| opendevreview | Matt Crees proposed openstack/election master: Add Matt Crees candidacy for Blazar PTL 2027.1 https://review.opendev.org/c/openstack/election/+/1000414 | 07:55 |
|---|---|---|
| fungi | reminder that there's another public meeting of the openinfra foundation governing board in approximately two hours, at 15:00 utc, details at https://board.openinfra.org/meetings/2026-08-11 for those interested in attending | 13:04 |
| opendevreview | Andriy Kurilin proposed openstack/election master: Add Andriy Kurilin candidacy for Rally 2027.1 PTL https://review.opendev.org/c/openstack/election/+/1000456 | 13:41 |
| opendevreview | Merged openstack/security-doc master: [OSSN-0106] Ironic API ramdisk endpoints require network-level access controls https://review.opendev.org/c/openstack/security-doc/+/1000120 | 15:32 |
| gouthamr | tc-members: a gentle reminder that our weekly irc meeting will be hosted here in ~40 minutes | 16:21 |
| gouthamr | the agenda is here: https://wiki.openstack.org/wiki/Meetings/TechnicalCommittee#Agenda | 16:22 |
| gouthamr | #startmeeting tc | 17:00 |
| opendevmeet | Meeting started Tue Aug 11 17:00:45 2026 UTC and is due to finish in 60 minutes. The chair is gouthamr. Information about MeetBot at http://wiki.debian.org/MeetBot. | 17:00 |
| opendevmeet | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 17:00 |
| opendevmeet | The meeting name has been set to 'tc' | 17:00 |
| gouthamr | Welcome to the weekly meeting of the OpenStack Technical Committee. A reminder that this meeting is held under the OpenInfra Code of Conduct available at https://openinfra.dev/legal/code-of-conduct. | 17:01 |
| gouthamr | Today's meeting agenda can be found at https://wiki.openstack.org/wiki/Meetings/TechnicalCommittee | 17:01 |
| gouthamr | #topic Roll Call | 17:01 |
| frickler | o/ | 17:02 |
| mharley[m] | \o/ | 17:02 |
| spotz[m] | o/ | 17:02 |
| mnasiadka | o/ | 17:03 |
| gouthamr | courtesy-ping: noonedeadpunk, dansmith, cardoe, bauzas | 17:04 |
| cardoe | o/ | 17:05 |
| gouthamr | i _think_ i saw vacation notices from noonedeadpunk and bauzas elsewhere, but i'm not sure | 17:05 |
| gouthamr | alright, let's get started.. | 17:06 |
| gouthamr | #topic Last Week's Action Items | 17:06 |
| gouthamr | guess summertime is bad to make progress on some of this.. so i'll table stuff that no onedead punk was working on.. | 17:07 |
| gouthamr | we published the charter change proposal from frickler on treating "core reviewers" as AC/APC | 17:08 |
| gouthamr | fungi: you had the implementation follow up, ty for working on it | 17:08 |
| gouthamr | anything to discuss regarding that? | 17:09 |
| fungi | hoping to have it done before nominations end, in case we have any that don't qualify under the old rules | 17:09 |
| gouthamr | ++ | 17:09 |
| spotz[m] | I don't think we've started verifying candidates yet, could be wrong though | 17:10 |
| gouthamr | i see candidacies being proposed and merged | 17:10 |
| spotz[m] | Ok, I know Ian and Slaweq have an etherpad, haven't had a chance to peek at it | 17:11 |
| gouthamr | ack, the nomination window closes on Aug 19th 2026 23:45 UTC | 17:12 |
| mharley[m] | I was thinking about candidating myself to the TC. :-) | 17:13 |
| gouthamr | so under 10 days, which is hopefully good time to see PTL and TC candidacies being proposed | 17:13 |
| gouthamr | nice mnasiadka | 17:13 |
| gouthamr | ugh, tab complete. mharley[m]* | 17:14 |
| spotz[m] | It's nice to see a fresh face who comes to the meetings | 17:14 |
| gouthamr | this week is the final week to see Extra-AC submissions | 17:14 |
| mharley[m] | Oh, OK. | 17:15 |
| gouthamr | if you're in a SIG or project team that would like to recognize contributors, please do via this process | 17:15 |
| gouthamr | here's an example of how the i18n SIG does it: | 17:16 |
| gouthamr | #link https://review.opendev.org/c/openstack/governance/+/941743 (Propose Extra-ACs from I18n SIG (2025.1)) | 17:16 |
| gouthamr | i'll renew the ACs added here: | 17:17 |
