Tuesday, 2022-11-01

*** dviroel|rover|dinner is now known as dviroel|rover00:33
*** dviroel|rover is now known as dviroel|out00:36
-opendevstatus- NOTICE: review.opendev.org (Gerrit) is currently down, we are working to restore service as soon as possible07:31
*** dviroel|out is now known as dviroel|rover11:28
*** dasm|off is now known as dasm13:29
-opendevstatus- NOTICE: review.opendev.org (Gerrit) is back online14:26
*** ministry is now known as __ministry14:52
d34dh0r53#startmeeting keystone15:00
opendevmeetMeeting started Tue Nov  1 15:00:56 2022 UTC and is due to finish in 60 minutes.  The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot.15:00
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:00
opendevmeetThe meeting name has been set to 'keystone'15:00
d34dh0r53#topic Roll Call15:01
d34dh0r53admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, knikolla, lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek15:01
knikolla[m]o/15:01
hiromuo/15:02
d34dh0r53Hi folks!15:03
d34dh0r53#topic Review past meeting work items15:03
d34dh0r53We had a few, first up is15:03
d34dh0r53dmendiza[m] will look at https://bugs.launchpad.net/keystone/+bug/199098715:03
d34dh0r53dmendiza[m]: any update?15:04
dmendiza[m]👀15:04
dmendiza[m]Still looking15:04
d34dh0r53ack15:04
d34dh0r53next up is15:04
d34dh0r53d34dh0r53 look into user-defined attribute access control15:04
d34dh0r53no updates15:05
d34dh0r53we have some reviewathon items that we were going to look at15:05
d34dh0r53reviewathon review https://review.opendev.org/c/openstack/keystoneauth/+/83810415:05
d34dh0r53reviewathon review https://review.opendev.org/c/openstack/keystone/+/83810815:05
d34dh0r53reviewathon review https://review.opendev.org/c/openstack/keystone/+/82260115:05
d34dh0r53reviewathon review https://review.opendev.org/c/openstack/keystone-specs/+/81861615:05
d34dh0r53We didn't get to the first one15:06
d34dh0r53nor the second15:06
d34dh0r53the third has -1's and commentary so that is in progress15:07
d34dh0r53the fourth is the default service role15:07
d34dh0r53next up is dmendiza[m] and d34dh0r53 make some time to start the gap analysis between CLI and OSC.15:07
d34dh0r53we didn't get to that15:08
d34dh0r53and finally we have d34dh0r53 try to reproduce https://bugs.launchpad.net/python-keystoneclient/+bug/199361415:08
d34dh0r53which I wasn't able to get to15:08
knikolla[m]the gap analysis is about sdk and the client15:08
knikolla[m]we don't have any other cli besides osc already :)15:08
*** dviroel|rover is now known as dviroel|rover|lunch15:09
d34dh0r53knikolla[m]: right15:09
d34dh0r53#action dmendiza[m] and d34dh0r53 make some time to start the gap analysis between SDK and the Client15:11
d34dh0r53#action dmendiza[m] will look at https://bugs.launchpad.net/keystone/+bug/199098715:11
d34dh0r53#action reviewathon review https://review.opendev.org/c/openstack/keystoneauth/+/83810415:11
d34dh0r53#action reviewathon review https://review.opendev.org/c/openstack/keystone/+/83810815:11
d34dh0r53#action d34dh0r53 look into user-defined attribute access control15:12
d34dh0r53ok, next up we have15:12
d34dh0r53#topic Liaison Updates15:12
d34dh0r53Nothing from VMT15:12
d34dh0r53dmendiza[m], knikolla[m] anything from Release Management?15:12
dmendiza[m]I can't think of anything15:13
d34dh0r53ok, thanks15:13
d34dh0r53#help still looking for additional cross-project liaisons15:14
d34dh0r53any other liaison updates?15:14
d34dh0r53#topic specification OAuth 2.0 (hiromu)15:15
hiromuthanks for the remind.15:15
hiromufirst, i've updated the spec15:15
hiromuhttps://review.opendev.org/c/openstack/keystone-specs/+/861554/2..315:16
hiromuI think it's now ready for the first review.15:16
hiromuand I have a question15:17
d34dh0r53ok15:17
hiromuthat i wrote on the etherpad.15:17
d34dh0r53the etherpad is here: https://etherpad.opendev.org/p/keystone-weekly-meeting15:18
d34dh0r53The question is, which is better?15:18
hiromuyes15:18
d34dh0r53supporting authentication with external OAuth 2.0 authorization servers (ext authz servers) by keystoneauth15:19
