*** ijw_ has quit IRC | 00:32 | |
*** Adri2000 has joined #openstack-meeting-alt | 00:46 | |
*** ijw has joined #openstack-meeting-alt | 00:47 | |
*** tetsuro has joined #openstack-meeting-alt | 01:15 | |
*** rfolco has quit IRC | 01:30 | |
*** rfolco has joined #openstack-meeting-alt | 01:38 | |
*** rfolco has quit IRC | 01:39 | |
*** rfolco has joined #openstack-meeting-alt | 01:40 | |
*** gyee has quit IRC | 01:48 | |
*** rfolco has quit IRC | 02:07 | |
*** yaawang has quit IRC | 02:36 | |
*** yaawang has joined #openstack-meeting-alt | 02:36 | |
*** macz has quit IRC | 02:37 | |
*** ijw has quit IRC | 03:03 | |
*** ijw has joined #openstack-meeting-alt | 03:05 | |
*** apetrich has quit IRC | 03:09 | |
*** ijw has quit IRC | 03:09 | |
*** ijw has joined #openstack-meeting-alt | 03:30 | |
*** ijw has quit IRC | 03:30 | |
*** ijw has joined #openstack-meeting-alt | 03:30 | |
*** macz has joined #openstack-meeting-alt | 03:46 | |
*** macz has quit IRC | 03:51 | |
*** tetsuro has quit IRC | 03:58 | |
*** yaawang has quit IRC | 04:01 | |
*** yaawang has joined #openstack-meeting-alt | 04:02 | |
*** tetsuro has joined #openstack-meeting-alt | 04:04 | |
*** tetsuro has quit IRC | 04:05 | |
*** tetsuro has joined #openstack-meeting-alt | 04:16 | |
*** baojg has quit IRC | 04:17 | |
*** tetsuro has quit IRC | 04:19 | |
*** tetsuro_ has joined #openstack-meeting-alt | 04:19 | |
*** baojg has joined #openstack-meeting-alt | 04:19 | |
*** tetsuro_ has quit IRC | 04:23 | |
*** tetsuro has joined #openstack-meeting-alt | 04:23 | |
*** igordc has quit IRC | 04:34 | |
*** tetsuro has quit IRC | 04:36 | |
*** tetsuro has joined #openstack-meeting-alt | 05:39 | |
*** tetsuro has quit IRC | 05:44 | |
*** ijw has quit IRC | 05:52 | |
*** links has joined #openstack-meeting-alt | 05:52 | |
*** tetsuro has joined #openstack-meeting-alt | 05:57 | |
*** ijw has joined #openstack-meeting-alt | 06:01 | |
*** ijw has quit IRC | 06:06 | |
*** ircuser-1 has joined #openstack-meeting-alt | 06:19 | |
*** jtomasek has joined #openstack-meeting-alt | 06:43 | |
*** ccamacho has quit IRC | 06:43 | |
*** yaawang has quit IRC | 06:47 | |
*** yaawang has joined #openstack-meeting-alt | 06:48 | |
*** brault has joined #openstack-meeting-alt | 07:05 | |
*** tetsuro_ has joined #openstack-meeting-alt | 07:06 | |
*** tetsuro has quit IRC | 07:08 | |
*** apetrich has joined #openstack-meeting-alt | 07:10 | |
*** masahito has joined #openstack-meeting-alt | 07:19 | |
*** masahito has quit IRC | 07:25 | |
*** masahito has joined #openstack-meeting-alt | 07:25 | |
*** masahito_ has joined #openstack-meeting-alt | 07:28 | |
*** masahito has quit IRC | 07:28 | |
*** masahito_ has quit IRC | 07:44 | |
*** slaweq has joined #openstack-meeting-alt | 07:45 | |
*** yaawang has quit IRC | 07:46 | |
*** masahito has joined #openstack-meeting-alt | 07:46 | |
*** masahito has quit IRC | 07:48 | |
*** yaawang has joined #openstack-meeting-alt | 07:48 | |
*** masahito has joined #openstack-meeting-alt | 07:48 | |
*** apetrich has quit IRC | 07:51 | |
*** masahito has quit IRC | 07:53 | |
*** apetrich has joined #openstack-meeting-alt | 07:53 | |
*** masahito has joined #openstack-meeting-alt | 07:59 | |
*** gibi has joined #openstack-meeting-alt | 08:03 | |
*** skatsaounis_ has joined #openstack-meeting-alt | 08:04 | |
*** masahito has quit IRC | 08:07 | |
*** masahito