17:06:00 #startmeeting openstack security group 17:06:01 Meeting started Thu Jan 15 17:06:00 2015 UTC and is due to finish in 60 minutes. The chair is hyakuhei. Information about MeetBot at http://wiki.debian.org/MeetBot. 17:06:02 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 17:06:04 The meeting name has been set to 'openstack_security_group' 17:06:13 weird... 17:06:17 hummm guess its bust, technology eh? :P 17:06:18 oh well, carry on :-) 17:06:33 well that was an exciting diversion! 17:06:40 hackers. 17:06:44 :P 17:06:47 haxors everywhere! 17:06:59 Right, back on topic. Which was, to set the agenda :) 17:07:11 Anchor, Bandit, Mid-Cycle - anything else? 17:07:37 ok 17:07:46 tkelsey: what’s the latest on Anchor? 17:07:47 sounds good to me 17:07:58 hyakuhei: test, test and more tests 17:08:18 well, slowly adding coverage 17:08:25 I also updated the wiki pages 17:08:32 Superb. Anyone want to get involved with Anchor? This is a great time. 17:08:46 Still need to workout where/when to write the Barbican plugin 17:08:52 #link https://wiki.openstack.org/wiki/Anchor 17:08:56 and bdpayne you wanted to talk about some stuff ? 17:09:00 hyakuhei: yeah good point 17:09:16 I did? 17:09:33 Yeh, I thought you mentioned something last week, ah well 17:09:50 So yes in general, we are feature freezing Anchor while we add a number of tests. 17:09:57 well, I have some thoughts that I'll keep to myself for now until I can dig into the code base some more 17:10:18 Righto, feel free to air them early, we won’t get offended :) 17:10:22 bdpayne: awesome :) input very welcome when your ready 17:10:25 * redrobot is fashionably late 17:10:28 cool 17:10:35 welcome redrobot ! 17:10:54 We were just talking about adding an Anchor plugin into Babrican :) 17:11:38 ok, so re: Anchor - get involved, write some tests :) 17:11:45 +1 :) 17:11:52 #topic Bandit 17:12:12 Bandit might be mostly a no-op this week 17:12:22 Last week we spoke about testing out Bandit in various places 17:12:24 i have a bandit user report 17:12:30 Excellent! 17:12:31 ooh 17:12:32 do tell 17:12:34 :D 17:12:37 i ran it against the sahara code base, it was smooth sailing 17:12:47 i followed the instructions and it worked like magic =) 17:12:48 find anything interesting? 17:12:50 elmiko: thats awesome news, find anything interesting ? 17:12:59 yea, i think so 17:13:05 awesome! 17:13:16 I've been meaning to run it against the Barbican code base... 17:13:21 #link https://gist.github.com/elmiko/94f063583912a5d8c3cb 17:13:24 that's our output 17:13:27 redrobot: +1 17:13:38 I did run it once a while back, found a few things iirc. 17:13:43 it mainly complains about our usage of /tmp, but that's occuring on our cluster nodes so maybe something to look at 17:13:58 that is scary. 17:14:13 sudo su - -c "mkdir /tmp/oozielib !!?? 17:14:40 eeeeeew 17:14:44 * elmiko feels like he just exposed sahara's bare ass 17:15:03 sudo /tmp/sahara-hadoop-init.sh :) 17:15:08 yea, we need some help =) 17:15:33 tmcpeak to be fair they created the directory 500 immediately before :) 17:15:43 That’s a good thing elmiko, what we are here for :) 17:15:56 hyakuhei: +1 17:15:56 ahh gotcha 17:16:01 er, not directory 17:16:12 * sicarie stops typing while caffeine goes through his system 17:16:52 anyways, aside from our issues, kudos to the bandit team. the process was painless and the docs were clear. 17:17:00 bandit is sure doing it's job if it's able to catch these issues. 17:17:14 elmiko: thanks for using it 17:17:22 so next step is to get it in the gate 17:17:25 i would like to learn how best to interpret it's output as my next task with bandit 17:17:27 elmiko: awesome, thanks for the feedback 17:17:45 yeah, nice to see real world usage :) 17:17:49 +1 17:17:51 elmiko: tmcpeak or myself can help if you have any questions 17:18:00 +1 17:18:09 tkelsey: awesome, i'll find you guys in openstack-security 17:18:18 I ran it on keystone quickly a month ago to see if it worked, and it worked fine... I think I asked for a feature to skip files (e.g., test directory) 17:18:21 bdpayne: btw, did you know if Lucas is planning on merging his improvements? 17:18:30 yeah he is 17:18:33 I'll ping him to do so 17:18:44 bknudson: oh right, I added that item to our wiki 17:18:46 bknudson: You mentioned before it might fit in the Keystone gate? 17:19:06 I would definitely like to see this in keystone gate. 17:19:19 What’s the process of doing a trial? 17:19:22 there's a little work we need to do to get it in requirements 17:19:36 and if you need project to start with I think keystone is a good target. 17:19:37 after that it should be easy to set up a non-blocking gate job for it 17:19:44 maybe middleware. 17:20:28 I think this would be a good topic for the cross-project meeting. 