| opendevreview | Douglas Mendizábal proposed openstack/keystone-specs master: spec: Explicit IDs for users https://review.opendev.org/c/openstack/keystone-specs/+/998242 | 02:33 |
|---|---|---|
| d34dh0r53 | #startmeeting keystone | 15:01 |
| opendevmeet | Meeting started Wed Jul 22 15:01:27 2026 UTC and is due to finish in 60 minutes. The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:01 |
| opendevmeet | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:01 |
| opendevmeet | The meeting name has been set to 'keystone' | 15:01 |
| d34dh0r53 | Reminder: This meeting takes place under the OpenInfra Foundation Code of Conduct | 15:01 |
| d34dh0r53 | #link https://openinfra.dev/legal/code-of-conduct | 15:01 |
| d34dh0r53 | #topic roll call | 15:01 |
| d34dh0r53 | admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann, zaitcev, reqa, dmendiza[m], dmendiza, mharley, jph, gtema, cardoe, deydra | 15:01 |
| gtema | o/ | 15:01 |
| d34dh0r53 | dmendiza: o/ | 15:01 |
| moutazchaara[m] | o/ | 15:02 |
| dmendiza[m] | 🙋 | 15:04 |
| d34dh0r53 | #topic review past meeting work items | 15:04 |
| d34dh0r53 | #link https://meetings.opendev.org/meetings/keystone/2026/keystone.2026-07-15-15.02.html | 15:04 |
| d34dh0r53 | One action item for me: dwilde plan mid-cycle keystone virtual meetup | 15:05 |
| d34dh0r53 | I'll get to that soon, but this week is crazy | 15:05 |
| d34dh0r53 | #action dwilde plan mid-cycle keystone virtual meetup | 15:05 |
| d34dh0r53 | nothing else to review | 15:05 |
| d34dh0r53 | #topic liaison updates | 15:05 |
| gtema | nothing from me | 15:06 |
| d34dh0r53 | nor me | 15:06 |
| d34dh0r53 | #topic specification Secure RBAC (dmendiza) | 15:06 |
| d34dh0r53 | #link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_ | 15:06 |
| d34dh0r53 | 2026.1 Release Timeline | 15:06 |
| d34dh0r53 | Update oslo.policy in keystone to enforce_new_defaults=True | 15:06 |
| d34dh0r53 | Update oslo.policy in keystone to enforce_scope=True | 15:07 |
| d34dh0r53 | Fix config options in keystone-tempest-plugin https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/930829 | 15:07 |
| gtema | should we just press +W on this change? | 15:07 |
| dmendiza[m] | I don't have any RBAC updates this week | 15:07 |
| gtema | I was confused by the amount of different changes not sure which ones are actually valid | 15:08 |
| d34dh0r53 | I'm good with +W on that one | 15:08 |
| gtema | done | 15:09 |
| d34dh0r53 | 👍️ | 15:09 |
| d34dh0r53 | next up | 15:09 |
| d34dh0r53 | #topic specification Secuirty Compliance Testing (dmendiza) | 15:10 |
| d34dh0r53 | #link https://review.opendev.org/c/openstack/devstack/+/957969 | 15:10 |
| dmendiza[m] | 🦗🦗🦗 | 15:10 |
| gtema | looool | 15:10 |
| d34dh0r53 | hahaha | 15:10 |
| gtema | not sure how that looks in pure IRC though | 15:10 |
| dmendiza[m] | I only use Unicode emoji 😜 | 15:11 |
| dmendiza[m] | But, yeah, I will eventually get back to this | 15:11 |
| dmendiza[m] | just hasn't been a priority lately | 15:11 |
| d34dh0r53 | lol, thanks dmendiza | 15:12 |
| d34dh0r53 | #topic specification User Specified Project/User UUIDs (dmendize, alee) | 15:12 |
| d34dh0r53 | https://review.opendev.org/c/openstack/keystone-specs/+/997320 | 15:12 |
| dmendiza[m] | I saw gtema reviewed it, will address the comments in the next patch | 15:13 |
| d34dh0r53 | cool | 15:13 |
| dmendiza[m] | I also uploaded the users side of the split | 15:13 |
| dmendiza[m] | #link https://review.opendev.org/c/openstack/keystone-specs/+/998242 | 15:13 |
| gtema | it's so funny - split of 1500 loc spec results in 2x1000loc | 15:14 |
| d34dh0r53 | efficiency | 15:14 |
| d34dh0r53 | #topic keystone-rs | 15:15 |
| d34dh0r53 | #link https://github.com/openstack-experimental/keystone | 15:15 |
| gtema | 1) finished implementing oauth2 OP role - now federation with keycloak and so on becomes unnecessary ;-) | 15:15 |
| gtema | especially with SCIM the Keystone can now fully take over the central IAM role in the cloud | 15:16 |
| gtema | 2. finished devstack plugin - in ci I test deployment of keystone-rs within devstack with running tempest tests | 15:16 |
| gtema | here it is deployed as the only keystone and not side-by-side, but this can be added when desired | 15:17 |
| gtema | 3. now chasing the tempest issues - right now 30% are passing | 15:17 |
| gtema | actually I am now pretty much finished with big features and focus on polishing/testing/deployment/operations | 15:18 |
| d34dh0r53 | very cool | 15:18 |
| gtema | that's it for now | 15:18 |
| d34dh0r53 | thanks gtema | 15:19 |
| d34dh0r53 | #topic open discussion | 15:19 |
| d34dh0r53 | cool, guess there's nothing today | 15:22 |
| d34dh0r53 | next up | 15:22 |
| d34dh0r53 | #topic bug review | 15:22 |
| d34dh0r53 | #link https://bugs.launchpad.net/keystone/?orderby=-id&start=0 | 15:22 |
