)]}'
{"id":"openstack%2Foctavia~956930","triplet_id":"openstack%2Foctavia~master~I91b6907c3e3e456860f7274153e0ecf030e0519e","project":"openstack/octavia","branch":"master","topic":"bug/2119987","attention_set":{},"removed_from_attention_set":{"37881":{"account":{"_account_id":37881,"name":"Wesley Hershberger","display_name":"Wesley Hershberger","email":"wesley.hershberger@canonical.com","username":"whershberger","status":"Support Engineering @ Canonical"},"last_update":"2025-08-15 01:23:52.000000000","reason":"Change was submitted"},"11628":{"account":{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},"last_update":"2025-08-14 17:14:28.000000000","reason":"\u003cGERRIT_ACCOUNT_11628\u003e replied on the change","reason_account":{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"}},"29244":{"account":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"last_update":"2025-08-14 06:38:30.000000000","reason":"\u003cGERRIT_ACCOUNT_29244\u003e replied on the change","reason_account":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"}}},"hashtags":[],"change_id":"I91b6907c3e3e456860f7274153e0ecf030e0519e","subject":"Reduce tune.ssl.cachesize for HTTPS terminating listeners","status":"MERGED","created":"2025-08-08 15:26:37.000000000","updated":"2025-08-15 01:24:49.000000000","submitted":"2025-08-15 01:23:52.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":2,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"956930-bug/2119987","meta_rev_id":"504315b1cefb1f3e3dfefa40a3e20b99b2971553","_number":956930,"virtual_id_number":956930,"owner":{"_account_id":37881,"name":"Wesley Hershberger","display_name":"Wesley Hershberger","email":"wesley.hershberger@canonical.com","username":"whershberger","status":"Support Engineering @ Canonical"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},{"value":0,"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2025-08-15 01:23:52.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"all":[{"value":2,"date":"2025-08-14 06:38:30.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},{"value":2,"date":"2025-08-14 17:14:28.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},"all":[{"value":0,"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},{"value":1,"date":"2025-08-14 17:14:28.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true},"Backport-Candidate":{"approved":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"all":[{"value":2,"date":"2025-08-14 06:38:30.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},{"value":0,"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do Not Backport","-1":"Not A Backport Candidate"," 0":"Backport Review Needed","+1":"Proposed Backport","+2":"Should Backport"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"CC":[{"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"}],"REVIEWER":[{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2025-08-08 18:37:15.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2025-08-13 13:33:32.000000000","updated_by":{"_account_id":37881,"name":"Wesley Hershberger","display_name":"Wesley Hershberger","email":"wesley.hershberger@canonical.com","username":"whershberger","status":"Support Engineering @ Canonical"},"reviewer":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"state":"REVIEWER"},{"updated":"2025-08-13 13:33:32.000000000","updated_by":{"_account_id":37881,"name":"Wesley Hershberger","display_name":"Wesley Hershberger","email":"wesley.hershberger@canonical.com","username":"whershberger","status":"Support Engineering @ Canonical"},"reviewer":{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},"state":"REVIEWER"},{"updated":"2025-08-13 15:31:29.000000000","updated_by":{"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"},"reviewer":{"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"},"state":"CC"}],"messages":[{"id":"8e7f2103ea96c45d47800839a71cf9a729a9d44d","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":37881,"name":"Wesley Hershberger","display_name":"Wesley Hershberger","email":"wesley.hershberger@canonical.com","username":"whershberger","status":"Support Engineering @ Canonical"},"date":"2025-08-08 15:26:37.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"806174f936b8922fac96bbdaa4af49e236f90c7a","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":37881,"name":"Wesley Hershberger","display_name":"Wesley Hershberger","email":"wesley.hershberger@canonical.com","username":"whershberger","status":"Support Engineering @ Canonical"},"date":"2025-08-08 15:32:47.000000000","message":"Uploaded patch set 2: Patch Set 1 was rebased.","accounts_in_message":[],"_revision_number":2},{"id":"1964dcf12de80f1a4005a7e6d03dbb717dece924","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-08-08 18:37:15.