Tuesday, 2020-05-19

*** jamesmcarthur has joined #openstack-meeting-alt00:09
*** slaweq has quit IRC00:26
*** slaweq has joined #openstack-meeting-alt00:37
*** slaweq has quit IRC00:42
*** EmilienM|off is now known as EmilienM00:46
*** jhesketh has joined #openstack-meeting-alt00:52
*** jamesmcarthur has quit IRC00:58
*** andrebeltrami has quit IRC00:58
*** yaawang has quit IRC01:22
*** jamesmcarthur has joined #openstack-meeting-alt01:23
*** yaawang has joined #openstack-meeting-alt01:25
*** hongbin has joined #openstack-meeting-alt03:00
*** jamesmcarthur has quit IRC03:09
*** jamesmcarthur has joined #openstack-meeting-alt03:10
*** gyee has quit IRC03:23
*** jamesmcarthur has quit IRC03:24
*** jamesmcarthur has joined #openstack-meeting-alt03:26
*** jamesmcarthur has quit IRC03:27
*** jamesmcarthur has joined #openstack-meeting-alt03:28
*** tetsuro has quit IRC03:45
*** tetsuro has joined #openstack-meeting-alt04:15
*** hongbin has quit IRC04:37
*** vishalmanchanda has joined #openstack-meeting-alt04:52
*** links has joined #openstack-meeting-alt05:19
*** vishakha has joined #openstack-meeting-alt05:30
*** ccamacho has joined #openstack-meeting-alt06:32
*** slaweq has joined #openstack-meeting-alt06:47
*** ircuser-1 has joined #openstack-meeting-alt06:49
*** jamesmcarthur has quit IRC06:49
*** jamesmcarthur has joined #openstack-meeting-alt06:50
*** jamesmcarthur has quit IRC06:55
*** tetsuro_ has joined #openstack-meeting-alt07:01
*** tetsuro has quit IRC07:04
*** jamesmcarthur has joined #openstack-meeting-alt07:14
*** jamesmcarthur has quit IRC07:16
*** jamesmcarthur has joined #openstack-meeting-alt07:17
*** ttsiouts has joined #openstack-meeting-alt07:18
*** jamesmcarthur has quit IRC07:22
*** jamesmcarthur has joined #openstack-meeting-alt07:23
*** adam_g has quit IRC07:24
*** adam_g has joined #openstack-meeting-alt07:24
*** ralonsoh has joined #openstack-meeting-alt07:33
*** vishalmanchanda has quit IRC07:39
*** ccamacho has quit IRC07:40
*** rdopiera has joined #openstack-meeting-alt07:51
*** lpetrut has joined #openstack-meeting-alt08:01
*** ttsiouts has quit IRC08:03
*** ttsiouts has joined #openstack-meeting-alt08:04
*** e0ne has joined #openstack-meeting-alt08:06
*** yaawang has quit IRC08:08
*** yaawang has joined #openstack-meeting-alt08:09
*** yaawang has quit IRC08:19
*** yaawang has joined #openstack-meeting-alt08:21
*** jamesmcarthur has quit IRC08:35
*** masahito has joined #openstack-meeting-alt09:08
*** vishalmanchanda has joined #openstack-meeting-alt09:24
*** ttsiouts has quit IRC09:25
*** links has quit IRC09:33
*** ttsiouts has joined #openstack-meeting-alt09:35
*** ttsiouts has quit IRC10:10
*** tetsuro_ has quit IRC10:17
*** derekh has joined #openstack-meeting-alt10:26
*** ttsiouts has joined #openstack-meeting-alt10:34
*** jamesmcarthur has joined #openstack-meeting-alt10:36
*** jamesmcarthur has quit IRC10:40
*** masahito has quit IRC10:56
*** rfolco|rover|off has joined #openstack-meeting-alt11:42
*** rfolco|rover|off is now known as rfolco|rover11:44
*** raildo has joined #openstack-meeting-alt11:57
*** enriquetaso has joined #openstack-meeting-alt12:05
*** ccamacho has joined #openstack-meeting-alt12:18
*** ttsiouts has quit IRC12:42
*** ttsiouts has joined #openstack-meeting-alt12:43
*** derekh has quit IRC13:01
*** derekh has joined #openstack-meeting-alt13:01
*** ttsiouts has quit IRC13:06
*** vishalmanchanda has quit IRC13:09
*** ttsiouts has joined #openstack-meeting-alt13:10
*** lbragstad_ has joined #openstack-meeting-alt13:36
*** lbragstad has quit IRC13:38
*** lpetrut has quit IRC13:52
*** tetsuro has joined #openstack-meeting-alt13:52
*** tetsuro has quit IRC14:04
*** vishakha has quit IRC14:10
*** andrebeltrami has joined #openstack-meeting-alt14:31
*** jamesmcarthur has joined #openstack-meeting-alt14:36
gagehugo#startmeeting openstack-helm15:00
