Tuesday, 2019-07-23

*** pcaruana has joined #openstack-barbican04:43
*** Luzi has joined #openstack-barbican05:05
*** dpawlik has joined #openstack-barbican05:44
*** irclogbot_1 has quit IRC07:20
*** openstackstatus has quit IRC07:20
*** irclogbot_2 has joined #openstack-barbican07:21
*** Anticimex has quit IRC07:24
*** Anticimex has joined #openstack-barbican07:29
openstackgerritHYSong proposed openstack/barbican master: fix secret_type_doc  https://review.opendev.org/67221107:38
openstackgerritHYSong proposed openstack/barbican master: fix secret_type_doc  https://review.opendev.org/67221107:57
*** ivve has joined #openstack-barbican08:22
*** jaosorior has joined #openstack-barbican09:52
*** dpawlik has quit IRC10:02
*** dpawlik has joined #openstack-barbican10:04
*** raildo has joined #openstack-barbican11:35
openstackgerritHYSong proposed openstack/barbican master: fix secret_type_doc  https://review.opendev.org/67221112:09
redrobot#startmeeting barbican13:02
openstackMeeting started Tue Jul 23 13:02:17 2019 UTC and is due to finish in 60 minutes.  The chair is redrobot. Information about MeetBot at http://wiki.debian.org/MeetBot.13:02
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.13:02
*** openstack changes topic to " (Meeting topic: barbican)"13:02
openstackThe meeting name has been set to 'barbican'13:02
redrobot#topic Roll Call13:02
*** openstack changes topic to "Roll Call (Meeting topic: barbican)"13:02
Luzio/13:02
redrobotCourtesy ping for ade_lee hrybacki jamespage lxkong moguimar raildo rm_work xek13:02
rm_workp/13:03
redrobotAs usual our agenda can be found here:13:03
redrobot#link https://etherpad.openstack.org/p/barbican-weekly-meeting13:03
jamespageo/13:05
redrobotAlrighty, let's get started!13:05
moguimaro/13:06
redrobot#topic Liaison Updates13:06
*** openstack changes topic to "Liaison Updates (Meeting topic: barbican)"13:06
redrobotmoguimar, o/13:06
redrobotmoguimar, any updates from Oslo land?13:06
moguimarnope13:06
redrobotcool13:07
redrobot#topic OpenstackSDK + Barbican13:09
*** openstack changes topic to "OpenstackSDK + Barbican (Meeting topic: barbican)"13:09
redrobotLuzi did you add this topic?13:09
Luziyes, it was mostly a question which came up in the last weeks image encryption meeting13:09
Luzibecause nova likes to rework their config stuff and use openstacksdk13:10
Luzibut no one did know how well keystoneauth1 would work with the connection to Barbican13:11
redrobot#link https://opendev.org/openstack/openstacksdk13:11
LuziDo you know whats the current state of this?13:12
redrobotNo, I haven't looked at any of that code recently13:12
redrobotIs the plan for Nova to use https://opendev.org/openstack/openstacksdk/src/branch/master/openstack/key_manager instead of python-barbicanclient?13:13
Luziwell it seems they would like to migrate to it, but there would be an exception for the barbicanclient13:13
Luzithats what efried told us so far and the reason he asked usif we knew something13:14
Luzii just wanted to ask this here, in case someone did knew something :D13:15
redrobotI can look into it and get back to you next week about the status.13:15
Luzithank you redrobot13:15
redrobotI don't really understand the purpose of openstacksdk though13:16
redrobotseems like doubling client efforts, but I'm not sure what the benefit is13:16
redrobotAre other teams deprecating their python-XXXXXclient in favor of openstacksdk?13:16
redrobot#action redrobot to look into the key_manager implementation of openstacksdk to determine feature gap13:17
Luzii have no idea, i did only speak to nova and cinder teams, and cinder doesn't want to migrate13:18
redrobotSeems like classic OpenStack™ 😂13:19
redrobotcool, I'll look into openstacksdk and see what we can figure out13:19
redrobotanything else on this topic?13:19
Luzinope, thank you13:19
*** openstackstatus has joined #openstack-barbican13:20
*** ChanServ sets mode: +v openstackstatus13:20
redrobot#topic Open Discussion13:25
*** openstack changes topic to "Open Discussion (Meeting topic: barbican)"13:25
redrobotanything else we should talk about?13:25
redrobotmoguimar? rm_work?13:26
* rm_work is dead13:26
redrobotrm_dead13:26