has joined #openstack-meeting-alt | 08:07 | |
*** masahito has quit IRC | 08:09 | |
*** masahito has joined #openstack-meeting-alt | 08:09 | |
*** macz has joined #openstack-meeting-alt | 08:12 | |
*** tesseract has joined #openstack-meeting-alt | 08:16 | |
*** macz has quit IRC | 08:16 | |
*** tmazur has joined #openstack-meeting-alt | 08:19 | |
*** ccamacho has joined #openstack-meeting-alt | 08:27 | |
*** masahito has quit IRC | 08:40 | |
*** masahito has joined #openstack-meeting-alt | 08:41 | |
*** masahito has quit IRC | 08:44 | |
*** masahito has joined #openstack-meeting-alt | 08:45 | |
*** skatsaounis_ has quit IRC | 09:07 | |
*** e0ne has joined #openstack-meeting-alt | 09:08 | |
*** skatsaounis_ has joined #openstack-meeting-alt | 09:24 | |
*** gshippey has joined #openstack-meeting-alt | 09:25 | |
*** yaawang has quit IRC | 09:45 | |
*** yaawang has joined #openstack-meeting-alt | 09:46 | |
*** rcernin has quit IRC | 10:06 | |
*** masahito has quit IRC | 10:32 | |
*** lpetrut has joined #openstack-meeting-alt | 10:34 | |
*** derekh has joined #openstack-meeting-alt | 10:35 | |
*** skatsaounis_ has quit IRC | 11:01 | |
*** skatsaounis_ has joined #openstack-meeting-alt | 11:02 | |
*** vishalmanchanda has joined #openstack-meeting-alt | 11:34 | |
*** lpetrut has quit IRC | 11:53 | |
*** raildo has joined #openstack-meeting-alt | 11:56 | |
*** rfolco has joined #openstack-meeting-alt | 12:12 | |
*** rfolco has quit IRC | 12:23 | |
*** rfolco has joined #openstack-meeting-alt | 12:24 | |
*** macz has joined #openstack-meeting-alt | 12:33 | |
*** macz has quit IRC | 12:38 | |
*** skatsaounis_ has quit IRC | 13:35 | |
*** lpetrut has joined #openstack-meeting-alt | 13:40 | |
*** skatsaounis_ has joined #openstack-meeting-alt | 13:52 | |
*** dave-mccowan has joined #openstack-meeting-alt | 14:02 | |
*** liuyulong has joined #openstack-meeting-alt | 14:15 | |
*** jhesketh has quit IRC | 14:27 | |
*** jhesketh has joined #openstack-meeting-alt | 14:28 | |
*** dave-mccowan has quit IRC | 14:42 | |
*** smyers has quit IRC | 14:47 | |
*** igordc has joined #openstack-meeting-alt | 14:57 | |
*** igordc has quit IRC | 15:17 | |
*** skatsaounis_ has quit IRC | 15:21 | |
*** munimeha1 has joined #openstack-meeting-alt | 15:22 | |
*** igordc has joined #openstack-meeting-alt | 15:25 | |
*** igordc has quit IRC | 15:30 | |
*** tesseract has quit IRC | 15:37 | |
*** gagehugo has joined #openstack-meeting-alt | 15:40 | |
*** jtomasek has quit IRC | 15:42 | |
*** tesseract has joined #openstack-meeting-alt | 15:48 | |
*** diablo_rojo has joined #openstack-meeting-alt | 15:48 | |
*** diablo_rojo has quit IRC | 15:49 | |
*** diablo_rojo has joined #openstack-meeting-alt | 15:49 | |
cmurphy | #startmeeting keystone | 16:00 |
---|---|---|
openstack | Meeting started Tue Dec 3 16:00:11 2019 UTC and is due to finish in 60 minutes. The chair is cmurphy. Information about MeetBot at http://wiki.debian.org/MeetBot. | 16:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 16:00 |
*** openstack changes topic to " (Meeting topic: keystone)" | 16:00 | |
openstack | The meeting name has been set to 'keystone' | 16:00 |
gagehugo | o/ | 16:00 |
cmurphy | #link https://etherpad.openstack.org/p/keystone-weekly-meeting agenda | 16:00 |
lbragstad | o/ | 16:00 |
knikolla | o/ | 16:00 |
bnemec | o/ | 16:00 |
cmurphy | I didn't have to make up the agenda today \o/ | 16:02 |