17:20:33 We’ll use it in Anchor soon but it looks like Keystone would be the first ‘proper’ project to test it with 17:20:51 what's the cross-project meeting? 17:21:02 is that a summit thing? 17:21:11 https://wiki.openstack.org/wiki/Meetings/CrossProjectMeeting 17:21:29 "Any cross-team issue is on-topic for this meeting." 17:21:48 ahh cool, I was not aware this was a thing :) 17:22:04 neither was I... interesting 17:22:19 it would be good to take care of any objections that might be raised... I don't anticipate any other than there might be a request for a cross-project spec. 17:22:34 bknudson: yeah, that looks like a good fit for that discussion 17:22:44 so you might want to get started on a spec. 17:22:57 cool 17:23:04 ok so todo: 1) requirements 2) spec 17:24:22 Anyone want to volunteer to take that as an action? 17:24:24 Here's an example cross-project spec: https://review.openstack.org/#/c/145544/ 17:24:35 another action would be to attend the cross-project meeting 17:24:42 which is at 21:00 UTC 17:24:59 let's attend when we have what we need in place 17:25:08 I'm a little bandwidth challenged right now, but I can at least work #1 17:25:20 cool 17:25:37 #action tmcpeak to take a look at the requirements regarding Bandit and Keystone Gate Tests 17:26:07 I might be able to assist with the spec 17:26:13 awesome! 17:26:20 Anything else on Bandit? 17:26:29 nope 17:26:40 is there a deadline for it? other than ASAP? 17:26:40 cool 17:26:55 next week would be good 17:27:15 as you're able 17:27:19 Ok, I'll work on it this weekend 17:27:31 you don't have to :) 17:27:37 the week after is fine 17:27:48 not trying to crack the whip 17:27:48 it gives me an excuse to avoid my teenager :) 17:27:58 haha ok, awesome 17:28:37 Ok, lets move along, thanks Bandit peoples! 17:28:43 #topic Mid-Cycle 17:28:46 #link https://etherpad.openstack.org/p/ossg-kilo-meetup 17:29:10 Agenda is looking pretty thin at the moment, I’d like to see more on there, especially if you’re a confirmed attendee 17:29:25 At the very least put your name down against the things that you think are most important 17:29:46 * bdpayne will add at least one agenda item 17:30:52 Thanks :) 17:31:26 looks like a HP/Nebula party? 17:31:30 I’m finalizing travel plans over the next 24 hours 17:31:39 Malini from Intel is going to try to come 17:31:46 * bdpayne added one item 17:32:14 Can we put an address on there for Geekdom? 17:32:17 I’ll try to add a few over the next few days. 17:32:19 yep, I'll get it 17:32:24 I need to convince my employer to get me to the security meetups. 17:32:25 thanks tmcpeak 17:32:46 also, it says "proposed dates" up top, but those _are_ the dates, right? 17:33:01 They have a decent bike lockup there fyi, I’ll be renting a roadie for a day or two while I’m there :) 17:34:13 So I don’t have a whole bunch more to add atm. I noticed a few prospective board members mentioning security 17:34:36 can we get some pandering? :) 17:34:37 Jesse Proudman used the recent glance vulnerability as an example of things not working great 17:34:52 Re bike lockup, that's nice as I'll probably be taking the train/bike to the spot each day 17:35:11 Cool 17:35:18 They can lend you a lock too bdpayne 17:36:20 what time are we starting on the first day? 17:36:20 and what time are we ending on the last day? 17:36:20 (to help people with travel plans) 17:36:35 So, we’ve got the place 9-5 Tuesday-Friday 17:36:41 with a 4pm finish on Thursday 17:36:51 * bdpayne doesn't trust someone else's lock, but thanks 17:36:54 Sure 17:37:16 should we just plan to start 9a on Tuesday than? 17:37:18 s/than/then/ 17:37:21 Yup 17:37:23 or is that too early? 17:37:28 9's good 17:37:37 Lets start strong ;) 17:37:50 for me, strong would be later in the morning ;-) 17:37:58 but, I can figure out the 9a thing 17:38:01 I hear it's possible 17:38:06 lol 17:38:14 You can be late 17:38:15 yeah bdpayne: that's a sub-optimal Caltrain ride you have to do 17:38:19 but you must bring cake. 17:38:46 yeah, it will be a bit painful 17:38:53 but I'd rather not be away from my family all week 17:38:55 so, eh 17:38:56 ;-) 17:39:16 I can do the bullet train 17:39:16 Whatever works bdpayne, it’s always a slow start on the first day. 17:39:30 no worries 17:40:04 I’m hoping we can have a social event one day. 17:40:35 I know some good spots around there 17:41:00 Cool 17:41:03 ah good, b/c I don't really know that area too well 17:41:09 I just found out about the OSSG meetup, I'd like to start getting involved, mind if I drop in on it? :) 17:41:19 sure 17:41:19 * jroll works upstairs from geekdom 17:41:23 a great way to get started 17:41:25 Sure jroll 17:41:28 https://etherpad.openstack.org/p/ossg-kilo-meetup 17:41:32 awesome, thanks 17:41:35 I'll add my name 17:42:04 Sweet! 17:42:46 Ok, if there’s nothing to add lets close it out :) 17:42:58 Thanks all! 17:43:00 #endmeeting