*** harlowja has joined #openstack-meeting-cp | 00:06 | |
*** lamt has joined #openstack-meeting-cp | 00:39 | |
*** jkomg has quit IRC | 01:15 | |
*** jkomg has joined #openstack-meeting-cp | 01:16 | |
*** jkomg has quit IRC | 01:20 | |
*** jkomg has joined #openstack-meeting-cp | 01:21 | |
*** lamt has quit IRC | 01:22 | |
*** bswartz has quit IRC | 01:24 | |
*** ducttape_ has joined #openstack-meeting-cp | 01:25 | |
*** jkomg has quit IRC | 01:25 | |
*** stevemar has quit IRC | 01:27 | |
*** brault has quit IRC | 01:27 | |
*** stevemar has joined #openstack-meeting-cp | 01:29 | |
*** brault has joined #openstack-meeting-cp | 01:29 | |
*** diablo_rojo has joined #openstack-meeting-cp | 01:47 | |
*** diablo_rojo has quit IRC | 01:48 | |
*** diablo_rojo has joined #openstack-meeting-cp | 01:49 | |
*** edtubill has joined #openstack-meeting-cp | 01:51 | |
*** mars has joined #openstack-meeting-cp | 01:54 | |
*** ducttape_ has quit IRC | 02:24 | |
*** ducttape_ has joined #openstack-meeting-cp | 02:29 | |
*** harlowja has quit IRC | 02:36 | |
*** mars has quit IRC | 02:45 | |
*** mars has joined #openstack-meeting-cp | 03:02 | |
*** ducttape_ has quit IRC | 03:15 | |
*** lcastell has quit IRC | 03:22 | |
*** luzC has quit IRC | 03:23 | |
*** diablo_rojo has quit IRC | 03:27 | |
*** gouthamr has quit IRC | 03:28 | |
*** diablo_rojo has joined #openstack-meeting-cp | 03:30 | |
*** sheel has joined #openstack-meeting-cp | 03:34 | |
*** alij has joined #openstack-meeting-cp | 03:46 | |
*** alij has quit IRC | 03:51 | |
*** lcastell has joined #openstack-meeting-cp | 04:20 | |
*** luzC has joined #openstack-meeting-cp | 04:22 | |
*** alij has joined #openstack-meeting-cp | 05:35 | |
*** alij has quit IRC | 06:35 | |
*** alij has joined #openstack-meeting-cp | 06:43 | |
*** edtubill has quit IRC | 07:02 | |
*** edtubill has joined #openstack-meeting-cp | 07:04 | |
*** rarcea has joined #openstack-meeting-cp | 07:07 | |
*** edtubill has quit IRC | 07:08 | |
*** alij_ has joined #openstack-meeting-cp | 07:12 | |
*** alij has quit IRC | 07:12 | |
*** alij has joined #openstack-meeting-cp | 07:13 | |
*** alij_ has quit IRC | 07:17 | |
*** dfflanders has quit IRC | 07:29 | |
*** diablo_rojo has quit IRC | 07:32 | |
*** jkomg has joined #openstack-meeting-cp | 07:36 | |
*** jkomg has quit IRC | 07:40 | |
*** alij has quit IRC | 07:40 | |
*** rarcea_ has joined #openstack-meeting-cp | 08:04 | |
*** rarcea has quit IRC | 08:04 | |
*** alij has joined #openstack-meeting-cp | 08:04 | |
*** rarcea_ has quit IRC | 08:05 | |
*** rarcea has joined #openstack-meeting-cp | 08:05 | |
*** markvoelker has joined #openstack-meeting-cp | 08:26 | |
*** alij has quit IRC | 08:29 | |
*** alij has joined #openstack-meeting-cp | 09:13 | |
*** dfflanders has joined #openstack-meeting-cp | 09:26 | |
*** alij has quit IRC | 10:05 | |
*** beisner has quit IRC | 10:21 | |
*** beisner has joined #openstack-meeting-cp | 10:22 | |
*** alij has joined #openstack-meeting-cp | 11:01 | |
*** dfflanders has quit IRC | 11:05 | |
*** alij has quit IRC | 11:06 | |
*** jkomg has joined #openstack-meeting-cp | 11:40 | |
*** jkomg has quit IRC | 11:44 | |
*** sdague has joined #openstack-meeting-cp | 12:25 | |
*** ducttape_ has joined #openstack-meeting-cp | 12:44 | |
*** alij has joined #openstack-meeting-cp | 13:06 | |
*** ducttape_ has quit IRC | 13:09 | |
*** alij has quit IRC | 13:10 | |
*** lamt has joined #openstack-meeting-cp | 13:23 | |
*** alij has joined #openstack-meeting-cp | 13:24 | |
*** lamt has quit IRC | 13:24 | |
*** alij has quit IRC | 13:30 | |
*** ducttape_ has