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/ed40a21441504a57b4df6937e59fbb81\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/e871f41c7de84c048f7ec90029ffecb1 : SUCCESS in 12m 24s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/a13e0458ca9f4d3bab5630aa71613403 : SUCCESS in 2m 37s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/f1db11ddac7b433494d0d31d0e87b5be : SUCCESS in 4m 41s\n- openstack-tox-py312 https://zuul.opendev.org/t/openstack/build/a0d180a97e994a15a8335405721ec13f : SUCCESS in 5m 29s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/87e623b1100743a4b32e103ac1df06db : SUCCESS in 4m 20s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/0904ad99a23247558fd0977ee0fa8009 : SUCCESS in 14m 07s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/b3f77e5a50114748bef6e0f3e41eb1fa : SUCCESS in 4m 37s\n- octavia-tox-py311-tips https://zuul.opendev.org/t/openstack/build/1ea43e0f0d754303b87b32ea3e13e345 : SUCCESS in 4m 24s\n- octavia-tox-functional-py311-tips https://zuul.opendev.org/t/openstack/build/e4099c0a6a5e4e98bf00b61014559204 : SUCCESS in 9m 15s\n- openstack-tox-pip-check-reqs https://zuul.opendev.org/t/openstack/build/5e80c0e227494b5c93ec36a5e32f84b7 : SUCCESS in 4m 58s\n- openstack-tox-functional-py310 https://zuul.opendev.org/t/openstack/build/f7009ef424b1477f87222dfe54e9db6b : SUCCESS in 6m 57s\n- openstack-tox-functional-py311 https://zuul.opendev.org/t/openstack/build/b6a1e00f711c451d9f63e74ac03c558a : SUCCESS in 8m 15s\n- octavia-v2-dsvm-noop-api https://zuul.opendev.org/t/openstack/build/1f7d0e3df16c49818d6d1d4254c4fb00 : SUCCESS in 1h 23m 52s\n- octavia-v2-dsvm-scenario-traffic-ops https://zuul.opendev.org/t/openstack/build/c15d7d1c97084d90941432bcb5934cc5 : SUCCESS in 1h 49m 37s\n- octavia-v2-dsvm-scenario-non-traffic-ops https://zuul.opendev.org/t/openstack/build/6be4e7bcbfe04753afbf0d8d173b34c5 : SUCCESS in 1h 00m 42s\n- octavia-v2-dsvm-scenario-traffic-ops-ubuntu-jammy https://zuul.opendev.org/t/openstack/build/4c931bc837174f0fb48f6c2731d6925a : SUCCESS in 1h 48m 09s (non-voting)\n- octavia-v2-dsvm-scenario-non-traffic-ops-ubuntu-jammy https://zuul.opendev.org/t/openstack/build/8e0a8cf458784bdfa91635bd488c20a9 : SUCCESS in 57m 34s (non-voting)\n- octavia-v2-dsvm-scenario-traffic-ops-jobboard https://zuul.opendev.org/t/openstack/build/f61eb8137f8f44079c9337650096d129 : SUCCESS in 1h 57m 39s\n- octavia-v2-dsvm-scenario-non-traffic-ops-jobboard https://zuul.opendev.org/t/openstack/build/8b1f3af5ef8247aa8a4668f5c07b6e7e : SUCCESS in 1h 05m 44s\n- octavia-v2-dsvm-tls-barbican https://zuul.opendev.org/t/openstack/build/1777512a64d84847a79b3e6dfda5c5a1 : SUCCESS in 34m 29s\n- octavia-grenade https://zuul.opendev.org/t/openstack/build/a69c2cc51474425280a99c941c570c55 : SUCCESS in 44m 48s\n- octavia-v2-act-stdby-dsvm-scenario https://zuul.opendev.org/t/openstack/build/a57e04efdfc14f78940e464c966cac6b : SUCCESS in 37m 55s (non-voting)\n- octavia-v2-dsvm-cinder-amphora https://zuul.opendev.org/t/openstack/build/90925c5b1f7640e199efa6395a053f37 : TIMED_OUT in 2h 32m 59s (non-voting)\n- octavia-v2-dsvm-scenario-two-node https://zuul.opendev.org/t/openstack/build/d4bedcabe46f42dea6895c62aaa8b438 : TIMED_OUT in 3h 03m 06s (non-voting)\n- octavia-v2-dsvm-scenario-ipv6-only https://zuul.opendev.org/t/openstack/build/3340a80b57ba4947bdf80a7788177259 : SUCCESS in 2h 18m 42s (non-voting)","accounts_in_message":[],"_revision_number":2},{"id":"0fb9c3e360b076e0fda77e0bd151d0bf789816c0","author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"date":"2025-08-14 06:38:30.000000000","message":"Patch Set 2: Backport-Candidate+2 Code-Review+2","accounts_in_message":[],"_revision_number":2},{"id":"8737551f26812555d4113e3e9b5d5c66e6a131e6","author":{"_account_id":37881,"name":"Wesley Hershberger","display_name":"Wesley Hershberger","email":"wesley.hershberger@canonical.com","username":"whershberger","status":"Support Engineering @ Canonical"},"date":"2025-08-14 13:12:14.000000000","message":"Patch Set 2:\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"f9df97abb67ae2cca2481883d040c2736c76e0d2","author":{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},"date":"2025-08-14 17:14:28.000000000","message":"Patch Set 2: Code-Review+2 Workflow+1\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"a680d7849f4eb36bc0a4472923a5b47ca08b1142","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-08-14 17:15:02.000000000","message":"Patch Set 