| *** edmondsw has quit IRC | 00:00 | |
| *** yamahata has quit IRC | 00:47 | |
| *** iyamahat has quit IRC | 00:48 | |
| *** edmondsw has joined #openstack-meeting-cp | 01:43 | |
| *** aselius has quit IRC | 01:46 | |
| *** feisky has joined #openstack-meeting-cp | 01:46 | |
| *** edmondsw has quit IRC | 01:48 | |
| *** gouthamr has joined #openstack-meeting-cp | 01:55 | |
| *** _pewp_ has quit IRC | 02:41 | |
| *** _pewp_ has joined #openstack-meeting-cp | 02:45 | |
| *** nhelgeson has quit IRC | 03:13 | |
| *** edmondsw has joined #openstack-meeting-cp | 03:32 | |
| *** edmondsw has quit IRC | 03:36 | |
| *** markvoelker has quit IRC | 04:03 | |
| *** dims has quit IRC | 05:02 | |
| *** eglute has quit IRC | 05:02 | |
| *** dhellmann has quit IRC | 05:02 | |
| *** ildikov has quit IRC | 05:02 | |
| *** tommylikehu has quit IRC | 05:02 | |
| *** kencjohnston_ has quit IRC | 05:02 | |
| *** tommylikehu has joined #openstack-meeting-cp | 05:02 | |
| *** ildikov has joined #openstack-meeting-cp | 05:02 | |
| *** dhellmann has joined #openstack-meeting-cp | 05:03 | |
| *** iyamahat has joined #openstack-meeting-cp | 05:04 | |
| *** eglute has joined #openstack-meeting-cp | 05:04 | |
| *** kencjohnston has joined #openstack-meeting-cp | 05:04 | |
| *** dims has joined #openstack-meeting-cp | 05:04 | |
| *** edmondsw has joined #openstack-meeting-cp | 05:19 | |
| *** edmondsw has quit IRC | 05:24 | |
| *** markvoelker has joined #openstack-meeting-cp | 06:04 | |
| *** coolsvap has joined #openstack-meeting-cp | 06:05 | |
| *** iyamahat_ has joined #openstack-meeting-cp | 06:15 | |
| *** iyamahat has quit IRC | 06:16 | |
| *** markvoelker has quit IRC | 06:38 | |
| *** gouthamr has quit IRC | 06:47 | |
| *** edmondsw has joined #openstack-meeting-cp | 07:08 | |
| *** edmondsw has quit IRC | 07:12 | |
| *** iyamahat_ has quit IRC | 07:23 | |
| *** iyamahat_ has joined #openstack-meeting-cp | 07:34 | |
| *** markvoelker has joined #openstack-meeting-cp | 07:35 | |
| *** iyamahat_ has quit IRC | 07:41 | |
| *** MarkBaker has joined #openstack-meeting-cp | 07:56 | |
| *** markvoelker has quit IRC | 08:08 | |
| *** edmondsw has joined #openstack-meeting-cp | 08:56 | |
| *** edmondsw has quit IRC | 09:00 | |
| *** markvoelker has joined #openstack-meeting-cp | 09:06 | |
| *** MarkBaker has quit IRC | 09:08 | |
| *** MarkBaker has joined #openstack-meeting-cp | 09:20 | |
| *** markvoelker has quit IRC | 09:39 | |
| *** feisky has quit IRC | 10:06 | |
| *** markvoelker has joined #openstack-meeting-cp | 10:36 | |
| *** edmondsw has joined #openstack-meeting-cp | 10:44 | |
| *** edmondsw has quit IRC | 10:48 | |
| *** markvoelker has quit IRC | 11:09 | |
| *** brault has quit IRC | 11:57 | |
| *** markvoelker has joined #openstack-meeting-cp | 12:07 | |
| *** kencjohnston has quit IRC | 12:12 | |
| *** ildikov has quit IRC | 12:12 | |
| *** knikolla has quit IRC | 12:13 | |
| *** kencjohnston has joined #openstack-meeting-cp | 12:14 | |
| *** ildikov has joined #openstack-meeting-cp | 12:15 | |
| *** knikolla has joined #openstack-meeting-cp | 12:15 | |
| *** brault has joined #openstack-meeting-cp | 12:17 | |
| *** markvoelker has quit IRC | 12:19 | |
| *** markvoelker has joined #openstack-meeting-cp | 12:20 | |
