17:00:26 #startmeeting openstack security group 17:00:27 Meeting started Thu Feb 26 17:00:26 2015 UTC and is due to finish in 60 minutes. The chair is hyakuhei. Information about MeetBot at http://wiki.debian.org/MeetBot. 17:00:28 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 17:00:31 The meeting name has been set to 'openstack_security_group' 17:00:52 Good morning/evening/whatever everybody! 17:00:54 o/ hyakuhei 17:00:58 yo/ 17:00:59 o/ 17:01:03 o/ 17:01:05 o/ 17:01:07 o/ 17:01:12 o/ 17:01:28 Oh, good crowd :D 17:01:34 elmiko: whatchu doing here? =P 17:01:41 heh. 17:01:44 sigmavirus24: hehe 17:01:55 hi 17:02:04 hi 17:02:07 Ok so I’ve been on the road the whole time since our mid-cycle so this is going to be a fairly open meeting. 17:02:21 Agenda wise I’d like to discuss a few things 17:02:31 Howdy all 17:02:32 Anchor, Bandit and Docs progress, security guidelines 17:02:37 What eles? 17:02:39 *else 17:03:24 bpb_: == Bryan Payne? 17:03:30 looks like a good list hyakuhei 17:03:58 ok great so Anchor and Bandit were the two technical projects that we focussed on last week 17:04:07 * bdpayne is here :-) 17:04:12 and updates/change requests have continued to flow for both which is awesome 17:04:15 hey bdpayne ! 17:04:24 Do you want to talk about the guide at all? 17:04:27 hyakuhei: bruce b 17:04:35 o/ 17:04:46 Hey Bruce. 17:04:52 hey 17:05:03 sure, I can talk about the guide at some point 17:05:14 Cool 17:05:28 So one thing we also did was write a bunch of developer oriented security guidelines 17:05:46 https://github.com/hyakuhei/OSSG-Security-Practices 17:06:12 hyakuhei: nice, +1 17:06:14 there's a note on the mailing list about cross-project developer guide, so maybe that would be a good place for these. 17:06:15 That will be moved to the openstack-security organisation on github for now while we work out a nice way to publish it into OpenStack proper 17:06:26 bknudson: can you fwd me that? 17:06:40 me too please 17:06:58 In other news I’ve been working with the TC on making us a formal part of OpenStack 17:07:10 I’ll have more to share on that soon :) 17:07:12 +1 17:07:27 +1 17:07:36 looking for the link. 17:07:42 So as we’ve had two great weeks of contributions and code development I really don’t have much to complain about here :P 17:08:11 #link http://lists.openstack.org/pipermail/openstack-dev/2015-February/057816.html 17:08:17 Great thanks bknudson 17:08:25 "creating a unified developer reference manual" 17:08:53 Ok so I’ve raised the things I needed to (longer meeting next week) 17:09:05 Open agenda, bdpayne, tmcpeak etc anything to discuss 17:09:22 I can take Bandit for a while 17:09:27 provide update, etc 17:09:32 please do 17:09:40 #topic bandit 17:09:59 cool, so we got a ton of great stuff done last week at the mid-cycle 17:10:14 fletcher and browne have started with development 17:10:20 ljfisher is now a core 17:10:33 congrats to ljfisher 17:10:44 congrats ljfisher! 17:10:51 i’ll try not to let the power go to my head :) 17:11:00 ljfisher: that's the wrong thing to do ;) 17:11:00 we have merged a lot of changes 17:11:03 ;-) 17:11:12 niiiiiice, congrats 17:11:32 fletcher: want to introduce yourself briefly for those who weren't at the meetup? 17:11:53 ljfisher: grats! 17:12:05 sure, I'm rob fletcher and I do application security things at uber! I have an irrational fear of the ocean and bears 17:12:16 lol, perfect 17:12:20 and bringer of swag 17:12:42 * bknudson wore uber hoodie today 17:12:51 :) 17:12:52 fletcher I wore my Uber hoodie yesterday and everyone in my office wanted one ;-) 17:13:04 internet fail 17:13:05 :( 17:13:16 anyway, so yeah. Bandit used in Keystone 17:13:24 bknudson: you mentioned wanting somebody to attend Keystone meeting? 