*** macza has joined #openstack-meeting-alt | 00:00 | |
*** tetsuro has joined #openstack-meeting-alt | 00:10 | |
*** igordc has joined #openstack-meeting-alt | 00:22 | |
*** macza has quit IRC | 00:24 | |
*** erlon has joined #openstack-meeting-alt | 00:42 | |
*** erlon has quit IRC | 01:05 | |
*** igordc has quit IRC | 01:05 | |
*** markvoelker has quit IRC | 01:08 | |
*** slaweq has joined #openstack-meeting-alt | 01:11 | |
*** slaweq has quit IRC | 01:15 | |
*** markvoelker has joined #openstack-meeting-alt | 02:09 | |
*** hongbin has joined #openstack-meeting-alt | 02:24 | |
*** lbragstad_503 has quit IRC | 02:38 | |
*** markvoelker has quit IRC | 02:43 | |
*** hongbin has quit IRC | 02:58 | |
*** hongbin has joined #openstack-meeting-alt | 03:01 | |
*** slaweq has joined #openstack-meeting-alt | 03:11 | |
*** apetrich has quit IRC | 03:14 | |
*** slaweq has quit IRC | 03:15 | |
*** hongbin has quit IRC | 03:16 | |
*** hongbin has joined #openstack-meeting-alt | 03:17 | |
*** hongbin has quit IRC | 03:17 | |
*** hongbin has joined #openstack-meeting-alt | 03:17 | |
*** hongbin has quit IRC | 03:20 | |
*** hongbin has joined #openstack-meeting-alt | 03:20 | |
*** hongbin has quit IRC | 03:21 | |
*** hongbin has joined #openstack-meeting-alt | 03:21 | |
*** hongbin has quit IRC | 03:22 | |
*** hongbin has joined #openstack-meeting-alt | 03:22 | |
*** rcernin has quit IRC | 03:35 | |
*** markvoelker has joined #openstack-meeting-alt | 03:41 | |
*** baojg has joined #openstack-meeting-alt | 03:48 | |
*** rcernin has joined #openstack-meeting-alt | 03:50 | |
*** lbragstad_503 has joined #openstack-meeting-alt | 03:54 | |
*** rcernin has quit IRC | 03:57 | |
*** rcernin has joined #openstack-meeting-alt | 03:58 | |
*** tetsuro_ has joined #openstack-meeting-alt | 04:09 | |
*** tetsuro has quit IRC | 04:11 | |
*** baojg has quit IRC | 04:12 | |
*** markvoelker has quit IRC | 04:13 | |
*** baojg has joined #openstack-meeting-alt | 04:18 | |
*** baojg has quit IRC | 04:23 | |
*** tetsuro has joined #openstack-meeting-alt | 04:31 | |
*** tetsuro_ has quit IRC | 04:31 | |
*** bhavikdbavishi has joined #openstack-meeting-alt | 04:56 | |
*** whoami-rajat has joined #openstack-meeting-alt | 05:04 | |
*** hongbin has quit IRC | 05:10 | |
*** markvoelker has joined #openstack-meeting-alt | 05:10 | |
*** slaweq has joined #openstack-meeting-alt | 05:11 | |
*** baojg has joined #openstack-meeting-alt | 05:11 | |
*** slaweq has quit IRC | 05:15 | |
*** baojg has quit IRC | 05:22 | |
*** sridharg has joined #openstack-meeting-alt | 05:23 | |
*** baojg has joined #openstack-meeting-alt | 05:23 | |
*** macza has joined #openstack-meeting-alt | 05:24 | |
*** macza has quit IRC | 05:29 | |
*** slaweq has joined #openstack-meeting-alt | 05:35 | |
*** markvoelker has quit IRC | 05:43 | |
*** igordc has joined #openstack-meeting-alt | 05:45 | |
*** radeks has joined #openstack-meeting-alt | 05:51 | |
*** e0ne has joined #openstack-meeting-alt | 05:52 | |
*** e0ne has quit IRC | 05:53 | |
*** lbragstad_503 has quit IRC | 05:57 | |
*** vishakha has joined #openstack-meeting-alt | 06:06 | |
*** ijw has quit IRC | 06:21 | |
*** vishalmanchanda has joined #openstack-meeting-alt | 06:34 | |
*** markvoelker has joined #openstack-meeting-alt | 06:40 | |
*** lpetrut has joined #openstack-meeting-alt | 07:12 | |
*** ccamacho has joined #openstack-meeting-alt | 07:12 | |
*** markvoelker has quit IRC | 07:14 | |
*** igordc has quit IRC | 07:27 | |
*** baojg has quit IRC | 07:36 | |
*** tssurya has joined #openstack-meeting-alt | 07:41 | |
*** baojg has joined #openstack-meeting-alt | 08:03 | |
*** macza has joined #openstack-meeting-alt | 08:05 | |
*** kopecmartin|off is now known as kopecmartin | 08:08 | |
*** macza has quit IRC | 08:09 | |
*** apetrich has joined #openstack-meeting-alt | 08:10 | |
*** jtomasek has joined #openstack-meeting-alt | 08:10 | |
*** markvoelker has joined #openstack-meeting-alt | 08:10 | |
*** markvoelker has quit IRC | 08:43 | |
*** masahito has joined #openstack-meeting-alt | 08:55 | |
*** rcernin has quit IRC | 08:56 | |
*** priteau has quit IRC | 08:56 | |
*** priteau has joined #openstack-meeting-alt | 08:57 | |
priteau | #startmeeting blazar | 09:00 |
---|---|---|
openstack | Meeting started Tue Jan 22 09:00:00 2019 UTC and is due to finish in 60 minutes. The chair is priteau. Information about MeetBot at http://wiki.debian.org/MeetBot. | 09:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 09:00 |
*** openstack changes topic to " (Meeting topic: blazar)" | 09:00 | |
openstack | The meeting name has been set to 'blazar' | 09:00 |
priteau | #topic Roll call | 09:00 |
*** openstack changes topic to "Roll call (Meeting topic: blazar)" | 09:00 | |
masahito | o/ | 09:00 |
priteau | Hi masahito | 09:01 |
tetsuro | o/ | 09:02 |
priteau | Hi tetsuro | 09:02 |
priteau | Agenda for today: stein-3 milestone and AOB | 09:03 |
priteau | #topicstein-3 milestone | 09:03 |
priteau | #topic stein-3 milestone | 09:03 |
*** openstack changes topic to "stein-3 milestone (Meeting topic: blazar)" | 09:03 | |
priteau | We have several patch series in progress | 09:04 |