2: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":2},{"id":"b0f309eae7c82f3c9be9721231312249d00cfeae","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-08-15 01:23:52.000000000","message":"Patch Set 2: Verified+2\n\nBuild succeeded (gate pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/cf4a232dd8d64797b9062bb73a875184\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/0d58fc5ef3ea4e1cbf6d26a7afb0664d : SUCCESS in 3m 28s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/aaf7210e1af249768dc46f21a8e714b3 : SUCCESS in 3m 25s\n- openstack-tox-py312 https://zuul.opendev.org/t/openstack/build/119af3a026664b4dbfb31034e20766a4 : SUCCESS in 3m 45s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/15d6267fa2034f848fa919407cf16767 : SUCCESS in 5m 56s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/72f1c258b587475eb2749b320d2291c6 : SUCCESS in 3m 21s\n- openstack-tox-pip-check-reqs https://zuul.opendev.org/t/openstack/build/81f81a3bfcff4242a494c156e36aaa6d : SUCCESS in 2m 05s\n- openstack-tox-functional-py311 https://zuul.opendev.org/t/openstack/build/740266f7993c452f9e62a24738f852c1 : SUCCESS in 4m 01s\n- octavia-v2-dsvm-noop-api https://zuul.opendev.org/t/openstack/build/0df70aec0fc042a091bd985cdd83b39b : SUCCESS in 35m 48s\n- octavia-v2-dsvm-scenario-traffic-ops https://zuul.opendev.org/t/openstack/build/9d25e5275aed46fc83b32e8b36e039c8 : SUCCESS in 1h 50m 39s\n- octavia-v2-dsvm-scenario-non-traffic-ops https://zuul.opendev.org/t/openstack/build/6d57d83a2fa9440993853ecfad4b1cb6 : SUCCESS in 1h 08m 42s\n- octavia-v2-dsvm-tls-barbican https://zuul.opendev.org/t/openstack/build/4b4c061d896d4335bd30344456de7439 : SUCCESS in 34m 22s\n- octavia-grenade https://zuul.opendev.org/t/openstack/build/61a696bc2fd140f08ed7734f67ca1610 : SUCCESS in 42m 45s","accounts_in_message":[],"_revision_number":2},{"id":"499fe1d5ebf03003ac24a2104d4787d809e33bb7","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-08-15 01:23:52.000000000","message":"Change has been successfully merged","accounts_in_message":[],"_revision_number":2},{"id":"504315b1cefb1f3e3dfefa40a3e20b99b2971553","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-08-15 01:24:49.000000000","message":"Patch Set 2:\n\nBuild succeeded (promote pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/c7bd7c086ce94530bb5c9a87a1a057f1\n\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/8578dbd9aba34b11a1b6ae29bdabb463 : SUCCESS in 48s\n- promote-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/5e816445b1404f139b87d447bd6fbd59 : SUCCESS in 47s","accounts_in_message":[],"_revision_number":2}],"current_revision_number":2,"current_revision":"6b51d75b0cb4cbff64ad717bfdf0fbc9486e26bc","revisions":{"8ca680c04e00b373beb58c6433f5742fe2ece809":{"kind":"REWORK","_number":1,"created":"2025-08-08 15:26:37.000000000","uploader":{"_account_id":37881,"name":"Wesley Hershberger","display_name":"Wesley Hershberger","email":"wesley.hershberger@canonical.com","username":"whershberger","status":"Support Engineering @ Canonical"},"ref":"refs/changes/30/956930/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/octavia","ref":"refs/changes/30/956930/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/octavia refs/changes/30/956930/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/octavia refs/changes/30/956930/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/octavia refs/changes/30/956930/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/octavia refs/changes/30/956930/1"}}},"commit":{"parents":[{"commit":"89c6b27a4195d950b116972a25fa51fef9e95b20","subject":"Merge \"Fix race condition in cascade delete\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/89c6b27a4195d950b116972a25fa51fef9e95b20"}]}],"author":{"name":"Wesley Hershberger","email":"wesley.hershberger@canonical.com","date":"2025-08-08 15:11:27.000000000","tz":-300},"committer":{"name":"Wesley Hershberger","email":"wesley.hershberger@canonical.com","date":"2025-08-08 15:22:37.000000000","tz":-300},"subject":"Reduce tune.ssl.cachesize for HTTPS terminating listeners","message":"Reduce tune.ssl.cachesize for HTTPS terminating listeners\n\n454cff5 introduced haproxy\u0027s `tune.ssl.cachesize` for TERMINATED_HTTPS\nlisteners. During a reload of haproxy the old worker process stays\nrunning until the new worker process is ready. This means that two TLS\nsession caches are allocated/held simultaneously during a reload of the\nservice.\n\nFor small Amphorae, this works fine. The default connection limit is\n50000, which takes enough of a chunk out of the 50% allocation that\nthere is enough wiggle room for the new haproxy worker to allocate its\ncache and coexist with the old worker for some time.