenkins
version
test,
do
whatever
they
need
to
do,
and
once
they
already,
they
promote
that
specific
version
to
the
master
branch,
and
then
it
become
prediction
everybody
has
access
to
this
so
being
able
to
really
have
promotion
of
artefact
is
something
very
important
for
the
security
we
kind
of
already
support
staging
environments
in
the
current
release
process.
So
if
we
just
want
to
change
the
mavin
repository
where
we
push
the
artifacts,
this
is
something
that
you
can
do
the
same
for
the
packages.
A
A
So
the
idea
is
ritu
have
like
a
real
staging
process.
Okay,.
B
So
so,
and
you
sounds
like
you're
you're
aware
there
and
ready
for
the
things
like
packaging,
the
Debian,
Patchett
packaging,
the
RPM,
doing
the
darker
image
generation,
things
that
are
all
downstream
of
the
war
file
creation,
but
really
shouldn't
be
disclosed
publicly
until
the
security
release
is
ready.
Great.
Thank
you.
A
So
the
next
topic
that
the
chain
over
the
last
week,
we
started
using
fastly
for
multiple
website,
so
we
first
configure
it
for
plugins
a
changes
that
a
young
accepted,
minor
glitch
I
think
it
was
a.
It
was
a
success.
It
was
easy
to
put
in
place
and
it's
scale
up
very
well,
so
we
started
using
it
for
Picasso
Jenkins
at
I/o
and
Jenkins
early
on
for
champions
that
I
yo.
We
had
to
switch
from
the
up
X
domain
to
the
to
the
Supplemental.
A
You
www,
the
main
advantage
of
doing
this
is
first,
we
support
ipv6,
so
you
can
go
there
using
music
ipv6
addresses,
and
otherwise
it's
not
so
the
main.
The
main
limitation
of
the
app
X
I
mean
at
least
and
fast
leave
that,
because
you
cannot
have
a
cname
on
the
epics
domain,
you
have
to
be
redirected
to
a
specific
IP
s.
So
there
is
one
IPS
that
have
all
the
loads,
but
if
we
use
the
name,
we
will
wait
attempt
easily.
A
A
The
main
challenge
that
we
have
here
is
potato
Jenkins,
that
I
own
the
the
endpoint
is
in
front
of
a
machine
called
potato
cheated
on
you,
I
know
it's
not
I
mean
it's
not
easy,
but
he's
recently
that
you
have
to
understand
here
and
the
package
that
Jenkins
at
a
new
machine
has
some
it's
not
about
anymore,
to
handle
the
load
that
happened
during
the
morning,
your
Europe
time
and
morning
us
time,
and
so
basically
every
week
around
the
same
periods.
Basically,
what
happened
there?
A
A
You
think
using
parsley
for
potential
Jenkins
that
onion
it's
I
mean
give
us
more
time
to
basically
work
on
the
machine,
so
the
machine
can
be
both
under
the
to
other
websites,
so
basically
disease.
We
also
change
Israel
and
the
update
center
I'm
dead
center
I
am
use
most
of
the
traffic
I
need
to
be
refactor
on.
Maybe
maybe
we
just
have
to
find
you.
The
Apache
configuration
that
there
are
some
improvement
that
we
didn't
that
machine
one
of
the
when
I've.
The
other
challenge
that
we
have
with
that
machine.
A
Any
question
before
I
move
on
the
next,
your
brain,
which
is
which
is
kind
of
related.
Please
so
another
thing
yeah
something
that
I
also
forget
to
mention.
So
in
the
past
potential
changes
that
idea
was
configured
somebody's
typing
them
under
the
match.
Is
it
March
mark
your
keyboard?
No,
it's
not!
You
I
tell.
A
Nice
college
eyes:
that's
another
thing
that
is
another
chain
that
I
introduced
and
potential
change
in
sileo's,
so
basically
package
18.
That
IO
is
a
website.
That's
returned
with
other
time
formation
for
Debian,
RedHat
and
SUSE
repository.
So
if
you
want,
let's
say
to
install
Jenkins
from
Debian,
your
your
installer
will
go
to
potential
changes
at
I/o
and
so
one.
A
So,
basically,
the
request
was
sent
to
packages
includes
an
IU
then
sent
to
a
measure,
blob
storage
and
Ansari
instead
of
relying
on
a
move
of
infrastructure,
and
so
what
I
did
here
is
I,
stopped
redirecting
and
asked
into
the
blob
storage,
so
I'm
planning
to
just
remove
any
duplicates
that
blob
storage.
