*** nikparasyr has joined #openstack-barbican | 07:16 | |
*** tosky has joined #openstack-barbican | 07:39 | |
*** mgoddard has quit IRC | 07:45 | |
*** mgoddard has joined #openstack-barbican | 07:50 | |
*** Luzi has joined #openstack-barbican | 10:03 | |
*** dwilde has joined #openstack-barbican | 12:53 | |
redrobot | #startmeeting barbican | 13:00 |
---|---|---|
openstack | Meeting started Tue May 11 13:00:17 2021 UTC and is due to finish in 60 minutes. The chair is redrobot. Information about MeetBot at http://wiki.debian.org/MeetBot. | 13:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 13:00 |
*** openstack changes topic to " (Meeting topic: barbican)" | 13:00 | |
openstack | The meeting name has been set to 'barbican' | 13:00 |
redrobot | #topic Roll Call | 13:00 |
*** openstack changes topic to "Roll Call (Meeting topic: barbican)" | 13:00 | |
redrobot | Courtesy ping for ade_lee dave-mccowan hrybacki jamespage Luzi lxkong mhen moguimar raildo rm_work tosky xek nearyo oleksandry | 13:01 |
redrobot | As usual the agenda can be found here: | 13:01 |
redrobot | #link https://etherpad.opendev.org/p/barbican-weekly-meeting | 13:01 |
Luzi | o/ | 13:01 |
redrobot | Hi Luzi | 13:01 |
Luzi | hi redrobot | 13:01 |
moguimar | o/ | 13:02 |
redrobot | Hi moguimar! | 13:02 |
tosky | hi | 13:03 |
redrobot | Hi tosky! | 13:03 |
redrobot | Let's get started | 13:03 |
redrobot | #topic LIaison Updates | 13:03 |
*** openstack changes topic to "LIaison Updates (Meeting topic: barbican)" | 13:03 | |
redrobot | moguimar? tosky? | 13:04 |
moguimar | I missed the oslo meeting yesterday | 13:04 |
moguimar | no updates | 13:04 |
redrobot | no worries, moguimar | 13:04 |
*** dwilde has quit IRC | 13:04 | |
redrobot | tosky must be multitasking ... let's move on to the next topic | 13:06 |
tosky | nothing special (just a tiny patch) | 13:06 |
tosky | but yeah, #nexttopic :) | 13:06 |
redrobot | ack, we'll get to it during Wayward Reviews | 13:06 |
redrobot | #topic Kanban Review | 13:06 |
*** openstack changes topic to "Kanban Review (Meeting topic: barbican)" | 13:06 | |
moguimar | no progress on hvac | 13:06 |
redrobot | #link https://tree.taiga.io/project/dmend-openstack-barbican/kanban | 13:06 |
redrobot | OK, just added card #16 to track the fix to the Vault backend encoding issue | 13:08 |
redrobot | moguimar any updates on your end? | 13:08 |
*** rajivmucheli has joined #openstack-barbican | 13:09 | |
moguimar | nope | 13:11 |
redrobot | OK, moving on | 13:11 |
redrobot | #topic Bug Review | 13:11 |
*** openstack changes topic to "Bug Review (Meeting topic: barbican)" | 13:11 | |
redrobot | #link https://storyboard.openstack.org/#!/project_group/barbican | 13:11 |
redrobot | looks like no new barbican stories | 13:11 |
redrobot | #link https://bugs.launchpad.net/castellan/+bugs?orderby=-id&start=0 | 13:11 |
redrobot | And no new Catellan bugs | 13:11 |
redrobot | #link https://bugs.launchpad.net/cursive/+bugs?orderby=-id&start=0 | 13:12 |
redrobot | and no new Cursive bugs | 13:12 |
redrobot | #topic Wayward Reviews | 13:12 |
*** openstack changes topic to "Wayward Reviews (Meeting topic: barbican)" | 13:12 | |
redrobot | #link https://tinyurl.com/y3zto3ad | 13:12 |
redrobot | moguimar easy one: https://review.opendev.org/c/openstack/barbican/+/787916 | 13:13 |
moguimar | easy indeed | 13:14 |
redrobot | I'm not sure about this one: https://review.opendev.org/c/openstack/barbican-tempest-plugin/+/787046 | 13:18 |
redrobot | Channeling my inner Zen of Python: "Explicit is better than implicit" | 13:18 |
