*** yamamoto has quit IRC | 00:03 | |
*** gyee has quit IRC | 00:11 | |
*** erlon has joined #openstack-meeting-alt | 00:17 | |
*** zhurong has joined #openstack-meeting-alt | 00:20 | |
*** number80 has quit IRC | 00:21 | |
*** HeOS has joined #openstack-meeting-alt | 00:21 | |
*** number80 has joined #openstack-meeting-alt | 00:35 | |
*** HeOS has quit IRC | 00:39 | |
*** anilvenkata has quit IRC | 00:48 | |
*** shu-mutow has joined #openstack-meeting-alt | 00:49 | |
*** tovin07_ has joined #openstack-meeting-alt | 00:50 | |
*** kumarmn has joined #openstack-meeting-alt | 00:56 | |
*** slaweq has joined #openstack-meeting-alt | 01:03 | |
*** slaweq has quit IRC | 01:08 | |
*** Zames has joined #openstack-meeting-alt | 01:09 | |
*** Zames has quit IRC | 01:10 | |
*** salv-orl_ has joined #openstack-meeting-alt | 01:15 | |
*** salv-orlando has quit IRC | 01:18 | |
*** mhen has quit IRC | 01:20 | |
*** fzdarsky_ has joined #openstack-meeting-alt | 01:22 | |
*** mhen has joined #openstack-meeting-alt | 01:25 | |
*** fzdarsky|afk has quit IRC | 01:25 | |
*** fzdarsky_ has quit IRC | 01:27 | |
*** janki has joined #openstack-meeting-alt | 01:27 | |
*** dsariel has quit IRC | 01:27 | |
*** kumarmn has quit IRC | 01:29 | |
*** jcoufal has joined #openstack-meeting-alt | 01:31 | |
*** fzdarsky_ has joined #openstack-meeting-alt | 01:32 | |
*** hongbin has joined #openstack-meeting-alt | 01:33 | |
*** markstur_ has quit IRC | 01:34 | |
*** jchhatbar has joined #openstack-meeting-alt | 01:40 | |
*** cloudrancher has quit IRC | 01:41 | |
*** cloudrancher has joined #openstack-meeting-alt | 01:41 | |
*** janki has quit IRC | 01:43 | |
*** dsariel has joined #openstack-meeting-alt | 01:45 | |
*** yamahata has quit IRC | 01:53 | |
*** kumarmn has joined #openstack-meeting-alt | 02:04 | |
*** kumarmn has quit IRC | 02:09 | |
*** salv-orlando has joined #openstack-meeting-alt | 02:10 | |
*** dave-mccowan has joined #openstack-meeting-alt | 02:12 | |
*** salv-orl_ has quit IRC | 02:13 | |
*** erlon has quit IRC | 02:25 | |
*** SumitNaiksatam has joined #openstack-meeting-alt | 02:29 | |
*** SumitNaiksatam has quit IRC | 02:41 | |
*** yamamoto has joined #openstack-meeting-alt | 02:41 | |
*** yamamoto has quit IRC | 02:45 | |
*** dave-mccowan has quit IRC | 02:48 | |
*** tovin07_ has quit IRC | 02:51 | |
*** fnaval has quit IRC | 03:00 | |
*** slaweq has joined #openstack-meeting-alt | 03:04 | |
*** jcoufal has quit IRC | 03:07 | |
*** slaweq has quit IRC | 03:09 | |
*** harlowja has quit IRC | 03:16 | |
*** ianychoi has quit IRC | 03:16 | |
*** kumarmn has joined #openstack-meeting-alt | 03:16 | |
*** ianychoi has joined #openstack-meeting-alt | 03:20 | |
*** kumarmn has quit IRC | 03:24 | |
*** armaan has quit IRC | 03:26 | |
*** markstur has joined #openstack-meeting-alt | 03:30 | |
*** SumitNaiksatam has joined #openstack-meeting-alt | 03:36 | |
*** zhurong has quit IRC | 03:41 | |
*** hongbin has quit IRC | 03:57 | |
*** harlowja has joined #openstack-meeting-alt | 03:57 | |
*** sridharg has joined #openstack-meeting-alt | 04:00 | |
*** marius1 has joined #openstack-meeting-alt | 04:00 | |
*** rkmrHonjo has joined #openstack-meeting-alt | 04:02 | |
*** hiro-kobayashi has joined #openstack-meeting-alt | 04:03 | |
*** bhavik1 has joined #openstack-meeting-alt | 04:03 | |
*** bhavik1 has quit IRC | 04:08 | |
*** marius1 has quit IRC | 04:09 | |
*** kumarmn has joined #openstack-meeting-alt | 04:09 | |
*** vabada2 has joined #openstack-meeting-alt | 04:10 | |
*** strigazi has quit IRC | 04:11 | |
*** rochaporto has quit IRC | 04:12 | |
*** vabada has quit IRC | 04:13 | |
*** strigazi has joined #openstack-meeting-alt | 04:14 | |
*** kumarmn has quit IRC | 04:14 | |
*** rochaporto has joined #openstack-meeting-alt | 04:14 | |
*** ianychoi has quit IRC | 04:14 | |
*** ianychoi has joined #openstack-meeting-alt | 04:16 | |
*** trinaths has joined #openstack-meeting-alt | 04:20 | |
*** radeks has joined #openstack-meeting-alt | 04:31 | |
*** chhagarw has joined #openstack-meeting-alt | 04:32 | |
*** lpetrut has joined #openstack-meeting-alt | 04:54 | |
*** marios has joined #openstack-meeting-alt | 04:58 | |
*** rkmrHonjo has quit IRC | 05:00 | |
*** yamamoto has joined #openstack-meeting-alt | 05:08 | |
*** yamahata has joined #openstack-meeting-alt | 05:10 | |
*** links has joined #openstack-meeting-alt | 05:11 | |
*** yamamoto has quit IRC | 05:12 | |
*** strigazi_ has joined #openstack-meeting-alt | 05:13 | |
*** rochapor1o has joined #openstack-meeting-alt | 05:14 | |
*** vabada has joined #openstack-meeting-alt | 05:14 | |
*** vabada2 has quit IRC | 05:17 | |
*** strigazi has quit IRC | 05:17 | |
*** rochaporto has quit IRC | 05:17 | |
*** cloudrancher has quit IRC | 05:21 | |
*** lpetrut has quit IRC | 05:37 | |
*** ianychoi has quit IRC | 05:47 | |
*** lpetrut has joined #openstack-meeting-alt | 05:47 | |
*** marius1 has joined #openstack-meeting-alt | 05:47 | |
*** ianychoi has joined #openstack-meeting-alt | 05:49 | |
*** belmoreira has joined #openstack-meeting-alt | 06:00 | |
*** ethfci has joined #openstack-meeting-alt | 06:02 | |
*** markstur has quit IRC | 06:10 | |
*** macermak has joined #openstack-meeting-alt | 06:15 | |
*** lpetrut has quit IRC | 06:19 | |
*** armaan has joined #openstack-meeting-alt | 06:30 | |
*** anilvenkata has joined #openstack-meeting-alt | 06:35 | |
*** yamamoto has joined #openstack-meeting-alt | 06:37 | |
*** harlowja has quit IRC | 06:40 | |
*** rcernin has quit IRC | 06:41 | |
*** kopecmartin has joined #openstack-meeting-alt | 06:44 | |
*** arnewiebalck has joined #openstack-meeting-alt | 06:47 | |
*** slaweq has joined #openstack-meeting-alt | 06:47 | |
*** salv-orlando has quit IRC | 06:48 | |
*** salv-orlando has joined #openstack-meeting-alt | 06:48 | |
*** alexchadin has joined #openstack-meeting-alt | 06:52 | |
*** slaweq has quit IRC | 06:53 | |
*** salv-orlando has quit IRC | 06:53 | |
*** lpetrut has joined #openstack-meeting-alt | 06:53 | |
*** slaweq has joined #openstack-meeting-alt | 06:56 | |
*** jtomasek has joined #openstack-meeting-alt | 07:01 | |
*** lpetrut has quit IRC | 07:03 | |
*** yamamoto has quit IRC | 07:12 | |
*** yamamoto has joined #openstack-meeting-alt | 07:14 | |
*** yamamoto has quit IRC | 07:14 | |
*** dsariel has quit IRC | 07:14 | |
*** yamamoto has joined #openstack-meeting-alt | 07:15 | |
*** tesseract has joined #openstack-meeting-alt | 07:19 | |
*** yamamoto has quit IRC | 07:19 | |
*** radeks has quit IRC | 07:21 | |
*** radeks has joined #openstack-meeting-alt | 07:21 | |
*** salv-orlando has joined #openstack-meeting-alt | 07:23 | |
*** tssurya has joined #openstack-meeting-alt | 07:26 | |
*** pgadiya has joined #openstack-meeting-alt | 07:26 | |
*** jhesketh_ has joined #openstack-meeting-alt | 07:31 | |
*** jhesketh has quit IRC | 07:37 | |
*** fzdarsky_ is now known as fzdarsky | 07:39 | |
*** belmoreira has quit IRC | 07:43 | |
*** florianf has joined #openstack-meeting-alt | 07:49 | |
*** pgadiya has quit IRC | 07:49 | |
*** rossella_s has quit IRC | 07:50 | |
*** pgadiya has joined #openstack-meeting-alt | 08:09 | |
*** pgadiya has quit IRC | 08:09 | |
*** lpetrut has joined #openstack-meeting-alt | 08:16 | |
*** dsariel has joined #openstack-meeting-alt | 08:21 | |
*** hiro-kobayashi has quit IRC | 08:22 | |
*** jesusaur has quit IRC | 08:23 | |
*** jesusaur has joined #openstack-meeting-alt | 08:27 | |
*** priteau has joined #openstack-meeting-alt | 08:27 | |
*** adisky__ has joined #openstack-meeting-alt | 08:30 | |
*** pbourke has joined #openstack-meeting-alt | 08:35 | |
*** bfernando has joined #openstack-meeting-alt | 08:39 | |
*** dsariel has quit IRC | 08:49 | |
*** radeks has quit IRC | 08:50 | |
*** radeks has joined #openstack-meeting-alt | 08:50 | |
*** hiro-kobayashi has joined #openstack-meeting-alt | 08:53 | |
*** bertys has joined #openstack-meeting-alt | 08:58 | |
*** macermak has quit IRC | 08:59 | |
*** caowei has quit IRC | 08:59 | |
*** masahito has joined #openstack-meeting-alt | 09:01 | |
masahito | hi blazar folks, time to blazar meeting | 09:02 |
