Tuesday, 2020-07-21

*** openstack has joined #openstack-meeting-alt07:30
*** ChanServ sets mode: +o openstack07:30
ttxeavesdrop is up for me07:30
ianwyeah, it should be back .. i don't know the host had just stopped accepting connections07:31
*** geguileo has quit IRC07:32
*** geguileo has joined #openstack-meeting-alt07:33
*** rcernin_ has quit IRC07:34
ricolinyeah, is up now07:35
*** rcernin_ has joined #openstack-meeting-alt08:17
*** priteau has joined #openstack-meeting-alt08:25
*** derekh has joined #openstack-meeting-alt08:25
*** rcernin_ has quit IRC08:26
*** e0ne has joined #openstack-meeting-alt08:31
*** rcernin_ has joined #openstack-meeting-alt08:47
*** baojg has quit IRC08:56
*** baojg has joined #openstack-meeting-alt08:57
*** tetsuro has joined #openstack-meeting-alt08:58
*** tetsuro has quit IRC09:00
priteau#startmeeting blazar09:01
openstackMeeting started Tue Jul 21 09:01:07 2020 UTC and is due to finish in 60 minutes.  The chair is priteau. Information about MeetBot at http://wiki.debian.org/MeetBot.09:01
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.09:01
*** openstack changes topic to " (Meeting topic: blazar)"09:01
openstackThe meeting name has been set to 'blazar'09:01
priteau#topic Roll call09:01
*** openstack changes topic to "Roll call (Meeting topic: blazar)"09:01
*** tetsuro has joined #openstack-meeting-alt09:03
priteauHi tetsuro09:03
tetsuroHi09:03
priteauAgenda for today:09:06
priteauSpecs update09:06
priteauCode review priorities09:06
priteauAOB09:06
priteau#topic Specs update09:06
*** openstack changes topic to "Specs update (Meeting topic: blazar)"09:06
*** rcernin_ has quit IRC09:07
priteauAt the last meeting we discussed your spec draft for GPU support09:07
priteau#link http://eavesdrop.openstack.org/meetings/blazar/2020/blazar.2020-07-07-09.00.log.html09:07
priteauWe agreed to create a new draft spec for PCI passthrough09:08
priteauWere you able to make any progress on this?09:09
tetsuroNo, I don't have any progress09:10
tetsuroI'm not sure how we can extend the feature to any PCI devices09:11
priteauI've worked a bit with PCI passthrough so I take over the PCI passthrough spec09:12
tetsuroThat would be nice, thanks priteau09:13
priteau#action priteau create new draft spec for PCI passthrough09:13
priteau#topic Code review priorities09:15
*** openstack changes topic to "Code review priorities (Meeting topic: blazar)"09:15
priteauWe have a few code maintenance patches that we can merge, related to ubuntu focal testing09:16
priteauhttps://review.opendev.org/#/c/740358/09:16
priteauhttps://review.opendev.org/#/c/740359/09:16
priteauhttps://review.opendev.org/#/c/740357/09:16
*** markvoelker has joined #openstack-meeting-alt09:16
priteauOtherwise the review priority is still https://review.opendev.org/#/c/731586/09:18
priteauI started reviewing it but I am not very familiar with the way context objects are used09:18
priteau#topic AOB09:21
*** openstack changes topic to "AOB (Meeting topic: blazar)"09:21
priteauAnything else to share today?09:21
*** markvoelker has quit IRC09:21
*** tetsuro has quit IRC09:22
*** tetsuro has joined #openstack-meeting-alt09:25
tetsurosorry, my network is not stable09:25
tetsuroI don't have any other business09:25
priteauThanks tetsuro, let's wrap up for today.09:26
priteau#endmeeting09:27
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/"09:27
openstackMeeting ended Tue Jul 21 09:27:23 2020 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)09:27
openstackMinutes:        http://eavesdrop.openstack.org/meetings/blazar/2020/blazar.2020-07-21-09.01.html09:27
openstackMinutes (text): http://eavesdrop.openstack.org/meetings/blazar/2020/blazar.2020-07-21-09.01.txt09:27