| gouthamr | #link https://review.opendev.org/c/openstack/governance/+/956836 (Add Extra ACs for governance repositories) right after this meeting | 17:17 |
| gouthamr | the next action item was dangling work to get the github.com/openstack/cursive mirror working | 17:17 |
| gouthamr | has there been any work on this? or does it need some attention from oslo maintainers? | 17:19 |
| fungi | i'm chipping away at it, the job now has the authentication/authorization it needs, but it's hitting some conflicts from half-completed transfers i've been fixing up manually | 17:20 |
| gouthamr | ah, thank you fungi | 17:20 |
| fungi | basically just lingering cleanup now that the keys have been replaced | 17:21 |
| gouthamr | alright, its a wrap on action items.. it's a busy couple of weeks in OpenStack land with a triple-whammy of M-3/feature freeze for cycle-with-rc deliverables.. alongside elections; and with people taking much-needed time away for summer | 17:22 |
| gouthamr | was there anything else you were working on that you wanted to note? | 17:22 |
| gouthamr | okay, let's move to the next topic | 17:24 |
| gouthamr | #topic PQC Migration Pop-up Team update (Mauricio Harley) | 17:24 |
| gouthamr | mharley[m]: the floor is yours | 17:24 |
| mharley[m] | \o/ | 17:24 |
| mharley[m] | Thanks, gouthamr . | 17:24 |
| mharley[m] | Hello, everyone. | 17:24 |
| mharley[m] | So, I just wanted to provide a quick update on the PQC pop-up team. We completed the cross-project cryptographic inventory earlier this year: almost 600 findings across 30 project areas, published on the wiki at https://wiki.openstack.org/wiki/Post_quantum_openstack. | 17:25 |
| mharley[m] | The critical areas are key generation in Barbican and Castellan, token signing in Keystone, image signing through openstacksdk and cursive, and TLS configuration across multiple operators. I personally think the TLS part is the most challenging one. | 17:26 |
| gouthamr | what are operators? | 17:27 |
| gouthamr | in this context | 17:27 |
| mharley[m] | I mean, multiple projects. | 17:27 |
| mnasiadka | I’m surprised skydive is there - it’s been dead for like 2 years | 17:28 |
| mharley[m] | We currently have about 20 patches across roughly 10 projects, 8 already merged and 12 under review. | 17:29 |
| mharley[m] | Mentioning the already merged ones, we have landed TLS 1.3 hardening in Ironic and IPA, we also added PQC readiness configuration in Designate, cleaned up deprecated crypto dependencies in global requirements, and we got JWT signing algorithm made configurable in Keystone. | 17:29 |
| mharley[m] | And still under review, we have... | 17:29 |
| gmaan | but if that is configurable it is still ok right? I mean if we have hardcoded tls vesion <1.3 then it is issue otherwise user can choose the >1.3 | 17:29 |
| mharley[m] | Crypto-agility work in Barbican, PBKDF2 hardening and SAML signing improvements in Keystone, TLS modernization in oslo.messaging, HMAC upgrade in osprofiler, CMS deprecation in python-keystoneclient, SSH cipher control in networking-generic-switch, PQC check mode for Octavia, and TLS readiness for ovn-octavia-provider. | 17:30 |
| mharley[m] | That's right, gmaan . Crypto-agility is the key keyword here. The proposal is not to break anything, but simply choose safer options. | 17:31 |
| mharley[m] | Based on all this, I'm working on a community goal proposal to coordinate the remaining effort across projects, mainly around TLS modernization, crypto-agility, and finding a path forward for an quantum-safe alternative to paramiko. | 17:32 |
| gmaan | 'choose safer options' you mean test if safe option work and not 'make it min or madatory or default' | 17:32 |
| mharley[m] | That's correct. | 17:32 |
| fungi | it could influence decisions as to what behaviors to make default in new releases | 17:32 |
| mharley[m] | Give the possibility to choose a safer option. | 17:32 |
| mharley[m] | I plan to send the community goal proposal to openstack-discuss for feedback before formally submitting it on Gerrit. | 17:33 |