joined #openstack-meeting-cp | 13:53 | |
*** xyang1 has joined #openstack-meeting-cp | 13:54 | |
*** alij has joined #openstack-meeting-cp | 13:57 | |
*** daniela_ebert has joined #openstack-meeting-cp | 13:57 | |
*** alij has quit IRC | 14:02 | |
*** daniela_ebert has quit IRC | 14:08 | |
*** gouthamr has joined #openstack-meeting-cp | 14:13 | |
*** diablo_rojo_phon has joined #openstack-meeting-cp | 14:55 | |
*** alij has joined #openstack-meeting-cp | 14:59 | |
*** alij has quit IRC | 15:03 | |
*** ducttape_ has quit IRC | 15:10 | |
*** david-lyle has joined #openstack-meeting-cp | 15:13 | |
*** openstack has joined #openstack-meeting-cp | 15:18 | |
*** ChanServ sets mode: +o openstack | 15:18 | |
*** ttx has quit IRC | 15:19 | |
*** sheeprine has quit IRC | 15:19 | |
*** notmyname has quit IRC | 15:19 | |
*** dstanek has quit IRC | 15:19 | |
*** mgagne has quit IRC | 15:19 | |
*** Daviey has quit IRC | 15:19 | |
*** DuncanT has quit IRC | 15:19 | |
*** eeiden has quit IRC | 15:19 | |
*** reed has quit IRC | 15:19 | |
*** mrhillsman has quit IRC | 15:19 | |
*** fungi has quit IRC | 15:19 | |
*** sheeprine has joined #openstack-meeting-cp | 15:19 | |
*** notmyname has joined #openstack-meeting-cp | 15:19 | |
*** fungi has joined #openstack-meeting-cp | 15:20 | |
*** mrhillsman has joined #openstack-meeting-cp | 15:20 | |
*** ttx has joined #openstack-meeting-cp | 15:21 | |
*** dstanek has joined #openstack-meeting-cp | 15:22 | |
*** mgagne has joined #openstack-meeting-cp | 15:22 | |
*** Daviey has joined #openstack-meeting-cp | 15:22 | |
*** reed has joined #openstack-meeting-cp | 15:22 | |
*** mgagne has quit IRC | 15:23 | |
*** mgagne has joined #openstack-meeting-cp | 15:23 | |
*** mgagne is now known as Guest58531 | 15:23 | |
*** DuncanT has joined #openstack-meeting-cp | 15:27 | |
*** bswartz has joined #openstack-meeting-cp | 15:33 | |
*** david-lyle has quit IRC | 15:36 | |
*** david-lyle_ has joined #openstack-meeting-cp | 15:36 | |
*** david-lyle_ has quit IRC | 15:37 | |
*** david-lyle_ has joined #openstack-meeting-cp | 15:37 | |
*** sheel has quit IRC | 15:37 | |
*** david-lyle_ has quit IRC | 15:41 | |
*** homerp has quit IRC | 15:42 | |
*** kencjohnston_ has quit IRC | 15:42 | |
*** homerp has joined #openstack-meeting-cp | 15:42 | |
*** kencjohnston has joined #openstack-meeting-cp | 15:43 | |
*** david-lyle has joined #openstack-meeting-cp | 15:47 | |
*** ducttape_ has joined #openstack-meeting-cp | 15:48 | |
*** jaugustine has joined #openstack-meeting-cp | 15:50 | |
*** eeiden has joined #openstack-meeting-cp | 15:53 | |
*** ravelar has joined #openstack-meeting-cp | 15:57 | |
*** gagehugo has joined #openstack-meeting-cp | 15:58 | |
*** _ducttape_ has joined #openstack-meeting-cp | 15:58 | |
*** alij has joined #openstack-meeting-cp | 15:59 | |
*** morgan has joined #openstack-meeting-cp | 16:00 | |
lbragstad | #startmeeting policy | 16:00 |
---|---|---|
openstack | Meeting started Wed Jan 18 16:00:14 2017 UTC and is due to finish in 60 minutes. The chair is lbragstad. Information about MeetBot at http://wiki.debian.org/MeetBot. | 16:00 |
lbragstad | ping raildo, ktychkova, dolphm, dstanek, rderose, htruta, atrmr, gagehugo, lamt, thinrichs, edmondsw, ruan, ayoung, stevemar, ravelar | 16:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 16:00 |
*** openstack changes topic to " (Meeting topic: policy)" | 16:00 | |
openstack | The meeting name has been set to 'policy' | 16:00 |
lbragstad | agenda #link https://etherpad.openstack.org/p/keystone-policy-meeting | 16:00 |
gagehugo | o/ | 16:00 |
