| opendevreview | Boris Bobrov proposed openstack/keystone master: Update last_active_at on app cred auth https://review.opendev.org/c/openstack/keystone/+/982029 | 00:28 |
|---|---|---|
| opendevreview | Boris Bobrov proposed openstack/keystone master: Update last_active_at on app cred auth https://review.opendev.org/c/openstack/keystone/+/979763 | 00:30 |
| opendevreview | OpenStack Proposal Bot proposed openstack/keystone master: Imported Translations from Zanata https://review.opendev.org/c/openstack/keystone/+/977563 | 04:17 |
| *** zseguin_ is now known as zseguin | 06:11 | |
| d34dh0r53 | #startmeeting keystone | 15:04 |
| opendevmeet | Meeting started Wed Mar 25 15:04:15 2026 UTC and is due to finish in 60 minutes. The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:04 |
| opendevmeet | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:04 |
| opendevmeet | The meeting name has been set to 'keystone' | 15:04 |
| d34dh0r53 | Reminder: This meeting takes place under the OpenInfra Foundation Code of Conduct | 15:05 |
| d34dh0r53 | #link https://openinfra.dev/legal/code-of-conduct | 15:05 |
| d34dh0r53 | #topic roll call | 15:05 |
| d34dh0r53 | admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann, zaitcev, reqa, dmendiza[m], dmendiza, mharley, jph, gtema, cardoe, deydra | 15:05 |
| d34dh0r53 | #topic review past meeting work items | 15:05 |
| d34dh0r53 | #undo | 15:05 |
| opendevmeet | Removing item from minutes: #topic review past meeting work items | 15:05 |
| d34dh0r53 | sorry, I'll leave some time for roll call | 15:06 |
| d34dh0r53 | dmendiza 👋 | 15:06 |
| dmendiza[m] | 🙋 | 15:07 |
| xek | o/ | 15:08 |
| gtema | o/ | 15:08 |
| d34dh0r53 | hi all :) | 15:09 |
| d34dh0r53 | #topic review past meeting work items | 15:09 |
| d34dh0r53 | #link https://meetings.opendev.org/meetings/keystone/2026/keystone.2026-03-18-15.27.html | 15:09 |
| d34dh0r53 | no action items from last week | 15:09 |
| d34dh0r53 | #topic liaison updates | 15:09 |
| d34dh0r53 | nothing from me | 15:09 |
| gtema | neither from me | 15:09 |
| d34dh0r53 | #topic specification Secure RBAC (dmendiza) | 15:10 |
| d34dh0r53 | #link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_ | 15:10 |
| d34dh0r53 | 2026.1 Release Timeline | 15:10 |
| d34dh0r53 | Update oslo.policy in keystone to enforce_new_defaults=True | 15:10 |
| d34dh0r53 | Update oslo.policy in keystone to enforce_scope=True | 15:10 |
| dmendiza[m] | Not a whole lot of progress still... maybe we can make this a priority for HIbiscus? | 15:14 |
| dmendiza[m] | IIRC, gmaan was saying we should just burn it all to the ground and start over, lol | 15:15 |
| gtema | sounds great. With a statement like that I am for it - in the sense of saying the secure RBAC is wrong ;-) | 15:16 |
| d34dh0r53 | lol | 15:17 |
| d34dh0r53 | SSRBAC the first S is for Super | 15:17 |
| gtema | neah, I rather say - go for the OpenPolicyAgent reimplementation for openstack with the policy agent talking directly to keystone to ask for necessary data | 15:18 |
| gtema | links to my zero-trust concept | 15:18 |
| dmendiza[m] | 💯 OPA would be awesome | 15:19 |
| dmendiza[m] | but let's at least get rid of the legacy pre-SRBAC policies | 15:19 |
| gtema | yeah | 15:19 |
| d34dh0r53 | indeed, PTG topic for H? | 15:20 |
| gtema | let's do | 15:20 |
| d34dh0r53 | #link https://etherpad.opendev.org/p/apr2026-ptg-keystone | 15:21 |
| dmendiza[m] | Yeah, do we have an etherpad for the PTG yet? | 15:21 |
| d34dh0r53 | btw | 15:21 |
| dmendiza[m] | ha, beat me to it | 15:21 |
| gtema | I am lost in all those letters, so for me they mean nothing | 15:21 |
| dmendiza[m] | lol, PTG=Project Teams Gathering | 15:22 |
| dmendiza[m] | H=Hibiscus cycle | 15:22 |
| d34dh0r53 | btw = by the way | 15:22 |
| d34dh0r53 | moving on | 15:22 |
| d34dh0r53 | #topic specification Secuirty Compliance Testing (dmendiza) | 15:22 |
| gtema | are you trolling me? | 15:22 |
| d34dh0r53 | #link https://review.opendev.org/c/openstack/devstack/+/957969 | 15:22 |
| d34dh0r53 | gtema: yes | 15:23 |
| d34dh0r53 | :) | 15:23 |
| dmendiza[m] | XD | 15:24 |
| d34dh0r53 | any updates on compliance testing dmendiza ? | 15:26 |
| dmendiza[m] | Nope, I need to sync with MIlana at some point to see if she's still going to work on this? | 15:27 |