| *** brault has quit IRC | 12:22 | |
| *** brault has joined #openstack-meeting-cp | 12:22 | |
| *** markvoelker has quit IRC | 12:32 | |
| *** edmondsw has joined #openstack-meeting-cp | 12:32 | |
| *** markvoelker has joined #openstack-meeting-cp | 12:34 | |
| *** edmondsw has quit IRC | 12:36 | |
| *** edmondsw has joined #openstack-meeting-cp | 13:13 | |
| *** david-lyle has quit IRC | 13:36 | |
| *** gouthamr has joined #openstack-meeting-cp | 13:47 | |
| *** gouthamr has quit IRC | 13:49 | |
| *** gouthamr has joined #openstack-meeting-cp | 13:49 | |
| *** rarcea has joined #openstack-meeting-cp | 14:08 | |
| *** david-lyle has joined #openstack-meeting-cp | 14:10 | |
| *** MarkBaker has quit IRC | 14:21 | |
| *** coolsvap has quit IRC | 14:25 | |
| *** MarkBaker has joined #openstack-meeting-cp | 14:35 | |
| *** zhipeng has joined #openstack-meeting-cp | 14:50 | |
| *** zhipeng has quit IRC | 14:53 | |
| *** zhipeng has joined #openstack-meeting-cp | 15:04 | |
| *** aselius has joined #openstack-meeting-cp | 15:19 | |
| *** hemna_ has joined #openstack-meeting-cp | 15:24 | |
| *** Rockyg has joined #openstack-meeting-cp | 15:53 | |
| *** xyang1 has joined #openstack-meeting-cp | 15:57 | |
| *** zhipeng has quit IRC | 15:59 | |
| *** blancos has joined #openstack-meeting-cp | 15:59 | |
| *** zhipeng has joined #openstack-meeting-cp | 16:00 | |
| lbragstad | #startmeeting policy | 16:00 |
|---|---|---|
| openstack | Meeting started Wed Aug 23 16:00:05 2017 UTC and is due to finish in 60 minutes. The chair is lbragstad. Information about MeetBot at http://wiki.debian.org/MeetBot. | 16:00 |
| openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 16:00 |
| lbragstad | ping raildo, ktychkova, rderose, htruta, hrybacki, atrmr, gagehugo, lamt, thinrichs, edmondsw, ruan_he, ayoung, morgan, raj_singh, johnthetubaguy, knikolla, nhelgeson | 16:00 |
| *** openstack changes topic to " (Meeting topic: policy)" | 16:00 | |
| openstack | The meeting name has been set to 'policy' | 16:00 |
| edmondsw | o/ | 16:00 |
| lbragstad | #link https://etherpad.openstack.org/p/keystone-policy-meeting | 16:00 |
| lbragstad | agenda ^ | 16:00 |
| blancos | o/ | 16:00 |
| lbragstad | o/ | 16:00 |
| knikolla | o/ | 16:00 |
| lamt | o/ | 16:00 |
| lbragstad | i know we have a couple more folks join - so we'll wait a minute | 16:01 |
| lbragstad | joining* | 16:01 |
| lbragstad | alright - let's get started | 16:03 |
| lbragstad | short agenda today | 16:03 |
| lbragstad | #topic global roles update | 16:03 |
| *** openstack changes topic to "global roles update (Meeting topic: policy)" | 16:03 | |
| lbragstad | #link #link https://review.openstack.org/#/q/status:open+project:openstack/keystone+branch:master+topic:bp/global-roles | 16:03 |
| lbragstad | ^ there is the implementation for global role assignments for users and groups | 16:03 |
| hrybacki | o/ | 16:03 |
| lbragstad | i plan to get a patch up that allows you to get a globally scoped token by the end of the week | 16:04 |
| lbragstad | once i get a little more planning done for the PTG i'll start that | 16:04 |
| lbragstad | but please feel free to start playing with the implementation and reviewing | 16:04 |
| lbragstad | i'm always a fan of early feedback | 16:04 |