---|---|---|
priteau | Hello! | 09:02 |
masahito | #startmeeting blazar | 09:02 |
openstack | Meeting started Tue Apr 10 09:02:18 2018 UTC and is due to finish in 60 minutes. The chair is masahito. Information about MeetBot at http://wiki.debian.org/MeetBot. | 09:02 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 09:02 |
*** openstack changes topic to " (Meeting topic: blazar)" | 09:02 | |
openstack | The meeting name has been set to 'blazar' | 09:02 |
masahito | #topic RollCall | 09:02 |
*** openstack changes topic to "RollCall (Meeting topic: blazar)" | 09:02 | |
priteau | o/ | 09:02 |
masahito | priteau: hello | 09:02 |
hiro-kobayashi | o/ | 09:02 |
bertys | o/ | 09:02 |
*** belmoreira has joined #openstack-meeting-alt | 09:03 | |
masahito | hiro-kobayashi, bertys: hello | 09:03 |
masahito | today's agenda is | 09:03 |
masahito | 1. the Forum | 09:03 |
masahito | 2. story board migration | 09:03 |
masahito | 3. AOB | 09:03 |
masahito | anything else? | 09:03 |
*** HeOS has joined #openstack-meeting-alt | 09:03 | |
priteau | Agenda looks good to me | 09:04 |
masahito | let's get started. | 09:04 |
masahito | #topic the Forum | 09:04 |
*** openstack changes topic to "the Forum (Meeting topic: blazar)" | 09:05 | |
masahito | As we discussed in the previous meeting, the Blazar team is thinking to propose a forum topic. | 09:05 |
masahito | I wrote a breif draft for the submission. Please see/review it. | 09:06 |
masahito | https://etherpad.openstack.org/p/blazar-forum-vancouver | 09:06 |
hiro-kobayashi | thanks! | 09:07 |
masahito | The dedline of the submission is this weekend. I'll submit it in few days. | 09:08 |
priteau | Thank you masahito. I am making some small changes. | 09:08 |
masahito | priteau: thank you. | 09:08 |
masahito | There is less topics. I hope our proposal will be accepted. | 09:09 |
masahito | https://wiki.openstack.org/wiki/Forum/Vancouver2018 | 09:09 |
priteau | Does it make sense to list PCI-passthrough devices as a potentially reservable resource? | 09:09 |
masahito | yes | 09:10 |
bertys | masahito: thanks for your initial draft! Makes sense to me. Let's collect more use cases/requirements | 09:10 |
masahito | priteau: ah, It's not an attribute of instance or host, is it? | 09:11 |
priteau | If you reserve a full host, you'll get the PCI devices with it, so that's already covered | 09:11 |
priteau | But, for instance reservation, I am not sure if that would already work | 09:12 |
masahito | I see. The number of PCI device is limited, so that's need to be reserved in case of instance reservation. | 09:13 |
priteau | Yes, I think so. | 09:13 |
masahito | let's move on to next | 09:15 |
*** yamamoto has joined #openstack-meeting-alt | 09:15 | |
priteau | OK, I have made all my changes. I changed Demands to Requirements in the title. | 09:15 |
priteau | Demands is a bit strong ;-) | 09:15 |
masahito | priteau: thank you. It looks better to me. | 09:16 |
masahito | #topic StoryBoard migration | 09:16 |
*** openstack changes topic to "StoryBoard migration (Meeting topic: blazar)" | 09:16 | |
masahito | There're some discussion in openstack-dev ML regarding to storyboard migration. | 09:17 |
*** shu-mutow has quit IRC | 09:17 | |
*** links has quit IRC | 09:18 | |
masahito | And storyboard team told me that the migration script from the launchpad to the storyboard works for Blazar project. | 09:18 |
masahito | And also said if possible, let's think about moving to storyboad now. | 09:19 |
masahito | My topic in the meeting is do you want to move to the storyboard in the R cycle? | 09:20 |
priteau | masahito: which ML thread is it? | 09:20 |
masahito | lots of thread | 09:20 |
*** matrohon has joined #openstack-meeting-alt | 09:20 | |
priteau | The recent ones seem to be project-specific, e.g. tripleo | 09:21 |
priteau | I haven't read them, is the feedback from projects good so far? | 09:21 |
priteau | If others are satisfied with storyboard, I am happy to move as well. | 09:22 |
hiro-kobayashi | priteau: Agree | 09:23 |
masahito | I've not read them yet. | 09:23 |
hiro-kobayashi | What is expected to be migrated to storyboard? Blueprints? | 09:23 |
masahito | The script only migrates bug reports. | 09:24 |
masahito | What we need to do are 1. migrating BP, 2. creating whiteboard? for milestone, 3. other misc things. | 09:25 |
masahito | I'm asking the them the two things: 1. who does BP migration, we or storyboard team? 2. how can we handle milestone and release in the storyboard. | 09:27 |
masahito | So if there | 09:28 |
masahito | if there's no problem, I'm okay to move it unless we have time to do that :-) | 09:28 |
masahito | This blog is a overview of storyboard. https://storyboard-blog.io/ | 09:29 |
*** matrohon has quit IRC | 09:30 | |
hiro-kobayashi | +1 we should follow standards | 09:30 |
masahito | If needed, please glance the blog. | 09:30 |
priteau | Thanks masahito for discussing with the Storyboard team | 09:30 |
masahito | And this is a view of blazar project. https://storyboard-dev.openstack.org/#!/project/300 | 09:30 |
*** derekh has joined #openstack-meeting-alt | 09:30 | |
bertys | masahito: I had quick look at https://storyboard-dev.openstack.org/#!/project/300. Looks ok. Let's clarify who is responsible for what. Thanks | 09:31 |
priteau | masahito: Does it lose bug categorisation on import, i.e. importance (high, medium, etc.) and status (confirmed, in progress, etc.)? | 09:32 |
*** Zames_ has joined #openstack-meeting-alt | 09:33 | |
*** links has joined #openstack-meeting-alt | 09:33 | |
*** caowei has joined #openstack-meeting-alt | 09:33 | |
masahito | priteau: looks like yes. That's one of my question to the team. | 09:34 |
priteau | So I would say let's wait until those questions are answered. Maybe the migration script will improve. | 09:35 |
masahito | According to the blog, each developers can create own worklists for piroriterizing. | 09:35 |
*** panda|off is now known as panda | 09:37 | |
masahito | Yes. My plan is migrating storyboard after r-3 milestone if the tool is better than the launchpad | 09:37 |
*** Zames_ has quit IRC | 09:37 | |
masahito | There're less activities after r-3. It's easy to migrate | 09:37 |
bertys | +1 and let's experiment a bit in the meantime | 09:38 |
*** macermak has joined #openstack-meeting-alt | 09:39 | |
masahito | #topic AOB | 09:40 |
*** openstack changes topic to "AOB (Meeting topic: blazar)" | 09:40 | |
masahito | Does someone have something to share/discuss/etc? | 09:40 |