| d34dh0r53 | ack, thanks | 15:28 |
| d34dh0r53 | #topic keystone-rs | 15:28 |
| d34dh0r53 | #link https://github.com/openstack-experimental/keystone | 15:28 |
| gtema | I spent one week of work, multiple kWh of energy to save some Wh of energy during compilation of the rs (bringing it down from 2min to 1min) | 15:29 |
| gtema | it costed me quote some gray hairs | 15:29 |
| gtema | but now it it going much better and the laptop is not causing burn to the body | 15:31 |
| d34dh0r53 | :) awesome | 15:31 |
| gtema | there was also a distraction caused by openapi-core python package update that broke codegenerator and while fixiing it I spotted few issues crawled while it was not very nit-picky | 15:31 |
| gtema | anyway - now I am back at implementing mTLS | 15:31 |
| gtema | I promise | 15:31 |
| gtema | :) | 15:31 |
| gtema | last week and this week was deep into the profiling compiler - it is not a fun | 15:32 |
| gtema | that's it on the topic this week | 15:33 |
| d34dh0r53 | 👍️ | 15:36 |
| d34dh0r53 | #topic open discussion | 15:36 |
| gtema | I do not have anything | 15:39 |
| d34dh0r53 | cool, moving on | 15:39 |
| d34dh0r53 | 'v | 15:39 |
| d34dh0r53 | #topic bug review | 15:39 |
| d34dh0r53 | #link https://bugs.launchpad.net/keystone/?orderby=-id&start=0 | 15:39 |
| d34dh0r53 | no new bugs for keystone | 15:39 |
| d34dh0r53 | #link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=0 | 15:40 |
| d34dh0r53 | nothing new for python-keystoneclient either | 15:40 |
| d34dh0r53 | #link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=0 | 15:40 |
| d34dh0r53 | keystoneauth is good | 15:40 |
| d34dh0r53 | #link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=0 | 15:40 |
| d34dh0r53 | so is keystonemiddleware | 15:41 |
| d34dh0r53 | #link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=0 | 15:41 |
| d34dh0r53 | no new bugs in pycadf | 15:41 |
| d34dh0r53 | #link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=0 | 15:41 |
| d34dh0r53 | It looks like there was a bug in ldappool last week that I missed | 15:42 |
| d34dh0r53 | bbobrov_ is working on it | 15:43 |
| d34dh0r53 | #link https://bugs.launchpad.net/ldappool/+bug/2144440 | 15:43 |
| d34dh0r53 | #topic conclusion | 15:44 |
| d34dh0r53 | Thanks folks, PTG etherpad is up if you want to add anything | 15:44 |
| d34dh0r53 | #link https://etherpad.opendev.org/p/apr2026-ptg-keystone | 15:44 |
| gtema | yupp, thanks Dave | 15:45 |
| d34dh0r53 | #endmeeting | 15:46 |
| opendevmeet | Meeting ended Wed Mar 25 15:46:17 2026 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:46 |
| opendevmeet | Minutes: https://meetings.opendev.org/meetings/keystone/2026/keystone.2026-03-25-15.04.html | 15:46 |
| opendevmeet | Minutes (text): https://meetings.opendev.org/meetings/keystone/2026/keystone.2026-03-25-15.04.txt | 15:46 |
| opendevmeet | Log: https://meetings.opendev.org/meetings/keystone/2026/keystone.2026-03-25-15.04.log.html | 15:46 |
| opendevreview | Harry Kominos proposed openstack/keystone master: [doc] Amend IDP list-idp example https://review.opendev.org/c/openstack/keystone/+/979910 | 17:31 |
| opendevreview | Boris Bobrov proposed openstack/keystone master: Block app credential token rescoping https://review.opendev.org/c/openstack/keystone/+/982171 | 22:04 |
| opendevreview | Boris Bobrov proposed openstack/keystone master: Include system scope in rescope guard https://review.opendev.org/c/openstack/keystone/+/982172 | 22:04 |
| opendevreview | Boris Bobrov proposed openstack/keystone master: Block app credential token rescoping https://review.opendev.org/c/openstack/keystone/+/982171 | 22:05 |
| opendevreview | Boris Bobrov proposed openstack/keystone master: Include system scope in rescope guard https://review.opendev.org/c/openstack/keystone/+/982172 | 22:05 |
| opendevreview | Boris Bobrov proposed openstack/keystone master: Block app credential token rescoping https://review.opendev.org/c/openstack/keystone/+/982171 | 22:39 |
| opendevreview | Boris Bobrov proposed openstack/keystone master: Include system scope in rescope guard https://review.opendev.org/c/openstack/keystone/+/982172 | 22:39 |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!