*** mhen_ is now known as mhen | 02:11 | |
d34dh0r53 | #startmeeting keystone | 15:04 |
---|---|---|
opendevmeet | Meeting started Wed Dec 4 15:04:05 2024 UTC and is due to finish in 60 minutes. The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:04 |
opendevmeet | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:04 |
opendevmeet | The meeting name has been set to 'keystone' | 15:04 |
d34dh0r53 | Reminder: This meeting takes place under the OpenInfra Foundation Code of Conduct | 15:04 |
d34dh0r53 | #link https://openinfra.dev/legal/code-of-conduct | 15:04 |
d34dh0r53 | #topic roll call | 15:04 |
d34dh0r53 | admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann, zaitcev, reqa, dmendiza[m], dmendiza, mharley, jph, gtema, cardoe | 15:04 |
gtema | 0- | 15:04 |
cardoe | o/ | 15:05 |
d34dh0r53 | #topic review past meeting work items | 15:06 |
d34dh0r53 | #link https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-11-20-15.12.html | 15:06 |
d34dh0r53 | There was one action item: | 15:06 |
d34dh0r53 | d34dh0r53 Update SHA in https://review.opendev.org/c/openstack/releases/+/934599 to HEAD of keystoneauth | 15:07 |
d34dh0r53 | This has been done | 15:07 |
d34dh0r53 | #topic liaison updates | 15:07 |
d34dh0r53 | nothing from VMT nor releases | 15:07 |
d34dh0r53 | #topic specification OAuth 2.0 (hiromu) | 15:09 |
d34dh0r53 | #link https://review.opendev.org/q/topic:bp%252Foauth2-client-credentials-ext | 15:09 |
d34dh0r53 | #link https://review.opendev.org/q/topic:bp%252Fenhance-oauth2-interoperability | 15:09 |
d34dh0r53 | External OAuth 2.0 Specification | 15:09 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystone-specs/+/861554 (merged) | 15:09 |
d34dh0r53 | OAuth 2.0 Implementation | 15:09 |
d34dh0r53 | #link https://review.opendev.org/q/topic:bp%252Fsupport-oauth2-mtls | 15:09 |
d34dh0r53 | OAuth 2.0 Documentation | 15:09 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystone/+/838108 (merged) | 15:09 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystoneauth/+/838104 (merged) | 15:09 |
d34dh0r53 | no updates from me on this one | 15:09 |
d34dh0r53 | next up | 15:09 |
d34dh0r53 | #topic specification Secure RBAC (dmendiza[m]) | 15:09 |
d34dh0r53 | #link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_ | 15:09 |
d34dh0r53 | 2024.1 Release Timeline | 15:10 |
d34dh0r53 | Update oslo.policy in keystone to enforce_new_defaults=True | 15:10 |
d34dh0r53 | Update oslo.policy in keystone to enforce_scope=True | 15:10 |
d34dh0r53 | dmendiza: you around? | 15:11 |
d34dh0r53 | guess not | 15:13 |
d34dh0r53 | #topic specification OpenAPI support (gtema) | 15:13 |
d34dh0r53 | #link https://review.opendev.org/q/topic:%22openapi%22+project:openstack/keystone | 15:13 |
gtema | after merging some of the latest changes I noticed some jsonschemas became corrupted (the ones which are not attached to api yet) | 15:13 |
gtema | but for the moment I have implemented workaround | 15:13 |
gtema | that tells we need to speed up a bit merging the changes | 15:14 |
gtema | and so the work is in progress. Nothing else about openapi | 15:14 |
d34dh0r53 | ack, do any of them need reviews right now? | 15:14 |
gtema | will check today what is up next | 15:15 |
d34dh0r53 | ack, thanks gtema (Artem Goncharov) | 15:15 |
d34dh0r53 | #topic specification domain manager (mhen) | 15:15 |
d34dh0r53 | still unmerged are: | 15:15 |
d34dh0r53 | documentation: https://review.opendev.org/c/openstack/keystone/+/928135 | 15:15 |
d34dh0r53 | tempest tests: https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/924222 | 15:15 |
d34dh0r53 | dmendiza, Grzegorz Grasza please review these | 15:15 |
dmendiza[m] | 🙋♂️ | 15:16 |
d34dh0r53 | o/ dmendiza | 15:16 |
dmendiza[m] | Ack, will take a look at Domain Manager patches | 15:17 |
d34dh0r53 | thanks! | 15:18 |
d34dh0r53 | next up | 15:18 |
d34dh0r53 | #topic specification Include bad password details in audit messages (stanislav-z) | 15:18 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystone-specs/+/915482 | 15:18 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystone/+/932423 | 15:18 |
d34dh0r53 | 20-Nov update: spec and implementation updated for HMAC-based hashing. Looking for reviews. | 15:18 |
d34dh0r53 | Stanislav Zaprudskiy: any updates? | 15:18 |
gtema | I guess our reviews are missing | 15:19 |
d34dh0r53 | indeed | 15:20 |
gtema | sadly I had no time to look at it so far | 15:20 |
d34dh0r53 | nor me | 15:21 |
d34dh0r53 | we can dedicate some time during the reviewathon this week | 15:21 |
d34dh0r53 | #action reviewathon look at the Bad Password spec https://review.opendev.org/c/openstack/keystone-specs/+/915482 | 15:22 |
d34dh0r53 | next up | 15:22 |
d34dh0r53 | #topic open discussion | 15:22 |
d34dh0r53 | new gate (un)blocker | 15:22 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystone/+/936721 | 15:22 |
