Monday, 2024-09-02

rafaelweingartner#startmeeting cloudkitty14:01
opendevmeetMeeting started Mon Sep  2 14:01:07 2024 UTC and is due to finish in 60 minutes.  The chair is rafaelweingartner. Information about MeetBot at http://wiki.debian.org/MeetBot.14:01
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.14:01
opendevmeetThe meeting name has been set to 'cloudkitty'14:01
rafaelweingartnerHello guys!14:01
rafaelweingartner Roll count14:01
rafaelweingartner\o14:01
mattcreeso/14:01
priteau_o/14:02
rafaelweingartner#topic Impact of oslo.policy bump14:03
rafaelweingartnerI see that you added this topic in the meeting. Would you like to expand on this one?14:03
priteau_Hello14:04
priteau_This is only something I discovered today14:04
priteau_gmann has sent the following email to the mailing list: https://lists.openstack.org/archives/list/openstack-discuss@lists.openstack.org/thread/MPHSVG222OFHJL2AQD2A7CJGTH57SRCJ/14:05
priteau_TL;DR: oslo.policy 4.4.0 enables the RBAC new defaults by default, which means those will be enabled for all the OpenStack services unless they have disabled them by overriding the default value14:05
priteau_However, we have not received any patches related to this, unlike many other projects14:05
rafaelweingartnerI saw the email as weill, but I did not fully understand it.14:06
rafaelweingartnerWhat is it about?14:06
priteau_It is about this general RBAC change in OpenStack: https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html14:06
priteau_So it is possible that as soon as https://review.opendev.org/c/openstack/requirements/+/925464 merges we will break, which would affect the project for Dalmatian14:07
priteau_I think for this release we can disable the new defaults (this was done in some other projects)14:08
priteau_But we will have to catch up in the next release (Epoxy) with a backlog of changes we haven't made14:08
priteau_It is more a heads-up than a call for action. I think mattcrees and I can handle it.14:09
rafaelweingartnerI still did not think. You mean, the default is going to be scoped tokens?14:10
priteau_Not really. I think we are supposed to make some admin calls system-scope only14:12
priteau_I need to review this RBAC policy change in full14:12
rafaelweingartnerI thought that would not affect much, as these policies are defined in that policy.json file, right?14:12
rafaelweingartnerthat maps an API call security path to a set of attributes that describe the user in the token14:13
priteau_The policy file (yaml now, json is deprecated) is only for the admin overrides14:14
priteau_Policy is defined in code now14:15
priteau_Anyway, I will pursue the conversation with gmann to understand the impact and push some changes if needed (probably with help from mattcrees)14:16
rafaelweingartnerok14:16
rafaelweingartnerthanks14:16
rafaelweingartnerBesides this topic, we do not have any new topics14:18
rafaelweingartnerI mean, nothing that we see from our side14:18
rafaelweingartnerdo you guys have something else to add?14:19
rafaelweingartnerah, there is something14:19
rafaelweingartner#link https://github.com/gnocchixyz/gnocchi/pull/139614:19
rafaelweingartnerthis patch in Gnocchi, it will require some changes on CloudKitty side to now overload Gnocchi14:19
rafaelweingartneras soon as a new release of Gnocchi is made, we will propose this patch in CloudKitty14:19
priteau_thanks14:22
priteau_This reminds me that a colleague of mine had issues with cloudkitty/gnocchi/ceilometer recently14:22
priteau_He has posted a bug on storyboard: https://storyboard.openstack.org/#!/story/201121714:22
priteau_I haven't looked at the issue with him yet. Any input is welcome.14:24
rafaelweingartnerI saw it14:29
rafaelweingartnerbut we would need more details14:29
rafaelweingartnerI will ask for some details there14:30
rafaelweingartneris there something else from your side guys?14:32
mattcreesnothing new from me this time14:33
priteau_There was the Elasticsearch topic?14:33
rafaelweingartnerwe decided to "remove any deprecation message in both logs and code"14:34
rafaelweingartnerdo we need to go back on this decision?14:34
priteau_No, I think we should undeprecate14:37
priteau_But we should do it now, before Dalmatian release14:37
priteau_Do we have a patch up? I don't remember14:39
rafaelweingartnernot yet14:39
rafaelweingartnerI will create a patch for it then14:39
priteau_Thanks14:41
rafaelweingartnerThank you guys for participating. Have a nice week.14:51
rafaelweingartner#endmeeting14:51
opendevmeetMeeting ended Mon Sep  2 14:51:41 2024 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)14:51
opendevmeetMinutes:        https://meetings.opendev.org/meetings/cloudkitty/2024/cloudkitty.2024-09-02-14.01.html14:51
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/cloudkitty/2024/cloudkitty.2024-09-02-14.01.txt14:51
opendevmeetLog:            https://meetings.opendev.org/meetings/cloudkitty/2024/cloudkitty.2024-09-02-14.01.log.html14:51
opendevreviewPierre Riteau proposed openstack/cloudkitty master: Remove import of deprecated module  https://review.opendev.org/c/openstack/cloudkitty/+/92774214:54
opendevreviewGhanshyam proposed openstack/cloudkitty master: DNM: testing oslo.policy 4.4.0  https://review.opendev.org/c/openstack/cloudkitty/+/92775317:50
gmannpriteau_: ^^ cloudkitty have not implemented the new RBAC so there is no impact on cloudkitty but still I am testing cloudkitty with that17:51
gmannpriteau_: for new RBAC, we have removed the system scope from goal, we need to implement only project perosnas (1. admin stay same 2. member role 3. reader role). please refer this doc for details and let me know if any query https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#phase-117:53
gmannI can propose Cloudkitty change in E cycle and you all can see how it looks like17:53
priteau_Thanks gmann19:11
*** priteau_ is now known as priteau19:12

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!