moguimarme is on its way too13:26
LuziI have a quastion regarding the default policies13:26
rm_worki guess, how did the secret consumers thing go13:26
* moguimar *13:26
redrobotrm_work, spec was merged, moguimar will be working on implementation13:26
redrobotLuzi, what's up?13:26
rm_workcool13:26
moguimarI'll start working on it soon13:27
moguimarprobably next week13:27
Luziuhm, why do the roles in the default policies differ from the ones used in other projects (like nova and cinder))13:29
Luzi?13:29
Luzithe deployed roles often ar only admin and _member_ - so why there are Observer, creator and audit ?13:31
redrobotThe idea was to have more fine-grained control over Secrets13:31
redrobotsince they contain sensitive information13:31
Luzii understand that part13:32
Luziare these roles used somewhere by users or so?13:32
redrobotadmin shoudl have full access.  We don't use member yet, but we have been talking about working with the Keystone team to works towards a unified policy13:33
Luziah, thats nice, thank you for that information :D13:34
redrobotI'll talk to Harry Rybacki about it.  IIRC he was the one who wanted to work with us on getting the roles updated.13:34
redrobot#action redrobot to talk to hrybacki about unified roles13:34
redrobotAny other questions/topics we should talk about?13:37
moguimarjust a quick update13:38
moguimarI was at EuroPython two weeks ago13:38
moguimarwith a poster about secrets in configs13:38
moguimarusing oslo.config, castellan and HashiCorp vault in a local demo13:38
redrobotmoguimar, nice!  how'd it go?13:39
moguimarhttps://ep2019.europython.eu/media/conference/slides/m7RV4BB-protecting-secrets-with-osloconfig-and-hashicorp-vault.pdf13:39
moguimarlots of questions about HashiCorp Vault 😅13:39
moguimarpeople were quite interested in secret leases13:39
moguimarin my demo I was able to generate unique credentials to a Postgres DB and pass it to a node using a unique token for that node.13:40
moguimarso different nodes had different credentials13:40
moguimarno secrets in config files at all13:40
moguimartoken injected via ENV vars with the env config driver of oslo.config13:41
moguimarand database credentials fetched via castellan config driver13:41
moguimarI should write some readme in the demo, there are links to the code in the poster13:42
moguimarsome people asked if Barbican also delivers temporary credentials like HashiCorp vault13:42
moguimarthat was it13:43
redrobotWe do not :(13:43
redrobotthanks for the update moguimar13:43
redrobot:D13:44
redrobotok, y'all, thanks for coming13:44
redrobotsee you next week!13:44
moguimarcya13:44
redrobot#endmeeting13:44
*** openstack changes topic to "OpenStack PTG Denver - https://etherpad.openstack.org/p/barbican-train-ptg"13:44
openstackMeeting ended Tue Jul 23 13:44:26 2019 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)13:44
openstackMinutes:        http://eavesdrop.openstack.org/meetings/barbican/2019/barbican.2019-07-23-13.02.html13:44
openstackMinutes (text): http://eavesdrop.openstack.org/meetings/barbican/2019/barbican.2019-07-23-13.02.txt13:44
openstackLog:            http://eavesdrop.openstack.org/meetings/barbican/2019/barbican.2019-07-23-13.02.log.html13:44
*** Luzi has quit IRC13:51
*** trident has quit IRC15:18
*** trident has joined #openstack-barbican15:20
*** dpawlik has quit IRC15:30
*** trident has quit IRC15:52
*** jaosorior has quit IRC15:53
*** trident has joined #openstack-barbican15:55
*** trident has quit IRC17:07
*** trident has joined #openstack-barbican17:10
*** pcaruana has quit IRC20:50
*** irclogbot_2 has quit IRC21:32
*** altlogbot_0 has quit IRC21:33
*** altlogbot_1 has joined #openstack-barbican21:33
*** irclogbot_2 has joined #openstack-barbican21:33
*** irclogbot_2 has quit IRC21:59
*** altlogbot_1 has quit IRC22:01
*** altlogbot_1 has joined #openstack-barbican22:21
*** altlogbot_1 has quit IRC22:27
*** raildo has quit IRC22:35
*** altlogbot_0 has joined #openstack-barbican23:13
*** altlogbot_0 has quit IRC23:19
*** altlogbot_0 has joined #openstack-barbican23:27
*** irclogbot_3 has joined #openstack-barbican23:31

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!