Monday, 2021-11-29

*** amoralej|off is now known as amoralej10:28
*** pojadhav is now known as pojadhav|brb11:28
*** pojadhav|brb is now known as pojadhav12:25
*** amoralej is now known as amoralej|lunch13:09
*** pojadhav is now known as pojadhav|brb13:15
*** tosky is now known as Guest714213:37
*** tosky_ is now known as tosky13:37
*** pojadhav|brb is now known as pojadhav13:45
*** amoralej|lunch is now known as amoralej14:07
*** ykarel is now known as ykarel|away14:27
*** pojadhav is now known as pojadhav|afk14:46
opendevreviewLance Bragstad proposed openstack/governance master: Rework the yoga secure RBAC community goal  https://review.opendev.org/c/openstack/governance/+/81515815:22
lbragstadmnaser gmann ^ updated with the new phase ordering15:22
lbragstadshould be up-to-date and addresses dansmith's most recent comments15:22
gmannlbragstad: ack, also Brian commented that system reader might be more useful in phase2 or service role15:25
lbragstadgmann i'll let dansmith and brian battle that one out :) 15:26
gmannlbragstad: but I am not much worry about the phase2/3 ordering and let's merge this and start phase1. later after discussion we can reorder too15:26
gmannlbragstad: yeah and we have time for that so that do not block the current goal to merge15:26
dansmithI think service role has a huge amount of actual benefit15:27
dansmithsystem-reader may be useful for some people, although I haven't heard anyone clamoring for it, while service role makes *everyone* more secure15:27
gmanndansmith: I am thinking for Audit but that can be done with system admin but yeah let's discuss those later15:28
lbragstadi do know some people need system-reader, but it's not a universal request like project-reader would be 15:28
lbragstads/would be//15:28
gmannricolin: mnaser please check this and re-vote  and other tc-members too https://review.opendev.org/c/openstack/governance/+/81515815:29
lbragstadand yeah - locking down service communication is a big won15:29
lbragstadwin*15:29
dansmithyeah, I'm not saying it has no purpose, just a very limited subset.. *everyone* has a service role today, and either has to define their own to make it secure, or use the default which is way too much power15:29
lbragstad++15:29
gmannyeah. 15:31
lbragstadalso - i think that's even more apparent now that we're keeping system completely separate from project resources (e.g., i can't use system-reader to list all instances in the deployment) 15:32
opendevreviewGhanshyam proposed openstack/governance master: Select secure and consistent RBAC as a community-wide goal  https://review.opendev.org/c/openstack/governance/+/81881715:32
gmannlbragstad: dansmith ^^ just rebased this goal selection patch too.15:32
gmanntc-members: and this too which need formal-vote https://review.opendev.org/c/openstack/governance/+/81881715:33
gmannlbragstad: good point. and system reader need enforce_scope=True by default so moving to phase-3 make sense to me now. 15:36
opendevreviewGhanshyam proposed openstack/governance master: Move completed goals into the completed directory  https://review.opendev.org/c/openstack/governance/+/81884516:12
*** amoralej is now known as amoralej|off16:29
opendevreviewLance Bragstad proposed openstack/governance master: Address followup comments to secure RBAC community goal  https://review.opendev.org/c/openstack/governance/+/81966418:03
opendevreviewLance Bragstad proposed openstack/governance master: Address followup comments to secure RBAC community goal  https://review.opendev.org/c/openstack/governance/+/81966418:04
*** tosky is now known as Guest716720:17
*** tosky_ is now known as tosky20:17
lbragstadyoctozepto just checking if https://review.opendev.org/c/openstack/governance/+/815158 is good to go now that we've pulled the other changes into a separate patch21:40
lbragstador is there still something you'd like me to change in 815158? 21:40
*** tosky_ is now known as tosky21:57

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!