*** rfolco|rover|off has quit IRC | 00:25 | |
*** tetsuro has joined #openstack-meeting-alt | 00:30 | |
*** tetsuro_ has joined #openstack-meeting-alt | 00:40 | |
*** tetsuro has quit IRC | 00:43 | |
*** Liang__ has joined #openstack-meeting-alt | 00:59 | |
*** redrobot has quit IRC | 01:34 | |
*** masahito has joined #openstack-meeting-alt | 01:39 | |
*** tetsuro has joined #openstack-meeting-alt | 01:44 | |
*** tetsuro_ has quit IRC | 01:47 | |
*** lbragstad_ is now known as lbragstad | 01:52 | |
*** tetsuro_ has joined #openstack-meeting-alt | 02:12 | |
*** tetsuro has quit IRC | 02:15 | |
*** andrebeltrami has quit IRC | 02:28 | |
*** tetsuro has joined #openstack-meeting-alt | 03:06 | |
*** tetsuro_ has quit IRC | 03:09 | |
*** lbragstad has quit IRC | 03:18 | |
*** gyee has quit IRC | 03:18 | |
*** masahito has quit IRC | 03:22 | |
*** dustinc has quit IRC | 03:34 | |
*** tetsuro_ has joined #openstack-meeting-alt | 04:06 | |
*** tetsuro has quit IRC | 04:09 | |
*** diablo_rojo has quit IRC | 04:44 | |
*** links has joined #openstack-meeting-alt | 05:34 | |
*** tetsuro has joined #openstack-meeting-alt | 05:43 | |
*** tetsuro_ has quit IRC | 05:47 | |
*** ccamacho has joined #openstack-meeting-alt | 06:00 | |
*** tetsuro_ has joined #openstack-meeting-alt | 06:23 | |
*** tetsuro has quit IRC | 06:26 | |
*** tetsuro has joined #openstack-meeting-alt | 06:29 | |
*** ttsiouts has joined #openstack-meeting-alt | 06:30 | |
*** tetsuro_ has quit IRC | 06:32 | |
*** links has quit IRC | 06:37 | |
*** ttsiouts has quit IRC | 06:39 | |
*** links has joined #openstack-meeting-alt | 06:40 | |
*** ttsiouts has joined #openstack-meeting-alt | 06:41 | |
*** lpetrut has joined #openstack-meeting-alt | 06:42 | |
*** slaweq has joined #openstack-meeting-alt | 06:51 | |
*** vishalmanchanda has joined #openstack-meeting-alt | 07:03 | |
*** pavani_pedd has joined #openstack-meeting-alt | 07:04 | |
*** apetrich has quit IRC | 07:11 | |
*** tetsuro_ has joined #openstack-meeting-alt | 07:24 | |
*** tetsuro has quit IRC | 07:27 | |
*** pavani_pedd has quit IRC | 07:31 | |
*** ralonsoh has joined #openstack-meeting-alt | 07:42 | |
*** apetrich has joined #openstack-meeting-alt | 07:45 | |
*** apetrich has quit IRC | 07:45 | |
*** apetrich has joined #openstack-meeting-alt | 07:46 | |
*** e0ne has joined #openstack-meeting-alt | 08:05 | |
*** ttsiouts has quit IRC | 08:34 | |
*** tetsuro_ has quit IRC | 08:47 | |
*** ttsiouts has joined #openstack-meeting-alt | 08:53 | |
*** tetsuro has joined #openstack-meeting-alt | 09:07 | |
*** tetsuro has quit IRC | 09:23 | |
*** jraju__ has joined #openstack-meeting-alt | 09:27 | |
*** links has quit IRC | 09:28 | |
*** Liang__ has quit IRC | 09:32 | |
*** links has joined #openstack-meeting-alt | 09:47 | |
*** jraju__ has quit IRC | 09:47 | |
*** derekh has joined #openstack-meeting-alt | 10:20 | |
*** vishakha has joined #openstack-meeting-alt | 10:47 | |
*** yamamoto has joined #openstack-meeting-alt | 11:43 | |
*** yamamoto has quit IRC | 11:43 | |
*** rfolco has joined #openstack-meeting-alt | 12:04 | |
*** rfolco is now known as rfolco|rover | 12:05 | |
*** raildo has joined #openstack-meeting-alt | 12:05 | |
*** lpetrut has quit IRC | 12:46 | |
*** ianychoi has quit IRC | 12:55 | |
*** gshippey has joined #openstack-meeting-alt | 13:03 | |
*** ttsiouts has quit IRC | 13:04 | |
*** enriquetaso has joined #openstack-meeting-alt | 13:12 | |
*** ttsiouts has joined #openstack-meeting-alt | 13:13 | |
*** lbragstad has joined #openstack-meeting-alt | 13:23 | |
*** ttsiouts has quit IRC | 13:32 | |
*** redrobot has joined #openstack-meeting-alt | 13:34 | |
*** liuyulong has joined #openstack-meeting-alt | 13:49 | |
*** sfernand has joined #openstack-meeting-alt | 14:04 | |
*** ttsiouts has joined #openstack-meeting-alt | 14:12 | |
*** ttsiouts has quit IRC | 14:17 | |
*** lpetrut has joined #openstack-meeting-alt | 14:29 | |
e0ne | #startmeeting horizon | 15:01 |