openstackLog:            http://eavesdrop.openstack.org/meetings/blazar/2020/blazar.2020-07-21-09.01.log.html09:27
*** tetsuro has quit IRC09:29
*** rcernin_ has joined #openstack-meeting-alt09:42
*** baojg has quit IRC09:52
*** baojg has joined #openstack-meeting-alt09:53
*** rcernin_ has quit IRC09:55
*** ricolin has quit IRC10:18
*** Liang__ has quit IRC10:26
*** markvoelker has joined #openstack-meeting-alt10:27
*** rcernin_ has joined #openstack-meeting-alt10:29
*** markvoelker has quit IRC10:31
*** baojg has quit IRC11:13
*** baojg has joined #openstack-meeting-alt11:14
*** markvoelker has joined #openstack-meeting-alt11:18
*** markvoelker has quit IRC11:22
*** baojg has quit IRC11:54
*** baojg has joined #openstack-meeting-alt11:54
*** raildo has joined #openstack-meeting-alt12:01
*** vishakha has joined #openstack-meeting-alt12:05
*** rfolco has joined #openstack-meeting-alt12:08
*** ricolin has joined #openstack-meeting-alt12:15
*** dave-mccowan has joined #openstack-meeting-alt12:27
*** diurnalist has joined #openstack-meeting-alt12:33
*** diurnalist has quit IRC12:37
*** baojg has quit IRC12:44
*** baojg has joined #openstack-meeting-alt12:45
*** rcernin_ has quit IRC12:54
*** ricolin has quit IRC12:56
*** bnemec has joined #openstack-meeting-alt13:38
*** baojg has quit IRC13:46
*** baojg has joined #openstack-meeting-alt13:47
*** yaawang has quit IRC14:05
*** yaawang has joined #openstack-meeting-alt14:05
*** ricolin has joined #openstack-meeting-alt14:21
*** markmcclain has quit IRC14:23
*** markmcclain has joined #openstack-meeting-alt14:24
*** diurnalist has joined #openstack-meeting-alt14:32
gagehugo#startmeeting openstack-helm15:00
openstackMeeting started Tue Jul 21 15:00:08 2020 UTC and is due to finish in 60 minutes.  The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot.15:00
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:00
*** openstack changes topic to " (Meeting topic: openstack-helm)"15:00
*** andrii_ostapenko has joined #openstack-meeting-alt15:00
openstackThe meeting name has been set to 'openstack_helm'15:00
gagehugo#link https://etherpad.opendev.org/p/openstack-helm-weekly-meeting agenda15:00
lamt\o15:00
*** sangeet has joined #openstack-meeting-alt15:00
gagehugoo/15:01
sangeeto/15:01
andrii_ostapenkoo/15:01
megheisler\o15:04
gagehugo#topic Remove opensuse support15:05
*** openstack changes topic to "Remove opensuse support (Meeting topic: openstack-helm)"15:05
gagehugoandrii o/15:05
andrii_ostapenkoso I was working on introducing testing for images in osh-images and faced lots of failures with build of leap related failures. Tin suggested we should disable opensuse builds since there's no support of them for almost a year15:07
andrii_ostapenkohttps://review.opendev.org/#/c/74182415:08
gagehugoThat's fine15:08
gagehugoCan always be re-enabled15:08
gagehugothanks andrii15:10
gagehugo#topic open discussion15:10
*** openstack changes topic to "open discussion (Meeting topic: openstack-helm)"15:10
gagehugoAnyone have anything else for this week?  The floor is open15:10
andrii_ostapenkoalso related to images testing changes to review https://review.opendev.org/#/c/741855 and https://review.opendev.org/#/c/74182315:11
andrii_ostapenkoI also spent some time to reverse engineer buildset registry thing - ephemeral registry that is spinned up for particular set of builds for one change to have a pre-review images testing - https://review.opendev.org/#/c/74155115:12
andrii_ostapenkobasically we have this ability now15:13
andrii_ostapenkothough I think it's enough to have it on post-review only15:13
gagehugoThanks everyone, have a good week15:17
gagehugo#endmeeting15:17
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/"15:17
