opendevreview | OpenStack Proposal Bot proposed openstack/keystone master: Imported Translations from Zanata https://review.opendev.org/c/openstack/keystone/+/924460 | 02:42 |
---|---|---|
*** __ministry is now known as Guest1708 | 08:51 | |
opendevreview | Markus Hentsch proposed openstack/keystone master: Implement the Domain Manager Persona for Keystone https://review.opendev.org/c/openstack/keystone/+/924132 | 13:26 |
opendevreview | Markus Hentsch proposed openstack/keystone-tempest-plugin master: Extend tests for new Domain Manager Persona https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/924222 | 13:26 |
*** __ministry is now known as Guest1728 | 13:53 | |
opendevreview | Markus Hentsch proposed openstack/keystone master: Implement the Domain Manager Persona for Keystone https://review.opendev.org/c/openstack/keystone/+/924132 | 13:55 |
d34dh0r53 | #startmeeting keystone | 15:04 |
opendevmeet | Meeting started Wed Aug 28 15:04:29 2024 UTC and is due to finish in 60 minutes. The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:04 |
opendevmeet | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:04 |
opendevmeet | The meeting name has been set to 'keystone' | 15:04 |
d34dh0r53 | there we go, the bot was slow | 15:05 |
xek | o/ | 15:05 |
d34dh0r53 | #topic roll call | 15:05 |
d34dh0r53 | admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann, zaitcev, reqa, dmendiza[m], mharley, jph, gtema | 15:05 |
d34dh0r53 | o/ | 15:05 |
mhen | o/ | 15:05 |
gtema | o/ | 15:05 |
dmendiza[m] | 🙋♂️ | 15:06 |
d34dh0r53 | #topic review past meeting work items | 15:07 |
d34dh0r53 | #link https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-08-21-15.00.html | 15:07 |
d34dh0r53 | just one: dmendiza please review the updates to https://review.opendev.org/c/openstack/keystone/+/924132 | 15:07 |
d34dh0r53 | I workflowed that about 5 minutes ago | 15:08 |
dmendiza[m] | lgtm | 15:08 |
dmendiza[m] | thank you, mhen | 15:08 |
mhen | thanks dmendiza[m] for the review and the suggestions regarding simplifications due to role inheritance! | 15:08 |
gtema | thats awesome, thanks guys. We are right in time for the feature freeze | 15:09 |
d34dh0r53 | Indeed, it's great that we got that merged, thank you all! | 15:10 |
d34dh0r53 | well, almost merged 🤞 | 15:10 |
d34dh0r53 | next up | 15:11 |
d34dh0r53 | #topic liaison updates | 15:11 |
d34dh0r53 | nothing from VMT | 15:11 |
d34dh0r53 | as mentioned we're coming up on feature freeze on Friday so any last things, now is the time :) | 15:11 |
d34dh0r53 | that's it from Release Management | 15:11 |
d34dh0r53 | #topic specification OAuth 2.0 (hiromu) | 15:12 |
d34dh0r53 | #link https://review.opendev.org/q/topic:bp%252Foauth2-client-credentials-ext | 15:13 |
d34dh0r53 | t | 15:13 |
d34dh0r53 | #link https://review.opendev.org/q/topic:bp%252Fenhance-oauth2-interoperability | 15:13 |
d34dh0r53 | External OAuth 2.0 Specification | 15:13 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystone-specs/+/861554 (merged) | 15:13 |
d34dh0r53 | OAuth 2.0 Implementation | 15:13 |
d34dh0r53 | #link https://review.opendev.org/q/topic:bp%252Fsupport-oauth2-mtls | 15:14 |
d34dh0r53 | OAuth 2.0 Documentation | 15:14 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystone/+/838108 (merged) | 15:14 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystoneauth/+/838104 (merged) | 15:14 |
d34dh0r53 | no updates | 15:14 |
d34dh0r53 | next up | 15:14 |
d34dh0r53 | #topic specification Secure RBAC (dmendiza[m]) | 15:14 |
d34dh0r53 | #link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_ | 15:14 |
