Wednesday, 2023-07-19

d34dh0r53#startmeeting keystone14:59
opendevmeetMeeting started Wed Jul 19 14:59:50 2023 UTC and is due to finish in 60 minutes.  The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot.14:59
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.14:59
opendevmeetThe meeting name has been set to 'keystone'14:59
xeko/15:01
d34dh0r53#topic roll call15:02
d34dh0r53admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, knikolla[m], lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann, zaitcev, reqa, dmendiza[m]15:02
d34dh0r53o/15:02
hiromuo/15:03
zaitcevo/15:03
zaitcevI'm here, but also not really.15:03
d34dh0r53:)15:04
d34dh0r53#topic review past meeting work items15:04
d34dh0r53#link https://meetings.opendev.org/meetings/keystone/2023/keystone.2023-07-11-14.59.html15:04
d34dh0r53 d34dh0r53 Look into adding/restoring a known issues section to our documentation15:05
d34dh0r53#action d34dh0r53 Look into adding/restoring a known issues section to our documentation15:05
d34dh0r53#action d34dh0r53 add https://bugs.launchpad.net/keystone/+bug/1305950 to the known issues section of our documentation15:05
d34dh0r53d34dh0r53 pin keystone-tempest-plugin to wallaby for keystone stable/wallaby15:07
d34dh0r53this was done in https://review.opendev.org/c/openstack/keystone/+/887072, thanks stephenfin 15:07
d34dh0r53I'll try to get to the known issues documentation stuff this week15:07
d34dh0r53#topic liaison updates15:08
d34dh0r53nothing from VMT15:08
d34dh0r53moving on15:11
d34dh0r53#topic specification OAuth 2.0 (hiromu)15:12
d34dh0r53#link https://review.opendev.org/q/topic:bp%252Foauth2-client-credentials-ext15:12
d34dh0r53External OAuth 2.0 Specification15:12
d34dh0r53#link https://review.opendev.org/c/openstack/keystone-specs/+/86155415:12
d34dh0r53OAuth 2.0 Implementation15:12
d34dh0r53#link https://review.opendev.org/q/topic:bp%252Fsupport-oauth2-mtls15:12
d34dh0r53OAuth 2.0 Documentation15:12
d34dh0r53#link https://review.opendev.org/c/openstack/keystone/+/83810815:12
d34dh0r53#link https://review.opendev.org/c/openstack/keystoneauth/+/83810415:12
hiromuRecently, we submitted patches that add system-scoped token and caching to ext OAuth2.0 https://review.opendev.org/c/openstack/keystonemiddleware/+/88852315:13
d34dh0r53ack, thank you hiromu 15:15
d34dh0r53I will start reviewing them15:15
hiromuthanks15:15
d34dh0r53next up15:16
d34dh0r53#topic specification Secure RBAC (dmendiza[m])15:16
d34dh0r53#link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_15:17
d34dh0r53Service Role Implementation15:17
d34dh0r53#link https://review.opendev.org/c/openstack/keystone/+/86342015:17
d34dh0r53Manager Role Implementation15:17
d34dh0r53#link https://review.opendev.org/c/openstack/keystone/+/82260115:17
d34dh0r53Keystone Tempest Plugin Updates15:17
d34dh0r53#link https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/88579915:17
d34dh0r53I saw that there is a new patch to add a default service role to the keystone-manage bootstrap command15:17
d34dh0r53#link https://review.opendev.org/c/openstack/keystone/+/86342015:17
d34dh0r53thanks for the reviews on that15:18
d34dh0r53cool, moving on15:20
d34dh0r53#topic specification SQLAlchemy 2.0 (stephenfin)15:21
d34dh0r53#link https://review.opendev.org/q/topic:sqlalchemy-20+is:open+project:openstack/keystone15:21
d34dh0r53there is only one patch left and it's a doc fix, awesome work by all getting all of these patches in, thank you!15:21
stephenfinAwesome work indeed. FYI there are still barbican patches that need to get in so maybe that link should be updated?15:21
stephenfinhttps://review.opendev.org/q/topic:sqlalchemy-20+is:open+project:openstack/barbican15:22
stephenfin(there's a low-prio bug in sqlalchemy that is causing the two last patches to fail: we've worked around it in oslo.db and will cut a release shortly)15:22