redrobot | seems like spelling out py36 and py38 would be better than a floating py3 that would run whatever 3.x is available. | 13:19 |
moguimar | ah, I heard about this one | 13:20 |
moguimar | is a governance thing | 13:20 |
moguimar | projects should move to py3 and have the specific version determined by the CI jobs | 13:20 |
redrobot | Hmm... | 13:23 |
redrobot | I'll need to dig into it further | 13:23 |
redrobot | because I don't like it. :-P | 13:23 |
moguimar | yeah | 13:24 |
moguimar | I'd like to see a link to a thread in the ML | 13:24 |
redrobot | Right... it looks like tosky doesn't like it either on that python-barbicanclient patch. :) | 13:25 |
*** dwilde has joined #openstack-barbican | 13:25 | |
tosky | yeah, and I don't like even more those massive changes sent without any coordination or announcement (or prior agreement) | 13:27 |
redrobot | tosky++ | 13:27 |
redrobot | I'm gonna go ahead and reject all those patches | 13:27 |
redrobot | moguimar another easy one: https://review.opendev.org/c/openstack/barbican-tempest-plugin/+/788851 | 13:29 |
moguimar | done | 13:30 |
tosky | the patch I mentioned before is https://review.opendev.org/c/openstack/barbican-tempest-plugin/+/790237 | 13:31 |
rajivmucheli | Hi, do the below links assist in: | 13:34 |
rajivmucheli | 1. Vault as backend for Barbican : | 13:34 |
rajivmucheli | https://docs.openstack.org/barbican/latest/install/barbican-backend.html#vault-plugin | 13:34 |
rajivmucheli | 2. Barbican as backend for Vault : | 13:34 |
rajivmucheli | https://docs.openstack.org/security-guide/secrets-management/barbican.html#vault-plugin | 13:34 |
*** dwilde has quit IRC | 13:34 | |
redrobot | hi rajivmucheli | 13:37 |
redrobot | tosky looking ... your patch is small, but I'm having to look into tempest clients to understand it. 😅 | 13:38 |
redrobot | rajivmucheli #1 is correct, Hashicorp Vault can be used as a backend for Barbican (although there's a huge bug in orders that I'm fixing) | 13:39 |
redrobot | rajivmucheli #2 is incorrect. I don't think Barbican can be used as a backend to Vault | 13:40 |
tosky | redrobot: it's a follow-up of an older patch (not sure why I didn't catch it back then) | 13:41 |
redrobot | tosky cool, I'll finish reviewing it after the meeting | 13:41 |
redrobot | #topic Open Discussion | 13:41 |
*** openstack changes topic to "Open Discussion (Meeting topic: barbican)" | 13:41 | |
redrobot | Anything else y'all want to talk about? | 13:41 |
rajivmucheli | thanks redrobot, are there any plugins or scope to configure Barbican as backend for Vault ? | 13:42 |
redrobot | rajivmucheli not here, we don't do any Vault development. You would have to ask the Vault developers. | 13:43 |
rajivmucheli | oops ok, | 13:43 |
rajivmucheli | another question, i was configuring octavia listener to use a barbican secret | 13:44 |
rajivmucheli | why does barbican validate if its a secret or secret container ? | 13:45 |
rajivmucheli | https://github.com/openstack/octavia/blob/master/doc/source/user/guides/basic-cookbook.rst#deploy-a-tls-terminated-https-load-balancer | 13:45 |
rajivmucheli | when i execute this command `openstack loadbalancer listener create --protocol-port 443 --protocol TERMINATED_HTTPS --name listener1 --default-tls-container=$(openstack secret list | awk '/ tls_secret1 / {print $2}') lb1` | 13:45 |
redrobot | I think the first implementation in Octavia used a secret-container for the different parts (key, cert) | 13:46 |