morgan | lbragstad: you should add me to the ping list | 16:00 |
stevemar | o/ | 16:00 |
rderose | o/ | 16:00 |
*** diablo_rojo has joined #openstack-meeting-cp | 16:00 | |
morgan | o/ | 16:00 |
lbragstad | ping raildo, ktychkova, dolphm, dstanek, rderose, htruta, atrmr, gagehugo, lamt, thinrichs, edmondsw, ruan, ayoung, stevemar, ravelar, morgan | 16:00 |
lbragstad | :) | 16:00 |
gagehugo | o/ | 16:00 |
lbragstad | morgan done | 16:00 |
morgan | lbragstad: tyvm | 16:00 |
knikolla | o/ | 16:01 |
lbragstad | also - if anyone knows of anyone else that is interested in policy and isn't on the ping list, let them know | 16:01 |
lbragstad | (cross project especially) | 16:01 |
*** ducttape_ has quit IRC | 16:01 | |
lbragstad | # topic Recap discussion from mailing list | 16:02 |
lbragstad | #topic Recap discussion from the mailing list | 16:02 |
*** openstack changes topic to "Recap discussion from the mailing list (Meeting topic: policy)" | 16:02 | |
lbragstad | #link http://lists.openstack.org/pipermail/openstack-dev/2017-January/109967.html | 16:02 |
*** spilla has joined #openstack-meeting-cp | 16:02 | |
lbragstad | If you remember from last meeting, we wanted to try and come to consensus on the status of the two policy files we have | 16:02 |
lbragstad | Looks like we don't have any feedback so far :( | 16:02 |
lbragstad | If you have any thoughts or ideas, please don't hesitate to share them! | 16:03 |
lbragstad | cc morgan ^ | 16:03 |
morgan | so. i can say why we have 2 | 16:03 |
morgan | it is a very simple reason | 16:03 |
lbragstad | #topic keystone's policy file tribal knowledge | 16:03 |
*** openstack changes topic to "keystone's policy file tribal knowledge (Meeting topic: policy)" | 16:03 | |
stevemar | ++ to topic | 16:04 |
morgan | the orignial dumb file is installed by default and the v3 policy file would break many deployments not overriding it without new additional roles | 16:04 |
lbragstad | morgan go for it | 16:04 |
stevemar | lets all gather around the fire | 16:04 |
morgan | v3 policy file was created as a template for what we wanted | 16:04 |
*** alij has quit IRC | 16:04 | |
morgan | but things like bootstrap didn't exist | 16:04 |
lbragstad | morgan `keystone-manage boostrap`? | 16:04 |
morgan | so everything was done mostly in migrations and in direct sql injection | 16:04 |
morgan | lbragstad: yep | 16:04 |
lbragstad | ah | 16:05 |
stevemar | so how can we migrate over to the new one? | 16:05 |
morgan | the main reason we haven't pivoted to the v3 policy is because any deployment relying on dumb policy would stop working | 16:05 |
morgan | 2 options have been proposed | 16:05 |
morgan | break people (bad) | 16:05 |
morgan | but doable | 16:05 |
lbragstad | stevemar i have an idea how - but i'll wait for others to weigh in | 16:05 |
morgan | with a upgrade doc | 16:05 |
stevemar | are we really breaking people? they don't just blindly copy the file over | 16:05 |
lbragstad | morgan what would the upgrade consist of? | 16:06 |
morgan | 2: pivot the config for policy, make it shift to a new default if it exists (not "sample") we use it, | 16:06 |
morgan | with an upgrade doc | 16:06 |
morgan | stevemar: it's not us it is packagers | 16:06 |
morgan | and deployment tools | 16:06 |
morgan | some have in the past copied it | 16:06 |
morgan | with the death of v2 coming soon (tm), it may be an easier sell | 16:06 |
*** ruan_19 has joined #openstack-meeting-cp | 16:07 | |
morgan | the upgrade is setting up the new roles, assigning the roles to the right (user, project) combos | 16:07 |
morgan | and setting up things like is-admin-project (if needed) | 16:07 |