cmurphy | #topic review requests | 16:02 |
*** openstack changes topic to "review requests (Meeting topic: keystone)" | 16:02 | |
cmurphy | there are two already in the agenda | 16:02 |
cmurphy | #link https://review.opendev.org/#/c/687990/ Stop adding entry in local_user while updating ephemerals | 16:02 |
cmurphy | #link https://review.opendev.org/#/c/693838/ | 16:03 |
cmurphy | Update OIDC documentation to handle bearer access token flow | 16:03 |
cmurphy | #undo | 16:03 |
openstack | Removing item from minutes: #link https://review.opendev.org/#/c/693838/ | 16:03 |
cmurphy | #link https://review.opendev.org/#/c/693838/ | 16:03 |
cmurphy | >.> | 16:03 |
cmurphy | #undo | 16:03 |
openstack | Removing item from minutes: #link https://review.opendev.org/#/c/693838/ | 16:03 |
cmurphy | #link https://review.opendev.org/#/c/693838/ | 16:03 |
cmurphy | i give up | 16:03 |
* knikolla gives cmurphy a cup of coffee | 16:04 | |
lbragstad | i was just going to say - it's early | 16:04 |
cmurphy | thanks :) | 16:04 |
cmurphy | this is already my second hour of meetings | 16:04 |
lbragstad | 0.o | 16:05 |
cmurphy | i'll check out the oidc doc change soon | 16:05 |
cmurphy | any comment on these changes? any other review requests? | 16:05 |
cmurphy | #topic OpenID Connect Authentication Plugin | 16:09 |
*** openstack changes topic to "OpenID Connect Authentication Plugin (Meeting topic: keystone)" | 16:09 | |
cmurphy | I don't think aloga is here | 16:09 |
cmurphy | I wonder if knikolla has context for this? | 16:09 |
knikolla | i had a conversation with them about a week ago | 16:09 |
knikolla | they weren't able to satisfy their use case with the current way that oidc works with apache | 16:10 |
knikolla | hence needing a custom plugin | 16:10 |
knikolla | i'll hunt for an irc log | 16:11 |
knikolla | #link http://eavesdrop.openstack.org/irclogs/%23openstack-keystone/%23openstack-keystone.2019-11-26.log.html#t2019-11-26T16:52:49 | 16:12 |
vishakha | o/ | 16:12 |
cmurphy | if the redirect behavior changed when flask was introduced that sounds like a regression that should be fixed, no argument there | 16:12 |
knikolla | agree on that. | 16:13 |
cmurphy | i can comment on the bug | 16:16 |
cmurphy | not sure there's anything else to discuss on this? | 16:16 |
*** aloga has joined #openstack-meeting-alt | 16:16 | |
aloga | howdy | 16:16 |
cmurphy | aloga: hi | 16:17 |
aloga | cmurphy: hello | 16:17 |
cmurphy | we were just discussing your topic | 16:17 |
aloga | sorry, I did not realise the time | 16:17 |
cmurphy | it sounded like a regression was introduced when we moved to flask, i have no objection to fixing the regression | 16:17 |
cmurphy | would be good to have more information, like versions where it worked and didn't work and steps to reproduce | 16:18 |
aloga | cmurphy: the point is that IIRC, it was possible to raise HTTP errors in the past, and those were rendered properly to the users | 16:18 |
aloga | so for instance a redirect would actually redirect the user | 16:18 |
aloga | cmurphy: hmm, I would need to check with my team, as I was not directly involved | 16:18 |
*** gyee has joined #openstack-meeting-alt | 16:19 | |
*** dave-mccowan has joined #openstack-meeting-alt | 16:19 | |
aloga | cmurphy: this is useful for instance for an OpenID Connect plugin for Keystone, as redirects are required | 16:19 |