openstackMeeting ended Tue Jul 21 15:17:36 2020 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:17
openstackMinutes:        http://eavesdrop.openstack.org/meetings/openstack_helm/2020/openstack_helm.2020-07-21-15.00.html15:17
openstackMinutes (text): http://eavesdrop.openstack.org/meetings/openstack_helm/2020/openstack_helm.2020-07-21-15.00.txt15:17
openstackLog:            http://eavesdrop.openstack.org/meetings/openstack_helm/2020/openstack_helm.2020-07-21-15.00.log.html15:17
*** baojg has quit IRC15:20
*** baojg has joined #openstack-meeting-alt15:21
*** gyee has joined #openstack-meeting-alt15:41
*** ricolin has quit IRC16:02
*** strigazi has joined #openstack-meeting-alt16:06
*** diurnalist has quit IRC16:10
*** sangeet has quit IRC16:16
*** sangeet has joined #openstack-meeting-alt16:19
*** sangeet has quit IRC16:24
*** priteau has quit IRC16:28
*** diurnalist has joined #openstack-meeting-alt16:38
*** ralonsoh_ has joined #openstack-meeting-alt16:41
*** ralonsoh has quit IRC16:43
knikolla#startmeeting keystone16:59
openstackMeeting started Tue Jul 21 16:59:23 2020 UTC and is due to finish in 60 minutes.  The chair is knikolla. Information about MeetBot at http://wiki.debian.org/MeetBot.16:59
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.16:59
*** openstack changes topic to " (Meeting topic: keystone)"16:59
openstackThe meeting name has been set to 'keystone'16:59
knikollao/16:59
vishakhao/16:59
whoami-rajat__Hi17:00
*** derekh has quit IRC17:01
*** priteau has joined #openstack-meeting-alt17:01
knikollai'll give it a few more minutes in hope of having some form of quorum.17:03
gagehugoo/17:06
lbragstado/o/17:09
knikollaseems like we have enough attendance to proceed :)17:09
knikolla#topic Review Requests17:10
*** openstack changes topic to "Review Requests (Meeting topic: keystone)"17:10
vishakha#link https://review.opendev.org/#/c/737225/ This patch closes bug targeted for victoria miltstone 217:11
vishakha#link https://review.opendev.org/#/c/739784/ , that closes-bug #link https://bugs.launchpad.net/keystone/+bug/1886017 need one more approval17:12
openstackLaunchpad bug 1886017 in OpenStack Identity (keystone) ""allow expired" feature is broken against json web token" [Medium,In progress] - Assigned to Vishakha Agarwal (vishakha.agarwal)17:12
vishakhaand a small one #link https://review.opendev.org/#/c/742233/17:13
knikollathanks, added to my to-do list. i had somehow missed the first one.17:13
knikolla#topic Bugs17:16
*** openstack changes topic to "Bugs (Meeting topic: keystone)"17:16
knikollalast week we talked about https://review.opendev.org/#/c/731087/17:16
vishakha#link https://review.opendev.org/#/c/731087/, we discussed this in the last meeting but did not come to any conclusion. There were two approaches for this one, to update the operators about deleting stale role in release note or to go for upgrade check17:16
knikollai think the upgrade check method was problematic in not working within the same release, but requiring an upgrade.17:17
knikollaso i thought we were okay with a release note.17:17
knikollaand apparently there was a precedent.17:18
vishakhaYes there was. Since all are okay to update release notes with a SQL query to remove stale role assignments17:19
vishakhaI will update the patch set.17:19
vishakhaThanks knikolla17:20
*** priteau has quit IRC17:21
knikolla#topic Keystone project hierarchy manual validation17:22
*** openstack changes topic to "Keystone project hierarchy manual validation (Meeting topic: keystone)"17:22
knikollawhoami-rajat__: o/17:22
whoami-rajat__Hi everyone17:22
whoami-rajat__I've some doubts regarding the hierarchical multi tenancy spec17:23
