Tuesday, 2022-05-03

*** dasm|ruck|bbl is now known as dasm|ruck|off03:11
*** ministry is now known as __ministry07:44
*** dviroel|out is now known as dviroel11:18
*** dasm|ruck|off is now known as dasm|ruck12:17
gmannRBAC meeting started now, details https://wiki.openstack.org/wiki/Consistent_and_Secure_Default_Policies_Popup_Team#Meeting14:01
dmendiza[m]knikolla: around? ☝️14:06
knikolladmendiza[m]: yes14:07
knikollaJoining14:07
dmendiza[m]Waiting until the SRBAC meeting is over to start the Keystone Weekly meeting ...15:01
dmendiza[m]gmann knikolla dansmith https://meet.google.com/qax-tkne-dmk15:03
alexYefimov_I have a question about the para "minimum_password_age" in keystone.  Does this parameter effect admin and non-admin users exactly the same way?15:23
dmendiza[m]#startmeeting Keystone15:26
opendevmeetMeeting started Tue May  3 15:26:29 2022 UTC and is due to finish in 60 minutes.  The chair is dmendiza[m]. Information about MeetBot at http://wiki.debian.org/MeetBot.15:26
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:26
opendevmeetThe meeting name has been set to 'keystone'15:26
dmendiza[m]#topic Roll Call15:26
dmendiza[m]Courtesy ping for admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, knikolla, lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe15:26
dmendiza[m]As usual the agenda is over here:15:27
dmendiza[m]#link https://etherpad.opendev.org/p/keystone-weekly-meeting15:27
knikollao/15:28
d34dh0r53o/15:29
dmendiza[m]OK, let's get started15:30
dmendiza[m]#topic Review Past Meeting Action Items15:30
dmendiza[m]#link https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-04-26-15.02.html15:30
dmendiza[m]Looks like we didn't have any15:30
dmendiza[m]#topic Liaison Updates15:31
dmendiza[m]I don't have any updates this week.15:31
dmendiza[m]#topic OAuth 2.015:33
dmendiza[m]We had a review session last week15:33
dmendiza[m]#link https://review.opendev.org/q/topic:bp%252Foauth2-client-credentials-ext15:34
dmendiza[m]I don't think we have any updates for today15:34
dmendiza[m]moving on ...15:39
dmendiza[m]#topic Secure RBAC15:39
dmendiza[m]In case you missed the Google Meet session, we did discuss the "service" role a bit15:39
dmendiza[m]We'll continue discussions next week.15:40
dmendiza[m]#topic Guidance for storing user tokens15:40
dmendiza[m]dansmith asked this in the channel a while back (sorry we didn't get to it last week)15:40
dmendiza[m]He's basically looking for guidance in handling user tokens.15:41
dmendiza[m]IIRC, they're wanting to log them or store them in the DB15:41
dmendiza[m]presumable to be reused again, during long-running tasks.15:41
dmendiza[m]*presumably15:41
knikollaHmmm, interesting15:43
knikollaMy initial gut reaction is no15:43
knikollaBut I can see the need for it15:45
d34dh0r53Can we set an expiry on issued tokens?15:47
knikollaThat’s the way it aready is. Configurable but defaults to 45 mins I think15:49
dmendiza[m]d34dh0r53: yeah, tokens expire, but some services can still use them for context when doing long running tasks15:49
d34dh0r53but not overrideable during the issue?15:49
knikollaNo, you can’t ask for a longer living token than the config15:50
knikollaNo, you can’t ask for a longer living token than the config15:51
d34dh0r53hmm, ack15:51
dmendiza[m]We may need to think about it for a bit15:52
dmendiza[m]but it would be good to have an opinion on best practices for what to do with the tokens15:53
*** dviroel is now known as dviroel|lunch15:53
knikollaAgree, i can spend some time thinking about this15:53
dansmithdmendiza[m]: to be clear, I want to neither store nor log them15:54
dansmithI just want there to be some guidance about that being a bad idea that I can point to whilst arguing :P15:54
d34dh0r53:)15:55
knikollaThat’s easier :)15:56
dmendiza[m]ack, I missed that last time, haha15:57
knikollaStore tokens, bad. You can link to this irc log, haha.15:57
dansmithknikolla: ack, I'll take it as better than nothing, but.. seems like it might be good to capture some of those sorts of recommendation somewhere.. I know, easy for me to say15:59
knikollaI’m sure there’s something in the docs and if not I’ll put it there16:00
dmendiza[m]OK, we're just about out of time.16:00
dmendiza[m]No bug review this week.16:00
dmendiza[m]We'll get back to normal once the Secure RBAC sessions start winding down.16:01
dmendiza[m]Thanks for joining, everyone!16:01
dmendiza[m]#endmeeting16:01
opendevmeetMeeting ended Tue May  3 16:01:18 2022 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)16:01
opendevmeetMinutes:        https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-05-03-15.26.html16:01
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-05-03-15.26.txt16:01
opendevmeetLog:            https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-05-03-15.26.log.html16:01
*** dasm|ruck is now known as dasm|ruck|bbl16:50
*** dviroel|lunch is now known as dviroel16:56
opendevreviewBoris Bobrov proposed openstack/keystone-specs master: Prepare for Zed  https://review.opendev.org/c/openstack/keystone-specs/+/83987316:57
opendevreviewBoris Bobrov proposed openstack/keystone-specs master: Gate inherited assignments from parent  https://review.opendev.org/c/openstack/keystone-specs/+/33436416:58
*** dasm|ruck|bbl is now known as dasm|ruck18:01
*** dviroel is now known as dviroel|out21:30

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!