Wednesday, 2026-07-22

opendevreviewDouglas Mendizábal proposed openstack/keystone-specs master: spec: Explicit IDs for users  https://review.opendev.org/c/openstack/keystone-specs/+/99824202:33
d34dh0r53#startmeeting keystone15:01
opendevmeetMeeting started Wed Jul 22 15:01:27 2026 UTC and is due to finish in 60 minutes.  The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot.15:01
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:01
opendevmeetThe meeting name has been set to 'keystone'15:01
d34dh0r53Reminder: This meeting takes place under the OpenInfra Foundation Code of Conduct15:01
d34dh0r53#link https://openinfra.dev/legal/code-of-conduct15:01
d34dh0r53#topic roll call15:01
d34dh0r53admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann, zaitcev, reqa, dmendiza[m], dmendiza, mharley, jph, gtema, cardoe, deydra15:01
gtemao/15:01
d34dh0r53dmendiza: o/15:01
moutazchaara[m]o/15:02
dmendiza[m]🙋 15:04
d34dh0r53#topic review past meeting work items15:04
d34dh0r53#link https://meetings.opendev.org/meetings/keystone/2026/keystone.2026-07-15-15.02.html15:04
d34dh0r53One action item for me: dwilde plan mid-cycle keystone virtual meetup15:05
d34dh0r53I'll get to that soon, but this week is crazy15:05
d34dh0r53#action dwilde plan mid-cycle keystone virtual meetup15:05
d34dh0r53nothing else to review15:05
d34dh0r53#topic liaison updates15:05
gtemanothing from me15:06
d34dh0r53nor me15:06
d34dh0r53#topic specification Secure RBAC (dmendiza)15:06
d34dh0r53#link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_15:06
d34dh0r532026.1 Release Timeline15:06
d34dh0r53Update oslo.policy in keystone to enforce_new_defaults=True15:06
d34dh0r53Update oslo.policy in keystone to enforce_scope=True15:07
d34dh0r53Fix config options in keystone-tempest-plugin https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/93082915:07
gtemashould we just press +W on this change?15:07
dmendiza[m]I don't have any RBAC updates this week15:07
gtemaI was confused by the amount of different changes not sure which ones are actually valid15:08
d34dh0r53I'm good with +W on that one15:08
gtemadone15:09
d34dh0r53👍️15:09
d34dh0r53next up15:09
d34dh0r53#topic specification Secuirty Compliance Testing (dmendiza)15:10
d34dh0r53#link https://review.opendev.org/c/openstack/devstack/+/95796915:10
dmendiza[m]🦗🦗🦗15:10
gtemalooool15:10
d34dh0r53hahaha15:10
gtemanot sure how that looks in pure IRC though15:10
dmendiza[m]I only use Unicode emoji 😜15:11
dmendiza[m]But, yeah, I will eventually get back to this15:11
dmendiza[m]just hasn't been a priority lately15:11
d34dh0r53lol, thanks dmendiza 15:12
d34dh0r53#topic specification User Specified Project/User UUIDs (dmendize, alee)15:12
d34dh0r53https://review.opendev.org/c/openstack/keystone-specs/+/99732015:12
dmendiza[m]I saw gtema reviewed it, will address the comments in the next patch15:13
d34dh0r53cool15:13
dmendiza[m]I also uploaded the users side of the split15:13
dmendiza[m]#link https://review.opendev.org/c/openstack/keystone-specs/+/99824215:13
gtemait's so funny - split of 1500 loc spec results in 2x1000loc15:14
d34dh0r53efficiency15:14
d34dh0r53#topic keystone-rs15:15
d34dh0r53#link https://github.com/openstack-experimental/keystone15:15
gtema1) finished implementing oauth2 OP role - now federation with keycloak and so on becomes unnecessary ;-)15:15
gtemaespecially with SCIM the Keystone can now fully take over the central IAM role in the cloud15:16
gtema2. finished devstack plugin - in ci I test deployment of keystone-rs within devstack with running tempest tests15:16
gtemahere it is deployed as the only keystone and not side-by-side, but this can be added when desired15:17
gtema3. now chasing the tempest issues - right now 30% are passing15:17
gtemaactually I am now pretty much finished with big features and focus on polishing/testing/deployment/operations15:18
d34dh0r53very cool15:18
gtemathat's it for now15:18
d34dh0r53thanks gtema 15:19
d34dh0r53#topic open discussion15:19
d34dh0r53cool, guess there's nothing today15:22
d34dh0r53next up15:22
d34dh0r53#topic bug review15:22
d34dh0r53#link https://bugs.launchpad.net/keystone/?orderby=-id&start=015:22
d34dh0r53two new keystone bugs15:23
d34dh0r53#link https://bugs.launchpad.net/keystone/+bug/216110315:23
