Tuesday, 2021-06-15

*** iurygregory_ is now known as iurygregory06:19
lxkonghi barbican team, may I know what is it possible to mark a secret/container private when creating?11:02
lxkongif not, is it a reasonable feature requirement?11:03
redrobotHi lxkong12:04
redrobotIn my opinion, the best way to make things "private" is for a user to create a new project in Keystone for which they are the only user that has roles assigned on that project.12:05
redrobotlxkong it is also possible to set the "project-access" flag to false in both a secret or a container using the ACL API: https://docs.openstack.org/barbican/latest/api/reference/acls.html12:07
redrobothowever, it's not exactly private, because users with the "admin" role on the project can still access them.  In other words, it only prevents users with "reader" or "member" roles from accessing a secret.12:07
redrobot#startmeeting barbican13:00
opendevmeetMeeting started Tue Jun 15 13:00:35 2021 UTC and is due to finish in 60 minutes.  The chair is redrobot. Information about MeetBot at http://wiki.debian.org/MeetBot.13:00
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.13:00
opendevmeetThe meeting name has been set to 'barbican'13:00
redrobot#topic Roll Call13:00
redrobotCourtesy ping for ade_lee dave-mccowan hrybacki jamespage Luzi lxkong mhen moguimar raildo rm_work tosky xek nearyo oleksandry13:00
rosmaitao/13:01
redrobotHi rosmaita13:01
rosmaitahello13:01
redrobotAs usual the agenda can be found here:13:01
redrobot#link https://etherpad.opendev.org/p/barbican-weekly-meeting13:01
Luzio/13:02
rosmaitaredrobot: https://review.opendev.org/c/openstack/barbican/+/796284 has finally passed zuul, if you could look when you have time, it's blocking some of the cinder gates13:03
rosmaitatook 3 rechecks, but looks like that was due to mirroring problems for dependencies where the jobs landed13:03
redrobot#topic Barbican Gates13:03
redrobotThanks for working ont hat patch rosmaita.  13:03
rosmaitathat was all Gorka, i am just following up13:04
redrobotgotcha13:04
redrobotYeah, I'm not sure how so much SQLAlchemy broke all at once13:04
rosmaitawell, the "major" projects got advance notice a few months ago13:04
redrobotheh13:04
rosmaitai left a comment on the patch that more projects should be notified, but it got lost13:04
rosmaitaanyway, 1.4 intentionally introduced some backward incompatibilities13:05
rosmaitato prepare for 2.013:05
redrobotI'll take a look at the patch right after this meeting and try to catch ade_lee for a second review when he comes online13:05
rosmaitacool, ty13:05
rosmaitai have one more "none of my business, but" comment (or i can wait for open discussion later)13:06
redrobotshoot13:06
rosmaitai noticed that there's a place in the barbican code where you have deleted=1 in a sqlalchemy query13:06
rosmaita'deleted' is boolean in the model, though13:06
rosmaitai believe it's not a problem for mysql/mariadb13:07
rosmaitabut might be worth using boolean to be consistent13:07
rosmaita(since db use is kind of important for barbican)13:07
redrobotAh yeah, that's a good catch13:07
toskyhi13:07
redrobothi tosky13:08
rosmaitawe got burned once by that in glance when someone was using postgresql13:08
toskyI see the main topic I was going to raise has been taken care of already13:08
rosmaita:)13:08
tosky(i.e. broken gates for everyone!)13:08
redrobot😅😅😅13:08
redrobotI'm hoping we can get everything back online in the next couple of hours13:08
rosmaitai wonder whether we should propose that the cinder-tempest-plugin tests be run in the requirements gate -- currently it's just unit tests for select projects13:09
rosmaitathat way barbican would get a workout13:10
rosmaitai was going to propose that barbican unit tests should be added, but that wouldn't have caught this event13:10
rosmaitaanyway, something to think about ... i will be happy to help push this if you think it's a good idea13:11
redrobotMore testing is always good IMO13:11
rosmaitaand actually, i am wrong about the barbican UTs not catching a problem, so maybe those would be sufficient13:11
redrobotlet's propose a patch and see what the requirements folks have to say abou tit13:12
rosmaitasounds good13:13
redrobotOK, moving on ...13:14
redrobot#topic Liaison Updates13:14
redrobottosky anything else you want to talk about?13:14
toskynothing else (usual stuff about grenade still pending)13:17
redrobotcool, thanks tosky13:18
redrobot#topic Kanban Review13:18
redrobot#link https://tree.taiga.io/project/dmend-openstack-barbican/kanban13:18
redrobotI have a WIP patch to fix the unicode error when using the Vault backend: https://review.opendev.org/c/openstack/barbican/+/79606513:19
redrobotthe patch works for a new deployment, but I still need to add the logic to handle inconsistent encodings for existing deployments13:20
redrobot#topic Bug Review13:21
redrobot#link https://storyboard.openstack.org/#!/project_group/barbican13:21
redrobotWe have one new bug for the db migration that was broken by sqlachemy https://storyboard.openstack.org/#!/story/200896713:22
redrobot#link https://bugs.launchpad.net/castellan/+bugs?orderby=-id&start=013:22
redrobotNo new Castellan bugs13:22
redrobot#link https://bugs.launchpad.net/cursive/+bugs?orderby=-id&start=013:22
redrobotAnd no new Cusrvie bugs13:23
redrobot#topic Wayward Reviews13:23
redrobotusually me and moguimar would look at reviews now, but he won't be around very much anymore :(13:23
redrobotThat said, if anyone here is interested in being a core reviewer let me know and we can work on a plan to get you there. ;)13:24
redrobot#topic Open Discussion13:24
redrobotAnything else y'all want to talk about?13:24
rosmaitaredrobot: will you propose a patch to add barbican UTs to the requirements check?13:28
redrobotrosmaita yeah, I can do that13:28
redrobot#action redrobot to propose patch for requirements check to include barbican unit tests13:28
rosmaitacool, ping me in #openstack-cinder and I will leave a comment on it13:28
rosmaitai will talk offline with tosky about the advisibility of proposing cinder-tempest-plugin jobs for requirements13:29
rosmaitaif we put up a patch, i will ping you13:29
redrobotack, sounds good13:29
rosmaitaexcellent, thank you13:29
redrobotThanks for joining, everyone!13:32
redrobot#endmeeting13:32
opendevmeetMeeting ended Tue Jun 15 13:32:03 2021 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)13:32
opendevmeetMinutes:        https://meetings.opendev.org/meetings/barbican/2021/barbican.2021-06-15-13.00.html13:32
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/barbican/2021/barbican.2021-06-15-13.00.txt13:32
opendevmeetLog:            https://meetings.opendev.org/meetings/barbican/2021/barbican.2021-06-15-13.00.log.html13:32
*** ricolin_ is now known as ricolin16:26
*** ricolin_ is now known as ricolin17:32
rosmaitaredrobot: ade_lee: reminder to please look at https://review.opendev.org/c/openstack/barbican/+/79628420:04
opendevreviewDouglas Mendizábal proposed openstack/barbican master: Fix alembic migrations  https://review.opendev.org/c/openstack/barbican/+/79605920:49
lxkongredrobot: Thanks for the answer. So creating a secret/container and then `openstack acl submit URI --no-project-access` would work for me.20:51
opendevreviewMerged openstack/barbican master: Fix unit tests and migration to unblock gate  https://review.opendev.org/c/openstack/barbican/+/79628421:57

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!