*** fredli__ has joined #openstack-meeting-cp | 01:01 | |
*** markvoelker has quit IRC | 01:40 | |
*** markvoelker has joined #openstack-meeting-cp | 01:41 | |
*** markvoelker has quit IRC | 01:45 | |
*** yamahata_ has quit IRC | 01:56 | |
*** fredli__ has quit IRC | 02:02 | |
*** yamahata_ has joined #openstack-meeting-cp | 03:00 | |
*** markvoelker has joined #openstack-meeting-cp | 03:29 | |
*** aselius has quit IRC | 03:47 | |
*** gouthamr has quit IRC | 04:43 | |
*** MarkBaker has joined #openstack-meeting-cp | 04:49 | |
*** MarkBaker has quit IRC | 04:55 | |
*** MarkBaker has joined #openstack-meeting-cp | 05:00 | |
*** MarkBaker has quit IRC | 05:10 | |
*** pewp has quit IRC | 05:40 | |
*** pewp has joined #openstack-meeting-cp | 05:44 | |
*** diablo_rojo has quit IRC | 05:57 | |
*** MarkBaker has joined #openstack-meeting-cp | 06:08 | |
*** MarkBaker has quit IRC | 06:17 | |
*** markvoelker has quit IRC | 07:00 | |
*** markvoelker has joined #openstack-meeting-cp | 07:00 | |
*** markvoelker has quit IRC | 07:01 | |
*** markvoelker has joined #openstack-meeting-cp | 07:01 | |
*** markvoelker has quit IRC | 07:01 | |
*** edmondsw has joined #openstack-meeting-cp | 07:03 | |
*** markvoelker has joined #openstack-meeting-cp | 07:07 | |
*** edmondsw has quit IRC | 07:08 | |
*** f13o has joined #openstack-meeting-cp | 07:23 | |
*** edmondsw has joined #openstack-meeting-cp | 08:51 | |
*** edmondsw has quit IRC | 08:56 | |
*** yamahata_ has quit IRC | 08:57 | |
*** MarkBaker has joined #openstack-meeting-cp | 09:29 | |
*** MarkBaker has quit IRC | 09:42 | |
*** MarkBaker has joined #openstack-meeting-cp | 09:44 | |
*** f13o has quit IRC | 10:09 | |
*** f13o has joined #openstack-meeting-cp | 10:23 | |
*** edmondsw has joined #openstack-meeting-cp | 10:39 | |
*** edmondsw has quit IRC | 10:45 | |
*** MarkBaker has quit IRC | 10:54 | |
*** f13o has quit IRC | 11:07 | |
*** beekhof has joined #openstack-meeting-cp | 11:12 | |
*** f13o has joined #openstack-meeting-cp | 11:20 | |
*** edmondsw has joined #openstack-meeting-cp | 12:21 | |
*** pewp has quit IRC | 12:57 | |
*** pewp has joined #openstack-meeting-cp | 13:04 | |
*** f13o has quit IRC | 13:06 | |
*** gouthamr has joined #openstack-meeting-cp | 13:06 | |
*** MarkBaker has joined #openstack-meeting-cp | 13:18 | |
*** f13o has joined #openstack-meeting-cp | 13:18 | |
*** MarkBaker_ has joined #openstack-meeting-cp | 13:42 | |
*** MarkBaker has quit IRC | 13:43 | |
*** diablo_rojo has joined #openstack-meeting-cp | 13:47 | |
*** MarkBaker_ has quit IRC | 13:48 | |
*** MarkBaker has joined #openstack-meeting-cp | 13:57 | |
*** zhipeng has joined #openstack-meeting-cp | 13:57 | |
*** MarkBaker has quit IRC | 14:12 | |
*** felipemonteiro has joined #openstack-meeting-cp | 14:14 | |
*** felipemonteiro_ has joined #openstack-meeting-cp | 14:15 | |
*** MarkBaker has joined #openstack-meeting-cp | 14:16 | |
*** felipemonteiro has quit IRC | 14:19 | |
*** zhipeng has quit IRC | 14:26 | |
*** f13o has quit IRC | 14:27 | |
*** MarkBaker has quit IRC | 14:28 | |
*** gouthamr has quit IRC | 14:37 | |
*** gouthamr has joined #openstack-meeting-cp | 14:37 | |
*** aselius has joined #openstack-meeting-cp | 14:40 | |
*** markvoelker has quit IRC | 14:40 | |
*** f13o has joined #openstack-meeting-cp | 14:40 | |
*** zhipeng has joined #openstack-meeting-cp | 14:42 | |
*** markvoelker has joined #openstack-meeting-cp | 14:57 | |
*** yamahata_ has joined #openstack-meeting-cp | 15:09 | |
*** david-lyle has joined #openstack-meeting-cp | 15:10 | |
*** f13o has quit IRC | 15:32 | |
*** felipemonteiro_ has quit IRC | 15:38 | |
*** Rockyg has joined #openstack-meeting-cp | 15:41 | |
*** zhipeng has quit IRC | 15:53 | |
*** blancos has joined #openstack-meeting-cp | 15:58 | |
*** markvoelker has quit IRC | 15:58 | |
*** markvoelker has joined #openstack-meeting-cp | 15:59 | |
*** diablo_rojo has quit IRC | 16:00 | |
lbragstad | #startmeeting policy | 16:00 |