| lbragstad | more information on what we'll be doing for the PoC in Denver can be found in another etherpad | 16:05 |
| lbragstad | #link https://etherpad.openstack.org/p/keystone-global-roles-poc | 16:05 |
| lbragstad | that's about all i had for an update - does anyone have questions? | 16:06 |
| hrybacki | not atm, thanks for spear heading that lbragstad | 16:06 |
| lbragstad | yep! happy to | 16:06 |
| edmondsw | +1 | 16:06 |
| lbragstad | #topic open discussion | 16:06 |
| *** openstack changes topic to "open discussion (Meeting topic: policy)" | 16:06 | |
| lbragstad | floor is open | 16:07 |
| hrybacki | lbragstad: if no one has anything else, let's talk about global role vision per our earlier convo | 16:07 |
| lbragstad | hrybacki: go for it | 16:07 |
| hrybacki | okay, so tl;dr we want to think about where we would be in an ideal world e.g. what are the services fully responsible for vs keystone* | 16:08 |
| hrybacki | in a world where global roles are already a thing* | 16:08 |
| hrybacki | 1 second, my client is acting up | 16:09 |
| *** zhipeng has quit IRC | 16:10 | |
| *** Rocky_g has joined #openstack-meeting-cp | 16:11 | |
| *** markvoelker_ has joined #openstack-meeting-cp | 16:11 | |
| lbragstad | hrybacki: still having issues? | 16:12 |
| hrybacki | my browser keeps freezing up, sorry | 16:12 |
| lbragstad | hrybacki: just with irccloud? | 16:13 |
| *** Rockyg has quit IRC | 16:13 | |
| *** markvoelker has quit IRC | 16:13 | |
| lbragstad | ok - i can pick things up until hrybacki get's things squared away | 16:13 |
| lbragstad | i guess what he wanted clarification on was what policy definition/maintenance looks like after global roles are in place | 16:14 |
| lbragstad | and my initial response was that policy at the service should not consist of a scope check in policy, but in code, and the policy just consists of a mapping from the role to the action | 16:15 |
| knikolla | yes | 16:16 |
| edmondsw | +1 | 16:16 |
| lbragstad | is there anything else that should be tacked on to that? | 16:16 |
| *** coolsvap has joined #openstack-meeting-cp | 16:16 | |
| hrybacki | back, thanks lbragstad | 16:16 |
| lbragstad | hrybacki: get it working? | 16:16 |
| hrybacki | I think so. Maybe I just need to do some solid tab-closing maintenance | 16:17 |
| edmondsw | so the service responsibility is to do proper scope checking in code | 16:17 |
| lbragstad | edmondsw: yeah - i'd agree with that | 16:17 |
| hrybacki | What if we have a set of standard (Default) global roles | 16:18 |
| lbragstad | i think that will be easy to build on once projects have defaults in code | 16:18 |
| hrybacki | What if an operator decides to add a new global role | 16:18 |
| edmondsw | hrybacki you mean standard roles... it is an assignment that adds scope, and we don't have standard assignments | 16:18 |
| edmondsw | i.e., standard roles, not standard global roles | 16:19 |
| hrybacki | edmondsw: I'm thinking down the road. What if were to have standard global roles | 16:19 |
| lbragstad | standard roles being "project_admin" | 16:19 |
| edmondsw | we won't | 16:19 |
| hrybacki | agreed upon by the community e.g. a global observer | 16:19 |
| edmondsw | that would just be observer, not global observer | 16:19 |