morgan | then dropping the policy file in place | 16:07 |
morgan | many production systems still just use :admin: and :member: and the very limited default policy | 16:07 |
morgan | so we need to communicate the deprecation and encode the new stuff in the tools such as `keystone manage-bootstrap` | 16:08 |
morgan | AND we need dsvm to run with v3 policy | 16:08 |
morgan | right now it can't afaik | 16:08 |
lbragstad | morgan so bootstrap would be used to create new roles? | 16:08 |
stevemar | lbragstad: just a handful? | 16:08 |
morgan | lbragstad: or at least it needs a template for the proper defaults | 16:09 |
morgan | probably a yaml that sets the mappings up | 16:09 |
morgan | so a deployer can override the basics if needed (otherwise it;ll have like 5-10 more cli options to fill in) | 16:09 |
breton | fuel doesn't modify it and uses basically the on in etc/ | 16:09 |
lbragstad | got it - | 16:10 |
morgan | breton: thanks, that is my point right there. many tools use the simple basic policy file. | 16:10 |
lbragstad | so we have three options | 16:10 |
morgan | i am still an advocate for moving this way | 16:10 |
morgan | it just was a mire of mess before we had more of our own tools in place | 16:10 |
lbragstad | 1.) break people by just switching the default policy to the v3 cloud sample one | 16:10 |
breton | for example the new policy file will probably break hierarchical quotas in cinder | 16:11 |
lbragstad | 2.) use keystone-manage bootstrap to provide a migration path by creating new roles and assigning them | 16:11 |
*** markvoelker has quit IRC | 16:11 | |
morgan | now we have more options and with v2 coming up on eol, it becomes much more straight forward to say it makes sense to put the effort in, since v2 member/admin is still a requirement of roles | 16:11 |
morgan | without those roles v2 wont work | 16:11 |
breton | because cinder lists projects being an admin somewhere and in v3 it requires to be domain admin | 16:11 |
breton | *v3cloudsample | 16:12 |
morgan | it sounds like we need a dsvm to be able to be run that does the cross-gate thing to validate what all is horked | 16:12 |
morgan | and this is going to be a lot like getting people on v3 auth | 16:12 |
morgan | ftr | 16:12 |
morgan | a long, painful process | 16:12 |
morgan | (probably not as painful as v3 auth) | 16:12 |
breton | i also think it will make us re-think how we deal with service users now | 16:13 |
morgan | breton: that is mostly a function of what roles the cinder user has. | 16:13 |
morgan | breton: largely that is a v2 vs v3 thing that has been on the backburner | 16:13 |
breton | because today everybody assumes that service user is an admin (everywhere) and can do whatever it wants | 16:14 |
morgan | since v2 was still *required* until recently to run a cloud | 16:14 |
morgan | meaning admin just was the right choice | 16:14 |
morgan | anyway, story time is over :) | 16:14 |
morgan | now yall know the tribal history | 16:14 |
lbragstad | morgan thanks | 16:14 |
lbragstad | the third option would be | 16:14 |
lbragstad | option 3.) codify the existing (insufficient for v3) policy into oslo.policy like nova has done, and use tooling in oslo.policy to move the defaults to something that works for v3cloudsample | 16:15 |
lbragstad | so - using oslo.policy as the vehicle to consolidate | 16:15 |
morgan | that is option 3, which we didn't have until very recently | 16:16 |
lbragstad | morgan right | 16:16 |
morgan | i like options 2 and 3. | 16:16 |
lbragstad | I would be fine with either 2 or 3 depending on the migration of #2 | 16:16 |
