*** antosh has quit IRC | 00:20 | |
*** abishop has quit IRC | 01:45 | |
*** mhen has quit IRC | 01:48 | |
*** mhen has joined #openstack-barbican | 01:50 | |
*** dave-mccowan has joined #openstack-barbican | 02:06 | |
*** dave-mcc_ has joined #openstack-barbican | 02:24 | |
*** dave-mccowan has quit IRC | 02:25 | |
*** openstackgerrit has joined #openstack-barbican | 02:46 | |
openstackgerrit | Vu Cong Tuan proposed openstack/barbican master: Switch to stestr https://review.openstack.org/581619 | 02:46 |
---|---|---|
*** dave-mcc_ has quit IRC | 03:30 | |
*** Luzi has joined #openstack-barbican | 05:52 | |
*** DongHM has joined #openstack-barbican | 06:13 | |
*** alee has quit IRC | 06:28 | |
*** alee has joined #openstack-barbican | 06:28 | |
*** alee has quit IRC | 06:29 | |
*** alee has joined #openstack-barbican | 06:30 | |
*** velizarx has joined #openstack-barbican | 06:46 | |
*** Luzi has quit IRC | 06:50 | |
*** velizarx has quit IRC | 07:03 | |
*** peereb has joined #openstack-barbican | 07:04 | |
*** Luzi has joined #openstack-barbican | 07:05 | |
*** serlex has quit IRC | 07:12 | |
*** velizarx has joined #openstack-barbican | 07:23 | |
*** ducnv has quit IRC | 07:39 | |
*** ducnv has joined #openstack-barbican | 07:39 | |
*** pbourke has quit IRC | 08:35 | |
openstackgerrit | Lingxian Kong proposed openstack/barbican master: Fix getting secret for vault plugin https://review.openstack.org/583149 | 08:36 |
*** serlex has joined #openstack-barbican | 08:39 | |
*** pbourke has joined #openstack-barbican | 08:52 | |
*** annp has quit IRC | 09:18 | |
*** DongHM has quit IRC | 09:25 | |
*** annp has joined #openstack-barbican | 09:26 | |
*** salmankhan has joined #openstack-barbican | 09:30 | |
*** Luzi has quit IRC | 10:34 | |
*** velizarx has quit IRC | 10:54 | |
*** velizarx has joined #openstack-barbican | 10:58 | |
*** noslzzp has joined #openstack-barbican | 10:59 | |
*** dave-mccowan has joined #openstack-barbican | 11:18 | |
*** abishop has joined #openstack-barbican | 11:39 | |
*** vanduc_ has joined #openstack-barbican | 11:41 | |
*** alee_ has joined #openstack-barbican | 11:42 | |
*** alee has quit IRC | 11:44 | |
*** Luzi has joined #openstack-barbican | 11:49 | |
*** vanduc_ has quit IRC | 11:58 | |
*** ducnv_ has joined #openstack-barbican | 11:58 | |
redrobot | dave-mccowan, o/ | 12:00 |
dave-mccowan | hi redrobot o/ | 12:00 |
redrobot | dave-mccowan, alee said you're leading the barbican meeting right now? | 12:05 |
dave-mccowan | sorry, lost track of time. thanks! | 12:05 |
dave-mccowan | #startmeeting barbican | 12:05 |
openstack | Meeting started Tue Jul 17 12:05:40 2018 UTC and is due to finish in 60 minutes. The chair is dave-mccowan. Information about MeetBot at http://wiki.debian.org/MeetBot. | 12:05 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 12:05 |
*** openstack changes topic to " (Meeting topic: barbican)" | 12:05 | |
openstack | The meeting name has been set to 'barbican' | 12:05 |
dave-mccowan | #topic roll call | 12:05 |
*** openstack changes topic to "roll call (Meeting topic: barbican)" | 12:05 | |
dave-mccowan | o/ | 12:05 |
Luzi | o/ | 12:05 |
mhen | o/ | 12:06 |
redrobot | o/ | 12:06 |
dave-mccowan | is there an agenda posted? | 12:07 |
dave-mccowan | i don't see one on the agenda page. | 12:08 |
dave-mccowan | #topic milestone 3 | 12:08 |
*** openstack changes topic to "milestone 3 (Meeting topic: barbican)" | 12:08 | |
dave-mccowan | this week is the deadline for milestone 3 for the release | 12:08 |