openstackMeeting started Tue May 19 15:00:21 2020 UTC and is due to finish in 60 minutes.  The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot.15:00
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:00
*** openstack changes topic to " (Meeting topic: openstack-helm)"15:00
openstackThe meeting name has been set to 'openstack_helm'15:00
gagehugo#link https://etherpad.opendev.org/p/openstack-helm-weekly-meeting agenda15:00
gagehugoo/15:02
lamt\o15:02
portdirecto/15:02
stevthedevHello15:05
gagehugoLets get started15:05
gagehugo#topic next week meeting15:05
*** openstack changes topic to "next week meeting (Meeting topic: openstack-helm)"15:05
gagehugoI plan on canceling next week's meeting since I will be out, if anyone wants to host then lemme know15:05
gagehugo#topic virtual ptg - june15:06
*** openstack changes topic to "virtual ptg - june (Meeting topic: openstack-helm)"15:06
gagehugoReminder that the OpenDev PTG is coming up in < 2 weeks15:06
gagehugo#link https://etherpad.opendev.org/p/openstack-helm-ptg-victoria15:06
gagehugo^ add topics to discuss there, otherwise it might be a quiet conference call15:06
gagehugo:)15:06
gagehugo#topic TLS15:06
*** openstack changes topic to "TLS (Meeting topic: openstack-helm)"15:06
gagehugopordirect: I assume this is you15:07
portdirect:)15:07
portdirectso - it think the planets are alining for internal tls15:07
portdirectwe have had a few rough starts on this before15:07
portdirectbut evaluating jetstacks cert manager, it looks to be the missing link in what was attempted before15:08
portdirectid therefore like to propose that we use that to get this effort moving again15:08
portdirectwhich we could break down into a couple of steps:15:08
portdirect1) Jetstack Cert Manager15:09
portdirecta) Chart15:09
portdirectb) Deploy in gate with snakeoil ca15:09
portdirect2) Chart updates15:09
portdirecta) Add in option to create TLS cr, with required hostnames - ideally via htk macro similar to the ingress rule generator15:09
portdirectb) Get tls certs generated for all internal services15:09
portdirectc) Mount secrets into api pods15:09
portdirectd) Enable tls and also set the ingress rule to support secure backends15:09
gagehugojetstack looks interesting15:10
portdirectits used by the cluster api and several other projects15:10
gagehugohmm15:11
portdirectany thoughts on this approach?15:12
gagehugoIt's the best one we have so far15:12
lamtI need to read up on it15:12
gagehugosame15:12
portdirectok - please do15:12
gagehugoI assume this means we don't need that sidecar stuff from years ago?15:13
lamtI read about kube-lego before15:13
lamtbut it has been a while15:13
portdirectgagehugo: i think thats the next phase following this15:13
portdirectlets make it simple15:13
lamtI guess they already have a chart15:13
portdirectand then optimise15:13
lamtI will play around with it15:13
portdirectthis is a pretty similar approach to what i did on another openstack-on-k8s project15:14
portdirectand it worked very well there15:14
gagehugonice15:14
portdirectthough i was using dogtag/freeipa then ;)15:14
lamtif we can load the certs with the correct CN as secret, the rest should follow15:15