d34dh0r53xek, dmendiza[m] what do you think?15:22
knikollastephenfin: we owe you a beer/juice/seltzer. thanks for all the amazing work. 15:23
xek@stephenfin Hey, I saw your patches and mentioned them on the barbican meeting15:23
d34dh0r53indeed knikolla 15:23
stephenfin:w15:24
stephenfinwhoops15:24
stephenfinxek: d34dh0r53: Great, we can probably remove that from the keystone meeting agenda so if it's being tracked elsewhere15:25
xekYeah, Barbican is a separate project15:25
d34dh0r53sweet15:25
d34dh0r53:wq ing the SQLAlchemy section on the etherpad15:26
d34dh0r53#topic open discussion15:27
d34dh0r53(drencrom) Remove cache invalidation when using expired token15:27
d34dh0r53#link https://review.opendev.org/c/openstack/keystonemiddleware/+/88473815:27
stephenfin:)15:27
d34dh0r53just issued a recheck on that job, if zuul still won't vote I'll ping infra about it15:28
d34dh0r53(mustafakemalgilor) PooledLdapHandler message.clean() patch backports15:29
d34dh0r53those are all merged, I'll :wq that section as well, unless there's something else we need to look at15:29
d34dh0r53next up15:30
d34dh0r53(reqa) Add openstack cli support for OAuth 2.0 Device Authorization Grant with PKCE:15:30
d34dh0r53review request15:30
d34dh0r53#link https://review.opendev.org/c/openstack/keystoneauth/+/88385215:31
d34dh0r53Reasoning: When switching wsgi-keystone.conf to use PKCE for WebSSO, this also applies to the CLI (e.g. ForgeRock implemented the same)15:31
d34dh0r53I'm going to test this as we're starting work on some CLI stuff with OIDC and it likely dovetails15:31
d34dh0r53#topic bug review15:32
d34dh0r53#link https://bugs.launchpad.net/keystone/?orderby=-id&start=015:32
d34dh0r531 new bug in keystone https://bugs.launchpad.net/keystone/+bug/202772915:33
d34dh0r53knikolla: anything to add?15:34
d34dh0r53I think we just need to remove the offending line in the docs?15:34
d34dh0r53just read the RFC, really good to know15:36
d34dh0r53I was wrong, there is actually a 2nd bug in keystone that is new15:37
d34dh0r53https://bugs.launchpad.net/keystone/+bug/202634515:37
d34dh0r53based on my reading we need to fix our pillow version in docs/requirements.txt15:38
d34dh0r53please assign those bugs to yourself if you're interested in fixing them15:38
d34dh0r53next up python-keystoneclient15:38
d34dh0r53#link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=015:38
d34dh0r53no new bugs there15:39
d34dh0r53keystoneauth?15:39
d34dh0r53#link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=015:39
d34dh0r53nothing new15:39
d34dh0r53on to keystonemiddleware15:39
d34dh0r53#link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=015:39
d34dh0r53no new bugs there either15:39
d34dh0r53#link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=015:40
d34dh0r53pycadf is clean15:40
d34dh0r53#link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=015:40
d34dh0r53as is ldappool15:40
d34dh0r53#topic conclusion15:40
d34dh0r53Hopefully this Wednesday time works for everyone, please let me know any feedback on the change15:41
d34dh0r53That's all I have this week, hope to see folks at the reviewathon15:41
d34dh0r53Thanks all!15:41
d34dh0r53#endmeeting15:41
opendevmeetMeeting ended Wed Jul 19 15:41:45 2023 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:41
opendevmeetMinutes:        https://meetings.opendev.org/meetings/keystone/2023/keystone.2023-07-19-14.59.html15:41
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/keystone/2023/keystone.2023-07-19-14.59.txt15:41
opendevmeetLog:            https://meetings.opendev.org/meetings/keystone/2023/keystone.2023-07-19-14.59.log.html15:41
opendevreviewMerged openstack/keystone master: doc: Correct typo  https://review.opendev.org/c/openstack/keystone/+/88844318:39

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!