dave-mccowan | does anyone have status to discuss for development line item? | 12:09 |
dave-mccowan | we should be feature-complete after this deadline, and move on to testing and bug fixing for the rest of the cycle. | 12:09 |
*** namnh has joined #openstack-barbican | 12:10 | |
dave-mccowan | hi namnh | 12:11 |
dave-mccowan | ok, in that case, please help out with patch reviews for the next couple of days so we can get as much as possible in for m3. | 12:11 |
namnh | alee_: :)) Hi Ade, long time no chat :) | 12:12 |
dave-mccowan | #topic barbican client | 12:12 |
*** openstack changes topic to "barbican client (Meeting topic: barbican)" | 12:12 | |
dave-mccowan | m3 is also usually the release date for client libraries. has anyone been working with the client lately? is it good for release? | 12:12 |
redrobot | namnh, I don't think alee_ is here... probably just a bouncer. | 12:13 |
redrobot | pretty sure the client needs some TLC | 12:13 |
redrobot | not sure if anyone has picked up the UUID issue | 12:13 |
namnh | dave-mccowan: hi dave, maybe I sent wrong address ;) | 12:13 |
redrobot | but it would be awesome if we could get it done before m3 | 12:13 |
dave-mccowan | redrobot yep. people keep asking about it, but i don't think anyone is working on it. | 12:14 |
dave-mccowan | i finally got --file parameter submitted. but, there's still a couple other things that have been hanging around for a very long time. | 12:15 |
redrobot | I'll try to get a lot of reviewing done this week | 12:16 |
dave-mccowan | redrobot thanks! | 12:16 |
namnh | redrobot: thanks ! | 12:16 |
dave-mccowan | both testing and reviewing would be great from anyone who can spend some time early this week. (especially for barbican client) | 12:17 |
dave-mccowan | #topic validation | 12:17 |
*** openstack changes topic to "validation (Meeting topic: barbican)" | 12:17 | |
dave-mccowan | Luzi: last week you and Ade talked about bit length validation. do you have an update or any further questions? | 12:18 |
Luzi | no, he wanted to discuss this with more people | 12:18 |
redrobot | #link https://review.openstack.org/#/c/575800/ | 12:19 |
redrobot | Luzi, I think this is the place to discuss :D | 12:19 |
dave-mccowan | redrobot excellent! | 12:19 |
dave-mccowan | #topic OVO | 12:19 |
*** openstack changes topic to "OVO (Meeting topic: barbican)" | 12:19 | |
dave-mccowan | namnh How's OVO going? | 12:20 |
namnh | yeah, I am writing unittests for OVO | 12:20 |
redrobot | I think we still need lots o' reviews too | 12:20 |
namnh | there are some patch sets which I pushed | 12:20 |
namnh | but, for now, I am an idea about this task | 12:21 |
namnh | because, the final target is that Barbican can rolling upgrade. | 12:22 |
namnh | after I review all barbican database, RPC -> there is no change in the recent cycle. | 12:22 |
namnh | and I tried to rolling upgrade with barbican, and the result is good. So I am thinking that we can create a docs to guide operators to rolling upgrade | 12:24 |
namnh | after that we can also push a patch set to get "rolling upgrade" tag from TC. | 12:24 |
namnh | then we still continue to implement OVO as Neutron is doing | 12:25 |
namnh | what do you think? | 12:25 |
namnh | dave-mccowan and redrobot | 12:26 |
namnh | :) | 12:26 |
redrobot | Hmm... I thought OVO was required for rolling upgrades? Would be aewsome if it's not | 12:26 |
dave-mccowan | i see... since there is no database change in Queens to Rocky, then we can roll without OVO for that upgrade. | 12:26 |