17:13:45 y, if we're going to enable it for keystone should answer questions from other cores / developers 17:13:52 if they have any questions. 17:13:53 ok cool 17:13:56 sounds good 17:14:09 I feel like those aren't irrational btw 17:14:29 #link https://review.openstack.org/#/c/157930/ 17:14:32 i ran Bandit against the Barbican source code. i opened a bug against Bandit, since it's treating DocStrings like source code Strings. 17:14:50 ^ is in-progress change to add tox env for keystone 17:15:18 will keep working on it as bandit changes, and then it'll be available to enable the gating 17:15:21 I’m really excited about having Bandit land in a gate 17:15:28 ok, I think I have procured better internet 17:15:38 anyway, bknudson what are the details 17:15:43 maybe a few of us can attend 17:15:53 I think people are going to want to know what bandit does 17:16:04 e.g., might have a question about what kind of checks it does 17:16:10 and how to configure it... where's docs 17:16:12 cool, should definitely be able to answer any of those questions 17:16:19 oh.. the docs 17:16:22 :\ 17:16:36 and what the output looks like currently... can run the tox -e bandit to see that. 17:16:39 our docs are pretty immature/non-existent 17:16:46 but yeah, I'm happy to show up and answer any questions 17:16:57 send out the details? 17:17:22 #link https://wiki.openstack.org/wiki/Meetings/KeystoneMeeting 17:17:28 I'd encourage anybody else interested to attend that meeting too, will be interesting to see what our first real world gate test user thinks 17:17:30 add yourself to the agenda if you can make next week. 17:17:55 ok cool, will do 17:18:12 anybody else have anything they want to mention for Bandit? 17:18:23 or for anything else :) bdpayne maybe? 17:18:33 Sure, I'll give some quick book updates 17:18:40 #topic Security Guide 17:19:03 First, we are going to have a weekly meeting to discuss the book in more detail 17:19:05 that will be in #openstack-security on Mondays at 10a 17:19:14 should run for no more than 30 min 17:19:21 we will triage bugs, plan work, etc 17:19:34 a few other things worth mentioning: 17:19:34 10a pacific that is 17:19:45 10a pacific, yes, thanks :-) 17:20:06 1) we plan to start releasing versions of the book for each openstack release starting with Liberty 17:20:14 so we will be needing to start planning for that very soon here 17:20:46 2) we are working to get a series of checklists into the book that will help people consume the content 17:21:27 I think that’s a great idea! 17:21:33 3) we recently took an entire new chapter (thanks elmiko!) on data processing 17:21:46 =) 17:21:57 4) we added to https://wiki.openstack.org/wiki/Security/How_To_Contribute#Writers_.2F_Editors to make it a little easier for people to find out how to get involved, but I think more details would be even better 17:22:15 That's all that I have unless there's some discussion / questions on the book 17:22:49 hyakuhei back to you then 17:22:53 woo! 17:23:43 So I don’t have a huge amount to share this week, there’s some interesting stuff I’m working out with the TC that should result in some cool announcements next week :) Tune in again, same time, same place! 17:24:03 So I should extend my thanks to everyone who came to and contributed remotely to the OSSG mid-cycle 17:24:13 indeed, it was a great week last week 17:24:25 it was a really excellent week, thanks everyone! 17:24:33 thanks to HP and Rackspace for the sponsorship of the week! 17:24:39 thanks for getting it all organized 17:24:53 I’m really pleased you found it useful 17:24:53 looking forward to 6 months from now 17:24:59 +1 17:25:24 me too, i found the meetup really beneficial 17:25:31 thanks everyone 17:25:55 #endmeeting