Tuesday, 2022-10-11

*** dviroel|biab is now known as dviroel|out00:20
*** dasm is now known as dasm|off04:20
opendevreviewYonggen Sun proposed openstack/keystoneauth master: OAuth 2.0 Mutual-TLS Support  https://review.opendev.org/c/openstack/keystoneauth/+/86061405:11
opendevreviewYonggen Sun proposed openstack/keystone master: OAuth 2.0 Mutual-TLS Support  https://review.opendev.org/c/openstack/keystone/+/86061305:12
opendevreviewYonggen Sun proposed openstack/keystonemiddleware master: OAuth 2.0 Mutual-TLS Support  https://review.opendev.org/c/openstack/keystonemiddleware/+/86061505:12
opendevreviewYonggen Sun proposed openstack/keystoneauth master: Add doc of OAuth 2.0 Mutual-TLS Authenticate  https://review.opendev.org/c/openstack/keystoneauth/+/86092307:02
opendevreviewYonggen Sun proposed openstack/keystoneauth master: Add doc of OAuth 2.0 Mutual-TLS Authenticate  https://review.opendev.org/c/openstack/keystoneauth/+/86092308:18
opendevreviewYonggen Sun proposed openstack/keystoneauth master: Add doc of OAuth 2.0 Mutual-TLS Authenticate  https://review.opendev.org/c/openstack/keystoneauth/+/86092308:22
opendevreviewYonggen Sun proposed openstack/keystone master: Add doc of OAuth 2.0 Mutual-TLS Authenticate  https://review.opendev.org/c/openstack/keystone/+/86092808:46
opendevreviewYonggen Sun proposed openstack/keystone master: Add doc of OAuth 2.0 Mutual-TLS Authenticate  https://review.opendev.org/c/openstack/keystone/+/86092808:48
fkrahoi09:37
*** dviroel|out is now known as dviroel11:06
opendevreviewYusuke Niimi proposed openstack/keystoneauth master: [WIP]Add doc of OAuth 2.0 Mutual-TLS Authenticate  https://review.opendev.org/c/openstack/keystoneauth/+/86092311:35
opendevreviewYusuke Niimi proposed openstack/keystone master: [WIP]Add doc of OAuth 2.0 Mutual-TLS Authenticate  https://review.opendev.org/c/openstack/keystone/+/86092811:35
*** dasm|off is now known as dasm12:41
d34dh0r53#startmeeting keystone15:02
opendevmeetMeeting started Tue Oct 11 15:02:07 2022 UTC and is due to finish in 60 minutes.  The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot.15:02
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:02
opendevmeetThe meeting name has been set to 'keystone'15:02
d34dh0r53#topic Roll Call15:02
xeko/15:02
d34dh0r53admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, knikolla, lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek15:02
h-asahinao/15:02
d34dh0r53o/15:02
d34dh0r53sorry for the late start folks15:02
dmendiza[m]🙋‍♂️15:03
dmendiza[m]I don't apologize for late starts until 5 minutes after. 😜15:03
d34dh0r53lol, thanks dmendiza[m], noted15:03
d34dh0r53#topic Review past meeting work items15:03
d34dh0r53#link https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-10-04-15.01.html15:04
d34dh0r53looks like there were 4 action items from last week15:04
d34dh0r53dmendiza[m] submit a patch to request the release for keystoneauth15:04
dmendiza[m]working on that right meow15:04
d34dh0r53thanks dmendiza[m], I won't add another action item then15:05
d34dh0r53d34dh0r53 work with dmendiza[m] to reserve a slot for the operator hours for keystone at the ptg15:05
d34dh0r53this has been done, our operator hours are on Friday 21-Oct to 15:00-16:0015:06
d34dh0r53in the Mitaka room15:06
d34dh0r53d34dh0r53 work with dmendiza[m] to reserve our regular slots for the PTG (2 hours on 2 days, total of 4 hours)15:06
d34dh0r53also done, our schedule is on the PTGBot site15:07
d34dh0r53#link https://ptg.opendev.org/ptg.html15:07
d34dh0r53Monday and Tuesday 13:00-15:00 UTC15:08
d34dh0r53dmendiza[m] will look at https://bugs.launchpad.net/keystone/+bug/199098715:08
dmendiza[m]did not get a chance to look at it, let's bump it to next week15:08
d34dh0r53dmendiza[m]: ack15:08
d34dh0r53#action dmendiza[m] will look at https://bugs.launchpad.net/keystone/+bug/199098715:09
d34dh0r53next up we have15:09
d34dh0r53#topic Liaison Updates15:09
d34dh0r53anything from release management?15:10
d34dh0r53ok,15:10
dmendiza[m]I think all the releases have shipped for Zed?15:10
*** dviroel is now known as dviroel|lunch15:11
d34dh0r53I think so, it looks like everything other pycadf and ldappool have releases for zed and I don't think we release those per cycle15:13
d34dh0r53next up is VMT15:13
d34dh0r53I filed a bug regarding a medium CVE in keystone that I'm currently working on15:14
d34dh0r53#link https://bugs.launchpad.net/keystone/+bug/199218315:15
d34dh0r53sorry, it's a high15:15
d34dh0r53Any other liaison updates?15:16
d34dh0r53#help still looking for additional cross-project liaisons15:16
d34dh0r53ping me if you're interested15:16
d34dh0r53on to specs15:17
d34dh0r53#topic specification OAuth 2.0 (h_asahina)15:17
d34dh0r53#link https://review.opendev.org/q/topic:bp%252Foauth2-client-credentials-ext15:17
d34dh0r53#link https://review.opendev.org/c/openstack/keystone-specs/+/84376515:17
h-asahinaWe've submitted patches for mtls OAuth2.015:17
h-asahina    https://review.opendev.org/c/openstack/keystoneauth/+/86061415:17