| gmaan | ok because changing default still can break things so 'possibility to choose safer option' is better even those are not default | 17:33 |
| mharley[m] | Sure thing. | 17:33 |
| clarkb | mlkem for paramiko is proposed in https://github.com/paramiko/paramiko/pull/2668 but does require openssl 3.5 or newer | 17:34 |
| mharley[m] | If there's anyone interested in helping out or co-sponsoring, feel free to join us on #openstack-pqc. I'll be more than happy to take questions. | 17:34 |
| mharley[m] | Yeah, clarkb, but this is depending on a single person availability... And we have some evidence that libssh could be a good candidate for it. | 17:35 |
| mharley[m] | That PR is quite new BTW. The author submitted another before this one, closed it and opened the one you referred. | 17:35 |
| clarkb | sure but if the option is upgrade paramiko or completely replace it with an unrelated library/tool one seems easier | 17:36 |
| clarkb | yes its from alex gaynor | 17:36 |
| mharley[m] | Replacement is not the best therm here. I'd choose propose an alternative. A quantum-safe option that is at least as capable as paramiko. | 17:37 |
| fungi | but to be clear, libssh is not a drop-in replacement for paramiko | 17:37 |
| mharley[m] | In other words, lose no functionalities whereas at the same time obtaining crypto protection. | 17:37 |
| mharley[m] | That's why I used "could be", fungi . ;-) The verifications are not done at all. | 17:38 |
| fungi | yep | 17:39 |
| mharley[m] | Folks, what I'm communicating here is that we progressed towards discovering weaknesses in the codebase, we already proposed several patches (some of them merged) and we are crafting a plan (the community goal) to tackle the other topics. | 17:39 |
| mharley[m] | Does anyone have questions about this marvelous topic? | 17:40 |
| gouthamr | yeah, thanks for that update.. i'm glad to see the progress that the pop up team's been making. I think it's still very dense to catch up on the wiki.. consider a short, human-readable update to the ML perhaps, or brief posts tackling specific topics | 17:40 |
| mharley[m] | Good tip, gouthamr. Thanks a lot. | 17:41 |
| spotz[m] | Thanks mharley | 17:41 |
| mharley[m] | Appreciate it, spotz. | 17:41 |
| gouthamr | and all of this is good if it's tested/documented.. the FIPS testing wound was cut deep, and is still bleeding | 17:42 |
| mharley[m] | Yeah, I'm aware of that wound... | 17:43 |
| gouthamr | have you been getting project maintainer feedback as you folks work through this? anything major/at risk that we need to be aware of? | 17:43 |
| clarkb | the upside to this problem space is you can easily default to these options or enable them without reboots and special deployments | 17:43 |
| clarkb | so testing shouldn't be difficult | 17:43 |
| gouthamr | +1 | 17:43 |
| cardoe | Yeah the Ironic project has been looking at the issues around paramiko and netmiko with the switch configuration plugin / code. | 17:44 |
| gouthamr | that, for cinder/manila would be painful as well i'd assume | 17:46 |
| gouthamr | s/assume/know | 17:46 |
| gouthamr | i presume we'll catch up on this as one of the subtopics elsewhere | 17:47 |
| gouthamr | anything else to share here, mharley[m]? | 17:47 |
| mharley[m] | You're right, gouthamr. Manila is quite "affected" by Paramiko. | 17:47 |
| mharley[m] | That's it, sir. Thank you for the room. :-) | 17:47 |
| mharley[m] | So, please stay put for the community goal. I hope to send it out still this month. | 17:48 |
| gouthamr | good stuff, thanks for the update, and for all the work you folks have been doing.. | 17:48 |
| mharley[m] | We appreciate it. | 17:48 |
| cardoe | https://specs.openstack.org/openstack/ironic-specs/specs/not-implemented/ngs-libssh-migration.html is the ironic effort to switch away from netmiko/paramiko | 17:49 |
| gouthamr | fresh off the presses | 17:50 |
| cardoe | It's worth noting that some hardware vendors don't work with libssh | 17:50 |
| spotz[m] | do we have a list of which ones? | 17:52 |
| gouthamr | worth digging into as a separate topic | 17:52 |