cmurphy | aloga: was there some concern that we wouldn't want the bugfix? | 16:19 |
aloga | cmurphy: in order to complete the flow, etc. | 16:19 |
aloga | cmurphy: sorry? I do not understand | 16:20 |
cmurphy | aloga: i'm just wondering what we need to discuss about this, assuming that the bug is valid and reproducible then the answer seems straightforward | 16:21 |
knikolla | i asked them to add the topic on the agenda to get a better feel of if there was something else we could do to provide better oidc support | 16:21 |
aloga | cmurphy: I do not know, I was told to add this to the agenda | 16:21 |
knikolla | since deployments with that experience are hard to come by | 16:21 |
aloga | cmurphy: but I think this was because OpenID connect was mentioned | 16:22 |
aloga | I can try to make a rationale | 16:22 |
aloga | I am working in an environment (European Open Science Cloud) where several OpenStack sites are federated | 16:23 |
aloga | identity is based on OpenID, with a myriad of different IdPs | 16:23 |
aloga | the current (Apache + mod_oidc + Keystone) is difficult and cumbersome to manage because of several reasons | 16:24 |
aloga | OpenStack CLI is an OIDC client itself (i.e. it requires a client id and secret) | 16:24 |
aloga | the CLI uses Oauth2 rather than OIDC, therefore there might be different claims at the server, as the Oauth2 introspection and the OIDC userinfo endpoint return different information | 16:25 |
aloga | for operators, the configuration is done on Apache, and not on Keystone | 16:26 |
aloga | and, last but not least, the mod_oidc does not allow to use several Oauth2 idps per server (it allows several OIDC though) | 16:26 |
aloga | therefore we levearated the federated auth code in Keystone to build a native plugin (we have a prototype) | 16:26 |
aloga | but, in order to get it fully working, we need to redirect from Keystone | 16:27 |
knikolla | is there anything else that you need besides redirect functionality? | 16:27 |
aloga | (i.e. 302) | 16:27 |
aloga | knikolla: nope | 16:27 |
aloga | knikolla: actually the changes are minimal | 16:28 |
knikolla | cool | 16:28 |
cmurphy | aloga: does this tie into https://review.opendev.org/373983 ? | 16:29 |
aloga | cmurphy: yes, indeed | 16:29 |
aloga | cmurphy: that was the seed of all of this | 16:29 |
aloga | cmurphy: I guess that the spec is better explained | 16:29 |
cmurphy | okay, so at a minimum we can fix the flask bug and get your external auth plugin working | 16:34 |
aloga | I know that several of these things can be alleviated by implementing an IdP proxy, as some providers or national infrastructures do, but sometimes this is not an option | 16:34 |
aloga | cmurphy: that would be awesome | 16:34 |
cmurphy | we should also revisit this spec and maybe merge it to the backlog | 16:35 |
cmurphy | tbh i don't know why it didn't get any feedback since 2018 | 16:35 |
aloga | cmurphy: tbh I could not follow it so closely as I would have liked to | 16:35 |
cmurphy | aloga: would you want to continue driving it now? | 16:37 |
aloga | cmurphy: yes | 16:37 |
cmurphy | okay, team please review https://review.opendev.org/373983 and provide feedback | 16:38 |
*** lpetrut has quit IRC | 16:38 | |
cmurphy | thanks aloga | 16:39 |
cmurphy | anything else on this? | 16:39 |
aloga | cmurphy, knikolla thanks | 16:39 |
