Wednesday, 2024-03-13

*** mhen_ is now known as mhen02:28
*** mklejn__ is now known as mklejn09:05
opendevreviewTakashi Kajinami proposed openstack/keystone master: Update regex to detect closed branch  https://review.opendev.org/c/openstack/keystone/+/91272710:27
opendevreviewTakashi Kajinami proposed openstack/keystone master: Deprecate templated catalog driver  https://review.opendev.org/c/openstack/keystone/+/91276613:10
tkajinamxek, dmendiza[m]  I wonder what you think about ^^^. if that makes sense then we may want to merge it before 2024.1 rc13:11
tkajinam(it seems d34dh0r53 is not online now13:11
opendevreviewJosephine Seifert proposed openstack/keystone-specs master: Add identity spec for domain-manager persona  https://review.opendev.org/c/openstack/keystone-specs/+/90317213:43
Luzidmendiza[m], if you have some time, could you look at this spec^ ? thank you13:43
*** blarnath is now known as d34dh0r5314:51
d34dh0r53#startmeeting keystone15:01
opendevmeetMeeting started Wed Mar 13 15:01:32 2024 UTC and is due to finish in 60 minutes.  The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot.15:01
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:01
opendevmeetThe meeting name has been set to 'keystone'15:01
d34dh0r53#topic roll call15:01
d34dh0r53admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, knikolla[m], lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann, zaitcev, reqa, dmendiza[m], mharley, jph, gtema15:01
d34dh0r53o/15:01
gtemao/15:02
dmendiza[m]🙋15:02
d34dh0r53#topic review past meeting work items15:03
d34dh0r53#link https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-02-28-15.02.html15:03
d34dh0r53no updates on my action items15:03
d34dh0r53#action d34dh0r53 Look into adding/restoring a known issues section to our documentation15:03
d34dh0r53d34dh0r53 add https://bugs.launchpad.net/keystone/+bug/1305950 to the known issues section of our documentation15:03
d34dh0r53#action d34dh0r53 add https://bugs.launchpad.net/keystone/+bug/1305950 to the known issues section of our documentation15:03
d34dh0r53moving on15:03
d34dh0r53#topic liaison updates15:04
d34dh0r53nothing from VMT,15:04
d34dh0r53working on approving all of the caracal-1 things15:04
d34dh0r53for release management15:04
d34dh0r53#topic specification OAuth 2.0 (hiromu)15:04
d34dh0r53#link https://review.opendev.org/q/topic:bp%252Foauth2-client-credentials-ext15:05
d34dh0r53#link https://review.opendev.org/q/topic:bp%252Fenhance-oauth2-interoperability15:05
d34dh0r53External OAuth 2.0 Specification15:05
d34dh0r53#link https://review.opendev.org/c/openstack/keystone-specs/+/86155415:05
d34dh0r53OAuth 2.0 Implementation15:05
d34dh0r53#link https://review.opendev.org/q/topic:bp%252Fsupport-oauth2-mtls15:05
d34dh0r53OAuth 2.0 Documentation15:05
d34dh0r53#link https://review.opendev.org/c/openstack/keystone/+/83810815:05
d34dh0r53#link https://review.opendev.org/c/openstack/keystoneauth/+/83810415:05
d34dh0r53hmm, hiromu hasn't been around in quite a while, anyone know what the status of this work is?15:06
d34dh0r53ok, next up15:08
d34dh0r53#topic specification Secure RBAC (dmendiza[m])15:08
d34dh0r53Secure RBAC (dmendiza[m])15:08
d34dh0r53#link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_15:08
d34dh0r532024.1 Release Timeline15:08
d34dh0r53Update oslo.policy in keystone to enforce_new_defaults=True15:08
d34dh0r53Update oslo.policy in keystone to enforce_scope=True15:08
d34dh0r53#link https://review.opendev.org/c/openstack/keystone/+/902730 (Merged)15:08
d34dh0r53#link https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/90371315:08
mharleyo/15:08
d34dh0r53hi mharley, welcome :)15:08
dmendiza[m]^^ was also merged.15:08
d34dh0r53woot15:09
mharleyHi. Thanks!15:09
dmendiza[m]Next, I'm working on getting Keystone tested in the Tempest repo15:09
dmendiza[m]Tempest already has an SRBAC test, but it is not currently testing Keystone15:09
dmendiza[m]WIP patch is here:15:10
d34dh0r53ahh15:10
dmendiza[m]#link https://review.opendev.org/c/openstack/tempest/+/91248915:10
dmendiza[m]Two issues so far15:10
dmendiza[m]First, I'm trying to figure out how Tempest decides the scope of the admin clients15:10
dmendiza[m]Tempest has an option to auto-create networks when dynamically creating accounts15:10
dmendiza[m]but it's using the wrong scope to do it15:11
dmendiza[m]so it is currently failing for SRBAC15:11
dmendiza[m]There seem to be some inconsistencies in the devstack plugin that sets up srbac for keystone15:12
d34dh0r53that's not surprising :)15:12
dmendiza[m]I am unsure why policy.yaml needs to be set here:15:12
dmendiza[m]#link https://opendev.org/openstack/keystone/src/branch/master/devstack/lib/scope.sh#L1815:12
dmendiza[m]Also admin_system is supposed to be set to all, but it is currently set to true:15:12
dmendiza[m]#link https://opendev.org/openstack/keystone/src/branch/master/devstack/lib/scope.sh#L2415:12
dmendiza[m]We also probably want to use... (full message at <https://matrix.org/_matrix/media/v3/download/matrix.org/SZzFqKcjIZODNjTeQrtWdcIL>)15:13
d34dh0r53hmm15:13
dmendiza[m]instead of what we currently use: [identity-feature-enabled] enforce_scope = true15:13
