Tuesday, 2022-06-14

opendevreviewYusuke Niimi proposed openstack/keystone master: OAuth2.0 Client Credentials Grant Flow Support  https://review.opendev.org/c/openstack/keystone/+/83073909:10
*** dviroel|out is now known as dviroel11:22
*** dasm|off is now known as dasm14:31
dmendiza[m]#startmeeting keystone15:04
opendevmeetMeeting started Tue Jun 14 15:04:18 2022 UTC and is due to finish in 60 minutes.  The chair is dmendiza[m]. Information about MeetBot at http://wiki.debian.org/MeetBot.15:04
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:04
opendevmeetThe meeting name has been set to 'keystone'15:04
dmendiza[m]#topic Roll Call15:04
dmendiza[m]Courtesy ping for admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, knikolla, lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek15:05
xeko/15:05
h_asahinao/15:05
knikollao/15:05
dmendiza[m]Hi y'all!15:05
dmendiza[m]Let's get started15:06
dmendiza[m]#topic Review Last Meeting Action Items15:06
dmendiza[m]#link https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-05-31-15.00.html15:06
dmendiza[m]There was a few15:07
dmendiza[m]> d34dh0r53 talk to dmendiza[m] about next weeks meeting15:07
dmendiza[m]I assume this was about whether or not we were going to meet last week15:07
dmendiza[m]So, no. :)15:07
dmendiza[m]With most folks at the summit, I figured we'd skip the meeting.15:07
dmendiza[m]> d34dh0r53 dmendiza[m] knikolla review meeting logs and discuss https://review.opendev.org/c/openstack/keystone-specs/+/843765/4/specs/keystone/zed/support-oauth2-mtls.rst15:08
dmendiza[m]I probably should've looked at meeting logs15:09
dmendiza[m]so I just learned about this.15:09
dmendiza[m]We'll add it to the agenda to review specs15:10
dmendiza[m]> d34dh0r53 dmendiza[m] knikolla review https://review.opendev.org/c/openstack/keystone-specs/+/33436415:10
knikollai've cleared up a lot from my calendar today so i can catch up on reviews :/ 15:11
dmendiza[m]Cool15:15
dmendiza[m]I'll add this spec to the spec reviews as well15:16
dmendiza[m]and the last action item15:17
dmendiza[m]> d34dh0r53 ask dmendiza[m] about this bandit line in the agenda15:17
dmendiza[m]>     bandit seems to be broken, cannot build keystone from git 15:17
dmendiza[m]I think that's what d34dh0r53 was talking about15:18
dmendiza[m]I think admiyo was talking about not being able to run bandit from a fresh clone15:18
dmendiza[m]I can try to do that and see how it goes15:19
dmendiza[m]#action dmendiza[m] to try to run keystone from a fresh clone15:19
dmendiza[m]#topic Liaison Updates15:19
dmendiza[m]I don't have any 15:19
dmendiza[m]#topic Summit Recap15:20
dmendiza[m]I unfortunately had to cancel my trip to the Summit15:20
dmendiza[m]Anyone make it to Berlin and want to give a quick recap?15:26
dmendiza[m]I'll take that as a no15:29
dmendiza[m]moving on ...15:29
dmendiza[m]#topic OAuth 2.015:29
dmendiza[m]Looks like we still need lots of reviews 15:29
dmendiza[m]#link https://review.opendev.org/q/topic:bp%252Foauth2-client-credentials-ext15:29
dmendiza[m]Also a new spec15:30
dmendiza[m]#link https://review.opendev.org/c/openstack/keystone-specs/+/84376515:30
dmendiza[m]h_asahina: did you want to talk about these15:30
h_asahinayes15:30
h_asahinaI put the brief explanation on agenda 31th May.15:31
h_asahinaas I wrote there I've submitted the spec and I've changed the contents from BP I submitted before.15:31
h_asahinahttps://blueprints.launchpad.net/keystone/+spec/enhance-oauth2-interoperability15:31
h_asahinaThe reason behind this change is recent update of ETSI NFV SOL013.15:32
h_asahinaLike I said before, I came from OpenStack Tacker that is aiming at implementing ETSI NFV standard,15:33
h_asahinaand the latest version of that standard forces NFV components like Tacker to implement mutual TLS15:33
dmendiza[m]I haven't had a chance to read the spec, but I think mtls would be a good addition15:34
h_asahinathat's glad to hear15:35
h_asahinaSo, I proposed mutual TLS in Spec15:35
h_asahinabut the detailed implementation is not clear in the standard like whether or not we should implement mutual-TLS OAuth2.0 or just mutual-TLS. so, we're confirming it to standarad organization now.15:36
h_asahinaTherefore, we might omit some work items listed in the spec, but we won't add additional items.15:37
h_asahinaI wrote a kind of the maximum work items as we can imagne. so please kindly review it and hopefully give us your feedback.15:38
h_asahinaand I'd like to note that as dmendiza said mutual-TLS will not ruin the security of Keystone.15:40
dmendiza[m]thanks h_asahina 15:40
dmendiza[m]Hopefully we'll get back to reviewathons this week15:41
dmendiza[m]and we'll look at the specs15:41
h_asahinagreat. thanks.15:41
dmendiza[m]#topic Secure RBAC15:41
dmendiza[m]#link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_15:41
dmendiza[m]Ok, took me a second to find the link I needed15:47
dmendiza[m]#link https://review.opendev.org/c/openstack/keystone-specs/+/81860315:47
dmendiza[m]looks like the spec is merged15:47
dmendiza[m]The review needs some TLC15:48
dmendiza[m]#link https://review.opendev.org/c/openstack/keystone/+/82260115:48
dmendiza[m]We'll try to get to those for reviewathon15:50
dmendiza[m]I haven't had a chance to look into what I missed for the Summit with regards to SRBAC15:50
dmendiza[m]Hopefully not to much15:51
dmendiza[m]*too much15:51
dmendiza[m]Moving on ...15:51
dmendiza[m]#topic Gate inherited assignments from parent (bbobrov)15:51
dmendiza[m]#link https://review.opendev.org/c/openstack/keystone-specs/+/33436415:51
dmendiza[m]We should probably review this at reviewathon also15:51
*** dviroel is now known as dviroel|lunch15:58
dmendiza[m]Aaand we're out of time.16:01
dmendiza[m]See y'all Friday for the reviewathon.16:02
dmendiza[m]#endmeeting16:02
opendevmeetMeeting ended Tue Jun 14 16:02:11 2022 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)16:02
opendevmeetMinutes:        https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-06-14-15.04.html16:02
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-06-14-15.04.txt16:02
opendevmeetLog:            https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-06-14-15.04.log.html16:02
*** dviroel|lunch is now known as dviroel17:17
*** dviroel is now known as dviroel|afk20:46
*** dasm is now known as dasm|off21:02

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!