*** yamamoto has quit IRC | 09:41 | |
*** yamamoto has joined #openstack-meeting-alt | 09:41 | |
priteau | I just noticed this commit in governance: https://git.openstack.org/cgit/openstack/governance/commit/?id=c85c5b5fbc6e55f8e73d7c263daa2db64443ab18 | 09:41 |
priteau | Have we relinquished direct tagging/branch creation rights? | 09:41 |
*** dosaboy has quit IRC | 09:42 | |
masahito | yes. | 09:42 |
priteau | Great, just checking. | 09:43 |
priteau | In AOB, I am behind on code reviews due to travel and deadlines, but hopefully will get back to it later this week. | 09:43 |
masahito | We don't need to have the right because the release/tagging/branch creation are handled by release repo because Blazar is an official project. | 09:44 |
masahito | priteau: Got it. | 09:44 |
masahito | Speaking of release. Next week is r-1 milestone. | 09:44 |
masahito | I'll put the 2.0.0.0b1 tag in next week. | 09:45 |
*** dosaboy has joined #openstack-meeting-alt | 09:45 | |
priteau | Is that because we are an official project, we will now increase the major version number at each OpenStack release? | 09:47 |
masahito | yes. | 09:47 |
*** dosaboy has quit IRC | 09:48 | |
masahito | From my understand, major project increments its major version at each release. | 09:48 |
*** dosaboy has joined #openstack-meeting-alt | 09:49 | |
*** dosaboy has quit IRC | 09:49 | |
*** dosaboy has joined #openstack-meeting-alt | 09:50 | |
*** armaan has quit IRC | 09:50 | |
priteau | Sounds good | 09:51 |
masahito | Is there another topic? If nothing, let's finish the meeting early. | 09:51 |
hiro-kobayashi | Nothing from me. | 09:51 |
*** armaan has joined #openstack-meeting-alt | 09:51 | |
*** dosaboy has quit IRC | 09:51 | |
priteau | Thanks everyone, talk to you next week! | 09:52 |
masahito | thanks all, bye! | 09:52 |
*** alexchadin has quit IRC | 09:52 | |
masahito | #endmeeting | 09:52 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 09:52 | |
openstack | Meeting ended Tue Apr 10 09:52:29 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 09:52 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/blazar/2018/blazar.2018-04-10-09.02.html | 09:52 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/blazar/2018/blazar.2018-04-10-09.02.txt | 09:52 |
openstack | Log: http://eavesdrop.openstack.org/meetings/blazar/2018/blazar.2018-04-10-09.02.log.html | 09:52 |
hiro-kobayashi | thanks all | 09:52 |
*** hiro-kobayashi has quit IRC | 09:52 | |
*** bertys has quit IRC | 09:52 | |
*** trinaths has quit IRC | 09:55 | |
*** dosaboy has joined #openstack-meeting-alt | 09:56 | |
*** MarkBaker has joined #openstack-meeting-alt | 09:58 | |
*** salv-orl_ has joined #openstack-meeting-alt | 09:59 | |
*** pgadiya has joined #openstack-meeting-alt | 09:59 | |
*** pgadiya has quit IRC | 10:00 | |
*** masahito has quit IRC | 10:00 | |
*** salv-orl_ has quit IRC | 10:01 | |
*** strigazi_ is now known as strigazi | 10:01 | |
*** salv-orl_ has joined #openstack-meeting-alt | 10:01 | |
*** kaisers1 has quit IRC | 10:02 | |
*** armaan has quit IRC | 10:02 | |
*** jesusaur has quit IRC | 10:02 | |
*** salv-orlando has quit IRC | 10:02 | |
*** armaan has joined #openstack-meeting-alt | 10:02 | |
*** radeks has quit IRC | 10:03 | |
*** kaisers1 has joined #openstack-meeting-alt | 10:03 | |
*** dsariel has joined #openstack-meeting-alt | 10:04 | |
*** salv-orl_ has quit IRC | 10:06 | |
*** fzdarsky has quit IRC | 10:09 | |
*** fzdarsky has joined #openstack-meeting-alt | 10:10 | |
*** fzdarsky has quit IRC | 10:15 | |
*** jesusaur has joined #openstack-meeting-alt | 10:15 | |
*** yamamoto has quit IRC | 10:17 | |
*** fzdarsky has joined #openstack-meeting-alt | 10:20 | |
*** yamamoto has joined #openstack-meeting-alt | 10:21 | |
*** MarkBaker has quit IRC | 10:23 | |
*** kumarmn has joined #openstack-meeting-alt | 10:25 | |
*** yamamoto has quit IRC | 10:27 | |
*** yamamoto has joined #openstack-meeting-alt | 10:27 | |
*** kumarmn has quit IRC | 10:29 | |
*** pbourke has quit IRC | 10:30 | |
*** MarkBaker has joined #openstack-meeting-alt | 10:32 | |
*** marius1 has quit IRC | 10:41 | |
*** MarkBaker has quit IRC | 10:48 | |
*** radeks has joined #openstack-meeting-alt | 10:49 | |
*** macermak has quit IRC | 10:50 | |
*** yamamoto has quit IRC | 10:58 | |
*** cloudrancher has joined #openstack-meeting-alt | 10:59 | |
*** strigazi is now known as strigaz_ | 10:59 | |
*** strigaz_ is now known as strigazi_ | 10:59 | |
*** strigazi_ is now known as strigazi | 10:59 | |
*** yamamoto has joined #openstack-meeting-alt | 11:00 | |
*** tpsilva has joined #openstack-meeting-alt | 11:01 | |
*** yamamoto has quit IRC | 11:01 | |
*** salv-orlando has joined #openstack-meeting-alt | 11:02 | |
*** sambetts|afk is now known as sambetts | 11:04 | |
*** macermak has joined #openstack-meeting-alt | 11:06 | |
*** salv-orlando has quit IRC | 11:06 | |
*** dprince has joined #openstack-meeting-alt | 11:20 | |
*** links has quit IRC | 11:26 | |
*** jchhatbar has quit IRC | 11:27 | |
*** dprince has quit IRC | 11:28 | |
*** arxcruz|ruck has quit IRC | 11:29 | |
*** alexchadin has joined #openstack-meeting-alt | 11:31 | |
*** caowei has quit IRC | 11:32 | |
*** links has joined #openstack-meeting-alt | 11:39 | |
*** markvoelker has joined #openstack-meeting-alt | 11:40 | |
*** panda is now known as panda|lunch | 11:43 | |
*** arxcruz has joined #openstack-meeting-alt | 11:47 | |
*** arxcruz is now known as arxcruz|ruck | 11:48 | |
*** zhurong has joined #openstack-meeting-alt | 11:53 | |
*** marius1 has joined #openstack-meeting-alt | 11:59 | |
*** learnmore has joined #openstack-meeting-alt | 12:01 | |
*** salv-orlando has joined #openstack-meeting-alt | 12:02 | |
*** weshay_pto is now known as weshay | 12:03 | |
*** rfolco|off is now known as rfolco|rover | 12:03 | |
*** salv-orlando has quit IRC | 12:07 | |
*** macermak has quit IRC | 12:07 | |
*** janki has joined #openstack-meeting-alt | 12:11 | |
*** raildo has joined #openstack-meeting-alt | 12:17 | |
*** edmondsw has joined #openstack-meeting-alt | 12:17 | |
*** learnmore has quit IRC | 12:18 | |
*** dave-mccowan has joined #openstack-meeting-alt | 12:19 | |
*** jchhatbar has joined #openstack-meeting-alt | 12:19 | |
*** janki has quit IRC | 12:22 | |
*** gouthamr has joined #openstack-meeting-alt | 12:23 | |
*** kumarmn has joined #openstack-meeting-alt | 12:25 | |
*** macermak has joined #openstack-meeting-alt | 12:27 | |
*** edmondsw has quit IRC | 12:28 | |
*** jcoufal has joined #openstack-meeting-alt | 12:29 | |
*** kumarmn has quit IRC | 12:31 | |
*** yamamoto has joined #openstack-meeting-alt | 12:35 | |
*** marius1 has quit IRC | 12:36 | |
*** marius1 has joined #openstack-meeting-alt | 12:37 | |
*** matrohon has joined #openstack-meeting-alt | 12:39 | |
*** yamamoto has quit IRC | 12:41 | |
*** gouthamr has quit IRC | 12:43 | |
*** gouthamr has joined #openstack-meeting-alt | 12:44 | |
*** yamamoto has joined #openstack-meeting-alt | 12:44 | |
*** gouthamr has quit IRC | 12:45 | |
*** pgadiya has joined #openstack-meeting-alt | 12:47 | |
*** pgadiya has quit IRC | 12:47 | |
*** edmondsw has joined #openstack-meeting-alt | 12:51 | |
*** julim has quit IRC | 12:52 | |
*** vgreen has joined #openstack-meeting-alt | 12:53 | |
*** julim has joined #openstack-meeting-alt | 12:53 | |
*** salv-orlando has joined #openstack-meeting-alt | 12:53 | |
*** zhurong has quit IRC | 12:54 | |
*** yamamoto has quit IRC | 12:57 | |
*** radeks has quit IRC | 12:58 | |
*** radeks has joined #openstack-meeting-alt | 12:58 | |
*** dustins has joined #openstack-meeting-alt | 12:59 | |
*** zhurong has joined #openstack-meeting-alt | 12:59 | |
*** panda|lunch is now known as panda | 12:59 | |
zhurong | #startmeeting murano | 13:01 |