morgan | option 1 is still distateful | 16:16 |
morgan | distasteful* | 16:16 |
lbragstad | right | 16:16 |
lbragstad | I would agree | 16:16 |
lbragstad | does anyone else have thoughts? | 16:16 |
morgan | regardless of the path, we need a gate job to test (like we have for v3 only) | 16:16 |
rderose | once v2 is eol'd, can we just move to the new policy file? | 16:17 |
lbragstad | morgan yeah - so the gate job would run with all v3cloudsample policies overriding the defaults | 16:17 |
morgan | rderose: same issues as before. we don't want to just break people | 16:18 |
lbragstad | rderose that's a good question, because I assume there will still be deployers that are using the *old* policy file | 16:18 |
morgan | but we can provide a clean migration path | 16:18 |
morgan | i think the migration path will be hard to build because who knows what people have done in their deployments | 16:18 |
lbragstad | right | 16:19 |
lbragstad | but that's the nice thing about option 3 | 16:19 |
ruan_19 | is it possilbe to delegate to an external PDP like Fortress? | 16:19 |
lbragstad | anything they have in their policy file will override the defaults | 16:19 |
*** alij has joined #openstack-meeting-cp | 16:19 | |
morgan | fwiw, i have always thought we should get much more prescriptive on required policy setup | 16:19 |
morgan | aka a service user looks like X | 16:19 |
morgan | and we start pushing down that path to force the issue | 16:19 |
morgan | with little wiggle room | 16:20 |
lbragstad | ruan_19 we have had people do that before - but fortress doesn't really take project scope into consideration | 16:20 |
morgan | i don't like taking options away from deployers, but in the case of policy, i think we need to | 16:20 |
morgan | ruan_19: we have support in oslo.policy, but we don't have anyone gating on it | 16:20 |
ruan_19 | I mean make the possibility to an external PDP | 16:20 |
morgan | ruan_19: we could, it is supported | 16:21 |
morgan | just not currently tested directly in that manner | 16:21 |
lbragstad | it would provide deployers with another option for policy enforcement | 16:21 |
morgan | lbragstad: i am not really usually for taking a ton of options away from deployers, but i thnk in the case of policy we (openstack) needs to be much more opinionated/prescriptive | 16:21 |
morgan | so we can have more consistency/better security story | 16:22 |
lbragstad | morgan i would agree | 16:22 |
ruan_19 | when I check the current code, the PDP delegation is not easy, we should modify the configuration file for each service | 16:22 |
morgan | ruan_19: correct. it is not easy, it is doable | 16:22 |
morgan | at least in keystone it is doable. it was a requirement from henrynash | 16:23 |
lbragstad | morgan so far - I envision that process starting with encoding policy into oslo.policy and using that to move to better defaults out of the box, then we should start documenting the patterns (hopefully into a community goal or project assertion?) | 16:23 |
morgan | lbragstad: that works for me. | 16:23 |
ruan_19 | if we agree to consolidate policies, the delegation will be easier | 16:23 |
lbragstad | i think it would be great to have a document that defines what policy is in openstack | 16:23 |
morgan | ruan_19: that is a hard sell, consolidations become difficult in the distributed architecture of openstack | 16:24 |
lbragstad | ruan_19 consolidate the policy files for each service? | 16:24 |
morgan | it becomes a distribution/chicken/egg issue and many tools used for configuration cannot handle it. | 16:24 |