priteau | I have tried to fix the Tempest API tests for resource allocation: https://review.openstack.org/#/c/586859/ | 09:05 |
priteau | There are still errors that need to be investigated | 09:05 |
priteau | While browsing the logs, I noticed some errors related to placement | 09:06 |
priteau | e.g. http://logs.openstack.org/59/586859/4/check/blazar-devstack-dsvm/e884936/logs/screen-blazar-m.txt.gz#_Jan_15_07_41_09_087968 | 09:06 |
priteau | tetsuro: Do you think you could take a look and check why we're seeing these errors? | 09:06 |
tetsuro | priteau: got it | 09:07 |
priteau | There was also a placement-related bug open: https://bugs.launchpad.net/blazar/+bug/1812642 | 09:08 |
openstack | Launchpad bug 1812642 in Blazar "Host creation failed with the error "Remote error: ResourceProviderCreationFailed Failed to create resource provider blazar_<hostname>" [Undecided,New] | 09:08 |
tetsuro | Okay. Looks like I should see that. | 09:08 |
masahito | priteau: thanks for updating the patch. | 09:09 |
priteau | We still have a few weeks to squash bugs but we need stable code near the release | 09:09 |
priteau | The new patch set from tetsuro also needs reviews: https://review.openstack.org/#/q/status:open+project:openstack/blazar+branch:master+topic:bp/no-affinity-instance-reservation | 09:12 |
masahito | I reviewed few patches in the set. | 09:14 |
priteau | Thanks masahito | 09:15 |
priteau | tetsuro: I just added you to the blazar-core and blazar-release groups :-) | 09:15 |
masahito | One question for all is should blazar accept affinity=True/None before merging the patch series? | 09:16 |
masahito | Welcome to the team :-) | 09:16 |
tetsuro | priteau: Ah, thanks. I work to merge good things. | 09:16 |
tetsuro | masa: thanks | 09:16 |
priteau | masahito: I don't understand your question | 09:17 |
masahito | The first patches removes the constraints for affinity option. But some patches on the first one have some changes for supporting affinity=True/None. | 09:18 |
tetsuro | I think I understanc your question. | 09:19 |
masahito | My question is should the constraints be removed at end of the patch series? | 09:19 |
tetsuro | I think you want me to move the constraints check and DB upgrade part from the bottom of the series to top of the series. | 09:20 |
tetsuro | which sounds fair to me. | 09:21 |
masahito | right. | 09:21 |
tetsuro | Ack, will do. | 09:21 |
priteau | Sounds good. You can also rebase on top of master while you're working on it. | 09:21 |
tetsuro | roger, captain :) | 09:22 |
priteau | masahito: Is this patch dependent on soft delete? https://review.openstack.org/#/c/585698/ | 09:23 |
masahito | yes | 09:24 |
priteau | OK, I need to revisit my soft delete patch | 09:24 |
*** tssurya has quit IRC | 09:25 | |
masahito | We can merge rest of the patch set to support allocation API and revisit it after blazar support soft-delete. | 09:25 |
priteau | Sounds good to me | 09:25 |
priteau | We need another +2 for bp/resource-allocation-api, from either Bertrand of Tetsuro | 09:26 |
tetsuro | Will revisit it tomorrow if possiblw. | 09:26 |
priteau | And also working API tests would be good :) | 09:27 |
priteau | Anything else to discuss for stein-3 patches? | 09:29 |
tetsuro | nope | 09:30 |
masahito | nothing | 09:30 |
priteau | #topic AOB | 09:31 |
*** openstack changes topic to "AOB (Meeting topic: blazar)" | 09:31 | |
priteau | Anything else to share? | 09:31 |
tetsuro | nope | 09:33 |
masahito | nope | 09:33 |
priteau | Nothing special from me either, so we can finish early this week. More time to work on patches :-) | 09:34 |
priteau | Have a good week everyone, talk to you next Tuesday! | 09:34 |
masahito | Have a good week, too! | 09:35 |
masahito | bye. | 09:35 |
priteau | #endmeeting | 09:35 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 09:35 | |
openstack | Meeting ended Tue Jan 22 09:35:50 2019 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 09:35 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/blazar/2019/blazar.2019-01-22-09.00.html | 09:35 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/blazar/2019/blazar.2019-01-22-09.00.txt | 09:35 |
openstack | Log: http://eavesdrop.openstack.org/meetings/blazar/2019/blazar.2019-01-22-09.00.log.html | 09:35 |
tetsuro | Thanks! | 09:36 |