openstack | Meeting started Tue Apr 10 13:01:56 2018 UTC and is due to finish in 60 minutes. The chair is zhurong. Information about MeetBot at http://wiki.debian.org/MeetBot. | 13:01 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 13:01 |
*** openstack changes topic to " (Meeting topic: murano)" | 13:01 | |
openstack | The meeting name has been set to 'murano' | 13:01 |
*** alexchadin has quit IRC | 13:02 | |
zhurong | #topic RoleCall | 13:02 |
*** openstack changes topic to "RoleCall (Meeting topic: murano)" | 13:02 | |
zhurong | hi | 13:02 |
*** salv-orl_ has joined #openstack-meeting-alt | 13:04 | |
*** salv-orlando has quit IRC | 13:05 | |
*** finucannot is now known as stephenfin | 13:05 | |
*** yamamoto has joined #openstack-meeting-alt | 13:07 | |
*** toscalix_ has joined #openstack-meeting-alt | 13:11 | |
*** kumarmn has joined #openstack-meeting-alt | 13:11 | |
*** kumarmn has quit IRC | 13:12 | |
zhurong | #endmeeting | 13:12 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 13:12 | |
openstack | Meeting ended Tue Apr 10 13:12:46 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 13:12 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/murano/2018/murano.2018-04-10-13.01.html | 13:12 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/murano/2018/murano.2018-04-10-13.01.txt | 13:12 |
openstack | Log: http://eavesdrop.openstack.org/meetings/murano/2018/murano.2018-04-10-13.01.log.html | 13:12 |
*** kumarmn has joined #openstack-meeting-alt | 13:12 | |
*** zhurong has quit IRC | 13:13 | |
*** armaan has quit IRC | 13:13 | |
*** yamamoto has quit IRC | 13:16 | |
*** kumarmn has quit IRC | 13:17 | |
*** marius1 has quit IRC | 13:17 | |
*** marius11 has joined #openstack-meeting-alt | 13:17 | |
*** yamamoto has joined #openstack-meeting-alt | 13:20 | |
*** pbourke has joined #openstack-meeting-alt | 13:20 | |
*** marius11 has quit IRC | 13:20 | |
*** marius1 has joined #openstack-meeting-alt | 13:20 | |
*** pbourke has quit IRC | 13:21 | |
*** pbourke has joined #openstack-meeting-alt | 13:21 | |
*** fuqiao has joined #openstack-meeting-alt | 13:22 | |
*** yamamoto has quit IRC | 13:23 | |
*** cloudrancher has quit IRC | 13:25 | |
*** kopecmartin has quit IRC | 13:26 | |
*** cloudrancher has joined #openstack-meeting-alt | 13:26 | |
*** toscalix_ has quit IRC | 13:27 | |
*** kumarmn has joined #openstack-meeting-alt | 13:28 | |
*** kopecmartin has joined #openstack-meeting-alt | 13:29 | |
*** dklyle has quit IRC | 13:33 | |
*** alexchadin has joined #openstack-meeting-alt | 13:34 | |
*** marius1 has quit IRC | 13:42 | |
*** lbragstad has joined #openstack-meeting-alt | 13:42 | |
*** toscalix_ has joined #openstack-meeting-alt | 13:47 | |
*** armaan has joined #openstack-meeting-alt | 13:47 | |
*** toscalix_ has quit IRC | 13:47 | |
*** hongbin has joined #openstack-meeting-alt | 13:50 | |
*** serverascode has quit IRC | 13:50 | |
*** serverascode has joined #openstack-meeting-alt | 13:51 | |
*** yamamoto has joined #openstack-meeting-alt | 13:51 | |
*** yamamoto has quit IRC | 13:54 | |
*** fdegir has quit IRC | 13:54 | |
*** fdegir has joined #openstack-meeting-alt | 13:54 | |
*** kopecmartin has quit IRC | 13:54 | |
*** yamamoto has joined #openstack-meeting-alt | 14:02 | |
*** ianychoi has quit IRC | 14:02 | |
*** ianychoi has joined #openstack-meeting-alt | 14:03 | |
*** DuncanT has quit IRC | 14:04 | |
*** DuncanT has joined #openstack-meeting-alt | 14:04 | |
*** yamamoto has quit IRC | 14:05 | |
*** kopecmartin has joined #openstack-meeting-alt | 14:06 | |
*** timirnich has quit IRC | 14:08 | |
*** ildikov has quit IRC | 14:08 | |
*** timirnich has joined #openstack-meeting-alt | 14:09 | |
*** ildikov has joined #openstack-meeting-alt | 14:09 | |
*** yamamoto has joined #openstack-meeting-alt | 14:10 | |
*** jaypipes has joined #openstack-meeting-alt | 14:10 | |
*** chhavi__ has joined #openstack-meeting-alt | 14:12 | |
*** yamamoto has quit IRC | 14:13 | |
*** links has quit IRC | 14:13 | |
*** chhagarw has quit IRC | 14:15 | |
*** markvoelker_ has joined #openstack-meeting-alt | 14:18 | |
*** gouthamr has joined #openstack-meeting-alt | 14:19 | |
*** csatari has quit IRC | 14:19 | |
*** csatari has joined #openstack-meeting-alt | 14:19 | |
*** guyr-infinidat has quit IRC | 14:19 | |
*** guyr-infinidat has joined #openstack-meeting-alt | 14:20 | |
*** markvoelker has quit IRC | 14:21 | |
*** aprice has quit IRC | 14:25 | |
*** aprice has joined #openstack-meeting-alt | 14:25 | |
*** wxy has quit IRC | 14:27 | |
*** wxy has joined #openstack-meeting-alt | 14:27 | |
*** omolchanov__ has quit IRC | 14:27 | |
*** omolchanov__ has joined #openstack-meeting-alt | 14:27 | |
*** zhuli has quit IRC | 14:28 | |
*** zhuli has joined #openstack-meeting-alt | 14:28 | |
*** kopecmartin has quit IRC | 14:29 | |
*** knikolla has quit IRC | 14:30 | |
*** knikolla has joined #openstack-meeting-alt | 14:30 | |
*** matrohon has quit IRC | 14:31 | |
*** macermak has quit IRC | 14:32 | |
*** felipemonteiro has joined #openstack-meeting-alt | 14:36 | |
*** masahito has joined #openstack-meeting-alt | 14:36 | |
*** markvoelker has joined #openstack-meeting-alt | 14:36 | |
*** masahito has quit IRC | 14:37 | |
*** lpetrut_ has joined #openstack-meeting-alt | 14:38 | |
*** lpetrut_ has quit IRC | 14:38 | |
*** markvoelker_ has quit IRC | 14:39 | |
*** gouthamr has quit IRC | 14:40 | |
*** lpetrut has quit IRC | 14:41 | |
*** yamamoto has joined #openstack-meeting-alt | 14:41 | |
*** yamamoto has quit IRC | 14:41 | |
*** markvoelker_ has joined #openstack-meeting-alt | 14:42 | |
*** markvoelker has quit IRC | 14:44 | |
*** markvoelker has joined #openstack-meeting-alt | 14:46 | |
*** dklyle has joined #openstack-meeting-alt | 14:46 | |
*** yamamoto has joined #openstack-meeting-alt | 14:47 | |
*** felipemonteiro_ has joined #openstack-meeting-alt | 14:47 | |
*** alexchadin has quit IRC | 14:47 | |
*** fnaval has joined #openstack-meeting-alt | 14:47 | |
*** markvoelker_ has quit IRC | 14:49 | |
*** markvoelker_ has joined #openstack-meeting-alt | 14:49 | |
*** gagehugo has joined #openstack-meeting-alt | 14:50 | |
*** markstur has joined #openstack-meeting-alt | 14:50 | |
*** felipemonteiro has quit IRC | 14:51 | |
*** markvoelker has quit IRC | 14:53 | |
*** markvoelker has joined #openstack-meeting-alt | 14:56 | |
*** markvoelker_ has quit IRC | 14:58 | |
*** wxy| has joined #openstack-meeting-alt | 15:00 | |
*** yamamoto has quit IRC | 15:01 | |
*** anilvenkata has quit IRC | 15:01 | |
*** yamamoto has joined #openstack-meeting-alt | 15:01 | |
*** markvoelker_ has joined #openstack-meeting-alt | 15:05 | |
*** markvoelker_ has quit IRC | 15:08 | |
*** matrohon has joined #openstack-meeting-alt | 15:09 | |
*** markvoelker has quit IRC | 15:09 | |
*** markvoelker has joined #openstack-meeting-alt | 15:10 | |
*** markvoelker_ has joined #openstack-meeting-alt | 15:10 | |
*** julim has quit IRC | 15:15 | |
*** markvoelker has quit IRC | 15:15 | |
*** belmoreira has quit IRC | 15:17 | |
*** yamamoto has quit IRC | 15:19 | |
*** yamamoto has joined #openstack-meeting-alt | 15:19 | |
*** salv-orl_ has quit IRC | 15:22 | |
*** salv-orlando has joined #openstack-meeting-alt | 15:23 | |
*** jaypipes has quit IRC | 15:23 | |
*** yamamoto has quit IRC | 15:26 | |
*** rwsu has quit IRC | 15:26 | |
*** salv-orlando has quit IRC | 15:27 | |
*** matrohon has quit IRC | 15:28 | |
*** salv-orlando has joined #openstack-meeting-alt | 15:28 | |
*** yamamoto has joined #openstack-meeting-alt | 15:31 | |
*** gyee has joined #openstack-meeting-alt | 15:31 | |
*** jchhatbar has quit IRC | 15:33 | |
*** armaan has quit IRC | 15:38 | |
*** armaan has joined #openstack-meeting-alt | 15:38 | |
*** rwsu has joined #openstack-meeting-alt | 15:39 | |
*** tssurya has quit IRC | 15:41 | |
*** fuqiao has quit IRC | 15:42 | |
*** yamamoto has quit IRC | 15:43 | |
*** yamamoto has joined #openstack-meeting-alt | 15:44 | |
*** sonuk has joined #openstack-meeting-alt | 15:55 | |
lbragstad | #startmeeting keystone | 16:00 |