dmendiza[m]#link https://opendev.org/openstack/keystone/src/branch/master/devstack/lib/scope.sh#L2315:14
d34dh0r53yeah, I think we definitely want to switch to that15:14
d34dh0r53although the docs are pretty confusing15:14
dmendiza[m]So yeah, more work to do in SRBAC15:14
d34dh0r53ack, thanks dmendiza[m] 15:15
d34dh0r53next up15:15
d34dh0r53#topic specification Improve federated users management (gtema)15:15
d34dh0r53#link https://review.opendev.org/c/openstack/keystone-specs/+/748748 - waiting for reviews15:15
gtemaso after you last review there were minor nits to the spec and it was updated15:16
d34dh0r53I saw that, I'll take some to to re-review this week15:16
gtemaand since there were also again questions about mess in federation setup I decided to do "-1" on the way of api change, since it only makes it more complex15:16
gtemabut sadly after that Rafael is not responding15:16
gtemaI would appreciate if you analyze this particular issue on your re-review15:17
d34dh0r53yes, I will focus on that15:17
gtemaperfect, thanks15:18
d34dh0r53no problem, anything else on that?15:18
gtemabtw, I proposed https://review.opendev.org/c/openstack/keystone-specs/+/910584 for next cycle to start improving openapi life15:18
d34dh0r53great, I'll take a look at that as well15:18
gtemagreat. This is a "copy" of same for Nova, so it is not something totally crazy15:19
d34dh0r53excellent15:19
d34dh0r53#topic open discussion15:21
d34dh0r53passlib update15:21
d34dh0r53The maintainer responded to the bug, and one of the top priorities is to fix the bcrypt version bug15:21
d34dh0r53#link https://foss.heptapod.net/python-libs/passlib/-/issues/19015:21
d34dh0r53The maintainer is working on setting up some more core reviewers and maintainers so the project so that the project will no longer be unmaintained15:21
gtemaI noticed that today as well, great news15:21
d34dh0r53I think we can just hold on and wait for an updated passlib which is nice and should save us quite a bit of work in trying to remove it15:21
gtemabut also he himself admitted it got too complex - this is exactly what I observed looking at the code15:22
gtemaits over-designed15:22
d34dh0r53indeed, I think multiple project realized the same thing.  Hopefully going forward it will be streamlined into what people use it for15:23
gtemaright15:23
d34dh0r53based on the feedback from the maintenance status bug I think several projects will step up to help maintain it as it's used in a *lot* of places15:24
gtemaindeed. Would be great to see that15:24
d34dh0r53anything else for open-discussion?15:24
fungijust a heads up that i proposed backports of https://review.opendev.org/c/openstack/keystone/+/908850 to all open branches because otherwise they're just going to lead to zuul configuration errors as soon as the node labels are removed (which for centos-7 will be friday, but the others will be soon as well)15:25
fungiin order to expedite things, i may just go ahead and bypass gating to merge those directly in gerrit, if there are no objections15:26
fungi#link https://review.opendev.org/q/topic:%22drop-centos-7%2215:26
d34dh0r53thanks fungi, I have no objections15:26
fungiappreciated15:26
d34dh0r53likewise!15:27
fungimainly, some branches are in a bad enough state that the cleanup simply can't be merged any other way without disabling or fixing lots of other jobs in the process15:27
d34dh0r53yeah :/15:29
d34dh0r53moving on15:32
d34dh0r53#topic bug review15:32
d34dh0r53#link https://bugs.launchpad.net/keystone/?orderby=-id&start=015:32
d34dh0r53no new bugs for keystone15:32
d34dh0r53#link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=015:32
d34dh0r53nor for python-keystoneclient15:32
d34dh0r53#link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=015:33
d34dh0r53keystoneauth is good15:33
d34dh0r53#link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=015:33
d34dh0r53so is keystonemiddleware15:33
d34dh0r53#link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=015:33
d34dh0r53nothing new for pycadf15:34
d34dh0r53#link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=015:34
d34dh0r53ldappool is also good to go15:34
d34dh0r53#topic conclusion15:34
d34dh0r53Reminder to register for the PTG15:35
d34dh0r53#link https://ptg2024.openinfra.dev15:35
d34dh0r53It's free and virtual15:35
d34dh0r53I'm thinking about hosting 2 1-hour sessions, but if we need more please let me know and I can add them15:35
d34dh0r53That does it for me, thanks folks!15:36
d34dh0r53#endmeeting15:37
opendevmeetMeeting ended Wed Mar 13 15:37:01 2024 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:37
opendevmeetMinutes:        https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-03-13-15.01.html15:37
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-03-13-15.01.txt15:37
opendevmeetLog:            https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-03-13-15.01.log.html15:37
tkajinamd34dh0r53, oops sorry I wasn't aware we had irc meeting today...16:26
tkajinamwas wondering if I can ask for your thoughts on https://review.opendev.org/c/openstack/keystone/+/91276616:26
tkajinammainly if we want to have it to 2024.1 so that we can make an early decision16:27

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!