*** tetsuro has quit IRC | 09:36 | |
*** iyamahat_ has quit IRC | 09:40 | |
*** markvoelker has joined #openstack-meeting-alt | 09:40 | |
*** derekh has joined #openstack-meeting-alt | 09:41 | |
*** bhavikdbavishi has quit IRC | 09:51 | |
*** baojg has quit IRC | 09:57 | |
*** baojg has joined #openstack-meeting-alt | 09:58 | |
*** masahito has quit IRC | 10:00 | |
*** iyamahat has joined #openstack-meeting-alt | 10:01 | |
*** erlon has joined #openstack-meeting-alt | 10:08 | |
*** baojg has quit IRC | 10:09 | |
*** markvoelker has quit IRC | 10:13 | |
*** erlon_ has joined #openstack-meeting-alt | 10:23 | |
*** e0ne has joined #openstack-meeting-alt | 10:24 | |
*** erlon has quit IRC | 10:26 | |
*** tetsuro has joined #openstack-meeting-alt | 10:34 | |
*** bhavikdbavishi has joined #openstack-meeting-alt | 10:56 | |
*** markvoelker has joined #openstack-meeting-alt | 11:10 | |
*** apetrich has quit IRC | 11:13 | |
*** sridharg has quit IRC | 11:44 | |
*** markvoelker has quit IRC | 11:44 | |
*** sridharg has joined #openstack-meeting-alt | 11:47 | |
*** radeks_ has joined #openstack-meeting-alt | 11:52 | |
*** radeks has quit IRC | 11:55 | |
*** apetrich has joined #openstack-meeting-alt | 11:57 | |
*** bhavikdbavishi has quit IRC | 12:07 | |
*** macza has joined #openstack-meeting-alt | 12:21 | |
*** ttsiouts has joined #openstack-meeting-alt | 12:22 | |
*** e0ne has quit IRC | 12:25 | |
*** macza has quit IRC | 12:26 | |
*** e0ne has joined #openstack-meeting-alt | 12:30 | |
*** bhavikdbavishi has joined #openstack-meeting-alt | 12:36 | |
*** tssurya has joined #openstack-meeting-alt | 12:38 | |
*** markvoelker has joined #openstack-meeting-alt | 12:41 | |
*** tetsuro has quit IRC | 12:53 | |
*** baojg has joined #openstack-meeting-alt | 13:00 | |
*** radeks_ has quit IRC | 13:06 | |
*** radeks_ has joined #openstack-meeting-alt | 13:06 | |
*** markvoelker has quit IRC | 13:09 | |
*** bhavikdbavishi has quit IRC | 13:17 | |
*** bhavikdbavishi has joined #openstack-meeting-alt | 13:19 | |
*** lpetrut has quit IRC | 13:20 | |
*** bhavikdbavishi has quit IRC | 13:28 | |
*** lpetrut has joined #openstack-meeting-alt | 13:28 | |
*** jcoufal has joined #openstack-meeting-alt | 13:35 | |
*** priteau has quit IRC | 13:46 | |
*** bhavikdbavishi has joined #openstack-meeting-alt | 13:51 | |
*** lbragstad_503 has joined #openstack-meeting-alt | 13:56 | |
*** lbragstad_503 is now known as lbragstad | 14:03 | |
*** e0ne has quit IRC | 14:05 | |
*** e0ne has joined #openstack-meeting-alt | 14:08 | |
*** TxGirlGeek has joined #openstack-meeting-alt | 14:18 | |
*** priteau has joined #openstack-meeting-alt | 14:21 | |
*** lbragstad has quit IRC | 14:23 | |
*** lbragstad has joined #openstack-meeting-alt | 14:26 | |
*** ttsiouts has quit IRC | 14:39 | |
*** TxGirlGeek has quit IRC | 14:39 | |
*** ttsiouts has joined #openstack-meeting-alt | 14:39 | |
*** ttsiouts has quit IRC | 14:41 | |
*** ttsiouts has joined #openstack-meeting-alt | 14:41 | |
*** efried_mlk is now known as efried | 14:45 | |
*** eggmaster is now known as eggs | 14:56 | |
*** efried1 has joined #openstack-meeting-alt | 15:00 | |
*** wxy| has joined #openstack-meeting-alt | 15:00 | |
*** efried has quit IRC | 15:01 | |
*** efried1 is now known as efried | 15:01 | |
*** hongbin has joined #openstack-meeting-alt | 15:09 | |
*** liuyulong has joined #openstack-meeting-alt | 15:13 | |
*** ijw has joined #openstack-meeting-alt | 15:28 | |
*** ccamacho has quit IRC | 15:37 | |
*** ccamacho has joined #openstack-meeting-alt | 15:37 | |
*** sridharg has quit IRC | 15:43 | |
*** lpetrut has quit IRC | 15:46 | |
*** gagehugo has joined #openstack-meeting-alt | 15:51 | |
*** dklyle has joined #openstack-meeting-alt | 15:53 | |
*** TxGirlGe_ has joined #openstack-meeting-alt | 15:55 | |
*** ayoung has joined #openstack-meeting-alt | 15:58 | |
*** efried has quit IRC | 16:00 | |
lbragstad | #startmeeting keystone | 16:00 |
openstack | Meeting started Tue Jan 22 16:00:42 2019 UTC and is due to finish in 60 minutes. The chair is lbragstad. Information about MeetBot at http://wiki.debian.org/MeetBot. | 16:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 16:00 |
*** openstack changes topic to " (Meeting topic: keystone)" | 16:00 | |
openstack | The meeting name has been set to 'keystone' | 16:00 |
lbragstad | #link https://etherpad.openstack.org/p/keystone-weekly-meeting | 16:00 |
lbragstad | agenda ^ | 16:00 |
cmurphy | o/ | 16:00 |
* cmurphy in double meetings | 16:00 | |
lbragstad | hola | 16:00 |
kmalloc | o/ | 16:01 |
wxy| | o/ | 16:01 |
*** TxGirlGe_ has quit IRC | 16:01 | |
kmalloc | hi wxy| ! | 16:01 |
kmalloc | :) | 16:01 |
wxy| | kmalloc: welcome back~ | 16:01 |
gagehugo | o/ | 16:01 |
vishakha | o/ | 16:01 |
kmalloc | thanks! :) | 16:01 |
lbragstad | we have quite a bit to get through today | 16:02 |
* ayoung mentally pronounces wxy| as Waxy. | 16:02 | |
lbragstad | so we'll go ahead and get started | 16:02 |
lbragstad | #topic Announcements | 16:02 |
*** openstack changes topic to "Announcements (Meeting topic: keystone)" | 16:02 | |
lbragstad | #info Feature proposal freeze is next week | 16:02 |
lbragstad | I *think* all features have code in review, which is good | 16:02 |
kmalloc | ayoung: so i'm hearing the boston accent with that pronunciation (at least in my head) | 16:02 |
lbragstad | #info Feature freeze is 6 weeks out | 16:02 |
kmalloc | lbragstad: nice. that is good news | 16:03 |
lbragstad | so - this one concerns me a bit mroe | 16:03 |
lbragstad | especially with gate status over the last release | 16:03 |
lbragstad | and there are a lot of things that need review | 16:03 |
kmalloc | realistically we can push things through past the freeze if it's just gate failures | 16:03 |
