Monday, 2024-02-19

*** mklejn_ is now known as mklejn08:36
Luzi#startmeeting image_encryption13:00
opendevmeetMeeting started Mon Feb 19 13:00:10 2024 UTC and is due to finish in 60 minutes.  The chair is Luzi. Information about MeetBot at http://wiki.debian.org/MeetBot.13:00
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.13:00
opendevmeetThe meeting name has been set to 'image_encryption'13:00
Luzi#topic Roll Call13:00
Luziwaiting for people to join13:02
fungioh, hey there!13:05
Luzihi fungi13:05
fungisorry, got sidetracked with some code reviews13:05
Luzino problem13:05
Luzithis will be a short meeting again13:05
Luzi#topic Image Encryption Patches13:05
Luziwell i got positive signs from scs to help with testing, but they have a lot of things to do too.. so i think this will be a good starting point for the next cycle13:06
Luzibesides that, i don't have anything for today13:07
Luzido you have any topic?13:07
fungithat's a great update, thanks for following up!13:08
fungino, i didn't have anything13:08
Luziokay, well then that was it for today13:08
Luzithank you for joining and have anice week13:08
fungihave a great week!13:08
Luzi#endmeeting image_encryption13:08
opendevmeetMeeting ended Mon Feb 19 13:08:40 2024 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)13:08
opendevmeetMinutes:        https://meetings.opendev.org/meetings/image_encryption/2024/image_encryption.2024-02-19-13.00.html13:08
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/image_encryption/2024/image_encryption.2024-02-19-13.00.txt13:08
opendevmeetLog:            https://meetings.opendev.org/meetings/image_encryption/2024/image_encryption.2024-02-19-13.00.log.html13:08
Luzibtw, are you involved in the secure RBAC topic?13:09
fungiLuzi: i haven't followed it as closely as i would like, but if you have questions i can try to help get some answers for you13:13
fungii think i'm fairly up on the current state and planned direction openstack-wide, but less certain what the per-project situation is at the momenyt13:14
Luziokay thank you, do you know how long the "old" policies can still be used?13:15
Luziso i mean, for the caracal release, it seems, like there is still a difference in progress for many projects13:16
Luzican the old policies still be applied with this release? And is there a plan on when the new policies will be mandatory?13:16
fungiLuzi: from what i've seen, not all projects have completed the current phase of adding the read-only role. i'm also not sure the plan included any guidance (beyond the normal configuration handling requirement for upgrades) about backward-compatibility for policies. though also at least the nova team has traditionally considered policy files to be service data rather than13:19
fungiconfiguration so even there the compatibility guarantees may vary13:19
Luziokay thank you fungi 13:20
fungiLuzi: by "old" policies are you referring to the json formatted ones, or the non-rbac ones?13:20
fungii think the policy yaml transition happened a while ago13:21
Luzithe unscoped ones, that can be changed in the yaml file13:21
fungiokay, that's what i thought you meant, just making sure13:22
fungiLuzi: the goal writeup refers to a status tracking pad at https://etherpad.opendev.org/p/rbac-goal-tracking13:22
fungithe timeslider indicates it was last updated a couple of weeks ago, so may be reasonably current13:23
fungifrom that, it looks like cinder may be the lone holdout of the commonly-deployed projects (not counting tacker) for phase 1 completion13:24
Luziyeah, i know that one - i am just a little bit concerned about the different defaults13:25
Luziwell, we will see13:25
fungiLuzi: it might be worth asking the secure rbac pop-up team to amend https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html with backward compatibility guidance/parameters as part of the timeframe laid out therein13:27
fungiin particular, with clarification around the slurp upgrade cadence which didn't exist when that plan was originally drafted13:28
fungithe only mention of backwards compatibility i see is about halfway through the direction change section where it talks about allowing system users to operate on project-owned resources with system-scoped tokens13:30
*** NeilHanlon is now known as nhanlon19:00
*** nhanlon is now known as NeilHanlon19:02
gmannfungi: ack,  yeah I need to update that rbac goal doc and with some of the timeline also. I will do it sometime in this week. thanks for notice19:16
fungigmann: no worries, probably fine if it's discussed at the ptg really19:17
gmannyeah, I was supposed to update those but always missed to do that. but I added it in my this week TODO19:19

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!