morgan | it is not a bad idea, just we;ve been down the path many times | 16:24 |
morgan | just ask ayoung ;) | 16:24 |
morgan | so lots of pitfalls to navigate | 16:25 |
lbragstad | right - that's hard | 16:25 |
lbragstad | ruan_19 I assume you mean taking all policy files and collapsing them somewhere under a specific service | 16:25 |
ruan_19 | yes, what we are looking for | 16:26 |
ruan_19 | what we are working | 16:26 |
lbragstad | ayoung spent a lot of time trying to do that with his dynamic policy approach | 16:28 |
morgan | and with the policy api | 16:28 |
morgan | and with other things | 16:29 |
morgan | it really has been tried 5 or 6 ways now | 16:29 |
morgan | it still isn't a bad idea. it just has a lot of pitfalls | 16:29 |
morgan | like... what happens when a file is updated, how does the service know | 16:29 |
*** _ducttape_ has quit IRC | 16:29 | |
morgan | make sure distribution is there, make sure we don't add yet-another-round-trip to check if something is allowed | 16:30 |
lbragstad | i think strong arming the other projects to relinquish control of their policy files is going to be hard | 16:30 |
*** ducttape_ has joined #openstack-meeting-cp | 16:30 | |
lbragstad | i would opt for developing a clear and explicit set of guidelines that help them correct their policy on their own | 16:30 |
morgan | lbragstad: and a "keystone will stop using 'member' and 'admin' by XXX" | 16:30 |
morgan | lbragstad: by default | 16:30 |
lbragstad | right - we could make that a goal and have something to tie to each project, like a project tag | 16:31 |
rderose | morgan: ++ | 16:31 |
lbragstad | asserts:support-rich-rbac | 16:31 |
morgan | or... a gate job >.> | 16:31 |
lbragstad | asserts:supports-rich-rbac | 16:32 |
morgan | but sure. a tag if the TC is up for that type of tagging | 16:32 |
morgan | (psst stevemar weigh in here) | 16:32 |
lbragstad | morgan in addition to a gate job since it would have to be tested somehow | 16:32 |
*** ravelar has quit IRC | 16:34 | |
lbragstad | ok - so it sounds like we have an action item to document the tribal knowledge discussed here | 16:36 |
*** ducttape_ has quit IRC | 16:36 | |
lbragstad | and vocalize the options we have? | 16:36 |
morgan | sounds about right. | 16:36 |
lbragstad | then we can start moving forward on one | 16:36 |
morgan | make sure you drop a post to the operator list | 16:36 |
lbragstad | ++ | 16:36 |
*** _ducttape_ has joined #openstack-meeting-cp | 16:37 | |
lbragstad | i think once we have an upgrade path in place, we could probably start looking at what the defaults should be for each operation | 16:37 |
lbragstad | (and start moving towards a richer policy) | 16:37 |
*** edmondsw has joined #openstack-meeting-cp | 16:37 | |
lbragstad | but I would expect that work to come after we setup guidelines with other projects (?) | 16:38 |
lbragstad | for example; in OpenStack what should a 'reader' role be able to do? | 16:38 |
morgan | yep | 16:39 |
*** harlowja has joined #openstack-meeting-cp | 16:39 | |
morgan | i would also like to set much stricter guidelines on "service" accounts | 16:39 |
lbragstad | I would like to see if we could start having that discussion in ATL | 16:39 |
lbragstad | morgan example? | 16:40 |
*** jkomg has joined #openstack-meeting-cp | 16:40 | |
morgan | such as "cannot be admin" | 16:40 |
lbragstad | ah | 16:40 |
morgan | must have a "service" role... or some such | 16:40 |
lbragstad | so - identifying operations in openstack that a service user is required to perform | 16:40 |
morgan | make sure service accounts are really scoped to actions | 16:40 |
