14:00:11 #startmeeting glance 14:00:11 Meeting started Thu Feb 16 14:00:11 2023 UTC and is due to finish in 60 minutes. The chair is pranali. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:00:11 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 14:00:11 The meeting name has been set to 'glance' 14:00:11 #topic roll call 14:00:11 #link https://etherpad.openstack.org/p/glance-team-meeting-agenda 14:00:17 o/ 14:00:43 o/ 14:00:54 o/ 14:01:20 o/ 14:02:29 o/ 14:02:34 shall we start ? I think almost everyone is here 14:03:06 let's go 14:03:08 let's start 14:03:12 #topic release/periodic jobs updates 14:03:33 This is M3 release this week and to tag m3 we need few patches to get merged which we will see in next topic 14:03:52 Periodic job all green except TIME_OUT for fips jobs & oslo-master RETRY_LIMIT 14:04:55 moving to next 14:04:58 #topic Code Reviews 14:05:08 #link https://review.opendev.org/c/openstack/glance/+/872522/8 - Enabled new defaults and scope checks by default 14:05:09 #link https://review.opendev.org/c/openstack/glance/+/873372/7 - Remove deprecated ``enforce_secure_rbac`` option 14:05:09 #link https://review.opendev.org/c/openstack/glance/+/874078/2 - Refresh Glance example configs for antelope milestone 3 14:05:09 #link https://review.opendev.org/c/openstack/glance/+/874079/2 - Release notes for Antelope Milestone 3 14:06:13 So, these SRBAC changes we need in m3, so I created a dependency chain for updated config refresh & releasenote patch on top of those 14:06:21 Kindly please have a look 14:06:21 all looks good to me 14:06:28 Yeah the main issue is the CI, isn't it? :) 14:06:36 yeah :) 14:06:47 fingers crossed .. 14:06:51 there is one more in queue, https://review.opendev.org/c/openstack/glance/+/866584 14:07:40 ohh did we miss this in last review party ? 14:07:48 Do we want this one in the release? 14:08:05 this was updated today 14:08:56 I think we can move it to next cycle but this should be decided by pranali 14:09:41 yeah we can move this to next cycle 14:09:52 I'm gonna mention this one more time for the record. We should not default to the new rbac and remove the options before the global adminness of project admins issue has been sorted. But you do what you do with that. 14:10:49 jokke_, old policies will be still there but just disabled by default 14:14:40 and as of now we don't have project admin related policy (admin scoped to project level) 14:16:08 abhishekk: that's the point. Anyone having project scoped admin credentials (for any other services that actually has them implemented) gets treated as global admin by glance. And this has been the issue from the very beginning and was supposed to be addressed before we start defaulting to rbac 14:17:52 AFAIK none of the project so far has project scoped admin implemented, 14:18:36 gmann, if you are around, do you have any specific views here? 14:20:18 jokke_, it would be helpful if you add your views on the patch so that gmann and other member can share their views there 14:20:59 shall we move to next ? 14:22:17 we can revisit this in open discussion 14:22:23 yeah 14:22:30 #topic Stable patches - a new, exciting segment! 14:22:55 croelandt, is that you ? 14:22:59 yes :) 14:23:07 Items 1 & 3 I will abandon if there is no objection 14:23:14 Item 2 I could use reviews :) 14:23:26 It should be pretty straight-forward as it's a simple backport of a patch already merged 14:23:29 no objection from me 14:23:47 what happened to our CVE backports? 14:24:37 I need to check those 14:24:47 abhishekk: oh I only linked the yoga & zed backports :) 14:25:04 abhishekk: I think we still have the grenade issue and might need to do backports of gmann's patches as well 14:25:23 no problem, but I think those needs to be put on priority :) 14:25:59 ack 14:26:01 Honestly, they would required a full meeting/email thread since the CI issues are out of our hands 14:26:09 ++ 14:26:58 ok, so that's it for today 14:27:04 let's move to open discussions 14:27:14 #topic Open Discussion 14:29:21 anyone has anything else to discuss ? 14:29:23 I don't have anything rather than CVE backports 14:29:27 * croelandt has nothing 14:29:49 I think you should send mail mentioning failures and get opinions on how to fix those 14:30:03 nothing from me 14:30:10 jokke_, please add your comment on the SRBAC patch, so that we can continue the dicsussion there 14:30:24 abhishekk, ack 14:30:41 include infra,ci,sec groups in subject line 14:31:02 ok 14:31:21 also we need to release stable branches where CVE has been merged 14:31:46 ohh yes 14:32:46 that's it from me 14:33:01 cool, let's wrap up then 14:33:13 Thanks everyone for joining ! 14:33:28 thanks all 14:33:40 #endmeeting