lbragstad | we can - but it takes away from time we spend firming up the release | 16:04 |
kmalloc | we have plenty of time on that front | 16:04 |
ayoung | wxy|, https://review.openstack.org/#/c/605235/ is easy except for updating the error message | 16:04 |
kmalloc | really | 16:04 |
lbragstad | just something to be mindful of | 16:04 |
kmalloc | if the code is really just a gate failure, it should not be subjected to feature freeze | 16:04 |
lbragstad | also - the PTL self-nomination period starts in 6 weeks | 16:05 |
ayoung | lbragstad, this your last go-round? | 16:05 |
lbragstad | if you're thinking about running and would like some more information about the role or have questions in general, please don't hesitate to reach out | 16:05 |
lbragstad | i've always been a proponent that leadership changes are healthy | 16:06 |
lbragstad | just something to think about as we get closer to that date | 16:07 |
lbragstad | #topic Previous action items | 16:07 |
*** openstack changes topic to "Previous action items (Meeting topic: keystone)" | 16:07 | |
kmalloc | people should be encouraged to run even if lance is running again | 16:07 |
lbragstad | last week we had an action item to go through the TC vision statement and red line it | 16:07 |
lbragstad | kmalloc ++ | 16:07 |
lbragstad | cmurphy put together some notes | 16:08 |
kmalloc | however, i would like to have lance let us know earlier rather than at the wire if he is planning to run (he may of course change his mind) | 16:08 |
lbragstad | #link https://etherpad.openstack.org/p/keystone-technical-vision-notes | 16:08 |
lbragstad | kmalloc at this point, i'm not planning on it | 16:08 |
kmalloc | lbragstad: thanks for the clarification | 16:08 |
lbragstad | so - i'd like for us to go through what is in that etherpad | 16:09 |
*** efried has joined #openstack-meeting-alt | 16:09 | |
lbragstad | and treat it like a discussion | 16:09 |
*** TxGirlGeek has joined #openstack-meeting-alt | 16:09 | |
ayoung | Self service is fairly close to non-existant in OpenStack | 16:09 |
lbragstad | ultimately, we'll be putting a version of that into our contributor guide | 16:10 |
ayoung | I mean, in Keystone | 16:10 |
vishakha | I also pasted some points that satisfies the pillars of cloud https://etherpad.openstack.org/p/vision | 16:10 |
lbragstad | ayoung right - keep in mind this is a vision statement | 16:10 |
ayoung | If we are going to embrace that, we need to be serious and talk it through | 16:10 |
lbragstad | and is designed to help us make decisions that enable it | 16:10 |
ayoung | A user needs to be able to create a project, and needs to be able to delete a project. And they need to have all their resources cleaned up when they do that. That is baseline for Azure an AWS, and so far from what we can do in OpenStack | 16:11 |
kmalloc | ayoung: with a drive towards a full featured idp, self service is much more important than the early-on design of keystone | 16:11 |
* knikolla will read back on the meeting logs. Getting on a plane from ROC to BOS. | 16:12 | |
lbragstad | right - the idea here is to just get agreement on the specifics of keystone's vision (since it's more detailed than what is in the openstack cloud vision) | 16:12 |
ayoung | I'm not making that connection. I mean, I agree, but how is that due to IdP? | 16:12 |
gagehugo | knikolla have a safe flight | 16:12 |
lbragstad | safe flight knikolla | 16:13 |
kmalloc | ayoung: because we can't rely on an external project to do it for us. a real full-featured service allows for at least grantable self-service in my view | 16:13 |
ayoung | So what you are saying is "now it is time to to all the things right.?" | 16:14 |
kmalloc | it may not be the default behavior (to begin with) but it shouldn't be arcane invocations to allow it to happen. | 16:14 |
ayoung | The resource cleanup is my nightmare, but OK | 16:15 |
kmalloc | if we're making big changes, don't stop short | 16:15 |
*** dims has quit IRC | 16:15 | |
kmalloc | not so much "just do it" or "do it all the things right" (we can aspire to that last one... but we might miss) | 16:15 |
lbragstad | is there anything in that etherpad that people disagree with from a vision-perspective? | 16:16 |
ayoung | Nope, it is good as far as it goes. | 16:17 |
kmalloc | it looks good to me. | 16:17 |
lbragstad | even if there is - i wouldn't be opposed to getting this into review, so we can iterate on it there | 16:17 |
lbragstad | we should make it a habit to come back to this every release and keep it in check | 16:18 |
lbragstad | but if people don't have anything major here, we can move on | 16:18 |
lbragstad | #topic Stein Features | 16:19 |
*** openstack changes topic to "Stein Features (Meeting topic: keystone)" | 16:19 | |
lbragstad | this is just a touch point based on what we've committed to for the release | 16:19 |
lbragstad | I think ayoung has an implementation up for explicit domain ids? | 16:19 |
ayoung | yeah, there is a problem with error messages so I've had to leave it for a bit | 16:20 |
ayoung | its dumb and I should have solved it already | 16:20 |