openstack | Meeting started Tue Apr 10 16:00:02 2018 UTC and is due to finish in 60 minutes. The chair is lbragstad. Information about MeetBot at http://wiki.debian.org/MeetBot. | 16:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 16:00 |
*** openstack changes topic to " (Meeting topic: keystone)" | 16:00 | |
openstack | The meeting name has been set to 'keystone' | 16:00 |
lbragstad | ping ayoung, breton, cmurphy, dstanek, gagehugo, henrynash, hrybacki, knikolla, lamt, lbragstad, lwanderley, kmalloc, rderose, rodrigods, samueldmq, spilla, aselius, dpar, jdennis, ruan_he, wxy, sonuk | 16:00 |
gagehugo | o/ | 16:00 |
lbragstad | #link https://etherpad.openstack.org/p/keystone-weekly-meeting | 16:00 |
lbragstad | o/ | 16:00 |
lbragstad | agenda ^ | 16:00 |
hrybacki | o/ | 16:00 |
ayoung | Hey Ho. Lets go. | 16:00 |
wxy| | o/ | 16:00 |
*** edmondsw has quit IRC | 16:00 | |
lbragstad | give folks another minute or two to show up | 16:00 |
kmalloc | o/ | 16:00 |
kmalloc | i'm here... | 16:01 |
sonuk | o/ | 16:01 |
lbragstad | sonuk: welcome | 16:01 |
*** edmondsw has joined #openstack-meeting-alt | 16:01 | |
jgrassler | o/ | 16:01 |
sonuk | lbragstad: thanks | 16:01 |
lbragstad | #topic specifications | 16:01 |
*** openstack changes topic to "specifications (Meeting topic: keystone)" | 16:01 | |
lbragstad | things are moving and we had some good iterations over the last week | 16:02 |
*** lamt has joined #openstack-meeting-alt | 16:02 | |
lbragstad | i'll likely keep specs as an item on the meeting agenda until we get things where we want them | 16:02 |
lbragstad | #info specification proposal freeze is going to be next week | 16:03 |
lbragstad | just a reminder in case there is anything we're missing for Rocky | 16:03 |
lbragstad | #topic Application Credentials | 16:03 |
*** openstack changes topic to "Application Credentials (Meeting topic: keystone)" | 16:03 | |
lbragstad | #link https://review.openstack.org/#/c/396331/ | 16:03 |
lbragstad | i've reviewed this a few times and my comments are getting really nit picky :) | 16:04 |
lbragstad | i think this is looking good | 16:04 |
jgrassler | I take that as a good sign :-) | 16:04 |
lbragstad | jgrassler: yep! | 16:04 |
lbragstad | i'd like to have a few other reviews give it a once over though | 16:04 |
lbragstad | just to make sure we're not missing anything before we merge it | 16:04 |
kmalloc | lbragstad: +2/+A'd that spec | 16:05 |
kmalloc | lbragstad: just reviewed it again | 16:05 |
kmalloc | if you want me to rescind my +A i will | 16:05 |
lbragstad | fastest review ever | 16:05 |
kmalloc | but it looks ready | 16:05 |
kmalloc | he had to change 1 thing from the last round for me to +2. | 16:06 |
kmalloc | it was ready. | 16:06 |
jgrassler | kmalloc: thanks :-) | 16:06 |
lbragstad | cool | 16:06 |
lbragstad | looks good to me | 16:06 |
lbragstad | if anyone sees anything in that spec, please say something | 16:06 |
lbragstad | or leave a comment | 16:06 |
kmalloc | or propose a followup | 16:06 |
lbragstad | we can address things in a follow up if needed | 16:06 |
ayoung | Yeah...App Creds looks good | 16:07 |
lbragstad | #topic default roles | 16:07 |
*** openstack changes topic to "default roles (Meeting topic: keystone)" | 16:07 | |
lbragstad | hrybacki: around? | 16:07 |
hrybacki | o/ Alright so, after discussions w/ Adam yesterday I'm in support of using implied roles for default roles. I had a basic misunderstanding how he envisioned them being used. Since all of the work will be on our end*, and it clears up the policy files I think it's the best move. | 16:07 |
ayoung | We really should get a lighter process, where we approve the spec in a general sense, and then start ones and twos on it. | 16:08 |
kmalloc | ayoung: that was at the PTG | 16:08 |
hrybacki | all-in-all I think the spec is shaping up nicely though. Lots of feedback coming in | 16:08 |
kmalloc | ayoung: "this is something we want, we like it, now iterate on it and get it ready to merge" | 16:08 |
ayoung | to be clear, I really only see three roles, with 2 an inference rules between them | 16:09 |
ayoung | admin -> member and member -> reader | 16:09 |
lbragstad | admin -> member -> auditor right? | 16:09 |
hrybacki | ^^ +2 | 16:09 |
ayoung | right | 16:09 |
ayoung | auditor | 16:09 |
ayoung | and then the policy files get simpler, you remove the ORs | 16:09 |
ayoung | it also gives you a tool to further refine things down the line: | 16:09 |
kmalloc | ah and fill in the policy behind the scenes | 16:09 |
hrybacki | a good point | 16:09 |
kmalloc | thats pretty solid | 16:09 |
hrybacki | kmalloc: aye. | 16:09 |
lbragstad | hrybacki: are you working that into the next revision? | 16:10 |
hrybacki | lbragstad: I am -- but wanted to discuss here before posting | 16:10 |
*** yamamoto has quit IRC | 16:10 | |
lbragstad | ack | 16:10 |
ayoung | want to break member up into smaller pieces? Start with a new role, then a new inference rule, and finally a new policy, and you've not broken anything | 16:10 |
hrybacki | +1 | 16:10 |
kmalloc | ayoung: that is quite reasonable | 16:10 |
lbragstad | we're going to need to be ready to explain the concepts to other services | 16:10 |
ayoung | thanks | 16:10 |
*** yamamoto has joined #openstack-meeting-alt | 16:10 | |
kmalloc | lbragstad: i think this makes it easier | 16:11 |
lbragstad | right - but we're also a bunch of keystone developers :) | 16:11 |
hrybacki | and implied roles are the way we are asking deployments to handle edge cases | 16:11 |
ayoung | and the same mechanism that sets up the default roles sets up the rules. | 16:11 |
lbragstad | i can just see developers from other services having questions about what this exactly means for them | 16:12 |
ayoung | keystone-manage I assume | 16:12 |
lbragstad | and we'll need to be prepared to field those | 16:12 |
lbragstad | so that we can keep things moving | 16:12 |
ayoung | lbragstad, that is why we get it in the spec first: the example policy should spell it out | 16:12 |
hrybacki | WRT domain scope -- I do not think we should integrate it into the spec. I understand that user/groups tie directly to the concept and are a sticky point but cmurphy made some very good points about it not being a 'real' scope and that we should err on the side of not misleading consumers | 16:13 |