---|---|---|
openstack | Meeting started Wed Jun 21 16:00:04 2017 UTC and is due to finish in 60 minutes. The chair is lbragstad. Information about MeetBot at http://wiki.debian.org/MeetBot. | 16:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 16:00 |
*** gagehugo has joined #openstack-meeting-cp | 16:00 | |
*** openstack changes topic to " (Meeting topic: policy)" | 16:00 | |
openstack | The meeting name has been set to 'policy' | 16:00 |
lbragstad | ping raildo, ktychkova, rderose, htruta, hrybacki, atrmr, gagehugo, lamt, thinrichs, edmondsw, ruan, ayoung, morgan, raj_singh, johnthetubaguy, knikolla, nhelgeson | 16:00 |
gagehugo | o/ | 16:00 |
blancos | o/ | 16:00 |
hrybacki | o/ | 16:00 |
lbragstad | o/ | 16:00 |
lbragstad | #link https://etherpad.openstack.org/p/keystone-policy-meeting | 16:00 |
lbragstad | agenda ^ | 16:00 |
morgan | Just 10 more minutes... I promise I'll wake up then :P | 16:00 |
*** diablo_rojo has joined #openstack-meeting-cp | 16:00 | |
lbragstad | morgan: sounds like a reason to hit snooze | 16:01 |
morgan | Or.. erm.. I guess I'm here :P | 16:01 |
hrybacki | lol | 16:01 |
morgan | Right!? | 16:01 |
lbragstad | i say that to my phone every morning | 16:01 |
*** gnarld_ is now known as cFouts | 16:01 | |
edmondsw | o/ | 16:02 |
lbragstad | alrighty - let's go ahead and get started | 16:02 |
lbragstad | pretty light agenda today - so we should have plenty of time to discuss open topics | 16:02 |
lbragstad | #topic policy-docs goal | 16:02 |
*** openstack changes topic to "policy-docs goal (Meeting topic: policy)" | 16:02 | |
lbragstad | #link https://review.openstack.org/#/c/469954/ | 16:03 |
lbragstad | queens goals are getting firmed up | 16:03 |
hrybacki | how many rolecall votes do we need to land this | 16:03 |
lbragstad | those those unfamiliar with that proposal - it would be great to get your feedback on it | 16:03 |
lbragstad | hrybacki: i believe it needs the majority or unanimous vote from the TC | 16:03 |
hrybacki | how many members are on the TC? | 16:04 |
lbragstad | and the members of the TC are the only ones with Rollcall power, I believe | 16:04 |
* hrybacki googles | 16:04 | |
hrybacki | okay, 3 more votes and we are gold | 16:04 |
lbragstad | hrybacki: https://review.openstack.org/#/admin/groups/205,members | 16:05 |
lbragstad | #link https://review.openstack.org/#/admin/groups/205,members | 16:05 |
hrybacki | lbragstad++ | 16:05 |
lbragstad | which leads to our next topic | 16:05 |
lbragstad | #topic policy-docs patches | 16:05 |
*** openstack changes topic to "policy-docs patches (Meeting topic: policy)" | 16:05 | |
lbragstad | #link https://review.openstack.org/#/q/status:open+project:openstack/keystone+branch:master+topic:bp/policy-docs | 16:05 |
lbragstad | we only have a few patches left | 16:06 |
lbragstad | i approved a couple yesterday | 16:06 |
hrybacki | I'm close with https://review.openstack.org/#/c/449278/ -- trying to resolve one more failing test that's being a pain | 16:06 |
lbragstad | hrybacki: sounds good | 16:06 |
lbragstad | #link https://review.openstack.org/#/c/449244/ looks ready to go | 16:06 |
lbragstad | #link https://review.openstack.org/#/c/449337/ is also ready to go but I proposed it so i'll abstain from merging it | 16:07 |
lbragstad | #link https://review.openstack.org/#/c/449255/ is in the same boat | 16:07 |
hrybacki | I'll take a look at the later two after this mtg | 16:08 |
lbragstad | awesome | 16:09 |
lbragstad | moving on | 16:09 |
lbragstad | #topic global roles work | 16:09 |