ayoung | but... | 16:20 |
lbragstad | no major blockers? | 16:20 |
*** dims has joined #openstack-meeting-alt | 16:20 | |
ayoung | https://github.com/openstack/keystone/blob/master/keystone/resource/core.py#L225 | 16:20 |
ayoung | if someone wants to swat it, I'd appreciate | 16:20 |
lbragstad | good to know | 16:20 |
ayoung | right now, it gives the wrong error, as wxy| noted | 16:21 |
lbragstad | ack | 16:21 |
ayoung | But to fix, I need to know why we got a conflict error, which is more of a rewrite than I wanted to do | 16:21 |
kmalloc | oh. huh | 16:21 |
ayoung | maybe I could make one message for both? | 16:21 |
ayoung | "Now it always says the name is duplicated even using different name but the same id." | 16:21 |
kmalloc | it should be super simple to check why there is a conflict. | 16:22 |
kmalloc | but if not, feel free to say "name or id is duplicated" | 16:22 |
kmalloc | we've done similar in the past. | 16:22 |
ayoung | I think for now I'll do that, and we can fix it after it merges and one of us goes "Duhr...it shouod have benn..." | 16:23 |
lbragstad | i'll make sure to poke at that when i review it | 16:23 |
kmalloc | i'll look at the conflict exception | 16:23 |
kmalloc | it might already be bubbled up for us. | 16:23 |
lbragstad | otherwise - no major blockers i assume? | 16:23 |
kmalloc | or the SQL-A bit(s) | 16:24 |
lbragstad | ok - moving on | 16:25 |
lbragstad | wxy| has reviews up for domain limit support | 16:25 |
lbragstad | and they are looking pretty good | 16:25 |
wxy| | lbragstad: have to refresh the patches according to your comments. | 16:26 |
*** ianychoi has joined #openstack-meeting-alt | 16:26 | |
lbragstad | afaict, i'm not seeing anything major that should block this, but more eyes would be good | 16:26 |
wxy| | I'll do that later. | 16:26 |
lbragstad | awesome - i'll take another look this week then | 16:26 |
lbragstad | cmurphy has WIP patches up for app creds | 16:27 |
lbragstad | and capability lists | 16:27 |
ayoung | W00t! | 16:27 |
lbragstad | i'm not sure if she's looking for reviews yet | 16:27 |
lbragstad | but something to keep tabs on | 16:27 |
lbragstad | or check out and play with locally | 16:28 |
lbragstad | i have a series of patches up for the JWS token provider | 16:28 |
lbragstad | and they are ready for review | 16:28 |
ayoung | cool. I'll look | 16:28 |
lbragstad | i spent last week digging into the crypto stuff and checking on some things for jwt based on the PyJWT implementation | 16:28 |
lbragstad | i've proposed updates to the specification - and rewrote the implementation accordingly | 16:29 |
lbragstad | feedback is welcome | 16:29 |
lbragstad | last feature we have a specification for is MFA receipts | 16:29 |
lbragstad | which is only waiting on documentation | 16:29 |
lbragstad | #link https://review.openstack.org/#/c/580535/ | 16:29 |
lbragstad | but that's it for formal feature work | 16:30 |
lbragstad | any questions, comments, or concerns here? | 16:30 |
lbragstad | alright - moving on | 16:31 |
lbragstad | #topic Reviews that need attention | 16:31 |
*** openstack changes topic to "Reviews that need attention (Meeting topic: keystone)" | 16:31 | |
lbragstad | does anyone have patches they need eyes on? | 16:31 |
lbragstad | outside of what we've already talked about? | 16:32 |
ayoung | Aside from that one that languished.... | 16:32 |
ayoung | I'd like you to remove the -1 from the other id based on... | 16:33 |
*** ccamacho has quit IRC | 16:33 | |
ayoung | https://review.openstack.org/#/c/605169/ | 16:34 |
lbragstad | ah - just pulled it up | 16:34 |
ayoung | There is nothing wrong with provider-to-provider calls | 16:34 |
ayoung | Providers are our own abstraction for things we can swap out, and in this case, the id as a provider is the right abstraction | 16:34 |
lbragstad | my concerns wasn't provider to provider | 16:34 |
ayoung | that was the comment | 16:34 |
lbragstad | my concern was backend to provider | 16:34 |
kmalloc | no it is a driver -> provider | 16:34 |
kmalloc | and this is an exceptional case, imo | 16:35 |
vishakha | I need some eyes on https://review.openstack.org/#/c/588211/ | 16:35 |
lbragstad | vishakha cool - i saw that get updated, i can take another look | 16:35 |
kmalloc | lbragstad: we should generally move id generation up higher. | 16:35 |
kmalloc | but it's a bit of a mess right now. | 16:36 |
lbragstad | kmalloc what makes this exceptional in your opinion? | 16:36 |
vishakha | lbragstad: Thanks | 16:36 |
kmalloc | the nature of how ids are generated in general | 16:36 |
kmalloc | in trying to keep that change as small as possible moving it up is a lot more code | 16:36 |
kmalloc | i'd rather see it as a separate cleanup | 16:36 |
kmalloc | if that makes sense. | 16:36 |
ayoung | cmurphy, I think that vishakha 's request is really for you, as he addressed you comments mostly in his last commit? | 16:36 |
kmalloc | and cover all id generation, pass ids down to the driver consistently | 16:36 |
ayoung | kmalloc, yeah, agreed. | 16:36 |
lbragstad | i need to look at the id generation code | 16:37 |