lamtbut lemme play around with jetstack and read up on the docs15:16
gagehugoI will read up on it as well15:16
gagehugoand look at that chart15:16
stevthedevMe too. Would be cool to get mTLS working15:16
lamtwe just need tls not mtls right?15:18
gagehugoI assume just TLS15:20
stevthedevSorry, did I misunderstand? Is this for TLS within the cluster?15:21
stevthedevMaybe I a mixing my acronyms :)15:22
stevthedevGotta read up in any case15:22
gagehugoportdirect: anything else for TLS? I think the path forward is to read up on jetstack for now15:24
*** ttsiouts has quit IRC15:27
gagehugothanks everyone, have a good rest of the week15:29
gagehugo#endmeeting15:29
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/"15:29
openstackMeeting ended Tue May 19 15:29:22 2020 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:29
openstackMinutes:        http://eavesdrop.openstack.org/meetings/openstack_helm/2020/openstack_helm.2020-05-19-15.00.html15:29
openstackMinutes (text): http://eavesdrop.openstack.org/meetings/openstack_helm/2020/openstack_helm.2020-05-19-15.00.txt15:29
openstackLog:            http://eavesdrop.openstack.org/meetings/openstack_helm/2020/openstack_helm.2020-05-19-15.00.log.html15:29
*** lbragstad_ is now known as lbragstad15:36
*** gyee has joined #openstack-meeting-alt15:46
*** lpetrut has joined #openstack-meeting-alt16:02
*** ttsiouts has joined #openstack-meeting-alt16:04
*** ttsiouts has quit IRC16:10
*** rdopiera has quit IRC16:15
*** lpetrut has quit IRC16:50
*** ayoung has joined #openstack-meeting-alt16:50
*** vishakha has joined #openstack-meeting-alt16:50
*** derekh has quit IRC16:59
knikolla#startmeeting keystone17:00
openstackMeeting started Tue May 19 17:00:08 2020 UTC and is due to finish in 60 minutes.  The chair is knikolla. Information about MeetBot at http://wiki.debian.org/MeetBot.17:00
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.17:00
*** openstack changes topic to " (Meeting topic: keystone)"17:00
openstackThe meeting name has been set to 'keystone'17:00
lbragstado/17:00
cmurphyo/17:00
gagehugoo/17:00
knikollao/17:00
bnemeco/17:00
knikollahow's everyone doing?17:01
vishakhao/17:01
cmurphyhanging in there17:01
lbragstadsame here17:01
bnemecObligatory: https://i2.wp.com/www.newromantimes.com/wp-content/uploads/2016/11/sales-of-hang-in-there-2.jpg17:02
cmurphylol17:03
knikollathat is more like hanging out there though17:03
bnemecThere's a sloth version! https://encrypted-tbn0.gstatic.com/images?q=tbn%3AANd9GcQwTynAfWY15vRIBjwfji9b-Qoi04oFzFomjWATBF-txx6H4vUv&usqp=CAU17:04
*** alistarle has joined #openstack-meeting-alt17:04
knikollaadorable!17:04
bnemecGoogle image search, the gift that keeps on giving. :-)17:04
*** jamesmcarthur has quit IRC17:04
bnemeclol, for our Suse folks: https://images.fineartamerica.com/images/artworkimages/mediumlarge/2/hang-in-there-magical-chameleon-john-schwegel.jpg17:05
* bnemec is done posting memes17:06
knikollano announcement, but make sure everyone registers for the ptg https://virtualptgjune2020.eventbrite.com/17:06
knikolla#topic Review Requests17:06
*** openstack changes topic to "Review Requests (Meeting topic: keystone)"17:06
vishakhaI have couple of reviews17:07
vishakha#link https://review.opendev.org/#/q/topic:update-onboarding+(status:open+OR+status:merged)17:07
*** ttsiouts has joined #openstack-meeting-alt17:08
vishakhaThanks cmurphy  for the reviews. I updated these according to your comments17:08
vishakha#link https://review.opendev.org/#/c/728387/17:09