ayoung | BTW, I see what y'all were saying about Domain level roles. My last comment suggests dropping the user example, and just adding a note "leave these alone" | 16:13 |
lbragstad | yeah... i'm fine with that assessment | 16:14 |
ayoung | "they are Keystone only" | 16:14 |
hrybacki | ayoung: yeah, that's just a leftover I missed | 16:14 |
lbragstad | honestly, we have a good seam to work on that later | 16:14 |
ayoung | for a service level operation, suggest hypervisor management | 16:14 |
lbragstad | if we get the whole "project" scope and "system" scope work done, we can come through later and do all the domain stuff as it's own specification | 16:14 |
ayoung | https://developer.openstack.org/api-ref/compute/#hypervisors-os-hypervisors | 16:14 |
hrybacki | #link https://developer.openstack.org/api-ref/compute/#hypervisors-os-hypervisors | 16:15 |
*** thomasduval has joined #openstack-meeting-alt | 16:15 | |
lbragstad | we might need to clarify the intent that domain scope will be tackled later in the specification | 16:16 |
ayoung | #link http://git.openstack.org/cgit/openstack/nova/tree/nova/policies/hypervisors.py?h=stable/queens#n37 | 16:16 |
*** bfernando has quit IRC | 16:16 | |
hrybacki | lbragstad: I can add a 'future work' section | 16:16 |
ayoung | lbragstad, Domain scope would be in a Keystone specific spec, so we should be OK | 16:16 |
lbragstad | not necessarily | 16:16 |
lbragstad | i can see a case where using a domain-scoped token for other services would be useful | 16:17 |
ayoung | lbragstad, so can I, but they don't have the data stored to work on it | 16:17 |
lbragstad | e.g. using a domain scoped token to perform a GET /servers call | 16:17 |
hrybacki | yeah it's tricky. Users/groups should not necessarily be controlled by anyone with system scope (ideally) | 16:17 |
ayoung | yeah, but they don't have the tree today. So, while it might be someday in the future, it would require a good be of reengineering to get there | 16:17 |
lbragstad | sure - that's a good candidate for future work | 16:18 |
lbragstad | but i wouldn't say domain-scope is "keystone" specific | 16:18 |
lbragstad | because then it seems like it's only something that we will use | 16:18 |
*** sridharg has quit IRC | 16:19 | |
ayoung | Sounds good. I think we see things from the same perspective | 16:19 |
hrybacki | ++ | 16:20 |
lbragstad | i just don't want another service developer to automatically file "domain-scope" as something they don't have to ever think about | 16:20 |
lbragstad | but instead as something like "oh, yeah... we'll cross that bridge in the future" | 16:20 |
lbragstad | anything else we want to talk about for default roles? | 16:21 |
* hrybacki shakes his head | 16:21 | |
hrybacki | thanks all for the great feedback (and persistence!) | 16:21 |
lbragstad | thanks for keeping things updated | 16:22 |
lbragstad | #topic jwt | 16:22 |
*** openstack changes topic to "jwt (Meeting topic: keystone)" | 16:22 | |
lbragstad | #link https://review.openstack.org/#/c/541903/ | 16:22 |
lbragstad | this still needs feedback | 16:22 |
lbragstad | and reviews | 16:22 |
lbragstad | i'll be available during office hours if people want to ask specific questions about it | 16:23 |
lbragstad | #topic hierarchical limits | 16:23 |
*** openstack changes topic to "hierarchical limits (Meeting topic: keystone)" | 16:23 | |
lbragstad | #link https://review.openstack.org/#/c/540803/ | 16:23 |
lbragstad | #link https://review.openstack.org/#/c/549766/ | 16:23 |
lbragstad | ^ those are in the same boat | 16:23 |
lbragstad | we need reviews on them - especially from a usability perspective | 16:24 |
ayoung | looking at all three of thoes reviews | 16:24 |
lbragstad | thanks ayoung | 16:24 |
ayoung | lbragstad, on JWT | 16:24 |
ayoung | do we have a size limit> | 16:24 |
ayoung | that was what made PKI painful, and are we sure we will be OK with JWT sizes? | 16:25 |
lbragstad | we plan to | 16:25 |
lbragstad | it will be similar to fernet size-wise | 16:25 |
lbragstad | but not as compat | 16:25 |
lbragstad | compact* | 16:25 |
ayoung | I'm actually OK if we don't | 16:25 |
ayoung | really, the limit is 8k which should be attainable | 16:25 |
ayoung | that is the size of the header between Apache and mod_wsgi, and where things break down | 16:26 |
ayoung | other than that, and so long as it is optional, I like the alternative | 16:26 |
ayoung | would JWT allow for PKI signing? | 16:26 |
lbragstad | right - but i would be opposed to including unbound things in the token | 16:26 |
lbragstad | because it opens that door up | 16:26 |
lbragstad | JWT has two different paths we can exercise | 16:26 |
lbragstad | JWS and JWE, which is signing and encryption respectively | 16:27 |
*** felipemonteiro_ has quit IRC | 16:27 | |
*** felipemonteiro_ has joined #openstack-meeting-alt | 16:27 | |
lbragstad | JWE is very similar to our fernet implementation | 16:27 |
lbragstad | JWS is kinda similar to what we had with PKI | 16:27 |
ayoung | Sounds good. This review is just "move the spec to the next release" right? | 16:28 |
*** cloudran_ has joined #openstack-meeting-alt | 16:28 | |
lbragstad | yeah - but we need to figure out some details | 16:28 |
ayoung | Can we approve the move, and do the details in a follow on spec? | 16:28 |
lbragstad | and we have to update them before we can merge it... since we did some investigation and found a few things that need to be looked at | 16:28 |
ayoung | or, follow on review | 16:28 |
ayoung | makes it easier to track | 16:28 |
lbragstad | probably not, they are significant to the actual design | 16:29 |
*** cloudrancher has quit IRC | 16:29 | |
lbragstad | we'll have to talk about them at some point | 16:29 |
lbragstad | i attempted to highlight the main things i found in the reproposed version | 16:30 |
ayoung | Agreed. hrybacki our team supports JOSE, right? | 16:30 |
lbragstad | i think nkinder was saying something like that | 16:30 |
*** julim has joined #openstack-meeting-alt | 16:30 | |
lbragstad | or saying there was a connection there? | 16:31 |
hrybacki | JOSE? | 16:31 |
* gagehugo needs to step away but will be back in a bit | 16:31 | |
lbragstad | py-jose | 16:31 |
hrybacki | that doesn't ring a bell with me (but that doesn't mean we don't support it) | 16:31 |
lbragstad | #link https://pypi.python.org/pypi/python-jose/2.0.2 | 16:31 |
ayoung | So...summary: we have 3 libraries we can use that do JWT only. | 16:32 |
lbragstad | its one of the three libraries we would use to implement JWS | 16:32 |
*** jessegler has joined #openstack-meeting-alt | 16:32 | |
*** cloudrancher has joined #openstack-meeting-alt | 16:32 | |
ayoung | Pretty sure simo championed it a few years back | 16:32 |
hrybacki | now this rings a bell. Yes, someone at RH is supporting one of those libraries (but I can't recall which) | 16:32 |
*** cloudran_ has quit IRC | 16:32 | |
*** yamamoto has quit IRC | 16:33 | |
lbragstad | we won't be able to use JWCrypto because of licensing | 16:33 |
* hrybacki is asking internally | 16:33 | |
lbragstad | and that's the only one that supports JWE | 16:33 |
lbragstad | PyJWT and python-jose support JWS to date | 16:33 |
ayoung | lbragstad, so...suggest we start by driving on with JWT only, and we can look into JWE second. IIUC, it is really JWT that has taken off, and it gives us new functionality | 16:33 |