moutazchaara[m]Yes for the one #2161103, we discovered the bug. 15:24
moutazchaara[m]and it is mainly because of the marker passed to ldap15:24
moutazchaara[m]i attached the patch to it. the whole flow is currently broken. 15:25
gtemaI am not sure that will realy work - I have not found any way to have a proper pagination across keystone and ldap. You can't simply "skip" x entries to fetch next page15:26
moutazchaara[m]i can confirm that the patch worked on the local/qa environment. but it can be the case that i forgot some edge cases with this ldap pagination it is quite tricky15:28
gtemaldap can only paginate within one client session, and this session is between keystone and ldap and not keystone client and ldap15:29
moutazchaara[m]i noticed three things actually:... (full message at <https://matrix.org/oftc/media/v1/media/download/AXAW5v4OlOzBExGrNXwpfKtA4uQMEvw7UQijYvd0t9CPC7WBdwC1RkpFEPB5QiSG0zc32b3_QmhIsNrzm8se-5NCef0oxsHQAG1hdHJpeC5vcmcvVk5JcVpMcURiU29sZ0p0VU5QUU5LYk1u>)15:30
gtemawhen keystone handover first page it "closes" the session. The client only gets the marker. You can't map the marker down to number of entries fetched15:31
moutazchaara[m]yes, and that was the answer for "why not use LDAP's native cursor?" in my head15:31
gtemabecause you can't keep the session alive and you need to embed the cursor info into the client response - which breaks current pagination15:32
moutazchaara[m]yes, it is not like the others providers. you have to get the userID and starrt from there. so it is not a position 15:33
gtemacorrect15:33
moutazchaara[m]that's why in the patch the olnly option was to get full fetch + client-side slice.15:34
d34dh0r53let's move on for the sake of time15:34
d34dh0r53that was a good discussion, maybe move it to the patch/bug15:34
d34dh0r53next keystone bug15:35
d34dh0r53#link https://bugs.launchpad.net/keystone/+bug/216150815:35
d34dh0r53thoughts dmendiza ?15:37
gtemaI would agree with the bug statement15:38
d34dh0r53as would I15:38
d34dh0r53I'll let dmendiza know about that one15:40
d34dh0r53that does it for keystone bugs15:41
d34dh0r53#link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=015:41
d34dh0r53nothing new here15:41
d34dh0r53#link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=015:41
d34dh0r53keystoneauth is good15:41
d34dh0r53#link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=015:41
d34dh0r53so is keystonemiddleware15:41
d34dh0r53#link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=015:42
d34dh0r53nothing new in pycadf15:42
d34dh0r53#link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=015:42
d34dh0r53nor ldappool15:42
d34dh0r53#topic conclusion15:42
d34dh0r53Thanks folks! I'll let you know about the midcycle15:42
gtemathanks guys15:42
d34dh0r53#endmeeting15:43
opendevmeetMeeting ended Wed Jul 22 15:43:09 2026 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:43
opendevmeetMinutes:        https://meetings.opendev.org/meetings/keystone/2026/keystone.2026-07-22-15.01.html15:43
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/keystone/2026/keystone.2026-07-22-15.01.txt15:43
opendevmeetLog:            https://meetings.opendev.org/meetings/keystone/2026/keystone.2026-07-22-15.01.log.html15:43
moutazchaara[m]thanks all, gtema would be great if you take a look at the patch and let me know your thoughts :) 15:43
gtemayes, I will15:44
opendevreviewMoutaz Chaara proposed openstack/keystone master: Fix LDAP marker pagination always returning first page  https://review.opendev.org/c/openstack/keystone/+/99772416:02
opendevreviewTakashi Kajinami proposed openstack/keystone-tempest-plugin master: Add minimum pyproject.toml to support pip 23.1  https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/99833516:18
tkajinam^^^ it seems we need ^^ to fix k-t-p gate job.16:19
tkajinamgtema, I wonder if you will merge https://review.opendev.org/c/openstack/keystonemiddleware/+/995705 soon to unblock keystonemiddleware CI ?16:19
gtemadone16:21
tkajinamthanks !16:21
opendevreviewMerged openstack/keystonemiddleware master: Replace deprecated `timeutils.set_time_override`  https://review.opendev.org/c/openstack/keystonemiddleware/+/99570517:32

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!