ayoung | the alternative is to change the method signature everywhere to pass in the id | 16:37 |
kmalloc | sure. just in general driver should *never* generate ids | 16:37 |
ayoung | and...there is not much benefit to that. | 16:37 |
kmalloc | we should fix that, and the manager should always pass down the id. | 16:37 |
kmalloc | explicitly everywhere | 16:37 |
ayoung | Exactly, so it is better to get the IDs from the id generator directly. | 16:37 |
vishakha | ayoung: its she not he :) | 16:37 |
kmalloc | but that is a bigger change. | 16:37 |
ayoung | vishakha, my apologies | 16:38 |
ayoung | and...good to meet yoou! | 16:38 |
cmurphy | ayoung: yes i'll take a look soon | 16:38 |
* ayoung has been out of it for too long | 16:38 | |
vishakha | ayoung: same here | 16:38 |
ayoung | vishakha, you coming to Denver? | 16:38 |
* kmalloc is happy to return with new faces at the meeting | 16:38 | |
kmalloc | oh man, that's coming up soon isn't it? | 16:38 |
*** e0ne has quit IRC | 16:38 | |
ayoung | ayuh | 16:38 |
kmalloc | i need to make sure i have travel funding for that and book it/tickets | 16:38 |
vishakha | ayoung: I hope a session of mine is selected. Then I will be there for sure | 16:39 |
ayoung | ++ | 16:39 |
*** e0ne has joined #openstack-meeting-alt | 16:39 | |
kmalloc | vishakha: well good luck! hope your session is selected and it makes it easier to join us :) | 16:39 |
ayoung | kmalloc, ROAD TRIP...Oh Wait, you are on the wrong coast, damnit | 16:39 |
vishakha | kmalloc: thanks. Nice to meet you too | 16:39 |
kmalloc | ayoung: fly to seattle, hope brie will join and we can drive again :P | 16:39 |
lbragstad | ayoung i'll take another look - i need to see the id generation stuff | 16:40 |
kmalloc | but we only have 1 car now... so if she doesn't join... anyway... talk later. | 16:40 |
ayoung | lbragstad, sounds good. | 16:40 |
lbragstad | ayoung thanks for bringing it up again | 16:40 |
lbragstad | anyone else have reviews that need attention besides ayoung and vishakha ? | 16:40 |
ayoung | lbragstad, Iguess the other thing is to fix this one | 16:41 |
ayoung | https://review.openstack.org/#/c/623117/ | 16:41 |
* lbragstad nods | 16:41 | |
ayoung | that was a quick spike to externalize the id generation | 16:42 |
lbragstad | ok - looks like it needs some cleanup, but we're targeting it for stein? | 16:43 |
ayoung | lbragstad, that is the alternative way. I would rather not | 16:43 |
lbragstad | oh | 16:43 |
ayoung | I think some of those test failures are significant | 16:43 |
lbragstad | i'll keep tabs on it and revisit it if you come back to it | 16:44 |
ayoung | But we can do that longer term if we want to externalize ALL of the Id generation like kmalloc suggested | 16:44 |
lbragstad | got it | 16:44 |
kmalloc | and we should. | 16:44 |
kmalloc | but that should be a consistency fix across all of keystone | 16:44 |
lbragstad | ok | 16:44 |
ayoung | Lets put that on the Train then | 16:44 |
ayoung | not in the Stein | 16:44 |
ayoung | :) | 16:44 |
kmalloc | ++ | 16:45 |
kmalloc | damn you beat me to the joke :P | 16:45 |
kmalloc | i was typing the same exact thing. | 16:45 |
lbragstad | i have some reviews i'd like to get feedback on | 16:45 |
lbragstad | #link https://review.openstack.org/#/q/status:open+project:openstack/keystone+branch:master+topic:implement-default-roles | 16:45 |
ayoung | "For all our mutual experience our separate conclusions are the same." | 16:45 |
lbragstad | most of those are trying to address #link https://bugs.launchpad.net/keystone/+bugs?field.tag=policy | 16:45 |
ayoung | Wow | 16:46 |
lbragstad | i'm hesitant to push more until some of those start merging | 16:46 |
lbragstad | but the majority of them are strings of 5 - 6 patches | 16:46 |
ayoung | lbragstad, I'll commit to moving them along | 16:46 |
*** jaosorior has joined #openstack-meeting-alt | 16:47 | |
lbragstad | if anyone has questions - i'm available to help walk folks through the approach | 16:47 |
lbragstad | vishakha has been helping on that front, too | 16:47 |
ayoung | I should be able to help there | 16:48 |
lbragstad | we have a few topics left | 16:48 |
vishakha | lbragstad: I updated the role assignment patch too. https://review.openstack.org/#/c/609210/. You can have a look | 16:48 |
lbragstad | vishakha will do - thanks! | 16:48 |
lbragstad | if that's it for reviews, we can move on | 16:48 |
lbragstad | #topic Launchpad | 16:48 |
*** openstack changes topic to "Launchpad (Meeting topic: keystone)" | 16:48 | |
lbragstad | I haven't been doing a good job of keeping launchpad in check this release | 16:48 |
lbragstad | i'll be trying to get things back in order over the next week or two | 16:49 |
lbragstad | really just going through and updating closed bugs with appropriate milestones | 16:49 |
lbragstad | and doing triage | 16:49 |
lbragstad | if that's a process that interests you, just ping me | 16:49 |
lbragstad | #topic Athenz plugin update | 16:49 |
*** openstack changes topic to "Athenz plugin update (Meeting topic: keystone)" | 16:49 | |
ayoung | lbragstad, why is create_user system admin and not domain admin? | 16:49 |
