Wednesday, 2024-02-14

*** mhen_ is now known as mhen02:58
tkajinamCan anyone review https://review.opendev.org/c/openstack/ldappool/+/904662 and https://review.opendev.org/c/openstack/ldappool/+/906966 ?09:29
tkajinamthese have been kept open for some time09:29
*** d34dh0r5- is now known as d34dh0r5315:02
d34dh0r53#startmeeting keystone15:02
opendevmeetMeeting started Wed Feb 14 15:02:41 2024 UTC and is due to finish in 60 minutes.  The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot.15:02
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:02
opendevmeetThe meeting name has been set to 'keystone'15:02
d34dh0r53#topic roll call15:03
d34dh0r53admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, knikolla[m], lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann, zaitcev, reqa, dmendiza[m], mharley, jph, gtema15:03
bbobrovhello15:03
d34dh0r53o/15:03
xeko/15:04
dmendiza[m]🙋‍♂️15:07
d34dh0r53#topic review past meeting work items15:09
d34dh0r53no updates on either of mine :/15:10
d34dh0r53#action d34dh0r53 Look into adding/restoring a known issues section to our documentation15:10
d34dh0r53#action d34dh0r53 add https://bugs.launchpad.net/keystone/+bug/1305950 to the known issues section of our documentation15:10
d34dh0r53oops, forgot the link15:10
d34dh0r53#link https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-02-07-15.02.html15:11
d34dh0r53next up15:11
d34dh0r53#topic liaison updates15:11
opendevreviewBoris Bobrov proposed openstack/keystone master: Test listing app creds with deleted role  https://review.opendev.org/c/openstack/keystone/+/90899815:12
opendevreviewBoris Bobrov proposed openstack/keystone master: Test listing app creds with deleted role  https://review.opendev.org/c/openstack/keystone/+/90899815:13
d34dh0r53one note from releases, we've transitioned stable/yoga to unmaintained/yoga as part of the new TC resolution 2023-07-24 Unmaintained status replaces Extended Maintenance15:13
d34dh0r53#link https://governance.openstack.org/tc/resolutions/20230724-unmaintained-branches.html15:13
d34dh0r53and I don't have any VMT updates15:14
d34dh0r53#topic specification OAuth 2.0 (hiromu)15:15
d34dh0r53#link https://review.opendev.org/q/topic:bp%252Foauth2-client-credentials-ext15:15
d34dh0r53#link https://review.opendev.org/q/topic:bp%252Fenhance-oauth2-interoperability15:15
d34dh0r53External OAuth 2.0 Specification15:15
d34dh0r53#link https://review.opendev.org/c/openstack/keystone-specs/+/86155415:15
d34dh0r53OAuth 2.0 Implementation15:15
d34dh0r53#link https://review.opendev.org/q/topic:bp%252Fsupport-oauth2-mtls15:15
d34dh0r53OAuth 2.0 Documentation15:15
d34dh0r53#link https://review.opendev.org/c/openstack/keystone/+/83810815:15
d34dh0r53#link https://review.opendev.org/c/openstack/keystoneauth/+/83810415:15
d34dh0r53doesn't look like hiromu is around15:17
d34dh0r53so we'll move on15:18
d34dh0r53#topic specification Secure RBAC (dmendiza[m])15:18
d34dh0r53#link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_15:18
d34dh0r532024.1 Release Timeline15:18
d34dh0r53Update oslo.policy in keystone to enforce_new_defaults=True15:18
d34dh0r53Update oslo.policy in keystone to enforce_scope=True15:18
d34dh0r53#link https://review.opendev.org/c/openstack/keystone/+/902730 (Merged)15:18
d34dh0r53#link https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/90371315:18
dmendiza[m]Yeah, I finally updated all the tempest tests 15:21
dmendiza[m]Just looking for reviews now 15:21
d34dh0r53sweet! thanks dmendiza[m] 15:22
d34dh0r53I think I've reviewed everything, but please let me know if not15:22
dmendiza[m]I think there's one more backport I need. I'll ping you once I get the patch up for review.15:22
d34dh0r53thanks dmendiza[m] 15:22
d34dh0r53next up15:23
d34dh0r53#topic specification Improve federated users management (previously: Add schema version and support to "domain" attribute in mapping rules) (gtema)15:23