dave-mccowan | that seems like it is cheating. without OVO, we can't promise that R to S upgrade will be rolling. i don't think we should request the tag until OVO is working. | 12:28 |
namnh | redrobot: OVO is a method for rolling upgrade, but it is not required. It depends on the architecture of each project. | 12:28 |
namnh | dave-mccowan: yeah, I know, as I mentioned, we still implement OVO after creating docs for rolling-upgrade | 12:29 |
namnh | dave-mccowan: because OVO take time for us. Although, Barbican for now can be upgraded without downtime. | 12:30 |
namnh | and I believe that Barbican can rolling upgrade from Pike | 12:32 |
dave-mccowan | we can wait for Ade to return to discuss more. but, i'm not totally comfortable claiming support without OVO, since we don't know release S will contain. | 12:32 |
namnh | dave-mccowan: Yeah, I understood, that is just my idea to discuss :) | 12:33 |
dave-mccowan | namnh Thanks for suggesting it. Maybe we can document it for operators with a warning? We should make it a goal to merge OVO before we merge a patch that changes the database. | 12:34 |
dave-mccowan | #topic Anything else? | 12:35 |
*** openstack changes topic to "Anything else? (Meeting topic: barbican)" | 12:35 | |
Luzi | yeah | 12:35 |
Luzi | well, I would at least like to hear, what you all think about https://review.openstack.org/#/c/577096/ | 12:36 |
namnh | dave-mccowan: btw, can you review the OVO patch set that got +2 from Ade | 12:36 |
dave-mccowan | namnh yes, i'll do that today. | 12:36 |
namnh | dave-mccowan: thanks :) | 12:36 |
Luzi | should there be still a validation for bit-lengths, which would need to allow 512 bits for aes-xts | 12:37 |
Luzi | or should barbican be able to generate keys of any bit length? | 12:37 |
dave-mccowan | simple sounds good to me. seems like we'll always be chasing the future if we try to maintain a list of supported bit lengths for each new thing. | 12:40 |
*** raildo has joined #openstack-barbican | 12:40 | |
dave-mccowan | anyone else? redrobot namnh? | 12:40 |
namnh | dave-mccowan: that's all from me. | 12:41 |
namnh | :) | 12:41 |
redrobot | I may be the only dissenting opinion about bit lengths. I'm on the explicitly supported in some crypto algorithm camp. | 12:41 |
dave-mccowan | redrobot cool. let's discuss in the review: https://review.openstack.org/#/c/577096/ | 12:42 |
Luzi | redrobot, that's something i also consider. | 12:42 |
redrobot | I've been deep diving into Vault. I think the Vault plugin for both Barbican and Castellan will need some improvements. | 12:42 |
redrobot | right now they depend on a ROOT TOKEN to work | 12:43 |
redrobot | but no one in their right mind should be using root tokens that way | 12:43 |
redrobot | Vault docs say: "the Vault team recommends that root tokens are only used for just enough initial setup (usually, setting up auth methods and policies necessary to allow administrators to acquire more limited tokens) or in emergencies, and are revoked immediately after they are no longer needed." | 12:43 |
redrobot | so, I'm digging into Vault Policy and hope to come up with a better scheme for using non-root tokens | 12:43 |
dave-mccowan | redrobot thanks! | 12:44 |
redrobot | That's all I got... | 12:45 |
*** raildo has quit IRC | 12:45 | |
dave-mccowan | Thanks everyone! See ya later... | 12:45 |
dave-mccowan | #endmeeting | 12:46 |