*** ttsiouts has quit IRC17:09
*** jamesmcarthur has joined #openstack-meeting-alt17:09
cmurphyi haven't had a chance to look at the new revisions but wanted to ask the team, what's the consensus on using the terms "controller" and "manager"?17:09
vishakhaI blocked patching of access_id of EC2 credentials as discussed. Tempest had no problem with it17:09
cmurphyi still always use "controller" and "manager" in my head because i'm old but i can see how that would be confusing to someone looking at the code post-flask and post-providerAPI17:10
lbragstad++17:10
lbragstadi agree17:10
knikollai think since there aren't really references to controller in the code anymore, we should update the docs17:11
cmurphywhat should it be called then? i suggested things like "API resource" in my reviews17:11
cmurphyand is the stuff in core.py still a "manager" or is it something else?17:12
knikollagood point17:12
lbragstadi always mentally mapped "controller" to "this stuff handles request logic" and "managers" contain "keystone-specific business logic"17:13
cmurphylbragstad: yeah exactly17:13
cmurphyit's kind of still the same17:13
lbragstadyeah17:13
cmurphyit's just the python classes and file names don't match17:13
lbragstadwould that make core.py (the managers) a model?17:13
lbragstadmeh... probably not17:14
cmurphyin an mvc sense i think the sql backend is the model17:14
lbragstadright17:15
lbragstadso the managers would really be the controllers17:15
lbragstadand the controllers would be the view17:15
cmurphyheh yeah kind of17:15
* lbragstad isn't helping anything17:15
cmurphy:P17:15
knikollalet's invent new terminology17:17
cmurphyknikolla: suggestions?17:18
vishakhaAPI resource seemed reasonable17:18
knikollano, i was just reminded of a team at my work who named the view for a project "picasso" and the manager "einstein" and I got PTSD from reviewing their code.17:19
cmurphyhahaha17:19
cmurphypersonally i think i'd be comfortable continuing to call the providerAPI stuff "managers" and the flask stuff "controllers", or renaming the flask stuff "API ... resources/handlers/controllers/something"17:19
knikollai say we go with API <something> since it's part of their name and file path17:20
knikolla /file path/package/17:20
knikollamanager and controller have the same implication of being in charge, whereas API doesn't have any connotations.17:22
cmurphythe class names for the request handler part are {Thing}Resource so "API Resource" fits17:24
cmurphythe routes are defined in {Thing}API but i think we should still call them routes17:24
*** jamesmcarthur has quit IRC17:24
knikolla++17:24
vishakhaokay.17:26
alistarleHi, thanks for your review on oslo.limits : https://review.opendev.org/#/q/owner:%22Victor+Coutellier%22+status:open+project:openstack/oslo.limit17:28
alistarleI have updated it with your comments17:28
cmurphythanks alistarle17:28
* bnemec still has that window open somewhere17:29
alistarleBut there is still a openstacksdk patch to be merged for mine to work, I don't used to updating dependency workflow17:29
cmurphybnemec: you can open a new window!17:29
alistarleShould I wait for it to be merged, then wait a new version of the sdk, and update the lower-constraints of oslo_limit ?17:30
bnemecETOOMANYWINDOWS17:30
cmurphyalistarle: you can add "Depends-on: " with a link to the openstacksdk patch in the commit message17:30
cmurphythat will prevent it from being merged before the dependency is merged17:30
knikollabnemec: i keep a firefox addon that doesn't let me open more than 7 tabs17:30