d34dh0r53 | 2024.1 Release Timeline | 15:14 |
d34dh0r53 | Update oslo.policy in keystone to enforce_new_defaults=True | 15:15 |
d34dh0r53 | Update oslo.policy in keystone to enforce_scope=True | 15:15 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystone/+/902730 (Merged) | 15:15 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/903713 (Merged) | 15:15 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/tempest/+/912489 (Merged) | 15:15 |
gtema | is anything open on srbac at all? | 15:16 |
gtema | feels like everything is completed | 15:16 |
dmendiza[m] | Not sure if we've tested with the new srbac defaults in oslo.policy? | 15:17 |
d34dh0r53 | not sure either, sorry, my element timeline is really confused so I got lost | 15:19 |
gtema | aren't all the tempest tests everywhere doing that already since the change in oslo.policy merged? | 15:19 |
dmendiza[m] | Possibly? ... Depends on whether Keystone is overriding the oslo defaults or not (e.g. using set_default(...)) | 15:20 |
gtema | hmm, ok | 15:20 |
d34dh0r53 | Are we done with Phase 3 from the Governance doc? | 15:22 |
gtema | we even went further and implemented another persona ;-) | 15:23 |
gtema | btw, I think there is no much for project-manager in keystone. It is more for other services | 15:24 |
d34dh0r53 | Yeah, I was just wondering because I didn't see anything about keystone in the tracking etherpad | 15:25 |
d34dh0r53 | brb, I hate element | 15:25 |
d34dh0r53 | back | 15:26 |
gtema | and everything is still here ;-) I think it is not the element with a problem but a oftc bridge | 15:27 |
d34dh0r53 | It could be the bridge | 15:27 |
d34dh0r53 | but element has some UX things that bother me, but in this case I do think it's the bridge | 15:27 |
gtema | indeed | 15:28 |
d34dh0r53 | Ok, we should clean up the SRBAC speci section of the weekly etherpad then | 15:28 |
gtema | +1 | 15:29 |
d34dh0r53 | and perhaps remove it entirely | 15:29 |
d34dh0r53 | dmendiza: can you take a stab at that? | 15:29 |
dmendiza[m] | ack | 15:30 |
d34dh0r53 | #action dmendiza clean up the SRBAC Specification section of the weekly meeting etherpad | 15:30 |
d34dh0r53 | thanks! | 15:31 |
d34dh0r53 | next up | 15:31 |
d34dh0r53 | #topic specification OpenAPI support (gtema) | 15:31 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystone-specs/+/910584 (merged) | 15:31 |
d34dh0r53 | #link https://review.opendev.org/q/topic:%22openapi%22+project:openstack/keystone | 15:31 |
d34dh0r53 | gtema: changes awaiting review | 15:31 |
d34dh0r53 | I will review these today | 15:32 |
gtema | great, appreciate | 15:32 |
d34dh0r53 | no problem | 15:36 |
d34dh0r53 | next up | 15:36 |
d34dh0r53 | #topic specification domain manager (mhen) | 15:36 |
d34dh0r53 | #link https://review.opendev.org/q/topic:%22domain-manager%22 | 15:36 |
d34dh0r53 | keystone patchset adjusted according to Douglas' review, keystone-tempest-plugin aligned accordingly | 15:36 |
gtema | hopefully Zuul will not complain | 15:37 |
d34dh0r53 | yeah, thanks again Grzegorz Grasza, dmendiza and mhen for getting this in before the deadline | 15:37 |
mhen | seconded, much appreciated! | 15:38 |
d34dh0r53 | cool, there are some tests to merge but those should be easier to get in | 15:39 |
d34dh0r53 | that does it for specifications | 15:39 |
d34dh0r53 | next up | 15:39 |
d34dh0r53 | #topic open discussion | 15:40 |
d34dh0r53 | codebase renovation (gtema) | 15:40 |
d34dh0r53 | #link https://review.opendev.org/q/topic:%22renovate%22+is:open | 15:40 |
d34dh0r53 | I think these are all merged | 15:40 |