*** openstack changes topic to "Discussion about development of OpenStack Barbican and its client libraries. - Logs: http://eavesdrop.openstack.org/irclogs/%23openstack-barbican/" | 12:46 | |
openstack | Meeting ended Tue Jul 17 12:46:29 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 12:46 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/barbican/2018/barbican.2018-07-17-12.05.html | 12:46 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/barbican/2018/barbican.2018-07-17-12.05.txt | 12:46 |
*** raildo has joined #openstack-barbican | 12:46 | |
openstack | Log: http://eavesdrop.openstack.org/meetings/barbican/2018/barbican.2018-07-17-12.05.log.html | 12:46 |
*** ducnv_ has quit IRC | 12:46 | |
*** raildo has quit IRC | 12:50 | |
*** alee_ has quit IRC | 12:52 | |
*** raildo has joined #openstack-barbican | 12:52 | |
*** peereb has quit IRC | 12:56 | |
*** alee_ has joined #openstack-barbican | 12:59 | |
*** raildo has quit IRC | 13:00 | |
*** raildo has joined #openstack-barbican | 13:00 | |
*** raildo has quit IRC | 13:03 | |
*** raildo has joined #openstack-barbican | 13:03 | |
*** salmankhan has quit IRC | 13:09 | |
*** velizarx has quit IRC | 13:35 | |
*** raildo has quit IRC | 13:35 | |
*** velizarx has joined #openstack-barbican | 13:35 | |
*** raildo has joined #openstack-barbican | 13:36 | |
*** salmankhan has joined #openstack-barbican | 13:36 | |
*** raildo has quit IRC | 13:37 | |
*** raildo has joined #openstack-barbican | 13:39 | |
*** raildo has quit IRC | 13:41 | |
*** raildo has joined #openstack-barbican | 14:07 | |
*** antosh has joined #openstack-barbican | 14:21 | |
*** velizarx has quit IRC | 14:27 | |
*** jmlowe has joined #openstack-barbican | 14:36 | |
*** tidwellr has joined #openstack-barbican | 14:41 | |
*** FrankZhang has joined #openstack-barbican | 14:57 | |
*** namnh has quit IRC | 14:57 | |
*** alee_ has quit IRC | 15:02 | |
*** alee_ has joined #openstack-barbican | 15:03 | |
*** jmlowe has quit IRC | 15:09 | |
*** jmlowe has joined #openstack-barbican | 15:18 | |
*** Luzi has quit IRC | 15:25 | |
*** jmlowe has quit IRC | 15:53 | |
*** jmlowe has joined #openstack-barbican | 15:58 | |
*** alee_ has quit IRC | 15:59 | |
*** alee_ has joined #openstack-barbican | 16:00 | |
*** alee_ has quit IRC | 16:14 | |
*** jmlowe has quit IRC | 16:48 | |
*** serlex has quit IRC | 16:50 | |
*** jmlowe has joined #openstack-barbican | 16:51 | |
*** noslzzp has quit IRC | 16:57 | |
*** livelace2 has joined #openstack-barbican | 17:19 | |
*** salmankhan has quit IRC | 17:22 | |
*** tidwellr has quit IRC | 18:10 | |
*** tidwellr has joined #openstack-barbican | 18:10 | |
*** raildo has quit IRC | 20:31 | |
*** FrankZhang has quit IRC | 20:38 | |
*** raildo has joined #openstack-barbican | 20:38 | |
*** raildo has quit IRC | 20:50 | |
*** abishop has quit IRC | 21:17 | |
*** tidwellr has quit IRC | 21:37 | |
openstackgerrit | Lingxian Kong proposed openstack/barbican master: Fix getting secret for vault plugin https://review.openstack.org/583149 | 21:56 |
*** antosh has quit IRC | 22:00 | |
*** dave-mccowan has quit IRC | 22:16 | |
*** antosh has joined #openstack-barbican | 22:30 | |
lxkong | hi, anybody is actually working on solving the CI issue? | 23:08 |
redrobot | hi lxkong, which CI issue are you talking about? | 23:45 |
lxkong | https://review.openstack.org/#/q/project:openstack/barbican | 23:45 |
lxkong | the jenkins keeps failing for recent patches | 23:45 |
lxkong | the job `barbican-kmip-devstack-functional` | 23:45 |
redrobot | lxkong, oh yikes. :( | 23:47 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!