cmurphy | #topic next up for bug duty | 16:40 |
*** openstack changes topic to "next up for bug duty (Meeting topic: keystone)" | 16:40 | |
cmurphy | #link https://etherpad.openstack.org/p/keystone-l1-duty | 16:40 |
cmurphy | looks like gagehugo is up for bug duty this week starting today, gagehugo still up for it? | 16:41 |
gagehugo | cmurphy: sure | 16:41 |
cmurphy | following the rotation i'll be up next unless anyone else wants to take it ;) | 16:41 |
knikolla | I was going to offer too. | 16:41 |
knikolla | But I can go the week after that. | 16:42 |
cmurphy | knikolla: by all means :) | 16:42 |
cmurphy | #topic office hours | 16:43 |
*** openstack changes topic to "office hours (Meeting topic: keystone)" | 16:43 | |
cmurphy | I think this is about our policy testing sync up after this meeting? | 16:43 |
cmurphy | lbragstad: ? | 16:43 |
lbragstad | I was curious if we're still planning on going through patrole stuff during office hours today? | 16:44 |
cmurphy | I think so but I wasn't driving it, do we have everyone we need for that meeting? | 16:45 |
cmurphy | gagehugo was going to bring someone in from AT&T i think? and ade was interested too? | 16:46 |
lbragstad | cmurphy yeah - ade is hanging out in our channel | 16:47 |
*** ccamacho has quit IRC | 16:48 | |
lbragstad | do we know if the patrole folks are still coming? | 16:49 |
gagehugo | I can message him, idk if he will be around in irc | 16:49 |
cmurphy | assuming we do have the meeting, do we want to do it over irc or jitsi? | 16:51 |
lbragstad | i'm good with either | 16:52 |
cmurphy | me too | 16:53 |
cmurphy | i guess we can decide after gagehugo gets in touch with the patrole person | 16:54 |
lbragstad | ++ | 16:54 |
cmurphy | can follow up in #openstack-keystone in a few minutes | 16:54 |
cmurphy | #topic open discussion | 16:54 |
*** openstack changes topic to "open discussion (Meeting topic: keystone)" | 16:54 | |
cmurphy | #info spec proposal freeze is next week | 16:54 |
gagehugo | I pinged him to see if he's free | 16:54 |
cmurphy | proposals for the alembic migration (vishakha) and federated attrs (knikolla) and renewable group membership (knikolla) are expected next week | 16:55 |
knikolla | right! roger! | 16:55 |
cmurphy | #link https://releases.openstack.org/ussuri/schedule.html | 16:56 |
cmurphy | :) | 16:56 |
cmurphy | 4 minutes left for any other discussion :) | 16:57 |
cmurphy | okay will close it now, see you in #openstack-keystone | 16:58 |
cmurphy | #endmeeting | 16:58 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 16:58 | |
openstack | Meeting ended Tue Dec 3 16:58:43 2019 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 16:58 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/keystone/2019/keystone.2019-12-03-16.00.html | 16:58 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/keystone/2019/keystone.2019-12-03-16.00.txt | 16:58 |
openstack | Log: http://eavesdrop.openstack.org/meetings/keystone/2019/keystone.2019-12-03-16.00.log.html | 16:58 |