lbragstad | and only allowing those operations through that role | 16:40 |
morgan | not "can do whatever they want" | 16:41 |
lbragstad | right | 16:41 |
morgan | they may be "admin" in their service | 16:41 |
morgan | but not globally | 16:41 |
edmondsw | I think there should actually be different service roles for different services... e.g. "nova" role vs. "cinder" role | 16:41 |
lbragstad | that'd be a good security exercise | 16:41 |
morgan | we may also want to revisit unscoped roles. | 16:41 |
morgan | action to discuss within keystone | 16:41 |
morgan | it may make sense to go back on the previous choice and allow roles tht are not project/domain locked | 16:42 |
lbragstad | #action let's revisit the concept of unscoped roles | 16:42 |
morgan | it may not make sense for a service user to need a project scope for example. | 16:42 |
lbragstad | #action document the tribal knowledge around keystone's policy files in http://lists.openstack.org/pipermail/openstack-dev/2017-January/109967.html | 16:42 |
edmondsw | morgan I'm definitely of the opinion that we should support global role assignments | 16:42 |
morgan | but that is a keystone-specific convo being brought back from an action here | 16:43 |
morgan | i am unsure how i feel about global roles, but it is worth re-visiting the discussion | 16:43 |
edmondsw | and not just for service roles | 16:43 |
morgan | (it may also simplify 'cloud admin') | 16:43 |
morgan | long term. | 16:43 |
lbragstad | at this point - i'm open to any/all discussions | 16:43 |
edmondsw | it *definitely* simplifies cloud admin | 16:43 |
morgan | but a lot of mechanisms need to be fixed that assume "scope" if we do that | 16:43 |
morgan | since we're revisiting policy, we might as well revisit some core RBAC concepts we have had for a while | 16:44 |
*** ravelar has joined #openstack-meeting-cp | 16:46 | |
lbragstad | morgan like what? | 16:46 |
morgan | global roles | 16:46 |
morgan | ;) | 16:46 |
morgan | sorry, that was implied not said directly | 16:46 |
lbragstad | oh - sure | 16:46 |
lbragstad | ok - are there any action items that were missed? | 16:47 |
*** sheel has joined #openstack-meeting-cp | 16:48 | |
lbragstad | #topic open discussion | 16:49 |
*** openstack changes topic to "open discussion (Meeting topic: policy)" | 16:49 | |
lbragstad | does anyone have anything else? | 16:49 |
lbragstad | questions, comments, concerns, snide remarks? | 16:50 |
lbragstad | ;) | 16:50 |
lbragstad | alright - we can end early to give folks some time back | 16:51 |
* morgan throws things from the peanut gallery | 16:52 | |
lbragstad | thanks for coming and thanks for the discussion! | 16:52 |
lbragstad | #endmeeting | 16:52 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings" | 16:52 | |
openstack | Meeting ended Wed Jan 18 16:52:18 2017 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 16:52 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/policy/2017/policy.2017-01-18-16.00.html | 16:52 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/policy/2017/policy.2017-01-18-16.00.txt | 16:52 |
openstack | Log: http://eavesdrop.openstack.org/meetings/policy/2017/policy.2017-01-18-16.00.log.html | 16:52 |