| gouthamr | it'll be a rabbit hole, and the ironic/cinder/manila teams may have more insights to share | 17:52 |
| gouthamr | let's move down the agenda | 17:53 |
| gouthamr | #topic A check on gate health | 17:53 |
| gouthamr | any updates to share wrt the gate this week? | 17:53 |
| fungi | nothing major, we did have some job failures in one region because the apache proxy cache on the mirror server was using space faster than the cache cleaner could free it | 17:54 |
| cardoe | spotz[m]: I don't. Just a note committed to the docs of netmiko after the libssh backend was added. | 17:54 |
| fungi | so we adjusted the cache cleaning frequency to hopefully address that | 17:54 |
| spotz[m] | Ok thanks | 17:54 |
| clarkb | there was also the anubis honeypot issue with gitea | 17:54 |
| clarkb | that reexposed that many Zuul jobs are not using the zuul git caches that zuul prepares for them | 17:55 |
| fungi | oh right, that affected some jobs that were connecting to gitea instead of using zuul-provided checkouds | 17:55 |
| clarkb | (they are talking to gitea instead which they shouldn't do) | 17:55 |
| fungi | checkouts | 17:55 |
| fungi | it seems like some projects had precommit configured to grab the hacking plugin via git remote url not from a local copy | 17:56 |
| clarkb | I think sean-k-mooney figured out how to do that properly but I don't know if it landed anywhere | 17:56 |
| * gouthamr recalls this discussion on this channel months ago | 17:56 | |
| * gouthamr summons sean-k-mooney :D | 17:57 | |
| clarkb | yes this issue was brought up when we were getting DDoS'd more effectively | 17:57 |
| clarkb | and it recurred due to an unexpected anubis behavior after we upgraded to 1.26.2 | 17:57 |
| gouthamr | ack | 17:58 |
| sean-k-mooney | yes but i didnt get that merge yet | 17:59 |
| sean-k-mooney | i can get the change one sec | 17:59 |
| fungi | the new anubis behavior was also possibly complicated by how we do load balancing between the gitea servers | 17:59 |
| gouthamr | we're at the hour.. | 18:00 |
| gouthamr | #topic Open Discussion | 18:00 |
| gouthamr | was there anything else to note for the meeting today? | 18:00 |
| gouthamr | i'll try and make some room for the tracker in future meetings.. i was going down the list myself.. if you own any items over there, please add your updates | 18:01 |
| gouthamr | I updated https://wiki.openstack.org/wiki/CrossProjectLiaisons to drop the VMT/security liaisons since we started maintaining these on the governance repo as of the last couple of weeks | 18:01 |
| gouthamr | we're starting to use that info in the VMT | 18:02 |
| sean-k-mooney | clarkb: fungi https://review.opendev.org/q/topic:%22local-pre-commit%22 | 18:03 |
| gouthamr | ty ^ | 18:03 |
| gouthamr | alright, let's wrap it up here.. | 18:03 |
| gouthamr | thank you all for attending | 18:03 |
| gouthamr | #endmeeting | 18:03 |
| opendevmeet | Meeting ended Tue Aug 11 18:03:47 2026 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 18:03 |
| opendevmeet | Minutes: https://meetings.opendev.org/meetings/tc/2026/tc.2026-08-11-17.00.html | 18:03 |
| opendevmeet | Minutes (text): https://meetings.opendev.org/meetings/tc/2026/tc.2026-08-11-17.00.txt | 18:03 |
| opendevmeet | Log: https://meetings.opendev.org/meetings/tc/2026/tc.2026-08-11-17.00.log.html | 18:03 |
| sean-k-mooney | https://review.opendev.org/c/openstack/watcher/+/983933/1/.pre-commit-config.yaml the tl;dr is almost all the hook we actully use are packaged on pyps as concoled scrtip | 18:04 |
| spotz[m] | Goutham log in:) | 18:04 |
| gouthamr | ah coming spotz[m] | 18:05 |
| sean-k-mooney | so instead of using a hook via git you can just defein a local hook that uses the cli direcly and that will use our pip caches | 18:05 |
| clarkb | sean-k-mooney: thanks | 18:05 |
| sean-k-mooney | clarkb: stephenfin tired to get native supprot added to pre-commit but the maintnaer didnt want to do it | 18:05 |
| sean-k-mooney | clarkb: he then followed up with the prek rust version and they were open to it | 18:05 |