*** openstack changes topic to "global roles work (Meeting topic: policy)" | 16:09 | |
lbragstad | #link https://review.openstack.org/#/c/464763/ is proposed to backlog | 16:09 |
*** felipemonteiro has joined #openstack-meeting-cp | 16:09 | |
lbragstad | we have several other specs proposed to backlog as well | 16:09 |
*** felipemonteiro_ has joined #openstack-meeting-cp | 16:10 | |
lbragstad | even though we are in specification freeze, I'd be ok merging some of those to backlog (pending reviews) since it won't affect our work for Pike | 16:10 |
lbragstad | I'm also planning on setting aside time next week to start writing that implementation | 16:10 |
lbragstad | and get something in review well before the PTG | 16:10 |
lbragstad | #topic open discussion | 16:11 |
*** openstack changes topic to "open discussion (Meeting topic: policy)" | 16:11 | |
hrybacki | out-of-band: how does backlog work for upstream projects? | 16:11 |
lbragstad | hrybacki: good question - if we generally agree on something we should do as a project, or a spec, but don't have bandwidth to implement in the current cycle, we merge it to backlog | 16:12 |
lbragstad | when we're ready to commit resources to it, its moved from the backlog directory to the release we want to target | 16:12 |
hrybacki | ah I see the directory now | 16:12 |
lbragstad | during the move from backlog, we take the opportunity to update any stale information in the spec (like the people picking up the implementation) | 16:13 |
* hrybacki nods | 16:13 | |
hrybacki | So are you envisioning moving this out of backlog before Pike GA? | 16:13 |
lbragstad | so - in this case, we'd try to merge global roles to backlog, and then as soon as spec freeze is lifted we'd repropose it to queens | 16:13 |
*** felipemonteiro has quit IRC | 16:14 | |
* hrybacki nods | 16:14 | |
hrybacki | I understand now, thanks lbragstad | 16:14 |
*** spilla has joined #openstack-meeting-cp | 16:14 | |
lbragstad | hrybacki: anything | 16:14 |
lbragstad | anytime* rather | 16:14 |
lbragstad | do folks have anything else policy wise? | 16:14 |
hrybacki | lbragstad: you feel good about the state of policy and docs in code? | 16:15 |
hrybacki | in that we'll likely have votes we need in time | 16:15 |
lbragstad | hrybacki: i think it's a good path forward and it seems to have positive support | 16:16 |
lbragstad | our next step will be working with the oslo.policy team quite a bit | 16:16 |
lbragstad | we'll need to develop some functionality in that library in order for some of the policy-in-code and policy-docs work to be super useful | 16:17 |
* hrybacki nods | 16:17 | |
lbragstad | but that will be work in queens for sure | 16:17 |
lbragstad | edmondsw: have you heard any follow up on the scoping for global tokens? | 16:18 |
lbragstad | edmondsw: i believe that discussion was hanging on security vs. usability related concerns | 16:19 |
edmondsw | lbragstad no, I've totally lost track of that | 16:19 |
lbragstad | edmondsw: ok | 16:19 |
edmondsw | haven't had a chance to look at anything policy related in a while | 16:19 |
lbragstad | edmondsw: i haven't heard much either - last thing i did was drop a line in #openstack-security asking for advice | 16:19 |
lbragstad | maybe i should go poke again | 16:20 |
edmondsw | do you remember what the concerns were? or where someone wrote them down? | 16:20 |
lbragstad | edmondsw: yeah | 16:20 |
lbragstad | edmondsw: the useability concern was that global roles would be adding yet another scoping mechanism that users have to know about in order to do something | 16:21 |
lbragstad | (e.g. i want to live migrate, so i need a globally scoped token from keystone) | 16:21 |
lbragstad | the argument was that it makes things harder for clients | 16:21 |
lbragstad | and users to understand | 16:21 |