gtema | I see everything landed. Thanks a lot guys | 15:40 |
gtema | in the next cycle I will start working on getting rid of passkey | 15:41 |
gtema | passlib | 15:41 |
d34dh0r53 | oh sweet, I was just looking at some replies on that | 15:41 |
d34dh0r53 | it's not looking good upstream, the maintainer has disappeared again | 15:43 |
gtema | looking at growing amount of issues and deprecation in next py I am pretty convinced there is no way around dropping it | 15:43 |
d34dh0r53 | someone on the thread mentioned #link https://github.com/frankie567/pwdlib | 15:45 |
gtema | yes, looking currently | 15:45 |
gtema | I just that if it doesn't offer compatibility with passlib we certanly should avoid exchanging apples with peaches | 15:46 |
d34dh0r53 | I haven't looked into it much | 15:46 |
d34dh0r53 | exactly | 15:46 |
gtema | it's not worth of introducing new dependency when native python core libs already do everything we need | 15:46 |
d34dh0r53 | yeah, that's a goal for next cycle, and I'll add it to the PTG agenda | 15:50 |
gtema | good | 15:50 |
d34dh0r53 | anything else for open discussion before we move on? | 15:51 |
gtema | not from me | 15:51 |
d34dh0r53 | cool, moving on | 15:52 |
d34dh0r53 | #topic bug review | 15:52 |
d34dh0r53 | #link https://bugs.launchpad.net/keystone/?orderby=-id&start=0 | 15:52 |
d34dh0r53 | no new bugs for keystone | 15:52 |
d34dh0r53 | #link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=0 | 15:53 |
d34dh0r53 | nothing new for python-keystoneclient | 15:53 |
d34dh0r53 | #link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=0 | 15:53 |
d34dh0r53 | keystoneauth is good | 15:53 |
d34dh0r53 | #link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=0 | 15:53 |
d34dh0r53 | keystonemiddleware is also good | 15:53 |
d34dh0r53 | #link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=0 | 15:54 |
d34dh0r53 | pycadf is looking good | 15:54 |
d34dh0r53 | #link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=0 | 15:54 |
d34dh0r53 | so it ldappool | 15:54 |
d34dh0r53 | #topic conclusion | 15:54 |
d34dh0r53 | Thanks again for the fantastic effort in reviewing and merging things before the freeze | 15:55 |
d34dh0r53 | It's very much appreciated!! | 15:55 |
d34dh0r53 | The PTG is coming up, please start thinking about topics and we'll get them on the agenda. | 15:56 |
d34dh0r53 | I've resubmitted my candidacy for PTL for Keystone, and am looking forward to another successful cycle | 15:57 |
gtema | :) it is a funny election cycle. All the typical PTLs submit patch in the last 1-2 days | 15:58 |
d34dh0r53 | I know :) I think fungi nailed it | 15:59 |
d34dh0r53 | anyways, that's all from me for this week, thanks again!! | 16:00 |
d34dh0r53 | #endmeeting | 16:00 |
opendevmeet | Meeting ended Wed Aug 28 16:00:30 2024 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 16:00 |
opendevmeet | Minutes: https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-08-28-15.04.html | 16:00 |
opendevmeet | Minutes (text): https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-08-28-15.04.txt | 16:00 |
opendevmeet | Log: https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-08-28-15.04.log.html | 16:00 |
gtema | thanks | 16:00 |
*** ykarel is now known as ykarel|away | 16:09 | |
*** __ministry is now known as Guest1744 | 17:21 | |
opendevreview | Merged openstack/keystone master: Implement the Domain Manager Persona for Keystone https://review.opendev.org/c/openstack/keystone/+/924132 | 18:29 |
Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!