h-asahina    https://review.opendev.org/c/openstack/keystonemiddleware/+/86061515:17
h-asahina    https://review.opendev.org/c/openstack/keystone/+/86061315:17
d34dh0r53great, thank you!15:18
h-asahina:)15:19
* dmendiza[m] adds patches to review queue15:19
d34dh0r53thanks dmendiza[m], and we'll look at these during the reviewathon on Friday15:20
h-asahinathanks. it's also welcome if you have additional comments for spec after reading these patches.15:20
d34dh0r53excellent, thanks again h-asahina15:20
d34dh0r53#topic specification Secure RBAC (dmendiza[m])15:21
d34dh0r53#link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_15:21
d34dh0r53dmendiza[m]: any s-rbac updates?15:21
dmendiza[m]I added a topic to discuss this during PTG15:24
dmendiza[m]I want to make sure we're all on the same page as far as next steps for this cycle15:24
d34dh0r53great, thank you15:24
d34dh0r53#topic Open Discussion15:25
d34dh0r53drencom has added a review request for15:26
d34dh0r53#link https://bugs.launchpad.net/keystonemiddleware/+bug/198735515:26
d34dh0r53it looks like there has been a patch submitted, please review that if you have time and we'll look at this one during the reviewathon too15:26
d34dh0r53#topic Open Discussion - Antelope PTG15:28
d34dh0r53As I said earlier we have slots reserved for the PTG15:28
d34dh0r53We have two 2 hour blocks on Monday and Tuesday and an operator-hours on Friday15:29
d34dh0r53You can see all of the times on the PTGBot site15:29
d34dh0r53#link https://ptg.opendev.org/ptg.html15:30
d34dh0r53and our agenda is here15:30
d34dh0r53#link https://etherpad.opendev.org/p/antelope-ptg-keystone15:30
d34dh0r53If you have conflicts, or if you'd like to suggest different times for our slots please let me know and I'll see what we can do15:31
d34dh0r53and please feel free to add any agenda items that you'd like to discuss15:31
d34dh0r53anything else for open discussion?15:32
h-asahinaah, I have an question.15:32
d34dh0r53go ahead h-asahina 15:32
h-asahinahttps://etherpad.opendev.org/p/keystone-weekly-meeting15:32
h-asahinawe're trying to realize fine grained access control in Tacker15:33
h-asahinafor example, adding "vendor" and "location" attributes to users and use them to control access.15:33
h-asahinamy question is does keystone allow using user-defined users' attribute for the access control?15:34
d34dh0r53hmm, I don't think so, but dmendiza[m] or knikolla[m] might know for sure15:35
d34dh0r53#action d34dh0r53 look into user-defined attribute access control15:40
d34dh0r53h-asahina: I'll get back to you on that15:40
h-asahinagreat. thanks.15:40
d34dh0r53anything else for open discussion?15:40
d34dh0r53#topic bug review15:41
d34dh0r53#link https://bugs.launchpad.net/keystone/?orderby=-id&start=015:41
d34dh0r53looks like we have a couple of new bugs15:41
d34dh0r53#link https://bugs.launchpad.net/keystone/+bug/199218615:41
d34dh0r53"int object is not iterable" when using numerical group names15:41
d34dh0r53it looks like there is already a patch up for this with several reviews15:42
d34dh0r53#link https://review.opendev.org/c/openstack/keystone/+/86072615:42
d34dh0r53next up we have the bug I filed15:43
d34dh0r53#link https://bugs.launchpad.net/keystone/+bug/199218315:43
d34dh0r53Openstack: Application credential token remains valid longer than expected Edit15:43
d34dh0r53#action d34dh0r53 submit fix for Bug/199218315:44
d34dh0r53should have something later in the week15:44
d34dh0r53other than those two there aren't any new bugs for Keystone15:44
d34dh0r53#link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=015:45
d34dh0r53nothing new for python-keystoneclient15:45
d34dh0r53#link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=015:45
d34dh0r53nothing new here either15:46
d34dh0r53next up keystonemiddleware15:46
d34dh0r53#link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=015:46
d34dh0r53#link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=015:47
d34dh0r53pycadf doesn't have any new bugs either15:47
d34dh0r53#link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=015:47
d34dh0r53ldappool is good to go15:47
d34dh0r53#topic wrap up15:48
d34dh0r53Anyone have anything else to bring up before we close for this week?15:48
d34dh0r53one additional housekeeping note, there won't be a weekly meeting next week due to the PTG15:49
d34dh0r53we'll resume on 25-Oct15:49
d34dh0r53thanks folks!15:50
d34dh0r53#endmeeting15:50
opendevmeetMeeting ended Tue Oct 11 15:50:06 2022 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:50
opendevmeetMinutes:        https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-10-11-15.02.html15:50
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-10-11-15.02.txt15:50
opendevmeetLog:            https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-10-11-15.02.log.html15:50
*** dviroel|lunch is now known as dviroel16:24
*** dviroel is now known as dviroel|biab19:19

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!