\n\nHowever, for larger amphorae, the memory calculated for the session\ncache approaches 50%.\n\nhaproxy allocates an additional 48 bytes for each 200 byte chunk, so\nthe total memory allocated exceeds 50% of the available memory,\ntriggering the OOM-killer on haproxy reload.\n\nOut of an abundance of caution this also reduces the proportion of\nmemory Octavia considers \"available\" for the TLS session cache from 1/2\nto 2/5.\n\nCloses-Bug: #2119987\nChange-Id: I91b6907c3e3e456860f7274153e0ecf030e0519e\nSigned-off-by: Wesley Hershberger \u003cwesley.hershberger@canonical.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/8ca680c04e00b373beb58c6433f5742fe2ece809"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/8ca680c04e00b373beb58c6433f5742fe2ece809"}]},"branch":"refs/heads/master"},"6b51d75b0cb4cbff64ad717bfdf0fbc9486e26bc":{"kind":"TRIVIAL_REBASE","_number":2,"created":"2025-08-08 15:32:47.000000000","uploader":{"_account_id":37881,"name":"Wesley Hershberger","display_name":"Wesley Hershberger","email":"wesley.hershberger@canonical.com","username":"whershberger","status":"Support Engineering @ Canonical"},"ref":"refs/changes/30/956930/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/octavia","ref":"refs/changes/30/956930/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/octavia refs/changes/30/956930/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/octavia refs/changes/30/956930/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/octavia refs/changes/30/956930/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/octavia refs/changes/30/956930/2"}}},"commit":{"parents":[{"commit":"f88e706c01b0c851faced2be255dddb568e74ace","subject":"Merge \"Remove deprecated datetime.utcnow()\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/f88e706c01b0c851faced2be255dddb568e74ace"}]}],"author":{"name":"Wesley Hershberger","email":"wesley.hershberger@canonical.com","date":"2025-08-08 15:11:27.000000000","tz":-300},"committer":{"name":"Wesley Hershberger","email":"wesley.hershberger@canonical.com","date":"2025-08-08 15:32:36.000000000","tz":-300},"subject":"Reduce tune.ssl.cachesize for HTTPS terminating listeners","message":"Reduce tune.ssl.cachesize for HTTPS terminating listeners\n\n454cff5 introduced haproxy\u0027s `tune.ssl.cachesize` for TERMINATED_HTTPS\nlisteners. During a reload of haproxy the old worker process stays\nrunning until the new worker process is ready. This means that two TLS\nsession caches are allocated/held simultaneously during a reload of the\nservice.\n\nFor small Amphorae, this works fine. The default connection limit is\n50000, which takes enough of a chunk out of the 50% allocation that\nthere is enough wiggle room for the new haproxy worker to allocate its\ncache and coexist with the old worker for some time.\n\nHowever, for larger amphorae, the memory calculated for the session\ncache approaches 50%.\n\nhaproxy allocates an additional 48 bytes for each 200 byte chunk, so\nthe total memory allocated exceeds 50% of the available memory,\ntriggering the OOM-killer on haproxy reload.\n\nOut of an abundance of caution this also reduces the proportion of\nmemory Octavia considers \"available\" for the TLS session cache from 1/2\nto 2/5.\n\nCloses-Bug: #2119987\nChange-Id: I91b6907c3e3e456860f7274153e0ecf030e0519e\nSigned-off-by: Wesley Hershberger \u003cwesley.hershberger@canonical.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/6b51d75b0cb4cbff64ad717bfdf0fbc9486e26bc"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/6b51d75b0cb4cbff64ad717bfdf0fbc9486e26bc"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"CLOSED","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"}},{"label":"Workflow","status":"MAY","applied_by":{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"}},{"label":"Backport-Candidate","status":"MAY","applied_by":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"}}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dMAX"],"failing_atoms":["label:Verified\u003dMIN"],"atom_explanations":{}}},{"name":"Backport-Candidate","description":"Backport candidate status","status":"NOT_APPLICABLE","is_legacy":false,"applicability_expression_result":{"fulfilled":false,"status":"FAIL"},"submittability_expression_result":{"expression":"is:true","fulfilled":true,"status":"NOT_EVALUATED","passing_atoms":[],"failing_atoms":[],"atom_explanations":{}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX"],"failing_atoms":["label:Code-Review\u003dMIN"],"atom_explanations":{}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dMAX"],"failing_atoms":["label:Workflow\u003dMIN"],"atom_explanations":{}}}]}