whoami-rajat__So currently cinder quotas validate the project in the following manner17:23
whoami-rajat__1) if context project is immediate parent of the target project17:23
whoami-rajat__2) context project is the root of the subtree for which the target project is a part of17:24
whoami-rajat__#link https://github.com/openstack/cinder/blob/master/cinder/api/contrib/quotas.py#L91-L11017:24
whoami-rajat__so my questions are, is the sub project part of keystone still promoted/used or replaced by a better solution17:25
whoami-rajat__second, if it's still used, is our method of validation mentioned above right?17:25
knikollalooking at the code17:26
whoami-rajat__also (if my question doesn't sound too dumb), what does is_admin_project signify? I've seen that being true in all the combinations of project and users17:28
knikollais_admin_project was a previous attempt to solve the issue with admin on a project being admin everywhere, but we've deprecated that approach in favor of system scope for admin operations.17:30
whoami-rajat__ack. would be great to know if any project has used that feature for authorization17:31
knikollawhoami-rajat__: you mean the admin project or the new system scoping?17:31
whoami-rajat__system scoping17:32
knikollanova has implemented it, but it's not enabled by default. keystone as well, but likewise, it's not enabled by default.17:32
whoami-rajat__ok. would refer nova for the same.17:33
knikollain https://github.com/openstack/cinder/blob/be4a682890e6c5aeee0f34891a80bfbe2aab7c6a/cinder/api/contrib/quotas.py#L95 i'm not sure why you're checking if the scoped project has a parent (first half of the conditional)17:33
*** ralonsoh_ has quit IRC17:33
whoami-rajat__knikolla: if it has a parent means it's not the root of the tree, and it should be the immediate parent of the target project17:34
knikollaah, got it.17:34
knikollaif it is the root it doesn't matter if it's not the immediate parent of the target.17:34
whoami-rajat__yep, that's my understanding of this validation check17:35
knikollai don't think any other project has validation checks in place to allow operations only on the immediate parent (or root)17:35
knikollaso this is something new to me.17:36
whoami-rajat__oh17:36
whoami-rajat__i thought this was the purpose of hierarchical projects17:36
knikollai think we envisioned these sort of operations to be performed by the domain admin.17:36
knikollalbragstad, gagehugo: correct me if i'm wrong on ^17:37
whoami-rajat__just for some more context, we're developing a new feature which will enable default types for each project. so this is the only validation in place in cinder17:38
whoami-rajat__to set, get or delete default types for a project17:38
whoami-rajat__If there's a better way to authorize this, would be great to know that17:39
*** alistarle has joined #openstack-meeting-alt17:39
knikollahttps://docs.openstack.org/keystone/latest/admin/service-api-protection.html17:39
knikollathis is how we envisioned the different permission levels that people may require17:40
knikollain particular Domain Administrators17:40
*** ralonsoh has joined #openstack-meeting-alt17:41
whoami-rajat__all this info exists in the context right?17:41
lbragstadoslo.context knows how to represent systme-scoped tokens, yes17:42
knikollayes, a project has a domain_id, and the token would have either system-scope (for global admin) or domain-scope on that domain (for domain admin)17:42
whoami-rajat__I've one context dict that i took out while debugging the code17:44
whoami-rajat__http://paste.openstack.org/show/796184/17:44
*** alistarle has quit IRC17:44
knikolla'project_domain_id': 'default'17:44