| clarkb | sean-k-mooney: which is crazy to me since thats the primary way people consume this software not through git | 18:06 |
| sean-k-mooney | clarkb: so fi that has merge in prek we coudl also swap to that potically | 18:06 |
| clarkb | like having the option for both seems fine, but not having the otpion for the primary tool is weird to me | 18:06 |
| sean-k-mooney | https://github.com/j178/prek/issues/1925 | 18:06 |
| sean-k-mooney | ah its now a dicussion https://github.com/j178/prek/discussions/2520 | 18:07 |
| cardoe | sean-k-mooney: +++++++ prek | 18:08 |
| sean-k-mooney | anyway i need ot revivie that locall hook patch | 18:08 |
| sean-k-mooney | i jsut had other thing on my plate | 18:08 |
| sean-k-mooney | i woudl prefer the prek feature if it becomes a thing | 18:08 |
| sean-k-mooney | as its cleaner | 18:08 |
| sean-k-mooney | but both work | 18:08 |
| sean-k-mooney | i.e. - repo: pypi_package:ruff | 18:08 |
| sean-k-mooney | rev: "0.16.0" | 18:09 |
| sean-k-mooney | hooks: | 18:09 |
| sean-k-mooney | - id: ruff-format | 18:09 |
| sean-k-mooney | is a log clener then definign the same hook locally and manually declaring the dep | 18:09 |
| sean-k-mooney | which looks like this | 18:09 |
| sean-k-mooney | - id: ruff-format | 18:10 |
| sean-k-mooney | name: ruff-format | 18:10 |
| sean-k-mooney | language: python | 18:10 |
| sean-k-mooney | entry: ruff format --force-exclude | 18:10 |
| sean-k-mooney | types_or: [python, pyi, jupyter] | 18:10 |
| sean-k-mooney | require_serial: true | 18:10 |
| sean-k-mooney | additional_dependencies: ['ruff==0.15.7'] | 18:10 |
| sean-k-mooney | clarkb: if this is still causing pain for hacking specificly that is easy to update to a local hook without needign to update all the others | 18:11 |
| sean-k-mooney | clarkb: so we coudl jsut do it for hacking intially | 18:12 |
| fungi | it's probably the main offender in openstack's projects, just because of how many projects rely on it for linting | 18:13 |
| sean-k-mooney | oh lol | 18:13 |
| sean-k-mooney | https://github.com/openstack/watcher/blob/master/.pre-commit-config.yaml#L111-L119 | 18:13 |
| sean-k-mooney | ok that did merge and i didnt notice | 18:13 |
| clarkb | I mean at this point I'm happy to let ya'll jobs fail when they don't need to :P | 18:13 |
| clarkb | I've described the problem multiple times including when I objected to pre-commit in the first place | 18:13 |
| clarkb | I'd just appreciate if people went "oh ya this is the problem we were warned about don't need to bug clarkb about this failure" | 18:13 |
| sean-k-mooney | we have not had an issue with this for watcher that i can tell since we mad ethat change | 18:13 |
| sean-k-mooney | ill add moving cybrog to my todo list before the end of the cycle | 18:14 |
| sean-k-mooney | speaking of todo list i need to create my ptl election nominaiton this week... | 18:15 |
| dansmith | gouthamr: sorry about the meeting I got stuck somewhere unexpectedly | 19:57 |
| fungi | i swear i wasn't the one who poured glue on your chair | 19:58 |
| dansmith | uh, "metaphorically stuck" :P | 20:00 |
| gouthamr | haha, all good dansmith! | 20:13 |
| gouthamr | sean-k-mooney: adding more to the train: https://review.opendev.org/q/topic:%22local-pre-commit%22 | 20:31 |
| opendevreview | Merged openstack/election master: Add Matt Crees candidacy for Blazar PTL 2027.1 https://review.opendev.org/c/openstack/election/+/1000414 | 21:35 |
| opendevreview | Merged openstack/election master: Add Artem Goncharov candidacy for OpenStackSDK PTL https://review.opendev.org/c/openstack/election/+/1000320 | 21:42 |
| opendevreview | Merged openstack/election master: Add Artem Goncharov candidacy for Keystone PTL https://review.opendev.org/c/openstack/election/+/1000321 | 21:42 |
| opendevreview | Merged openstack/election master: Add Erkin Mussurmankulov candidacy for Trove PTL https://review.opendev.org/c/openstack/election/+/1000328 | 21:44 |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!