Tuesday, 2022-09-13

*** dviroel|afk is now known as dviroel00:41
*** dviroel is now known as dviroel|out00:50
*** tkajinam is now known as Guest16206:33
*** marlinc is now known as Guest16708:04
*** dviroel|out is now known as dviroel11:36
*** dasm|off is now known as dasm13:21
dmendiza[m]#startmeeting keystone15:02
opendevmeetMeeting started Tue Sep 13 15:02:50 2022 UTC and is due to finish in 60 minutes.  The chair is dmendiza[m]. Information about MeetBot at http://wiki.debian.org/MeetBot.15:02
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:02
opendevmeetThe meeting name has been set to 'keystone'15:02
dmendiza[m]#topic Roll Call15:02
dmendiza[m]Courtesy ping for admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, knikolla, lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek15:03
knikollao/15:03
h_asahinao/15:03
dmendiza[m]As usual the agenda is over here:15:03
dmendiza[m]#link https://etherpad.opendev.org/p/keystone-weekly-meeting15:03
dmendiza[m]OK, let's get started15:08
dmendiza[m]#topic Review Past Meeting Action Items15:08
dmendiza[m]#link https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-09-06-15.00.html15:08
dmendiza[m]> dmendiza[m] to look into making a new keystoneauth release15:09
dmendiza[m]I have not made a new release yet15:09
dmendiza[m]s/made/requested15:09
dmendiza[m]#action dmendiza[m] to request a new keystoneauth release15:09
dmendiza[m]which is a good segue into 15:10
dmendiza[m]#topic Liaison Updates15:10
dmendiza[m]It's RC1 week15:11
dmendiza[m]#link https://review.opendev.org/c/openstack/releases/+/85711615:11
dmendiza[m]That's the RC1 release patch for keystone15:11
dmendiza[m]at 1ea9f7557dc442c56805f70b3f0c9393b427a77015:11
dmendiza[m]#link https://opendev.org/openstack/keystone/commit/1ea9f7557dc442c56805f70b3f0c9393b427a77015:12
dmendiza[m]which is currently the master branch15:12
dmendiza[m]are there any patches we should try to merge before we approve the release?15:13
h_asahinaOAuth2.0 documatations are remaining. is that okey to leave them?15:13
knikollai haven't had the time to review them, but we can definitely backport docs patches15:14
h_asahinathanks. that a relief.15:15
dmendiza[m]Yeah, I would not hold back RC1 for docs15:16
dmendiza[m]Cool, sounds like we're good to +1 the release patch15:17
dmendiza[m]That's all I have for liaison updates15:19
dmendiza[m]#topic Antelope PTL15:19
dmendiza[m]We're technically "leaderless" for the Antelope cycle 15:20
dmendiza[m]but d34dh0r53 did submit his candidacy15:21
dmendiza[m]#link https://review.opendev.org/c/openstack/election/+/85629715:21
knikollaWith my TC hat on: The TC will likely appoint d34dh0r53 as PTL given his candidacy. 15:22
dmendiza[m]That's good to hear. 15:25
dmendiza[m]Not sure I mentioned it in the channel before, but I'll be taking a lot of time off work during the Antelope cycle15:26
dmendiza[m]otherwise I'd be happy to keep helping out as PTL.15:26
dmendiza[m]So, thanks to d34dh0r53 for volunteering.15:27
dmendiza[m]OK, moving on ...15:27
dmendiza[m]#topic Core Team updats15:27
dmendiza[m]#undo15:27
opendevmeetRemoving item from minutes: #topic Core Team updats15:27
dmendiza[m]#topic Core Team updates15:27
dmendiza[m]knikolla suggested we should consider growing the core team15:28
dmendiza[m]and nominate xek for core15:29
dmendiza[m]which I know he'll be very much interested in15:29
dmendiza[m]unfortunately he's out on vacation and won't be back for a couple of weeks.15:29
dmendiza[m]So we'll check with xek to make sure he's still on board and get that process started when he gets back15:30
dmendiza[m]Ok, moving on ...15:33
dmendiza[m]#topic OAuth 2.015:34
dmendiza[m]At this point we should go ahead and re-target this spec to antelope15:35
dmendiza[m]#link https://review.opendev.org/c/openstack/keystone-specs/+/84376515:35
h_asahinaagree15:35
h_asahinawe've started the implementation, so we can show the codes immediately after the spec is merged.15:36
dmendiza[m]we should be on track to get mTLS merged early in the antelope cycle, which is awesome15:37
dmendiza[m]anything other updates on this topic h_asahina ?15:38
h_asahinaI'd like to confirm that :knikolla do you think it better to show our codes to you or writing rest of parts after seeing your demo?15:38
knikollah_asahina: is the code based on federation and mappings?15:39
knikollai'm almost done with the demo, just having issues with Apache not passing the SSL environment variables to Keystone15:39
h_asahinayes. technically we are using mapping API of Federation API.15:40
knikollaGood :)15:40
knikollaIt's okay to push code for review even if the spec hasn't merged yet. 15:41
knikollaFor early feedback. We just will make sure not to merge it until after the spec does. 15:41
h_asahinaok, good. it depends on how to share your codes, but if you can show your draft codes, we'd like to see it. 15:42
h_asahinamaybe we can modify our codes based on your codes.15:42
knikollaMy code is just some bash setting up keystone with tls, generating client certs, and making the route to the authentication endpoint for the mapped plugin protected by ssl client verify, and trying to fetch the environment variables from the succesful ssl verification in apache and use them in a mapping. :)15:44
knikollaI'm simply trying to demonstrate using client tls as an authentication mechanism using the mapped plugin15:45
knikolladoes that make sense to you?15:46
h_asahinai see. so far, it looks similar with our understanding.15:46
h_asahinawill push the codes as you said. after you demo becomes ready, we'll update our code based on both your comments and demo.15:47
h_asahinais that okey?15:48
knikollayes15:49
*** dviroel is now known as dviroel|lunch15:51
dmendiza[m]sounds like we've got a plan 15:52
dmendiza[m]OK, let's move on ...15:52
dmendiza[m]#topic Open Discussion 15:53
dmendiza[m]Any last minute topics y'all want to discuss?15:53
dmendiza[m]Sounds like we're done for today. 15:57
h_asahinait's not discussion, but as it's almost the end of Zed cycle, I'd like to sincerely appreciate all keystone cores support for OAuth2.0 patches.15:57
dmendiza[m]h_asahina: thank you guys for your contributions and patience. 👍️15:58
dmendiza[m]See y'all online!15:58
knikollayes, thank you for you contribution and patience over the numerous iterations. 15:58
dmendiza[m]#endmeeting15:58
opendevmeetMeeting ended Tue Sep 13 15:58:46 2022 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:58
opendevmeetMinutes:        https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-09-13-15.02.html15:58
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-09-13-15.02.txt15:58
opendevmeetLog:            https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-09-13-15.02.log.html15:58
*** dviroel|lunch is now known as dviroel16:57
*** dviroel is now known as dviroel|brb20:10
*** dasm is now known as dasm|off22:28
*** dasm|off is now known as Guest30523:03

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!