cmurphybut it will also probably need a new release of openstacksdk before oslo.limit can use it17:31
alistarleAnd a new release of oslo.limit before using it into glance :/17:31
cmurphyright17:31
alistarleBTW, I have written the full spec for glance about unified limit, if you want to take a look : https://review.opendev.org/#/c/729187/17:31
bnemecknikolla: That would never work for me. :-P17:32
alistarleGlance guy's already told me to put that in the PTG agenda, do you think it is usefull to synchronize a session with you ?17:32
bnemecDid any of the migration tools ever get written?17:32
cmurphynot afaik but i haven't kept up with the nova team on that17:33
alistarleI don't think so, neither for glance, but as there is no quota yet, maybe there is no migration :p17:33
bnemecOh, glance doesn't have any existing quotas? That would make it easier. :-)17:34
alistarleYes, only hard limit in config file, that's why I think it will be easier than nova17:34
cmurphyoh good17:35
bnemecMaybe you can just ping us during the Glance discussion?17:36
alistarleSure17:36
knikolla#topic Open Floor17:37
*** openstack changes topic to "Open Floor (Meeting topic: keystone)"17:37
knikollaoops, Bug Duty first :)17:38
knikolla#topic Bug Duty17:38
*** openstack changes topic to "Bug Duty (Meeting topic: keystone)"17:38
knikollaThere were a few reported bugs last week17:38
* bnemec notes that meetbot has an undo command17:38
knikollaooo, thanks!17:39
knikolla#link https://bugs.launchpad.net/keystone/+bug/187893817:39
openstackLaunchpad bug 1878938 in OpenStack Identity (keystone) "System role assignments exist after system role delete" [Undecided,New]17:39
knikollaa quick check at the code shows that Role_id isn't a foreign key in either normal assignment or role assignments17:40
knikollaare we doing the cleanup in code instead of cascading delete?17:40
knikollaor is it because we define them as separate backends?17:40
knikollathem = role_backend and assignment_backend17:41
cmurphyif they're not in the same backend then it is supposed to be handled with notifications17:41
cmurphywhich are easy to forget17:41
knikollai see.17:42
* knikolla needs to look at how they're implemented since I haven't played much with them. 17:42
knikollacmurphy is covering this week, anyone volunteering for next?17:44
vishakhaI can take for the next week17:44
knikollathanks vishakha :)17:45
vishakhanp17:45
knikolla#topic Open Floor17:46
*** openstack changes topic to "Open Floor (Meeting topic: keystone)"17:46
*** ayoung has quit IRC17:47
cmurphyi had a couple more reviews https://review.opendev.org/726727 https://review.opendev.org/72672917:47
vishakhaI had some more too :)17:48
* knikolla is failing hard at chairing meetings17:48
vishakha#link https://review.opendev.org/#/c/71272417:48
vishakha#link https://review.opendev.org/#/c/725634/17:48
lbragstadlooks like we're having some issues with py35 testing17:49
lbragstadi've been noticing a bunch of failures with ksa on master recently17:49
lbragstadexample: https://review.opendev.org/#/c/727498/317:49
*** jamesmcarthur has joined #openstack-meeting-alt17:50
knikollaCould not find a version that satisfies the requirement oslotest===4.2.017:50
*** ayoung has joined #openstack-meeting-alt17:51
bnemecIs py35 even still supported on master branches?17:51
lbragstadksa doesn't have a a tox env for it, but it is part of the zuul jobs17:51
bnemecI believe the Victoria unit test jobs are py36 and py38. At least that's what I'm seeing in a project that has been migrated to the victoria template.17:55
