Wednesday, 2025-02-12

*** mhen_ is now known as mhen02:50
opendevreviewYaguang Tang proposed openstack/keystoneauth master: fix: correct oidc request error handling logic  https://review.opendev.org/c/openstack/keystoneauth/+/94120303:27
opendevreviewYaguang Tang proposed openstack/keystoneauth master: fix: correct oidc request error handling logic  https://review.opendev.org/c/openstack/keystoneauth/+/94120304:30
opendevreviewYaguang Tang proposed openstack/keystoneauth master: fix: correct oidc request error handling logic  https://review.opendev.org/c/openstack/keystoneauth/+/94120306:07
opendevreviewYaguang Tang proposed openstack/keystoneauth master: fix: correct oidc request error handling logic  https://review.opendev.org/c/openstack/keystoneauth/+/94120306:38
opendevreviewYaguang Tang proposed openstack/keystoneauth master: fix: correct oidc request error handling logic  https://review.opendev.org/c/openstack/keystoneauth/+/94120307:19
opendevreviewYaguang Tang proposed openstack/keystoneauth master: fix: correct oidc request error handling logic  https://review.opendev.org/c/openstack/keystoneauth/+/94120308:19
opendevreviewYaguang Tang proposed openstack/keystoneauth master: fix: correct oidc request error handling logic  https://review.opendev.org/c/openstack/keystoneauth/+/94120308:51
opendevreviewYaguang Tang proposed openstack/keystoneauth master: fix: correct oidc request error handling logic  https://review.opendev.org/c/openstack/keystoneauth/+/94120309:53
opendevreviewYaguang Tang proposed openstack/keystoneauth master: fix: correct oidc request error handling logic  https://review.opendev.org/c/openstack/keystoneauth/+/94120310:07
opendevreviewGrzegorz Grasza proposed openstack/keystoneauth master: [WiP] External OAuth2.0 plugin  https://review.opendev.org/c/openstack/keystoneauth/+/94108211:13
d34dh0r53#startmeeting keystone15:06
opendevmeetMeeting started Wed Feb 12 15:06:06 2025 UTC and is due to finish in 60 minutes.  The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot.15:06
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:06
opendevmeetThe meeting name has been set to 'keystone'15:06
d34dh0r53Reminder: This meeting takes place under the OpenInfra Foundation Code of Conduct15:07
d34dh0r53#link https://openinfra.dev/legal/code-of-conduct15:07
d34dh0r53#topic roll call15:07
gtemao/15:07
d34dh0r53admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann, zaitcev, reqa, dmendiza[m], dmendiza, mharley, jph, gtema, cardoe, deydra15:07
d34dh0r53dmendiza 15:07
d34dh0r53o/15:07
d34dh0r53#topic review past meeting work items15:10
d34dh0r53#link https://meetings.opendev.org/meetings/keystone/2025/keystone.2025-02-05-15.01.html15:10
d34dh0r53no action items from our last meeting15:10
d34dh0r53#topic liaison updates15:10
d34dh0r53nothing from VMT or releases15:10
d34dh0r53#topic specification OAuth 2.0 (hiromu)15:11
d34dh0r53#link https://review.opendev.org/q/topic:bp%252Foauth2-client-credentials-ext15:12
d34dh0r53#link https://review.opendev.org/q/topic:bp%252Fenhance-oauth2-interoperability15:12
d34dh0r53External OAuth 2.0 Specification15:12
d34dh0r53#link https://review.opendev.org/c/openstack/keystone-specs/+/861554 (merged)15:12
d34dh0r53OAuth 2.0 Implementation15:12
d34dh0r53#link https://review.opendev.org/q/topic:bp%252Fsupport-oauth2-mtls (merged)15:12
d34dh0r53OAuth 2.0 Documentation15:12
d34dh0r53#link https://review.opendev.org/c/openstack/keystone/+/838108 (merged)15:12
d34dh0r53#link https://review.opendev.org/c/openstack/keystoneauth/+/838104 (merged)15:12
d34dh0r53no updates from me this week15:12
gtemanot directly related to that in particular, I started writing down ideas around oauth2/oidc/federation in https://gtema.github.io/posts/rethinking-openstack-auth-authz/15:13
d34dh0r53oh cool, I'll give it a read15:13
gtemaI touched that aspect as well. I think generally idea with adding support for oauth2 for external auth is good, but not in that implementation - we need to flip it around and make keystone issue jwt that can be checked by middleware15:14
gtemaanyway - it is a working draft with many topics around 15:14