ayoung | JWE sounds like a longer term effort, but would be a good 1-to-1 replacement for Fernet | 16:34 |
ayoung | so...split the spec, and do JWT this round? | 16:34 |
lbragstad | well - JWE and JWS are subsets of the JWT specification if i understand it correctly | 16:34 |
ayoung | And see if we can get an intern to build JWE into JOSE? | 16:34 |
*** yamamoto has joined #openstack-meeting-alt | 16:34 | |
lbragstad | if we want to do JWS, we can rework the specification to include that | 16:35 |
lbragstad | and retarget JWE when we actually have an implememtation that supports it | 16:36 |
lbragstad | implementation* | 16:36 |
ayoung | I think JWT is built on JWS. I suspect the issue is symmetric versus asym, with JWT being built on Asym | 16:36 |
ayoung | lbragstad, ++ | 16:36 |
ayoung | anyone have a counterpoint? | 16:37 |
lbragstad | either way - reviews on the spec will be needed | 16:37 |
lbragstad | i linked to a few security concerns with JWT in the specification, too | 16:37 |
ayoung | OK, I have the context I need | 16:39 |
lbragstad | if anyone wants to talk jwt after the meeting, let me know | 16:39 |
lbragstad | i'll be in -keystone | 16:39 |
lbragstad | happy to answer questions and get into the details | 16:39 |
lbragstad | #topic unique domain ids for identity providers | 16:39 |
*** openstack changes topic to "unique domain ids for identity providers (Meeting topic: keystone)" | 16:39 | |
ayoung | lbragstad, so on https://review.openstack.org/#/c/549766/ that is tagged WIP. How aggressive are we in pursuing that | 16:39 |
ayoung | heh...you move too fast | 16:40 |
lbragstad | #undo | 16:40 |
openstack | Removing item from minutes: #topic unique domain ids for identity providers | 16:40 |
ayoung | :) | 16:40 |
lbragstad | backing up | 16:40 |
lbragstad | sorry | 16:40 |
lbragstad | #topic hierarchical limits | 16:40 |
*** openstack changes topic to "hierarchical limits (Meeting topic: keystone)" | 16:40 | |
lbragstad | we need reviews on it, that's for sure | 16:40 |
lbragstad | wxy|: has a specification up to | 16:40 |
ayoung | is it "either or" between those specs? | 16:40 |
wxy| | I'd like to pick it up if John has no time. | 16:40 |
lbragstad | people from cern are interested in it | 16:41 |
ayoung | so...two level is interesting | 16:41 |
*** marios has quit IRC | 16:41 | |
*** SumitNaiksatam has quit IRC | 16:41 | |
lbragstad | they're really the only people who have said "this is how we expect limits to work in a hierarchical settign" | 16:41 |
ayoung | and...I think I can say that it smells right | 16:41 |
*** SumitNaiksatam has joined #openstack-meeting-alt | 16:41 | |
wxy| | John's is focus on the first model we'll support. Mine is focus on the whole enforce flow. | 16:41 |
lbragstad | yeah ^ that's an important distinction | 16:42 |
lbragstad | because what wxy| has in his specification includes work that needs to be done regardless of the enforcement model | 16:42 |
ayoung | so...it feels like 2 specs | 16:43 |
ayoung | one which is ``include_all_children=True`` and one is the "2 level hierarchy" | 16:43 |
*** SumitNaiksatam has quit IRC | 16:44 | |
ayoung | but...they don't really say why a 2 levle limit is essential, do they? | 16:44 |
lbragstad | because the problem gets substantially harder with more than two levels | 16:45 |
ayoung | I get that...from years of discussion | 16:45 |
ayoung | but on the Nova side. a project still doesn't know its parent | 16:45 |
lbragstad | and the problem we discovered during the PTG was that we lack opinions on how things should behave with more than 2 levels | 16:45 |
ayoung | all a project is is a uuid on a vm | 16:45 |
lbragstad | right | 16:45 |
ayoung | ok...so I think if we are going to enforce 2 level project hierarchies, it has to be inside the resource backend, not limits | 16:47 |
ayoung | otherwise, what happens if you have: | 16:47 |
ayoung | A->B->C | 16:47 |
ayoung | they can still create C as a child of B, but the quota for it is not based on B | 16:47 |
ayoung | I can see saying "ok, all preexsing get grandfathered in" | 16:48 |
ayoung | but how do you keep people from making deep trees in the future? | 16:48 |
lbragstad | that's where enforcement models come it | 16:48 |
lbragstad | come in* | 16:48 |
ayoung | would it make sense to tag an "allowed depth" field on the project record in the backend? | 16:48 |
lbragstad | we already have a configuration options for that | 16:49 |
lbragstad | i think | 16:49 |
*** kumarmn has quit IRC | 16:49 | |
lbragstad | some sort of max project level | 16:49 |
ayoung | if we do, the spec should reference how to use them in conjunction | 16:50 |
*** sambetts is now known as sambetts|afk | 16:50 | |
ayoung | wxy|, can you look in to that? | 16:50 |
wxy| | sure | 16:50 |
ayoung | ++ | 16:50 |
lbragstad | well - i think we need to review his spec too :) | 16:50 |
ayoung | I'm good. | 16:50 |
ayoung | lbragstad, of course | 16:51 |
lbragstad | sounds like we have some actions to chase there | 16:51 |
lbragstad | any other questions on limits? | 16:51 |
lbragstad | #topic domains and identity provider uniqueness | 16:52 |
*** openstack changes topic to "domains and identity provider uniqueness (Meeting topic: keystone)" | 16:52 | |
lbragstad | a while back we made it so that identity providers needed to have a domain | 16:52 |
lbragstad | that was part of the shadow user work | 16:52 |
lbragstad | #link https://review.openstack.org/#/c/559676/1 | 16:53 |
lbragstad | wxy|: has a patch up to clarify that relationship | 16:53 |
lbragstad | do we have an opinion on that? | 16:53 |
*** felipemonteiro__ has joined #openstack-meeting-alt | 16:53 | |
lbragstad | do we want to have a hard constraint there? | 16:53 |
ayoung | so we are saying that an IdP has exactly one domain? | 16:53 |
lbragstad | ayoung: i think that's the question we need to answer | 16:54 |
ayoung | I wanted that years ago | 16:54 |
ayoung | I lost | 16:54 |
ayoung | OK...what is this going to break: | 16:54 |
lbragstad | i rememebr someone at the boston forum asking for the ability to associate multiple domains to a single identity provider | 16:54 |
ayoung | right now, we use Keycloak as a way to add additional providers | 16:54 |
ayoung | kinda like how CERN used ADFS | 16:55 |
ayoung | instad of changing the config on the Keystone server, we add additional providers at the WebSSO level. | 16:55 |
ayoung | My gut says that this patch is right, just trying to rationalize it | 16:55 |
*** marius1 has joined #openstack-meeting-alt | 16:55 | |
ayoung | so...we configure Apapche once, and say that /OS-FEDERATION is protected by WebSSO... | 16:56 |
ayoung | gah, that means that you cannot have any other provider....grrr | 16:56 |
lbragstad | right | 16:56 |
lbragstad | a provider would have a single domain | 16:56 |
ayoung | its backwards...if you wanted to do SAML AND KERBEROS | 16:56 |
ayoung | now, for a single IdP, we would want to map multiple protocols to the same Domain. | 16:57 |
*** thomasduval has quit IRC | 16:57 | |
*** felipemonteiro_ has quit IRC | 16:57 | |
lbragstad | three minute warning | 16:57 |
ayoung | But...from an Apache perspective, we could not have multiple protocols, which would be suboptimal. | 16:57 |
ayoung | OK, I'll chime in on that patch. I think it does not affect anything | 16:57 |