---|---|---|
openstack | Meeting started Wed May 13 15:01:44 2020 UTC and is due to finish in 60 minutes. The chair is e0ne. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:01 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:01 |
*** openstack changes topic to " (Meeting topic: horizon)" | 15:01 | |
openstack | The meeting name has been set to 'horizon' | 15:01 |
*** priteau has joined #openstack-meeting-alt | 15:01 | |
Nizars | Hi! | 15:01 |
jberg-dev | Hello | 15:02 |
*** links has quit IRC | 15:02 | |
e0ne | hi | 15:02 |
*** Andreas681 has joined #openstack-meeting-alt | 15:02 | |
vishalmanchanda | hi all | 15:02 |
e0ne | let's wait for a few minutes to get more people here | 15:02 |
Andreas681 | Hello | 15:02 |
amotoki | hi | 15:04 |
e0ne | let's start | 15:05 |
e0ne | #topic Notices | 15:05 |
*** openstack changes topic to "Notices (Meeting topic: horizon)" | 15:05 | |
e0ne | OpenStack Ussuri is released today! | 15:05 |
e0ne | #link https://releases.openstack.org/ussuri/index.html | 15:05 |
Nizars | Nice! | 15:05 |
amotoki | http://lists.openstack.org/pipermail/openstack-announce/2020-May/002035.html | 15:06 |
amotoki | this is the official announcement :) | 15:06 |
Nizars | Interesting :) | 15:06 |
* e0ne didn't check my mailbox today :( | 15:06 | |
e0ne | thanks everybody for your contributions! | 15:07 |
e0ne | and special thanks to Akihiro amotoki for being our PTL during Ussury cycle | 15:07 |
amotoki | thanks all! | 15:07 |
*** lpetrut has quit IRC | 15:08 | |
Nizars | Hopefully I will be able to contribute next time :) | 15:08 |
amotoki | Nizars: hope so :) | 15:08 |
e0ne | here is victoria schedule: https://releases.openstack.org/victoria/schedule.html | 15:09 |
e0ne | this time, V, means virtual | 15:10 |
e0ne | it could be un-official release name this time :( | 15:10 |
vishalmanchanda | hehe🙂) | 15:11 |
-amotoki- wonders what is a virtual release :) | 15:11 | |
e0ne | PTG will be virtual too | 15:11 |
e0ne | #link https://etherpad.opendev.org/p/horizon-v-ptg | 15:11 |
e0ne | feel free to add topics you would like to discuss | 15:11 |
e0ne | PTG registration is open | 15:12 |
e0ne | #link https://www.openstack.org/ptg | 15:12 |
e0ne | it's free to attend but OSF recommends to register | 15:12 |
Nizars | Nice :) | 15:13 |
Nizars | Can I bring up the topic I would like to discuss now? | 15:13 |
e0ne | that's all announcements I've got for today | 15:15 |
amotoki | Nizars: if you are bringing up a topic to this meeting, "On-demand agenda" section would be the one you want. | 15:15 |
Nizars | I see, I still haven't familiarized myself properly with the format. I will wait until I see that appear. | 15:16 |
Nizars | amotoki: Thank you :) | 15:16 |
e0ne | amotoki, vishalmanchanda : do you have anything to add as announcements? | 15:17 |
amotoki | nothing from me | 15:18 |
vishalmanchanda | e0ne: no. | 15:18 |
e0ne | ok | 15:18 |
e0ne | #topic Open Discussion | 15:18 |
*** openstack changes topic to "Open Discussion (Meeting topic: horizon)" | 15:18 | |
e0ne | NizarsL it's your turn | 15:18 |
Nizars | Thank! | 15:18 |
Nizars | So me and my team have been working on developing a plugin for Horizon | 15:19 |
Nizars | This is how it currently looks like: | 15:19 |
Nizars | https://imgur.com/RB0o7Br | 15:19 |
Nizars | We have created a blueprint for it and we are hoping to have it approved. | 15:19 |
Nizars | https://blueprints.launchpad.net/horizon/+spec/policies-plugin | 15:19 |
Nizars | Here is the code for the plugin: | 15:20 |
Nizars | https://github.com/nizos/horizon-policies-plugin | 15:20 |
e0ne | usually, blueprints are required for some features | 15:20 |
e0ne | a new plugin is a new project, so I'm not sure we need a plugin | 15:20 |
Nizars | you mean that you are not sure we need a *blueprint right? | 15:21 |
e0ne | Nizars: are you going to move this plugin under openstack umbrella to opendev? | 15:21 |
Nizars | We are hoping to contribute with it yes. | 15:21 |