knikollabut ideally, you should use oslo.policy for the policy checking and not really need to do this in code manually17:45
whoami-rajat__yes, we use context.authorize but i guess it just authorizes the user is an admin or owner or ... depending on the policy in code17:45
whoami-rajat__https://github.com/openstack/cinder/blob/master/cinder/api/contrib/quotas.py#L171-L17217:46
*** alistarle has joined #openstack-meeting-alt17:46
whoami-rajat__or maybe I've some limited understanding of the policies17:48
knikollathere is a popup team to help address this openstack-wide https://wiki.openstack.org/wiki/Consistent_and_Secure_Default_Policies_Popup_Team17:49
knikollanot sure if raildo is around17:50
raildoknikolla, o/17:50
alistarleHi, about these oslo.limit review : https://review.opendev.org/#/c/733881/ then https://review.opendev.org/#/c/726929/, do we have any status ?17:51
whoami-rajat__knikolla: yeah Brian is the cinder liaison but has the same doubts as me :D17:51
whoami-rajat__knikolla: anyway, thanks a lot for all the information17:51
whoami-rajat__i will go through it and let you know if i have more doubts?17:52
knikollawhoami-rajat__: of course, this is definitely a longer discussion than just this meeting and should be tracked in an etherpad.17:52
raildowhoami-rajat__, we can talk about that on #openstack-keystone after the meeting, if you want to17:52
whoami-rajat__knikolla: raildo  Thanks but it is very late here in India, 23:23 , can we discuss this tomorrow?17:53
raildowhoami-rajat__, for sure, just ping me whenever you see me online :)17:54
whoami-rajat__raildo: sure, thanks a lot :)17:54
knikollaalistarle: i can have a look at them, but they're not my area of expertise. I'd defer to either lbragstad or cmurphy on them.17:56
alistarleGood, I think at least the first one is pretty staightforward, and it is a requirement for the second, which is a requirement for glance integration :D17:56
lbragstadwhoami-rajat__ if you need help with the policy work or understanding it, just let me know17:58
whoami-rajat__thanks lbragstad , sure :)17:58
lbragstadwhoami-rajat__ i'd be happy to set aside some time and organize a high-bandwidth meeting if necessary17:58
whoami-rajat__i think Brian would be interested in that as well17:59
knikollawe used to have a weekly meeting just for policy stuff around 2 years ago.17:59
knikollaalright, we're out of time, off to #openstack-keystone.18:00
knikollathanks all18:00
knikolla#endmeeting18:00
whoami-rajat__thanks everyone!18:00
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/"18:00
openstackMeeting ended Tue Jul 21 18:00:19 2020 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)18:00
openstackMinutes:        http://eavesdrop.openstack.org/meetings/keystone/2020/keystone.2020-07-21-16.59.html18:00
openstackMinutes (text): http://eavesdrop.openstack.org/meetings/keystone/2020/keystone.2020-07-21-16.59.txt18:00
openstackLog:            http://eavesdrop.openstack.org/meetings/keystone/2020/keystone.2020-07-21-16.59.log.html18:00
*** ralonsoh has quit IRC18:08
*** alistarle has quit IRC18:14
*** diurnalist has quit IRC18:24
*** vishalmanchanda has quit IRC18:26
*** diurnalist has joined #openstack-meeting-alt18:35
*** diurnalist has quit IRC18:39
*** diurnalist has joined #openstack-meeting-alt18:49
*** sangeet has joined #openstack-meeting-alt19:35
*** sangeet has left #openstack-meeting-alt19:35
*** vishakha has quit IRC20:27
*** e0ne has quit IRC20:27
*** ircuser-1 has joined #openstack-meeting-alt20:40
*** raildo has quit IRC21:08
*** rcernin_ has joined #openstack-meeting-alt22:22
*** rcernin has joined #openstack-meeting-alt22:34
*** bnemec has quit IRC22:47
*** rdopiera has quit IRC22:50

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!