| frickler | xek: iiuc nothing will pass gate without https://review.opendev.org/c/openstack/keystone/+/989615 getting merged and backported | 05:14 |
|---|---|---|
| frickler | oh, well stable/2025.1 patches are green because the oidc job for some reason has been made non-voting there | 05:18 |
| opendevreview | Grzegorz Grasza proposed openstack/keystone stable/2025.2: Fix project policy allowing unauthorized access to root domains https://review.opendev.org/c/openstack/keystone/+/990614 | 08:55 |
| opendevreview | Grzegorz Grasza proposed openstack/keystone stable/2025.1: Fix project policy allowing unauthorized access to root domains https://review.opendev.org/c/openstack/keystone/+/990615 | 08:56 |
| opendevreview | Merged openstack/keystone master: Add audience mapper to devstack Keycloak client https://review.opendev.org/c/openstack/keystone/+/989615 | 09:21 |
| opendevreview | Artem Goncharov proposed openstack/keystone stable/2026.1: Add audience mapper to devstack Keycloak client https://review.opendev.org/c/openstack/keystone/+/990617 | 09:29 |
| opendevreview | Artem Goncharov proposed openstack/keystone stable/2025.2: Add audience mapper to devstack Keycloak client https://review.opendev.org/c/openstack/keystone/+/990618 | 09:30 |
| opendevreview | Dr. Jens Harbott proposed openstack/keystone stable/2025.1: Add audience mapper to devstack Keycloak client https://review.opendev.org/c/openstack/keystone/+/990621 | 09:56 |
| frickler | tobias-urdin: ^^ I get a merge-conflict when I try to cherry-pick ^^ into 2024.1, maybe you have time to look into that? | 10:02 |
| tobias-urdin | frickler: ack, thanks for notifying me about that one i will have a look but probably next week | 11:55 |
| frickler | gtema: xek: seems there are two more failing jobs for 2025.2, maybe missing some further backports? cf. https://review.opendev.org/c/openstack/keystone/+/990618 | 12:04 |
| blanson[m] | Hello guys. I'm currently working on some patch for kolla-ansible keystone deployment, and I'm wondering what would be the recommendations for rotating (if at all) credential encryption keys ? https://docs.openstack.org/keystone/latest/admin/credential-encryption.html does not mention rotation schedules, wo I'm wondering what could be a sane default ? | 12:26 |
| bbobrov | blanson[m]: i don't think there is a fit-for-all answer. I would apply the requirements of your ogranization on technical/service password rotation. | 12:38 |
| bbobrov | frickler: https://review.opendev.org/c/openstack/keystone/+/990631 | 12:39 |
| blanson[m] | bbobrov: that's not for my, that's for a sensitive default values for kolla-ansible. would it make sense to rotate at all by default ? or are we better off just not rotating by default, and letting the user decide maybe ? | 13:04 |
| blanson[m] | for my org* | 13:04 |
| bbobrov | blanson[m]: i'd go with letting the user decide with 14 days default. | 13:33 |
| opendevreview | Merged openstack/keystone stable/2026.1: Add audience mapper to devstack Keycloak client https://review.opendev.org/c/openstack/keystone/+/990617 | 14:57 |
| -opendevstatus- NOTICE: Gerrit will be restarted to pick up a bugfix in the replication plugin. You may notice a short outage of a few minutes. | 15:33 | |
| opendevreview | Mathieu Gagné proposed openstack/keystone master: Remove leading space from operation path user policy https://review.opendev.org/c/openstack/keystone/+/990574 | 16:10 |
| opendevreview | Merged openstack/keystone master: Enforce delegation project boundary for delegated tokens https://review.opendev.org/c/openstack/keystone/+/990485 | 17:34 |
| opendevreview | Merged openstack/keystone stable/2025.1: Temporarily make grenade non-voting https://review.opendev.org/c/openstack/keystone/+/990476 | 17:34 |
| opendevreview | Merged openstack/keystone stable/2025.1: Add audience mapper to devstack Keycloak client https://review.opendev.org/c/openstack/keystone/+/990621 | 17:35 |
| -opendevstatus- NOTICE: The Gerrit service on review.opendev.org will be offline again monentarily while we restart for a configuration adjustment, but should return to service within a few minutes | 19:09 | |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!