amotoki | to the horizon repo or a separate repo? | 15:22 |
Nizars | We are ok with either, you know better. :) | 15:22 |
amotoki | Nizars: I think we discussed it several weeks before. Any update since then? | 15:23 |
Nizars | Not really, we have been working on it. We are starting testing soon. There is one implementation left, which is the permissions check with openstack_auth. | 15:24 |
Nizars | We are currently working on that and cleaning out a few UI bugs and so on. | 15:25 |
amotoki | I am not sure it was from you, but we discussed the UI for policies several weeks ago. Is it from some different folks? | 15:26 |
Nizars | It was us, that is correct. :) | 15:26 |
amotoki | thanks for the confirmation | 15:27 |
amotoki | so, perhaps what we need to discuss are (1) updates from the previous discussion here and (2) the actual plan for the next steps | 15:27 |
Nizars | We are all very new to openstack and open source contribution but we hope we can contribute with this effort. Directions, guidance, critique and feedback is appreciated. :) | 15:28 |
amotoki | Nizars: IIRC, you said you will discuss it in oslo meeting. any update? | 15:28 |
amotoki | Nizars: from my memory, another action item is to check how the default policies are loaded. | 15:29 |
e0ne | also, there was a concern, that current implementation will work only if we've got single node deployment | 15:31 |
Nizars | Ok, the goal of the plugin is to allow the installer to quickly view the policies and make modifications to them. We were recommended to look into the permissions so that not anyone can access/modify policies through it. We are currently adding that functionality through openstack_auth. An issue that was brought up was how would this plugin be used with policies of projects on other servers and so on. We | 15:32 |
Nizars | don't think we have a solution for that at the moment without going outside of the scope of the initial goal. We will have to look into creating a back end functionality that is to be installed on the different servers/nodes and allow them to communicate. | 15:32 |
Nizars | I discussed the matter with either oslo or keystone, can't remember which one it was. The other one didn't sart their meeting at the time I was anticipating them to. There isn't really much to update you about from that discussion. There was something about finding a fitting team for us or something like that. | 15:34 |
Nizars | I will attend the future meetings and check again with them. | 15:34 |
amotoki | first of all, openstack_auth just provides policies for GUI (horizon and plugins) (via openstack_auth.policy) | 15:35 |
Nizars | Exactly | 15:35 |
amotoki | openstack_auth is not a place to handle policies used by backend services like nova, neutorn, cinder and so on | 15:35 |
amotoki | is it same as your understanding | 15:35 |
amotoki | ? | 15:35 |
Nizars | Yeah, no. That is not what I intended to communicate. | 15:36 |
Nizars | We are on the same page. | 15:36 |
amotoki | so what would your solution like to provide? | 15:37 |
amotoki | is it an UI to view and edit policies as a preparation for deployment? | 15:37 |
Nizars | We have currently just implemented it for usage with Horizon "identity" but it should easily be made to work with any other project on the same node. | 15:38 |
amotoki | a single node deployment is just for testing :( | 15:39 |
amotoki | we need to consider real deployment scenarios with multinode controllers (ie API nodes) | 15:39 |
amotoki | so, we need to clarify how your UI can be used in production deployments | 15:40 |
Nizars | The solution is to allow for easy access and modification of policies. It provides functionalities such as autocomplete suggestion in the editor, tooltip information, restoring policies from uploaded file, download policy back ups, print, copy, search, sort, filter, view scopes, operations and descriptions for policies etc... | 15:40 |