*** aning has joined #openstack-meeting-alt | 16:50 | |
* ayoung too slow | 16:50 | |
lbragstad | ayoung sorry - lets sync after | 16:50 |
ayoung | ++ | 16:50 |
lbragstad | james, from oath, it currently swamped in other things | 16:50 |
lbragstad | he was going to take a stab at drafting a spec for the athenz plugin oath open-sourced | 16:50 |
ayoung | I got it anyway | 16:50 |
lbragstad | today in the edge call, ildikov suggested that we consider drafting something and having him review it instead | 16:51 |
lbragstad | i put this on the agenda to see if there are other interested parties | 16:51 |
ayoung | knikolla has nothing better to do now | 16:51 |
lbragstad | ftr - this would clearly be something we would target for Train | 16:52 |
ayoung | What would be the use case? | 16:52 |
ayoung | adding Oath to an existing deployment. or making it easier for Yahoo to work with OpenStack? | 16:52 |
lbragstad | athenz is an identity provider that issues tokens and x.509 certificates | 16:52 |
ayoung | That is all Federation, tho | 16:53 |
lbragstad | right | 16:53 |
lbragstad | the general idea is to investigate generalizing the shadow mapping work we have in keystone | 16:53 |
lbragstad | and instead of only having those properties come from SAML | 16:53 |
lbragstad | they could come from something like a certificate | 16:54 |
cmurphy | i did some investigation and keystone is already capable of this without any changes | 16:54 |
lbragstad | cmurphy oh - nice! | 16:54 |
cmurphy | https://docs.openstack.org/keystone/latest/admin/external-authentication.html | 16:54 |
*** ttsiouts has quit IRC | 16:55 | |
*** ttsiouts has joined #openstack-meeting-alt | 16:55 | |
lbragstad | cmurphy would we still need a way to send attributes from a cert to the shadow mapping? | 16:55 |
cmurphy | we need to update our docs because the meat of how it works is in here https://docs.openstack.org/keystone/latest/admin/configure_tokenless_x509.html except that tokenless auth itself doesn't work that well right now | 16:56 |
ayoung | any attributes in an assertion can show up in Keystone if the module can pass them | 16:56 |
cmurphy | the mapping picks up the attributes from mod_ssl | 16:56 |
cmurphy | so this helps for athenz but it doesn't help at all for edge because you still need to auth with keystone | 16:57 |
ayoung | tokenless was such a good idea | 16:59 |
ayoung | we need to use that like, everywhere | 16:59 |
cmurphy | we can talk about it more after the meeting | 16:59 |
lbragstad | right now, athenz wraps the shadow mapping work we did, but what we have today with x.509 isn't a drop-in replacement? | 16:59 |
ayoung | So...assuming wee fix tokenless, what do we need to do? | 17:00 |
cmurphy | lbragstad: i think it is a drop-in replacement for what they do | 17:00 |
cmurphy | ayoung: https://bugs.launchpad.net/keystone/+bug/1811605 firt | 17:00 |
openstack | Launchpad bug 1811605 in OpenStack Identity (keystone) "Tokenless authentication is broken" [Undecided,New] | 17:00 |
cmurphy | first* | 17:00 |
*** ttsiouts has quit IRC | 17:00 | |
lbragstad | ack - let's move to -keystone | 17:00 |
cmurphy | and then it seems like the middleware component was never fully working | 17:00 |
cmurphy | or i couldn't get it to work | 17:00 |
lbragstad | thanks for the time, everyone! | 17:00 |
*** efried has quit IRC | 17:00 | |
lbragstad | #endmeeting | 17:01 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 17:01 | |
openstack | Meeting ended Tue Jan 22 17:01:01 2019 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 17:01 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/keystone/2019/keystone.2019-01-22-16.00.html | 17:01 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/keystone/2019/keystone.2019-01-22-16.00.txt | 17:01 |
openstack | Log: http://eavesdrop.openstack.org/meetings/keystone/2019/keystone.2019-01-22-16.00.log.html | 17:01 |
*** wxy| has quit IRC | 17:01 | |
*** panda is now known as panda|off | 17:02 | |
*** macza has joined #openstack-meeting-alt | 17:02 | |
*** e0ne has quit IRC | 17:02 | |
*** macza_ has joined #openstack-meeting-alt | 17:06 | |
*** macza has quit IRC | 17:07 | |
*** radeks__ has joined #openstack-meeting-alt | 17:08 | |
*** radeks_ has quit IRC | 17:10 | |
*** ccamacho has joined #openstack-meeting-alt | 17:16 | |
*** ayoung has left #openstack-meeting-alt | 17:20 | |
*** igordc has joined #openstack-meeting-alt | 17:28 | |
*** radeks__ has quit IRC | 17:33 | |
*** igordc has quit IRC | 17:39 | |
*** radeks has joined #openstack-meeting-alt | 17:47 | |
*** efried has joined #openstack-meeting-alt | 17:49 | |
*** erlon_ has quit IRC | 17:49 | |
*** radeks has quit IRC | 17:50 | |
*** ccamacho has quit IRC | 17:51 | |
*** bhavikdbavishi has quit IRC | 17:55 | |
*** derekh has quit IRC | 18:00 | |
*** priteau has quit IRC | 18:05 | |
*** rdopiera has quit IRC | 18:19 | |
*** rdopiera has joined #openstack-meeting-alt | 18:22 | |
*** yamahata has quit IRC | 18:22 | |
*** iyamahat has quit IRC | 18:22 | |
*** iyamahat has joined #openstack-meeting-alt | 18:36 | |
*** kopecmartin is now known as kopecmartin|off | 18:38 | |
*** gagehugo has left #openstack-meeting-alt | 18:47 | |
*** TxGirlGeek has quit IRC | 18:48 | |
*** yamahata has joined #openstack-meeting-alt | 18:55 | |
*** baojg has quit IRC | 18:57 | |
*** baojg has joined #openstack-meeting-alt | 18:57 | |
*** baojg has quit IRC | 18:58 | |
*** baojg has joined #openstack-meeting-alt | 18:58 | |
*** baojg has quit IRC | 18:58 | |
*** baojg has joined #openstack-meeting-alt | 18:59 | |
*** jesusaur has quit IRC | 18:59 | |
*** baojg has quit IRC | 18:59 | |
*** baojg has joined #openstack-meeting-alt | 18:59 | |
*** TxGirlGeek has joined #openstack-meeting-alt | 18:59 | |
*** baojg has quit IRC | 19:00 | |
*** baojg has joined #openstack-meeting-alt | 19:00 | |
*** baojg has quit IRC | 19:01 | |
*** baojg has joined #openstack-meeting-alt | 19:01 | |
*** baojg has quit IRC | 19:02 | |
*** ianw_pto is now known as ianw | 19:02 | |
*** baojg has joined #openstack-meeting-alt | 19:02 | |
*** baojg has quit IRC | 19:02 | |
*** baojg has joined #openstack-meeting-alt | 19:03 | |
*** baojg has quit IRC | 19:04 | |
*** baojg has joined #openstack-meeting-alt | 19:04 | |
*** baojg has quit IRC | 19:05 | |
*** baojg has joined #openstack-meeting-alt | 19:05 | |
*** baojg has quit IRC | 19:06 | |
*** iyamahat has quit IRC | 19:06 | |
*** baojg has joined #openstack-meeting-alt | 19:06 | |
*** iyamahat has joined #openstack-meeting-alt | 19:06 | |
*** baojg has quit IRC | 19:06 | |
*** e0ne has joined #openstack-meeting-alt | 19:07 | |
*** baojg has joined #openstack-meeting-alt | 19:07 | |
*** baojg has quit IRC | 19:08 | |
*** baojg has joined #openstack-meeting-alt | 19:08 | |
*** baojg has quit IRC | 19:09 | |
*** baojg has joined #openstack-meeting-alt | 19:09 | |
*** baojg has quit IRC | 19:09 | |
*** baojg has joined #openstack-meeting-alt | 19:10 | |
*** baojg has quit IRC | 19:10 | |
*** baojg has joined #openstack-meeting-alt | 19:11 | |
*** baojg has quit IRC | 19:11 | |
*** TxGirlGeek has quit IRC | 19:11 | |
*** baojg has joined #openstack-meeting-alt | 19:11 | |
*** baojg has quit IRC | 19:12 | |
*** baojg has joined #openstack-meeting-alt | 19:13 | |
*** baojg has quit IRC | 19:13 | |
*** TxGirlGeek has joined #openstack-meeting-alt | 19:14 | |
*** baojg has joined #openstack-meeting-alt | 19:14 | |
*** baojg has quit IRC | 19:14 | |
*** baojg has joined #openstack-meeting-alt | 19:15 | |
*** baojg has quit IRC | 19:15 | |
*** baojg has joined #openstack-meeting-alt | 19:15 | |
*** baojg has quit IRC | 19:16 | |
*** baojg has joined #openstack-meeting-alt | 19:16 | |
*** baojg has quit IRC | 19:17 | |
*** baojg has joined #openstack-meeting-alt | 19:17 | |
*** baojg has quit IRC | 19:17 | |
*** baojg has joined #openstack-meeting-alt | 19:19 | |
*** baojg has quit IRC | 19:20 | |
*** jesusaur has joined #openstack-meeting-alt | 19:25 | |
*** gryf has left #openstack-meeting-alt | 19:29 | |
*** tssurya has quit IRC | 19:36 | |
*** e0ne has quit IRC | 19:42 | |
*** iyamahat_ has joined #openstack-meeting-alt | 19:43 | |
*** TxGirlGeek has quit IRC | 19:46 | |
*** iyamahat has quit IRC | 19:46 | |
*** iyamahat__ has joined #openstack-meeting-alt | 19:48 | |
*** iyamahat_ has quit IRC | 19:51 | |
*** whoami-rajat has quit IRC | 19:52 | |
*** diablo_rojo has joined #openstack-meeting-alt | 19:56 | |
*** TxGirlGeek has joined #openstack-meeting-alt | 19:58 | |
*** diablo_rojo has quit IRC | 20:05 | |
*** dims has quit IRC | 20:40 | |
*** dims has joined #openstack-meeting-alt | 20:42 | |
*** jcoufal has quit IRC | 20:47 | |
*** dims has quit IRC | 20:50 | |
*** dave-mccowan has joined #openstack-meeting-alt | 20:51 | |
*** isq has joined #openstack-meeting-alt | 20:52 | |
*** dims has joined #openstack-meeting-alt | 20:52 | |
*** baojg has joined #openstack-meeting-alt | 21:21 | |
*** baojg has quit IRC | 21:27 | |
*** efried has quit IRC | 21:30 | |
*** efried has joined #openstack-meeting-alt | 21:30 | |
*** dklyle has quit IRC | 21:39 | |
*** priteau has joined #openstack-meeting-alt | 21:42 | |
*** priteau has quit IRC | 22:08 | |
*** rcernin has joined #openstack-meeting-alt | 22:10 | |
*** slaweq has quit IRC | 22:12 | |
*** rcernin has quit IRC | 22:17 | |
*** rcernin has joined #openstack-meeting-alt | 22:19 | |
*** TxGirlGeek has quit IRC | 22:24 | |
*** TxGirlGe_ has joined #openstack-meeting-alt | 22:24 | |
*** slaweq has joined #openstack-meeting-alt | 22:29 | |
*** TxGirlGe_ has quit IRC | 22:31 | |
*** slaweq has quit IRC | 22:33 | |
*** lifeless_ is now known as lifeless | 22:34 | |
*** TxGirlGeek has joined #openstack-meeting-alt | 22:40 | |
*** baojg has joined #openstack-meeting-alt | 22:52 | |
*** efried has quit IRC | 22:53 | |
*** TxGirlGeek has quit IRC | 22:59 | |
*** slaweq has joined #openstack-meeting-alt | 23:00 | |
*** TxGirlGeek has joined #openstack-meeting-alt | 23:03 | |
*** slaweq has quit IRC | 23:05 | |
*** TxGirlGeek has quit IRC | 23:35 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!