| d34dh0r53 | two new keystone bugs | 15:23 |
| d34dh0r53 | #link https://bugs.launchpad.net/keystone/+bug/2161103 | 15:23 |
| moutazchaara[m] | Yes for the one #2161103, we discovered the bug. | 15:24 |
| moutazchaara[m] | and it is mainly because of the marker passed to ldap | 15:24 |
| moutazchaara[m] | i attached the patch to it. the whole flow is currently broken. | 15:25 |
| gtema | I am not sure that will realy work - I have not found any way to have a proper pagination across keystone and ldap. You can't simply "skip" x entries to fetch next page | 15:26 |
| moutazchaara[m] | i can confirm that the patch worked on the local/qa environment. but it can be the case that i forgot some edge cases with this ldap pagination it is quite tricky | 15:28 |
| gtema | ldap can only paginate within one client session, and this session is between keystone and ldap and not keystone client and ldap | 15:29 |
| moutazchaara[m] | i noticed three things actually:... (full message at <https://matrix.org/oftc/media/v1/media/download/AXAW5v4OlOzBExGrNXwpfKtA4uQMEvw7UQijYvd0t9CPC7WBdwC1RkpFEPB5QiSG0zc32b3_QmhIsNrzm8se-5NCef0oxsHQAG1hdHJpeC5vcmcvVk5JcVpMcURiU29sZ0p0VU5QUU5LYk1u>) | 15:30 |
| gtema | when keystone handover first page it "closes" the session. The client only gets the marker. You can't map the marker down to number of entries fetched | 15:31 |
| moutazchaara[m] | yes, and that was the answer for "why not use LDAP's native cursor?" in my head | 15:31 |
| gtema | because you can't keep the session alive and you need to embed the cursor info into the client response - which breaks current pagination | 15:32 |
| moutazchaara[m] | yes, it is not like the others providers. you have to get the userID and starrt from there. so it is not a position | 15:33 |
| gtema | correct | 15:33 |
| moutazchaara[m] | that's why in the patch the olnly option was to get full fetch + client-side slice. | 15:34 |
| d34dh0r53 | let's move on for the sake of time | 15:34 |
| d34dh0r53 | that was a good discussion, maybe move it to the patch/bug | 15:34 |
| d34dh0r53 | next keystone bug | 15:35 |
| d34dh0r53 | #link https://bugs.launchpad.net/keystone/+bug/2161508 | 15:35 |
| d34dh0r53 | thoughts dmendiza ? | 15:37 |
| gtema | I would agree with the bug statement | 15:38 |
| d34dh0r53 | as would I | 15:38 |
| d34dh0r53 | I'll let dmendiza know about that one | 15:40 |
| d34dh0r53 | that does it for keystone bugs | 15:41 |
| d34dh0r53 | #link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=0 | 15:41 |
| d34dh0r53 | nothing new here | 15:41 |
| d34dh0r53 | #link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=0 | 15:41 |
| d34dh0r53 | keystoneauth is good | 15:41 |
| d34dh0r53 | #link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=0 | 15:41 |
| d34dh0r53 | so is keystonemiddleware | 15:41 |
| d34dh0r53 | #link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=0 | 15:42 |
| d34dh0r53 | nothing new in pycadf | 15:42 |
| d34dh0r53 | #link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=0 | 15:42 |
| d34dh0r53 | nor ldappool | 15:42 |
| d34dh0r53 | #topic conclusion | 15:42 |
| d34dh0r53 | Thanks folks! I'll let you know about the midcycle | 15:42 |
| gtema | thanks guys | 15:42 |
| d34dh0r53 | #endmeeting | 15:43 |
| opendevmeet | Meeting ended Wed Jul 22 15:43:09 2026 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:43 |
| opendevmeet | Minutes: https://meetings.opendev.org/meetings/keystone/2026/keystone.2026-07-22-15.01.html | 15:43 |
| opendevmeet | Minutes (text): https://meetings.opendev.org/meetings/keystone/2026/keystone.2026-07-22-15.01.txt | 15:43 |
| opendevmeet | Log: https://meetings.opendev.org/meetings/keystone/2026/keystone.2026-07-22-15.01.log.html | 15:43 |
| moutazchaara[m] | thanks all, gtema would be great if you take a look at the patch and let me know your thoughts :) | 15:43 |
| gtema | yes, I will | 15:44 |
| opendevreview | Moutaz Chaara proposed openstack/keystone master: Fix LDAP marker pagination always returning first page https://review.opendev.org/c/openstack/keystone/+/997724 | 16:02 |
| opendevreview | Takashi Kajinami proposed openstack/keystone-tempest-plugin master: Add minimum pyproject.toml to support pip 23.1 https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/998335 | 16:18 |
| tkajinam | ^^^ it seems we need ^^ to fix k-t-p gate job. | 16:19 |
| tkajinam | gtema, I wonder if you will merge https://review.opendev.org/c/openstack/keystonemiddleware/+/995705 soon to unblock keystonemiddleware CI ? | 16:19 |
| gtema | done | 16:21 |
| tkajinam | thanks ! | 16:21 |
| opendevreview | Merged openstack/keystonemiddleware master: Replace deprecated `timeutils.set_time_override` https://review.opendev.org/c/openstack/keystonemiddleware/+/995705 | 17:32 |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!