bnemecBut maybe ksa makes broader compatibility guarantees? I know we've done that with pbr at times.17:55
cmurphyoh wait i just remembered https://review.opendev.org/72108417:56
knikollahttps://review.opendev.org/#/c/721093/17:56
cmurphyyeah that17:56
lbragstadah17:57
bnemecOkay, guess you can't just drop the job then. :-)17:58
cmurphyso yes py35 is still supported in ksa master and there is some governance saying that requirements etc should still work for py35 so if it's not we should help fix it17:58
*** alistarle has quit IRC17:58
cmurphylooks like gmann responded on https://review.opendev.org/727498 and there's some ongoing work to fix it18:00
lbragstadso we have to maintain our own constraints for ksa?18:02
*** e0ne has quit IRC18:02
lbragstadis what it sounds lik?18:02
lbragstadlike*18:03
knikollalet's continue on #openstack-keystone18:03
knikolla#endmeeting18:03
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/"18:03
openstackMeeting ended Tue May 19 18:03:10 2020 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)18:03
openstackMinutes:        http://eavesdrop.openstack.org/meetings/keystone/2020/keystone.2020-05-19-17.00.html18:03
openstackMinutes (text): http://eavesdrop.openstack.org/meetings/keystone/2020/keystone.2020-05-19-17.00.txt18:03
openstackLog:            http://eavesdrop.openstack.org/meetings/keystone/2020/keystone.2020-05-19-17.00.log.html18:03
gmannlbragstad: cmurphy discussing on requirement channel if it can be maintained on req side or project side have to maintain18:04
*** ayoung has quit IRC18:06
*** e0ne has joined #openstack-meeting-alt18:07
*** ayoung has joined #openstack-meeting-alt18:10
*** jamesmcarthur has quit IRC18:12
*** jamesmcarthur has joined #openstack-meeting-alt18:14
*** jamesmcarthur has quit IRC18:17
*** jamesmcarthur has joined #openstack-meeting-alt18:17
*** jamesmcarthur has quit IRC18:29
*** jamesmcarthur has joined #openstack-meeting-alt18:30
*** ayoung has quit IRC18:31
*** ayoung has joined #openstack-meeting-alt18:33
*** rcernin has quit IRC18:34
*** diablo_rojo has joined #openstack-meeting-alt18:53
*** ralonsoh has quit IRC18:58
*** raildo has quit IRC19:04
*** raildo has joined #openstack-meeting-alt19:19
*** ayoung has quit IRC19:25
*** ayoung has joined #openstack-meeting-alt19:29
*** ayoung has quit IRC19:55
*** enriquetaso has quit IRC20:10
*** enriquetaso has joined #openstack-meeting-alt20:13
*** vishakha has quit IRC20:29
*** ccamacho has quit IRC21:09
*** jamesmcarthur has quit IRC21:20
*** jamesmcarthur has joined #openstack-meeting-alt21:24
*** raildo has quit IRC21:24
*** jamesmcarthur has quit IRC21:31
*** jamesmcarthur has joined #openstack-meeting-alt21:32
*** jamesmcarthur has quit IRC21:34
*** jamesmcarthur has joined #openstack-meeting-alt21:34
*** jamesmcarthur has quit IRC21:37
*** jamesmcarthur has joined #openstack-meeting-alt21:39
*** slaweq has quit IRC21:41
*** jamesmcarthur has quit IRC21:41
*** jamesmcarthur has joined #openstack-meeting-alt21:41
*** jamesmcarthur has quit IRC22:33
*** jamesmcarthur has joined #openstack-meeting-alt22:33
*** jamesmcarthur_ has joined #openstack-meeting-alt22:40
*** jamesmcarthur has quit IRC22:44
*** rcernin has joined #openstack-meeting-alt22:56
*** jamesmcarthur_ has quit IRC23:05
*** jamesmcarthur has joined #openstack-meeting-alt23:12
*** andrebeltrami has quit IRC23:19
*** lbragstad has quit IRC23:38
*** jamesmcarthur has quit IRC23:56
*** jamesmcarthur has joined #openstack-meeting-alt23:57

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!