d34dh0r53i.e., users can use openstack command as usual when using ext authn servers.15:19
d34dh0r53or do not support ext authn servers by keystoneauth15:19
d34dh0r53i.e., users set an access token as an environment variable, e.g., OS_TOKEN, to call API of OpenStack services. This is not unnatural, assuming the programmatic access which must be a major usecase of the client credentials grant.15:19
hiromuthank you d34dh0r53 :)15:19
d34dh0r53:)15:20
d34dh0r53I think the second approach is simpler and consistent with the way many things already work15:21
hiromuI agree with you15:22
d34dh0r53knikolla[m], dmendiza[m] any thoughts?15:22
knikolla[m]I also don't think we should worry about authenticating with external servers with keystoneauth15:23
d34dh0r53ok, so we're in agreement15:24
hiromuok, i'll go with the second one.15:24
d34dh0r53awesome!15:24
dmendiza[m]👍️15:24
hiromuthanks a lot15:24
d34dh0r53thank you hiromu!15:24
d34dh0r53#topic Secure RBAC (dmendiza[m])15:25
dmendiza[m]Not a whole lot of progress this week.  I did bring up the next two tasks with my team downstream:15:25
dmendiza[m]#link https://review.opendev.org/c/openstack/keystone/+/82260115:26
*** knikolla[m] is now known as knikolla15:27
dmendiza[m]Getting the "manager" role patch updated/landed.  15:27
dmendiza[m]and 2)15:27
dmendiza[m]The "service" role spec:15:28
dmendiza[m]#link https://review.opendev.org/c/openstack/keystone-specs/+/81861615:28
dmendiza[m]followed by implementation15:28
dmendiza[m]I'll try to help out as much as possible for the next +/-2 weeks before I take leave for a few months.15:29
d34dh0r53ack, thanks dmendiza[m] 15:31
d34dh0r53#action reviewathon https://review.opendev.org/c/openstack/keystone-specs/+/81861615:31
d34dh0r53we really need to get that spec reviewed and merged15:32
dmendiza[m]Agreed.  I'm going to read/comment in the next few days and maybe we can check progress on Friday15:32
dmendiza[m]for the reviewathon15:32
d34dh0r53ack15:32
* d34dh0r53 needs to remember to look at the meeting log for the reviewathon action items15:33
d34dh0r53#topic Open Discussion15:33
d34dh0r53we don't have anything on the agenda, does anyone have anything before we do bug review?15:34
d34dh0r53ok, moving on then15:34
d34dh0r53#topic bug review15:34
d34dh0r53First off we have keystone15:35
d34dh0r53#link https://bugs.launchpad.net/keystone/?orderby=-id&start=015:35
d34dh0r53no new bugs here15:35
d34dh0r53next up, python-keystoneclient15:35
d34dh0r53#link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=015:35
d34dh0r53no new bugs, I'll attempt to reproduce the create service bug this week15:36
d34dh0r53keystoneauth is next15:36
d34dh0r53#link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=015:36
d34dh0r53no new bugs15:36
d34dh0r53#link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=015:36
d34dh0r53nothing new in keystonemiddleware15:37
d34dh0r53pycadf15:37
d34dh0r53#link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=015:37
d34dh0r53nothing new15:37
d34dh0r53finally we have ldappool15:37
d34dh0r53#link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=015:37
d34dh0r53no new bugs there either15:38
d34dh0r53thanks for joining today everyone! Is there anything else before we close?15:38
d34dh0r53have a great rest of your week then :)15:39
d34dh0r53#endmeeting15:39
opendevmeetMeeting ended Tue Nov  1 15:39:16 2022 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:39
opendevmeetMinutes:        https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-11-01-15.00.html15:39
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-11-01-15.00.txt15:39
opendevmeetLog:            https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-11-01-15.00.log.html15:39
dmendiza[m]Thanks d34dh0r53!!15:42
*** dviroel|rover|lunch is now known as dviroel|rover16:12
*** dviroel|rover is now known as dviroel|rover|bbl21:32
*** dasm is now known as dasm|off23:09
*** dasm|off is now known as Guest20223:37

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!