| edmondsw | and then if you want bob to have that role globally, you give them a global role assignment. If you want julie to have that role on a specific project, you give them a project-specific assignment | 16:20 |
| lbragstad | yeah - then you can give something the `observer` role globally, to a project, or on a domain | 16:20 |
| hrybacki | /me nods | 16:20 |
| edmondsw | that's one of the beautiful things about what we're doing here... we avoid all that nonsense from previous discussions about the role itself having global scope | 16:21 |
| knikolla | agree with that. | 16:22 |
| lbragstad | then when projects move scope checks into code, the scope check enforces things automatically | 16:22 |
| lbragstad | operation.scope == 'global' but not context.global: | 16:22 |
| lbragstad | raise Forbidden | 16:22 |
| hrybacki | okay, thanks for fielding my questions :) | 16:23 |
| lbragstad | does that clear things up? | 16:23 |
| hrybacki | for now. I need to re-read the BPs keeping this in mind | 16:24 |
| lbragstad | anyone have anything else? | 16:24 |
| lbragstad | looks like we can get some time back | 16:25 |
| lbragstad | thanks for coming! | 16:25 |
| *** zhipeng has joined #openstack-meeting-cp | 16:25 | |
| lbragstad | #endmeeting | 16:25 |
| *** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings" | 16:25 | |
| openstack | Meeting ended Wed Aug 23 16:25:33 2017 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 16:25 |
| openstack | Minutes: http://eavesdrop.openstack.org/meetings/policy/2017/policy.2017-08-23-16.00.html | 16:25 |
| openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/policy/2017/policy.2017-08-23-16.00.txt | 16:25 |
| openstack | Log: http://eavesdrop.openstack.org/meetings/policy/2017/policy.2017-08-23-16.00.log.html | 16:25 |
| *** blancos has quit IRC | 16:25 | |
| hrybacki | o/ | 16:25 |
| *** rarcea has quit IRC | 16:29 | |
| *** zhipeng has quit IRC | 16:43 | |
| *** zhipeng has joined #openstack-meeting-cp | 16:43 | |
| *** zhipeng has quit IRC | 16:50 | |
| *** zhipeng has joined #openstack-meeting-cp | 16:55 | |
| *** zhipeng has quit IRC | 17:00 | |
| *** Rocky_g has quit IRC | 17:21 | |
| *** MarkBaker has quit IRC | 17:26 | |
| *** diablo_rojo has joined #openstack-meeting-cp | 17:41 | |
| *** diablo_rojo has quit IRC | 17:50 | |
| *** diablo_rojo has joined #openstack-meeting-cp | 17:50 | |
| *** gouthamr has quit IRC | 17:57 | |
| *** iyamahat has joined #openstack-meeting-cp | 18:00 | |
| *** gouthamr has joined #openstack-meeting-cp | 18:00 | |
| *** yamahata has joined #openstack-meeting-cp | 18:16 | |
| *** coolsvap has quit IRC | 18:25 | |
| *** brault has quit IRC | 18:44 | |
| *** diablo_rojo has quit IRC | 18:55 | |
| *** diablo_rojo has joined #openstack-meeting-cp | 19:05 | |
| *** aselius has quit IRC | 20:29 | |
| *** aselius has joined #openstack-meeting-cp | 20:39 | |
| *** diablo_rojo has quit IRC | 20:44 | |
| *** gouthamr has quit IRC | 20:58 | |
| *** edmondsw has quit IRC | 21:30 | |
| *** gouthamr has joined #openstack-meeting-cp | 21:35 | |
| *** xyang1 has quit IRC | 21:58 | |
| *** diablo_rojo has joined #openstack-meeting-cp | 22:08 | |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!