lbragstad | thanks ayoung | 16:57 |
lbragstad | i didn't want to cut you off but gagehugo has some exciting new | 16:58 |
lbragstad | news8 | 16:58 |
lbragstad | bah | 16:58 |
lbragstad | n-e-w-s-* | 16:58 |
lbragstad | nailed it | 16:58 |
lbragstad | #topic keystonemiddleware is now under VMT | 16:58 |
*** openstack changes topic to "keystonemiddleware is now under VMT (Meeting topic: keystone)" | 16:58 | |
lbragstad | gagehugo: o/ | 16:58 |
ayoung | Vermont? | 16:58 |
gagehugo | o/ i forgot i had irc on my phone | 16:58 |
gagehugo | ayoung tes | 16:59 |
gagehugo | Yes | 16:59 |
lbragstad | this has been over a year in the makig | 16:59 |
lbragstad | making* | 16:59 |
lbragstad | thanks gagehugo for pushing on this | 16:59 |
gagehugo | Np, it was an interesting experience | 16:59 |
lbragstad | #link https://review.openstack.org/#/c/555934/ | 17:00 |
lbragstad | and with that | 17:00 |
lbragstad | we're out of time | 17:00 |
lbragstad | thanks for coming folks! | 17:00 |
lbragstad | #endmeeting | 17:00 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 17:00 | |
openstack | Meeting ended Tue Apr 10 17:00:12 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 17:00 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/keystone/2018/keystone.2018-04-10-16.00.html | 17:00 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/keystone/2018/keystone.2018-04-10-16.00.txt | 17:00 |
openstack | Log: http://eavesdrop.openstack.org/meetings/keystone/2018/keystone.2018-04-10-16.00.log.html | 17:00 |
*** yamamoto has quit IRC | 17:00 | |
*** derekh has quit IRC | 17:02 | |
*** arxcruz|ruck is now known as arxcruz|off | 17:03 | |
*** julim has quit IRC | 17:03 | |
*** julim has joined #openstack-meeting-alt | 17:04 | |
*** pbourke has quit IRC | 17:05 | |
*** wxy| has quit IRC | 17:05 | |
*** vgreen has quit IRC | 17:06 | |
*** vgreen has joined #openstack-meeting-alt | 17:06 | |
*** erlon has joined #openstack-meeting-alt | 17:08 | |
*** kumarmn has joined #openstack-meeting-alt | 17:08 | |
*** yamamoto has joined #openstack-meeting-alt | 17:08 | |
*** david-lyle has joined #openstack-meeting-alt | 17:10 | |
*** kumarmn has quit IRC | 17:12 | |
*** dklyle has quit IRC | 17:14 | |
*** yamamoto has quit IRC | 17:15 | |
*** yamamoto has joined #openstack-meeting-alt | 17:15 | |
*** tesseract has quit IRC | 17:16 | |
*** sonuk has quit IRC | 17:17 | |
*** gagehugo has left #openstack-meeting-alt | 17:22 | |
*** SumitNaiksatam has joined #openstack-meeting-alt | 17:23 | |
*** dustins has quit IRC | 17:32 | |
*** cloudrancher has quit IRC | 17:45 | |
*** cloudrancher has joined #openstack-meeting-alt | 17:46 | |
*** david-lyle has quit IRC | 17:53 | |
*** SumitNaiksatam has quit IRC | 17:53 | |
*** dklyle has joined #openstack-meeting-alt | 17:54 | |
*** cloudrancher has quit IRC | 17:54 | |
*** cloudrancher has joined #openstack-meeting-alt | 17:55 | |
*** dsariel has quit IRC | 18:08 | |
*** gouthamr has joined #openstack-meeting-alt | 18:13 | |
*** pbourke has joined #openstack-meeting-alt | 18:18 | |
*** gouthamr has quit IRC | 18:19 | |
*** ianychoi has quit IRC | 18:22 | |
*** ianychoi has joined #openstack-meeting-alt | 18:23 | |
*** harlowja has joined #openstack-meeting-alt | 18:25 | |
*** oikiki has joined #openstack-meeting-alt | 18:28 | |
*** marius1 has quit IRC | 18:35 | |
*** gouthamr has joined #openstack-meeting-alt | 18:38 | |
*** ianychoi has quit IRC | 18:41 | |
*** ianychoi has joined #openstack-meeting-alt | 18:42 | |
*** gouthamr has quit IRC | 18:43 | |
*** salv-orlando has quit IRC | 18:57 | |
*** salv-orlando has joined #openstack-meeting-alt | 18:58 | |
*** salv-orlando has quit IRC | 19:02 | |
*** marius1 has joined #openstack-meeting-alt | 19:17 | |
*** dkehn_ has quit IRC | 19:26 | |
*** markvoelker_ has quit IRC | 19:41 | |
*** markvoelker has joined #openstack-meeting-alt | 19:41 | |
*** vgreen has quit IRC | 19:42 | |
*** markvoelker has quit IRC | 19:45 | |
*** jessegler has quit IRC | 19:45 | |
*** pbourke has quit IRC | 19:50 | |
*** markvoelker has joined #openstack-meeting-alt | 19:54 | |
*** salv-orlando has joined #openstack-meeting-alt | 19:58 | |
*** salv-orlando has quit IRC | 20:03 | |
*** salv-orlando has joined #openstack-meeting-alt | 20:07 | |
*** kumarmn has joined #openstack-meeting-alt | 20:08 | |
*** kumarmn has quit IRC | 20:12 | |
*** markvoelker_ has joined #openstack-meeting-alt | 20:17 | |
*** kumarmn has joined #openstack-meeting-alt | 20:19 | |
*** dsariel has joined #openstack-meeting-alt | 20:20 | |
*** markvoelker has quit IRC | 20:21 | |
*** erlon has quit IRC | 20:23 | |
*** florianf has quit IRC | 20:25 | |
*** chhavi__ has quit IRC | 20:29 | |
*** raildo has quit IRC | 20:44 | |
*** felipemonteiro__ has quit IRC | 20:56 | |
*** priteau has quit IRC | 20:59 | |
*** priteau has joined #openstack-meeting-alt | 21:00 | |
*** dustins has joined #openstack-meeting-alt | 21:01 | |
*** julim has quit IRC | 21:01 | |
*** slaweq has quit IRC | 21:02 | |
*** slaweq has joined #openstack-meeting-alt | 21:02 | |
*** priteau has quit IRC | 21:04 | |
*** slaweq has quit IRC | 21:07 | |
*** rfolco|rover is now known as rfolco|off | 21:08 | |
*** jcoufal has quit IRC | 21:16 | |
*** marius1 has quit IRC | 21:36 | |
*** edmondsw has quit IRC | 21:42 | |
*** edmondsw has joined #openstack-meeting-alt | 21:42 | |
*** edmondsw has quit IRC | 21:43 | |
*** marius1 has joined #openstack-meeting-alt | 21:49 | |
*** marius1 has quit IRC | 21:53 | |
*** yamamoto has quit IRC | 21:54 | |
*** yamamoto has joined #openstack-meeting-alt | 21:54 | |
*** dustins has quit IRC | 21:56 | |
*** priteau has joined #openstack-meeting-alt | 21:58 | |
*** dsariel has quit IRC | 21:59 | |
*** kumarmn has quit IRC | 22:03 | |
*** kumarmn has joined #openstack-meeting-alt | 22:04 | |
*** priteau has quit IRC | 22:08 | |
*** kumarmn has quit IRC | 22:09 | |
*** edmondsw has joined #openstack-meeting-alt | 22:09 | |
*** edmondsw has quit IRC | 22:10 | |
*** tpsilva has quit IRC | 22:17 | |
*** kumarmn has joined #openstack-meeting-alt | 22:18 | |
*** kumarmn has quit IRC | 22:18 | |
*** rcernin has joined #openstack-meeting-alt | 22:23 | |
*** kumarmn has joined #openstack-meeting-alt | 22:31 | |
*** yamamoto has quit IRC | 22:35 | |
*** yamamoto has joined #openstack-meeting-alt | 22:39 | |
*** kumarmn has quit IRC | 22:40 | |
*** yamamoto has quit IRC | 22:40 | |
*** oikiki has quit IRC | 22:40 | |
*** kumarmn has joined #openstack-meeting-alt | 22:40 | |
*** lbragstad has quit IRC | 22:42 | |
*** hongbin has quit IRC | 22:42 | |
*** yamahata has quit IRC | 22:45 | |
*** kumarmn has quit IRC | 22:45 | |
*** panda is now known as panda|off | 22:46 | |
*** dave-mccowan has quit IRC | 22:49 | |
*** erlon has joined #openstack-meeting-alt | 22:55 | |
*** slaweq has joined #openstack-meeting-alt | 23:03 | |
*** fnaval has quit IRC | 23:06 | |
*** slaweq has quit IRC | 23:08 | |
*** lbragstad has joined #openstack-meeting-alt | 23:09 | |
*** radeks has quit IRC | 23:21 | |
*** fnaval has joined #openstack-meeting-alt | 23:25 | |
*** HeOS has quit IRC | 23:38 | |
*** yamamoto has joined #openstack-meeting-alt | 23:40 | |
*** yamamoto has quit IRC | 23:46 | |
*** iyamahat has joined #openstack-meeting-alt | 23:52 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!