edmondsw | I just pulled up the global roles spec, and my first comment is going to be that I don't know that live migrate is a great example | 16:22 |
lbragstad | i believe gyee wrote that concern down in the spec | 16:22 |
lbragstad | edmondsw: if you can think of a better example, I'll incorporate it into the current revision for sure | 16:22 |
edmondsw | lbragstad the prime example in my mind is something like nova's GET /v2.1/servers?all_tenants | 16:23 |
edmondsw | you shouldn't be able to see things in all tenants unless you have a global role assignment | 16:23 |
lbragstad | that works today if a user has the admin role, right? | 16:23 |
edmondsw | right | 16:23 |
lbragstad | aha - ok | 16:23 |
lbragstad | agreed | 16:23 |
lbragstad | well... | 16:24 |
lbragstad | you need the global role assignment and it needs to match the role required for that policy in nova | 16:24 |
lbragstad | (if i'm thinking about this right) | 16:24 |
edmondsw | right | 16:24 |
lbragstad | ok - cool | 16:24 |
lbragstad | we're on the same page then | 16:24 |
edmondsw | so you could just have an observer role, not necessarily admin, as long as it was globally scoped | 16:25 |
lbragstad | edmondsw: if you leave a comment, i can update the spec with that example instead | 16:25 |
edmondsw | will do | 16:25 |
lbragstad | edmondsw: right - yep | 16:25 |
lbragstad | sounds like i have a few action itmes | 16:26 |
lbragstad | #action lbragstad to update the global roles spec with better examples of global operations | 16:26 |
lbragstad | #action lbragstad to follow up with the security team on the usability vs. security concerns of using unscoped tokens for global roles | 16:26 |
lbragstad | cool - does anyone have anything else? | 16:27 |
*** yamahata_ has quit IRC | 16:28 | |
lbragstad | looks like we'll get some time back - thanks all! | 16:28 |
lbragstad | #endmeeting | 16:28 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings" | 16:28 | |
openstack | Meeting ended Wed Jun 21 16:28:49 2017 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 16:28 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/policy/2017/policy.2017-06-21-16.00.html | 16:28 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/policy/2017/policy.2017-06-21-16.00.txt | 16:28 |
hrybacki | o/ | 16:28 |
openstack | Log: http://eavesdrop.openstack.org/meetings/policy/2017/policy.2017-06-21-16.00.log.html | 16:28 |
*** blancos has left #openstack-meeting-cp | 16:30 | |
*** MarkBaker has joined #openstack-meeting-cp | 16:33 | |
*** gagehugo has left #openstack-meeting-cp | 16:44 | |
*** harlowja has joined #openstack-meeting-cp | 17:07 | |
*** yamahata_ has joined #openstack-meeting-cp | 17:09 | |
*** MarkBaker has quit IRC | 18:01 | |
*** pewp has quit IRC | 18:08 | |
*** pewp has joined #openstack-meeting-cp | 18:11 | |
*** Rockyg has quit IRC | 18:17 | |
*** stvnoyes has left #openstack-meeting-cp | 18:19 | |
*** kbyrne has quit IRC | 18:22 | |
*** kbyrne has joined #openstack-meeting-cp | 18:23 | |
*** spilla has left #openstack-meeting-cp | 18:51 | |
*** MarkBaker has joined #openstack-meeting-cp | 19:34 | |
*** MarkBaker has quit IRC | 19:46 | |
*** benj_ has quit IRC | 19:49 | |
*** MarkBaker has joined #openstack-meeting-cp | 19:49 | |
*** benj_ has joined #openstack-meeting-cp | 19:51 | |
*** gouthamr has quit IRC | 20:09 | |
*** gouthamr has joined #openstack-meeting-cp | 20:48 | |
*** markvoelker has quit IRC | 22:04 | |
*** markvoelker_ has joined #openstack-meeting-cp | 22:06 | |
*** markvoelker_ has quit IRC | 22:11 | |
*** felipemonteiro_ has quit IRC | 22:12 | |
*** markvoelker has joined #openstack-meeting-cp | 22:17 | |
*** brault has quit IRC | 22:51 | |
*** sdague has quit IRC | 23:11 | |
*** diablo_rojo has quit IRC | 23:33 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!