*** _ducttape_ has quit IRC | 16:56 | |
*** ducttape_ has joined #openstack-meeting-cp | 16:56 | |
*** spilla has left #openstack-meeting-cp | 16:58 | |
*** edmondsw has left #openstack-meeting-cp | 16:59 | |
*** ruan_19 has quit IRC | 17:07 | |
*** MarkBaker has joined #openstack-meeting-cp | 17:14 | |
*** edtubill has joined #openstack-meeting-cp | 17:15 | |
*** ravelar has quit IRC | 17:16 | |
*** alij_ has joined #openstack-meeting-cp | 17:23 | |
*** alij has quit IRC | 17:23 | |
*** alij has joined #openstack-meeting-cp | 17:24 | |
*** edtubill has quit IRC | 17:27 | |
*** alij_ has quit IRC | 17:27 | |
*** harlowja has quit IRC | 17:33 | |
*** david-lyle is now known as bailing-wire | 17:37 | |
*** markvoelker has joined #openstack-meeting-cp | 17:38 | |
*** markvoelker_ has joined #openstack-meeting-cp | 17:44 | |
*** markvoelker has quit IRC | 17:46 | |
*** bailing-wire has quit IRC | 17:46 | |
*** alij has quit IRC | 17:48 | |
*** mugsie has left #openstack-meeting-cp | 17:48 | |
*** markvoelker has joined #openstack-meeting-cp | 17:58 | |
*** markvoelker_ has quit IRC | 18:01 | |
*** jkomg has quit IRC | 18:03 | |
*** jkomg has joined #openstack-meeting-cp | 18:04 | |
*** edtubill has joined #openstack-meeting-cp | 18:08 | |
*** MarkBaker has quit IRC | 18:13 | |
*** edtubill has quit IRC | 18:17 | |
*** alij has joined #openstack-meeting-cp | 18:18 | |
*** alij has quit IRC | 18:23 | |
*** gagehugo has left #openstack-meeting-cp | 18:50 | |
*** alij has joined #openstack-meeting-cp | 18:53 | |
*** edtubill has joined #openstack-meeting-cp | 18:55 | |
*** alij has quit IRC | 19:01 | |
*** diablo_rojo_phon has quit IRC | 19:10 | |
*** diablo_rojo_phon has joined #openstack-meeting-cp | 19:11 | |
*** bailing-wire has joined #openstack-meeting-cp | 20:00 | |
*** bailing-wire is now known as david-lyle | 20:02 | |
*** markvoelker_ has joined #openstack-meeting-cp | 20:03 | |
*** markvoelker has quit IRC | 20:05 | |
*** markvoelker_ has quit IRC | 20:32 | |
*** _ducttape_ has joined #openstack-meeting-cp | 20:36 | |
*** ducttape_ has quit IRC | 20:39 | |
*** jkomg has quit IRC | 20:46 | |
*** jkomg has joined #openstack-meeting-cp | 20:56 | |
*** jkomg has quit IRC | 21:01 | |
*** alij has joined #openstack-meeting-cp | 21:02 | |
*** alij has quit IRC | 21:06 | |
*** jaugustine has quit IRC | 21:11 | |
*** _ducttape_ has quit IRC | 21:28 | |
*** ducttape_ has joined #openstack-meeting-cp | 21:28 | |
*** gouthamr has quit IRC | 21:34 | |
*** diablo_rojo_phon has quit IRC | 21:50 | |
*** gouthamr has joined #openstack-meeting-cp | 21:57 | |
*** diablo_rojo_phon has joined #openstack-meeting-cp | 22:01 | |
*** alij has joined #openstack-meeting-cp | 22:16 | |
*** jaugustine has joined #openstack-meeting-cp | 22:17 | |
*** alij has quit IRC | 22:20 | |
*** david-lyle has quit IRC | 22:32 | |
*** david-lyle has joined #openstack-meeting-cp | 22:40 | |
*** rarcea has quit IRC | 22:41 | |
*** jaugustine has quit IRC | 22:43 | |
*** edtubill has quit IRC | 22:51 | |
*** jkomg has joined #openstack-meeting-cp | 22:59 | |
*** ducttape_ has quit IRC | 23:16 | |
*** sheel has quit IRC | 23:24 | |
*** fungi has quit IRC | 23:24 | |
*** stevemar has quit IRC | 23:24 | |
*** brault has quit IRC | 23:24 | |
*** sheel has joined #openstack-meeting-cp | 23:24 | |
*** fungi has joined #openstack-meeting-cp | 23:24 | |
*** stevemar has joined #openstack-meeting-cp | 23:24 | |
*** brault has joined #openstack-meeting-cp | 23:24 | |
*** xyang1 has quit IRC | 23:29 | |
*** SergeyLukjanov has quit IRC | 23:34 | |
*** SergeyLukjanov has joined #openstack-meeting-cp | 23:37 | |
*** alij has joined #openstack-meeting-cp | 23:38 | |
*** alij_ has joined #openstack-meeting-cp | 23:40 | |
*** alij has quit IRC | 23:40 | |
*** alij_ has quit IRC | 23:45 | |
*** SergeyLukjanov has quit IRC | 23:57 | |
*** SergeyLukjanov has joined #openstack-meeting-cp | 23:59 | |
*** SergeyLukjanov has quit IRC | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!