So
first
it
will
reduce
the
time
to
upload
packages
to
the
blob
storage,
because
we
don't
need
that
I'm
steps
and
more
then
computer
also
said
I'll.
A
B
A
So,
basically,
instead
of
paying
on
Azure,
that
goes
we
move
too
fast.
Basically,
so
we
just
reduce
or
appeal
and
white
by
mentioning
about
the
costs
on
fasting
right
now,
I
hadn't
eaten
since
the
last
week.
We
use
last
slide
less
than
$100
so
right
now
the
cost
is
not
that
huge,
so
I'm
going
to
wait
for
the
for
the
full
month.
So
I
have
the
full
picture,
but
we
may
add
more
services
on
the
pathless
accounts.
A
A
A
So
then,
the
next
bit
that
I
want
to
highlight
is
that
so
now
I
fixed
the
release
process
in
order
to
also
upload
packages
to
get
the
Jenkins
that
I
own,
so
it
is
getting
more
stable.
While
we
still
have
to
change
to
reset
the
storage
at
least
now
weekly
releases
also
uploaded
and
the
all
behind
we
canĂ¡--.
We
still
cannot
use
it
because
stable
releases
and
security
releases
I
mean
the
current
process
for
security
releases
and
stable
release.
Do
not
upload
packages
together.
A
Jenkins
are
you,
but
at
least
we
are
getting
closer
and
something
also
important
that
that
website
currently
could
be
used,
for
example,
as
a
back-end
for
package,
touching
that
are
you,
but
it
cannot
definitely
cannot
be
used
for
the
update
center
because
we
didn't
work
on
the
bits
at
work
to
upload
also
artifact
there,
so
it
won't
work
for
them.
Flats.
B
So,
just
for
my
clarity
get
that
Jenkins
that
I,
oh
I,
still
am
mentally
thinking
of
it
as
a
pure
prototype
that
you
might,
if
you
needed
to
destroy
completely
and
recreate
that
any
one
depending
on
it
is,
should
not
expect
100%
reliability.
If
they
need
reliable,
they
should
go
to
pkg
that
Jenkins.
That
I/o
is
the
official
face
of
the
project
for
right
now.
Is
that
that
a
safe
assumption
or
if
I
misunderstood
so.
A
So
you
you
understood
almost
everything
correctly
so
basically
get
the
drinking's
at
I/o
it.
So
it's
just
a
replacement
of
your
the
author
jinkies.
The
radio
is
using
a
tool
called
me,
okay,
which
does
not
seems
to
be
maintained
since
two
years
now,
and
that
require
a
specific
environment,
and
that's
one
of
the
reason
why,
at
the
package
to
change
the
machine
itself
cannot
be
updated
anymore,
because
it's
require
specific
Python,
libraries
and
stuff
like
this,
and
so
each
time
I
try
to
update
the
machine.
It
brought
it
as
the
real
environment
or
mine.
A
So
that's
one
of
the
thing
and
so
get
the
drink
is
that
I
know
is
used.
Sorry
clean
get
the
Jenkins
radio
is
using
a
different
tool
called
bits
from
the
VFC
project,
and
so
the
approach
is
a
little
bit
different
is
still
a
service
in
front
of
multiple
girls.
So
it's
using
the
same
house
we
just
like
it
provides
HTTP.
A
So
it's
reporter
data
path,
so
what
which
our
brain
does
not
and
a
few
more
and
further
feature
just
like
more
Morrison's.
The
thing
is
the
biggest
challenges
I'm
facing
with
that
service
is
to
just
upload
the
right
information
to
the
service,
so
it's
definitely
a
prototype.
It
can
be
deleted
at
any
time
and,
more
importantly,
it's
not
mean
it's
not
because
a
package
has
been
published
together,
gently
dryer
that
it's
with
the
right
package.
A
So
it's
really
like
it's
not
the
most
virgin
thing
that
I'm
working
on
so
I
just
try
to
have
it
our
stable
enough
and
so
once
in
stable,
the
idea
is
to
replace
get
the
general
you
just
use
my
option.
I'm
about
32
Donadio,
just
switched
I
will
put
it
back
to
the
Nevada
Jenkins
Rio,
so
at
least
we
to
replace
your
brain
by
new
hobbits,
but
we
are
not
that
were
not
yet.
We
are
not
there
yet.
So.
A
B
Plugins
on
Jenkins,
CI,
Jenkins
audio
were
upgraded
this
morning
so
earlier
today,
as
part
of
that
upgrade,
we
have
avoided
a
problem
that
was
known
to
have
occurred
in
the
azure
credentials.
