16:00:14 #startmeeting keystone 16:00:16 Meeting started Tue Jul 16 16:00:14 2019 UTC and is due to finish in 60 minutes. The chair is cmurphy. Information about MeetBot at http://wiki.debian.org/MeetBot. 16:00:17 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 16:00:19 The meeting name has been set to 'keystone' 16:00:25 #link https://etherpad.openstack.org/p/keystone-weekly-meeting agenda 16:00:28 o/ 16:00:41 o/ 16:01:08 o/ 16:01:09 o/ 16:02:36 o/ 16:04:05 let's get started 16:04:20 #topic midcycle agenda draft posted 16:04:37 #link https://etherpad.openstack.org/p/keystone-train-midcycle-topics 16:04:54 the virtual midcycle will be happening next week 16:05:07 I started working out an agenda for discussion and hacking topics 16:05:23 posted in the above etherpad 16:05:39 feedback welcome - any thoughts on it? 16:06:56 * gagehugo takes a look 16:07:55 it will be flexible too so if we decide at the time we need to rework the discussion we can do that 16:08:20 The Oslo meeting is during the caching tech review. 16:08:35 But maybe we just cancel the meeting next week and have interested people join the midcycle call. 16:08:58 bnemec: it's easy enough to switch it around 16:09:53 although tuesday was iffy for kmalloc 16:10:04 i'll most likely be around 16:10:07 Yeah, although it would be a bit weird to not have the hackathon for caching follow the tech review, which limits the flexibility there somewhat. 16:10:32 mostly the caching tech review is to get more people on board with how caching works, concerns, and oslo.cache itself 16:10:41 we have a very small number of folks who understand it in depth 16:10:59 I also have a conflict on Tuesday, although I may be able to skip that meeting. 16:12:00 so would it 16:12:03 er 16:12:19 so would it work to swap the hackathon days or still a conflict? 16:13:25 oh you said conflict same time both days 16:13:28 It may still be an issue for me. 16:13:43 Monday is actually more flexible because I can cancel that meeting if I have to. 16:13:50 just realize i have a conflict on tuesday too. but it's only for 1 hour out of the 3 of the meeting. 16:14:34 bnemec: how about we move up the caching topics by an hour on monday 16:15:21 then you can be there for the review and do the hackathon only if you feel like canceling the other meeting 16:15:47 Sure, works for me. 16:16:13 ++ 16:16:22 cool 16:16:24 done 16:16:51 knikolla: what time is your conflict on tuesday? 16:16:59 Although that means I have to actually be awake right away on Monday. ;-) 16:17:31 bnemec: kmalloc and i cry for you 16:17:32 right in the middle of the midcycle. 11am EST to 12.00 EST 16:17:59 cmurphy: I'm sure. :-P 16:18:00 and i might miss the first few minutes on monday if my dental appointment goes long. 16:18:14 knikolla: okay so you can make it to the retrospective at least 16:18:34 sure 16:18:56 knikolla: gagehugo can you add your names to the attendees list too 16:19:29 will do 16:20:14 I shouldn't have any conflicts afaik 16:20:25 yay 16:20:35 any other questions concerns thoughts about the midcycle? 16:22:20 #topic PTG planning 16:22:32 planning all the events i guess 16:22:57 i sent a note to the ml, the foundation wants to know if we want space at the shanghai ptg 16:23:18 i almost just replied and said yes since we always use it, but i know this one is a little different 16:23:58 i'm looking for a very rough count of people who are thinking they probably intend to go to shanghai in november 16:24:08 i know nobody knows for sure at this point 16:24:30 #link https://etherpad.openstack.org/p/keystone-shanghai-ptg shanghai ptg planning 16:25:59 please add your names there if you think you're planning to be there 16:26:25 anyone besides kmalloc already know for sure that they *won't* be there? 16:26:33 I won't be there 16:27:12 i'm very unlikely to go, given the VISA pains I have to go through to leave the US and get back. 16:27:37 :( 16:28:12 i basically need to fly to albania from the us, to get a us visa, come back to the us, get a chinese visa, then travel to china. 16:29:05 knikolla: that sounds... awful 16:29:35 kmalloc: ikr, having to get out of the us to be able to come back... is mind boggling 16:31:10 that seems extremely inconvenient 16:32:33 i know sessions will be selected by the end of the month so presentation schedule will probably be out early august, so please try to let me know by around then whether you think you'll make it 16:33:00 if most of us can't make it then we should probably do a virtual ptg just before the event 16:33:31 cmurphy: sure 16:34:32 that might be a good idea 16:35:41 #topic Open reviews and ongoing work 16:36:12 there are a few reviews to touch base on 16:36:27 #link https://review.opendev.org/659434 Remove [signing] config 16:36:46 I was waiting for others opinion over it 16:36:48 we talked about this one last week, i think we're converging on changing the error code to a 410 16:37:10 anyone have other thoughts on it? 16:39:14 #link https://review.opendev.org/655166 Allows to use application credentials through group membership 16:40:02 this one is interesting, we've been back and forth on it for a while 16:40:12 i restored the original patchset from jose and explained in a comment why i think it's actually the right way to go 16:40:42 interested in hearing from knikolla about it and whether kmalloc had other thoughts since we talked about it last week 16:41:09 so basically app creds didn't check if the user had permissions from the group and failed? 16:42:06 right, when the app cred gets created it looks at the effective role assignments but the token was only looking at regular role assignments 16:42:21 so the app cred could be created but not used 16:43:30 will it distinguish between groups from mapping and groups concretely assigned to? 16:44:02 yes because only concrete groups can be looked up from the identity driver 16:44:41 mapped groups go through a completely different code path in a completely different subsystem 16:44:57 i'm ok with this and it's actually a critical fix 16:45:52 we still need the expiring group membership to make this work for federated users but that's really a separate issue 16:46:02 yup, but the latter depends on this 16:46:09 yep 16:46:35 ++ will review 16:46:41 awesome 16:46:54 #link https://review.opendev.org/633369 Add validation of app cred access rules 16:47:32 this one should be more readable now that kmalloc helped me with the regex implementation 16:47:42 i'd like to get that in and do a ksm release asap 16:48:41 the access rules work in keystone depends on that ksm patch 16:50:09 #link https://review.opendev.org/669790 update documentation for X.509 tokenless auth 16:50:38 gyee has been doing amazing work fixing that document 16:51:41 definitely worth reviewing just to learn more about it :) 16:53:01 nice! 16:54:22 #link https://review.opendev.org/669959 discourage external auth 16:54:50 related change from gyee, this took me by surprise a little so i think it's worth discussing 16:55:09 external auth is one of the default allowed auth methods 16:55:29 o/ 16:55:39 hi gyee 16:55:55 external auth is kinda dangerous in a multi domain env 16:57:12 is multidomain the only case when it's a bad idea? 16:57:17 and v3 is all about multi-domain so we should discourage using external auth unless deployer have a flat, single-domain IDP 16:58:20 and it cannot be used with multiple auth modules within apache either 16:58:27 we should probably remove it from the default list of auth methods too then 16:58:28 i.e. Kerberos and mod_ssl at the same time 16:59:23 1 minute remaining 16:59:28 #link https://review.opendev.org/#/c/666861/ stable/stein doc bug fix 16:59:33 one for the stable cores 16:59:50 any other reviews to highlight? 17:00:23 alright thanks everyone 17:00:26 #endmeeting