redrobot | But then they changed to a single secret in pkcs#7 format which includes both key and cert in a single file. | 13:46 |
rajivmucheli | i receive a HTTP 404 from container secret, which is correct since its a secret not secret container. i was wondering why the secret container check takes place | 13:46 |
johnsom | Right, we still support containers for backward compatibility, but have migrated to using pkcs12 bundles | 13:46 |
redrobot | Oops, pkcs12 not pkcs7 | 13:47 |
johnsom | Grin | 13:47 |
rajivmucheli | yes, its pkcs12, | 13:47 |
rajivmucheli | the doc explains `Combine the individual cert/key/intermediates to single PKCS12 files` | 13:47 |
openstackgerrit | Merged openstack/barbican master: setup.cfg: Replace dashes with underscores https://review.opendev.org/c/openstack/barbican/+/787916 | 13:48 |
redrobot | Maybe you need a different flag instead of --default-tls-container? | 13:49 |
johnsom | Nope | 13:49 |
johnsom | Server side automatically checks both. Are you getting an errror? | 13:50 |
johnsom | Or just seeing a log entry? | 13:51 |
rajivmucheli | its just a log entry showing http 404 from barbican-api, the listener is created though | 13:55 |
johnsom | Yeah, that is just the backward compatibility layer working. | 13:56 |
*** dwilde has joined #openstack-barbican | 13:57 | |
redrobot | "It's a feature, not a bug"â„¢ | 13:57 |
redrobot | 😎 | 13:57 |
redrobot | Alrighty, we're almost out of time. | 13:58 |
redrobot | Thanks for joining, everyone! | 13:58 |
redrobot | #endmeeting | 13:58 |
*** openstack changes topic to "OpenStack Barbican Development - Weekly Meeting Agenda: https://etherpad.openstack.org/p/barbican-weekly-meeting" | 13:58 | |
openstack | Meeting ended Tue May 11 13:58:13 2021 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 13:58 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/barbican/2021/barbican.2021-05-11-13.00.html | 13:58 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/barbican/2021/barbican.2021-05-11-13.00.txt | 13:58 |
openstack | Log: http://eavesdrop.openstack.org/meetings/barbican/2021/barbican.2021-05-11-13.00.log.html | 13:58 |
rajivmucheli | cool, i dint intend to report it as bug, i wanted to clarify! | 13:58 |
rajivmucheli | thank you! | 13:58 |
johnsom | rajivmucheli if you have more Octavia questions, we hang out in #openstack-lbaas | 13:59 |
*** Luzi has quit IRC | 13:59 | |
*** dwilde has quit IRC | 13:59 | |
*** dwilde has joined #openstack-barbican | 13:59 | |
rajivmucheli | (y) | 13:59 |
*** rajivmucheli has quit IRC | 14:05 | |
openstackgerrit | Merged openstack/barbican-tempest-plugin master: Add stable/wallaby jobs on master gate https://review.opendev.org/c/openstack/barbican-tempest-plugin/+/788851 | 14:07 |
*** iurygregory has quit IRC | 14:22 | |
*** iurygregory has joined #openstack-barbican | 14:22 | |
*** nikparasyr has left #openstack-barbican | 15:06 | |
*** dave-mccowan has quit IRC | 15:10 | |
*** dwilde has quit IRC | 16:18 | |
*** dwilde has joined #openstack-barbican | 16:25 | |
*** dwilde has quit IRC | 16:35 | |
*** dwilde has joined #openstack-barbican | 16:41 | |
*** dwilde has quit IRC | 17:34 | |
*** dwilde has joined #openstack-barbican | 17:48 | |
*** dwilde has quit IRC | 18:05 | |
*** dwilde has joined #openstack-barbican | 18:07 | |
*** dwilde has quit IRC | 19:39 | |
*** dwilde has joined #openstack-barbican | 19:57 | |
*** lxkong has quit IRC | 20:09 | |
*** lxkong has joined #openstack-barbican | 20:13 | |
*** dwilde has quit IRC | 21:03 | |
*** tosky has quit IRC | 23:24 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!