Plug-In
Tim
was
was
kind
enough
to
flag
that
we
unfortunately
did
encounter
a
problem
with
the
ec2
plug-in.
It
has
some
unknown
bug
that
Gunter
was
able
to
highlight
for
me
very
quickly
and
we
rolled
back.
One
version
restarted
and
everything
was
fine.
A
So,
just
just
regarding
our
recommendation
for
upgrading
see
any
changes
early
on
so
right
now
the
changes
are
you
still
using
the
stable
version,
so
I
think
it's
a
tight
light.
Gdk
live
and
stick
birth
of
the
magnets,
which
means
that
each
time
we
need
to
upgrade
it,
we
just
have
to
put
the
new.
The
new
docker
image
so
upgrade
is
not
yet
automated
and
it's
not
managed
by
ham
at
the
moment,
because
the
ljt
that
is
still
running
on
a
bare
metal
machine.
While
we
used
dr.
A
fritz
it's
not
running
on
communities
and
teamjacob
open
a
PR
to
deploy
its
own
communities.
The
main
thing
here
is
that
I
don't
want
to
use
public
abilities
for
the
CIA
environments,
because
the
kubernetes
cluster
is
quite
critical
and
we
don't
want
to
use
it
for
objectives
and
I
know,
but
we
have
to
deploy
a
new
Clemente's
cluster
on
Amazon.
This
is
something
that
we
need
to
work
on
in
there
in
the
pipe.
So
some
help
is
needed
here.
I
mean
not
needed,
but
would
be
useful.
A
A
Frozen
I
yeah,
it's
still
the
chase
so
wide
so
yeah.
So
this
bring
another
topic.
We
are
currently
in
the
process
to
transfer
to
our
account
to
the
CDF.
So
while
it
does
not
immediately
affect
them
as
Amazon
accounts,
it
means
that
we
are
starting
the
transfer
of
the
drink.
It
accounts
to
CF,
which
will
serve
so
I
hope
it
will
simplify
them
on
the
move
for
Amazon,
and
it's
almost
I
mean
it's
also
important.
A
That
billing
transfer
for
the
simple
reason
is
that
when
we
had
a
new
service
currently
under
Jenkins
project,
we
usually
put
our
own
information.
So,
for
example,
in
the
case
of
fast
I,
put
my
credit
cards
in
the
case
with
Azure
accounts,
it
was
Kiki
credit
cards,
and
so
this
is
something
that
we
would
like
to
do,
something
that
we
don't
want
to
do
anymore,
yeah.
A
B
So-
and
that
sounds
great,
thank
you
anything
else
and
Olivier
that
I'm
did
I
miss
any
notes
on
the
CI
that
drinking
that
IO
topic.
It
seems
like
we
continue
as
we
are
for
now.
We
have
a
vision
that
we
want
to
go
to
kubernetes
and
that
that
kubernetes
would
be
on
a
new
cluster,
not
on
the
existing
cluster,
and
that
new
cluster
therefore
won't
be
hosted
in
Azure.
It
would
thus
biasing
towards
AWS
for
the
current
current
choice
of
infrastructure,
yep.
A
B
A
So
we
have
sponsorship
from
hi
WS
for
the
father
to
me
at
least
for
a
coming
year,
and
so
we
have
to
move
for
CI
infrastructure
needs.
Oh
that's
that
that
I
mean
that
was.
That
was
why
that
was
a
topic
of
our
discussion
with
the
Airways
guys,
and
they
were
happy
to
help
us
and
so
yeah.
So
we
are
definitely
planning
to
deploy
theology
to
their
own
communities.
Great,
alright,.
C
A
C
A
A
Yep
I
try
I,
try
to
see
if
I
can
have
an
exception,
so
I
can
add
more
people
external
people
on
the
club.
Under
this
curve,
these
accounts
did
something
that
I
have
I
would
investigate.
B
A
So
my
my
focus
is
still
the
corrilesa
to
mission
project.
I.
Do
not
expect
it
to
be
a
big
work,
depending
on
my
meeting
with,
depending
on
the
output
of
managing
with
the
near
tomorrow.
I
have
a
better
view,
but
I
think
we
already
have
most
of
the
components.
I
mean
anything
we
got
in
the
car.
It
is
automation.
The
only
thing
that
I'm
not
sure
yet
is
how
to
have
different,
auto
call
the
different
profiles.
So
it's
better
to
have
multiple
jenkins
file
with
specific
parameter.
A
Should
we
move
most
of
the
jenkins
file
to
a
library
and
then
just
have
check
inspired
for
the
weekly
for
a
stable
for
the
security?
