12:00:43 #startmeeting TripleO Security Squad 12:00:44 Meeting started Wed Apr 25 12:00:43 2018 UTC and is due to finish in 60 minutes. The chair is jaosorior. Information about MeetBot at http://wiki.debian.org/MeetBot. 12:00:45 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 12:00:47 The meeting name has been set to 'tripleo_security_squad' 12:00:58 hey jaosorior , et al 12:01:03 https://etherpad.openstack.org/p/tripleo-security-squad 12:01:04 * beagles had a short doubletake that it looks like bogdando and dtantsur were discussing octavia ;) 12:01:11 #link https://etherpad.openstack.org/p/tripleo-security-squad 12:01:22 hello folks! how's it going? 12:01:25 lhinds: hey dude! 12:01:34 lets wait some minutes for more folks to join in before starting 12:01:39 hey jaosorior 12:03:28 raildo, alee__: around? 12:03:58 alright, I guess we can start 12:04:03 #topic Secret Management work update 12:04:25 So, most of the patches for the first task in this proposal have merged 12:04:49 which is mostly enabling Barbican for the containerized undercloud, which will enable us to do encrypted objects in Swift (where we store the overcloud plan) 12:05:04 only two are missing, which is tripleo-quickstart integration, so we can test it in upstream CI 12:05:13 dtantsur: PTAL https://review.openstack.org/#/c/564162 ;) 12:05:22 so.... these two https://review.openstack.org/#/q/topic:secret-management+status:open 12:05:32 hopefully we can merge them soon 12:05:56 bogdando: https://etherpad.openstack.org/p/tripleo-inspector-containers am I missing something? 12:05:57 after that we need to figure out the next steps to secure the rest of the secrets in the deployment 12:06:08 And that's all for that topic 12:06:13 any feedback/questions? 12:06:15 Chandan Kumar proposed openstack/tripleo-quickstart-extras master: Get the list of tempest/-plugins rpms installed within a tempest container https://review.openstack.org/564156 12:06:36 dtantsur: I'll take a look, thanks! Let's also write up a summary to the started openstack-dev topic 12:07:05 #topic Public TLS by default work update 12:07:37 most of the base work is done 12:07:40 and the patches are up there 12:07:42 #link https://review.openstack.org/#/q/topic:public-tls-default+status:open 12:07:53 however, what's currently blocking that work is that we need to make sure that the upgrade path works 12:07:59 lhinds, jaosorior: hey... I'm kinda here but not 100% :-) 12:08:10 owalsh: glad you made it though :) 12:08:35 today or tomorrow I'll start poking jistr|mtgs for some help on the ugrades path 12:08:53 basically we need to make sure that folks that already have a deployment without TLS, keep their configuration working 12:08:58 so, not force people to enable the new defaults 12:09:17 shouldn't be too hard, just gotta start doing that work and figure out where to put the changes. 12:09:32 so yeah, gotta have some updates on that before we can merge the rest of the patches 12:09:42 Any questions/feedback on that work? 12:11:33 #topic jaosorior won't be around on the next meeting 12:11:47 So, probably I won't be able to run the next meeting next week due to travel 12:12:02 want me to cover jaosorior ? 12:12:06 not sure if folks still want to have the next meeting (somebody else could run it) or if we cancel it 12:12:22 or we could defer 12:12:24 lhinds: if you want! that would be great 12:12:32 as you're currently quite central to a lot of the topics. 12:12:53 I probably won't get to do a lot of work for the next week, but if you have an update on your topics, that would be useful to record 12:13:01 in fact second thoughts, lets leave it for a week, but I will make sure I turn up here in case anyone else does not get the msg 12:13:20 Alright, that's probably a good idea 12:13:31 So, I'll write up in the etherpad that we won't have a meeting next week 12:13:38 I am migrating Bandit over to PyQA so won't have much to update over the next week. 12:13:50 nice work on that side 12:14:57 #topic Any other business 12:15:17 Anything that folks want to bring up to the meeting? 12:15:43 not from me. 12:16:59 Alright, that's it from my side 12:17:03 Thanks for joining folks! 12:17:06 #endmeeting