Nizars | It is true what you say. If we can find a good approach to solve the multi-node deployment issue it could be used in production and not just testing. | 15:41 |
amotoki | so, is the scenario in your mind that an operator check/update policies via your UI, then save it and deploy it to all nova/neutron/cinder API servers? | 15:42 |
*** gyee has joined #openstack-meeting-alt | 15:43 | |
e0ne | multi-node deployment is an extremely important in a containerised world | 15:43 |
Nizars | It should be possible to have it deploy the policies to the different projects. We just haven't done that yet. We just need to add the functionality to the back end and add the dictionary for the corresponding project policies. | 15:44 |
amotoki | I don't understand your last statement... | 15:45 |
amotoki | individual projects (API servers) configure RBAC via policy files | 15:46 |
amotoki | I am not sure what you mean by "dictionary". | 15:46 |
Nizars | I agree, we would like to have it work in multi-node deployments. Maybe if a backend piece of software can be developed to communicate encrypted policy read/write instructions within the network, it should be able to do its job. | 15:46 |
Nizars | The dictionary is this: | 15:47 |
Nizars | https://github.com/nizos/horizon-policies-plugin/blob/master/policies_plugin/api/resources/keystone_fields.py | 15:47 |
amotoki | In addition, the current OpenStack services can work with empty policy files because default policies are defined in their python codes. | 15:47 |
amotoki | I am not sure how it works with your proposal. | 15:47 |
amotoki | even in a single node. | 15:48 |
Nizars | The name of the file should be identity not keystone, it will be fixed in the next commit. But it is where the description, scopes, default rule, operation values and so on are retrieved from for the policies. | 15:48 |
Nizars | The plugin displays default rules | 15:48 |
amotoki | how are they loaded? | 15:49 |
Nizars | It merges default rules from code with ones defined in the policy files. | 15:49 |
Nizars | This is the client: | 15:49 |
Nizars | https://github.com/nizos/horizon-policies-plugin/blob/master/policies_plugin/api/rest/client.py | 15:49 |
amotoki | no, the default rules are defined in (for example) keystone.common.policies | 15:50 |
Nizars | It uses oslo policy enforcer to get the rules | 15:50 |
amotoki | most operators uses policy files only when they would like to define different rules from the default ones. | 15:50 |
Nizars | I see | 15:51 |
Nizars | I assume that there is still value in viewing the default rules nonetheless? maybe an option can be configured to show/hide default rules. | 15:51 |
amotoki | note that horizon policy support is behind the current situation and we the horizon team is trying to catch up with the current situation. | 15:52 |
amotoki | you cannot assume the horizon openstakc-auth implementation is the latest oen. | 15:52 |
Nizars | Noted | 15:52 |
amotoki | I think we need to discuss the next step rather than digging into the detail of imps. | 15:53 |
amotoki | *implementations | 15:53 |
Nizars | I see, do you think implementing something to make policies accessible to the plugin in multi-node deployments is feasible? | 15:54 |
amotoki | in my current impression, it does not fit into the horizon repo at least because horizon provides GUI on top of REST APIs from backend services like keystone, nova, neutron and so on. | 15:54 |
Nizars | I see. | 15:54 |
amotoki | your proposal sounds like a help tool to check/edit policy files. | 15:55 |
amotoki | a separate repository sounds better. | 15:55 |
Nizars | Understood | 15:55 |
amotoki | my next suggestion is to discuss it with operators to understand their real scenarios. | 15:55 |
Nizars | It's no problem for us. | 15:55 |
Nizars | ok | 15:56 |
amotoki | I don't have a good suggestion where you can discuss but openstack-discuss ml would be a good place. | 15:56 |