gtema | last week I identified (after working on pagination) that I accidentally introduced new blocker with the change in devstack that got merged | 15:23 |
d34dh0r53 | ack, I just reviewed it | 15:23 |
d34dh0r53 | dmendiza: can you push the go button on https://review.opendev.org/c/openstack/keystone/+/936721 | 15:23 |
gtema | this change fixes that. Point is that 1st I introduced new wsgi module, 2nd devstack switched to using that, 3rd - there are no federation jobs running in devstack changes so I missed breaking federation tests | 15:24 |
gtema | thks | 15:24 |
dmendiza[m] | lgtm | 15:24 |
d34dh0r53 | 👍️ | 15:25 |
d34dh0r53 | next up | 15:25 |
d34dh0r53 | pagination (gtema) | 15:25 |
d34dh0r53 | #link https://review.opendev.org/q/topic:%22pagination%22+project:openstack/keystone | 15:25 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystone/+/933598 must be merged before next work can be started | 15:25 |
gtema | right, so last week I have figured out that the change was already paginating domains | 15:26 |
gtema | because domains are, well, projects | 15:26 |
gtema | so I fine-tuned the change to explicitly tell that and added sufficient unit tests for the changed API | 15:26 |
d34dh0r53 | ahh | 15:26 |
d34dh0r53 | is the zuul failure still unrelated? | 15:27 |
gtema | this is the one from above | 15:27 |
gtema | the federation stuff | 15:27 |
gtema | once that is merged should be fine | 15:27 |
d34dh0r53 | ack | 15:27 |
d34dh0r53 | I'll try to review pagination this week | 15:27 |
gtema | awesome, thanks | 15:28 |
d34dh0r53 | anything else for open discussion? | 15:28 |
gtema | not from me | 15:28 |
d34dh0r53 | #topic bug review | 15:29 |
d34dh0r53 | #link https://bugs.launchpad.net/keystone/?orderby=-id&start=0 | 15:29 |
d34dh0r53 | #link https://bugs.launchpad.net/keystone/+bug/2089051 | 15:29 |
d34dh0r53 | gtema (Artem Goncharov): have you seen this one? | 15:29 |
d34dh0r53 | it looks like Takashi is working on it, but wanted you to see it | 15:30 |
gtema | I think I have seen that report | 15:30 |
d34dh0r53 | not sure if it coincides with what you're working on | 15:30 |
gtema | to some extend it does, but not heavily | 15:31 |
d34dh0r53 | ok | 15:31 |
d34dh0r53 | next up | 15:31 |
d34dh0r53 | #link https://bugs.launchpad.net/keystone/+bug/2089403 | 15:31 |
gtema | we identified that working on openapi | 15:32 |
gtema | if you remember we have this one change removing "experimental" label from the unified limits api | 15:33 |
gtema | and this is one interesting gotcha there | 15:33 |
d34dh0r53 | indeed | 15:33 |
d34dh0r53 | based on the test that is expected behavior though, which is interesting | 15:33 |
gtema | yeah, I think people have overseen that | 15:34 |
d34dh0r53 | ok, we at least need documentation | 15:36 |
d34dh0r53 | that does it for keystone | 15:37 |
d34dh0r53 | next up | 15:37 |
d34dh0r53 | #link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=0 | 15:37 |
d34dh0r53 | no new bugs in python-keystoneclient | 15:37 |
d34dh0r53 | #link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=0 | 15:38 |
d34dh0r53 | looks like keystoneauth is good | 15:38 |
d34dh0r53 | #link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=0 | 15:38 |
d34dh0r53 | as is keystonemiddleware | 15:38 |
d34dh0r53 | #link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=0 | 15:38 |
d34dh0r53 | pycadf is good | 15:38 |
d34dh0r53 | #link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=0 | 15:38 |
d34dh0r53 | so is ldappool | 15:39 |
d34dh0r53 | #topic conclusion | 15:39 |
d34dh0r53 | That's all I have, thanks everyone! | 15:39 |
gtema | thks | 15:39 |
d34dh0r53 | #endmeeting | 15:39 |
opendevmeet | Meeting ended Wed Dec 4 15:39:39 2024 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:39 |
opendevmeet | Minutes: https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-12-04-15.04.html | 15:39 |
opendevmeet | Minutes (text): https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-12-04-15.04.txt | 15:39 |
opendevmeet | Log: https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-12-04-15.04.log.html | 15:39 |
opendevreview | Merged openstack/keystone master: Fix wsgi service name for the federation tests https://review.opendev.org/c/openstack/keystone/+/936721 | 17:07 |
opendevreview | Ghanshyam proposed openstack/oslo.policy master: DNM: testing gate https://review.opendev.org/c/openstack/oslo.policy/+/937062 | 19:35 |
gmann | dmendiza[m]: xek: can you check these two easy change https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/934272 https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/933470 | 19:45 |
*** elodilles is now known as elodilles_pto | 19:54 | |
opendevreview | Oria Weng proposed openstack/keystone master: Add JSON schema to `registered limits` https://review.opendev.org/c/openstack/keystone/+/937069 | 21:34 |
Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!