d34dh0r53thanks gtema 15:15
d34dh0r53#topic specification Secure RBAC (dmendiza[m])15:15
d34dh0r53#link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_15:15
d34dh0r532024.1 Release Timeline15:15
d34dh0r53Update oslo.policy in keystone to enforce_new_defaults=True15:15
d34dh0r53Update oslo.policy in keystone to enforce_scope=True15:15
d34dh0r53dmendiza: are you around?15:15
d34dh0r53guess not15:17
d34dh0r53moving on15:17
d34dh0r53#topic specification OpenAPI support (gtema)15:17
d34dh0r53#link https://review.opendev.org/q/topic:%22openapi%22+project:openstack/keystone15:17
gtemanot much from me this week. I finally got permissions on openstackdocstheme so that I can go on making api-ref builds15:18
gtemaother then that few changes are hanging around (I guess) from our intern. Will look later this week15:18
dmendiza[m]🙋15:19
d34dh0r53ohai dmendiza !15:19
d34dh0r53any updates on SRBAC dmendiza ?15:21
dmendiza[m]Negative.15:21
dmendiza[m]I think there's a pop-up meeting scheduled today.  Not sure if it'll actually happen.15:22
d34dh0r53ack, thank you15:23
d34dh0r53and thanks gtema let us know if/when there are more openapi things to review15:23
d34dh0r53moving on15:23
d34dh0r53'v15:24
d34dh0r53#topic specification domain manager (mhen)15:24
d34dh0r53still unmerged are:15:24
d34dh0r53documentation: https://review.opendev.org/c/openstack/keystone/+/92813515:24
d34dh0r53tempest tests: https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/92422215:24
d34dh0r53dmendiza: can you take a look at those?15:24
dmendiza[m]ack, yeah, sorry, I've been slacking on gerrit reveiws15:24
d34dh0r53no worries15:27
d34dh0r53#topic specification Include bad password details in audit messages (stanislav-z)15:27
d34dh0r53#link https://review.opendev.org/c/openstack/keystone-specs/+/915482 (merged)15:27
d34dh0r53#link https://review.opendev.org/q/topic:%22pci-dss-invalid-password-reporting%2215:27
d34dh0r53#link https://review.opendev.org/c/openstack/keystone/+/93242315:27
d34dh0r535-Feb update: implementation to be updated to reflect merged spec state (WIP by @stanislav-z)15:27
stanislav-zhi, no updates so far - didn't find the time yet to bring it to a proper state. will try in the following days/week15:28
d34dh0r53ack, thank you Stanislav Zaprudskiy 15:29
d34dh0r53#topic open discussion15:29
d34dh0r53nothing from me15:29
gtemai don't have anything either15:29
d34dh0r53ack, moving on15:29
d34dh0r53#topic bug review15:29
d34dh0r53#link https://bugs.launchpad.net/keystone/?orderby=-id&start=015:29
d34dh0r53one new bug in keystone15:30
d34dh0r53#link https://bugs.launchpad.net/keystone/+bug/209755015:30
d34dh0r53we have quite a bit of flask-restful it looks like15:32
gtemajfyi: I am currently working on "reimplementing" keystone in rust. We could actually combine this with addressing flask. I know how it sounds, so just fyi15:33
d34dh0r53:) it may be the catalyst we need15:34
d34dh0r53thanks gtema 15:34
d34dh0r53#link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=015:34
d34dh0r53no new bugs in python-keystoneclient15:35
d34dh0r53#link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=015:35
d34dh0r53keystoneauth has no new bugs15:35
d34dh0r53#link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=015:35
d34dh0r53and keystonemiddleware is clean too15:35
d34dh0r53#link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=015:35
d34dh0r53nothing new in pycadf15:36
d34dh0r53#link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=015:36
d34dh0r53nor in ldappool15:36
d34dh0r53#topic conclusion15:36
d34dh0r53nothing from me today, thanks everyone15:36
gtemathks Dave15:36
d34dh0r53#endmeeting15:38
opendevmeetMeeting ended Wed Feb 12 15:38:17 2025 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:38
opendevmeetMinutes:        https://meetings.opendev.org/meetings/keystone/2025/keystone.2025-02-12-15.06.html15:38
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/keystone/2025/keystone.2025-02-12-15.06.txt15:38
opendevmeetLog:            https://meetings.opendev.org/meetings/keystone/2025/keystone.2025-02-12-15.06.log.html15:38

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!