Wednesday, 2025-08-27

*** mhen_ is now known as mhen01:17
opendevreviewArtem Goncharov proposed openstack/keystone stable/2025.1: Ignore typing on the single import  https://review.opendev.org/c/openstack/keystone/+/95866514:51
d34dh0r53#startmeeting keystone15:04
opendevmeetMeeting started Wed Aug 27 15:04:20 2025 UTC and is due to finish in 60 minutes.  The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot.15:04
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:04
opendevmeetThe meeting name has been set to 'keystone'15:04
d34dh0r53Reminder: This meeting takes place under the OpenInfra Foundation Code of Conduct15:04
d34dh0r53#link https://openinfra.dev/legal/code-of-conduct15:04
d34dh0r53#topic roll call15:04
gtemao/15:04
d34dh0r53admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann, zaitcev, reqa, dmendiza[m], dmendiza, mharley, jph, gtema, cardoe, deydra15:04
d34dh0r53dmendiza: o/15:04
xeko/15:05
dmendiza[m]🙋‍♂️15:05
d34dh0r53hi all15:06
d34dh0r53#topic review past meeting work items15:06
d34dh0r53#link https://meetings.opendev.org/meetings/keystone/2025/keystone.2025-08-20-15.02.html15:06
d34dh0r53we have one, which I haven't got to yet15:06
d34dh0r53dwilde/gtema add PTG topic about service account15:06
gtemaand I found i my personal notes that we already talked about that last PTG15:07
gtema:)15:07
d34dh0r53ahh, I do recall that15:07
gtemabut we should do this again and agree. I will definitely implement some poc in the Rust side15:08
d34dh0r53yeah, agreed15:08
d34dh0r53#action dwilde/gtema add PTG topic about service account15:09
d34dh0r53#topic liaison updates15:09
gtemanothing from me15:09
d34dh0r53nor me15:09
d34dh0r53#topic specification OAuth 2.0 (hiromu)15:10
d34dh0r53#link https://review.opendev.org/q/topic:bp%252Foauth2-client-credentials-ext15:10
d34dh0r53#link https://review.opendev.org/q/topic:bp%252Fenhance-oauth2-interoperability15:10
d34dh0r53no updates from me on this one15:10
d34dh0r53#topic specification Secure RBAC (dmendiza)15:10
d34dh0r53#link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_15:10
d34dh0r532025.2 Release Timeline15:11
d34dh0r53Update oslo.policy in keystone to enforce_new_defaults=True15:11
d34dh0r53Update oslo.policy in keystone to enforce_scope=True15:11
dmendiza[m]No updates this week, still haven't had a chance to look into the failures in the devstack patch15:12
d34dh0r53ack, thanks dmendiza 15:12
d34dh0r53#topic specification OpenAPI support (gtema)15:12
d34dh0r53#link https://review.opendev.org/q/topic:%22openapi%22+project:openstack/keystone15:12
gtemamaybe only a fix that was mentioned last week15:13
gtemahttps://review.opendev.org/c/openstack/keystone/+/95754715:13
gtemaone +2 and +W remaining15:13
d34dh0r53I can take a look today15:14
gtemacool, thks15:14
gtemanothing else this week, busy also on other fronts15:14
d34dh0r53thanks gtema 15:14
d34dh0r53#topic open discussion15:15
d34dh0r53drencrom15:15
d34dh0r53Patch proposal: https://review.opendev.org/c/openstack/keystone/+/95179215:15
d34dh0r53Dependent bugs have been merged, needs a workflow vote15:15
gtemadone15:15
d34dh0r53beat me to it :)15:15
d34dh0r53thanks drencrom 15:15
d34dh0r53#topic bug review15:16
d34dh0r53#link https://bugs.launchpad.net/keystone/?orderby=-id&start=015:16
d34dh0r53looks like on new bug in keystone that is already being worked15:17
d34dh0r53#link https://bugs.launchpad.net/keystone/+bug/212115215:17
dmendiza[m]🙋‍♂️15:17
dmendiza[m]I need to add the regex thing to the agenda15:17
d34dh0r53okay, go ahead dmendiza 15:18
d34dh0r53#topic password regex testing15:18
dmendiza[m]I added a second patch as an alternative to the first one: 15:18
dmendiza[m]#link https://review.opendev.org/c/openstack/devstack/+/95796915:18
dmendiza[m]The main point of this patch is to change KEYSTONE_SECURITY_COMPLIANCE_ENABLED=False by default15:18
dmendiza[m]it makes things much easier, since we don't have to worry about every single devstack job out there having it turned on.15:19
dmendiza[m]It seems Sean Mooney is on board, but gmaan may need some convincing.15:19
dmendiza[m]It also adds a job to set it to True to test it, and we can override passwords just in that new job15:20
dmendiza[m]I will iterate on this to move the job into the Keystone repo instead of having it in devstack.15:20
d34dh0r53Seems like a good compromise to me15:22
dmendiza[m]Yeah, if folks really want that enabled they can then opt-in and override passwords as necessary15:23
dmendiza[m]and we can still use a complex regex for testing15:23
dmendiza[m]That's it for this week on this topic15:24
dmendiza[m]I'll get it added to the agenda for next week.15:24
d34dh0r53Thanks dmendiza 15:24
d34dh0r53back to bug review15:24
d34dh0r53#topic bug review15:25
d34dh0r53#link https://bugs.launchpad.net/keystone/?orderby=-id&start=015:25
d34dh0r53like I said there is one bug that's already being worked15:25
d34dh0r53#link https://bugs.launchpad.net/keystone/+bug/212115215:25
d34dh0r53I'll review the patch today15:27
d34dh0r53that's it for keystone15:27
d34dh0r53#link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=015:27
d34dh0r53no new bugs in python-keystoneclient15:28
d34dh0r53#link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=015:28
d34dh0r53keystoneauth is good15:28
d34dh0r53#link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=015:28
d34dh0r53all clear or keystonemiddleware15:29
d34dh0r53#link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=015:29
d34dh0r53pycadf has no new bugs15:29
d34dh0r53#link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=015:29
d34dh0r53nor does ldappool15:29
d34dh0r53#topic conclusion15:29
d34dh0r53nothing else from me15:29
gtemahttps://review.opendev.org/c/openstack/keystone/+/958665 is gate unblocker for 2025.115:30
gtemaoneliner15:30
d34dh0r53thanks gtema , +2 from me15:30
gtemathks15:30
d34dh0r53dmendiza, Grzegorz Grasza mind reviewing as well?15:31
dmendiza[m]Ack 15:32
d34dh0r53thanks!15:32
d34dh0r53#endmeeting15:32
opendevmeetMeeting ended Wed Aug 27 15:32:23 2025 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:32
opendevmeetMinutes:        https://meetings.opendev.org/meetings/keystone/2025/keystone.2025-08-27-15.04.html15:32
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/keystone/2025/keystone.2025-08-27-15.04.txt15:32
opendevmeetLog:            https://meetings.opendev.org/meetings/keystone/2025/keystone.2025-08-27-15.04.log.html15:32
gtemathks guys, have a nice day15:33
gmaandmendiza[m]: ack, I will check it again. did not look into the sean reply16:57
opendevreviewMerged openstack/keystone master: Fix AD nested groups issues  https://review.opendev.org/c/openstack/keystone/+/95179219:14

Generated by irclog2html.py 4.0.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!