Should
we
just
call
everything
from
one
jenkins
file
so
that
that
was
the
design
right
now,
but
now
that
I
realized,
for
example,
that
the
security
need
to
change
different
parameter
and
weekly
arm
yeah,
it's
small
I
can
that's
that,
doesn't
anything
that,
but
it
was.
The
descripton
is
the
same
for
the
three
different
releases.
We
just
have
to
adjust
a
different
parameter.
A
D
D
Yeah,
it's
more
for
plugins,
I!
Think
so
it's
when
it's
when
Jenkins
is
doing
like
the
check
now
to
try
and
get
the
updates
since
adjacent
file,
or
so
that's
the
one
that
users
normally
complain
about.
So
they
had
checked
now
to
update
plug-in
until
the
train
boots
and
it's
getting
connection
timeout
to
updates
watching
history.
Oh
the
water
was
users
command
this
morning
about
package
touching
as
IO,
but
it's
not
as
often.
D
A
B
A
The
two
places
where
I
loops
so
the
first
one
so
yeah
I,
started
looking
looking
at
multiple
times,
and
so
we
have
different
ways
that
we
can
improve
the
situation.
The
first
one
is
to
increase
the
vehm
size
to
something
that
I
did
last
year
in
June
because
of
the
same
reason,
so
the
issues
that
we
have
on
packet
agenda
that
I
know
of
this
generally,
something
that
effect
us
since
more
than
a
year.
It's
just
that
at
the
beginning.
A
It
was
just
a
delay
this
increasing
month
of
the
month,
so
the
the
downtime
is
just
bigger
and
bigger.
So
we
need
to
find
a
way
to
solve
this.
So
first
I
credit
of
the
VM
sighs.
It
just
delay
the
problem,
and
now
the
program
program
is
back
again.
The
second
thing
is
I
had
a
look
to
be
home
plain
to
see
if
we
could
fine
tune
the
configuration
while
I
see
that
there
are
a
lot
of
house
regarding
the
all
grains
and
the
database
on
the
machine.
So
we
had
like
500
gigabytes
of
aha.
A
Just
saying,
like
some
information
were
me,
some
some
cache
information
were
missing.
I
don't
know
if
I
share
this
information.
A
A
On
top
of
that,
we
also
have
the
release
tools
for
reddit's
and
open
source
on
the
machining,
because
when
we
generate
real,
a
package
with
SSH
on
the
machine
generate
the
packages
there
and
that
and
that
machine
is
also
configured
to
upload
to
the
different
new
house.
So
we
have
quite
a
lot
of
stuff
there
and
so
something
that
I
that
I
would
like
to
have
just
remove
package
included
there
from
there
I'd
say
for
the
update,
Center
and
so
just
keep
that
machine.
Just
like
a
big,
a
storage
and
that's
it.
A
D
A
So
I,
just
specifically
before
that
I
propose
to
set
up
a
call
with
Team
Jacob.
So
we
can
see
how
we
can
work
on
that
specific
problem,
because
yeah
that
machine
is
quite
clean
with
a
lot
of
different
services.
Then
it's
quite
hard
to
name
it
hard
to
understand.
If
you
don't
see
it
and
if
you
don't
have
access
to
it,
and
it
also,
and
also
something
important
is
because
that
machine
is
really
for
a
really
long
time.
You
have
a
lot
of
scripts
turn.
A
You
have
a
lot
of
tools,
and
so,
when
you
modify
something
it
has
done
site.
So
basically
what
happened
in
the
past
beautiful
time
like
each
time,
I
try
to
modify
or
remove
one
service
there.
It
brought
something
else.
A
simple
example
that
happened
last
week
when
we
switch
package
entities
that
I
know
to
fastly.
A
Initially
it
sounds
like
a
good
idea
and
then
I
realized
that
multiple
scripts
were
cooling
by
canto
Jenkins
on
you
to
SSH
on
the
machine
to
upload
files,
but
because
potatoes
in
Catania
was
not
used
by.
If
asking
does
he
all,
those
could
try
to
SSH
on
fasting
machine
to
upload
file,
which
is
I
mean,
does
not
work,
and
so
that
was
a
small
change
and
yeah.
A
It
took
meet
quite
a
lot
of
time,
several
hours
to
just
review
the
script
and
visa
scripts
and
discuss
with
the
different
people
you
go
up
there,
and
especially
because
okay
and
so
yeah
that
yeah,
that
machine
is
something
like
it's
an
important
mission
and
it's
difficult
on
that
modified
without
breaking
stuff.
Yeah.