amotoki | e0ne: vishalmanchanda: any comment? | 15:56 |
Nizars | We can communicate with some of the devs at City Network who work with Openstack, they might have some feedback for us. | 15:57 |
e0ne | amotoki: nothing more from my side | 15:57 |
amotoki | my comments above are based on my operator experience (not from the dev experience) | 15:57 |
Nizars | It's appreciated! | 15:57 |
vishalmanchanda | amotoki: it's good to discuss it on ml and tag tc as well. | 15:57 |
Nizars | What is ml? | 15:57 |
amotoki | Nizars: openstack-discuss ML | 15:57 |
amotoki | ML = mailing list | 15:58 |
vishalmanchanda | Nizars: Open-discuss list | 15:58 |
Nizars | Ah ok! | 15:58 |
amotoki | Nizars: generally speaking, it is nice to have UI to check/view/modify policies | 15:58 |
amotoki | as it is not easy to check all policies | 15:59 |
e0ne | amotoki: +1 | 15:59 |
Nizars | True, it just turned out to be more complicated than we originally anticipated. | 15:59 |
amotoki | but the implementation needs to consider the current oslo.policy support and oeprators' scenarios. | 15:59 |
Nizars | I had no idea what openstack was a couple of months ago so there is a lot to learn here and a lot is being picked up along the way. | 15:59 |
amotoki | it is not just a GUI topic | 15:59 |
Nizars | I agree | 16:00 |
-amotoki- we are out of time.... | 16:00 | |
Nizars | Thanks for everything. :) | 16:01 |
e0ne | Nizars: we can continue the discussion in the horizon channel | 16:01 |
amotoki | I will be there for a while after the meeting | 16:01 |
e0ne | thanks everybody for [articipation | 16:01 |
Nizars | Another day maybe, I need to get some rest but thanks for all the help. :) | 16:01 |
e0ne | #endmeeting | 16:01 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 16:01 | |
openstack | Meeting ended Wed May 13 16:01:51 2020 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 16:01 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/horizon/2020/horizon.2020-05-13-15.01.html | 16:01 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/horizon/2020/horizon.2020-05-13-15.01.txt | 16:01 |
openstack | Log: http://eavesdrop.openstack.org/meetings/horizon/2020/horizon.2020-05-13-15.01.log.html | 16:01 |
amotoki | o/ | 16:02 |
*** sfernand has quit IRC | 16:13 | |
*** andrebeltrami has joined #openstack-meeting-alt | 16:14 | |
*** liuyulong has quit IRC | 16:17 | |
*** rf0lc0 has joined #openstack-meeting-alt | 16:20 | |
*** rfolco|rover has quit IRC | 16:23 | |
*** Andreas681 has quit IRC | 16:25 | |
*** rf0lc0 is now known as rfolco|rover | 16:56 | |
*** derekh has quit IRC | 17:03 | |
*** enriquetaso has quit IRC | 17:10 | |
*** hemna_ has quit IRC | 17:29 | |
*** hemna has joined #openstack-meeting-alt | 17:29 | |
*** priteau has quit IRC | 17:38 | |
*** ralonsoh has quit IRC | 17:44 | |
*** e0ne has quit IRC | 17:55 | |
*** enriquetaso has joined #openstack-meeting-alt | 18:06 | |
*** vishakha has quit IRC | 19:29 | |
*** ttsiouts has joined #openstack-meeting-alt | 20:13 | |
*** gshippey has quit IRC | 20:24 | |
*** ttsiouts has quit IRC | 20:30 | |
*** vishalmanchanda has quit IRC | 20:31 | |
*** ttsiouts has joined #openstack-meeting-alt | 20:32 | |
*** ccamacho has quit IRC | 20:54 | |
*** enriquetaso has quit IRC | 21:00 | |
*** rfolco|rover has quit IRC | 21:16 | |
*** raildo has quit IRC | 21:46 | |
*** slaweq has quit IRC | 21:57 | |
*** slaweq has joined #openstack-meeting-alt | 22:08 | |
*** slaweq has quit IRC | 22:13 | |
*** slaweq has joined #openstack-meeting-alt | 22:23 | |
*** slaweq has quit IRC | 22:28 | |
*** ttsiouts has quit IRC | 22:43 | |
*** ttsiouts has joined #openstack-meeting-alt | 22:44 | |
*** hongbin has joined #openstack-meeting-alt | 23:05 | |
*** Liang__ has joined #openstack-meeting-alt | 23:29 | |
*** rcernin has quit IRC | 23:31 | |
*** rcernin has joined #openstack-meeting-alt | 23:32 | |
*** early has quit IRC | 23:38 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!