*** redrobot has joined #openstack-meeting-alt | 16:59 | |
*** vkmc has left #openstack-meeting-alt | 17:02 | |
*** tesseract has quit IRC | 17:03 | |
*** diablo_rojo has quit IRC | 17:04 | |
*** diablo_rojo has joined #openstack-meeting-alt | 17:15 | |
*** skatsaounis_ has joined #openstack-meeting-alt | 17:34 | |
*** e0ne has quit IRC | 17:35 | |
*** links has quit IRC | 17:40 | |
*** ijw has joined #openstack-meeting-alt | 17:41 | |
*** jhesketh has quit IRC | 17:42 | |
*** gagehugo has left #openstack-meeting-alt | 17:43 | |
*** jhesketh has joined #openstack-meeting-alt | 17:44 | |
*** tmazur has quit IRC | 17:47 | |
*** diablo_rojo has quit IRC | 17:49 | |
*** skatsaounis_ has quit IRC | 17:51 | |
*** diablo_rojo has joined #openstack-meeting-alt | 17:56 | |
*** ijw has quit IRC | 18:05 | |
*** igordc has joined #openstack-meeting-alt | 18:15 | |
*** vishalmanchanda has quit IRC | 18:21 | |
*** vishalmanchanda has joined #openstack-meeting-alt | 18:21 | |
*** jtomasek has joined #openstack-meeting-alt | 18:24 | |
*** jtomasek has quit IRC | 18:24 | |
*** jtomasek has joined #openstack-meeting-alt | 18:25 | |
*** derekh has quit IRC | 18:29 | |
*** diablo_rojo has quit IRC | 18:30 | |
*** elico has joined #openstack-meeting-alt | 18:36 | |
*** raildo has quit IRC | 18:37 | |
*** raildo has joined #openstack-meeting-alt | 18:38 | |
*** bobmel has joined #openstack-meeting-alt | 18:44 | |
*** bobmel has quit IRC | 18:49 | |
*** diablo_rojo has joined #openstack-meeting-alt | 18:49 | |
*** ayoung has quit IRC | 18:52 | |
*** gmann is now known as gmann_afk | 19:00 | |
*** e0ne has joined #openstack-meeting-alt | 19:26 | |
*** ijw has joined #openstack-meeting-alt | 19:41 | |
*** ijw has quit IRC | 19:47 | |
*** ijw has joined #openstack-meeting-alt | 20:22 | |
*** diablo_rojo has quit IRC | 20:22 | |
*** gmann_afk is now known as gmann | 20:25 | |
*** ijw has quit IRC | 20:26 | |
*** diablo_rojo has joined #openstack-meeting-alt | 20:27 | |
*** diablo_rojo has quit IRC | 20:28 | |
*** e0ne has quit IRC | 20:30 | |
*** diablo_rojo has joined #openstack-meeting-alt | 20:33 | |
*** vesper11 has quit IRC | 20:49 | |
*** vesper11 has joined #openstack-meeting-alt | 20:51 | |
*** ijw has joined #openstack-meeting-alt | 20:53 | |
*** ijw has quit IRC | 20:58 | |
*** rfolco has quit IRC | 21:08 | |
*** rfolco has joined #openstack-meeting-alt | 21:09 | |
*** e0ne has joined #openstack-meeting-alt | 21:09 | |
*** e0ne has quit IRC | 21:11 | |
*** e0ne has joined #openstack-meeting-alt | 21:15 | |
*** raildo has quit IRC | 21:16 | |
*** ijw has joined #openstack-meeting-alt | 21:16 | |
*** e0ne has quit IRC | 21:18 | |
*** ijw has quit IRC | 21:20 | |
*** ijw has joined #openstack-meeting-alt | 21:22 | |
*** smyers has joined #openstack-meeting-alt | 21:24 | |
*** ijw has quit IRC | 21:26 | |
*** rfolco has quit IRC | 21:26 | |
*** ijw has joined #openstack-meeting-alt | 21:42 | |
*** ijw has quit IRC | 21:45 | |
*** ijw has joined #openstack-meeting-alt | 21:47 | |
*** ijw has quit IRC | 21:53 | |
*** ijw has joined #openstack-meeting-alt | 22:06 | |
*** ijw has quit IRC | 22:09 | |
*** ijw has joined #openstack-meeting-alt | 22:11 | |
*** slaweq has quit IRC | 22:15 | |
*** elico has quit IRC | 22:36 | |
*** munimeha1 has quit IRC | 22:43 | |
*** bobmel has joined #openstack-meeting-alt | 22:48 | |
*** elico has joined #openstack-meeting-alt | 22:51 | |
*** elico has quit IRC | 22:52 | |
*** elico has joined #openstack-meeting-alt | 22:52 | |
*** rcernin has joined #openstack-meeting-alt | 22:57 | |
*** elico has quit IRC | 23:23 | |
*** slaweq has joined #openstack-meeting-alt | 23:25 | |
*** slaweq has quit IRC | 23:31 | |
*** ijw has quit IRC | 23:44 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!