Wednesday, 2026-06-03

opendevreviewTakashi Kajinami proposed openstack/keystone-tempest-plugin master: Use enforce_scope option from tempest  https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/93082903:54
opendevreviewDouglas Mendizábal proposed openstack/keystone master: DNM: Test keystone gates with enforce_scope enabled  https://review.opendev.org/c/openstack/keystone/+/99127604:23
*** ykarel__ is now known as ykarel04:46
opendevreviewGrzegorz Grasza proposed openstack/keystone stable/2025.2: Fix stable/2025.2 CI: nodeset, test skip, Keycloak audience mapper  https://review.opendev.org/c/openstack/keystone/+/99061808:48
opendevreviewMerged openstack/keystone stable/2025.2: Fix stable/2025.2 CI: nodeset, test skip, Keycloak audience mapper  https://review.opendev.org/c/openstack/keystone/+/99061811:43
d34dh0r53#starmeeting keystone15:04
d34dh0r53Reminder: This meeting takes place under the OpenInfra Foundation Code of Conduct15:05
d34dh0r53#link https://openinfra.dev/legal/code-of-conduct15:05
d34dh0r53#topic roll call15:06
d34dh0r53admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann, zaitcev, reqa, dmendiza[m], dmendiza, mharley, jph, gtema, cardoe, deydra15:06
d34dh0r53dmendiza: o/15:06
dmendiza[m]🙋 15:06
gtemasemi- o/ - am sick today15:06
d34dh0r53feel better gtema :)15:07
gtemathks15:07
d34dh0r53#topic review past meeting work items15:08
d34dh0r53#link https://meetings.opendev.org/meetings/keystone/2026/keystone.2026-05-27-15.02.html15:08
d34dh0r53no action items from last week15:08
d34dh0r53#topic liaison updates15:08
d34dh0r53nothing from me15:08
d34dh0r53#topic specification Secure RBAC (dmendiza)15:09
d34dh0r53#link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_15:09
d34dh0r532026.1 Release Timeline15:09
d34dh0r53Update oslo.policy in keystone to enforce_new_defaults=True15:09
*** ralonsoh is now known as ralonsoh_ooo15:09
d34dh0r53Update oslo.policy in keystone to enforce_scope=True15:09
d34dh0r53Devstack still defaults to enforce_scope = False https://opendev.org/openstack/devstack/src/branch/master/lib/keystone#L12015:09
dmendiza[m]Hey alright, actually did some work on this this week15:09
d34dh0r53Patch to default to true: https://review.opendev.org/c/openstack/devstack/+/95621015:09
d34dh0r53Fix config options in keystone-tempest-plugin https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/93082915:09
dmendiza[m]RIght, so we want devstack to stop turning off scope by default15:11
dmendiza[m]and that's what #956210 is about15:11
dmendiza[m]I had it as a WIP because I wanted to run the keystone gate first15:12
dmendiza[m]which I did here:15:12
dmendiza[m]#link https://review.opendev.org/c/openstack/keystone/+/99127615:12
dmendiza[m]OIDC gate job failed, but I think it's unrelated15:13
dmendiza[m]and the pep8 failed because of the bogus change I put in, so I think we should be good to go to get that change merged into devstack15:13
dmendiza[m]I'll remove the WIP and maybe get gmaan to go bend some elbows15:14
dmendiza[m]Related to SRBAC, there is a cleanup patch to remove a redundant option from tempest15:14
dmendiza[m]That's what #930829 is about15:14
dmendiza[m]and I see Dave Wilde (d34dh0r53) +2'd so I'll get that merged after this15:15
d34dh0r53Yeah, just looked at that one15:15
dmendiza[m]That's it for SRBAC this week15:15
gmaandmendiza[m]: ack15:15
d34dh0r53Thanks dmendiza 15:16
d34dh0r53#topic specification Secuirty Compliance Testing (dmendiza)15:16
d34dh0r53#link https://review.opendev.org/c/openstack/devstack/+/95796915:16
dmendiza[m]No updates on this one15:18
d34dh0r53cool, thanks15:18
d34dh0r53#topic keystone-rs15:18
d34dh0r53#link https://github.com/openstack-experimental/keystone15:18
gtemaI have finished work on the context. Now there is support for is_admin and "service"15:18
d34dh0r53cool15:18
gtemawith this and the admin inteface over the unix socket I am now working on bootstrap15:18
gtemaand bootstrap uses the normal API to provision entities15:18
gtemaand the policy now has a real "is_admin" support without any tweaks - absolutely native15:19
gtemawhich is what is used now to bootstrap the keystone15:19
gtemaboth admin and service rely on spiffe for mtls15:19
gtemaso internal interface and admin interface (over UDS) both support mTLS natively15:20
gtemathe whole work is necessary to provide an easier way to run API tests with real keystone running. Till now the test is running in k8 with python and rust keystones together, but I work now exactly on adding bootstrap so that the API test can be started easily without dependencies15:21
gtemathat's it this week15:21
d34dh0r53cool, thanks gtema 15:22
d34dh0r53#topic open discussion15:22
d34dh0r53There is one topic15:23
d34dh0r53#link https://review.opendev.org/c/openstack/keystone-specs/+/98399315:23
gtemathis is still the old one - should be deleted. I am looking into it and have some comments that I didn't finish posting yet15:23
gtemabut I also have some other ideas how something similar could be achieved in a more natural way (or better to say future-proof)15:24
d34dh0r53avk15:24
d34dh0r53ack15:24
d34dh0r53anything else for open discussion?15:25
d34dh0r53cool, moving on15:26
d34dh0r53#topic bug review15:26
d34dh0r53#link https://bugs.launchpad.net/keystone/?orderby=-id&start=015:26
d34dh0r53There are a couple of new bugs in Keystone15:26
d34dh0r533 actually15:27
d34dh0r53#link https://bugs.launchpad.net/keystone/+bug/215462915:27
d34dh0r53That looks like a pretty straightforward race condition and a fix in progress15:29
d34dh0r53next up15:29
d34dh0r53#link https://bugs.launchpad.net/keystone/+bug/215466615:29
d34dh0r53Good catch, and there is a fix in progress15:30
d34dh0r53next up15:30
d34dh0r53#link https://bugs.launchpad.net/keystone/+bug/215480815:30
d34dh0r53Also a good catch, with a fix in progress, thanks bbobrov 15:30
d34dh0r53that's it for Keystone, moving on15:31
d34dh0r53#link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=015:31
d34dh0r53nothing new here15:31
d34dh0r53#link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=015:31
d34dh0r53nothing new in keystoneauth either15:31
d34dh0r53#link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=015:31
d34dh0r53keystonemiddleware is good15:32
d34dh0r53#link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=015:32
d34dh0r53no new pycadf bugs15:32
d34dh0r53#link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=015:32
d34dh0r53nor any new ldappool bugs15:32
d34dh0r53#topic conclusion15:32
d34dh0r53That's it from me, thanks all!15:33
d34dh0r53#endmeeting15:33
gtemathks Dave Wilde (d34dh0r53) 15:33
opendevreviewAde Lee proposed openstack/keystone-specs master: spec: Add soft delete for projects, users, and domains  https://review.opendev.org/c/openstack/keystone-specs/+/99148918:37

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!