d34dh0r53#link https://review.opendev.org/c/openstack/keystone-specs/+/748748 - waiting for reviews15:23
gtemastill waiting for reviews;-)15:23
d34dh0r53ack, I'll try to get to it this week15:25
gtemawould be awesome, thanks15:25
d34dh0r53np15:26
d34dh0r53#topic open discussion15:26
d34dh0r53nothing is on the agenda but I'll leave the floor open for a few minutes15:26
d34dh0r53cool, moving on15:30
d34dh0r53#topic bug review15:30
d34dh0r53#link https://bugs.launchpad.net/keystone/?orderby=-id&start=015:30
d34dh0r53two new bugs for keystone15:30
d34dh0r53#link https://bugs.launchpad.net/keystone/+bug/205291615:31
d34dh0r53looks like someone is working on that, thank you!15:31
d34dh0r53#link https://bugs.launchpad.net/keystone/+bug/205313715:31
bbobrovthis is mine15:32
d34dh0r53ack15:32
bbobrovi have discovered a bit more after i posted it15:32
d34dh0r53thank you for looking into it15:32
d34dh0r53hmm, I wonder if that notification is ever being processed15:33
bbobrovthe problem is in listing role assignments with the role15:34
bbobrovhttps://opendev.org/openstack/keystone/src/commit/7dc175a41f92e3f01cf26912431d0f2c98a03b32/keystone/assignment/core.py#L103 returns an empty list15:34
bbobrovand i think i understand why15:35
bbobrovhttps://opendev.org/openstack/keystone/src/commit/7dc175a41f92e3f01cf26912431d0f2c98a03b32/keystone/assignment/core.py#L1342 because the role assignments are first deleted15:35
bbobrovand of course listing them then returns an empty list15:35
d34dh0r53I was just going to say, probably because the role_id no longer exists15:35
d34dh0r53I think #1342 needs to move below the notification15:36
bbobrovright, i switched the lines and my test passes15:36
bbobrovi will post the fix after my tox run finishes15:36
bbobrovhttps://review.opendev.org/c/openstack/keystone/+/908998 - the test to demo the issue btw15:36
d34dh0r53cool, thank you15:38
d34dh0r53ping when you're ready for reviews15:38
d34dh0r53next up15:39
d34dh0r53#link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=015:39
d34dh0r53no new bugs for python-keystoneclient15:39
d34dh0r53#link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=015:39
d34dh0r53keystoneauth is also good to go15:40
d34dh0r53#link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=015:40
d34dh0r53as is keystonemiddleware15:40
d34dh0r53#link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=015:40
d34dh0r53pycadf has no new bugs15:40
d34dh0r53#link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=015:41
d34dh0r53nor does ldappool15:41
d34dh0r53#topic conclusion15:41
d34dh0r53It looks like Registration is open for the PTG15:42
d34dh0r53#link https://openinfra.dev/ptg/15:42
d34dh0r53And here's a link to the etherpad we'll be using15:44
d34dh0r53#link https://etherpad.opendev.org/p/dalmation-ptg-keystone15:44
d34dh0r53I just started it so expect more soon15:44
bbobrovi am not sure that my company will pay that price for the ticket15:44
gtematoo many zeroes in the price?15:45
d34dh0r53lol15:46
d34dh0r53free ninety free!15:46
d34dh0r53Thanks everyone!15:47
d34dh0r53#endmeeting15:47
opendevmeetMeeting ended Wed Feb 14 15:47:54 2024 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:47
opendevmeetMinutes:        https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-02-14-15.02.html15:47
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-02-14-15.02.txt15:47
opendevmeetLog:            https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-02-14-15.02.log.html15:47
samcat116Hi all, we are trying to configure keystone OIDC with Azure AD and are hitting 400 errors very often. Sometimes I'll do things like hit the back button and it will get me into horizon with the proper user, but not usually. Running keystone with debug logs isn't showing any error messages at all. Any advice on what to look for?16:47
*** jph4 is now known as jph18:32

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!